Data BrokersPrivacyLegal

Data Broker Deletion: One-Time Opt-Out vs. Recurring Removal

DE

Drash Eldetron

Writes about digital privacy, reputation, and online presence.

September 3, 2026

The FTC says it plainly: “if the information in your public records changes, your information could re-appear for sale on people search sites.” That’s not a bug in how opt-outs work — it’s the predictable result of how these sites are built.

This post covers the actual mechanism behind reappearing listings, what data brokers say about it in their own disclosures, and the one regulatory system that was built specifically because one-time opt-outs kept failing.

Quick overview

Infographic explaining why data broker listings reappear after opt-outs: an FTC study finding 7 of 9 major data brokers supply data to each other, the re-scraping mechanism pulling from voter registrations, property records, and court filings, Spokeo's own disclosure admitting information may reappear without notice, California's 45-day DROP deletion cycle, and two CPPA enforcement actions -- Accurate Append fined $55,400 and Background Alert ordered to cease operations through 2028.

How Data Brokers Keep Re-Sourcing Your Information

A successful opt-out removes one listing from one site on one day. It doesn’t touch the pipeline that created that listing in the first place — and that pipeline keeps running.

Nothing about that is a bug in how any single broker handles requests; it’s a direct consequence of the regulatory gap covered in our guide to why no single law bans this business model.

People-search sites, per the FTC’s own consumer guidance, “buy information from other data brokers, collect information from social media profiles that are public or viewable by everyone, and compile data from federal, state, and local government public records.” Every one of those sources refreshes on its own schedule: a new voter registration, an updated property record, a court filing.

When the source updates, the broker’s next data pull can recreate the listing you already had removed — which is exactly why the FTC’s own advice isn’t “opt out once,” it’s to “periodically check the people search sites” and “submit a new opt-out request” when something new shows up. For the practical side of that ongoing process, see our guide to data broker removal.

The Broker-to-Broker Pipeline: One Opt-Out Doesn’t Reach the Network

It gets less linear from there. The FTC’s foundational study of nine major data brokers found that most of them don’t get their information straight from an original source at all — “the nine data brokers studied obtain most of their data from other data brokers rather than directly from an original source,” and seven of the nine supply data to each other directly.

Even government-sourced records often pass through an intermediary first, rather than coming straight from a state or county office.

The FTC’s report is blunt about what that means for a consumer trying to trace — let alone stop — the flow: it would be “virtually impossible for a consumer to determine how a data broker obtained his or her data,” since doing so would mean “retrac[ing] the path of data through a series of data brokers.” Opting out of one site like BeenVerified doesn’t opt you out of the dozen other brokers that might be quietly supplying it, or that it’s quietly supplying — sites like Whitepages run on the same kind of network, just with a different name on the homepage.

What Data Brokers Themselves Admit

Some of this isn’t speculation — it’s in the brokers’ own fine print. A 2026 EPIC audit of opt-out processes quotes Spokeo’s own disclosure directly: “since we continually receive new and updated records from public sources, your information may reappear on Spokeo in the future without notice.” Spokeo’s language also puts the burden squarely on the user, telling people they need to “regularly check Spokeo for additional listings that may appear.” If you’re dealing specifically with Spokeo, that admission is worth reading literally: there’s no setting that stops your data from being re-collected, only a process for catching and removing it again when it comes back.

That same EPIC audit looked at opt-out friction across 38 companies more broadly, and found it’s rarely simple even on the first attempt: at least 15 of the companies studied lacked a clear opt-out link on their homepage, at least 17 lacked a clear privacy-policy link, and at least 15 required submitting multiple separate requests rather than one. EPIC’s own recommendation is telling — it says companies “should ensure that they continually honor the opt-out request by conducting ongoing, periodic audits,” which is another way of confirming that a single opt-out was never designed to be permanent.

California’s Delete Act and DROP

California built a regulatory answer to exactly this problem. Under the Delete Act (SB 362), the California Privacy Protection Agency runs DROP — the Delete Request and Opt-out Platform — and its final regulations were approved in November 2025.

Registered data brokers pay an annual fee and, starting August 1, 2026, must check DROP for new deletion requests at least once every 45 days and process them. That “at least once every 45 days” requirement is the structural difference from an ordinary opt-out: it’s a standing, recurring obligation on the broker’s side, not a single action a consumer takes and hopes holds.

The CPPA has already shown it will enforce the registration side of this system. Accurate Append, Inc. was fined $55,400 for missing its 2024 registration deadline, and Background Alert, Inc. — a people-search operator that had marketed “it’s scary how much information you can dig up on someone” — was ordered to cease all data-broker operations through 2028 after failing to register on time.

What Other State Registries Do, and Don’t Fix

California isn’t the only state paying attention. Vermont passed the first data-broker registration law in the country back in 2018, and Texas and Oregon both passed their own registry laws in 2023, with registration actually becoming mandatory in 2024.

All four states now require brokers to identify themselves publicly. What most of them don’t do — and this is the part worth being precise about — is build a recurring, centralized deletion mechanism the way California’s DROP system does.

Registration tells you the broker exists and has to disclose certain practices; it doesn’t, on its own, force that broker to keep checking for and honoring your deletion request every few weeks the way DROP is now required to.

What Actually Keeps Records From Coming Back

None of this means opting out is pointless — it’s still the only way to get a listing down in the first place, and it’s the mechanism regulators are actively strengthening, not abandoning.

What it does mean is that a single request should be treated as the start of an ongoing process, not a finished task: check back periodically, especially after a move, a name change, or a new public record gets filed, and resubmit when something new turns up. That’s also the exact reasoning behind ongoing privacy monitoring rather than a one-time cleanup — the data sources that create these listings never stop running, so the removal process that keeps up with them can’t be a single event either.

A similar problem shows up outside data brokers entirely: an AI chatbot can keep repeating something baked into its training data long after the original page is gone, for reasons that have nothing to do with search-index caching — see our guide to why AI can’t simply forget you.


Not sure which data brokers currently have your information, or whether an old opt-out has quietly lapsed? Get a free assessment and we’ll show you exactly what’s out there right now.

Frequently asked questions

How difficult is it, in practice, to opt out of a people-search site?

More than it should be. A 2026 EPIC audit of 38 companies found at least 15 lacked a clear opt-out link on their homepage, at least 17 lacked a clear privacy-policy link, and at least 15 required multiple separate submissions rather than one.

Which state was first to require data brokers to register publicly?

Vermont, in 2018 — the first data-broker registration law in the country. Texas and Oregon added their own registries, both requiring registration starting in 2024, though most only require public disclosure, not a recurring deletion mechanism like California's newer DROP system.

What's the difference between a data-broker registry and an actual deletion system?

A registry, like Vermont's or Texas's, just makes brokers identify themselves publicly. California's DROP system goes further — it requires registered brokers to check for and honor consumer deletion requests on a recurring, roughly 45-day schedule.

Has California's privacy agency actually fined any data brokers?

Yes. The CPPA fined Accurate Append $55,400 for missing a 2024 registration deadline, and ordered Background Alert to cease all data-broker operations through 2028 after it missed its own 2025 deadline.

We can take it from here

If the steps above don't get you the result you need, tell us what's going on and we'll take a look.

Get in touch