The Profile You Never Built: How Data Brokers Assembled a Stranger Who Shares Your Name
Somewhere in the databases of companies most Americans have never heard of, a remarkably detailed portrait of your life exists — your approximate income range, your health-related browsing habits, the names of your relatives, your political leanings, and the neighborhood where you sleep at night. You did not consent to its creation. You cannot easily inspect it. And it is available for purchase to virtually anyone willing to pay. This is the data broker industry, and it may represent the most consequential privacy threat that American consumers are not actively thinking about.
An Industry Built on Aggregation
Data brokers — companies whose primary business model involves collecting, organizing, and reselling personal information — operate almost entirely in the background of American commercial life. Their source material is, in many cases, entirely legal to obtain: public records from county courthouses, voter registration rolls, property ownership filings, social media activity conducted on public settings, purchase history inferred from loyalty programs, and behavioral data licensed from app developers and website operators.
The power of this industry lies not in any single data point but in aggregation. Your name and address, individually, are trivial. Combined with your estimated household income, your inferred health interests (derived from the websites you visit), your vehicle registration, your professional history, the first names of your children, and a probabilistic assessment of your credit behavior, those trivial facts become something considerably more invasive — a commercial dossier assembled without your knowledge or participation.
Industry estimates suggest the data broker market generates revenues exceeding $200 billion annually in the United States. The largest players — companies like Acxiom, LexisNexis Risk Solutions, Oracle Data Cloud, and Experian's marketing services division — maintain records on hundreds of millions of American adults.
What Is Actually in Your File
The specific contents of a data broker profile vary by company and by how much information is publicly available about a given individual, but investigative reporting and academic research have consistently documented the following categories of data as commonly available:
Demographic and household data: Age, gender, estimated household income bracket, marital status, presence of children, homeownership status, length of residence at current address.
Behavioral and interest data: Purchase categories inferred from transaction data, media consumption habits, political donation history (a matter of public record), religious affiliation indicators, and health-interest categories derived from browsing behavior.
Relationship data: Names and approximate ages of household members, inferred family relationships, and in some cases, social network connections.
Location data: Historical location patterns derived from mobile device advertising identifiers, which can reveal regular commuting routes, places of worship, medical facility visits, and overnight locations.
Financial behavior indicators: Estimated credit score ranges, debt-to-income indicators, and spending pattern classifications.
It bears emphasizing that none of this requires a data breach to exist. It is compiled from sources that data brokers access through entirely legal channels.
Who Is Buying Your Shadow Profile
The legitimate customer base for data broker products is broad. Marketers use consumer profiles for targeted advertising. Lenders use them to supplement credit decisions. Employers use them for background screening. Insurance companies use them to refine risk assessments. Researchers use anonymized versions for academic and policy work.
The problem is that the same data products sold to legitimate commercial customers are also accessible — through direct purchase, through data breaches of broker databases themselves, or through fraudulent business accounts — to actors with considerably less benign intentions.
For scammers and fraudsters, a comprehensive data broker profile is an operational resource. It provides the biographical detail required to impersonate a target convincingly, to answer knowledge-based security questions, or to craft personalized phishing messages that reference real details of a person's life. Security researchers have repeatedly demonstrated that the information available through commercial data broker searches is sufficient to defeat the identity verification procedures used by banks, mobile carriers, and government agencies.
For stalkers and domestic abusers, these profiles present a more immediate physical threat. Residential address data, combined with information about daily routines inferred from location history, can enable harassment and violence in ways that few other data sources facilitate. Advocacy organizations working with domestic violence survivors have documented numerous cases in which abusers used commercially available people-search services to locate individuals who had gone to significant lengths to conceal their whereabouts.
For identity thieves, a data broker profile functions as a starting inventory — a list of the facts they need to verify and the gaps they need to fill before attempting account takeover or synthetic identity fraud.
The Regulatory Gap
The United States currently lacks a comprehensive federal privacy law governing data brokers. Unlike the European Union's General Data Protection Regulation, which imposes consent requirements and deletion rights applicable to commercial data processing, American consumers operate under a patchwork of state laws that vary significantly in scope and enforceability.
California's Consumer Privacy Act and its subsequent amendment, the CPRA, represent the most robust state-level framework, granting California residents the right to know what data has been collected about them, to request deletion, and to opt out of data sales. Vermont requires data brokers to register with the state. A small number of additional states have passed or are considering similar legislation.
For the majority of Americans, however, meaningful legal recourse remains limited. The Federal Trade Commission has pursued enforcement actions against specific data broker practices — particularly those involving the sale of sensitive location data to government agencies without appropriate legal process — but has operated under statutory constraints that limit its authority to mandate industry-wide reforms.
What Consumers Can Actually Do
The honest answer is that fully removing yourself from data broker databases is not feasible for most people. The industry is too large, the number of individual companies too great, and the re-aggregation of public records too continuous for any one-time opt-out to produce lasting results. However, meaningful mitigation is achievable.
Manual opt-out requests to major people-search platforms — including Spokeo, WhitePages, BeenVerified, Intelius, and MyLife — are tedious but effective for those specific platforms. Each company maintains its own opt-out procedure, typically requiring submission of identifying information and, in some cases, identity verification.
Data removal services such as DeleteMe, Privacy Bee, and Kanary automate the opt-out process across dozens or hundreds of broker databases, submitting removal requests on a recurring basis to account for data re-population. These services carry subscription costs but substantially reduce the manual burden.
Reducing your public data footprint at the source — using privacy-protective settings on social media, opting out of data sharing in loyalty programs, and limiting app permissions — slows the rate at which new information enters broker databases, even if it cannot address what has already been collected.
Monitoring for misuse through identity theft protection services and regular review of credit reports can surface early indicators that your profile data has been used for fraudulent purposes.
The data broker industry is a legal enterprise operating within a regulatory framework that has not kept pace with its capabilities. Until federal legislation imposes meaningful consent and deletion requirements, the burden of managing this particular privacy risk falls disproportionately on the individuals whose information is being sold — a situation that favors sophisticated, time-rich consumers and leaves everyone else exposed.