Who’s Selling Your Financial Data? Data Brokers Explained (and the New Way to Say No) – Reinvest Safe

Who’s Selling Your Financial Data? Data Brokers Explained (and the New Way to Say No)

Data brokers collect and sell your financial details to advertisers and lenders, and sometimes scammers. Here's how it works and how California's new DROP tool helps you opt out in 2026.

You’ve probably never heard of Acxiom, LexisNexis Risk Solutions, or CoreLogic. But there’s a good chance one of them, or a few dozen others just like them, has a file on you right now. It likely includes your income range, your estimated debt load, whether you recently searched for a personal loan, and maybe even how many times you’ve been late on a bill.

That’s the business of data brokers: companies that collect, package, and sell personal information about people they’ve never met and never asked for permission. You don’t sign up for it. Most people find out it’s happening only when a strangely specific ad shows up, or worse, when a scam call uses details that feel too accurate to be a coincidence.

This guide breaks down what data brokers actually do, how your financial life ends up in their files, and what’s changing in 2026 that finally gives you a real way to say no.

Woman reviewing a phone and paper mail at her kitchen table with a concerned expression

What Is a Data Broker, Exactly?

A data broker is a company that collects personal information from public records, online activity, and other businesses, then compiles it into profiles it sells to advertisers, insurers, lenders, and background-check services. The Federal Trade Commission (FTC) has described the industry for over a decade as one that operates almost entirely behind the scenes, with no direct relationship to the people whose data it trades.

Your data gets pulled from sources like:

  • Public records (property deeds, voter registrations, court filings)
  • Retailer loyalty programs and purchase histories
  • App permissions and location tracking
  • Credit header data (name, address, and phone number, not your score, sold off by credit bureaus)
  • Social media activity and browsing behavior tracked across websites

Individually, none of that looks alarming. Combined across dozens of sources, it becomes a surprisingly detailed picture of who you are and what you’re likely to buy, borrow, or fall for.

What They Know About Your Financial Life

This is where it gets uncomfortable for anyone focused on money management. Data brokers don’t just know your name and address. Many build financial behavior profiles that can include:

  • Estimated household income and net worth
  • Whether you’re likely carrying credit card debt or a large mortgage
  • Recent searches related to loans, bankruptcy, or debt relief
  • Segments like “financially vulnerable” or “credit seeker,” used internally by marketers
  • Life events that often trigger financial stress, such as divorce, job loss, or a new baby

These aren’t hypothetical categories. Consumer Reports and privacy researchers have documented data broker product sheets that segment people by exactly these traits, marketed to lenders and marketers as a way to target likely buyers of high-interest loans, debt consolidation offers, or extended warranties. The same profiling that fuels ordinary ad targeting can also steer costly financial products straight at people already under stress.

The Scam Connection Nobody Talks About Enough

There’s a darker use case too. Scammers increasingly buy or scrape data broker information to make fraud attempts more convincing. A caller who already knows your name, address, employer, and that you recently looked into refinancing your mortgage sounds a lot more legitimate than a stranger cold-calling from a script.

That specificity is exactly what powers schemes like long-con investment scams, where trust is built gradually using details that make the target feel like they’re talking to someone who already knows them. It’s also part of why payment app impersonation scams have gotten harder to spot, since a fraudster posing as “your bank’s fraud team” is far more convincing when they can recite your last transaction or your billing zip code. It’s also worth knowing the common mistakes that make P2P payment scams work in the first place, since data brokers are only part of the equation.

Data brokers aren’t the ones committing fraud. But the data ecosystem they’ve built gives scammers raw material they didn’t have a decade ago.

Is Any of This Legal?

Mostly, yes, and that surprises a lot of people. The United States doesn’t have a single federal law that broadly restricts data brokers the way the European Union’s GDPR does. Federal rules like the Fair Credit Reporting Act (FCRA) govern specific uses, such as credit and employment decisions, and the FTC has brought enforcement actions against brokers for deceptive practices or selling sensitive location data. But there’s no blanket law that says a company can’t collect and resell your basic profile. That gap is exactly why state-level action has become the main battleground for consumer protection here.

Your State Rights: A Patchwork, But a Growing One

A handful of states have passed laws that give residents real leverage over their data. Coverage and strength vary quite a bit, so what you’re entitled to may depend entirely on your zip code.

State What the Law Covers Notable Feature
California CCPA/CPRA plus the Delete Act DROP platform: one request deletes you from every registered broker
Texas Texas Data Privacy and Security Act Opt-out rights for sale of personal data
Oregon Oregon Consumer Privacy Act Broad definition of “sale,” including data traded for non-cash value
Vermont Data broker registration law Requires brokers to register annually with the state

Requirements and enforcement dates shift as legislatures act, so treat this as a starting point and confirm current rules with your state attorney general’s office before relying on it.

California’s DROP Platform: The New Way to Say No

This is the development that makes 2026 a meaningfully different year for anyone tired of chasing down individual opt-out forms. The California Privacy Protection Agency (CPPA) launched the Delete Request and Opt-out Platform, known as DROP, on January 1, 2026. It’s a single online tool that lets a California resident submit one deletion request that applies across every broker registered in the state, instead of filling out a separate form for each company one by one.

Registered brokers are required to start processing deletion requests submitted through DROP by August 1, 2026. Before this, opting out meant tracking down dozens of individual brokers, each with its own process, and repeating the process periodically since new brokers pop up constantly. DROP doesn’t erase the industry. But it turns a multi-day chore into something closer to a single afternoon task, at least for California residents.

If you don’t live in California, you still have options, just less centralized ones. Manual opt-outs through individual brokers, sometimes with the help of a paid removal service, remain the standard path outside of DROP-covered states.

Glowing digital lock icon above a stack of blank envelopes representing data privacy

What You Can Do Right Now, Regardless of Your State

You don’t have to wait on legislation to reduce your exposure. A few practical moves make a real dent:

  1. Check the California Data Broker Registry. The CPPA publishes a public list of registered brokers at cppa.ca.gov, useful even if you don’t live there, since it names companies actually operating in this space.
  2. Opt out of the largest people-search sites individually if you’re not covered by DROP. Sites like Spokeo, BeenVerified, and Whitepages typically publish opt-out instructions, though the process can be tedious and may need repeating.
  3. Freeze your credit so brokers and identity thieves can’t use financial header data to open new accounts in your name. A credit freeze is free by federal law and separate from opting out of marketing data sales.
  4. Limit app permissions that share your location or contacts, a major ongoing feed for broker profiles.
  5. Be skeptical of unsolicited calls that seem to “know” you. Specific details aren’t proof of legitimacy; they’re often proof someone bought a data profile.

None of this makes you invisible. The goal is more modest: fewer active listings, a smaller attack surface for scammers, and less fuel for the kind of predatory marketing aimed at people already under financial stress.

A Quick Note on What This Isn’t

This article is informational and doesn’t constitute legal, financial, or credit advice. Data broker laws vary by state and continue to change, so figures and requirements described here may shift after publication. If you’re dealing with a specific fraud situation or need help understanding your rights under state law, consider consulting your state attorney general’s consumer protection office or a qualified attorney.

Frequently Asked Questions

What exactly does a data broker do?

A data broker collects personal information from public records, commercial transactions, and online activity, then compiles and sells that information to other businesses, including advertisers, insurers, and background-check companies. Most brokers have no direct relationship with the people in their databases.

How do I remove my information from data brokers?

If you live in California, the CPPA’s DROP platform lets you submit one deletion request that covers every registered broker, with processing required by August 1, 2026. Outside California, you generally need to submit opt-out requests to individual brokers, a process that can take time and may need to be repeated as new brokers appear.

Who are the main data brokers?

Well-known names include Acxiom, LexisNexis Risk Solutions, CoreLogic, and Epsilon, along with consumer-facing people-search sites like Spokeo and BeenVerified. California’s public data broker registry lists companies that have registered to operate in the state, which offers one way to see who’s active in this space.

Are data brokers legal in the US?

Generally, yes. There’s no single federal law that broadly restricts data broker activity, though the Fair Credit Reporting Act and FTC enforcement actions cover specific practices. Several states, including California, Texas, and Oregon, have passed their own laws giving residents opt-out or deletion rights.

Can data brokers sell information that’s used against me financially?

They can sell profiles that include estimated income, debt levels, and financial stress indicators, and these profiles are legally marketed to lenders and advertisers. This is a key reason financial privacy advocates push for opt-out tools like DROP: the same data used for ordinary marketing can also be used to target people with costly financial products.

Does freezing my credit stop data brokers from selling my information?

Not directly. A credit freeze restricts who can access your credit report to open new accounts, which helps prevent identity theft, but it doesn’t stop data brokers from collecting or selling other types of personal information, like purchase history or app data. The two protections work differently and are worth doing together.