If a data broker has your information, send a focused deletion or opt-out request first and save proof that you made it. If the broker ignores the request, rejects it, or puts the same listing back, report that specific conduct to the regulator with jurisdiction.

Use the route that matches what you want done:

No regulator guarantees that an individual record will be deleted, and the FTC doesn't promise a 15-day response. What helps is a clear request, a dated evidence file, and a complaint sent to the agency that actually has authority.

Choose the right route first

A data broker complaint isn't the right tool for every privacy problem. Decide the outcome you want before you file.

Your goal Best first step Important limit
Remove your profile from a people-search or data broker site Use the broker's official opt-out or deletion process Removal from one broker does not remove copies held elsewhere
Stop a broker from selling or sharing information Submit the applicable opt-out request An opt-out may not delete information already retained
Report a misleading, hidden, or repeatedly ignored privacy process File with the FTC and, when appropriate, your state AG A complaint may support enforcement but usually is not an individual court order
Challenge information used for credit, employment, housing, or insurance Check whether the Fair Credit Reporting Act dispute process applies A general marketing opt-out is not the same as disputing a consumer report
Use European privacy rights Contact the controller first, then the relevant data protection authority GDPR coverage depends on the processing and people affected, not just the broker's location

People-search websites, advertising companies, credit-reporting agencies, public-record services, and other data businesses can be governed by different rules. The company's business model and how it uses your information matter more than the "data broker" label.

Build your evidence before contacting anyone

Make one folder for that broker and keep the original files, not later recaps. Include:

Stick to facts. "The profile displayed my current home address on March 4, and the deletion link returned an error" is more useful than "The company violated all privacy laws."

Give the broker only the information needed to match your record. Redact unrelated account numbers, full identity documents, Social Security numbers, and financial details unless an official process genuinely requires them. Keep a copy of anything you submit.

Send a direct deletion or opt-out request

Use the broker's own privacy or opt-out page, not a search advertisement or an unverified third-party form. Look for separate choices such as:

If you want deletion and an opt-out, request both when the applicable law allows it. Don't assume that selecting an opt-out also deletes the record.

You can keep the request short:

Subject: Request to delete or stop selling my personal information

To [Broker name]:

I am requesting [deletion of my personal information and/or opt-out of sale or sharing] for information associated with:

Name: [name]
Matching email or phone: [limited information needed to identify the record]
Profile URL or record number: [link or number]

I am making this request under [applicable law, if known]. Please confirm receipt, tell me what action you took, and explain any information you must retain or any exemption you are relying on. Please also provide the applicable appeal or complaint process.

I submitted this request on [date] through [method]. Attached are [screenshots and confirmation details].

Sincerely,
[name]

Save the confirmation page immediately. If the broker asks for more identity information, check that you're on the company's genuine domain and provide only what is reasonably necessary.

California residents: use the DROP platform

California's Delete Request and Opt-out Platform, known as DROP, is a specialized route for California residents who want covered data brokers to delete their information. Use the California DROP platform.

Before you submit, the platform requires you to verify that you are a California resident, as defined in section 17014 of Title 18 of the California Code of Regulations as that section read on September 1, 2017.

  1. Open the official DROP platform.
  2. Complete that residency verification.
  3. Submit the deletion request to the participating or covered brokers listed by the platform.
  4. Save the submission confirmation and review the status of each request.
  5. If a broker reports an exemption, no matching record, or another incomplete result, keep that result with your evidence.

If the verification providers can't confirm your California residency, the platform says you may request a review of that classification under section 7622 of Title 11 of the California Code of Regulations.

Beginning August 1, 2026, data brokers are required to process DROP deletion requests at least once every 45 days. That's a recurring processing duty. It isn't a promise that every record will be deleted within 45 days, or that every request will get the same outcome. A broker may report that information was deleted, opted out of sale, exempt, or not found.

DROP is a deletion-request platform, not a substitute for a complaint about deceptive conduct or a separate claim for damages. If a broker appears not to be processing the request, save the platform status, broker name, dates, and screenshots before contacting the appropriate California enforcement agency.

File a complaint with the FTC

The FTC complaint form is for suspected nationwide unfair or deceptive conduct. Examples include a broker that:

An FTC complaint is a report to the agency. It isn't a direct deletion request, a mediation service, or a guaranteed path to compensation. The FTC may use complaints to identify patterns and support investigations, but it generally doesn't give consumers a guaranteed individual resolution timeline.

Make the report specific:

  1. Identify the broker, website, app, and any related company name.
  2. Explain what information was collected, displayed, sold, or used.
  3. Give the dates and exact steps you took to opt out or request deletion.
  4. Quote the broker's relevant promise or response where possible.
  5. Describe the result, including an error message, denial, continued listing, or lack of response.
  6. State the outcome you want, such as review of the conduct or enforcement action.

Don't label a routine privacy dispute as identity theft unless someone actually used your information fraudulently. Accurate reports are more useful than dramatic ones.

Contact your state attorney general

When the issue involves a state privacy law, a state data broker registration requirement, or conduct affecting residents of that state, the state attorney general may be the better route. Start with the AG's official consumer complaint page and check its residency and documentation requirements.

You can report to the FTC and a state AG when both routes are relevant, but keep the facts consistent. Explain why the broker is connected to your state, and name the law or requirement only if you're reasonably sure it applies.

State rules vary. For example, the Texas Attorney General's data broker guidance says the Texas Data Broker Act requires covered entities to register, post a conspicuous data broker notice, and maintain comprehensive information-security safeguards. It also says the Texas Secretary of State does not investigate alleged violations of the Act; complaints should be directed to the Attorney General. The guidance states that penalties under the Act may not exceed $10,000 in a 12-month period.

That Texas rule doesn't establish the same deadline, penalty, or complaint process in another state. A state AG complaint may lead to an inquiry or enforcement action without producing a personal deletion, refund, or payment.

GDPR requests for people in Europe

If the GDPR or UK GDPR applies to the processing of your information, contact the data controller before filing with a supervisory authority.

A written request can ask for:

The controller normally must respond within one month. It may be able to extend the period for a complex request, but it should explain that within the initial response period. If the controller refuses, doesn't respond, or gives an inadequate answer, complain to the data protection authority in the relevant country. UK residents generally use the ICO, while people in the EU or EEA use the appropriate national authority.

GDPR doesn't automatically apply to every U.S. broker or every U.S. consumer. The broker's activities, the people targeted, and the nature of the processing determine whether the law applies. A U.S. consumer can't create GDPR coverage simply by sending an Article 17 request to an American company.

Write a regulator complaint that can be acted on

Use a short chronological narrative. Include the request and the failure, not a long description of the entire data broker industry.

Broker: [name and website]

On [date], I found a profile containing [specific information] at [page address].
The broker's privacy page said [briefly quote or describe the relevant process].
On [date], I submitted a request to [delete the information, opt out of sale or sharing, correct the record].
My confirmation number was [number].

On [date], the broker [denied the request, did not respond, displayed the profile again, or gave another result].
The information remains visible at [current page address], as shown in the attached screenshot.

I am asking the agency to review whether this conduct violates [specific law or stated privacy promise]. I want the agency to know that [brief description of consumer or safety impact].

If you don't know the exact law, describe the conduct plainly and say that you're asking the agency to determine which rule applies. Guessing several unrelated statutes can make a complaint harder to evaluate.

Timelines and escalation

There isn't a single data broker complaint deadline for every U.S. consumer. Use this as a planning guide:

Step What to expect
Direct broker request Follow the deadline stated by the applicable law or the broker's policy
California DROP Covered brokers must process requests at least once every 45 days beginning August 1, 2026
FTC complaint No guaranteed individual response or resolution period
State AG complaint Timing and follow-up depend on the state and the agency's workload
GDPR request Normally one month for the controller's response

A sensible escalation sequence is:

  1. Submit a focused request and save the confirmation.
  2. Wait through the applicable response period.
  3. Send one concise follow-up if the broker hasn't responded.
  4. File with the FTC, state AG, or data protection authority using the evidence you already organized.
  5. If the issue involves financial loss, a consumer report used for eligibility, threats, or sensitive personal safety concerns, consider the specialized dispute or support route for that problem.

A regulator's acknowledgment isn't the same as a finding that the broker violated the law. Likewise, a broker's deletion confirmation may not remove information held by another broker, a public-record source, or a separate business.

Why complaints are rejected or go nowhere

Most weak complaints fail because the agency can't tell what happened or whether it has authority. Common problems include:

Don't send multiple contradictory versions of the same complaint. If new evidence appears, add it to the existing timeline and explain what changed.

Frequently asked questions

Is an FTC complaint the same as a deletion request?

No. A deletion request goes to the broker. An FTC complaint reports possible unfair or deceptive conduct to a federal agency. Submit the direct request even if you also report the company to the FTC.

Does California DROP cover every company with my information?

Not necessarily. DROP applies to the data brokers covered by California's program. A company that isn't covered, a record reported as exempt, or a source outside the program may require a separate request.

Does the California 45-day period mean my data will be deleted in 45 days?

No. Beginning August 1, 2026, covered brokers must process DROP requests at least once every 45 days. The result still depends on whether the broker finds a matching record and whether an exemption applies.

Can a U.S. consumer use GDPR against any U.S. data broker?

No. GDPR coverage depends on the controller's activities and the processing involved. The broker's U.S. location alone doesn't establish a GDPR right.

What should I do if the broker publishes my information again?

Capture a new screenshot, record the date, compare the new listing with your original confirmation, and send a follow-up that references both events. If the pattern continues, include the repeated publication in an FTC or state AG complaint.

Save the broker's profile page and privacy-policy page first, then send one precise request with a date and a matching identifier you can safely provide.