Search your own name right now. If you have lived at more than one address, had more than one phone number, or been associated with any public records in the last two decades, you will find yourself listed on sites you have never heard of, with information you never provided, displaying details that range from mildly outdated to actively useful to someone trying to defraud you.
This is not a glitch. It is the intended function of an industry that has operated largely out of public view for decades. Data brokers collect, package, and sell personal information as a commercial product. The consumer-facing sites that display your information — the people search sites, the background check aggregators, the reverse phone lookup tools — are the retail layer of a much deeper supply chain. Understanding that supply chain is the prerequisite for understanding why removal is harder than it looks and why most people who try to handle it themselves are only partially solving the problem.
Jurisdiction Note
The data broker ecosystem described in this article, and the removal rights and opt-out processes that apply to it, are specific to the United States. The industry exists in this form because of the United States' comparatively permissive approach to commercial data collection. Residents of the European Union and other jurisdictions with strong data protection frameworks such as GDPR operate under different rules with meaningfully stronger removal rights. If you are based outside the US, some of what follows will apply in modified form, but the legal landscape and your available remedies are substantially different.
The fraud risk is real and underappreciated. Your digital footprint — the web of names, addresses, phone numbers, relatives, and associated identifiers that data brokers compile about you — is the easiest and cheapest entry point for identity theft, social engineering, phishing, and targeted fraud. Most people do not think about this until something has already gone wrong.
What Data Brokers Are and Where the Data Comes From
Data brokers are companies whose primary business is collecting information about individuals and making it available for sale or licensing. The category is broad. It includes companies that sell marketing lists to advertisers, background check services that sell to employers and landlords, people search sites that sell to anyone willing to pay a few dollars, and data aggregators that sell bulk consumer profiles to other businesses. They share a common characteristic: the people whose information is being sold are not the customer. They are the product.
The data itself comes from sources that are individually mundane but collectively comprehensive. Public records are the foundation: voter registrations, property records, court filings, marriage and divorce records, bankruptcy filings, professional license databases, and any other record that a government entity has made publicly accessible. Most people do not realize how much of their personal information is technically public by default in the United States.
On top of public records sits a layer of commercial data: purchase history from loyalty programs and retail transactions, magazine subscription records, catalog mailing lists, warranty registrations, sweepstakes entries, and online account information from companies that sell or license their customer data. Social media profiles, where users have made information publicly visible, are scraped and incorporated. Change-of-address filings with the postal service are a particularly valuable source, since they document exactly when someone moved and where they went.
Data brokers do not need your permission to collect this information. Most of what they hold was either public by law, disclosed by you voluntarily to some other company, or acquired from another data broker. The system is designed to aggregate, not to ask.
The result is a profile that can be surprisingly comprehensive: current and historical addresses, phone numbers both mobile and landline, names of relatives and household members, estimated age and income range, property ownership history, vehicle records, and in many cases a web of associated identifiers that links your various names, addresses, and accounts across time. A data broker profile does not capture everything about a person. But for the purposes of targeting, social engineering, or fraud, it captures enough.
The Supply Chain Behind People Search Sites
Most people who encounter their own information online encounter it on people search sites: Spokeo, WhitePages, BeenVerified, Intelius, Radaris, PeopleFinder, TruthFinder, and dozens of others. These are consumer-facing products, but they are not the source of the data they display. They are purchasing or licensing it from upstream data brokers who have already compiled and packaged it.
This distinction matters enormously for removal. When you submit an opt-out request to Spokeo, you are asking Spokeo to stop displaying your information. You are not affecting the upstream broker that sold Spokeo the data in the first place. That broker will continue to sell updated data to Spokeo, and to every other people search site they supply, on their normal refresh cycle. Even if Spokeo honors your opt-out today, your profile may be recreated the next time they receive a data refresh from their supplier — typically within weeks to months.
The aggregator layer
Below the people search sites and above the raw public record sources sits a layer of data aggregators that most consumers never interact with directly. Companies like LexisNexis, Acxiom, Experian, and TransUnion operate data businesses that supply information to thousands of downstream customers, including people search sites, background check companies, financial institutions, insurance companies, and marketing platforms. Removing your information from a consumer-facing people search site without addressing the aggregator layer is the equivalent of pulling a weed without touching the roots.
Opting out of aggregators is possible in some cases, but the process is substantially more involved than the consumer-facing opt-outs most removal guides describe. Some aggregators have formal opt-out processes. Others require written requests with identity verification. Some have limited opt-out rights tied to specific legal requirements, such as the Drivers Privacy Protection Act or state privacy laws, rather than general consumer preference. And the opt-outs, where they exist, do not necessarily cascade down to the companies the aggregator has already supplied.
The Google Tool That Does Not Solve the Problem
In 2022, Google launched a tool called Results About You, which allows users to request the removal of certain personal information from Google Search results. The tool covers specific categories of personally identifying information: home addresses, phone numbers, email addresses, login credentials, and certain financial and medical records when they appear in search results. Google expanded the tool's scope over time and made it more accessible within Google Search itself.
When it launched, there was genuine concern in the data removal industry that Google was about to give consumers a meaningful, free path to removing their personal information from public view. In practice, the concern was misplaced.
The Results About You tool removes content from Google's search index. It does not remove content from the sites where the information is hosted. It does not contact the data broker or people search site that published the information. It does not notify the upstream aggregator that supplied the data. What it does is instruct Google's crawler to stop displaying that URL in search results, or to de-index a page that contains the specified information.
What the Google Tool Actually Does
Google's Results About You tool removes your information from Google Search. It does not remove it from the source. The site still has the data. Other search engines still index it. Google re-crawls the web constantly, and if the page is still live, the removal may not hold permanently.
The gap this creates is significant. A person who successfully uses the Google tool to remove their address from search results has reduced their visibility on Google, temporarily. Their information is still on the data broker's site, still accessible through Bing, DuckDuckGo, or any other search engine, still being sold to downstream customers, and still available to anyone who knows where to look directly. For someone trying to reduce their exposure to stalking or targeted fraud, Google surface removal is a meaningful step. For someone trying to actually get their information out of the data broker ecosystem, it addresses the symptom while leaving the source entirely intact.
The whack-a-mole dynamic is real and persistent. A data broker site that receives a data refresh from its upstream supplier after you have submitted an opt-out request will often republish your information, sometimes with more current data than the original listing. Google will then re-index the new page. The Results About You tool will flag it again. The process repeats. This is not a flaw in Google's tool specifically. It is the structural reality of trying to remove information from a system that is continuously regenerating it from upstream sources.
Why This Is a Fraud Problem, Not Just a Privacy Problem
Most conversations about data broker exposure focus on the privacy dimension: the discomfort of having personal information publicly visible without consent. The fraud dimension is both more concrete and more consequential.
A comprehensive data broker profile on an individual provides almost everything needed to social engineer that person or their associates. A caller who knows your current address, your previous address, the names of your family members, your phone number history, and your approximate age has enough to impersonate a credible authority figure, to answer security questions, or to construct a pretext convincing enough to get a bank, an employer, or a service provider to take action on your behalf without your knowledge.
- SIM swapping attacks rely on convincing a mobile carrier that the attacker is the account holder. Data broker profiles provide the personal details that make those calls convincing.
- Account takeover fraud often begins with a password reset attempt that requires answering personal questions. Data broker information answers most of those questions.
- Phishing and spear-phishing are significantly more effective when the attacker can reference real personal details — your address, your previous employer, your relatives' names — that signal they are legitimate.
- Elder fraud disproportionately relies on public records and data broker profiles to identify targets and construct credible pretexts.
The connection between data broker exposure and fraud risk is not theoretical. It is the mechanism by which most non-technical identity theft and targeted fraud actually operates. The personal information sitting in data broker profiles is not just embarrassing or inconvenient. It is infrastructure for criminal activity, and most of the people whose information is there have no meaningful awareness that it exists.
What Effective Removal Actually Requires
Genuine reduction of data broker exposure — not just surface-level Google cleanup — requires working through multiple layers of the ecosystem simultaneously and maintaining that effort over time. The opt-out process for the consumer-facing people search sites is the most visible layer, and it is where most DIY guides start and stop. Platforms like Spokeo, WhitePages, BeenVerified, and their peers all have opt-out processes, some straightforward, some deliberately cumbersome, that require submitting requests site by site, often with email verification or identity confirmation steps.
The realistic count of consumer-facing sites that display personal information is in the hundreds. The time required to locate your listings, submit opt-out requests, verify each request, and follow up when listings reappear is substantial. Most people who attempt this on their own either give up before completing it or discover that listings they successfully removed have reappeared within a few months.
Effective removal services operate at scale across the full landscape of sites, not just the most prominent ones, and they run ongoing monitoring to catch and re-submit removals when listings reappear. The value of a removal service is not that it has access to a magic opt-out that individuals do not. The opt-outs are generally the same. The value is in systematically working through the full list of sites, tracking completion, and maintaining the effort on a recurring basis rather than treating removal as a one-time task.
The aggregator layer remains the hardest part. Consumer-facing opt-outs from Spokeo and WhitePages do not affect what LexisNexis or Acxiom has in their commercial databases. Addressing upstream aggregators requires either using the specific opt-out processes those companies offer under applicable law, or in some cases working through legal channels available under state privacy laws to the extent they apply. This is the layer that most removal services, and virtually all DIY guides, underaddress or ignore entirely.
The Bottom Line
Data brokers are not a fringe phenomenon. They are a well-established industry that collects, packages, and sells personal information at commercial scale. The people search sites most consumers encounter are the consumer-facing retail layer of a much deeper supply chain. Google's removal tool addresses search visibility, not the source. Effective removal requires working through multiple layers of the ecosystem on a sustained basis — not submitting a one-time opt-out to the three sites that came up in a Google search. The fraud risk attached to data broker exposure is real, direct, and underappreciated until it materializes.