Short answer: yes, in the US, it’s generally legal for data brokers to collect and sell your personal information, as long as it comes from public or otherwise lawfully-obtained sources. That surprises a lot of people who assume this must be illegal. It isn’t, and understanding why helps explain why opt-outs (not lawsuits) are the practical fix.
Where the data actually comes from
Data brokers build profiles from sources like:
- Public records, property records, court records, voter registrations, marriage/divorce filings, professional licenses
- Social media and other public web content
- Purchased or shared data from other brokers and companies
None of this requires your consent under current federal law. The US has no single comprehensive federal data-privacy law governing data brokers the way the EU’s GDPR does.
What’s actually regulated
A few specific situations ARE regulated:
- Credit, employment, tenant screening decisions, covered by the Fair Credit Reporting Act (FCRA). Companies using data for these purposes are “consumer reporting agencies” with stricter obligations. Most people-search sites explicitly say they are NOT consumer reporting agencies and can’t be used for these purposes.
- State-level data broker registries, California, Oregon, Texas, and a growing list of other states require brokers to register and, in some cases, offer opt-out mechanisms.
- State privacy laws, CCPA/CPRA (California), and similar laws in Virginia, Colorado, and other states give residents rights to know what’s collected and to opt out of sale/sharing.
What this means for you
Because collection itself is largely legal, there’s no lawsuit or complaint that makes it stop. The practical path is opting out broker-by-broker, either manually (free, see our
opt-out guides) or through an automated removal service that does it at scale and re-checks periodically, since brokers re-collect data over time.