Start here if you just want to know what’s in your file
This is the industry map — how the pieces fit together, who’s been caught doing what, and what regulators are actually doing about it. If you want the personal version first — what a broker profile on you specifically looks like and how to request deletion — read your data-broker profile, then come back here for the wider picture.
The industry isn’t one thing — it’s four
“Data broker” gets used as a catch-all, but the FTC’s own foundational study split the industry into distinct product categories with different business models, different data, and different harms. Its 2014 review of nine major brokers grouped their products into marketing (direct marketing, online marketing, and marketing analytics), risk mitigation (identity verification and fraud detection), and people search — and it found each category generated substantially different revenue, though from different subsets of the nine companies studied in 2012: five of the brokers sold marketing products that together generated over $196 million, four sold risk mitigation products that generated approximately $177 million, and three provided people-search products that generated over $52 million (FTC, Data Brokers: A Call for Transparency and Accountability). A fourth category has grown large enough since then to function as its own industry: location and mobile-SDK brokers, built entirely on data harvested from apps.
Marketing-data giants. These brokers build audience profiles — income bracket, interests, life stage, purchase history — sold mainly to advertisers. The FTC’s report described data brokers sorting consumers into categories like “Diabetes Interest” and “Expectant Parent” (see your data-broker profile for how these inferences get made).
Credit-header data. When a credit bureau compiles your credit report, the identifying information at the top — name, current and past addresses, phone numbers, date of birth, Social Security number — is called the “credit header.” The FTC has long taken the position that this header data, standing alone, isn’t a “consumer report” under the Fair Credit Reporting Act, so it doesn’t carry that law’s protections — it can be sold in bulk with far fewer restrictions than the credit file it’s attached to (EPIC, The Fair Credit Reporting Act). That gap is why the same “above the line” identity data at the top of your credit file can end up circulating through the broker economy.
People-search brokers. Sites like the ones covered in how people-search sites expose your address take exactly this kind of identifying information — much of it sourced from public records — and package it into a paid lookup: name in, address and relatives out. The FTC’s 2014 report singled this category out for different treatment than marketing data, because the product isn’t used to target ads — it’s used to find a specific person.
Location and mobile-SDK brokers. This is where the last decade of FTC enforcement has concentrated, and where the stalking risk is most direct: companies that collect precise, timestamped GPS coordinates from apps on your phone and resell them.
How the location data actually gets from your phone to a broker’s database
Two well-documented mechanisms drive much of it, and neither typically involves you knowingly selling your location to anyone.
Software Development Kits (SDKs). Many free apps embed a small piece of code from a data broker — an SDK — that reports device and location data back to that company in exchange for analytics tools or ad revenue the developer wouldn’t otherwise get. The Electronic Frontier Foundation describes it directly: “Apps that include Software Development Kits (SDKs) from some companies will instruct the app to send back troves of sensitive information for analytical insights or debugging purposes. The data brokers may offer market insights or financial incentives for app developers to include their SDKs” (EFF, Federal Regulators Limit Location Brokers). The FTC’s complaint against X-Mode Social found the company collected raw location data this way from its own apps and from third-party apps carrying its SDK, then sold it “to hundreds of clients in industries ranging from real estate to finance, as well as private government contractors” (FTC, X-Mode/Outlogic press release).
Real-time bidding (RTB) and the ad “bidstream.” Every time an app or website shows you a targeted ad, it typically runs a split-second auction: your device’s ad ID, rough location, and technical details get broadcast to potential advertisers so they can bid. As EFF explains, “Other companies will not ask apps to directly include their SDKs, but will participate in Real-Time Bidding (RTB) auctions, placing bids for ad-space on devices in locations they specify. Even if they lose the auction, they can glean valuable device location information just by participating” (EFF, Federal Regulators Limit Location Brokers). The FTC’s 2024 action against Mobilewalla was its first case built specifically on this bidstream harvesting: the agency alleged the company collected people’s location data from RTB exchanges “even when it did not place an ad through the bid,” then used it to build audience segments — including “Hispanic churchgoers, pregnant women, members of the LGBTQ+ community, workers participating in union organizing, and people who participate in political rallies” — by geofencing places like pregnancy centers and state capitols (FTC, Statement of Chair Khan Joined by Commissioner Bedoya and Commissioner Slaughter, In the Matter of Mobilewalla).
Loyalty and purchase data, and public records, round out the raw material: retail and warranty transactions feed marketing brokers, while property deeds, voter files, and court records feed people-search products (both covered in more depth in your data-broker profile). What connects much of it is resale: the FTC’s 2014 report found that seven of the nine brokers it studied bought from or sold information to each other, and that the brokers generally “obtain most of their data from other data brokers rather than directly from an original source” — which is part of why the report called it “virtually impossible for a consumer to determine the originator of a particular data element.”
The enforcement record: how regulators describe this industry when they’ve actually investigated it
Enforcement actions are the most reliable window into how this industry works, because they’re built on subpoenaed internal records, not marketing claims. Four cases anchor the picture.
FTC v. Kochava (filed 2022, resolved 2026). The FTC sued the Idaho-based data broker in August 2022 for selling geolocation data from “hundreds of millions of mobile devices” that it said could be used to trace the movements of individuals, in a format specific and unshielded enough that a buyer could trace a single device from a reproductive health clinic to a home address, and from there identify the person (FTC, FTC Sues Kochava). Kochava initially got the case dismissed, but in February 2024 an Idaho federal judge allowed an amended complaint to proceed, writing in his opinion that “by selling that data, Kochava arguably invades consumers’ privacy and exposes them to significant risks of secondary harms” (U.S. District Court for the District of Idaho, Memorandum Decision and Order). The case is now resolved: in May 2026 the FTC announced it would ban Kochava and its subsidiary, Collective Data Solutions (CDS) — which has taken over Kochava’s data broker business — from selling, sharing, or disclosing sensitive location data without consumers’ affirmative express consent, and a stipulated final order was entered by the court on June 25, 2026, running for 10 years (FTC, FTC to Ban Kochava and Subsidiary from Selling Sensitive Location Data; FTC, Stipulated Order for Injunction and Other Relief). The order also requires Kochava and CDS to build a sensitive-location-data program, confirm consumer consent before using supplier-provided location data, let consumers see who their location data was sold to and withdraw consent, and delete data on a set retention schedule.
X-Mode Social/Outlogic (January 2024). This was the FTC’s first-ever order banning a data broker from selling sensitive location data. The agency’s complaint found the company’s raw location data — tied to a persistent Mobile Advertiser ID, plus latitude, longitude, and timestamp — was “capable of matching an individual consumer’s mobile device with the locations they visited,” including “medical facilities, places of religious worship, places that may be used to infer an LGBTQ+ identification, domestic abuse shelters, and welfare and homeless shelters” (FTC, X-Mode Complaint). Until May 2023, the company had no policy at all for removing sensitive locations from the data it sold (FTC press release).
InMarket Media (January 2024, announced nine days after X-Mode). InMarket ran nearly 2,000 advertising “audience segment” lists built from location visits — categories the FTC’s press release named directly, including “parents of preschoolers,” “Christian church goers,” and “wealthy and not healthy” (FTC, InMarket press release). Its own shopping apps told users their location would be used for the app’s function — reward points, shopping-list reminders — without disclosing that the same data would be combined with other sources and sold for targeted advertising. The FTC also flagged InMarket’s five-year retention of geolocation data as longer than necessary, increasing the risk the data would be “disclosed, misused, or linked back to the consumer.”
GM/OnStar (complaint January 2025, FTC order finalized January 2026). General Motors and its OnStar subsidiary collected precise geolocation and driving-behavior data — hard braking, rapid acceleration, speed, seatbelt use, time and duration of trips — from vehicles enrolled in the OnStar Smart Driver feature, sometimes transmitting location data every three seconds, and sold it to consumer reporting agencies including LexisNexis and Verisk without clearly disclosing this to drivers (FTC, GM/OnStar final order press release; FTC complaint). Those consumer reporting agencies used the data to compile reports that insurers relied on to set rates or deny coverage. The FTC’s final order bans GM from disclosing this data to consumer reporting agencies for five years and requires affirmative consent for the full 20-year life of the order — relief the agency called appropriate given what it termed GM’s “egregious betrayal of consumers’ trust.” California’s Attorney General separately reached a parallel state settlement in May 2026, finding GM had made “approximately $20 million nationwide” selling this data and imposing a $12.75 million civil penalty — the state’s eighth enforcement action under the California Consumer Privacy Act, and its first case built on the law’s data-minimization requirement (California DOJ, GM privacy settlement).
Together, these cases establish a pattern regulators keep finding: consent screens that describe one use (app functionality) while the data is used for another (advertising, insurance, resale); SDKs and bidstream participation that harvest data with no visibility for the app developer, let alone the user; and retention periods that outlast any legitimate purpose, multiplying the damage if something goes wrong.
When something does go wrong: the Gravy Analytics breach
In January 2025, a hacker claimed to have stolen terabytes of data from Gravy Analytics, a location broker whose subsidiary Venntel sells location data to government agencies. The breach happened weeks after the FTC had banned Gravy Analytics and Venntel from collecting and selling Americans’ location data without consent over allegations they tracked people to “health-related locations and places of worship” (FTC, Gravy Analytics/Venntel press release). Gravy Analytics’ parent company, Unacast, confirmed to Norwegian regulators that an intruder had accessed its cloud storage “through a misappropriated key” (TechCrunch, A breach of Gravy Analytics’ huge trove of location data).
The published sample — analyzed by outside researchers and reported by TechCrunch — contained more than 30 million location data points tied to popular consumer apps, including fitness and health, dating, and transit apps, as well as popular games, with the data traceable to devices at sensitive sites. According to TechCrunch’s reporting, Gravy Analytics sourced much of this data “from a process called real-time bidding,” the same bidstream mechanism described above — meaning much of what leaked wasn’t data users had knowingly shared with Gravy Analytics at all, but data swept up during ad auctions run by apps that, in several cases, said they had no direct relationship with the broker (TechCrunch). The incident is a useful data point on its own terms: even brokers already under a federal consent order were holding troves of precise location history with security that failed.
The regulatory map, as it actually stands
There’s no single federal law regulating data brokers generally — the FTC’s authority comes primarily from Section 5 of the FTC Act, which prohibits “unfair or deceptive” practices, and that’s the legal theory behind every case above. Location data specifically has become the agency’s clearest enforcement priority, but the orders are case-by-case, not industry-wide rules.
State registration laws fill part of the gap. California, Oregon, Texas, and Vermont require data brokers to register publicly, which is the main reason outside researchers and journalists can identify who these companies are at all (California Privacy Protection Agency, DROP). California has gone furthest: its Delete Request and Opt-Out Platform (DROP) lets a verified resident submit one deletion request that reaches all registered brokers — over 600 of them — at once, with brokers required, under the Delete Act, to access the platform at least once every 45 days and process deletion requests starting August 1, 2026 (CPPA, Data Brokers). Vermont’s governor signed a broader overhaul of the state’s data broker law, Act 138, on June 16, 2026 (Vermont Legislature, Bill Status H.211 (Act 138)), but its new provisions don’t take effect until January 1, 2027, and a statewide deletion mechanism was only put under study rather than built (Vermont Legislature, H.211 Senate Proposal of Amendment) (see your data-broker profile for the full state-by-state breakdown, since that’s already covered in depth there).
What’s realistic for an individual to do about this
Nothing here makes any single company’s data disappear for good — opting out reduces what shows up in a casual search, it doesn’t erase the underlying record. A few things are worth doing anyway, roughly in order of impact:
- Cut off the pipeline, not just the output. The SDK and bidstream mechanisms described above lean heavily on your device’s advertising identifier, but brokers also correlate data using IP addresses and first-party or probabilistic identifiers, so no single setting closes off collection entirely. Resetting or limiting your advertising identifier — covered in advertising IDs — is still one of the more effective actions available, since it can disrupt the linkage brokers rely on for the SDKs and auctions that use it, even though it won’t stop identifiers based on your IP address or other signals.
- Use the tools built for the people-search layer specifically, since that’s the category most directly tied to being physically found: how people-search sites expose your address and DeSpy’s Data Broker Directory, built from the state registries above, cover the practical opt-out process.
- Know that this is a rolling task, not a one-time fix. Every enforcement action in this piece describes an ongoing business, not one that closed after the FTC’s order — brokers under a consent decree can keep operating, and new brokers keep entering the market to buy from the same app SDKs and ad exchanges.
If you’re trying to figure out whether a specific person could be using this kind of data to find or follow you right now, that’s a more urgent, different question — start with Is someone tracking my phone? and, if there’s any risk that acting on this information could tip someone off, read Safety first before you change anything.