Data brokers do not need one dramatic secret to build a profile about you. Their value often comes from connecting ordinary details: a purchase, loyalty-card registration, website visit, app permission, address change or public record. On their own, these details may seem harmless. Combined over time, they can suggest routines, interests, household characteristics and possible life circumstances.
That does not mean every profile is complete, accurate or equally sensitive. It also does not mean every company handling personal information is a data broker. But personal-data markets can allow information collected in one context to be used in another, beyond the relationship a person believes they have with an app, shop or website.
Reducing exposure is possible, although complete removal from the commercial data ecosystem is rarely realistic. The practical goal is to limit unnecessary collection, use available privacy rights and treat digital privacy as ongoing risk reduction rather than a one-time cleanup.
What is a data broker?
A data broker is generally a company that collects personal information from multiple sources, combines or analyses it, and makes information or data-derived services available to other organisations. The precise legal definition varies by country and by law.
Some data brokers provide marketing audiences, such as groups of frequent travellers, new homeowners or people likely to be interested in certain products. Others provide identity-verification, fraud-prevention, address-validation or risk-related services. Information may be supplied as lists, audience segments, matching tools, scores or software services rather than as a spreadsheet of names.
The term should not be applied indiscriminately. A retailer using its own customer data is not necessarily a data broker. An app provider collecting information to operate its service is not automatically one either. Credit-reporting agencies and financial institutions may also be subject to separate sector-specific rules.
These distinctions matter because organisations have different roles and legal obligations. Still, a common concern can arise across many business models: information collected or acquired in one setting can shape offers, advertising, verification or decisions elsewhere.
Where personal information comes from
Personal-data markets are built from many sources, not one master database. Privacy notices, regulatory investigations and academic research describe information gathered directly from consumers, licensed from other businesses and drawn from public sources.
- Retail and loyalty programmes: Purchases, product preferences, returns, store visits and membership details can help create a picture of consumer behaviour.
- Websites and advertising technology: Cookies, tracking pixels and embedded code can record visits, clicks, purchases and interactions. A pixel is a small piece of code that reports activity to the organisation that placed it or a technology partner.
- Mobile apps: Apps may collect account details, device information and usage data. Where permission is granted, they may also collect location information. Third-party software development kits, or SDKs, can send data to analytics, advertising or measurement providers.
- Mobile identifiers: Phones have advertising identifiers intended to support advertising measurement and personalisation. Modern operating systems offer controls over their use, but settings and app practices vary.
- Public records: Property transactions, company registrations, court filings, professional licences and other official documents may be public or legally available in some jurisdictions.
- Surveys, competitions and mailing lists: A form completed for a discount, prize draw or newsletter can provide information that may be shared under the terms accepted by the participant.
- Connected services: Smart televisions, vehicles, wearables and home devices can generate information about use patterns, depending on their settings and privacy policies.
Collection practices differ sharply between companies and countries. Privacy notices may describe broad recipient categories rather than every downstream organisation. Advertising and analytics supply chains can also involve several intermediaries, making it difficult for people to identify who holds their information.
How fragments become a profile
The process of joining separate records is often called identity resolution. In simple terms, it is an attempt to determine whether information from different devices, services or databases relates to the same person or household.
An email address, telephone number, postal address or customer account number can serve as a direct link. Companies may also use device identifiers, browser identifiers, encrypted versions of email addresses, IP-address patterns and other signals. These signals may not identify a named individual by themselves, but they can help associate activity with an account, device or household.
For example, someone might use the same email address for a retailer, travel site and newsletter. If those organisations share information with partners under their policies and applicable law, the email address can connect separate records. A home address can also link people into a household record, even when household members use different devices.
Identity resolution is not always accurate. Shared devices, recycled phone numbers, common names, moves and incomplete records can create errors. Even imperfect matching can be useful for broad audience selection, however, because a marketer may only be trying to reach a category of people rather than make a high-stakes decision about one individual.
What companies may infer rather than directly know
A profile can contain facts collected directly, but it can also include predictions. Based on purchases, browsing activity, location signals or household information, a business may infer likely interests, approximate income range, home ownership, parenthood, travel habits or a possible upcoming move.
These inferences are often expressed as categories, scores or audience labels rather than detailed biographies. A marketer may seek an audience of people likely to be interested in fitness equipment, luxury travel or home renovation. Fraud and identity companies may create risk signals intended to identify unusual account activity or a possible identity mismatch.
An inferred category is not proof. It can be outdated, overly broad or wrong. A person researching a medical condition for a relative, visiting a place once or buying a gift can be assigned an interest they do not have. The problem is not only inaccuracy: people may never see the inference, understand how it was generated or have a straightforward way to challenge it.
Why ordinary data can become sensitive
Many individual data points are routine. The concern grows when they are combined over time. Location history can suggest where someone works, sleeps, travels or regularly spends time. Purchase records can imply financial pressure, dietary choices or health-related interests. Repeated visits to particular places may suggest religious practice, political activity, medical appointments or relationships.
Inference is different from certainty. A location signal near a clinic does not establish why someone was there, and a purchase does not prove a medical condition. That distinction matters. Yet a mistaken or incomplete profile can still affect advertisements, offers, account reviews or the level of scrutiny applied to a transaction.
There can also be safety risks. Public records, people-search products and data leaks can make it easier for stalkers, harassers or abusive partners to locate someone. Data brokerage is not the sole cause of these harms, and many records originate in public systems. Aggregation can nevertheless make scattered information easier to search, package and use.
How data-broker profiles are used
Targeted advertising is the most visible use. Instead of giving an advertiser a list of names, a company may let it select an audience within an advertising system. A retailer, for example, might ask to show an advertisement to people in a particular region who appear interested in gardening.
Other uses are less visible. Data products can support marketing analysis, address updates, identity verification, fraud detection and customer matching. In some sectors, data may inform eligibility, pricing or risk processes. Those activities can be subject to additional laws and should not be treated as equivalent to ordinary advertising.
Not every data broker provides data for every purpose, and not every company using personal information makes high-impact decisions. The common thread is the conversion of information about people into a commercial asset or service.
The risks: power, accuracy and visibility
The immediate result of profiling may be unwanted advertising. Wider risks include persistent monitoring, inaccurate records, unwanted segmentation and the exposure of sensitive information through a breach, misuse or weak security.
There is also an information imbalance. A company may know which devices probably belong to a household, which products someone has considered and which audience labels have been assigned. The person being profiled may have little visibility into the process. That can make it difficult to correct errors or assess whether treatment was fair.
Privacy risks can be especially high for people facing harassment, domestic abuse, discrimination or identity theft. For them, reducing publicly discoverable contact details and reviewing public-facing records can be as important as changing online settings.
Why deleting one account is rarely enough
Deleting a social-media account can reduce future collection by that service, but it does not erase data held by retailers, apps, public authorities, marketing partners or other databases. Companies may also retain certain records for legal, security, fraud-prevention or accounting purposes.
Information can persist in backups for a period, remain in public records or be collected again from another source. Continued use of the same phone number, address, email address or loyalty account can create new links. A deletion request can be useful, but it is not a guarantee of permanent invisibility.
How privacy laws can help
Privacy rights depend on where a person lives, where an organisation operates and what type of information is involved. Consent is important in many situations, but it is not the only legal basis that may allow processing.
In the European Union, the General Data Protection Regulation, or GDPR, provides rights including access, correction, deletion in certain circumstances, objection to some processing and data portability in defined cases. People have a strong right to object when personal data is used for direct marketing. The GDPR also sets additional conditions for processing special categories of personal data, including health information and religious beliefs.
California’s California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives covered California residents rights to know about certain personal-information practices, request deletion and correction, and opt out of the sale or sharing of personal information in covered circumstances. It also provides a right to limit certain uses and disclosures of sensitive personal information. Exceptions apply, including for some security, legal-compliance and operational purposes.
Brazil’s Lei Geral de Proteção de Dados, or LGPD, provides rights including confirmation of processing, access, correction and information about sharing. Depending on the circumstances, it also offers routes to request anonymisation, blocking or deletion of unnecessary, excessive or unlawfully processed data, as well as portability subject to regulatory rules.
These laws do not create a universal delete button. They may not apply to every company, type of data or person outside the relevant jurisdiction. They have, however, led more organisations to publish privacy-request channels and explain aspects of their data practices.
Practical steps to reduce data exposure
The most useful habits reduce unnecessary collection at the source. They will not stop all online tracking, but they can make a profile less detailed and reduce the number of organisations receiving information.
- Review app permissions. Remove access to location, contacts, microphone, camera and photo libraries when an app does not genuinely need it. Choose approximate rather than precise location where your device offers that option.
- Check browser privacy controls. Use a browser with tracking protection, review third-party-cookie settings and clear cookies when appropriate. Blocking cookies does not eliminate all tracking, but it can limit common cross-site techniques.
- Adjust advertising settings. Apple, Google and other major providers offer advertising and privacy controls, although menu names and locations can change. Check device privacy settings and account advertising or data-and-privacy pages.
- Be selective with loyalty schemes and forms. Consider whether a discount is worth linking purchases to an identifiable account. Review whether promotions, surveys or competitions permit sharing with marketing partners.
- Separate identities where practical. An email alias for newsletters and shopping can reduce the number of services connected through one durable address. This is not anonymity, but it can reduce unnecessary linkage.
- Limit public profiles. Review what social accounts, professional pages and public posts reveal about your address, family, routine, workplace and travel.
- Protect core accounts. Use unique passwords and multi-factor authentication. A compromised email account can expose bills, identity documents and password-reset messages.
- Handle identity documents carefully. Do not send identification to a privacy service or opt-out site unless you have confirmed it is an official channel and understand why the document is required.
How to make a data broker opt-out or deletion request
Start with companies you can identify. Search for the privacy notice of a people-search site, marketing company, retailer, app or data service that appears to hold your information. Look for pages labelled privacy rights, privacy request, do not sell or share, opt out, delete my data or access request.
Use official channels rather than links in unsolicited emails or messages. Scammers can exploit privacy concerns by asking people to upload passports, identity cards or payment details. A legitimate organisation may need to verify identity before releasing or deleting data, but its privacy notice should explain the process and required information.
Keep a record of the request date, company, request type and confirmation number. If more information is requested, provide only what is necessary through a secure official channel. Response periods vary by law and company. Under the GDPR, organisations generally must respond without undue delay and normally within one month, although extensions may apply.
Commercial data-removal services may submit requests to multiple people-search and broker sites on a customer’s behalf. They can be useful for people with limited time, but coverage varies, many brokers may not be included and listings can reappear when new source data is obtained. Before paying, check which sites are covered, whether repeat removals are included and what personal information the service itself will receive.
Privacy is not perfect invisibility
Every privacy choice has trade-offs. Location sharing can support navigation, emergency features and local recommendations. Fraud systems may use device and behavioural signals to identify suspicious logins. Retailers may use customer information to provide receipts, returns, warranties and loyalty rewards.
The aim is not necessarily to reject every data use. It is to decide which uses are proportionate, understandable and worth the exchange. A useful question is not only whether a company has a privacy policy, but whether a person can reasonably understand what will happen to their information after collection.
What to watch next
Connected devices, location-based services and AI systems may make data-derived inferences more detailed and automated. AI does not create the underlying privacy issue by itself, but it can amplify it by finding patterns in large datasets and generating new predictions about people.
Stronger laws, enforcement actions and technical changes in browsers and mobile platforms may limit some forms of tracking. Their effect will depend on enforcement, business incentives, legal exceptions and whether companies replace one tracking method with another.
The central question is not whether someone has something to hide. It is whether people should be able to understand, question and influence the profile built about them. Data brokers make that harder because profiles can be assembled across many ordinary moments. Privacy begins with making those connections less automatic and more accountable.
Image by Саша Алалыкин on Pexels.