How Do Data Brokers Get Your Information? Inside the Data Broker Supply Chain

Data brokers get your information from public records, from companies you already do business with, and from each other. Nobody hacked you. The profile a people-search site shows under your name (address history, phone numbers, relatives, "possible associates") was assembled legally from two supply lines: records any member of the public can pull from a courthouse or county office, and a wholesale data market you have never knowingly dealt with. That market is fed by your credit applications, your loyalty cards, the apps on your phone and, lately, your car.

So how do data brokers get your information, concretely? This guide answers that at the level the industry itself documents: regulator reports, court records, and the brokers' own marketing to their business customers. It also covers the part no broker will tell you, which is where the specific fields in your profile came from, and it ends with what you can do about it.

What are data brokers?

A data broker is a company that collects personal information about people it has no relationship with and sells or licenses it to others. California's registration law, AB 1202, defines the term almost exactly that way: a business that knowingly collects and sells the personal information of consumers "with whom the business does not have a direct relationship."

The Federal Trade Commission's 2014 study of nine brokers, Data Brokers: A Call for Transparency and Accountability, sorted the industry into three product lines: marketing data, risk-mitigation products such as identity verification, and people search sites. The nine companies held "billions of data elements covering nearly every U.S. consumer." One had 3,000 data segments on nearly every American; another was adding three billion new records to its databases every month. The finding that matters most for this article is about sourcing: the nine obtained most of their data from other data brokers rather than from an original source, and seven of the nine supplied one another.

People-search sites are the visible end of that chain. Whitepages, Spokeo, TruthFinder and BeenVerified rarely originate anything. They buy and merge, and they will suppress your listing if you ask. Several of the biggest brands belong to one company, PeopleConnect, which is why five sites can know the same uncanny details about you.

Where do data brokers get your information? The four supply lines

Every field on a broker profile traces back to one of four inputs:

  • Public records: property deeds, court filings, marriage and divorce indexes, voter rolls, professional licenses, bankruptcies, liens.
  • Credit header data. The identifying top section of your credit file (name, aliases, current and former addresses, date of birth, phone numbers, Social Security number), which flows out of the credit bureaus under an exemption described below.
  • Commercial data you generated as a customer: loyalty programs, retailers' purchase histories, warranty cards, app location signals, and now connected vehicles, sold or matched onward.
  • Other brokers. Wholesalers such as Acxiom, Epsilon and LexisNexis Risk Solutions, which sell to the sites you can see and to each other.

The rest of this article walks each one, starting with how the industry got here.

Data broker history: from mailing lists to identity graphs

The data broker industry predates the internet by decades. Acxiom, for most of its life the largest consumer data company in the world, was founded in Conway, Arkansas in 1969 as Demographics, Inc., and its first job was building a mailing list for the Democratic Party. By the 1980s an ecosystem of list brokers bought, sold and rented files of names and addresses, and catalog retailers pooled their customer files into cooperative databases so that everyone's customers became everyone's prospects. The largest co-op, Abacus Direct, held purchase data on roughly 90 percent of American households.

In June 1999 the online ad company DoubleClick bought Abacus for more than a billion dollars and disclosed plans to link Abacus's real-name purchase histories with the "anonymous" browsing profiles its cookies collected. The FTC opened an investigation and class actions followed. On March 2, 2000, DoubleClick's CEO called the plan "a mistake" and shelved it; the FTC closed its case in January 2001, having found no violation, because there was no law to violate.

The idea outlived the apology. DoubleClick sold Abacus to Alliance Data's Epsilon unit for $435 million in 2006. And joining offline purchase identity to online behavior, the exact thing DoubleClick retreated from, is now the openly marketed function of "identity resolution" platforms and data clean rooms. Acxiom's own corporate history makes the point: in 2018 the company sold its marketing-data business and the Acxiom name to the ad conglomerate IPG and renamed the remaining company LiveRamp, after its identity-matching division. LiveRamp's identity graph is now the connective tissue of the clean-room economy described further down, and it is the direct descendant of the 1969 mailing-list company.

How do data brokers get your information from public records?

The visible layer of the supply chain is public records. Each record class is public on purpose: you should be able to check who owns the house next door and whether your contractor is licensed. The people-search industry's most honest defense is that it made none of this public.

What it did was remove the practical obscurity that made open records tolerable. A deed filed in a county recorder's office in 1995 was public in theory but protected in practice by the cost of finding it. People-search sites are aggregators: they bulk-acquire scattered records and merge everything matching a name into one report. Their product is the merged report, and merging is more powerful than it looks. In 2000 the computer scientist Latanya Sweeney showed that 87 percent of the U.S. population, 216 million of 248 million people in the census data she used, could likely be uniquely identified from just three fields: five-digit ZIP code, gender and date of birth. Once a broker holds a few mundane fields about you, nearly everything else on record about you can be matched in.

You can watch that merge happen on any broker's free preview page. When we capture these result pages for our opt-out guides, the free tier already shows a person's age, current and previous cities, relatives listed by full name, and phone numbers with only the last four digits masked. Because the matching is fuzzy, the preview for a common name also pulls in entirely different people with similar names, which is why we redact those screenshots word by word rather than trusting the site to have got the match right.

Public records still cannot explain everything on your listing. Your cell number was never in a courthouse file, and no county holds your last four addresses in order with move-in dates. Those come from the wholesale market.

The data broker supply chain: wholesalers that sell to brokers

Behind the consumer-facing sites sits a business-to-business market whose biggest firms most people have never heard of. The Senate Commerce Committee's December 2013 investigation of the industry found that data brokers collect "a huge volume of detailed information on hundreds of millions of consumers," sell segments built around financial vulnerability with names like "Rural and Barely Making It" and "Ethnic Second-City Strugglers," and "operate behind a veil of secrecy."

Acxiom is the marketing-data giant; its automotive marketing page claims eight of the ten largest automotive companies as clients. Epsilon runs loyalty and email infrastructure for major retailers and inherited the Abacus co-op. It also supplies the tier's cautionary tale: in January 2021, Epsilon Data Management entered a deferred prosecution agreement with the Justice Department and agreed to pay $150 million after spending 2008 to 2017 selling data on more than 30 million consumers, disproportionately elderly, to clients running mail-fraud schemes, and continuing to sell after learning those clients had been arrested and charged. The company sold its ordinary product to customers it knew were criminals, for nine years.

One giant has already left. Oracle spent a decade assembling an advertising-data business and in 2024 agreed to a $115 million settlement of a class action over it, the same year its CEO announced Oracle was exiting advertising altogether.

LexisNexis Risk Solutions fuses public records with credit-derived identifiers into products for insurers, collections firms, employers and government agencies. Its consumer opt-out is restricted to narrow categories, in its own words "public and elected officials, including law enforcement officers, and private individuals who are facing a substantial risk of physical harm or who are victims of identity theft."

The tiers are also consolidating into single owners. In December 2021 the credit bureau TransUnion closed its $3.1 billion purchase of Neustar, an identity-resolution company that connects data on people, devices and locations. A company that holds your credit file now also owns the company that knows which phone and which device are yours.

How do data brokers get your information from your credit file?

If one dataset explains why a people-search profile nails your exact address chronology, it is credit header data. The identifying top section of your credit file is the most accurate identity data in existence, because you curated it yourself: every credit application you ever submitted updated it truthfully, under penalty of being denied. For more than fifty years it has flowed out of the bureaus through a gap between two statutes.

The 1970 Fair Credit Reporting Act regulates "consumer reports," meaning data bearing on creditworthiness used for credit, employment and insurance decisions. Regulators long treated the identifying header fields as outside that definition, so the bureaus could license them to marketers, private investigators and people-search compilers. The Gramm-Leach-Bliley Act partially closed the gap: the FTC classified header data as personally identifiable financial information, and when Trans Union sued, the D.C. Circuit upheld the rule in 2002 (Trans Union LLC v. FTC, 295 F.3d 42). That brought header data under GLBA's limits on sharing with outside companies. GLBA's exceptions for fraud prevention, identity verification and legal compliance left other doors open, and the people-search and risk industries walked through them.

The most recent attempt to close those doors lasted five months. In December 2024 the Consumer Financial Protection Bureau proposed a rule under which brokers selling header identifiers would be treated as consumer reporting agencies, pulling the whole flow inside FCRA. In May 2025 the agency withdrew it, stating that rulemaking was "not necessary or appropriate at this time." There is still no consumer opt-out for credit header data. You cannot ask Experian, Equifax or TransUnion to stop licensing your identifiers for "verification," and every accurate address on your people-search profile is the downstream evidence.

How data brokers collect information from loyalty cards and connected cars

The supply line you feed most often runs through the checkout lane. When you key in a rewards number, the transaction does not stay at the store. According to the participating companies' own documentation, it runs like this:

  1. You identify yourself with a loyalty ID, a phone number at the keypad, or the card you pay with.
  2. The retailer converts your email or phone number into a hash, a scrambled identifier marketed as anonymization.
  3. The hash is matched inside a "data clean room." LiveRamp's retailer clean room, per its documentation, ingests hashed emails, names, addresses, phone numbers and mobile device IDs and resolves them to RampIDs, its "universal, pseudonymous identifiers," so that the same person can be recognized across companies.
  4. Your purchases, joined to your identity, become sellable audience data. Retailers now run "retail media networks" on exactly this join, a business eMarketer expects to reach roughly $40 billion in search and $23 billion in display ad spending in the U.S. in 2025.

The "anonymized" framing in step two does not survive contact with the research. Princeton researchers showed in 2018 that hashed email addresses are trivially reversible: hashing every plausible address costs a fraction of a cent, and one company at the time openly sold reversal at $0.04 per email. The researchers called the anonymity claim "misleading."

None of this plumbing is hidden. Epsilon's own client case studies name the programs it runs, including Walgreens' myWalgreens, with 105 million active members, whose loyalty data feeds the Walgreens Advertising Group. Where independent auditors have looked closely the picture matches: a May 2025 Consumer Reports investigation found Kroger building detailed profiles of its 63 million loyalty members, including an inferred "income predictor," and one shopper's data report showed sharing with more than 50 companies, data brokers among them.

The car is the newest loyalty card. In January 2025 the FTC charged General Motors and OnStar with collecting precise location and driving-behavior data from millions of vehicles through a misleading enrollment flow for OnStar Smart Driver, then selling it to consumer reporting agencies that used it to price insurance; FTC Chair Lina Khan said GM sold data "sometimes as often as every three seconds." The final order, issued in January 2026, bans GM from sharing that data with consumer reporting agencies for five years. Texas had already sued GM in August 2024 over the driving data of more than 1.5 million Texans in 2015-and-newer vehicles. The wholesale tier is ready for the input: Acxiom's automotive page advertises unifying "online research, media exposure, dealer visits, and purchases" into identity profiles.

Location data brokers and the FTC

Location is the layer where the supply chain does its most obvious damage, and the one place regulators have recently acted. Thousands of apps embed location-collecting software kits; the kit vendors aggregate the movement histories and sell them onward. In November 2020 Vice reported that the broker X-Mode was collecting location data through the prayer app Muslim Pro, downloaded more than 98 million times, and selling it to defense contractors serving the U.S. military. In July 2021 a Catholic newsletter used "commercially available" location data tied to the Grindr app to identify a senior priest, tracing his phone across 2018, 2019 and 2020; he resigned.

The FTC's response arrived in a cluster. A January 2024 order against X-Mode, by then renamed Outlogic, imposed the agency's first-ever ban on selling sensitive location data. A December 2024 order hit Gravy Analytics and its Venntel unit, which had sold location data for commercial and government uses without verifiable consent. And in May 2026, after suing in 2022, the agency settled with Kochava, banning it from selling sensitive location data without affirmative express consent. Note the shape of those orders: they ban sensitive location data (clinics, churches, shelters), company by company, under the FTC's general unfairness authority, because no statute gives it more. Location data that falls short of that line, sold by companies the FTC has not yet sued, remains legal to sell.

What happens when a data broker is breached

Everything above is the supply chain working as designed. Two incidents show its failure modes. In 2005 identity thieves posing as legitimate businesses simply opened accounts with the broker ChoicePoint and bought files on more than 163,000 consumers; the FTC's 2006 settlement imposed a $10 million penalty, then the largest in the agency's history, and established that brokers must vet their buyers.

In 2024 the database of National Public Data, a background-check operator run by a small Coral Springs, Florida company called Jerico Pictures, turned up on a criminal forum advertised as "2.9 billion records." As Krebs on Security documented, the 2.9 billion were rows; researchers counted about 272 million unique Social Security numbers, and Troy Hunt found 134 million unique email addresses. That October, Jerico Pictures filed for bankruptcy listing under $75,000 in assets, leaving no one to fine and no one to compel remediation. A company with under $75,000 in assets had warehoused Social Security numbers on a large fraction of the country, and the losses landed on the people in the files, who were never its customers. Our identity theft statistics page tracks what that exposure costs downstream.

Why you can't trace your own profile back to its source

Every tier above is documented at the category level. Try to move from category to instance and the trail ends. PeopleConnect's Intelius brand states in its privacy policy that it collects "Publicly Available Information or Public Data from various databases, government entities, commercial data providers, and websites." Which commercial data providers appears nowhere. Supplier relationships are trade secrets, and no law requires their disclosure. The FTC's 2014 report recommended that Congress require people-search brokers to "disclose to consumers the data brokers' sources of information, so that, if possible, consumers can correct their information at the source." Congress never acted.

The state laws that did pass require brokers to register their existence, starting with Vermont's Act 171 in 2018 and California's AB 1202 in 2019, and California's 2023 Delete Act added a one-request deletion mechanism. None requires disclosure of provenance. You can now, in one state, order every registered broker to delete your data. You still cannot, in any state, ask one where the data came from. The same structural failure has kept a federal privacy law from passing for decades.

Our own broker catalog shows how much of the visible industry is a storefront. A large share of the "people search sites" we track hold no records at all: they are WordPress skins or copied search forms whose only function is to redirect your query to one of a handful of real data holders, with an affiliate tag attached. Several of them serve a byte-identical search form, down to the missing field names, and all resolve to the same backend. An opt-out filed with one of those storefronts goes nowhere, because the storefront holds nothing; the request belongs at the real holder, and one request there covers every storefront in front of it.

What you can do: how to opt out of data brokers

Standing at the end of the pipe, an individual has real but bounded options, ordered here by payoff.

Start with the sites where results are visible. People-search sites are where a landlord, a stalker or a scammer actually finds you, and they accept opt-outs. The PeopleConnect Suppression Center clears TruthFinder, Intelius, Instant Checkmate and US Search in one request; our master removal walkthrough covers the rest, with a step-by-step guide for each site. Expect friction that has nothing to do with your eligibility: PeopleConnect wants a phone verification code before it will show you your own listing, several sites park their opt-out form behind a Cloudflare interstitial, and a few search boxes quietly hand your query to a different brand's site. Removing the assembled, searchable you is what most concrete harms require, even though it leaves the wholesale layer untouched.

If you live in California, use DROP. The Delete Act's Delete Request and Opt-out Platform opened to consumers on January 1, 2026, and since August 1, 2026 registered brokers have been required to check it at least every 45 days and process what is queued. One free request reaches more than 600 registered brokers. Our DROP guide covers the details and the exemptions.

Two of the big wholesalers accept opt-outs directly.

Acxiom opt out

Acxiom offers a free opt-out from the sale of your personal information at acxiom.com/optout. The U.S. form runs through a OneTrust privacy portal and needs a valid email address; you can also call 1-877-774-2094. Acxiom says requests are processed within two weeks of your confirming by email, and that data already shared with marketers before the request is out of its hands.

Epsilon opt out

Epsilon takes requests through its consumer information page: choose "Do Not Sell My Personal Information" on the request form, or call the Epsilon Consumer Preference Center at (866) 267-3861. As with Acxiom, this stops future sale from Epsilon's databases. It does nothing about past distribution, and it does not reach the retailers whose loyalty programs Epsilon runs.

Know where the wall is. LexisNexis suppresses public-records data only for the categories quoted above, with documentation such as a police report or protective order. Credit header data has no consumer opt-out at all. The exchanges, co-ops and clean rooms take no requests from you because you are not their customer. The only lever on those is upstream: pay without a loyalty ID, audit which apps hold location permission, decline the phone number at checkout. That stops future contribution and nothing else.

Why removed listings come back

The supply chain explains the broker behavior that frustrates people most, re-listing. Opting out of a people-search site deletes the assembled profile. The inputs keep running: the county keeps recording, the credit header keeps updating, the co-op keeps pooling, and the next data refresh can regenerate a profile your old suppression never covered. Your profile is effectively a saved search over live sources, and the search can be run again.

That is why removal is a recurring chore rather than a one-time fix, and it is what Delist My Data is being built to automate: filing removals across the people-search layer and re-filing when the supply chain regenerates a listing. We're in pre-launch; join the waitlist for founding-member access.

Sources

Find out which brokers are publishing your details.

No spam. One email when Delist My Data opens for your area.