A data broker is not one product category. The term covers businesses that assemble information about people or households for people search, identity resolution, advertising, fraud prevention, risk analysis, business prospecting, research, and other uses. A state statute may define a broker by collecting and selling personal information about a consumer with whom the business has no direct relationship. Another registry may apply a different threshold or contain explicit exclusions. The operational question is therefore both “what does this company do?” and “which definition governs this record?”
1. The broker role in a data supply chain
A broker typically sits between sources and users. Sources can include public records, government publications, property and professional filings, websites, commercial partners, surveys, purchase or interest signals, and data contributed through software or customer systems. The broker normalizes identifiers, resolves records that may refer to the same person, appends fields, creates segments or inferences, and then exposes an interface, file, API, score, audience, or search result.
The buyer or user may never receive a neat “profile.” A marketing platform might allow selection of an audience without disclosing individual names. A business-contact provider may expose a work email and job role. A people-search site may publish current and former addresses, relatives, telephone numbers, or links to public records. A fraud provider may return a confidence signal. These products feel different, but they all depend on acquiring, linking, or deriving information outside the immediate interaction where it will be used.
2. Legal definitions are narrower than ordinary language
In ordinary conversation, “data broker” can mean any company that trades or aggregates data. Statutory definitions are more precise. California’s privacy agency describes a broker as a business that knowingly collects and sells to third parties personal information about a consumer with whom it does not have a direct relationship. The California definition also contains exclusions for activity covered by specified laws. The California Privacy Protection Agency FAQ is a primary starting point, while the enacted statute and regulations supply the controlling detail.
The distinction matters. A company can maintain direct-customer data and brokered data in parallel. A financial institution may hold account data governed by the Gramm-Leach-Bliley Act while an affiliated service performs another function. A consumer-reporting agency may handle information under the Fair Credit Reporting Act. It is not accurate to conclude from a brand name alone that every record enters a comprehensive state-law deletion system.
3. People-search brokers
People-search sites make personal profiles discoverable through identifiers such as a name, phone number, email address, or street address. Results often combine public records with commercially sourced contact and household data. A free preview may expose enough detail to identify a person, while a paid report or sponsored link offers more. The exact operator matters because search pages, fulfillment providers, and advertised report services can be separate entities with separate opt-out routes.
Removal usually begins with locating the precise public profile. Some sites require the profile URL; others ask for matching identifiers and perform the search inside a privacy form. Email confirmation is common. A guide should say whether each duplicate profile needs a separate request and whether the site states a processing time. Trustifo’s verified removal guides publish those details only when the current first-party route can be observed.
4. Business-contact brokers
Business-contact databases organize professional information such as employer, job title, work email, direct dial, seniority, department, location, education, and professional social profiles. Customers use the data for sales, recruiting, market research, and account intelligence. A person may discover the record through an unexpected marketing message rather than a public search result.
The removal route may be labeled “Privacy Center,” “Manage my profile,” “Request removal,” “Delete my data,” or “Do not sell or share.” Marketing unsubscribe is usually a separate operation: it stops messages from one sender but may leave the professional profile available to customers. A person seeking removal should select the database or profile control, complete authentication, and ask whether the broker maintains a narrow suppression record to prevent re-entry.
5. Advertising and audience brokers
Advertising brokers may organize devices, browsing or purchase signals, locations, interests, demographics, and inferred attributes into audiences. The user of the audience may not learn the identity of every person inside it. Opt-out controls can involve cookies, mobile advertising identifiers, browser signals, account settings, or direct rights requests. Clearing a cookie can also clear the technical token that stored a previous choice, so an opt-out should be understood at the device and account level described by the provider.
Global Privacy Control and other universal opt-out mechanisms can communicate a preference automatically where law or company policy recognizes them. They do not necessarily delete historical data or remove a people-search profile. The operational effect depends on the signal, the browser or extension, the recipient, and the governing law.
6. Public records are inputs, not a complete explanation
Calling information “public record” does not explain how it was collected, combined, ranked, inferred, or redistributed. A county filing may be legally available at a clerk’s office while a broker makes the same field searchable by anyone worldwide and links it with telephone, household, and employment information. The privacy impact comes from accessibility and aggregation as well as from the source field.
A deletion request to a broker generally does not alter the government source. If the public record is inaccurate, the correction may need to begin with the responsible agency. After the source changes, a broker may still need time or a new request to refresh its copy. A precise workflow separates source correction, broker suppression, search-engine cache removal, and deletion from downstream recipients.
7. Identity resolution and record matching
Brokers use identity resolution to decide which observations belong together. Names vary, addresses change, work emails expire, phone numbers are reassigned, and households share devices or contact points. Matching systems use combinations of identifiers and may assign confidence rather than certainty. That is why a removal form can ask for a former city or an email address that appears on the record.
Matching creates two opposing risks. Too little information can leave the broker unable to authenticate or locate a record. Too much information can enrich the database or expose sensitive data unnecessarily. The practical rule is data minimization: provide the least sensitive combination reasonably necessary through a secure first-party channel, and ask for an alternative when the requested proof appears disproportionate.
8. Inferences and scores
A broker does not need a source that states an attribute directly. It can infer interests, household composition, purchasing intent, likely income band, risk, job function, or probable movement from other signals. An inference is still information about a person even when it is a prediction. California’s DROP materials expressly discuss deletion of associated inferences when a broker matches a covered request, subject to legal exceptions.
Removing a visible profile may not reveal which inferences were stored or supplied elsewhere. Access rights can help a person learn categories or specific pieces of information, but access and deletion are different operations. If understanding the record matters before erasure, the sequence may be access first, then correction or deletion. The tradeoff is that access can require stronger authentication and may extend the workflow.
9. Sale, sharing, licensing, and access
Privacy statutes define “sale” rather than relying on the everyday idea of handing over a spreadsheet for cash. Some definitions include exchange for other valuable consideration; others are narrower. Exceptions can apply to processors, requested transactions, disclosures directed by a consumer, mergers, or other specified transfers. “Sharing” under California law has a particular connection to cross-context behavioral advertising.
A company may license access to a searchable product, return an API result, activate an audience, or allow a customer to export a record. The commercial form does not by itself determine the legal label. For a request, use the language provided by the company’s privacy notice and the governing state source. If both deletion and opt-out of sale or sharing are available, consider whether the objective requires both.
10. Deletion, suppression, and de-indexing are different
Deletion generally seeks erasure of covered personal data, subject to authentication and exceptions. Suppression often means making a profile unavailable and retaining a small identifier so it does not return. De-indexing removes a result from a search system without necessarily changing the source. An unsubscribe stops a communication stream. A cookie opt-out changes tracking or advertising behavior. A careful guide never substitutes one for another.
Suppression can be the privacy-preserving outcome for a public directory because deleting every trace of the request may allow the next data refresh to recreate the profile. The remaining suppression list should be limited and protected. A reader can ask the broker whether the public record is hidden, whether distribution stops, which fields remain solely for suppression, and whether affiliates or downstream customers receive the choice.
11. The first-party route rule
A first-party route is hosted by the broker or linked by its official privacy notice. This rule reduces several common errors: submitting to a paid service presented as an advertisement, following instructions for a similarly named site, using a form retired after an acquisition, or sending personal data to a blog. Third-party guides are useful discovery tools, but the live broker page must settle the procedure.
The URL alone is not enough. Review the domain, legal entity, request purpose, required fields, verification method, and confirmation behavior. If the endpoint is blocked to automated review, a responsible publisher states that limitation. Trustifo keeps Pub360 as unverified rather than manufacturing a procedure from stale fragments.
12. A disciplined removal workflow
- Inventory exposure. Search the identifiers already associated with you: common name variations, phone numbers, personal and work emails, and current or former cities. Do not publish new identifiers to test a site.
- Confirm the operator. Read the footer and privacy notice to identify the company responsible for the record. Sponsored results may belong to another operator.
- Choose the right control. Distinguish public-profile suppression, deletion, access, correction, sale or sharing opt-out, and marketing unsubscribe.
- Minimize submission data. Start with the profile URL or identifier shown in the record and an email you control. Use secure verification routes.
- Preserve evidence. Record the date, source URL, confirmation number, and broker response. Do not keep unencrypted copies of more sensitive data than necessary.
- Recheck. Search after the stated processing time. Open the result to distinguish a live profile from a stale search-engine snippet.
- Escalate precisely. Ask for the denial reason and appeal route. Use a state complaint channel only after reading the law’s coverage and instructions.
13. Why records can return
A broker can receive a new data feed, resolve a record under a different identifier, rebuild an index, or treat a changed work profile as new information. A removal may cover one profile URL but not a duplicate. A suppression record may fail to match a new email or phone number. Recurrence is therefore a system property, not necessarily evidence that the initial request was ignored.
Recheck frequency should reflect risk and change. A person dealing with harassment or a newly exposed home address may need a shorter cycle. A stable professional record may be checked after a job transition. Keep a small log that records broker, profile URL, request type, submission date, confirmation reference, stated processing time, result, and next check. Do not turn the log into a new unprotected store of sensitive data.
14. State comprehensive privacy laws
By July 26, 2026, Trustifo tracks comprehensive privacy laws in 20 states: California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Their scopes and rights are not identical. The state matrix links each entry to a primary state source.
Common rights include access, deletion, correction, portability, and opt-out of sale, targeted advertising, or certain profiling. Iowa and Utah provide narrower deletion or opt-out formulations than some peers. Oregon gives covered residents a right connected to specific third parties in defined circumstances. Maryland emphasizes data minimization. Exact text, effective dates, exemptions, thresholds, and enforcement must be checked state by state.
15. California’s data-broker-specific system
The California DELETE Act created an accessible deletion mechanism implemented as the Delete Request and Opt-out Platform. California residents could begin submitting requests on January 1, 2026. Registered data brokers must begin accessing and processing the request lists on August 1, 2026 and repeat the cycle at least every 45 days, according to the California Privacy Protection Agency.
DROP is significant because it reduces the need to find hundreds of separate broker forms. It still relies on matching. A resident keeps a DROP ID and can review reported outcomes. A “record not found” result can mean the broker has no information or cannot match what was supplied. The complete Trustifo DROP guide explains the sequence and links to current agency materials.
16. Federal sectoral laws
The United States does not use one comprehensive federal consumer privacy statute for every broker. Sectoral laws cover particular records and activities. The FCRA governs consumer reports used for eligibility decisions and creates accuracy, disclosure, and dispute duties. Many people-search sites explicitly say they are not consumer reporting agencies and prohibit use of their products for employment, credit, housing, insurance, or similar decisions.
The DPPA restricts disclosure and use of personal information from state motor-vehicle records, subject to permitted uses. The GLBA addresses nonpublic personal information handled by covered financial institutions, including privacy notices and safeguards. State laws frequently refer to these regimes in exemptions, which is why a request should identify the data and activity rather than only the organization.
17. Authentication without unnecessary exposure
A broker has a legitimate reason to avoid giving a stranger access to or control over another person’s record. Authentication can involve an email link, SMS code, profile URL, known data fields, signed authorization, account login, or—in higher-risk contexts—document proof. Reasonableness depends on the sensitivity of the data and the requested action.
Use a dedicated email alias when the broker permits it, but understand that a broker may need an address already associated with the profile. Never send passwords or an unredacted identity document through ordinary email. If a form requests a document, read the retention and security explanation, mask unrelated data when allowed, and ask whether another method can verify the request. An authorized agent may need both proof of authority and separate consumer verification.
18. What to do after a denial
A useful denial response identifies the reason, the right involved, and any appeal mechanism. The problem may be failed authentication, inability to locate the record, an exemption, a legal retention duty, a request submitted to the wrong entity, or a limit on repetitive requests. Ask the broker to state which condition applies and what narrower request remains available.
Many state privacy laws provide an appeal process before a consumer contacts the enforcing authority. The deadline and notice requirements vary. Preserve the original request and response, then use the primary state source to find the complaint route. Do not assume that a regulator can remove the record immediately. A complaint documents an alleged failure; the regulator controls investigation and enforcement.
19. Measuring success
Success is not the submission screen. It is an observable change connected to the requested operation: the public profile no longer loads, a data-access response identifies no active record, the broker confirms an opt-out, or the company explains what limited information remains for suppression. Search engines can keep cached titles and snippets after a source disappears, so verify the source page before escalating.
Check duplicates, aliases, former locations, and the identifiers the broker uses for search. If one profile remains, determine whether it has a separate URL. If a downstream report still appears, identify its operator rather than assuming the first broker controls it. The Trustifo broker matrix records each reviewed brand separately and never sends readers to another site merely because the interfaces look related.
20. A sustainable privacy routine
Broker removal is maintenance, not a one-time purge. Keep the process small enough to repeat. Prioritize records that expose home contact details, high-risk professional information, or identifiers connected to harassment and fraud. Then handle widely distributed business-contact profiles and lower-risk directories. Use verified direct routes before paid automation, and understand what any service will collect to act as an agent.
A quarterly or event-driven review is often more manageable than constant searching. Trigger a check after a move, legal name change, new phone number, public filing, job change, or safety incident. Maintain only the evidence necessary to follow up. The goal is not to prove that no copy exists anywhere; it is to reduce exposed, searchable, and redistributed data through traceable actions.
21. How to use Trustifo
Start with Remove my data when the broker has a verified guide. Use the broker index to identify directory-only providers and understand why a procedure is withheld. Consult the law map for primary state and federal sources, and open the glossary when a form or response uses an unfamiliar term.
Each full guide answers the immediate question in its opening, displays method, processing, verification, and recurrence in a compact table, then gives the first-party steps, refusal handling, legal context, FAQ, verification date, and source. That structure is designed to make uncertainty visible. “Not stated” is more useful than an invented deadline; “directory only” is safer than a stale form.
Last reviewed July 26, 2026 by Trustifo Editorial. Core primary references: California Data Broker Registry, CalPrivacy on data brokers and DROP, and the government sources linked throughout the Trustifo law map. Informational reference, not legal advice.