If a data broker shows your address, exposes location information, or ignores a privacy request, start by preserving the record. Save the profile and URL, use the broker's official privacy channel when it is safe to do so, and report the facts through the Federal Trade Commission's ReportFraud.gov form. If a state privacy right or consumer-protection issue may apply, send the same evidence to the appropriate state regulator or attorney general. California residents may also use the state's Delete Request and Opt-Out Platform, known as DROP.
An FTC complaint is an enforcement tip, not a private lawsuit. Filing it won't automatically delete your information, produce compensation, or guarantee that an investigator will contact you. A useful complaint usually has three parts: a dated copy of the data profile, a documented deletion or opt-out request, and proof of what happened afterward.
This article is for U.S. consumers. State privacy rights, exemptions, and complaint procedures vary.
Choose the right complaint route
The companies involved may serve different roles. A website, app, advertising network, data broker, and downstream buyer may not be the same legal entity.
- The FTC: Accepts reports about potentially unfair or deceptive practices, including misleading privacy statements, questionable collection or sale of data, and harmful security or privacy practices. The agency may use individual reports to spot broader patterns.
- A state attorney general or privacy regulator: May accept complaints about state-law rights, deceptive conduct, data-broker registration, or a company's response to a privacy request.
- The broker itself: A direct deletion or sale opt-out request gives the company a chance to act and creates a paper trail.
- California's DROP platform: Gives eligible California residents a centralized way to submit deletion requests, subject to the platform's current instructions, verification requirements, and legal exceptions.
There is no single federal law that gives every U.S. resident a universal right to delete information from every data broker. A broker may offer an opt-out in its privacy policy even when a particular state law doesn't cover you. A broken policy promise and a legal violation aren't automatically the same thing.
Identify the broker and the conduct
Before filing, separate the facts from your assumptions. Record:
- The broker's name, website, legal entity, and privacy-policy link.
- The page or service where you found the information.
- The specific information displayed, such as your name, address, phone number, age, location history, household members, or inferred interests.
- Whether the page described the information as collected, inferred, matched, sold, shared, or used for advertising.
- The date and time you viewed it, including your time zone.
- Any registration listing or corporate contact information that helps identify the correct company.
For California residents, the California Privacy Protection Agency's data broker page can help you check the registry and current Delete Act information. Registration doesn't prove that a broker violated the law, but it may help you find the right legal entity.
Use precise language. Unless you have evidence of a transaction or disclosure, don't write that the broker "sold" your information. "The broker displayed my home address" or "the profile remained available after my deletion request" is easier to verify.
Preserve the evidence
Create a folder for the broker. Clear names such as broker-profile-2026-06-03.png and opt-out-confirmation-2026-06-04.pdf make the timeline easier to follow.
| Evidence | What to preserve | Why it helps |
|---|---|---|
| Data profile | Screenshots showing the page, web address, visible fields, and date and time | Shows what the broker displayed |
| Privacy policy | A saved PDF or screenshot of the relevant policy and opt-out language | Shows what the company represented |
| Request record | Your deletion or opt-out request, date sent, method, and confirmation number | Establishes when you asked the company to act |
| Broker response | Emails, denial messages, identity-verification requests, and failed-form notices | Shows how the company handled the request |
| Persistence | A later screenshot showing the same information still available | May support a claim that the request was not honored |
| Source information | App permissions, account notices, purchase records, or other records that may show how the data was collected | May help identify the source |
| Harm or risk | A police report number, threatening message, unwanted contact, identity-theft record, or documented financial loss | Connects the data practice to a specific impact |
Include the browser address bar in screenshots when possible. Keep the original files, not only cropped images. For email, save the complete message with its date information.
A short timeline is more useful than a pile of disconnected screenshots:
- June 3: The profile displayed my home address and an inferred health interest.
- June 4: I submitted a deletion and sale opt-out request.
- June 4: The broker sent a confirmation number.
- June 20: The profile was still visible.
- June 21: I sent a follow-up and received no response.
Redact passwords, Social Security numbers, full bank or card numbers, and unrelated medical details before uploading documents. Store unredacted originals securely in case an agency later asks for them. Don't access someone else's account, buy questionable personal data, or exaggerate what happened.
Send the broker a documented request
A direct request and a regulator complaint serve different purposes. The request may remove the profile or stop a sale or sharing practice, while the request record gives an agency a clearer timeline. Don't contact the broker first if doing so could create a safety risk.
- Open the broker's official privacy or opt-out page.
- Save the form and its instructions before submitting it.
- Ask for deletion and, if the broker offers the option, opt out of sale or sharing.
- Provide only the information reasonably needed to locate your record.
- Save the confirmation page, email, ticket number, and any stated processing information.
- Check the profile again after the stated processing period and record what you find.
If the form fails, save the error message. Then use an official privacy email address or mailing address listed by the company. Don't repeatedly send identity documents to an address you haven't verified. If the broker asks for more information than seems necessary, preserve that request and check the applicable state privacy guidance before complying.
A profile that reappears is useful evidence, but it doesn't always prove that the same company ignored your request. The information may have come from another broker, a public record, or a newly refreshed source. Compare the exact fields, page address, and legal entity before drawing a conclusion.
If the information creates an immediate stalking or personal-safety risk, consider speaking with a local victim advocate or law enforcement agency before contacting the broker. The removal process may require information you don't want to disclose.
File a complaint with the FTC
Use the ReportFraud.gov complaint form. Categories and wording can change, so select the closest available option for privacy, deceptive business practices, data collection, identity theft, or another relevant issue.
Include:
- The broker's legal name and website.
- Exactly what information appeared or was used.
- How and when you found it.
- What the broker's policy or other representation said.
- When you requested deletion or opted out.
- The response you received, or the fact that the form failed.
- Whether the information remained available or caused a particular risk or loss.
- Links to relevant pages and a description of your saved evidence.
Use a short chronology rather than a long accusation. You don't need to calculate a penalty or label the conduct a Section 5 violation. Explain what the company did, what it said, and why the conduct appears unfair, deceptive, unsafe, or inconsistent with its own statements.
The FTC form may not work like a court filing. If it offers an upload feature, submit relevant redacted documents. If it doesn't, summarize the evidence and keep the originals. Save the confirmation or report number and a copy of your submitted narrative.
FTC complaint template
Subject: Complaint about [broker name] and personal information
I am reporting [broker's legal name and website] because it displayed, collected, used, or failed to remove my personal information.
What I found: On [date], I found [specific information] at [page or service]. The page showed [brief description].
What I did: On [date], I submitted a [deletion or opt-out] request through [method]. My confirmation number was [number].
What happened next: On [date], [the broker refused, did not respond, the form failed, or the information remained visible].
Impact: This created [specific privacy, safety, identity-theft, or financial risk]. I have [screenshots, emails, notices, or other records] documenting the timeline.
Request: Please review whether the broker's collection, use, disclosure, security, or response practices may violate applicable consumer-protection or privacy requirements.I can provide additional records if requested.
Keep the wording factual. A report that identifies the conduct, dates, company representations, and evidence is more useful than one that simply demands the maximum fine.
California: DROP, the CCPA, and the CPPA
California residents may have several routes, and they don't all do the same thing.
The CPPA says that, beginning August 1, 2026, data brokers must access the accessible deletion mechanism at least once every 45 days and process deletion requests, subject to limited exceptions. The 45-day rule describes the broker's access schedule. It isn't a blanket promise that every individual request will be completed within 45 days.
If you use DROP:
- Follow the current consumer instructions on the CPPA's data broker page.
- Complete any required identity or account verification carefully.
- Save the submission confirmation and any result showing whether a broker matched your information.
- Compare the result with the broker's profile and correspondence.
- Preserve any refusal, failed verification, missing broker, or profile that remains visible.
- Use the CPPA's current complaint or enforcement instructions if the response appears inconsistent with the applicable requirements.
A broker may report that it found no matching record, couldn't verify the consumer, or qualifies for an exception. That result doesn't by itself prove unlawful conduct. Preserve it anyway if you have a dated profile showing otherwise.
The CPPA's LocateSmarter announcement describes a decision requiring LocateSmarter LLC, an Iowa data broker, to pay $116,490 and change its practices after failures involving timely registration and California privacy requirements. The decision shows that registration and deletion compliance can lead to agency enforcement. It doesn't promise an individual payment or prove that every broker profile violates California law.
Complain to a state attorney general
For a complaint outside California, check your state attorney general's official consumer-protection or privacy page. State rules differ on:
- Who qualifies as a protected consumer.
- Which businesses are covered.
- Whether deletion, access, correction, or sale opt-out rights apply.
- How the business must verify your identity.
- Which regulator accepts the complaint.
- What exceptions allow the company to retain information.
Use the evidence package you prepared for the FTC, but connect the facts to the state rule or company conduct you can identify. A state agency may investigate a pattern, refer the matter, or take no action. It generally isn't your personal attorney and doesn't guarantee deletion or payment.
If the information was used for eligibility
If the information appeared in a report used to decide credit, employment, housing, insurance, or another eligibility question, don't treat it only as a data-broker privacy issue. Consumer-reporting rules, including the Fair Credit Reporting Act, may apply.
Dispute inaccurate information with the reporting company and preserve the response from the company that used the report. A general FTC report doesn't replace that dispute process or automatically correct an adverse decision.
What enforcement examples show
Enforcement cases can indicate which practices regulators examine, but they don't establish that every profile is unlawful or guarantee money to someone who files a complaint.
The FTC's 2024 actions involving Mobilewalla and Gravy Analytics focused attention on sensitive location-data practices. A WilmerHale review of those FTC actions discusses the allegations and the restrictions regulators sought. For a consumer, the practical point is to document the data's sensitivity, the company's representations, and the specific way the information could expose people to harm.
The LocateSmarter decision reflects a different enforcement route: California action can involve registration and Delete Act or CCPA compliance, not only a dramatic disclosure of location data.
Be wary of pages that quote a maximum statutory penalty as if it were a guaranteed award. The amount depends on the agency, the law, the order, the facts, and the violations established.
What happens after filing?
The FTC or a state agency may:
- Compare your report with complaints about the same company or practice.
- Contact you for more information.
- Refer the matter to another regulator.
- Open an investigation or enforcement action.
- Take no visible action.
Agencies often can't discuss active investigative work, so silence doesn't necessarily mean the evidence was rejected. Filing also doesn't end the need to protect yourself. Keep monitoring the profile, save new screenshots, and send a brief update if the agency provides a way to do that.
Deal with any separate harm at the same time. For identity theft or account takeover, secure affected accounts, turn on multifactor authentication, and contact the relevant financial institution. Report urgent threats or immediate physical danger to local law enforcement. A privacy complaint isn't an emergency-response service.
Filing checklist
Before submitting, confirm that you have:
- [ ] Identified the broker's legal entity and the page where you found the information.
- [ ] Saved dated screenshots showing the exact data fields.
- [ ] Preserved the privacy policy and opt-out instructions.
- [ ] Sent a deletion or opt-out request when safe and appropriate.
- [ ] Saved the confirmation, response, or failed-form message.
- [ ] Written a simple chronological timeline.
- [ ] Described concrete harm or risk without speculation.
- [ ] Redacted passwords, financial numbers, and unnecessary identity documents.
- [ ] Chosen the correct route for your state.
- [ ] Saved the FTC, CPPA, or state complaint confirmation number.
Begin with the profile, URL, and date. Once those are safe, add the request record and the follow-up result; that same file can support a broker request, an FTC report, and a state complaint.