There isn't one nationwide deletion form for every U.S. data broker. If you found your name, address, or phone number in a profile, use that company's official privacy or opt-out page, save proof of the request, and check the listing later. California residents can also use the state's Delete Request and Opt-out Platform (DROP) to send deletion and sale opt-out requests to brokers on California's registry.

Data brokers collect personal information from multiple sources, combine it into profiles or audience segments, and sell, license, or share the results. You don't need an account with a broker for your name, address, phone number, interests, or likely location to appear in its records.

What do data brokers collect?

A broker may gather information from:

Some of that is reported directly. Other details are estimated. A broker might infer household income, interests, life events, likely workplace, or shopping habits from the data points it already has. Matching identifiers can also connect an old address or email address to a newer profile.

The FTC's study of the data broker industry shows why this activity can be hard for consumers to see or control.

What do data brokers do with the information?

Brokers can use personal information to create:

You may see names such as Acxiom, Experian, Equifax, TransUnion, Oracle, Epsilon, LexisNexis, Nielsen, and people-search companies. They don't all hold the same information or offer the same privacy controls. One company may also run separate credit, marketing, identity, or risk-data divisions.

That split is easy to miss. Opting out of a marketing database isn't the same as correcting a credit report, and removing a people-search listing won't necessarily change information held by a bank or lender.

Privacy risks for consumers

Collecting or selling this information doesn't automatically mean a company broke the law. The problems usually come from scale, accuracy, circulation, and sensitivity.

Risk Why it matters
Incorrect profiles An outdated address or wrong household connection can lead to unwanted contact or inaccurate decisions.
Persistent exposure A record removed from one website may remain with another broker or reappear later.
Sensitive inferences Health interests, family connections, finances, and routines may be inferred from ordinary activity.
Location exposure Detailed location information can reveal regular travel patterns, workplaces, or home areas.
Breach-related harm If a broker or vendor is breached, copied records may circulate beyond the original company.
Scams and harassment Names, phone numbers, addresses, and relatives can make phishing, impersonation, or unwanted contact easier.

Removal can reduce exposure. It can't recall every copy another business already received or collected on its own.

Opt out, delete, correct, or suppress: what is the difference?

Privacy forms often use these terms differently:

Read the confirmation. A button labeled "remove me" may apply only to a public listing, marketing emails, targeted advertising, or one database.

Which removal route should you use?

Start with the place where you found the information.

Where you found your information First step Key limitation
People-search profile Use that site's official suppression or opt-out form. It won't remove the underlying public record or copies held elsewhere.
Marketing or advertising database Use the company's privacy choices to opt out of sale, sharing, or targeted advertising. The record may remain for other purposes.
Credit report Use the credit-reporting company's access and dispute process. A general marketing opt-out isn't a credit-report correction.
Bank or financial institution Read the institution's privacy notice and follow its stated opt-out process. Financial privacy rules don't cover every independent data broker.
California data broker registry Use California's DROP platform if you're eligible. DROP is registry-based, not a universal deletion tool for every website.

U.S. privacy rules that may apply

Your options can depend on your state, the type of data, the company's activities, and why it is using the information.

California's DROP platform

California residents can use the official DROP platform to submit deletion and sale opt-out requests to data brokers in California's registry. You have to verify residency before a request is submitted. If you can't confirm residency through DROP's verification step, the platform says you can request a review of that classification.

The official platform says data brokers must process deletion requests at least once every 45 days beginning August 1, 2026. That's a processing cadence, not a promise that every record disappears immediately or that unrelated companies delete copies they already have.

The Electronic Frontier Foundation's explanation of DROP also notes the tool's registry-based scope. You may still need to contact a company directly if it isn't on the registry, if you want to correct an account, or if the information comes from a source outside the broker system.

Financial information and the GLBA

The Gramm-Leach-Bliley Act's Privacy Rule is narrower than a general right to erase all personal information. The FTC's guidance on the GLBA Privacy Rule says the rule applies to businesses significantly engaged in financial activities described in section 4(k) of the Bank Holding Company Act.

When a covered financial institution discloses nonpublic personal information to a nonaffiliated third party, and the disclosure doesn't fit an applicable exception, the institution generally must explain the consumer's right to opt out. Joint-marketing and service-provider arrangements can fall within exceptions.

If the issue is financial information, read your bank or lender's privacy notice and use the opt-out it describes. The GLBA doesn't give you a single switch that turns off every marketing, people-search, or advertising database.

Other state laws and the GDPR

Other state privacy laws may provide access, deletion, correction, or sale-sharing opt-out rights under specific conditions. Eligibility and exceptions vary, so use the law and privacy notice that apply to your residency and the company's activities.

The EU's GDPR isn't a universal U.S. opt-out. Don't assume a broker's international operations automatically create GDPR rights for a U.S. consumer. If you believe another jurisdiction's law covers you, verify that jurisdiction's requirements before relying on it.

How to remove your information from data brokers

1. Make a record of what you find

Search for combinations of:

Save the page address, a screenshot, the date, and the information displayed. That record helps if the listing returns or the company says it can't find your profile.

2. Identify the type of request you need

Decide whether your goal is to:

If a form offers several choices, select each one that matches your goal. Deleting a record and opting out of future sale are related, but they aren't always the same action.

3. Use the company's official privacy page

Look for links labeled Privacy Choices, Do Not Sell or Share, Your Privacy Rights, Delete My Information, or Opt Out. Start from the company's verified domain. Skip forms that arrive in unexpected emails or on sites that imitate a government service.

Give the company enough information to match your record, and don't send more than the form requires. Be cautious about entering a Social Security number or uploading identification. If a legitimate company asks for sensitive information, confirm that you're on its official domain and understand why it needs those details.

4. Complete verification and save the confirmation

Many opt-out forms send a verification email or ask you to confirm an address, phone number, or other identifier. Finish that step or the request may not be processed.

Keep the confirmation email, request number, submitted details, and any stated response period. Note whether the confirmation says deleted, suppressed, opted out, or something narrower.

5. Check the result

After the company's stated processing period, search again using the same details. If the listing remains, check whether:

Outside California, don't treat 45 days as a default deadline. Use the timeline in the privacy notice or confirmation, plus any state-law deadline that actually covers your request.

6. Follow up and escalate carefully

Reply through the company's designated privacy contact and include the original confirmation or case number. Ask whether it denied, completed, or limited the request, and which record or exception is involved.

If a company ignores a request you believe is protected by state law, keep your documentation and review the complaint or appeal process for your state privacy regulator or attorney general. A complaint may create an enforcement record. It doesn't replace the deletion request itself.

7. Reduce new collection

Removal works better when fewer new records are created. Review app location permissions, advertising settings, loyalty-program preferences, old online accounts, and marketing subscriptions. Consider using separate email addresses for future signups when appropriate.

Those steps won't erase existing broker records. They can reduce the information available for future matching.

Are paid data-removal services worth it?

A removal service can save time if you have many listings or don't want to repeat requests yourself. It still can't guarantee removal from every database, public record, downstream recipient, or newly created profile.

Before you subscribe, check:

Doing it yourself takes more time and gives you direct control over what is submitted. Either way, keep your own list of requests instead of relying only on a dashboard.

What data-broker removal cannot do

Removing a profile from one broker generally won't:

If you find evidence of fraud, unauthorized account activity, or exposed financial credentials, contact the affected financial institution promptly. Use established identity-theft and credit-reporting procedures in addition to requesting broker removal.

FAQ

Can a data broker have my information if I never used its service?

Yes. Brokers can obtain information from public records, business partners, apps, websites, purchases, and other data suppliers. Having no account with the broker doesn't necessarily prevent a profile from being created.

Does opting out of one data broker remove me from all of them?

No. Each company controls its own records, and a downstream business may have collected the same information independently. California's DROP platform can reach registered brokers in its system, but it isn't a universal deletion request for every website.

Is data-broker removal free?

Many companies provide their own privacy or opt-out forms without requiring a paid removal service. Check the company's official process first. If you pay a service, review its coverage, recurring price, cancellation terms, and limits before submitting your information.

Will a marketing opt-out change my credit report?

Not by itself. Marketing preferences, people-search listings, and credit files use different processes. If the problem is an inaccurate credit report, contact the credit-reporting company through its separate access or dispute channel.

How long does removal take?

There is no single timeline for every U.S. broker. Follow the company's confirmation and the law that applies to your request. For California, the official DROP information says brokers must process deletion requests at least once every 45 days beginning August 1, 2026. That doesn't guarantee instant or universal deletion.

What to do first

Search once with your current name, phone number, and address. Save that page, submit one official request, and keep the confirmation before you move on to the next broker.