Prevent This: Your Life, For Sale
California's DELETE Act goes live August 1, one request and 500+ data brokers are required to wipe your data. Here's how to opt-in, and also prevent your data from being sold elsewhere.
You are for sale. Or to be more precise: your information is for sale. Right now, as you read this, for about the price of a cup of coffee, a stranger can buy a file on you. Your home address. Your phone number. Your age, your income bracket, the names of your relatives, your purchase history.
You never filled out a form for any of it. You never agreed to it. And there are companies whose entire business is compiling that file and selling your information, to advertisers, to “people-search” websites, to debt collectors. To make matters worse, some companies will sell your data to unverified individuals (which could be scammers or stalkers).
These companies are called data brokers, and most people have never heard of them. That is about to change, because on August 1 California flips a switch that lets residents force hundreds of these companies to delete what they hold, all at once. It is the biggest consumer-privacy lever the US has seen in years, and it is worth understanding whether you live in California or not.
The Dossier You Didn’t Know Existed
A data broker is a company that collects, packages, and sells information about people it has no direct relationship with. You are not their customer. You are their product.
They come in three rough flavors. People-search sites (names like Whitepages, Spokeo, and BeenVerified) sell quick dossiers on individuals, home address, phone, age, relatives, sometimes for less than a dollar a record. Marketing brokers (Acxiom, Epsilon, Experian, Oracle) build detailed profiles for advertisers. And risk and identity brokers(LexisNexis Risk Solutions, and the credit bureaus) sell data used for lending, insurance, and background checks.
The scale is hard to picture. There are several thousand data brokers operating in the US. One of the largest, Acxiom, has been reported for over a decade to hold roughly 1,500 data points on each of hundreds of millions of people. The information comes from public records, your loyalty cards and app permissions, your online activity, and from other brokers, all traded and re-traded in a multibillion-dollar industry that runs almost entirely out of your sight.
Why This Isn’t Just Annoying
It would be easy to file this under “creepy but harmless.” It is not harmless. The file on you does real damage, in four ways.
It feeds the scam machine. The Justice Department has prosecuted brokers for selling lists of people profiled as vulnerable, elderly, isolated, in cognitive decline, to fraud rings, then refining them based on who fell for the last scam. Data from one broker, Epsilon, helped criminals target roughly 30 million people. Last year another was sentenced to ten years for selling information on seven million older Americans to a lottery-scam ring. When a scammer seems to “know” things about you, this is often where they learned them.
It puts people in physical danger. People-search sites publish home addresses, and to a stalker or an abusive ex, an address is the whole game. In a 1999 case that helped define the problem, Amy Boyer was murdered by a stalker who bought her details from a data broker. Domestic-violence advocates now treat brokers as a real safety threat, with a hard caveat: for someone being hunted, removing your data can tip the abuser off, so survivors should get help from a specialist first.
And it leaks. These are giant, aggregated troves, which makes brokers prime hacking targets. In 2024 a single broker, National Public Data, spilled billions of records including Social Security numbers, information most victims never knew the company held. Even a broker that plays by the rules is one breach away from handing your file to criminals for free. The less of you sitting in these piles, the less there is to lose.
For the pros: brokers turn attacker reconnaissance into a vending machine. The digging that once took hours is now a purchase, the who-reports-to-whom, the cell numbers, the home addresses behind spear-phishing and business email compromise. Federal advisories on today’s top social-engineering crews name commercial data aggregators among their inputs. Trimming your broker footprint shrinks your company’s attack surface.
California Just Changed the Game
Until recently, getting your data removed meant hunting down each broker one at a time and filling out a different opt-out form for each, hundreds of them, over and over, because they quietly re-add you. It was designed to be exhausting.
California’s DELETE Act attacks that directly. The state built a free tool called DROP(the Delete Request and Opt-out Platform), run by the California Privacy Protection Agency. Here is what makes it different: you submit one deletion request, and it reaches every data broker registered in the state, more than 500 of them, at once. You can read more or start the process at: https://privacy.ca.gov/drop/
The timeline is the news. California residents have been able to submit requests since January 1, 2026. The switch that matters flips on August 1, 2026, when those registered brokers are legally required to start honoring the deletions and to keep checking the platform at least every 45 days going forward. It is free, it is repeatable, and brokers that ignore it face penalties of 200 dollars per request, per day.
For now this is for California residents only, though other states are building similar registries. Unfortunately, DROP only covers registered data brokers, not everyone who holds your data. It does not cover the credit bureaus (which sell broker-style data but are regulated separately, under the FCRA), banks, healthcare providers, or the companies you actually do business with. So it is a large, powerful broom, not a magic eraser.
The Numbers
500+ data brokers reachable with one free California DROP request
~1,500 data points a major broker has been reported to hold on each person
Under $1 to buy a basic dossier from a people-search site
7 million older Americans whose data one broker sold to a scam ring, earning a 10-year sentence
Every 45 days how often California brokers must re-check the deletion platform
$200 per request, per day the penalty for ignoring a deletion
The Fix: How to Get Yourself Back
You cannot delete yourself from the internet completely. What you can do is make yourself much harder to target, and the payoff is the same at home and at work.
If you live in California: use DROP
Go to the California Privacy Protection Agency’s site (search “California DROP data broker” or visit privacy.ca.gov) and submit a deletion request. It is free, it takes a few minutes, and starting August 1 it obligates 500+ brokers to erase what they hold and to keep honoring it. This is the single most powerful privacy action available to a US consumer right now. Do it.
Everyone else: the manual playbook
1. Use Google’s free “Results about you” tool. Google offers a tool (search “Google Results about you”) that finds pages exposing your home address, phone, or email in its search results and lets you request removal from Google Search. It does not delete the source page, but it makes you far harder to find.
2. Opt out of the biggest people-search sites by hand. Start with the ones a stranger would actually use: Whitepages, Spokeo, BeenVerified, Radaris, and a handful of others. Each has an opt-out page (search “[site name] opt out”). It is tedious, an hour or two, but these are the sites that expose your address.
3. Consider a paid removal service. If you’d like to spend money on the problem, services like DeleteMe, Optery, and Kanary do the opt-out grind for you. (EDITOR’S NOTE: These are yearly subscription apps. You can buy it once and then unsubscribe after a year). They save real time, but independent testing has found they do not catch everything, and they work best as a time-saver, not a guarantee.
4. Repeat. This is the part nobody likes. Brokers re-add you from fresh public records, so a one-time cleanup fades. Redo the important opt-outs about every six months, or let a service handle the cadence.
The Bottom Line
There is a file on you that you never authorized, sold by companies you have never heard of, and it is the same file that powers the scam call to your grandmother and the spear-phishing email to your CFO. That is why data brokers belong in a newsletter for everyone: the problem sits exactly where your home life and your work life overlap.
For years the only defense was an exhausting, broker-by-broker slog that the industry counted on you quitting. That is changing as States recognize the problem. California residents can now clear more than 500 brokers with a single free request, and the rest of us can knock out the sites that matter most in an afternoon and keep them down with a twice-a-year habit.
You will never be fully off the market. But you can take yourself out of the bargain bin, and make the people who profit from selling you work a lot harder. Take the afternoon. Your future self will thank you, and the scammer who never gets through will never know why.
Intruvent EDGE Preview
This Thursday, our companion newsletter, Intruvent Edge, publishes its July threat briefing, the bi-weekly technical deep dive we write for security teams and IT leaders. This edition covers the threat actors that were most active this month, the tactics they are relying on right now, and the countermeasures that actually work against them. If you defend an organization, or the pro notes above were your favorite part, we will see you Thursday! Thanks for reading and please feel free to share this newsletter with others!
Helpful, free starting points:
California residents: the DROP deletion tool at privacy.ca.gov
Everyone: Google “Results about you” to remove personal info from search results
Opt-out lists: search “[Whitepages / Spokeo / BeenVerified] opt out”
Stalking or domestic violence: the National Network to End Domestic Violence Safety Net program, and the hotline at 1-800-799-7233
Report fraud tied to your exposed data: reportfraud.ftc.gov
Sources
California Privacy Protection Agency, DROP and DELETE Act (SB 362) materials, privacy.ca.gov and cppa.ca.gov (2026)
Alston & Bird and National Law Review analyses of the DELETE Act timeline and penalties (July 2026)
US Department of Justice prosecutions of data brokers for facilitating elder fraud (via Lawfare)
Electronic Privacy Information Center (EPIC), “Data Broker Harms: Domestic Violence Survivors” (Amy Boyer case)
Federal Trade Commission enforcement actions against data brokers (X-Mode/Outlogic, InMarket, Kochava), 2024 to 2026
Google, “Results about you” documentation
Consumer Reports testing of data-broker removal services (2024)
Prevent This is a weekly cybersecurity newsletter from Intruvent Technologies. Each week, we break down one cyber threat in plain language and give you the tools to protect yourself and the people you care about. For our bi-weekly technical deep dive, check out Intruvent Edge.





