Last updated on
Part 1 of 4 — Email Security 101. Coming up: Part 2, what to do after an email data breach · Part 3, types of phishing attacks · Part 4, what BIMI is and whether you need it.
The short version
- Data brokers quietly buy, package, and sell your name, address, email, phone, and habits — feeding spam, scam calls, and even doxxing.
- To remove yourself from data brokers you must opt out of each one individually — there’s no single switch — and the big people-search sites (Spokeo, Whitepages, BeenVerified…) each have their own form.
- Removal doesn’t stick — your data reappears in 3–6 months as brokers re-ingest public records. The lasting fix is to stop feeding them: give every site a separate email alias so there’s no single identifier to buy and resell.
Your personal information is being bought and sold right now by companies you’ve never heard of. If you want to remove yourself from data brokers — the firms that compile dossiers on you from public records, purchases, and app data — this guide walks you through exactly how: what they hold, how to opt out of the biggest ones, why your data keeps coming back, and the one habit that stops the whole machine from rebuilding your profile. This is Part 1 of our Email Security 101 series, and it starts here because a data broker’s favourite key to link everything about you together is the thing you hand out most freely: your email address.
What Data Brokers Are and How They Got Your Data
A data broker is a company whose product is you — or rather, a profile of you assembled from hundreds of sources and sold to anyone who pays. You never signed up, you’re rarely told, and yet detailed records of your life sit in their databases ready to be queried. There are well over 1,500 of them operating in the United States alone.
They build those profiles from a surprising range of feeds:
- Public records — voter rolls, property deeds, court filings, marriage and business registrations.
- Commercial data — loyalty cards, warranty registrations, magazine subscriptions, and purchase histories sold on by retailers.
- Online activity — app permissions, website trackers, and ad-network data tying your behaviour to an identity.
- Other brokers — they buy and cross-reference each other’s data, so one leak spreads everywhere.
The result is a dossier that can include your full name, current and past addresses, phone numbers, email addresses, age, relatives, employer, estimated income, and interests. And the thread that stitches those scattered feeds into one coherent profile is almost always a stable identifier you reuse everywhere — your email address chief among them.
It helps to grasp the scale, because it explains why this is so hard to escape. Data brokering is a multi-billion-dollar industry: the large players hold thousands of individual data points on hundreds of millions of people, and they sell access to marketers, insurers, background-check firms, debt collectors, and — through the people-search sites — anyone with a few dollars and your name. You are not a customer in this market; you are the inventory. That framing is the whole reason a deliberate effort to remove yourself from data brokers is worth making: nobody in the chain is incentivised to leave you out of it, so the initiative has to come from you.

Why You Should Remove Yourself From Data Brokers
This isn’t abstract privacy hygiene — a broker profile creates concrete, everyday harm. It’s worth being clear about the stakes before you decide how much effort to put into removal.
- Spam and scam targeting. Your email and phone in a broker’s file are exactly what fuel the marketing lists, robocalls, and phishing campaigns that flood you.
- Social engineering and fraud. The more a scammer knows about you — your address, relatives, employer — the more convincing their identity-theft and account-takeover attempts become.
- Doxxing and harassment. People-search sites make it trivial to look up a stranger’s home address. That’s the raw material for doxxing and real-world harassment.
- Bigger breach blast radius. Every broker holding your data is another database that can leak. When it does, your details join the next data breach dump, ready for reuse.
Here’s how those risks compound in practice. A scammer buys a cheap people-search report on you: it lists your email, your mobile number, your street address, and the names of two relatives. Now the phishing email that lands in your inbox isn’t generic — it uses your real name, references your city, and mentions a family member, so it sails past the instinct that would normally flag it. A robocaller “from your bank” already knows your address to sound legitimate. That combination of details, all sourced from brokers, is what turns a clumsy scam into a convincing one — and it’s why the data being out there is a security problem, not just a privacy annoyance.
None of this requires you to have done anything wrong online. The profile is built whether you’re careful or not — which is exactly why actively choosing to remove yourself from data brokers matters.
The Three Types of Data Brokers
“Data broker” covers three fairly different businesses, and knowing which is which tells you where your removal effort pays off most.
- People-search sites (Spokeo, Whitepages, BeenVerified, Intelius, Radaris and friends). These are the public-facing ones — type a name and get an address, phone, and relatives. They cause the most visible harm (doxxing, scam targeting) and, helpfully, are the easiest to opt out of.
- Marketing data brokers (Acxiom, Epsilon, and similar). These operate behind the scenes, selling audience segments to advertisers. You won’t find a public profile page, but they hold deep behavioural data. Opting out is possible but slower.
- Risk and verification brokers (LexisNexis, and the credit-adjacent bureaus). These feed identity verification, background checks, and fraud scoring. They’re the hardest to remove from — often you can only suppress or freeze rather than delete.
The reason the distinction is practical rather than academic: your effort has sharply diminishing returns as you move down the list. Clearing the people-search sites removes the exposure a stranger, ex, or scammer can find in thirty seconds — the stuff that enables doxxing and targeted fraud. The marketing brokers mostly affect how much spam and ad targeting you get. The risk brokers you often can’t fully leave at all, and in some cases you may not want to (they underpin legitimate fraud checks). So when you set out to remove yourself from data brokers, spend your energy top-down and don’t feel you’ve failed if the bottom tier proves stubborn.
How to Remove Yourself From Data Brokers, Step by Step
Here’s the uncomfortable truth up front: there is no universal opt-out. To remove yourself from data brokers you submit a separate request to each one. The process, though, is broadly the same everywhere:
- Find your listing. Search the broker’s site for your name and location, and copy the URL of the profile page that comes up. Many opt-out forms ask for that exact link.
- Open the opt-out page. It’s usually at a predictable path —
/optout,/opt-out, or a “privacy” / “suppression” link in the footer. - Submit the removal request. Paste your profile URL and provide the minimum details asked. Use an alias email here, not your real one — more on why below.
- Confirm. Most brokers email a confirmation link you must click; some (like Whitepages) verify by phone or text.
- Record it. Keep a simple list of which brokers you’ve opted out of and the date — you will be repeating this.
One deliberate move makes the whole process safer: use a dedicated email alias for these opt-outs rather than your primary inbox. You’re handing your identity to a company that sells data, so giving them a fresh, single-purpose alias — one that still forwards to you so you receive the confirmation link — means the opt-out itself doesn’t hand them a new key tied to your real identity. An email alias generator makes that a two-second step.
It’s worth being methodical about the order, too. Do the California DROP request first if you qualify (it clears the widest swath in one go), then the top people-search sites, then the marketing and risk brokers. Work from a checklist and paste each profile URL as you go — the single most common reason a removal fails is submitting the wrong or an incomplete profile link, so slow down on that one field. And whenever a broker offers both “suppress” and “delete,” choose delete; suppression often just hides the listing from public view while the underlying record lives on.
The Major Data Broker Opt-Out List
Start with the biggest people-search sites — clearing these removes most of what a casual searcher (or scammer) can find about you. The exact paths change, but the methods below are current as of 2026.
| Broker | Type | How to opt out | Turnaround |
|---|---|---|---|
| Spokeo | People-search | Find your listing, submit at spokeo.com/optout, confirm by email | 24–72 hours |
| Whitepages | People-search | Copy your profile URL to the suppression-requests page; verify by phone/text | A few days |
| BeenVerified | People-search | Online opt-out form, confirm by email | ~24 hours |
| Intelius | People-search | Opt-out form (shared with the PeopleConnect network) | Up to 72 hours |
| Radaris | People-search | Locate profile, request removal via their control page | A few days |
| Acxiom | Marketing | Form at acxiom.com/optout, or call (877) 774-2094 for full deletion | Up to 2 weeks |
| LexisNexis | Risk/verification | Formal suppression request; identity proof required | Weeks |
Beyond these, the long tail matters too — FastPeopleSearch, MyLife, PeopleFinders, TruthFinder and dozens more all carry versions of the same record. Working through the top ten covers most of the exposure; comprehensive lists run to a hundred or more brokers.
The California DELETE Act and One-Stop Opt-Out
There’s finally a shortcut — a partial one. Under California’s DELETE Act, the state launched its DROP platform in January 2026, which lets California residents submit a single request that data brokers registered in the state must honour. It’s the closest thing to a universal opt-out that exists.
The catch is scope. DROP covers the roughly 500 brokers registered in California — real progress, but only about a third of the 1,500-plus operating nationally, and it’s currently limited to California residents. So even if you qualify, it’s a powerful first sweep rather than a complete solution: you’ll still want to hit the major national people-search sites directly. Privacy laws like the California Consumer Privacy Act are steadily expanding these rights, but for now, removal is still mostly a manual, ongoing job.
Why Removal Doesn’t Stick
Here’s the part that surprises people and quietly undoes hours of effort: opting out is not permanent. Brokers continuously re-ingest public records and re-buy commercial data, so a profile you delete today typically reappears within three to six months. You didn’t do anything wrong — the same feeds that built the profile the first time simply rebuild it.
That means removal isn’t a one-time chore but a maintenance one. To actually stay off these sites you’d need to re-run your opt-outs every few months, forever. For most people that’s the point where doing it entirely by hand stops being realistic — and where the strategy has to shift from “delete what’s there” to “stop feeding what rebuilds it.”
It’s worth naming the trap here, because it catches careful people. You spend a weekend opting out, see your listings vanish, and mentally file the problem as solved. Four months later the profiles are back in full, but you’re no longer looking — so you carry on believing you’re private while a scammer can pull your address in seconds. A removal you don’t maintain is arguably worse than none, because it swaps a real risk for a false sense of safety. Accepting the maintenance reality up front is what separates people who stay off the brokers from people who did it once and forgot.
A Repeatable Data-Broker Removal Routine
Because the profiles come back, the goal isn’t a single heroic afternoon — it’s a light routine you can actually sustain. Here’s a realistic cadence to remove yourself from data brokers without it taking over your life:
- Do a thorough first pass. Set aside two or three hours once. Run DROP if you’re in California, then work down a current top-brokers list, opting out of each with your alias and profile URL. Save your checklist.
- Set a calendar reminder for four months out. That’s inside the three-to-six-month window in which most listings return, so you catch them as they reappear rather than long after.
- On each repeat, search first. You don’t need to redo every broker — search your name and only re-opt-out of the ones that have actually resurfaced. It’s far quicker than the first pass.
- Decide honestly whether to automate. If the reminder keeps getting ignored, that’s your answer: a removal service will do the upkeep you won’t. An unused checklist protects no one.
The routine matters because a half-finished removal gives false comfort — you feel covered while the biggest brokers quietly re-list you. Whichever cadence you pick, write it down and treat it like any other recurring security chore, alongside updating passwords and reviewing account access.
Stop Feeding the Brokers: Aliases Going Forward
You can’t undo the public records that already exist, but you can starve the machine that merges everything into one profile — and that’s where your email comes in. Remember the thread from the start of this guide: brokers rely on a stable identifier you reuse everywhere to link scattered data into a single dossier. Your email is that identifier.
Hand every website the same address and you gift brokers a ready-made join key: the shop, the newsletter, the app, and the forum all report “the same person,” and the profile writes itself. Give each site a different email alias, and that key disappears. There’s no shared thread to correlate, each service sees a unique address, and any one of them leaking or selling your data exposes only that single alias — which you can switch off.
This is the durable half of the strategy, and it’s what makes it worth reading our companion pieces on why using one email for everything is risky and whether you should use your real email. A dedicated email alias forwards to the inbox you already use, so you lose nothing, but brokers lose the one thing they need most. Because these are permanent, controllable forwarding addresses — not disposable inboxes that expire — you get lasting separation rather than a throwaway that breaks your accounts. It also quietly kills the tracking side of the equation, the same way blocking a tracking pixel does.
There’s a compounding effect worth appreciating. The first time you use an alias for a signup, it feels like a tiny thing. But a year later, when you have a different address behind your shop accounts, your newsletters, your apps, and your forums, a broker trying to assemble “you” hits a wall — the data points no longer share a key, so they stay as disconnected fragments instead of a saleable dossier. And if one of those services is breached or sells its list, the damage is quarantined to that single alias, which you disable in seconds. You can’t retroactively un-share the email you’ve already spread around, but every new alias from today makes the next attempt to profile you a little harder — and that’s the direction you want the trend line pointing while you work to remove yourself from data brokers on the cleanup side.
DIY vs Automated Removal Services
Given the every-few-months treadmill, many people reach for an automated data-broker removal service — DeleteMe and Incogni are the best known. They submit and re-submit opt-outs on your behalf across dozens or hundreds of brokers for an annual fee. The trade-off is straightforward:
- Do it yourself: free, and you control exactly what’s sent — but it’s genuinely tedious, and you must remember to repeat it every 3–6 months or the profiles quietly return.
- Automated service: costs money and requires you to hand a company your details to remove your details (mild irony), but it runs continuously and covers far more brokers than most people will by hand.
A reasonable rule of thumb: if your exposure is high (you’ve been doxxed, you’re in a public-facing role, or you’re escaping harassment) or you simply know you won’t keep up the manual cadence, a service is worth the fee. If your situation is ordinary and you’re willing to spend an afternoon a few times a year, doing it yourself is perfectly effective and costs nothing but time. There’s no wrong answer — the only real mistake is opting out once and assuming it’s permanent.
Either way, the removal step only addresses the data already out there. Whichever you choose, pair it with per-site aliases so you’re not refilling the bucket you’re paying to empty — and while you’re tightening things up, our guides on how to hide your email address online and how to stop spam emails cover the rest of the routine.
Final Thoughts
Removing yourself from data brokers is worth doing, and this is the order that works: run the California DROP request if you qualify, then opt out of the major people-search sites (Spokeo, Whitepages, BeenVerified and the rest of the top ten), then decide whether the every-few-months upkeep is worth doing by hand or worth paying a service to automate. But treat all of that as clearing the backlog. The reason your data keeps coming back is that you keep handing out the same identifier, so the profile keeps re-forming. Fix that going forward — a different alias for every site — and you turn an endless cleanup into a one-time one. That’s the whole thesis of this series: privacy isn’t a single heroic purge, it’s a few small habits that stop the problem at the source.
If you only take one action from this guide, make it this: create one alias today and use it for your next signup. It costs nothing, it’s free for your first ten aliases, it takes about as long as reading this sentence, and it’s the single change that flips you from quietly feeding the brokers to actively starving them. The opt-outs clear the past; the alias habit protects the future — and together they’re what it actually takes to remove yourself from data brokers and stay removed. Next in Email Security 101: exactly what to do in the first hour after your email turns up in a breach.
Frequently Asked Questions
How do I remove myself from data brokers?
There’s no single switch — you opt out of each broker individually. Start with the big people-search sites (Spokeo at spokeo.com/optout, Whitepages via its suppression-requests page, BeenVerified, Intelius, Radaris), then marketing brokers like Acxiom (acxiom.com/optout). For each: find your listing, submit the opt-out form with your profile URL, and confirm by email or phone. California residents can also use the state’s DROP platform for a broad first sweep. Then repeat every 3-6 months, because the data reappears.
Is it free to remove yourself from data brokers?
Yes, doing it yourself is free — every legitimate broker is legally required to offer a free opt-out. It just costs time, because you submit a separate request to each of the 100+ brokers and repeat it every few months. Paid services like DeleteMe or Incogni charge an annual fee to automate that ongoing work, but you never have to pay a broker itself to remove your data.
Why does my information come back after I opt out?
Because data brokers continuously re-ingest public records (property, voter, court filings) and re-buy commercial data. Opting out removes the current profile, but the same feeds rebuild it — typically within three to six months. That’s why removal is a recurring task, and why the durable fix is to stop feeding brokers a shared identifier: give each site a different email alias so there’s nothing to link a new profile together.
How long does data broker removal take?
Per broker, anywhere from about 24 hours (BeenVerified, Spokeo) to a couple of weeks (Acxiom), and longer for risk/verification brokers like LexisNexis. Working through the top ten people-search sites is a few hours of effort. The catch isn’t the wait — it’s that you have to redo it every 3-6 months as the listings return.
What is the California DELETE Act?
It’s a California law whose DROP platform (live since January 2026) lets California residents submit one request that all data brokers registered in the state must honour — the closest thing to a universal opt-out. The limit is scope: it covers roughly 500 California-registered brokers, about a third of the 1,500-plus nationwide, and applies to California residents. Use it as a broad first sweep, then opt out of the major national brokers directly.
Should I use my real email to opt out of data brokers?
No. You’re submitting details to companies whose business is selling data, so hand them an email alias, not your primary inbox. The alias still forwards the confirmation link to you, so the opt-out works, but it doesn’t give the broker a fresh tracking key tied to your real identity. Using a separate alias for these requests is a small step that avoids making the problem worse while you fix it.
Do email aliases stop data brokers?
They stop brokers from rebuilding one profile out of your scattered activity. Brokers rely on a stable identifier you reuse everywhere — usually your email — to merge data from many sources into a single dossier. Give each site its own alias and that shared key is gone: there’s no common thread to correlate, and a leak at one service exposes only that alias, which you can disable. Aliases don’t erase existing records, but they starve the machine that creates new ones.
Is removing yourself from data brokers worth it?
Yes — it cuts spam and scam targeting, makes doxxing and social-engineering harder, and shrinks how much of your data is exposed in the next breach. Just go in knowing it’s maintenance, not a one-time fix: the profiles return every few months. Pair the removal with per-site email aliases so you’re clearing the backlog and stopping new profiles from forming, rather than deleting the same data forever.
