Data brokers collect personal information from public records, commercial partners, websites, apps, devices, and other brokers. They then standardize and match those fragments, add inferences, and repeatedly update the resulting person or household profiles.
That describes a supply chain, not a single collection event. A broker may receive a purchase file from one source, obtain an address from another, associate both with a device identifier, and calculate an attribute from the combined record. The guide to what a data broker is explains the products built from this process.
The collection model in one view
The Federal Trade Commission’s study of nine data brokers documented three broad source groups—government, other publicly available, and commercial—and transfers through data feeds, APIs, web crawling, scanned records, and other brokers. It also showed that raw and inferred fields can appear in the same product. The historical study is not a current inventory of every broker.
| Source or stage | Typical input | How it reaches a broker | What may happen next |
|---|---|---|---|
| Government and public records | Property, licensing, court, voter, or directory information, subject to source-specific access rules | Direct access, bulk files, intermediaries, crawling, scanning, or manual entry | Records are standardized and linked to a person, address, or household |
| Commercial sources | Purchases, subscriptions, registrations, warranty records, and customer attributes | Purchase, license, reseller agreement, recurring feed, or API | Contact details may be appended and transaction patterns may become categories |
| Websites, apps, and devices | Browsing events, cookies, advertising IDs, app activity, or location signals | Tags, software development kits, partner integrations, or supplied event files | Online identifiers may be associated with offline records or audience segments |
| Other data brokers | Compiled public, commercial, or derived data | Dataset purchase, license, or reciprocal supply relationship | Provenance becomes layered because the immediate supplier may not be the original collector |
| Analysis inside the broker | Matched facts and behavioral signals | Rules, statistical models, or classification systems | The broker creates inferred interests, likely characteristics, scores, or segments |
The table separates sources from processing. A recorded home sale is an acquired data point. A conclusion about likely income, interests, or purchasing intent is a derived attribute. A profile can contain both without making the inference an independently verified fact.
Where the underlying records come from
Government and other public sources
Public records are created by different offices for different purposes. The FTC report identified professional and recreational licenses, property and assessor records, voter registration information, court records, bankruptcies, and selected vital records among sources used by the companies it studied. Some brokers obtained state and local records through intermediaries rather than directly from the responsible office.
Other public material may include directories, press reports, blogs, and information visible on social platforms or the open web. Crawlers can copy selected fields at scale; printed material can be scanned or entered manually. Public visibility does not show that the resulting profile is complete, current, or correctly matched.
Businesses with a direct customer relationship
Information can move from a first-party business to a broker or intermediary. Examples include account details, purchase histories, subscriptions, loyalty activity, warranty registrations, surveys, or promotions. CalPrivacy says brokers often obtain information from businesses people interact with directly and distinguishes transferred data from data retained only in the original first-party relationship (CalPrivacy source).
The FTC study describes supply, licensing, and reseller agreements, along with batch feeds and APIs. A fixed dataset may contain more fields than one product needs; extra fields can support matching, authentication, or modeling.
Websites, apps, and connected devices
Digital collection can attach activity to a browser, app, device, account, or advertising identifier. Mechanisms include cookies, site tags, software embedded in an app, and event data supplied by advertising or analytics partners. The signals may describe page visits, searches, ad interactions, app events, or location observations.
In its action involving X-Mode Social and Outlogic, the FTC said the companies obtained precise location data from their own apps, third-party apps containing a software development kit, and other brokers or aggregators (FTC order announcement). The matter shows possible routes; it does not establish that every app or broker collects precise location.
Other brokers and aggregators
Broker-to-broker collection makes provenance difficult to reconstruct. A vendor may combine public records, retail data, and another supplier’s dataset before transferring the result. In the FTC study, most of the nine brokers obtained most of their data from other brokers. That finding is not a universal industry percentage.
Layered transfers can put the same outdated address or mistaken association in several databases. Separate companies may share an upstream source rather than having observed the fact independently.
How separate fragments become a profile
Collection alone does not create a person-level product. Brokers must make differently formatted records comparable and decide which probably concern the same person, device, or household.
Standardization and matching
Standardization makes equivalent values consistent by formatting addresses, names, phone numbers, or email addresses. Matching then compares identifiers such as a name, current or former address, date of birth, email, phone number, device ID, or a combination.
The FTC found that matching standards varied by use. Some marketing products accepted a name-and-address match, while identity-verification products used more exact comparisons. People-search products used context such as age or residence to distinguish shared names. A match is an operational conclusion, not proof that every attached record belongs to that person.
Enrichment, inference, and segmentation
After linking records, a broker can append fields, group people with similar attributes, or apply a model. A purchase category may contribute to an inferred interest; household and transaction variables may contribute to a predicted response category. The FTC distinguished actual data elements, derived elements, and segments. CalPrivacy says processing can produce inferences about health, family, political views, or finances (agency explanation).
Useful reading therefore requires three labels:
- Observed: copied or received from a stated source, though it may still be stale or wrong.
- Linked: associated with a person or household through a matching process.
- Inferred: calculated, predicted, or assigned from other data rather than directly observed.
An exported attribute that looks precise can still be a household assignment, estimate, or model output.
Refreshing and distribution
Broker databases are not necessarily static. Suppliers may send batch files, APIs may return updated fields, and crawlers may revisit sources. A broker can replace or preserve conflicting values, then provide lists, append client files, return API results, or make audiences available through another system.
This cycle can reintroduce a removed copy if an upstream source continues to supply it, or preserve former addresses after a newer value arrives. No single refresh schedule applies to every broker.
Why broker profiles may be incomplete or wrong
Every stage introduces uncertainty. A public record can lag behind a real-world change. A commercial source can contain a typing error. Two people can share a name, address, phone number, or family relationship. A household attribute can be applied to each resident. A probabilistic match can join unrelated records, and a model can assign an interest that the person does not have.
The FTC found that some studied companies compared sources, tested consistency, or favored a source they considered more reliable, but practices varied. A broker profile is an assembled claim about identity and behavior, not a certified biography.
A practical way to trace likely collection routes
When investigating an unfamiliar profile or marketing contact, use evidence from the record rather than guessing at one source:
- Separate displayed facts from predictions. Mark exact identifiers, dated events, household associations, and broad interest labels differently.
- Look for source clues. Property details suggest an assessor or real-estate feed; a transaction category suggests commercial data; a device ID or precise movement pattern suggests a digital source.
- Compare variants. Old names, former addresses, duplicate profiles, and misspellings can reveal which records were joined or refreshed unevenly.
- Identify the responsible legal entity. A consumer-facing product name may differ from the company that controls the database. The broker index can help locate source-linked entity records without relying on a commercial people-search site.
- Read the first-party privacy notice. Check source categories, purposes, recipients, and rights language. An industry description does not prove how a specific field was collected.
- Use narrow privacy controls. Browser and device settings can reduce some future digital collection, but they do not erase public records, licensed commercial files, or copies already held elsewhere.
- Keep a neutral record. Save the company name, relevant page, date observed, fields at issue, and any response. Avoid sending extra sensitive identifiers until the recipient and purpose are clear.
Legal definitions and California’s broker system
“Data broker” can be an industry description or a legal category. The data broker glossary entry is orientation; the applicable statute controls. California defines a data broker as a business that knowingly collects and sells to third parties personal information about a consumer with whom it lacks a direct relationship, subject to stated exclusions (California Civil Code section 1798.99.80). Do not generalize that definition to other laws.
California’s DELETE Act is the law enacted through SB 362. DROP is the Data broker Requests and Opt-out Platform implementing its centralized request mechanism (official DROP page). They are related, not two names for the same thing. Use the Trustifo law map to reach current official sources before assessing rights or coverage.
Knowing how a record was collected helps identify the likely upstream source and the limits of any single control. It does not by itself establish that a practice is lawful or unlawful, that a company falls within a statutory definition, or that a particular right applies. This article provides general information, not legal advice.
Frequently asked questions
Where do data brokers get personal information?
Common sources include government and other public records, commercial transactions, websites and apps, and datasets obtained from other brokers or aggregators.
Do data brokers collect everything directly from individuals?
No. Many records reach brokers through public sources, businesses a person interacted with, technical collection partners, or other brokers rather than through a direct relationship.
How do data brokers connect separate records to one person?
They standardize fields and compare identifiers such as names, addresses, email addresses, phone numbers, device identifiers, and other available attributes, with matching methods varying by product.
Are all attributes in a data broker profile verified facts?
No. A profile may combine observed records with modeled or inferred attributes, and matching or source errors can assign information to the wrong person or household.
Can one privacy setting stop all data broker collection?
No. Browser or device controls may limit particular digital signals, but they do not remove government records, commercial files, previously transferred datasets, or broker-to-broker copies.
Primary sources
- Federal Trade Commission — Data Brokers: A Call for Transparency and Accountability
- Federal Trade Commission — Order involving X-Mode Social and Outlogic
- California Legislature — current Civil Code sections 1798.99.80–1798.99.89
- California Legislature — SB 362, the DELETE Act
- CalPrivacy — Personal information and data brokers
- CalPrivacy — Delete Request and Opt-out Platform (DROP)
This article provides general information, not legal advice.