Skip to content
Privacy & Safety

How data brokers get your email (and how to opt out)

Data brokers rarely get your email from public records. They collect it from signups, loyalty cards, and list sales, then merge it into a profile they sell.

Email Unsubscriber Team 11 min read

Updated

Flat vector illustration of a filing cabinet stuffed with address cards, fed by funnels from a loyalty card, a shopping bag, and a web form, beside a pulled OPT OUT lever ejecting one card toward a bin.

You never gave your address to the company now emailing you, and you never signed up for the “people search” site that lists you either. Both got you the same way: a data broker collected your email somewhere along the trail you leave online, then sold it. The question worth answering is where that collection happens, and what you can actually do to stop it.

Data brokers rarely get your email from public records. They collect it from the commercial trail you leave: store signups, loyalty programs, online purchases, sweepstakes forms, rented marketing lists, and breach dumps. Your address then becomes the identifier they use to merge scattered records into one profile they license to other companies.

What is a data broker, and how does it get your email?

A data broker is a company that collects personal information about people from many sources and sells it to other companies, even when the person never dealt with the broker directly. Your email address is one of the fields they collect, and it is one of the most useful, because it stays the same across every service you use it on.

Brokers do not get your address the way most people assume. Public records like voter rolls, property filings, and court documents rarely carry an email address at all. Your email enters the broker economy through commercial channels instead: the forms you fill in, the programs you join, the purchases you make, and the lists that get rented and resold between marketers. A breach adds a second supply line. Either way, the address arrives, and the broker attaches it to everything else it already knows about you.

Where do data brokers actually get your email?

From the everyday moments you hand it over, plus a few you never see. Most of these feel harmless in isolation. The value to a broker comes from combining them.

SourceHow your address gets inHow ordinary it feels
Store and account signupsYou create an account or enter an email for a discountRoutine
Loyalty and rewards programsTerms let the retailer share purchase data with third partiesRoutine
Online purchasesCheckout ties your address to what you boughtRoutine
Sweepstakes and contest formsEntry pages exist mainly to harvest opt-in addressesSometimes obvious
List rental and resaleMarketers rent and swap subscriber lists you are onInvisible
Apps and their partnersAn app SDK passes your address to a data partnerInvisible
Web tracking and hashed-email matchingYour address is matched to your browsing across sitesInvisible
Breach and infostealer dumpsA leaked database puts your address into circulationInvisible

The last row runs on a separate track from the rest. A breached address feeds a criminal resale chain that overlaps with, but is not the same as, the legal broker economy. We follow that route in detail in where your email address goes after a data breach. This post is about the legal side: the licensed brokers who build and sell profiles.

Why is your email address so useful to a broker?

Because it is the thread that ties every scattered record together. On its own, your address is a string of characters. As an identifier, it is stable and unique, which makes it the perfect join key for linking your loyalty purchases, your web-tracking history, and your survey answers into a single dossier keyed to you.

The compiled profiles are enormous. In its May 2014 report Data Brokers: A Call for Transparency and Accountability, the US Federal Trade Commission studied nine brokers, among them Acxiom, CoreLogic, Intelius, and Rapleaf, and found that one held data on 700 million consumers, with more than 3,000 data segments for nearly every US consumer. Another added over 3 billion records to its databases every month. A decade later, the FTC’s 2024 staff report A Look Behind the Screens found major platforms buying data from brokers about both their users and people who never used them at all. Your address does not sit alone in a spreadsheet. It labels a folder that already knows a great deal. There is a price attached to that folder too, which we break down in what your email address is actually worth.

Can you get your email off data-broker lists?

Partly, and it takes steady work rather than one click. You cannot recall copies a broker already sold, and you cannot force the criminal resale chain to forget a breached address. What you can do is send deletion requests, exercise your legal opt-out rights, and stop feeding brokers new signals. Each move shrinks your footprint without erasing the past.

Three levers do most of the work: California’s single-request deletion platform, the opt-out and deletion rights in state privacy laws, and cutting off the supply by handing out fewer real addresses. Take them in order.

How do you opt out with California’s DROP?

If you live in California, one request now reaches every registered broker at once. The state’s Delete Act, SB 362, was approved by the governor on October 10, 2023 and created the Delete Request and Opt-out Platform, known as DROP, run by the California Privacy Protection Agency. The agency announced on November 13, 2025 that “California consumers will be able to submit delete requests through the DROP starting January 2026,” and the platform opened on schedule.

  1. Open DROP and create an account. Go to the CPPA’s data-broker page and start a request through the platform. You set up a single account to manage it.
  2. Verify your identity once. DROP confirms who you are so brokers can match and delete the right records. You do this a single time, not per broker.
  3. Submit one deletion request. That request reaches every data broker on California’s public registry, hundreds of companies, instead of you filing with each separately.
  4. Wait for the processing window. From August 1, 2026, registered brokers must check DROP “at least every 45 days to retrieve and process consumer deletion requests,” then delete the personal data they hold about you, including your email address and the inferences built from it.

The expected outcome is one action standing in for hundreds of individual opt-outs. DROP is the first platform of its kind in the US, and for now it is a California right.

The registry behind it is not decorative. On January 8, 2026, the CPPA fined Rickenbacher Data LLC, trading as Datamasters, $45,000 for selling Californians’ personal information, including health-condition lists, without registering as a data broker, and fined S&P Global $62,600 over a registration failure it attributed to an administrative error. Brokers that skip the registry get found. If you live outside California, the next section is yours.

What if you don’t live in California?

You opt out broker by broker, and you lean on your own state’s privacy law. It is slower than DROP, but the tools exist. Start with the state data-broker registries, which list brokers and, in many cases, their opt-out pages. Vermont built the first one under its Act 171 of 2018, and California, Texas, and Oregon now run their own. Working through a registry beats guessing which brokers hold your data.

Your state privacy law may give you more direct rights, and California’s is the template most of the others copied. The Attorney General’s CCPA guidance sets out a right to make a business delete the personal information it collected from you, answered within 45 calendar days and extendable to 90, plus a right to tell it to stop selling or sharing that information, which it must act on within 15 business days. Most states with a comprehensive consumer privacy law grant the same trio: access, deletion, and opt-out of sale. We cover the 2026 wave in the new privacy laws taking effect this year. You can also switch on Global Privacy Control, a browser signal the California Attorney General says must be honored by covered businesses “as a valid consumer request to stop the sale or sharing of personal information.”

Outside the US, the GDPR hands you two levers a broker cannot argue its way past. Article 14 covers exactly the situation you are in, where a company got your data from somewhere other than you: it must tell you, within one month at the latest, “from which source the personal data originate, and if applicable, whether it came from publicly accessible sources.” Ask a broker that in writing and it owes you an answer. Article 21(2) is blunter. You have “the right to object at any time” to processing for direct marketing, “which includes profiling to the extent that it is related to such direct marketing,” and once you object, “the personal data shall no longer be processed for such purposes.” There is no balancing test to lose. This is general information rather than legal advice, but those two article numbers are the ones to put in the email you send.

Do not wait on a federal law to fix this. The Consumer Financial Protection Bureau proposed a rule in December 2024 to treat some data brokers as consumer reporting agencies under the Fair Credit Reporting Act, then withdrew that proposal in May 2025. With no comprehensive federal data-broker law, your strongest rights are the state ones above.

Are data-broker removal services like DeleteMe worth it?

They save you time, but they do not clear everything, and they miss the email side. Services like DeleteMe and Optery automate opt-out requests across many brokers for an annual fee. The convenience is real. The limits are real too.

The case for them: they file and refile opt-outs you would never keep up with by hand, and they cover hundreds of sites. The case against: independent testing found them incomplete. In Data Defense: Evaluating People-Search Site Removal Services, published on August 8, 2024, Consumer Reports and Tall Poppy signed 32 volunteers up for seven removal services and tracked their listings across 13 of the largest people-search sites. Only about 35 percent of the listings came off within four months, and information frequently reappeared. Optery and EasyOptOuts led the field at roughly 68 and 65 percent; the worst performers cleared 4 and 6 percent.

There is a second catch specific to your inbox: these services mostly target people-search sites that publish your name, address, and phone number, not the email-list brokers who feed marketing mail. Verdict: worth the fee if you value the time saved and want your public listings thinned, but not a substitute for DROP, your state deletion rights, or unsubscribing. No service removes you fully or forever.

How do you stop feeding brokers your email in the first place?

Cut the supply, because deletion is a treadmill and prevention is not. Every real address you hand out is a new record a broker can collect, match, and resell, so the most durable fix is to give out fewer of them. Two habits do most of the work.

First, stop handing every site your primary address. Masked email aliases give each store a throwaway forwarding address, so the next leak or list sale burns the alias instead of your real inbox, and you learn exactly who leaked it. If you want to pick one, we compare the main alias services side by side. Second, get off the marketing lists you are already on. Every legitimate sender you remove is one less company registering your opens and keeping your address priced as live, resellable inventory.

Doing that across years of accumulated senders by hand is slow, and not every unsubscribe tool deserves the inbox access it asks for. Email Unsubscriber scans your Gmail or Outlook in your own browser, lists every subscription sender, and fires the real one-click opt-out where the sender supports it. The scan runs on your device, and we never read, analyze, or monetize your email content. It is a one-off payment with nothing to cancel. You can run it on your own inbox and clear the backlog in one sitting.

The takeaway

Data brokers get your email from the commercial trail you leave, not from the public record. Store signups, loyalty programs, purchases, sweepstakes, rented lists, and breaches all feed it in, and your address becomes the join key that ties a 3,000-attribute profile to you. You cannot undo what has already sold, but you can act on it. California residents can delete across every registered broker with one DROP request. Everyone else can work the state registries, use state privacy-law rights, and switch on Global Privacy Control. Then cut the supply: hand out fewer real addresses, and unsubscribe from the lists already keeping your inbox full.

Frequently asked questions

How do data brokers get my email address?

Mostly from the commercial trail you leave, not from public records. Your address enters broker databases through store signups, loyalty and rewards programs, online purchases, sweepstakes and contest forms, apps that share data, rented marketing lists, and breach dumps. Brokers then use the address as a stable identifier to link those scattered records into one profile they license to other companies.

Can I remove my email from data broker lists?

Partly. You can send deletion requests, opt out of sale, and stop feeding brokers new data, but you cannot recall copies already sold. California residents can use one request through the DROP platform to reach every registered broker. Elsewhere you opt out broker by broker, use state privacy-law deletion rights, and give out fewer real addresses going forward.

How do I opt out of data brokers in California?

Use DROP, the state's Delete Request and Opt-out Platform, which opened to consumers in January 2026. You verify your identity once and submit a single deletion request that reaches every data broker on California's registry, hundreds of companies. From August 1, 2026, registered brokers must check DROP at least every 45 days and delete the personal data they hold, including your email address.

How do I opt out of data brokers if I don't live in California?

You opt out broker by broker, which is slower but works. Start with the state data-broker registries in Vermont, California, Texas, and Oregon to find brokers and their opt-out links. If your state has a comprehensive privacy law, use its deletion and opt-out-of-sale rights. Turning on Global Privacy Control also tells sites not to sell or share your data.

Are data broker removal services like DeleteMe worth it?

They save time but do not clear everything. Consumer Reports published a study on August 8, 2024 that signed 32 volunteers up for seven removal services and found only about 35 percent of listings came off within four months, with data often reappearing. They mainly target people-search sites rather than email-list brokers. Worth the fee for convenience, but no service removes you fully or permanently.

What rights do I have against data brokers under GDPR?

Two articles do most of the work. Article 14 says a company that obtained your data from someone other than you must tell you, within one month at the latest, which source it came from. Article 21(2) gives you the right to object at any time to processing for direct marketing, including related profiling, and once you object the data must no longer be processed for that purpose.

Does opting out of data brokers stop marketing emails?

Not on its own. Opting out of data brokers slows the pipeline by keeping your address from being passed to new marketers, so fewer fresh lists acquire you. It does not remove you from senders you already hear from. To stop existing marketing email you still unsubscribe from each sender, and under CAN-SPAM the sender has ten business days to stop.

Why is my email address so valuable to data brokers?

Because it is a stable, unique identifier that stays the same across every site you use it on. That makes it the perfect join key for tying loyalty purchases, public records, and web-tracking history into one profile. A confirmed, active address is also resellable inventory. The FTC found one broker holding more than 3,000 data segments for nearly every US consumer.

Is there a federal law that stops data brokers?

Not a comprehensive one. The Consumer Financial Protection Bureau proposed a rule in December 2024 to treat some data brokers as consumer reporting agencies under the Fair Credit Reporting Act, but it withdrew that proposal in May 2025. With no federal data-broker law, your strongest rights come from state privacy laws and state data-broker registries.