A data broker dispute is a request to correct, delete, or limit the use of personal information held by a data broker. The right process depends on the type of data involved.

For marketing profiles, people-search listings, and advertising data, start with the broker’s privacy or opt-out process. If inaccurate information affected your credit, housing, employment, or insurance application, use the separate consumer-report dispute process instead. A privacy request may remove a profile, but it won’t automatically correct a credit report or reverse a decision.

There also isn’t one federal FTC process that gives every data broker dispute a 30-day response. Deadlines depend on the law that applies, your state, the type of request, and the company’s own procedure.

What a data broker dispute can accomplish

Data brokers collect information from public records, commercial sources, websites, apps, and other companies. Profiles may include:

Depending on the company and your location, you may be able to request that it:

  1. Correct a specific inaccurate detail
  2. Delete some or all personal information
  3. Stop selling or sharing information
  4. Remove a public-facing people-search profile
  5. Explain how it uses or obtained certain information

These requests have limits. Deleting a record from one broker doesn’t remove copies held by other brokers, public agencies, lenders, landlords, employers, or the original data source. Information may also reappear if it’s collected again.

Use the right dispute process

Before filing, identify how the information was used. This decision prevents a common mistake: sending a privacy deletion request when you actually need to challenge a consumer report.

Problem First step What the request may not do
Wrong address or profile on a marketing or people-search site Submit a privacy correction, deletion, or opt-out request to that site It may not remove the same information elsewhere
Wrong information in a credit, tenant, employment, or insurance report Request the report and dispute the item with the consumer reporting company and the company that supplied it A general privacy opt-out may not correct the report
Spam calls, texts, or emails Opt out with the sender and relevant broker, then use carrier or email controls Removing a broker profile won’t stop every source of spam
Identity theft or exposed account credentials Secure affected accounts and use the appropriate fraud-reporting process A broker deletion request won’t repair a compromised account

Credit, tenant, employment, and insurance screening can fall under the Fair Credit Reporting Act, or FCRA. That process is different from a marketing-data opt-out. If a company denied you housing, credit, employment, or insurance, ask which reporting company supplied the information and preserve any adverse-action notice before requesting deletion.

A dispute with Experian about a credit report, for example, isn’t necessarily the same as a privacy request involving Experian’s other products. The same distinction applies to marketing data held by Acxiom and similar companies.

U.S. privacy rules and deadlines

Federal rules

The Federal Trade Commission, or FTC, can investigate deceptive or illegal business practices, but it isn’t a general dispute administrator for every data broker. The FTC’s contact and complaint information explains where to report suspected unlawful conduct.

A complaint can help regulators identify patterns. It usually doesn’t act as a direct instruction to remove your individual profile, and it doesn’t guarantee a response by a particular date.

California rules

California residents may have privacy rights under the California Consumer Privacy Act and related amendments. Eligibility, exemptions, and the type of data covered depend on the business and the request.

California’s Delete Act also created the state’s DROP mechanism for deletion requests involving registered data brokers. According to the California Privacy Protection Agency’s data broker information, beginning August 1, 2026, covered data brokers must access the accessible deletion mechanism at least once every 45 days and process consumer deletion requests, subject to limited exceptions.

The 45-day figure is an access interval for brokers. It shouldn’t be presented as a universal promise that every consumer’s data will disappear within 45 days. Check the CPPA’s current instructions for eligibility, portal availability, verification, and exceptions.

If a broker says it can’t fully comply, ask whether it:

Other states and other countries

Several U.S. states have privacy laws, but their definitions, deadlines, and exemptions differ. Your state of residence usually matters more than the broker’s headquarters. Read the broker’s privacy notice and your state regulator’s current guidance before relying on a deadline.

If you live in the European Union, European Economic Area, or United Kingdom, don’t assume that U.S. rules apply. Use the company’s local privacy or data-protection contact and follow the process available under the law that covers your location and the company’s processing activities.

How to file a data broker dispute

1. Preserve the evidence before asking for deletion

Save the information you’re challenging before submitting a request. Take screenshots that show:

If the information contributed to a rental, employment, credit, or insurance problem, preserve the report, denial notice, emails, and names of the companies involved. Deleting a profile first could make it harder to show what happened.

2. Define the result you want

Use a specific request instead of writing only “remove my data.” Choose one or more goals:

A correction request is often better than deletion if you need the record to remain available as evidence. If your goal is to stop exposure, deletion or suppression may be more appropriate.

3. Find the official submission channel

Start with the broker’s own website and privacy policy. Look for terms such as “privacy choices,” “consumer request,” “do not sell or share,” “opt out,” or “delete my information.”

For Acxiom, use the privacy or consumer-request process on the official Acxiom domain rather than relying on a third-party opt-out guide. For Experian, first decide whether you’re dealing with a credit report, a marketing profile, or another product.

Avoid forms that:

California residents should check the CPPA’s current DROP instructions rather than assuming a paid removal service can submit or manage every part of the state process for them.

4. Verify your identity carefully

A broker may need enough information to match your record. That could include your name, address, email address, or phone number. Provide only what the official process requires.

Use a secure web form when possible. Don’t send a full Social Security number, driver’s-license number, or passport number by ordinary email unless you’ve verified why it’s required and how it will be protected. Redact unnecessary numbers from supporting documents.

If the company asks for more information than seems necessary, ask whether it accepts an alternative form of verification.

5. Submit a precise request

Include the exact listing or data field, the correct information, and supporting evidence. State your residence if it affects eligibility, but don’t claim a law that doesn’t apply to you.

You can adapt this template:

Subject: Privacy request concerning personal information

[Your name]
[Your email or mailing address]
[Date]

[Company name]
Privacy or consumer-request team

I am writing about a profile or record associated with me at:
[Page URL, reference number, or other identifying detail]

I request that you:

[ ] Correct the following inaccurate information:
    [Describe the inaccurate field and provide the correct information.]

[ ] Delete my personal information where applicable.

[ ] Opt me out of the sale or sharing of my personal information, if available.

[ ] Remove my information from any publicly searchable profile.

The information I am challenging is:
[Describe the record clearly.]

I have attached only the documents needed to verify my identity or support this request. Please confirm receipt, explain what action you take, and identify any information you retain and the reason for retaining it. If you deny any part of this request, please provide the reason and explain any available appeal process.

I am a resident of [state]. If applicable, please treat this as a request under [applicable state law or company policy].

Sincerely,

[Your name]

Don’t attach sensitive documents automatically. Add them only when the official channel requires them or when they directly prove the correction.

6. Track the response and check the result

Record the date you filed, the method used, confirmation number, documents supplied, and any response. Set a reminder based on the deadline stated by the company or applicable law.

If there’s no deadline in the law or policy that applies to your request, don’t rely on a generic “30-day FTC rule.” Follow up in writing and ask for a status update.

After the company says it acted, revisit the same page and search for variations of your name, phone number, email address, and address. Save a screenshot of the result. Recheck later because data brokers can collect the information again.

What to do if the broker refuses or ignores you

A refusal doesn’t always mean the information is accurate. It may mean that the company couldn’t verify you, treats the record as exempt, believes the request is outside its legal obligations, or wants you to use a separate appeal channel.

Follow this order:

  1. Ask for the reason in writing.
  2. Request the company’s appeal or reconsideration process.
  3. Correct a verification problem without sending unnecessary sensitive data.
  4. Provide focused evidence, such as an official address record or the relevant page screenshot.
  5. Ask whether the company deleted, corrected, suppressed, or retained the information.
  6. Escalate to the appropriate state privacy regulator or attorney general when the company appears to be violating an applicable state right.
  7. Report suspected deception, unlawful data practices, or a scam to the FTC through its official complaint options.

If a screening decision is involved, return to the FCRA process. Ask the decision-maker for the report and dispute inaccurate information with both the reporting company and the source that furnished it. A privacy complaint to the FTC is not a substitute for that dispute.

DIY requests versus paid removal services

You can usually handle a small number of requests yourself. DIY removal costs less and lets you decide exactly what information to share, but it takes time and requires repeat checks.

Paid services can automate requests across a larger list of sites. For example, Incogni describes sending initial requests to covered brokers, tracking progress through a dashboard, and sending repeat requests. Its service information describes its own process, not a guarantee that every broker will comply.

Independent comparisons such as PCMag’s data-removal service review can help compare coverage and pricing, but both can change. Don’t treat advertised site counts or removal percentages as a universal success rate.

Before subscribing, check:

No service can promise that every copy of your information will disappear. A sensible approach is to handle high-impact or highly sensitive listings yourself, then consider automation for recurring, lower-risk searches.

How to measure success

A removal service’s “processed” count isn’t the same as a successful deletion. A useful result is one you can verify:

Keep checking the original source. Removing a people-search result won’t necessarily remove public records, and removing a marketing profile won’t necessarily stop messages from companies that already have your contact details.

Common questions

Is a data broker dispute the same as a credit report dispute?

No. A data broker privacy request usually concerns marketing, people-search, or profile information. A credit, tenant, employment, or insurance report may involve FCRA procedures, which have different responsibilities and deadlines.

Does the FTC remove my data for me?

Usually not. The FTC can receive complaints and investigate patterns of suspected unlawful conduct. File the request directly with the broker first, then report conduct that appears deceptive or illegal.

Is there a universal 30-day response deadline?

No. Don’t assume that every data broker must investigate or respond within 30 days under an FTC rule. Check the law that applies, the company’s privacy policy, and any state-specific process.

Can a broker refuse a deletion request?

It may be able to deny part of a request because of identity-verification problems, legal obligations, applicable exceptions, or a mismatch between the request and the company’s role. Ask for the reason, what was retained, and how to appeal.

Will one request remove my information from every broker?

No. Brokers operate separate databases, and information can be copied or collected again. California’s DROP mechanism is intended to centralize certain deletion requests, but coverage, timing, and exceptions still matter.

Start by saving the listing, identifying whether it’s marketing data or a consumer report, and sending a focused request through the company’s official privacy channel.