Every time you browse the internet, shop online, use social media, or sign up for a service, companies collect information about you. This data ranges from basic details like your name and email address to much more detailed information about your behavior, preferences, and location. Understanding what data exists about you is the first step toward managing your digital presence.
Your Free Guide to Managing Your Boss Relationship →
Major technology companies like Google, Facebook, Amazon, and Microsoft collect vast amounts of personal information. Google tracks your search history, YouTube viewing habits, location data from your phone, and information about websites you visit. Facebook collects data about your browsing habits across the internet through tracking pixels on websites, even when you're not logged into Facebook. Amazon stores your purchase history, browsing behavior, and payment information. These companies use this data to create detailed profiles for advertising purposes.
Beyond the major tech companies, data brokers—companies you've likely never heard of—collect and sell your personal information. These businesses gather data from public records, online sources, and purchase information to create profiles that they sell to marketing companies, insurance providers, and other organizations. Popular data brokers include companies like Experian, Equifax, and Acxiom, though hundreds of smaller brokers operate with little public awareness.
Your personal data typically includes several categories. Contact information includes your name, address, phone number, and email address. Financial data includes credit card numbers, bank account information, and purchase history. Behavioral data tracks websites you visit, search queries, videos you watch, and how long you spend on different sites. Health and sensitive information may include medical records, prescriptions, mental health information, and genetic data if you've used ancestry services. Location data shows where you are and where you've been. Device information includes what phones, computers, and tablets you use.
A practical example: A person living in Ohio who searches for "knee pain relief" on Google, visits health websites, and clicks on ads for pain medication creates a digital trail. That search data gets stored by Google. The websites visited may share that information with advertising networks. Data brokers may combine this information with the person's age, income level from public records, and purchase history to create a profile. Insurance companies or pharmaceutical advertisers may then purchase access to this profile to target ads.
Practical Takeaway: Start documenting the accounts you have and the information each company has about you. Make a list of every service you use regularly—email providers, social media platforms, shopping sites, streaming services, banks, and healthcare providers. Note what information you provided when you signed up and what data they may be collecting continuously.
Most major companies and many smaller ones are required by various privacy laws to tell you what personal data they hold about you. This information is sometimes called a "data subject access request" or "personal data request." The process and timeline varies depending on where you live and which company you're asking.
Free Guide to Equipment and Machinery Rental Options →
In the United States, several state laws require companies to disclose personal data upon request. California's Consumer Privacy Act (CCPA), which became effective in 2020, gives California residents the right to request what personal information a business has collected. Similar laws now exist in Virginia, Colorado, Connecticut, Utah, Montana, and other states. The federal Health Insurance Portability and Accountability Act (HIPAA) requires healthcare providers and health plans to provide copies of your medical records. The Fair Credit Reporting Act (FCRA) allows you to request reports from credit reporting agencies free once per year through AnnualCreditReport.com.
In Europe, the General Data Protection Regulation (GDPR) gives residents stronger rights. Any company processing data of European residents must respond to data requests within 30 days. Similar protections exist in other countries including Canada, Australia, and Brazil.
To request your data, you typically need to contact a company's privacy department. Most major tech companies have online forms on their websites labeled "Privacy" or "Data Request." You may need to provide proof of identity. Some companies respond within days; others take weeks or even the maximum allowed time. The company should provide your data in a readable format, often as a PDF or spreadsheet.
Common information companies disclose includes your profile information and settings, all your messages and communications, your location history if tracked, your search history and browsing activity, your contacts and connections, your payment and transaction history, your device information, advertising preferences and targeted segments they've created about you, and any data they received from third parties.
Here's a real example: When a person in California requested their data from a major social media platform, they received a file showing they had been categorized into 2,547 different advertising segments—including categories like "likely to purchase electronics," "interested in fitness," and "high income earner." The data showed their location history from years of using the app and included deleted messages they thought were gone.
Practical Takeaway: Visit the privacy pages of the five companies whose services you use most frequently. Look for a link labeled "Download Your Data," "Privacy," "Data Request," or "Your Information." Submit a request to each company. Keep records of when you submitted requests and what you received back. This gives you a clear picture of what data exists about you.
Data brokers are companies that buy and sell your personal information without your direct involvement. They collect data from many sources—public records, websites, purchase history, and information they buy from other companies—then package it and sell it to advertisers, marketers, and other businesses. Removing your information from these brokers is more complex than requesting deletion from social media because there are hundreds of data brokers operating in the United States alone.
Get Your Free First-Time Homebuyer Realtor Guide →
Some of the largest data brokers include Experian, Equifax, and TransUnion (which also function as credit reporting agencies), Acxiom, Epsilon, and Spokeo. Smaller brokers like Intelius, BeenVerified, and PeopleFinder collect and publish personal information online. Many data brokers operate quietly, collecting information about millions of people without those people ever knowing the brokers exist.
Several approaches can help reduce your presence in data broker databases. First, you can opt out directly. Many data brokers have opt-out pages on their websites where you can request removal. However, the process varies significantly—some brokers make it straightforward, while others bury opt-out options or require proof of identity. Requests must typically be made individually for each broker. The Federal Trade Commission maintains information about major brokers and how to contact them.
Some states have passed laws requiring data brokers to honor opt-out requests. California's CCPA allows residents to opt out of the sale or sharing of personal information, and similar rights exist in other states. However, federal laws don't require data brokers to honor deletion requests in most cases—they only require them to honor opt-out requests, meaning they still hold your data but won't sell it.
A practical approach involves several steps. Start by searching your name on major data broker websites to see what information they have published. Search sites like Spokeo, BeenVerified, and Intelius show what information is publicly available. For each site where you find your information, look for an opt-out or removal option. This is often labeled "Remove Your Information" or "Privacy." Document which sites you've contacted and when. Be aware that opting out from one data broker doesn't remove you from others—you must contact each one separately.
Removing your information from marketing email lists is a separate but related process. The CAN-SPAM Act requires commercial email senders to honor unsubscribe requests. Every commercial email should contain an unsubscribe link, usually at the bottom. Clicking this link should stop emails from that sender, though it may take several days to process. However, unsubscribing from marketing emails doesn't remove your information from the company's database—it just stops that particular type of email.
Practical Takeaway: Search your name on three major data brokers (Spokeo, BeenVerified, and Intelius). Write down what information appears about you. Then visit each broker's privacy or opt-out page and submit removal requests. Keep a spreadsheet tracking which brokers you've contacted, when, and what the status is. This is an ongoing process since new brokers may acquire your data later.
Social media platforms, email services, shopping sites, and other online accounts store extensive personal information. You can often delete or reduce the information these services maintain about you, though
This guide is for general information only and is not medical, financial, legal, or other professional advice. For decisions specific to your situation, consult a qualified professional. See our Editorial Policy.