Your Data
Your data has value. Learn how it’s collected, used, and sold.
Lesson 6 of 6 · Estimated read: 16 minutes · Level: everyone
Five lessons have covered where data comes from: your phone, your car, AI systems, your city, your home. This one is about the economy those streams feed: who buys, who sells, what it’s worth, and what rights you have.
It’s also the capstone, so it ends with a consolidated plan rather than another list of settings.
One correction up front, because it reframes everything that follows: almost nobody is “selling your data” the way people picture it. There’s no marketplace listing your name for $4.99. What actually happens is subtler and harder to opt out of. Companies sell access to you, and they sell decisions about you. The second one is where the real money and the real consequences are.
In this lesson
- Where your data comes from
- Data brokers and marketplaces
- How companies profit from your data
- Cookies, pixels, and tracking
- Data aggregation and profiling
- The sale and sharing of personal data
- Your rights under privacy laws
- Steps to protect your data
1. Where your data comes from
The basics
Four streams, and most people only think about the first:
- What you volunteer: forms, accounts, purchases, posts
- What you do: clicks, searches, viewing, movement
- What’s observed: sensors, location, cameras, network activity
- What’s inferred: predictions built from all of the above (Lesson 3)
Go deeper
There’s a fifth stream that dominates broker files and almost never comes up: public and offline records.
Property deeds and assessments. Voter registration. Court filings, liens, and bankruptcies. Marriage and divorce records. Professional licenses. Business registrations. In many states, motor vehicle records are available to permitted commercial recipients. None of this involved the internet, and all of it is bulk-purchasable.
This is why people-search sites know your address history, your relatives, and your age even if you’ve never had a social media account. The foundation of your broker profile is paperwork you filed with a government.
What most people don’t know
Some of the most sensitive data leakage has come from the websites you’d most expect to be careful, through tracking code the site owner installed voluntarily.
Investigative reporting and federal enforcement have documented tracking pixels on hospital appointment pages, mental health and telehealth services, tax preparation sites, and prescription discount services, all transmitting to advertising platforms information about what condition someone was looking up, what medication they searched, or what they entered into a tax form.
Enforcement followed: a prescription discount service and an online therapy provider both paid penalties for sharing health information with advertising platforms after promising they wouldn’t. A congressional investigation found major tax preparation services had transmitted financial details to advertising platforms.
The mechanism is mundane, which is why it kept happening: a marketing team adds a conversion-tracking snippet to measure ad performance, and the snippet reports the page URL and form fields by default. Nobody decided to leak health data. Nobody stopped it either.
The lesson for you as a reader: be most careful on exactly the sites that feel most legitimate. A hospital portal or a tax site has no special protection, and the sensitivity of what you type there is the entire risk.
Do this today
- Stop filling in optional form fields. Phone number, birthdate, and gender are usually optional and usually feed the profile.
- Use a browser with tracking protection for anything health, financial, or legal. See Section 4.
- If you’re a survivor of stalking or abuse, look up your state’s address confidentiality program. Many states let you use a substitute address on public records, which breaks the foundation of most broker profiles.
2. Data brokers and marketplaces
The basics
“Data broker” covers three very different industries:
- People-search sites: consumer-facing, sell background lookups to anyone with a credit card
- Marketing brokers: sell audiences and segments to advertisers
- Risk and identity brokers: sell investigative and verification data to insurers, employers, landlords, debt collectors, and law enforcement
Most privacy advice focuses on the first. The third matters most.
Go deeper
- Only a handful of states require brokers to register. Those registries are public, and they’re the best available list of who holds your data, far better than guessing.
- The industry is consolidating, which means opt-outs need periodic redoing as records migrate.
What most people don’t know
The risk and identity tier holds the most consequential data, and almost no consumer has heard of the companies in it.
These platforms aggregate Social Security numbers, address histories going back decades, relatives and associates, vehicles, licenses, employment, litigation, and property, into a single searchable dossier. Customers include law enforcement, skip tracers, insurers, and investigators. Some of these products are the reason a debt collector can find you at a new address within days.
The structural detail worth understanding: the same corporate parent often sells both a regulated and an unregulated product. When data is used for credit, insurance, employment, or housing decisions, it’s a consumer report and federal fair-credit rules apply, so you get access and dispute rights. Sold for marketing or investigation, the same underlying data faces far fewer constraints. The dividing line is the stated use, not the sensitivity.
Also documented: brokers offering lists organized around genuinely sensitive characteristics: health conditions, mental health status, financial distress, and in academic research, lists of people with dementia. Federal regulators have brought actions in this space, and rulemaking to bring more of it under fair-credit rules has been attempted.
Do this today
- Pull up the public broker registries in California, Vermont, Texas, and Oregon. They’re the master list. Work down it, or hand it to a removal service.
- Submit opt-outs to the major risk and identity brokers specifically. LexisNexis Risk Solutions, Thomson Reuters, TransUnion’s investigative products, and Experian’s non-credit divisions all maintain suppression or opt-out processes. These are the highest-value removals and the ones almost everyone skips.
- California residents: use the state’s single DROP mechanism to reach all registered brokers at once (Lesson 3).
3. How companies profit from your data
The basics
Two business models, and conflating them is why people misunderstand the whole industry.
Selling access to you. This is advertising. The platform keeps your data and rents your attention.
Selling decisions about you. This is risk scoring, pricing, and eligibility. Someone pays to know whether to insure you, hire you, rent to you, extend you credit, or trust your transaction.
Go deeper
- Advertising revenue per user is more modest than people assume. For major platforms it’s roughly tens of dollars per year globally, higher in wealthy markets. Your individual data is cheap. Aggregate data is enormously valuable. That asymmetry is why “just pay me for my data” proposals never work out in your favor: your share of the pie is small, while the aggregate leverage over you is large.
- This is also why data-dividend legislation has consistently failed. There’s no price at which selling your own profile is a good trade.
What most people don’t know
Personalized pricing is real, has been studied by federal regulators, and is largely invisible to the person being priced.
Differential pricing has been documented for over a decade: online retailers showing different prices based on inferred device type or on the distance to a competitor’s store, travel sites steering users toward different options based on their platform.
More recently, U.S. regulators used formal information demands to study the practice across intermediary firms and reported that consumer data, including location, browsing behavior, and inferred characteristics, is used to tailor prices and offers to individuals.
Why this is the most important item in the lesson: you cannot detect it. With advertising, you can at least see the ad. With pricing, you see one number and have no reference point. There’s no notification, no comparison, and no way to know you were charged more than the next person.
Which reframes the profit question. The advertising economy is annoying and visible. The decisions economy, covering pricing, insurance, credit, eligibility, and fraud scores, is consequential and invisible, and it’s where your data does the most to you.
Do this today
- For significant purchases, compare prices logged out, in a private window, and from a different device or network. Differences aren’t guaranteed, but the comparison costs nothing.
- Treat “free” services as priced in data, and prefer paying where a paid tier exists and removes the data model.
- Don’t try to sell your own data. The leverage is in withholding, not in pricing.
4. Cookies, pixels, and tracking
The basics
Cookies are small files a site stores in your browser. First-party cookies (from the site you’re on) keep you logged in. Third-party cookies (from other companies) followed you between sites, and browsers have largely killed them.
Pixels are the ones that matter now. A pixel is a snippet of code a site owner embeds that reports your activity back to an advertising platform: the page you loaded, what you clicked, what you purchased, and often form contents.
Go deeper
- Cookie consent banners are widely misunderstood. Many don’t fully do what “reject all” implies, and European regulators have found the dominant consent framework itself unlawful in its handling of the signals it generates.
- Some sites route tracker traffic through a subdomain of their own domain, making third-party requests look first-party specifically to evade blockers.
What most people don’t know
The death of third-party cookies didn’t reduce tracking. It moved tracking to servers, where none of your browser controls reach.
This is the most important technical shift in the last five years, and it’s still not widely understood.
Previously: your browser loaded a tracker, so blocking it in your browser worked. Now, increasingly: the merchant’s own server sends your purchase and identity data directly to the advertising platform’s server, via what’s called a conversions API or server-side tagging. You gave the merchant your email at checkout. Their server passes it onward. Your browser is never involved.
Consequences, and they’re uncomfortable:
- Ad blockers can’t block it. There’s no request to block.
- Cookie settings don’t apply. There’s no cookie.
- Private browsing doesn’t help. The data came from the merchant’s records, not your session.
Combined with the hashed-email matching from Lesson 3, this is a durable tracking system that operates entirely outside your device.
What still works: not being identifiable to the merchant in the first place. Aliased emails, guest checkout, and declining loyalty programs address the input to server-side tracking. Browser hardening addresses the older, visible layer. Still worth doing, just no longer sufficient.
Do this today
- Use a browser with strong default protection, such as Firefox with strict mode, Safari, or Brave, plus uBlock Origin.
- Turn on Global Privacy Control if your browser offers it. More on why in Section 6.
- Use aliased emails and guest checkout, which is the only thing that touches server-side tracking.
- Assume anything you type into a form may be transmitted, and be most careful on sensitive sites.
5. Data aggregation and profiling
The basics
Aggregation stitches your identifiers into one profile (covered in Lesson 3). Profiling is what gets done with it: sorting you into segments: “in-market for a vehicle,” “budget-conscious grocery shopper,” “recently moved,” “likely managing a chronic condition.”
Audience taxonomies run to tens of thousands of segments.
Go deeper
- Segments are sold as audiences to advertisers, and increasingly as inputs to decisions.
- Segment membership is a guess. There’s typically no accuracy standard and no mechanism for you to see or correct it.
What most people don’t know
Companies avoid collecting protected characteristics and infer them instead, and inference is regulated far more loosely than collection.
Nobody needs to record your race, religion, health status, or sexual orientation. Purchase patterns, location history, app usage, and network of contacts predict all of them with uncomfortable accuracy. The inferred attribute then drives targeting or decisions while the company can accurately state it never collected sensitive data.
This produces proxy discrimination: a model using ZIP code, shopping behavior, and device type as stand-ins for protected characteristics, reaching a discriminatory outcome without any prohibited variable in the model. It’s difficult to detect from outside and often difficult to detect from inside.
There’s precedent establishing this isn’t theoretical. A major platform reached a settlement with the U.S. Department of Justice over housing advertisement delivery, requiring it to rebuild its ad delivery system to reduce demographic variance between an advertiser’s intended audience and who actually saw the ad. The significance: the delivery algorithm itself was found to produce discriminatory outcomes, independent of what targeting the advertiser selected.
For a security professional, this is the interesting frontier. The harm doesn’t come from a breach or a leak, but from a system working exactly as designed on data lawfully collected.
Do this today
- Look at your inferred segments: Google’s My Ad Center, Meta’s ad preferences, Amazon’s advertising settings, LinkedIn’s ad settings.
- Request inferences explicitly when filing a privacy request. Several state laws cover them, and most companies disclose only raw data unless asked.
- Correct what’s wrong where correction is offered. Several state laws now include a right to correct.
6. The sale and sharing of personal data
The basics
“We do not sell your personal data” is usually technically accurate and substantively misleading.
Under most U.S. state laws, sale means disclosure for money or other valuable consideration. Companies restructured to avoid meeting that definition: data moves under a service provider contract, or as sharing for targeted advertising, or inside a partnership. No sale occurred. The data moved.
The useful question is not “do you sell my data.” It’s “do you share my data for cross-context behavioral advertising, and who are your service providers?”
Go deeper
- California’s law added “sharing” as a separate defined term precisely because “sale” had become easy to design around.
- The real-time bidding bidstream (Lesson 1) distributes your data to hundreds of companies per ad impression. No privacy policy describes this as a sale.
- Government agencies purchase commercially available data rather than compelling it (Lesson 4).
What most people don’t know
Your data is an asset in a bankruptcy, and privacy promises don’t reliably survive the sale.
When a company fails, its customer database has value, and a bankruptcy court’s job is maximizing creditor recovery. Regulators have intervened in some cases to enforce the privacy promises made at collection, and this precedent goes back decades. But it’s an intervention, not a guarantee. The 2025 bankruptcy of a major consumer genetics company put the question in the sharpest possible terms, with genetic data as a saleable asset and state attorneys general urging customers to delete before it changed hands.
The practical rule: when you give data to a company, you’re also giving it to that company’s eventual acquirer, or its creditors. Evaluate accordingly, especially for anything permanent.
Do this today
- Turn on Global Privacy Control. This is the most under-used right in U.S. privacy law. GPC is a signal your browser sends automatically to every site, indicating you opt out of sale and sharing. Under California and Colorado law it must be honored, and California regulators have brought enforcement action specifically over a company’s failure to honor it. One setting, applied to every site you visit, with legal force behind it. Firefox, Brave, and DuckDuckGo can send it; extensions add it to other browsers.
- Use “Do Not Sell or Share My Personal Information” links where you see them. That’s the second-best route when GPC isn’t honored.
- Before handing over permanent data, ask what happens to it if the company is acquired or fails.
7. Your rights under privacy laws
The basics
The U.S. has no comprehensive federal privacy law. You have a patchwork:
- State comprehensive laws: roughly twenty states, covering access, deletion, correction, portability, and opt-outs
- Sector-specific federal laws: health, credit, financial, education, children’s, and video rental privacy
- State wiretap and biometric laws: sometimes the strongest tools available
Typical state rights: know what’s collected, get a copy, delete it, correct it, opt out of sale/sharing and targeted advertising, opt out of profiling used for significant decisions, and limit use of sensitive data. Companies generally must respond in about 45 days, can’t discriminate against you for asking, and must offer an appeal.
Go deeper
- Most states allow an authorized agent to file on your behalf, which is what removal services use.
- Video privacy law from the 1980s is currently driving substantial litigation over tracking pixels on sites with video content, an old statute with sharp modern teeth.
What most people don’t know
Two things, and both are load-bearing.
First: HIPAA is far narrower than nearly everyone believes. It applies to health care providers, health plans, clearinghouses, and their business associates. It does not cover your period tracking app, your fitness wearable, a symptom-checker website, a direct-to-consumer genetics service, most wellness apps, or your employer. When a health app says your data is “HIPAA compliant,” that often describes an infrastructure vendor, not a legal obligation to you. The health data outside HIPAA’s scope now vastly exceeds the health data inside it.
Second: fair-credit law is the sleeper power, because it comes with a free audit. Any company whose reports are used for credit, insurance, employment, housing, or similar decisions is a consumer reporting agency, and owes you a free copy of your file annually plus the right to dispute errors.
There are dozens of these beyond the three credit bureaus: insurance claims history, employment screening, tenant screening, medical information, utility payment, check-writing, and gaming. The Consumer Financial Protection Bureau publishes an annual list of consumer reporting companies with contact details and instructions.
Requesting those files is the closest thing that exists to an audit log of your own life. It’s free, it’s a legal right, and hardly anyone does it, which is exactly why errors in these files go undiscovered until they cost someone a job or an apartment.
Do this today
- Get the CFPB list of consumer reporting companies and request files from the ones relevant to you. Insurance and tenant screening are the highest-value for most people.
- File a state privacy request with two or three companies holding a lot of your data. Ask for inferences and for the list of third parties they disclosed to.
- Know whether your state has a comprehensive law, and whether it has a universal opt-out requirement.
- Stop assuming HIPAA protects health data in apps. It doesn’t.
8. Steps to protect your data
This is the capstone, so here’s the consolidated plan across all six lessons.
One hour, once: the highest-return actions
- Freeze your credit at all three bureaus, and your children’s. Free, reversible, and the strongest single defense against identity fraud.
- Password manager, unique passwords, two-factor or passkeys on email and financial accounts first. Email is the master key to everything else.
- Turn on Global Privacy Control in your browser, and install uBlock Origin.
- Set encrypted, filtering DNS at your router. One change, every device in the house, including the ones with no settings.
- Kill your mobile ad ID and turn off ad personalization at Google, Meta, Amazon, and Microsoft.
One afternoon: the deeper cleanup
- Start using email aliases for new accounts. This breaks the key that links your profile across companies.
- Broker opt-outs. Work the state registries, prioritize the risk and identity tier, and use California’s DROP if eligible.
- Request your files: the CFPB specialty list, plus fraud and return scores (Lesson 3).
- Location cleanup: everything to “While Using,” precise off, history on-device with short retention.
- Device audit: disconnect the TV, delete voice and video history with auto-delete on, segment IoT onto its own network.
Ongoing: the habits that compound
- A family verification word against voice cloning. Costs nothing.
- Guest checkout and aliases rather than accounts and loyalty programs.
- Ask before connecting anything. Does this need internet access to do its job?
- Factory reset and deregister every device and vehicle before you sell or return it.
The honest limits
You will not achieve zero. That’s the wrong target, and pursuing it produces exhaustion rather than protection.
Broker removals repopulate, so it’s maintenance rather than a fix. Server-side tracking is beyond your browser’s reach. Deletion requests don’t reach models already trained on your data (Lesson 3). Public records stay public. And your relatives’ choices expose you regardless of your own discipline.
What you’re actually doing is reducing exposure and raising cost. Every link you break makes your profile less complete, less accurate, and less useful. That’s a real result, and it compounds, which is why the single most valuable insight across all six lessons is that prevention beats remediation. Data you never handed over requires no deletion request, survives no bankruptcy sale, and can’t be re-identified.
The course in six ideas
Lesson 1, Apps & Mobile. The permission prompt marks the edge of the visible, not the edge of what’s collected.
Lesson 2, Connected Vehicles. Your car transmits independently of your phone, and its app account is a spare key.
Lesson 3, AI & Digital Identity. Deletion removes records, not model weights. Prevention beats remediation.
Lesson 4, Connected Cities. You can’t consent your way out of public space, so the leverage is records requests, contracts, and ordinances. Privacy by architecture outlasts privacy by policy.
Lesson 5, Connected Home. You own this network, so fix it at the network level. That’s what protects the devices with no settings.
Lesson 6, Your Data. The advertising economy is visible and annoying. The decisions economy is invisible and consequential. Your rights are the audit log, and hardly anyone uses them.
Recap
- Public and offline records form the backbone of your broker profile, not your online activity.
- Tracking pixels on health, tax, and telehealth sites have leaked exactly the data people most wanted protected.
- The risk and identity broker tier holds the most consequential data and is the least known.
- Personalized pricing is documented, studied by regulators, and undetectable from your side.
- Third-party cookies dying moved tracking server-side, out of your browser’s reach.
- Companies infer protected characteristics rather than collecting them, and inference is loosely regulated.
- “We don’t sell your data” is usually true under a narrow legal definition of “sale.”
- Your data is an asset in a bankruptcy.
- HIPAA doesn’t cover health apps, wearables, or genetics services.
- Fair-credit law gives you free access to dozens of specialty files, the closest thing to an audit of yourself.
- Global Privacy Control is a legally binding opt-out signal, applied to every site, from one setting.
Key terms
- Data broker: a company that aggregates and resells personal data with no direct relationship to you.
- People-search vs. risk/identity broker: consumer background lookups vs. investigative dossiers sold to institutions.
- Pixel: tracking code a site owner embeds that reports your activity to an advertising platform.
- Server-side tracking / conversions API: data sent from a merchant’s server directly to an ad platform, bypassing your browser entirely.
- Segment: an inferred audience category you’ve been sorted into.
- Proxy discrimination: discriminatory outcomes produced by models using stand-ins for protected characteristics.
- Sale vs. sharing: narrow legal definitions that companies design around; “sharing for targeted advertising” is the term that matters.
- Global Privacy Control (GPC): an automatic browser signal opting you out of sale and sharing, legally enforceable in some states.
- Consumer reporting agency: any company whose reports drive credit, insurance, employment, or housing decisions; owes you file access and dispute rights.
- Authorized agent: someone permitted to file privacy requests on your behalf.
Check your understanding
1. A retailer’s privacy policy says they never sell your personal information. Is your data staying with them? Not necessarily. “Sale” is narrowly defined, and data commonly moves as “sharing for targeted advertising” or under service provider contracts without meeting it. The question to ask is whether they share for cross-context behavioral advertising.
2. You use an ad blocker, reject all cookies, and browse privately. A store you bought from still reports your purchase to an ad platform. How? Server-side tracking. Their server sends the transaction and your identifying details, often a hashed email, directly to the platform. Your browser was never involved, so no browser control applies. Aliased emails and guest checkout are what address this.
3. You want an audit of what companies have decided about you. What’s the single most productive thing you can request? Your files from consumer reporting agencies, using the CFPB’s list of specialty reporting companies, covering insurance claims, tenant screening, employment, and medical information. Free by law, disputable if wrong, and rarely requested.
You’ve completed the DeSpy Academy privacy course. Knowledge is privacy. The more you understand, the more you control.