CipherWatch All articles
Account Security

Sold by the Slice: How Data Brokers Piece Together a Portrait of Every American

CipherWatch
Sold by the Slice: How Data Brokers Piece Together a Portrait of Every American

Photo: data broker digital privacy surveillance profile information, via image.shutterstock.com

Somewhere in a data center you will never visit, a company you have almost certainly never heard of is maintaining a file on you. It knows your full legal name, your current and previous addresses, the estimated value of your home, your approximate income bracket, the vehicles registered in your name, and—depending on the broker—your political affiliation, your shopping habits, and the chronic conditions you searched for on the web last winter. No single agency compiled this dossier. It was assembled, piece by piece, from dozens of perfectly legal sources, then packaged and sold to anyone willing to pay a modest subscription fee.

Welcome to the data-broker economy, an industry that generates an estimated $250 billion in annual revenue in the United States and operates almost entirely outside public view.

What a Data Broker Actually Does

The term "data broker" covers a wide range of business models, but the core function is consistent: these companies collect personal information from as many sources as possible, cross-reference and clean the resulting records, and resell the aggregated output. Customers include marketers, insurers, employers conducting background checks, landlords, private investigators, and—critically—anyone else who can submit a credit card number.

Source material flows in from multiple directions simultaneously. Public records—property deeds, voter registrations, court filings, business licenses—form the foundation. Retailers sell purchase histories. Mobile apps sell location data harvested from GPS-enabled devices. Social media platforms sell behavioral signals. Credit-header data, which includes name, address, and phone number but stops short of credit scores, is sold by financial institutions. Loyalty programs, warranty registration cards, and online quizzes contribute additional layers. The result is a mosaic that, when fully assembled, can be more revealing than anything a private investigator could compile through traditional surveillance.

The Shocking Granularity of What Is for Sale

Researchers and journalists who have purchased their own broker profiles consistently report details they did not expect to find aggregated in a single record. A 2023 investigation by the Duke University Sanford School of Public Policy found that several brokers were willing to sell lists filtered by mental-health conditions, financial distress indicators, and religious beliefs—categories that carry obvious potential for exploitation or discrimination.

Location data represents a particularly acute risk. Brokers who specialize in mobile-derived geolocation can reconstruct months of movement history—identifying, for instance, that a specific device visited a particular medical clinic every three weeks, or that its owner commutes from a specific neighborhood to a specific office building. When that data is cross-referenced with a name and address from a separate source, the anonymization promise collapses entirely.

The detail available for purchase is not hypothetical. It is sitting in a database right now, indexed against your name, waiting for the next query.

The Legal Gray Zone That Keeps the Lights On

The United States has no single comprehensive federal privacy law governing data brokers. The patchwork of sector-specific statutes—HIPAA for health records, FCRA for credit reporting, COPPA for children's data—leaves vast quantities of consumer information unregulated at the federal level. Brokers have become expert at operating in the spaces between these statutes.

A handful of states have moved to fill the gap. California's Delete Act, signed into law in 2023, requires brokers registered with the state to honor deletion requests submitted through a single centralized mechanism—a significant step, but one limited to California residents. Texas and Oregon have enacted their own broker-registration requirements. Vermont maintains a public registry of brokers operating within its borders. Absent a federal standard, however, the protections available to any given American depend largely on which state they call home.

The Federal Trade Commission has brought enforcement actions against individual brokers for deceptive practices, but the agency has repeatedly called on Congress to enact broader legislation. As of mid-2025, no such legislation has passed.

Auditing Your Own Digital Footprint

Understanding your exposure is the necessary first step toward reducing it. The following approach will not eliminate your broker presence entirely, but it will provide a realistic picture of what is currently available and allow you to begin the removal process.

Step one: Search the major aggregators directly. Sites such as Spokeo, Whitepages, BeenVerified, Intelius, and MyLife index broker data and display it in consumer-facing interfaces. Searching your own name will reveal what a stranger could learn about you in under two minutes. Take note of which platforms return results.

Step two: Submit opt-out requests. Every broker that appears in your search maintains an opt-out mechanism—some straightforward, others deliberately cumbersome. Each must be addressed individually. The Privacy Rights Clearinghouse and the nonprofit organization Consumer Reports maintain updated guides listing opt-out URLs for major brokers.

Step three: Consider a data-removal service. Companies such as DeleteMe and Kanary charge annual fees to submit and re-submit opt-out requests on your behalf, which is necessary because brokers routinely re-populate removed records from fresh source data. These services do not guarantee complete removal, but they reduce the maintenance burden significantly.

Step four: Tighten the upstream sources. Opt out of data sharing in the privacy settings of loyalty programs, retail apps, and social media platforms. Disable precise location permissions for applications that do not require them to function. Use a separate email address for commercial registrations to limit cross-platform linkage.

Step five: Freeze your credit-header data. While a credit freeze does not directly restrict data-broker access, it limits the financial data that can flow into broker databases from credit-reporting agencies.

The Broader Implication

The data-broker industry is not populated exclusively by bad actors. Many of its customers use aggregated data for entirely legitimate purposes—fraud detection, academic research, journalism, and law enforcement among them. The problem is structural: a system built for benign use cases is equally available to stalkers, scammers, and hostile foreign intelligence services. When a phishing email arrives that accurately names your employer, references your neighborhood, and mentions a recent purchase, it was almost certainly assembled from broker data.

Digital privacy in the United States has long been treated as a personal responsibility rather than a systemic right. Until federal legislation changes that calculus, the burden of managing your own exposure falls squarely on you. Knowing what is out there—and who is selling it—is where that work begins.

All Articles

Related Articles

Always Listening: The Hidden Permission Creep That Turns Your Phone Into a Surveillance Device

Always Listening: The Hidden Permission Creep That Turns Your Phone Into a Surveillance Device

Ghost in the File: How Criminals Are Corrupting the Credit Bureaus Meant to Protect You

Ghost in the File: How Criminals Are Corrupting the Credit Bureaus Meant to Protect You

Locked But Not Sealed: The Real Boundaries of Encryption on Your Smartphone

Locked But Not Sealed: The Real Boundaries of Encryption on Your Smartphone