This article is for informational purposes only and does not constitute legal advice. If you believe a data broker has violated your rights, consult a qualified attorney in your state.
The Short Answer: It Depends
Finding your name, address, phone number, and family members listed on a people-search site feels like a violation. But can you actually sue over it? The honest answer is that it depends on the specific circumstances. Merely publishing information that was legally obtained from public records is generally protected activity in the United States. However, there are several important situations where data brokers do cross legal lines, and those situations can give you real grounds for a lawsuit.
When You Likely Cannot Sue
Data brokers typically collect information from public sources: voter registrations, property records, court filings, social media profiles, and commercially available databases. When a site like Spokeo, BeenVerified, or WhitePages aggregates this publicly available data and displays it, that activity is generally legal. Courts have consistently held that compiling and republishing public records does not, on its own, create liability. There is no broad federal privacy law in the U.S. that prevents companies from collecting and selling this type of information.
When You May Have Legal Grounds
FCRA Violations: Background Reports Used for Decisions About You
The Fair Credit Reporting Act (FCRA) is one of the strongest tools consumers have against data brokers. Under the FCRA, any company that sells reports used to make decisions about employment, housing, credit, or insurance qualifies as a “consumer reporting agency” and must follow strict rules: ensuring accuracy, screening who buys the data, and giving consumers the ability to dispute errors.
When data brokers ignore these requirements, they face serious consequences. In 2023, the FTC fined Instant Checkmate and TruthFinder a combined $5.8 million for selling background reports used in rental and employment screening without following FCRA requirements.[1] These companies were marketing their reports in ways that invited FCRA-covered uses but failed to verify that buyers had a permissible purpose or to maintain reasonable accuracy standards.
If a data broker sold a report about you that was used in a credit, employment, tenant, or insurance decision, and the report contained errors or the broker failed to follow FCRA procedures, you may have grounds for a private lawsuit. The FCRA allows individual consumers to sue, and courts have awarded significant damages in these cases.
False or Inaccurate Information: Defamation Claims
If a data broker publishes materially false information about you, and that false information causes real harm, you may have a defamation claim. For example, if a people-search site incorrectly associates you with a criminal record that belongs to someone else, and this causes you to lose a job opportunity or suffer reputational damage, that could form the basis of a lawsuit. The key requirements are that the information must be provably false, it must have been published to third parties, and you must be able to show actual harm resulted from it.
State Privacy Laws with a Private Right of Action
Several states have enacted laws that give individuals the right to sue data brokers directly. One of the most notable is New Jersey’s Daniel’s Law, which protects judges, law enforcement officers, and their families by requiring data brokers to stop disclosing that information within 10 business days of a takedown request.[2] The law provides for $1,000 in damages per violation plus attorneys’ fees, and more than 140 lawsuits have been filed under it.[3] A bipartisan group of 42 state attorneys general filed a brief supporting the constitutionality of this law when it was challenged.[4]
Other states are following New Jersey’s lead with similar protections for public officials and, in some cases, broader populations. The legal landscape here is changing rapidly. In August 2026 the New Jersey Supreme Court answered a certified question in that challenge, holding unanimously that Daniel’s Law requires no mental state at all for an award of actual damages: a broker that keeps publishing after a valid notice is liable whether or not it meant to. Whether the law survives the First Amendment challenge is still before the Third Circuit.[5]
State Anti-Doxxing and Harassment Laws
A growing number of states have passed anti-doxxing statutes that can apply when someone’s personal information is published with the intent to harass, threaten, or intimidate. If a data broker’s publication of your information is connected to a pattern of harassment or stalking, these laws may provide both criminal penalties and civil remedies. California, for example, lets a doxxing victim recover statutory damages of between $1,500 and $30,000, plus attorney’s fees, without having to itemize out-of-pocket losses.[6]
California: Strong Enforcement, Limited Private Lawsuits
California’s CCPA and Delete Act provide significant protections, but the private right of action under the CCPA is limited to data breach situations. If a data broker ignores your deletion request, you generally cannot sue them yourself under the CCPA.[7] Instead, enforcement falls to the California Privacy Protection Agency (CPPA) and the state Attorney General. The CPPA has been active on this front, fining multiple data brokers for failing to register under the Delete Act and ordering at least one company to stop selling Californians’ personal data entirely.[8][9] Californians also no longer have to chase brokers one at a time. The state’s Delete Request and Opt-out Platform (DROP) launched in January 2026, and data brokers began processing requests through it in August 2026: one free request reaches every broker on the state registry, and brokers are required to process it. If a broker ignores a DROP request or a direct deletion request, filing a complaint with the agency is your next step.[10]
What You Need to Sue Successfully
Across most of these legal theories, courts require you to demonstrate concrete harm. The U.S. Supreme Court has ruled that individuals may sue data brokers over incorrect published information, but plaintiffs must show they suffered, or are likely to suffer, real damage as a result.[11] Vague feelings of unease or general privacy concerns are usually not enough. Concrete harms include losing a job or housing opportunity because of inaccurate data, financial losses tied to identity theft enabled by a broker’s negligence, documented harassment or stalking facilitated by published personal information, and emotional distress supported by medical or therapeutic documentation.
Practical Steps If You Think You Have a Case
- Document everything. Save screenshots of the data broker listing, any inaccurate information, and evidence of harm you have experienced.
- Send a written opt-out or deletion request and keep a copy with the date. If the broker ignores it, that failure becomes part of your evidence.
- Check your state’s specific privacy laws. Protections vary significantly from state to state, and some offer much stronger remedies than others.
- Consult a consumer privacy or FCRA attorney. Many take these cases on contingency, meaning you pay nothing upfront. An attorney can evaluate whether your situation fits under the FCRA, a state law, or a defamation theory.
- File regulatory complaints. Even if you cannot sue directly, complaints to the FTC, your state attorney general, or the CPPA (for California residents) trigger enforcement actions that can result in fines and required changes to the broker’s practices.
The Bottom Line
You generally cannot sue a data broker simply for listing publicly available information about you. But if a broker sold inaccurate reports used in decisions about your employment or housing, published false information that damaged your reputation, ignored legally required deletion requests in states with strong privacy laws, or facilitated harassment through the release of your personal details, you may have a viable legal claim. The law in this area is evolving quickly, with more states passing data broker regulations and courts increasingly willing to hold these companies accountable. If you believe a data broker has crossed the line, talking to an attorney who specializes in privacy or consumer protection law is the best next step.
Sources
- Federal Trade Commission. FTC Says TruthFinder, Instant Checkmate Deceived Users About Background Report Accuracy, Violated FCRA While Marketing Reports for Employee and Tenant Screening. Press release, September 11, 2023. ftc.gov
- Atlas Data Privacy Corp. v. We Inform, LLC (A-8-25), Supreme Court of New Jersey, decided August 12, 2026. Opinion reciting the text of N.J.S.A. 56:8-166.1, including the 10-business-day compliance window and the $1,000 liquidated-damages rate. njcourts.gov
- In Re: Daniel’s Law Compliance Litigations, application for Multi-County Litigation designation, November 3, 2025. Reports 111 cases then pending in the New Jersey Superior Court plus 52 further cases removed to federal court. njcourts.gov
- Kelley Drye, Ad Law Access. Multistate Coalition Files Amicus Brief in Support of Anti-Doxing Law, May 23, 2025. Reports the bipartisan 42-attorney-general amicus brief to the Third Circuit. kelleydrye.com
- New Jersey Courts. A-8-25: Atlas Data Privacy Corp. v. We Inform, LLC, case record and filings. njcourts.gov
- California Civil Code § 1708.89 (Doxing Victims Recourse Act, A.B. 1979, 2024), subd. (c)(2): statutory damages of not less than $1,500 and not more than $30,000. leginfo.legislature.ca.gov
- California Office of the Attorney General. California Consumer Privacy Act (CCPA). FAQ: “You cannot sue businesses for most CCPA violations. You can only sue a business under the CCPA if there is a data breach.” oag.ca.gov
- California Privacy Protection Agency. CPPA Settles With First Set of Data Brokers, November 14, 2024. Fines for failure to register under the Delete Act. cppa.ca.gov
- California Privacy Protection Agency. Data Broker Promoting Ability to Dig Up ‘Scary’ Amounts of Information Agrees to Shut Down, February 27, 2025. cppa.ca.gov
- CalPrivacy (California Privacy Protection Agency). Delete Request and Opt-out Platform (DROP). Launched January 2026; data brokers began processing requests in August 2026; one free request reaches every registered data broker. privacy.ca.gov
- Spokeo, Inc. v. Robins, 578 U.S. 330 (2016). A plaintiff suing a people-search data broker under the FCRA must allege a concrete injury, not a bare procedural violation. Legal Information Institute, Cornell Law School. law.cornell.edu