Right now, without your consent and mostly without your knowledge, hundreds of companies are packaging up your name, home address, phone number, email, date of birth, relatives, and a great deal more, and selling it. They are called data brokers, and most people have never heard of a single one of them.
The scale is not a guess. California maintains a public registry of data brokers, and it lists nearly 600 of them. Of those, more than 110 sell people’s precise location. More than 40 sell identity data that can include Social Security numbers. Dozens sell information on gender identity, reproductive health, and union membership. This is the raw material behind the spam calls, the eerily specific ads, the doxxing, the stalking, and, as we have written about before, the warrantless surveillance where agencies simply buy the data they would otherwise need a warrant for.
The good news is that clawing your information back is more possible in 2026 than it has ever been, and for one group of people it just got dramatically easier. Here is how to do it.
If you live in California: use DROP, and you are mostly done
For years, opting out meant contacting each broker individually, one tedious form at a time, across a hundred-plus companies. California just replaced that grind with a single button.
Under the California Delete Act, the state’s privacy agency built the Delete Request and Opt-out Platform, or DROP. You submit one verified request, and every data broker registered in California, all roughly 600 of them, is legally required to find your information and delete it. Not only that: since the processing deadline passed in August 2026, brokers must check DROP at least every 45 days and keep deleting you, which finally addresses the oldest problem in this fight, that brokers just re-add you a few months later. It is free, it is run by the state rather than a company, and more than 300,000 Californians had already signed up within months of launch.
To use it, go to the official state platform at privacy.ca.gov/data-brokers, verify your California residency through the state’s identity gateway, and submit your identifying details. The platform immediately hashes that information, a one-way cryptographic scramble, so brokers match against it without the state handing your data around in the clear. Then you wait. Registered brokers are now on the hook, with fines of $200 per request per day for ignoring it.
That single request does what used to take a weekend of form-filling and then had to be repeated forever. If you are a California resident, this is the highest-leverage thirty minutes you can spend on your privacy this year.
If you live anywhere else: the manual method still works
DROP is California-only, for now, and it is likely a preview of where other states head. Until they do, the manual route is still entirely doable. It just takes more elbow grease.
Use your state’s privacy law. Roughly twenty states now have California-style privacy laws that give you the right to demand deletion and to opt out of the sale of your data. If you are in one, you can send deletion and “do not sell” requests to brokers directly and they generally must comply. Even if your state has no such law, many brokers extend the option nationwide rather than build two systems.
Hit the biggest offenders first. You do not have to do all 600 to get most of the benefit, because a handful of large people-search sites are what actually surface when someone Googles you. Prioritize the public-facing ones, names like Whitepages, Spokeo, BeenVerified, Intelius, Radaris, PeopleFinders, and MyLife, then the big wholesale aggregators behind the scenes like Acxiom, LexisNexis, Oracle, and Epsilon. Each has an opt-out or privacy-request process; you find your listing, submit the removal, and confirm it.
Use a maintained list for the live links, not a static one. Here is where we will be honest instead of padding this post with 147 links that will be broken within a year. Opt-out URLs and procedures change constantly, so the useful move is to work from a list somebody keeps current. California’s own data broker registry is a goldmine even if you cannot use DROP, because it names every registered broker and the categories of data they hold. Community-maintained resources like the well-known “Big Ass Data Broker Opt-Out List,” along with guides from the EFF and Consumer Reports, keep working links and step-by-steps updated as the brokers move things around. Start there and you will always have accurate instructions rather than a snapshot that rotted.
The catch nobody mentions: it is whack-a-mole
Whether you use DROP or do it by hand, understand the fundamental problem. Data brokers do not collect your information once and stop. They continuously re-scrape it from public records, purchases, apps, and each other. Opt out today and, absent a mechanism forcing them to keep you deleted, many will quietly re-list you within months. This is exactly the gap DROP’s every-45-days requirement was written to close for Californians, and it is why, everywhere else, opting out is a recurring chore rather than a one-time fix.
This is also why paid removal services exist. They will hit 100-plus brokers on your behalf and keep re-submitting on a schedule. They are a legitimate time-saver if you would rather pay than spend the hours, with two honest caveats: it is an ongoing subscription because the problem is ongoing, and no service catches every broker. Useful, not magic.
Cleanup is only half the job
Here is the part that ties all of this back to how we think about privacy. Everything above is cleanup. It removes the data that is already out there. It does nothing to stop new data from being generated and sold tomorrow.
And the single largest generator of that data, for most people, is the phone in their pocket. The advertising ID that ties your app activity together, the location constantly leaking to a dozen SDKs, the Google and Apple accounts vacuuming up your life, the apps quietly selling what they see, these are the faucet that keeps refilling the bucket you just spent a weekend bailing out. You can opt out of 600 brokers and still hand them a fresh copy of your life by Friday if the device itself is a data pump.
That is the case for a hardened, de-Googled phone, and for the whole approach we have written about across this series: no advertising ID to correlate you, no Google Services siphoning data to the ecosystem, a minimal app loadout with little to leak, and no accounts demanding your identity. Opting out mops the floor. A private phone turns off the faucet. You want both, and the order matters less than doing them together, because either one alone is a losing battle.
So: if you are in California, go use DROP this week, it is the best deal in privacy right now. If you are anywhere else, work the manual method from a maintained list and consider a removal service for the upkeep. And once the existing mess is cleaned up, stop feeding the machine.
If you want a device built so it stops generating the data in the first place, that is what we do. Email hello@spicycorp.com, or book a call.
SovereignOS is a hardened, de-Googled phone, set up the way we would build one we had to rely on ourselves. One-time price, no subscription, no account required.
See SovereignOSRecent Posts
- Your Phone, Laptop, and TV Are One Profile. Here’s How They Got Linked.
- Your Advertising ID Is a Tracking Number. Here’s How to Actually Kill It.
- Surveillance Capitalism in Plain English (You’re Not the Product, Your Future Is)
- Does iPhone Lockdown Mode Actually Work? (Yes, and Here’s Where It Stops.)
- Your Data Just Leaked. Here’s the First 48 Hours.
Recent Comments
Post Widget
Why Your VPN Isn’t Hiding Your IMEI
Should You Trust Signal?
Social Media Widget
Customer service
Real people, ready to help. Reach our team anytime at hello@spicycorp.com.
Fast Free Shipping
Get free shipping on orders of $150 or more (within the US)
Returns & Exchanges
We offer free returns and exchanges within 30 days of purchase.