DeSpy Privacy Academy Lesson 6

August 4, 2026

Your Data

Your data has value. Learn how it’s collected, used, and sold.

Lesson 6 of 6 · Estimated read: 16 minutes · Level: everyone

Five lessons have covered where data comes from: your phone, your car, AI systems, your city, your home. This one is about the economy those streams feed: who buys, who sells, what it’s worth, and what rights you have.

It’s also the capstone, so it ends with a consolidated plan rather than another list of settings.

One correction up front, because it reframes everything that follows: almost nobody is “selling your data” the way people picture it. There’s no marketplace listing your name for $4.99. What actually happens is subtler and harder to opt out of. Companies sell access to you, and they sell decisions about you. The second one is where the real money and the real consequences are.

In this lesson

  1. Where your data comes from
  2. Data brokers and marketplaces
  3. How companies profit from your data
  4. Cookies, pixels, and tracking
  5. Data aggregation and profiling
  6. The sale and sharing of personal data
  7. Your rights under privacy laws
  8. Steps to protect your data

1. Where your data comes from

The basics

Four streams, and most people only think about the first:

Go deeper

There’s a fifth stream that dominates broker files and almost never comes up: public and offline records.

Property deeds and assessments. Voter registration. Court filings, liens, and bankruptcies. Marriage and divorce records. Professional licenses. Business registrations. In many states, motor vehicle records are available to permitted commercial recipients. None of this involved the internet, and all of it is bulk-purchasable.

This is why people-search sites know your address history, your relatives, and your age even if you’ve never had a social media account. The foundation of your broker profile is paperwork you filed with a government.

What most people don’t know

Some of the most sensitive data leakage has come from the websites you’d most expect to be careful, through tracking code the site owner installed voluntarily.

Investigative reporting and federal enforcement have documented tracking pixels on hospital appointment pages, mental health and telehealth services, tax preparation sites, and prescription discount services, all transmitting to advertising platforms information about what condition someone was looking up, what medication they searched, or what they entered into a tax form.

Enforcement followed: a prescription discount service and an online therapy provider both paid penalties for sharing health information with advertising platforms after promising they wouldn’t. A congressional investigation found major tax preparation services had transmitted financial details to advertising platforms.

The mechanism is mundane, which is why it kept happening: a marketing team adds a conversion-tracking snippet to measure ad performance, and the snippet reports the page URL and form fields by default. Nobody decided to leak health data. Nobody stopped it either.

The lesson for you as a reader: be most careful on exactly the sites that feel most legitimate. A hospital portal or a tax site has no special protection, and the sensitivity of what you type there is the entire risk.

Do this today

2. Data brokers and marketplaces

The basics

“Data broker” covers three very different industries:

Most privacy advice focuses on the first. The third matters most.

Go deeper

What most people don’t know

The risk and identity tier holds the most consequential data, and almost no consumer has heard of the companies in it.

These platforms aggregate Social Security numbers, address histories going back decades, relatives and associates, vehicles, licenses, employment, litigation, and property, into a single searchable dossier. Customers include law enforcement, skip tracers, insurers, and investigators. Some of these products are the reason a debt collector can find you at a new address within days.

The structural detail worth understanding: the same corporate parent often sells both a regulated and an unregulated product. When data is used for credit, insurance, employment, or housing decisions, it’s a consumer report and federal fair-credit rules apply, so you get access and dispute rights. Sold for marketing or investigation, the same underlying data faces far fewer constraints. The dividing line is the stated use, not the sensitivity.

Also documented: brokers offering lists organized around genuinely sensitive characteristics: health conditions, mental health status, financial distress, and in academic research, lists of people with dementia. Federal regulators have brought actions in this space, and rulemaking to bring more of it under fair-credit rules has been attempted.

Do this today

3. How companies profit from your data

The basics

Two business models, and conflating them is why people misunderstand the whole industry.

Selling access to you. This is advertising. The platform keeps your data and rents your attention.

Selling decisions about you. This is risk scoring, pricing, and eligibility. Someone pays to know whether to insure you, hire you, rent to you, extend you credit, or trust your transaction.

Go deeper

What most people don’t know

Personalized pricing is real, has been studied by federal regulators, and is largely invisible to the person being priced.

Differential pricing has been documented for over a decade: online retailers showing different prices based on inferred device type or on the distance to a competitor’s store, travel sites steering users toward different options based on their platform.

More recently, U.S. regulators used formal information demands to study the practice across intermediary firms and reported that consumer data, including location, browsing behavior, and inferred characteristics, is used to tailor prices and offers to individuals.

Why this is the most important item in the lesson: you cannot detect it. With advertising, you can at least see the ad. With pricing, you see one number and have no reference point. There’s no notification, no comparison, and no way to know you were charged more than the next person.

Which reframes the profit question. The advertising economy is annoying and visible. The decisions economy, covering pricing, insurance, credit, eligibility, and fraud scores, is consequential and invisible, and it’s where your data does the most to you.

Do this today

4. Cookies, pixels, and tracking

The basics

Cookies are small files a site stores in your browser. First-party cookies (from the site you’re on) keep you logged in. Third-party cookies (from other companies) followed you between sites, and browsers have largely killed them.

Pixels are the ones that matter now. A pixel is a snippet of code a site owner embeds that reports your activity back to an advertising platform: the page you loaded, what you clicked, what you purchased, and often form contents.

Go deeper

What most people don’t know

The death of third-party cookies didn’t reduce tracking. It moved tracking to servers, where none of your browser controls reach.

This is the most important technical shift in the last five years, and it’s still not widely understood.

Previously: your browser loaded a tracker, so blocking it in your browser worked. Now, increasingly: the merchant’s own server sends your purchase and identity data directly to the advertising platform’s server, via what’s called a conversions API or server-side tagging. You gave the merchant your email at checkout. Their server passes it onward. Your browser is never involved.

Consequences, and they’re uncomfortable:

Combined with the hashed-email matching from Lesson 3, this is a durable tracking system that operates entirely outside your device.

What still works: not being identifiable to the merchant in the first place. Aliased emails, guest checkout, and declining loyalty programs address the input to server-side tracking. Browser hardening addresses the older, visible layer. Still worth doing, just no longer sufficient.

Do this today

5. Data aggregation and profiling

The basics

Aggregation stitches your identifiers into one profile (covered in Lesson 3). Profiling is what gets done with it: sorting you into segments: “in-market for a vehicle,” “budget-conscious grocery shopper,” “recently moved,” “likely managing a chronic condition.”

Audience taxonomies run to tens of thousands of segments.

Go deeper

What most people don’t know

Companies avoid collecting protected characteristics and infer them instead, and inference is regulated far more loosely than collection.

Nobody needs to record your race, religion, health status, or sexual orientation. Purchase patterns, location history, app usage, and network of contacts predict all of them with uncomfortable accuracy. The inferred attribute then drives targeting or decisions while the company can accurately state it never collected sensitive data.

This produces proxy discrimination: a model using ZIP code, shopping behavior, and device type as stand-ins for protected characteristics, reaching a discriminatory outcome without any prohibited variable in the model. It’s difficult to detect from outside and often difficult to detect from inside.

There’s precedent establishing this isn’t theoretical. A major platform reached a settlement with the U.S. Department of Justice over housing advertisement delivery, requiring it to rebuild its ad delivery system to reduce demographic variance between an advertiser’s intended audience and who actually saw the ad. The significance: the delivery algorithm itself was found to produce discriminatory outcomes, independent of what targeting the advertiser selected.

For a security professional, this is the interesting frontier. The harm doesn’t come from a breach or a leak, but from a system working exactly as designed on data lawfully collected.

Do this today

6. The sale and sharing of personal data

The basics

“We do not sell your personal data” is usually technically accurate and substantively misleading.

Under most U.S. state laws, sale means disclosure for money or other valuable consideration. Companies restructured to avoid meeting that definition: data moves under a service provider contract, or as sharing for targeted advertising, or inside a partnership. No sale occurred. The data moved.

The useful question is not “do you sell my data.” It’s “do you share my data for cross-context behavioral advertising, and who are your service providers?”

Go deeper

What most people don’t know

Your data is an asset in a bankruptcy, and privacy promises don’t reliably survive the sale.

When a company fails, its customer database has value, and a bankruptcy court’s job is maximizing creditor recovery. Regulators have intervened in some cases to enforce the privacy promises made at collection, and this precedent goes back decades. But it’s an intervention, not a guarantee. The 2025 bankruptcy of a major consumer genetics company put the question in the sharpest possible terms, with genetic data as a saleable asset and state attorneys general urging customers to delete before it changed hands.

The practical rule: when you give data to a company, you’re also giving it to that company’s eventual acquirer, or its creditors. Evaluate accordingly, especially for anything permanent.

Do this today

7. Your rights under privacy laws

The basics

The U.S. has no comprehensive federal privacy law. You have a patchwork:

Typical state rights: know what’s collected, get a copy, delete it, correct it, opt out of sale/sharing and targeted advertising, opt out of profiling used for significant decisions, and limit use of sensitive data. Companies generally must respond in about 45 days, can’t discriminate against you for asking, and must offer an appeal.

Go deeper

What most people don’t know

Two things, and both are load-bearing.

First: HIPAA is far narrower than nearly everyone believes. It applies to health care providers, health plans, clearinghouses, and their business associates. It does not cover your period tracking app, your fitness wearable, a symptom-checker website, a direct-to-consumer genetics service, most wellness apps, or your employer. When a health app says your data is “HIPAA compliant,” that often describes an infrastructure vendor, not a legal obligation to you. The health data outside HIPAA’s scope now vastly exceeds the health data inside it.

Second: fair-credit law is the sleeper power, because it comes with a free audit. Any company whose reports are used for credit, insurance, employment, housing, or similar decisions is a consumer reporting agency, and owes you a free copy of your file annually plus the right to dispute errors.

There are dozens of these beyond the three credit bureaus: insurance claims history, employment screening, tenant screening, medical information, utility payment, check-writing, and gaming. The Consumer Financial Protection Bureau publishes an annual list of consumer reporting companies with contact details and instructions.

Requesting those files is the closest thing that exists to an audit log of your own life. It’s free, it’s a legal right, and hardly anyone does it, which is exactly why errors in these files go undiscovered until they cost someone a job or an apartment.

Do this today

8. Steps to protect your data

This is the capstone, so here’s the consolidated plan across all six lessons.

One hour, once: the highest-return actions

  1. Freeze your credit at all three bureaus, and your children’s. Free, reversible, and the strongest single defense against identity fraud.
  2. Password manager, unique passwords, two-factor or passkeys on email and financial accounts first. Email is the master key to everything else.
  3. Turn on Global Privacy Control in your browser, and install uBlock Origin.
  4. Set encrypted, filtering DNS at your router. One change, every device in the house, including the ones with no settings.
  5. Kill your mobile ad ID and turn off ad personalization at Google, Meta, Amazon, and Microsoft.

One afternoon: the deeper cleanup

  1. Start using email aliases for new accounts. This breaks the key that links your profile across companies.
  2. Broker opt-outs. Work the state registries, prioritize the risk and identity tier, and use California’s DROP if eligible.
  3. Request your files: the CFPB specialty list, plus fraud and return scores (Lesson 3).
  4. Location cleanup: everything to “While Using,” precise off, history on-device with short retention.
  5. Device audit: disconnect the TV, delete voice and video history with auto-delete on, segment IoT onto its own network.

Ongoing: the habits that compound

  1. A family verification word against voice cloning. Costs nothing.
  2. Guest checkout and aliases rather than accounts and loyalty programs.
  3. Ask before connecting anything. Does this need internet access to do its job?
  4. Factory reset and deregister every device and vehicle before you sell or return it.

The honest limits

You will not achieve zero. That’s the wrong target, and pursuing it produces exhaustion rather than protection.

Broker removals repopulate, so it’s maintenance rather than a fix. Server-side tracking is beyond your browser’s reach. Deletion requests don’t reach models already trained on your data (Lesson 3). Public records stay public. And your relatives’ choices expose you regardless of your own discipline.

What you’re actually doing is reducing exposure and raising cost. Every link you break makes your profile less complete, less accurate, and less useful. That’s a real result, and it compounds, which is why the single most valuable insight across all six lessons is that prevention beats remediation. Data you never handed over requires no deletion request, survives no bankruptcy sale, and can’t be re-identified.

The course in six ideas

Lesson 1, Apps & Mobile. The permission prompt marks the edge of the visible, not the edge of what’s collected.

Lesson 2, Connected Vehicles. Your car transmits independently of your phone, and its app account is a spare key.

Lesson 3, AI & Digital Identity. Deletion removes records, not model weights. Prevention beats remediation.

Lesson 4, Connected Cities. You can’t consent your way out of public space, so the leverage is records requests, contracts, and ordinances. Privacy by architecture outlasts privacy by policy.

Lesson 5, Connected Home. You own this network, so fix it at the network level. That’s what protects the devices with no settings.

Lesson 6, Your Data. The advertising economy is visible and annoying. The decisions economy is invisible and consequential. Your rights are the audit log, and hardly anyone uses them.

Recap

Key terms

Check your understanding

1. A retailer’s privacy policy says they never sell your personal information. Is your data staying with them? Not necessarily. “Sale” is narrowly defined, and data commonly moves as “sharing for targeted advertising” or under service provider contracts without meeting it. The question to ask is whether they share for cross-context behavioral advertising.

2. You use an ad blocker, reject all cookies, and browse privately. A store you bought from still reports your purchase to an ad platform. How? Server-side tracking. Their server sends the transaction and your identifying details, often a hashed email, directly to the platform. Your browser was never involved, so no browser control applies. Aliased emails and guest checkout are what address this.

3. You want an audit of what companies have decided about you. What’s the single most productive thing you can request? Your files from consumer reporting agencies, using the CFPB’s list of specialty reporting companies, covering insurance claims, tenant screening, employment, and medical information. Free by law, disputable if wrong, and rarely requested.

You’ve completed the DeSpy Academy privacy course. Knowledge is privacy. The more you understand, the more you control.