Data Brokers in the United States: No Federal Privacy Law, 25 Major Brokers, and How to Opt Out

Data Brokers in the United States: No Federal Privacy Law, 25 Major Brokers, and How to Opt Out

No

No

No

Location

A deleteme briefing

The United States has no single, comprehensive federal privacy law. Unlike the European Union, where the GDPR gives individuals broad rights over how their personal data is collected, processed, and erased, the US still relies on a patchwork of sector-specific federal laws and state-by-state privacy statutes.

That gap has allowed a large data broker industry to develop. These companies collect, aggregate, enrich, and sell personal information about people who often have no direct relationship with them and may not even know they exist.

Data brokers build profiles from public records, commercial transactions, marketing lists, location signals, behavioural data, breach corpora, court filings, property records, and other open or semi-open sources. A single person may appear across many broker systems at once: as a people-search profile, a marketing segment, a credit-related record, a property record, a household profile, or a breach-linked identity.

This report explains what US law does and does not protect, how the state privacy patchwork works, which major brokers commonly hold US data, what practical opt-out steps exist, and where removal reaches its limit.

Why the US Has No Federal Privacy Law

The US privacy system is fragmented by design.

There is no federal equivalent of the GDPR. Instead, the US regulates specific categories of data through separate laws:

• HIPAA for certain health records;

• FCRA for credit and consumer reporting;

• COPPA for children’s data;

• GLBA for financial institutions;

• FERPA for education records.

These laws matter, but each applies only to a defined sector. A data broker holding general consumer profiles, addresses, relatives, phone numbers, purchase behaviour, inferred income, lifestyle signals, location data, or marketing segments, may fall outside those narrow federal regimes.

That is the central problem: data brokers often operate in the gaps between regulated sectors.

For deleteme clients, this means US exposure cannot be treated as one legal problem. It must be mapped by source type, broker category, state residency, use case, and whether the data is regulated, public, inferred, or commercially aggregated.

About Us

A deleteme briefing

The United States has no single, comprehensive federal privacy law. Unlike the European Union, where the GDPR gives individuals broad rights over how their personal data is collected, processed, and erased, the US still relies on a patchwork of sector-specific federal laws and state-by-state privacy statutes.

That gap has allowed a large data broker industry to develop. These companies collect, aggregate, enrich, and sell personal information about people who often have no direct relationship with them and may not even know they exist.

Data brokers build profiles from public records, commercial transactions, marketing lists, location signals, behavioural data, breach corpora, court filings, property records, and other open or semi-open sources. A single person may appear across many broker systems at once: as a people-search profile, a marketing segment, a credit-related record, a property record, a household profile, or a breach-linked identity.

This report explains what US law does and does not protect, how the state privacy patchwork works, which major brokers commonly hold US data, what practical opt-out steps exist, and where removal reaches its limit.

Why the US Has No Federal Privacy Law

The US privacy system is fragmented by design.

There is no federal equivalent of the GDPR. Instead, the US regulates specific categories of data through separate laws:

• HIPAA for certain health records;

• FCRA for credit and consumer reporting;

• COPPA for children’s data;

• GLBA for financial institutions;

• FERPA for education records.

These laws matter, but each applies only to a defined sector. A data broker holding general consumer profiles, addresses, relatives, phone numbers, purchase behaviour, inferred income, lifestyle signals, location data, or marketing segments, may fall outside those narrow federal regimes.

That is the central problem: data brokers often operate in the gaps between regulated sectors.

For deleteme clients, this means US exposure cannot be treated as one legal problem. It must be mapped by source type, broker category, state residency, use case, and whether the data is regulated, public, inferred, or commercially aggregated.

Key Responsibilities

A deleteme briefing

The United States has no single, comprehensive federal privacy law. Unlike the European Union, where the GDPR gives individuals broad rights over how their personal data is collected, processed, and erased, the US still relies on a patchwork of sector-specific federal laws and state-by-state privacy statutes.

That gap has allowed a large data broker industry to develop. These companies collect, aggregate, enrich, and sell personal information about people who often have no direct relationship with them and may not even know they exist.

Data brokers build profiles from public records, commercial transactions, marketing lists, location signals, behavioural data, breach corpora, court filings, property records, and other open or semi-open sources. A single person may appear across many broker systems at once: as a people-search profile, a marketing segment, a credit-related record, a property record, a household profile, or a breach-linked identity.

This report explains what US law does and does not protect, how the state privacy patchwork works, which major brokers commonly hold US data, what practical opt-out steps exist, and where removal reaches its limit.

Why the US Has No Federal Privacy Law

The US privacy system is fragmented by design.

There is no federal equivalent of the GDPR. Instead, the US regulates specific categories of data through separate laws:

• HIPAA for certain health records;

• FCRA for credit and consumer reporting;

• COPPA for children’s data;

• GLBA for financial institutions;

• FERPA for education records.

These laws matter, but each applies only to a defined sector. A data broker holding general consumer profiles, addresses, relatives, phone numbers, purchase behaviour, inferred income, lifestyle signals, location data, or marketing segments, may fall outside those narrow federal regimes.

That is the central problem: data brokers often operate in the gaps between regulated sectors.

For deleteme clients, this means US exposure cannot be treated as one legal problem. It must be mapped by source type, broker category, state residency, use case, and whether the data is regulated, public, inferred, or commercially aggregated.

Requirements

A deleteme briefing

The United States has no single, comprehensive federal privacy law. Unlike the European Union, where the GDPR gives individuals broad rights over how their personal data is collected, processed, and erased, the US still relies on a patchwork of sector-specific federal laws and state-by-state privacy statutes.

That gap has allowed a large data broker industry to develop. These companies collect, aggregate, enrich, and sell personal information about people who often have no direct relationship with them and may not even know they exist.

Data brokers build profiles from public records, commercial transactions, marketing lists, location signals, behavioural data, breach corpora, court filings, property records, and other open or semi-open sources. A single person may appear across many broker systems at once: as a people-search profile, a marketing segment, a credit-related record, a property record, a household profile, or a breach-linked identity.

This report explains what US law does and does not protect, how the state privacy patchwork works, which major brokers commonly hold US data, what practical opt-out steps exist, and where removal reaches its limit.

Why the US Has No Federal Privacy Law

The US privacy system is fragmented by design.

There is no federal equivalent of the GDPR. Instead, the US regulates specific categories of data through separate laws:

• HIPAA for certain health records;

• FCRA for credit and consumer reporting;

• COPPA for children’s data;

• GLBA for financial institutions;

• FERPA for education records.

These laws matter, but each applies only to a defined sector. A data broker holding general consumer profiles, addresses, relatives, phone numbers, purchase behaviour, inferred income, lifestyle signals, location data, or marketing segments, may fall outside those narrow federal regimes.

That is the central problem: data brokers often operate in the gaps between regulated sectors.

For deleteme clients, this means US exposure cannot be treated as one legal problem. It must be mapped by source type, broker category, state residency, use case, and whether the data is regulated, public, inferred, or commercially aggregated.

Qualifications

A deleteme briefing

The United States has no single, comprehensive federal privacy law. Unlike the European Union, where the GDPR gives individuals broad rights over how their personal data is collected, processed, and erased, the US still relies on a patchwork of sector-specific federal laws and state-by-state privacy statutes.

That gap has allowed a large data broker industry to develop. These companies collect, aggregate, enrich, and sell personal information about people who often have no direct relationship with them and may not even know they exist.

Data brokers build profiles from public records, commercial transactions, marketing lists, location signals, behavioural data, breach corpora, court filings, property records, and other open or semi-open sources. A single person may appear across many broker systems at once: as a people-search profile, a marketing segment, a credit-related record, a property record, a household profile, or a breach-linked identity.

This report explains what US law does and does not protect, how the state privacy patchwork works, which major brokers commonly hold US data, what practical opt-out steps exist, and where removal reaches its limit.

Why the US Has No Federal Privacy Law

The US privacy system is fragmented by design.

There is no federal equivalent of the GDPR. Instead, the US regulates specific categories of data through separate laws:

• HIPAA for certain health records;

• FCRA for credit and consumer reporting;

• COPPA for children’s data;

• GLBA for financial institutions;

• FERPA for education records.

These laws matter, but each applies only to a defined sector. A data broker holding general consumer profiles, addresses, relatives, phone numbers, purchase behaviour, inferred income, lifestyle signals, location data, or marketing segments, may fall outside those narrow federal regimes.

That is the central problem: data brokers often operate in the gaps between regulated sectors.

For deleteme clients, this means US exposure cannot be treated as one legal problem. It must be mapped by source type, broker category, state residency, use case, and whether the data is regulated, public, inferred, or commercially aggregated.

Perks and Benefits

A deleteme briefing

The United States has no single, comprehensive federal privacy law. Unlike the European Union, where the GDPR gives individuals broad rights over how their personal data is collected, processed, and erased, the US still relies on a patchwork of sector-specific federal laws and state-by-state privacy statutes.

That gap has allowed a large data broker industry to develop. These companies collect, aggregate, enrich, and sell personal information about people who often have no direct relationship with them and may not even know they exist.

Data brokers build profiles from public records, commercial transactions, marketing lists, location signals, behavioural data, breach corpora, court filings, property records, and other open or semi-open sources. A single person may appear across many broker systems at once: as a people-search profile, a marketing segment, a credit-related record, a property record, a household profile, or a breach-linked identity.

This report explains what US law does and does not protect, how the state privacy patchwork works, which major brokers commonly hold US data, what practical opt-out steps exist, and where removal reaches its limit.

Why the US Has No Federal Privacy Law

The US privacy system is fragmented by design.

There is no federal equivalent of the GDPR. Instead, the US regulates specific categories of data through separate laws:

• HIPAA for certain health records;

• FCRA for credit and consumer reporting;

• COPPA for children’s data;

• GLBA for financial institutions;

• FERPA for education records.

These laws matter, but each applies only to a defined sector. A data broker holding general consumer profiles, addresses, relatives, phone numbers, purchase behaviour, inferred income, lifestyle signals, location data, or marketing segments, may fall outside those narrow federal regimes.

That is the central problem: data brokers often operate in the gaps between regulated sectors.

For deleteme clients, this means US exposure cannot be treated as one legal problem. It must be mapped by source type, broker category, state residency, use case, and whether the data is regulated, public, inferred, or commercially aggregated.

How to Apply

A deleteme briefing

The United States has no single, comprehensive federal privacy law. Unlike the European Union, where the GDPR gives individuals broad rights over how their personal data is collected, processed, and erased, the US still relies on a patchwork of sector-specific federal laws and state-by-state privacy statutes.

That gap has allowed a large data broker industry to develop. These companies collect, aggregate, enrich, and sell personal information about people who often have no direct relationship with them and may not even know they exist.

Data brokers build profiles from public records, commercial transactions, marketing lists, location signals, behavioural data, breach corpora, court filings, property records, and other open or semi-open sources. A single person may appear across many broker systems at once: as a people-search profile, a marketing segment, a credit-related record, a property record, a household profile, or a breach-linked identity.

This report explains what US law does and does not protect, how the state privacy patchwork works, which major brokers commonly hold US data, what practical opt-out steps exist, and where removal reaches its limit.

Why the US Has No Federal Privacy Law

The US privacy system is fragmented by design.

There is no federal equivalent of the GDPR. Instead, the US regulates specific categories of data through separate laws:

• HIPAA for certain health records;

• FCRA for credit and consumer reporting;

• COPPA for children’s data;

• GLBA for financial institutions;

• FERPA for education records.

These laws matter, but each applies only to a defined sector. A data broker holding general consumer profiles, addresses, relatives, phone numbers, purchase behaviour, inferred income, lifestyle signals, location data, or marketing segments, may fall outside those narrow federal regimes.

That is the central problem: data brokers often operate in the gaps between regulated sectors.

For deleteme clients, this means US exposure cannot be treated as one legal problem. It must be mapped by source type, broker category, state residency, use case, and whether the data is regulated, public, inferred, or commercially aggregated.