">

If a data broker has ignored a documented opt-out or deletion request, preserve the listing and your confirmation, then send one concise follow-up after the broker's stated processing period. If the facts suggest a scam, deception, or unlawful business practice, you can report it through ReportFraud.gov. A state attorney general or privacy agency may also be relevant when you are asserting a state privacy right.

A regulator report can help identify a pattern of conduct, but it does not itself require the broker to erase your record, pay compensation, or respond to you by a set date.

This information is for U.S. consumers. There is no single federal rule requiring every data broker to delete every piece of information on request. The broker's own request process, the state where you live, the type of information involved, and any legal exception can all affect the result.

For threats, stalking, identity theft, impersonation, or an immediate safety risk, preserve what you can and report the danger promptly. Don't wait for a routine opt-out timeline.

Check that the broker actually failed to act

Before filing a complaint, make sure the page you still see belongs to the same business and is the same record covered by your request.

A search result alone may be misleading. It could point to:

Compare the legal business name, profile URL, visible data fields, and date of your screenshots. Also confirm what you asked for. An opt-out may limit sale, sharing, or certain uses of personal information without removing a public-facing profile. A deletion request seeks removal, but verification requirements and exceptions may apply.

A complaint is more credible when one of the following has happened:

A denial is not automatically unlawful. The company may have been unable to verify your identity, may not have matched the information you submitted to its record, or may be relying on an applicable exception. Ask for its reason before treating the outcome as a violation, unless the situation is urgent.

Build a file before you contact a regulator

Keep one folder or timeline for each broker. Regulators can do more with dates, URLs, and copies of responses than with a general statement that a company "wouldn't remove my data."

What to keep Useful details
Broker identity Legal name, website, privacy-policy page, and alternate business names
Original listing Direct profile URL, screenshots, visible information, and the date and time viewed
Your request Date, submission method, request type, and the details used to locate the record
Proof of submission Confirmation email, reference number, portal receipt, or screenshot of the completed form
Broker response Exact wording of a denial, verification request, status notice, or no-response timeline
Follow-up Dates and copies of each follow-up message
Harm or impact Specific consequences such as harassment, impersonation, or a documented decision based on inaccurate information

Do not place a full Social Security number, complete bank account number, password, or unnecessary identity document in an ordinary complaint narrative. Share only the information needed to identify the record or explain the problem.

The FTC's contact guidance says confidential material should be marked "Confidential" and sent by postal mail rather than casually included in an online communication. Keep sensitive records out of screenshots whenever possible, and redact information that is not necessary to show the issue.

Send a focused follow-up to the broker

Use the broker's official privacy page or removal portal, not a search advertisement, an unofficial removal service, or an unverified email address. Save a copy of the instructions before submitting if the page may change.

When a broker's stated processing period has passed, send one factual follow-up. Include the confirmation number, the direct listing link, and only the evidence needed to establish the timeline.

Subject: Follow-up on opt-out or deletion request

Date: [Month Day, Year]

To: [Broker's privacy or consumer-request contact]

On [date], I submitted a request through [official portal or email] to
[opt out of specified uses / delete my personal information].

Request or confirmation number: [number]
Listing or record: [profile link or description]

As of [date], [describe what remains visible or explain that no response
was received]. I have retained screenshots and proof of submission.

Please review the request and confirm its status. If you denied it, please
identify the reason, any applicable exception, and any available appeal or
next-step process under your policy or applicable law.

Please respond to [email or mailing address].

Sincerely,
[Name]

Avoid claiming that the company owes a particular fine or that a regulator has opened a case when neither is true. A short timeline with supporting records is more useful than a long message filled with legal conclusions.

Official starting points for Acxiom, Epsilon, and Spokeo

A request submitted to one broker does not remove information held by another broker, an affiliate, or a separate people-search service.

Broker Official starting point What to save
Acxiom Acxiom opt-out portal Submitted details, confirmation, and the date of each later check
Epsilon Epsilon privacy page The current instructions you followed, request confirmation, and any response
Spokeo Spokeo opt-out page The direct link for each profile you request to remove and proof of submission

Search for old addresses, alternate names, and duplicate profiles after completing a request. If multiple listings appear, document each one rather than assuming one submission covered them all.

Some brokers do not show consumer-facing profiles even though they hold marketing or business data. In that situation, use the company's privacy instructions to ask whether it holds information about you and which request channel applies.

Report suspected unlawful or deceptive conduct to the FTC

The FTC accepts reports about illegal business practices and scams through ReportFraud.gov. Describe what happened in date order. Focus on conduct you can document.

Include:

  1. The business name, website, and relevant profile URL.
  2. Your state of residence and how the company appears to have your information.
  3. The date and method of your opt-out or deletion request.
  4. The confirmation number or other proof that the request was received.
  5. The broker's response, or the absence of a response after its stated period.
  6. What remained visible or what use of your information appears to have continued.
  7. Any concrete harm, such as impersonation, harassment, or a documented inaccurate record.
  8. Why you believe the practice may be deceptive, unlawful, or part of a repeated failure to honor requests.

Keep copies of your evidence even if the reporting form does not request every document. An FTC report may contribute to pattern detection or enforcement, but it is not a private removal order or a guaranteed individual dispute-resolution process.

Continue with the broker's privacy process while your report is pending. If the broker later responds, add the new information to your records and keep the account of events consistent.

State complaint routes

Your state of residence and the privacy right you exercised usually matter more than the location of the broker's headquarters. State laws differ on eligibility, covered businesses, response periods, appeals, and exceptions.

California

California residents with a possible CCPA or CPRA issue should use the current information on the California Privacy Protection Agency website. Identify the right you exercised, the company's response, and the evidence showing the disputed practice continued.

California also has the Data Broker Requests and Opt-Out Platform, or DROP. Check the CPPA's live instructions for its current availability, coverage, processing rules, and submission steps. Save any DROP confirmation with your direct requests to individual companies.

Do not assume DROP reaches every business that holds your information or replaces a direct request where one is needed. California privacy rights also have exceptions and verification rules. An ordinary refusal to delete or opt out does not automatically create a private lawsuit; the CCPA's private right of action is limited and is generally associated with certain data-security incidents.

Vermont

Vermont has a data broker registration requirement. The Vermont Attorney General's data broker information provides regulatory background.

If you believe a business is operating as an unregistered data broker, mishandled a security incident, or engaged in an unlawful consumer practice, use the Vermont Attorney General's current complaint instructions. Explain why you believe the business qualifies as a data broker, identify its website and legal name, and provide your supporting records.

A registration complaint does not replace a direct privacy request. Reporting the company may support enforcement, but it will not by itself remove a particular profile.

Other states

For other states, look for the attorney general's consumer-protection or privacy complaint process. Before relying on a state privacy right, confirm that:

Don't borrow a California deadline or remedy for a complaint in another state.

What happens after you report the problem

There is no universal FTC or state-agency timetable for a data broker complaint. The broker's published processing period may differ from any deadline that applies under state law.

A practical record of events might look like this:

If a broker says the profile was removed but it still appears in search results, open the result. A stale search snippet is different from an active profile. If the live page belongs to another company, begin a separate request and evidence file for that company.

Information can also reappear after a broker collects it from another source. Periodic checks are sensible, especially for old addresses and name variations.

When a removal request is not enough

A people-search listing is not the same as a report used for credit, employment, housing, insurance, or another important decision. If a report contributed to an adverse decision, ask the decision-maker which reporting company supplied it and use the dispute process for that report. Do not rely on a general broker complaint as a substitute for any deadline in an adverse-action notice.

For identity theft, account misuse, impersonation, threats, or stalking, preserve the records and contact the relevant bank, platform, law-enforcement agency, or safety service. Describe the specific harm and any immediate risk, not just the fact that your information appeared online.

Common mistakes to avoid

Common questions

Does an FTC report remove my information?

No. A ReportFraud submission can document suspected illegal or deceptive conduct for possible enforcement. Keep pursuing the broker's direct opt-out or deletion process.

Should I report the broker before contacting it?

Usually, make the official request first so you can show what the company did or failed to do. Report immediately when the conduct involves fraud, threats, identity theft, impersonation, or another urgent risk.

Can I complain about Acxiom, Epsilon, or Spokeo?

Yes. Start through the company's current official privacy or opt-out channel, retain the proof, and escalate if the company does not follow its stated process or an applicable law. Each company may hold different information.

How long will a complaint take?

There is no single 30-, 45-, 60-, or 90-day resolution period for every broker complaint. Use the broker's stated timeline and any state-law deadline that applies to your request.

Start with one active listing: save its direct URL and screenshot, submit the official request, and note the date when you should check the result. That record will give any later follow-up or complaint a clear factual foundation.