Published

Data Brokers Are Selling Your Email Address Right Now

There are companies whose entire business model is collecting personal information about you and selling it. They're called data brokers, and most people have never heard of them.

Right now, somewhere between 20 and 200 data broker databases have your email address. Probably your phone number. Likely your home address. Possibly your income estimate, your political affiliation, your purchase history, and your interests.

You didn't consent to this directly. But you handed the raw material to them over years of online activity — and companies you trusted passed it along.

What Data Brokers Actually Collect

Data brokers pull from dozens of sources:

  • Public records — court filings, property records, voter registrations, business registrations
  • Loyalty programs — every supermarket card, retailer rewards program, and gas station app you've ever used
  • App data — location history, app usage, and browsing behavior sold by app developers
  • Social media — public profile information scraped or purchased
  • Transaction data — purchase histories sold by retailers and payment processors
  • Opt-in lists — newsletter sign-ups and survey responses that included data-sharing consent buried in terms of service

The major brokers — Acxiom, Epsilon, Oracle Data Cloud, LexisNexis, Experian — each have profiles on hundreds of millions of people. The total industry is estimated at over $300 billion annually.

Who Buys It

Advertisers: The most common use. Your email address gets added to "custom audiences" on advertising platforms, letting companies target you specifically based on your offline behavior.

Employers: Background check companies buy from data brokers. Pre-employment screening increasingly includes data beyond what you put on your CV.

Insurance companies: Health, auto, and life insurers use third-party data to build risk profiles. Your online purchase history and location data can influence your rates.

Political campaigns: Voter targeting relies heavily on data broker lists. Your political profile, estimated based on consumer behavior, is bought and sold.

Scammers and fraudsters: Not all data broker customers are legitimate businesses. Compiled lists end up in phishing campaigns, social engineering attacks, and SIM swapping attempts.

How Your Email Got There

Most people are surprised to learn how their information ends up in these databases. The main routes:

Newsletter sign-ups: Many free newsletters monetize by selling subscriber lists to "partners." The opt-out is in the footer. The data sharing happens immediately on sign-up.

Online shopping: Retailers sell purchase history and associated contact details. Your email from a one-time order a decade ago may still be circulating.

Contest entries: Free giveaways and sweepstakes are classic data collection mechanisms. The entry form is the product.

App permissions: Mobile apps that request contact access upload those contacts to servers — including emails of people who never consented.

Data breaches: Breached databases are purchased and merged with existing profiles, adding to the picture.

Sign-up reselling: When you sign up for any free service, that company's privacy policy likely allows them to share your information with "affiliates" and "partners." That's data broker language.

What You Can Do About It

For Future Exposure: Stop Feeding the System

The most effective thing you can do going forward is stop giving your real email address to services you don't trust.

tempy.email gives you a disposable email address instantly. Use it for:

  • Newsletter sign-ups you're not sure about
  • Contest entries and giveaways
  • Free trials and one-time downloads
  • Any service where you don't want ongoing contact

A disposable address that expires has no value to a data broker. They can't build a profile from a dead email. This doesn't undo past exposure, but it stops future accumulation.

For services you use regularly but don't fully trust, email aliases (SimpleLogin, addy.io) give you permanent protection with the ability to cut off contact by disabling the alias.

For Past Exposure: Opt-Out Requests

Data brokers are required by law in many jurisdictions to honor opt-out requests. The process is tedious — each broker has a separate opt-out form — but it works.

Major brokers to start with:

  • Spokeo
  • WhitePages
  • BeenVerified
  • Intelius
  • PeopleFinder
  • Acxiom (MyPrivacy portal)
  • LexisNexis (Consumer Center)
  • Epsilon (opt-out form)
  • Oracle Data Cloud (opt-out via NAI)

Expect to spend 3-5 hours working through the major ones. Records reappear over time as new data comes in, so periodic re-submission is needed.

Automated services: Companies like DeleteMe, Kanary, and Privacy Bee automate this process for $10-15/month. They submit removal requests on your behalf and re-submit periodically. If your time is worth more than their cost, these are reasonable.

For Advertisers: Opt Out of Data-Based Targeting

Even if your data is in broker databases, you can reduce how it's used for advertising.

  • NAI Opt-Out Tool (networkadvertising.org/choices) — opts you out of interest-based advertising from NAI member companies
  • Digital Advertising Alliance (optout.aboutads.info) — similar opt-out for DAA members
  • Google Ad Settings — turn off ad personalization in your Google account
  • Facebook Ad Preferences — restrict how Facebook uses data from off-platform activity

These don't delete your data from broker databases, but they reduce the number of companies actively targeting you with it.

The Realistic Picture

Complete removal from data broker databases is not possible. The industry is too large, the data re-accumulates from public records, and some brokers operate in jurisdictions with no opt-out requirements.

What is achievable:

  • Significant reduction in the number of brokers who have accurate, current information
  • Prevention of new data entering the system (via disposable email and aliases)
  • Reduction in how actively that data is used for ad targeting
  • Removal from the most commonly used consumer databases

For most people, that's enough to meaningfully reduce spam, unwanted solicitations, and the background hum of being commercially profiled.

The Exposure You Can Control Right Now

You can't take back the email address you gave to every service from 2010 onwards. But starting from today, you can control every new sign-up.

Before you enter your real email anywhere:

  1. Ask whether this service deserves your real contact information permanently
  2. If the answer isn't clearly yes — open tempy.email instead
  3. If you later decide you want the service, update to your real email then

That one habit, applied consistently, substantially limits what data brokers can add to your profile going forward.

Related reading: How to sign up for anything without being tracked · The privacy stack: temp email, VPN, and password manager · Stop giving your real email to free trials