Is data brokering legal?

By Updated Corrections

By Delist.ai · 6 min read · Last updated March 2026

At a glance

  • Data brokering is largely legal in the United States, where there is no comprehensive federal privacy law
  • Brokers rely on a First Amendment defense: they aggregate publicly available information
  • Specific categories of data are protected: health, children's, credit, and financial records
  • Gray areas exist around misuse of data for screening, discrimination, and enabling harm
  • The FTC and state attorneys general are increasingly bringing enforcement actions
  • State-level regulation is accelerating, with 15+ states now requiring broker registration

Most relevant if this is you: Privacy for legal professionals

The short answer

Yes, data brokering is mostly legal in the US. No federal law prohibits collecting, aggregating, or selling personal information. Spokeo, Whitepages, and Radaris operate lawfully by compiling data from public records, social media, and commercial sources, then selling access.

The legal foundation: if information is already public, such as court records, property filings, voter registrations, or your own social posts, aggregating it into a searchable profile is generally protected. Courts have held there is no privacy interest in information you have already made public, even when it is combined in ways you never anticipated.

But "mostly legal" is doing a lot of work. The exceptions matter, the gray areas are expanding, and the rules are shifting faster than at any point in the industry's history.

Why data brokering is legal

The data broker industry exists in a regulatory vacuum that is partly historical accident and partly constitutional design.

The public records doctrine. American law has long held that government records are public by default, including court filings, property deeds, marriage licenses, voter registrations, and business incorporations. Data brokers digitize and index these records, making searchable what was already accessible to anyone willing to visit a county clerk's office. Arguments to ban that run headfirst into a long tradition of open government.

First Amendment protection. Data brokers frame their work as speech: collecting facts and publishing them. The Supreme Court has held that truthful information, lawfully obtained, receives First Amendment protection. In Sorrell v. IMS Health (2011), the Court struck down a Vermont law restricting the sale of prescriber data, reinforcing that the sale of information is protected expression. Brokers cite this case frequently, and not without basis.

No comprehensive federal privacy law. The European Union has the GDPR. Canada has PIPEDA. Brazil has the LGPD. The United States has nothing comparable. Instead, American privacy law is a patchwork of sector-specific statutes, each covering a narrow category of data. If your information does not fall into one of those protected categories, there is no federal law preventing its sale.

The core legal argument data brokers make is simple: they are not creating new information. They are organizing information that is already available to the public. Whether that argument holds up against the reality of what modern data aggregation enables is one of the defining legal questions of our time.

The legal carve-outs

While no federal law covers data brokering generally, several laws restrict the collection and sale of specific types of personal data. These carve-outs are narrow but carry real consequences when violated.

These laws protect important categories of information. But they leave the vast majority of personal data, including your name, address, phone number, age, relatives, employment history, and property records, entirely unregulated at the federal level.

The gray areas

The most consequential legal battles in data brokering are not about clearly illegal conduct. They are about activity that falls into gray areas where the law has not yet caught up.

Non-FCRA data used for FCRA purposes. A broker can legally sell a background report that includes name, address, and criminal history, as long as the buyer does not use it for a credit, employment, or housing decision. The distinction is almost impossible to enforce. Landlords, small employers, and individuals routinely buy people-search reports and use them for exactly those purposes. The broker disclaims FCRA in their terms. The buyer ignores it. The subject has no way to prove what happened.

Selling to known bad actors. Brokers are not generally required to vet customers. But when a broker has reason to know a buyer intends to use data for stalking, harassment, or fraud, continuing to sell creates liability under state tort law and, in some cases, federal anti-stalking statutes. The FTC has argued in multiple enforcement actions that brokers who fail to screen out obviously harmful use cases are engaging in unfair business practices.

Data that enables discrimination. Selling profiles tagged with race, ethnicity, religion, or national origin, often inferred from name, address, or purchasing behavior, creates infrastructure for discriminatory targeting. The sale may be legal; using the data to discriminate in housing, employment, or credit is not. Whether a broker bears responsibility for foreseeable misuse remains unsettled.

State registration requirements are another emerging gray area. At least 15 states now require data brokers to register with a state authority and disclose their practices. California, Vermont, Texas, and Oregon have the most established registries. Brokers who fail to register can face fines of $100 to $10,000 per day. Many smaller brokers either do not know about these requirements or choose to ignore them.

See where your information is exposed. Delist scans for your exposure and shows exactly where your personal information appears.

Check your exposure free →

Active litigation and enforcement

Enforcement has shifted dramatically since 2023. Regulators who spent years studying the data broker industry are now bringing cases.

FTC enforcement. The FTC has brought actions against several brokers under its authority over unfair and deceptive practices. In 2024, the agency took action against X-Mode Social (now Outlogic) for selling precise location data that could be used to track visits to medical facilities and places of worship. It has also targeted people-search sites marketed as FCRA-compliant without meeting the statute's accuracy and dispute requirements.

State attorney general actions. Texas filed a landmark suit against Allstate's data subsidiary Arity in 2024, alleging the company collected driving data from 45 million Americans through mobile apps without adequate consent. California's AG has pursued CCPA enforcement, which gives residents the right to opt out of data sales. Oregon, Connecticut, and New Jersey have opened investigations against brokers operating without required state registrations.

Class action lawsuits. Private litigation has grown, though outcomes are mixed. Cases typically allege FCRA violations (for brokers functioning as de facto consumer reporting agencies), state consumer protection violations, or state biometric privacy violations. Illinois's BIPA has produced the largest settlements, though most data brokers do not collect biometric data directly.

The pattern in enforcement is the same: regulators or plaintiffs argue a broker's actual business practices are more harmful than its disclaimers suggest. Claims that they are not consumer reporting agencies, that data is "for informational purposes only," or that buyers are responsible for compliance: these disclaimers are increasingly being tested against what actually happens when the data is sold.

The constitutional tension

At the heart of the data brokering debate is a tension that American law has not resolved: your privacy interest versus the First Amendment's protection of information.

Individual public records are largely harmless alone. Your property deed sits at the county office. Your voter registration is public. Your court filing is accessible. Each fact standing alone presents minimal risk. The aggregation problem starts when one company combines hundreds of these points into a profile that reveals your daily patterns, finances, relationships, and location.

This is the "mosaic theory" of privacy: individually innocuous data points become surveillance-grade information when combined. The Supreme Court touched on this in Carpenter v. United States (2018), holding that long-term cell-phone location tracking constitutes a Fourth Amendment search, even though individual location points are not protected. But Carpenter applied to government surveillance, not commercial data.

Courts have not extended this reasoning to data brokers. Does the First Amendment protect compiling and selling a dossier on any American citizen, assembled from hundreds of public and commercial sources, available to anyone for a few dollars? The constitutional answer is genuinely uncertain. Lower courts have split, and the Supreme Court has not addressed it directly.

The aggregation problem in practice: your home address in a county filing is public. Your phone number in a business directory is public. Your employer on LinkedIn is public. But a single page that shows all three, alongside your relatives' names and your estimated income, creates something qualitatively different from any of its inputs. The law has not yet decided what to do about that difference.

Where the law is heading

The regulatory trajectory is clear, even if the timeline is not. Data brokering is becoming more regulated at every level of government.

State momentum. The most significant action is at the state level. California's CCPA, as amended, gives residents rights to know, delete, correct, limit certain uses, and opt out of sale or sharing. Other states use different thresholds, exemptions, enforcement models, and effective dates; a comprehensive privacy law does not automatically mean the state also has a data-broker registry. See our 50-state privacy law index for the current breakdown.

No comprehensive federal baseline. Congress has considered national consumer-privacy proposals, but a proposal does not create enforceable rights. Federal protections remain sector-specific, including the FCRA for consumer reports used for defined eligibility purposes. Check the current statute and your state's law before relying on a deletion or opt-out right.

The EU comparison. Under GDPR, brokers must have a lawful basis for processing personal data, typically consent or a legitimate interest that does not override the individual's rights. In practice, most US people-search business models would be illegal in Europe. EU regulators have fined data companies hundreds of millions of euros. The American model of "collect everything, let consumers opt out" is the inverse of Europe's "collect nothing unless justified." The gap is narrowing, but slowly.

The practical reality for Americans today: data brokering is legal, your information is being sold, and your primary recourse is to remove yourself from each broker individually. The law may eventually catch up. Until it does, the burden falls on you.

Frequently asked questions

Can I sue a data broker for publishing my information?

In most cases, no, not successfully. If the information is accurate and derived from public sources, publishing it is generally protected. However, you may have legal claims if the broker publishes materially inaccurate information that causes you harm (defamation), if the broker functions as a consumer reporting agency under FCRA and fails to meet accuracy or dispute requirements, or if your state has a privacy law that grants a private right of action. Consult an attorney familiar with privacy law in your state.

Is it illegal to buy someone's personal data from a broker?

Buying the data is generally legal. How you use it determines legality. Using a people-search report to make a credit, employment, or housing decision without FCRA compliance is illegal. Using purchased data to stalk, harass, or defraud someone is illegal regardless of how the data was obtained. The purchase itself, for personal or informational purposes, is lawful in most jurisdictions.

Do data brokers have to honor my removal request?

It depends on where you live. In California, brokers must honor removal requests under the CCPA/CPRA. Several other states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, and Texas, provide similar opt-out rights. In states without privacy legislation, brokers honor opt-outs voluntarily, often as a matter of stated policy rather than legal obligation. Most major brokers do process removal requests, though the process can be slow and data often reappears from other sources.

What is the difference between a data broker and a consumer reporting agency?

A consumer reporting agency (CRA) under the FCRA compiles information specifically for use in credit, employment, tenant screening, or insurance decisions. CRAs must follow strict rules about accuracy, consumer disputes, and permissible use. A data broker that sells "people search" reports for general informational purposes is not technically a CRA, but if buyers routinely use those reports for screening decisions, the broker may be functioning as one regardless of what its terms of service say. This is one of the most actively litigated questions in the industry.

Will a federal privacy law eventually ban data brokering?

A complete ban is unlikely given First Amendment constraints. More realistic outcomes include mandatory broker registration at the federal level, a universal opt-out mechanism, data minimization requirements (limiting collection to what is necessary for a stated purpose), and stronger enforcement against misuse. Any federal law will likely resemble the current state-level approach, regulating how data is collected, disclosed, and used rather than prohibiting the practice outright.

Sources

Sources accessed . See our source standards.

Find out what brokers have on you

Run a free scan to see which data brokers are publishing your personal information.

Run a free scan →