Skip to content
Privacy & Safety

How data brokers get your email (and how to opt out)

Data brokers rarely get your email from public records. They collect it from signups, loyalty cards, and list sales, then merge it into a profile they sell.

Email Unsubscriber Team 9 min read
Flat vector illustration of a filing cabinet stuffed with address cards, fed by funnels from a loyalty card, a shopping bag, and a web form, beside a pulled OPT OUT lever ejecting one card toward a bin.

You never gave your address to the company now emailing you, and you never signed up for the “people search” site that lists you either. Both got you the same way: a data broker collected your email somewhere along the trail you leave online, then sold it. The question worth answering is where that collection happens, and what you can actually do to stop it.

Data brokers rarely get your email from public records. They collect it from the commercial trail you leave: store signups, loyalty programs, online purchases, sweepstakes forms, rented marketing lists, and breach dumps. Your address then becomes the identifier they use to merge scattered records into one profile they license to other companies.

What is a data broker, and how does it get your email?

A data broker is a company that collects personal information about people from many sources and sells it to other companies, even when the person never dealt with the broker directly. Your email address is one of the fields they collect, and it is one of the most useful, because it stays the same across every service you use it on.

Brokers do not get your address the way most people assume. Public records like voter rolls, property filings, and court documents rarely carry an email address at all. Your email enters the broker economy through commercial channels instead: the forms you fill in, the programs you join, the purchases you make, and the lists that get rented and resold between marketers. A breach adds a second supply line. Either way, the address arrives, and the broker attaches it to everything else it already knows about you.

Where do data brokers actually get your email?

From the everyday moments you hand it over, plus a few you never see. Most of these feel harmless in isolation. The value to a broker comes from combining them.

SourceHow your address gets inHow ordinary it feels
Store and account signupsYou create an account or enter an email for a discountRoutine
Loyalty and rewards programsTerms let the retailer share purchase data with third partiesRoutine
Online purchasesCheckout ties your address to what you boughtRoutine
Sweepstakes and contest formsEntry pages exist mainly to harvest opt-in addressesSometimes obvious
List rental and resaleMarketers rent and swap subscriber lists you are onInvisible
Apps and their partnersAn app SDK passes your address to a data partnerInvisible
Web tracking and hashed-email matchingYour address is matched to your browsing across sitesInvisible
Breach and infostealer dumpsA leaked database puts your address into circulationInvisible

The last row runs on a separate track from the rest. A breached address feeds a criminal resale chain that overlaps with, but is not the same as, the legal broker economy. We follow that route in detail in where your email address goes after a data breach. This post is about the legal side: the licensed brokers who build and sell profiles.

Why is your email address so useful to a broker?

Because it is the thread that ties every scattered record together. On its own, your address is a string of characters. As an identifier, it is stable and unique, which makes it the perfect join key for linking your loyalty purchases, your web-tracking history, and your survey answers into a single dossier keyed to you.

The compiled profiles are enormous. In its 2014 report Data Brokers: A Call for Transparency and Accountability, the US Federal Trade Commission found that one broker held data on 700 million consumers, with more than 3,000 data segments for nearly every US consumer. Another added over 3 billion records to its databases every month. A decade later, the FTC’s 2024 staff report A Look Behind the Screens found major platforms buying data from brokers about both their users and people who never used them at all. Your address does not sit alone in a spreadsheet. It labels a folder that already knows a great deal. There is a price attached to that folder too, which we break down in what your email address is actually worth.

Can you get your email off data-broker lists?

Partly, and it takes steady work rather than one click. You cannot recall copies a broker already sold, and you cannot force the criminal resale chain to forget a breached address. What you can do is send deletion requests, exercise your legal opt-out rights, and stop feeding brokers new signals. Each move shrinks your footprint without erasing the past.

Three levers do most of the work: California’s single-request deletion platform, the opt-out and deletion rights in state privacy laws, and cutting off the supply by handing out fewer real addresses. Take them in order.

How do you opt out with California’s DROP?

If you live in California, one request now reaches every registered broker at once. The state’s Delete Act (SB 362), signed in October 2023, created the Delete Request and Opt-out Platform, known as DROP, run by the California Privacy Protection Agency. It went live for consumers on January 1, 2026.

  1. Open DROP and create an account. Go to the CPPA’s data-broker page and start a request through the platform. You set up a single account to manage it.
  2. Verify your identity once. DROP confirms who you are so brokers can match and delete the right records. You do this a single time, not per broker.
  3. Submit one deletion request. That request reaches every data broker on California’s public registry, more than 600 of them, instead of you filing with each separately.
  4. Wait for the processing window. Registered brokers must begin honoring DROP requests by August 1, 2026, and delete the personal data they hold about you, including your email address and the inferences built from it.

The expected outcome is one action standing in for hundreds of individual opt-outs. DROP is the first platform of its kind in the US, and for now it is a California right. If you live elsewhere, the next section is yours.

What if you don’t live in California?

You opt out broker by broker, and you lean on your own state’s privacy law. It is slower than DROP, but the tools exist. Start with the state data-broker registries, which list brokers and, in many cases, their opt-out pages. Vermont built the first registry in 2019, and California, Texas, and Oregon now run their own. Working through a registry beats guessing which brokers hold your data.

Your state privacy law may give you more direct rights. Roughly 20 US states now have a comprehensive consumer privacy law granting residents the right to access, delete, and opt out of the sale of their personal data, which includes your email address. We cover the 2026 wave in the new privacy laws taking effect this year. You can also switch on Global Privacy Control, a browser signal that tells sites not to sell or share your data, and which a dozen states now legally require businesses to honor.

Do not wait on a federal law to fix this. The Consumer Financial Protection Bureau proposed a rule in December 2024 to treat some data brokers as consumer reporting agencies under the Fair Credit Reporting Act, then withdrew that proposal in May 2025. With no comprehensive federal data-broker law, your strongest rights are the state ones above.

Are data-broker removal services like DeleteMe worth it?

They save you time, but they do not clear everything, and they miss the email side. Services like DeleteMe and Optery automate opt-out requests across many brokers for an annual fee. The convenience is real. The limits are real too.

The case for them: they file and refile opt-outs you would never keep up with by hand, and they cover hundreds of sites. The case against: independent testing found them incomplete. In a study published in August 2024, Consumer Reports found removal services took off only about 35 percent of listings within four months, and information frequently reappeared. Program manager Yael Grauer tested 13 services across 32 volunteers; the top performers were EasyOptOuts and Optery.

There is a second catch specific to your inbox: these services mostly target people-search sites that publish your name, address, and phone number, not the email-list brokers who feed marketing mail. Verdict: worth the fee if you value the time saved and want your public listings thinned, but not a substitute for DROP, your state deletion rights, or unsubscribing. No service removes you fully or forever.

How do you stop feeding brokers your email in the first place?

Cut the supply, because deletion is a treadmill and prevention is not. Every real address you hand out is a new record a broker can collect, match, and resell, so the most durable fix is to give out fewer of them. Two habits do most of the work.

First, stop handing every site your primary address. Masked email aliases give each store a throwaway forwarding address, so the next leak or list sale burns the alias instead of your real inbox, and you learn exactly who leaked it. If you want to pick one, we compare the main alias services side by side. Second, get off the marketing lists you are already on. Every legitimate sender you remove is one less company registering your opens and keeping your address priced as live, resellable inventory.

Doing that across years of accumulated senders by hand is slow, and not every unsubscribe tool deserves the inbox access it asks for. Email Unsubscriber scans your Gmail or Outlook in your own browser, lists every subscription sender, and fires the real one-click opt-out where the sender supports it. The scan runs on your device, and we never read, analyze, or monetize your email content. It is a one-off payment with nothing to cancel. You can run it on your own inbox and clear the backlog in one sitting.

The takeaway

Data brokers get your email from the commercial trail you leave, not from the public record. Store signups, loyalty programs, purchases, sweepstakes, rented lists, and breaches all feed it in, and your address becomes the join key that ties a 3,000-attribute profile to you. You cannot undo what has already sold, but you can act on it. California residents can delete across every registered broker with one DROP request. Everyone else can work the state registries, use state privacy-law rights, and switch on Global Privacy Control. Then cut the supply: hand out fewer real addresses, and unsubscribe from the lists already keeping your inbox full.

Frequently asked questions

How do data brokers get my email address?

Mostly from the commercial trail you leave, not from public records. Your address enters broker databases through store signups, loyalty and rewards programs, online purchases, sweepstakes and contest forms, apps that share data, rented marketing lists, and breach dumps. Brokers then use the address as a stable identifier to link those scattered records into one profile they license to other companies.

Can I remove my email from data broker lists?

Partly. You can send deletion requests, opt out of sale, and stop feeding brokers new data, but you cannot recall copies already sold. California residents can use one request through the DROP platform to reach every registered broker. Elsewhere you opt out broker by broker, use state privacy-law deletion rights, and give out fewer real addresses going forward.

How do I opt out of data brokers in California?

Use DROP, the state's Delete Request and Opt-out Platform, which launched on January 1, 2026. You verify your identity once and submit a single deletion request that reaches every data broker on California's registry, more than 600 of them. Registered brokers must begin processing those requests by August 1, 2026, and delete the personal data they hold, including your email address.

How do I opt out of data brokers if I don't live in California?

You opt out broker by broker, which is slower but works. Start with the state data-broker registries in Vermont, California, Texas, and Oregon to find brokers and their opt-out links. If your state has a comprehensive privacy law, use its deletion and opt-out-of-sale rights. Turning on Global Privacy Control also tells sites not to sell or share your data.

Are data broker removal services like DeleteMe worth it?

They save time but do not clear everything. A Consumer Reports study published in 2024 found removal services took off only about 35 percent of listings within four months, and data often reappeared. They mainly target people-search sites rather than email-list brokers. They can be worth the fee for convenience, but no service removes you fully or permanently.

Does opting out of data brokers stop marketing emails?

Not on its own. Opting out of data brokers slows the pipeline by keeping your address from being passed to new marketers, so fewer fresh lists acquire you. It does not remove you from senders you already hear from. To stop existing marketing email you still unsubscribe from each sender, and under CAN-SPAM the sender has ten business days to stop.

Why is my email address so valuable to data brokers?

Because it is a stable, unique identifier that stays the same across every site you use it on. That makes it the perfect join key for tying loyalty purchases, public records, and web-tracking history into one profile. A confirmed, active address is also resellable inventory. The FTC found one broker holding more than 3,000 data segments for nearly every US consumer.

Is there a federal law that stops data brokers?

Not a comprehensive one. The Consumer Financial Protection Bureau proposed a rule in December 2024 to treat some data brokers as consumer reporting agencies under the Fair Credit Reporting Act, but it withdrew that proposal in May 2025. With no federal data-broker law, your strongest rights come from state privacy laws and state data-broker registries.