Your personal information may travel beyond the websites where you originally supplied it. Intermediaries can aggregate it, combine it with other records and supply it to third parties. Understanding who buys data and why helps you decide how to limit unnecessary sharing through opt-outs and applicable erasure rights.
Who supplies personal data?
The ecosystem includes data brokers, marketing databases, people search services and partnerships between websites or apps. Practices vary: not every directory sells the same information or operates under the same model.
Records may contain names, contact details, age ranges and interests. They can be sold, licensed or used to provide services such as audience targeting or person lookup. Where the GDPR applies, rights including access, correction and erasure are subject to its conditions.
Our page on identifying brokers and acting explains the process from detection to follow-up. A free digital footprint scan helps identify exposure across covered websites, broker sources and known breaches. A detected listing alone does not prove a particular sale occurred.
Who buys data and why?
Businesses may use acquired information for direct marketing, advertising audiences, risk assessment, person lookup, debt recovery or further data supply. The chain can involve several intermediaries and successive partners.
The more widely records are held and shared, the harder it can be to trace every copy. To understand a specific organisation's processing, use its privacy notice and, where applicable, an access request asking about sources, purposes and recipients.
Limiting resale includes reducing unnecessary records at organisations that collect or supply your information. Erasure at one source can reduce future availability there; it does not automatically retrieve every copy already sent elsewhere.
How to limit sharing and resale
- Identify exposure. A scan can group relevant public-web and broker findings alongside known breaches.
- Exercise applicable erasure rights. GDPR Article 17 lets you request deletion when its conditions are met.
- Use opt-out procedures. Many brokers provide a privacy form or withdrawal process. Check what the opt-out actually covers and retain evidence.
- Follow up. If there is no response within the applicable period, normally one month under the GDPR, send a reminder and consider a CNIL complaint where appropriate.
You can manage these steps yourself or authorise us to send selected requests on your behalf. After the free scan, review what to address and track the sending process. Read our method.
Want to identify where your details appear? Start a free scan, review the report, then select your removal requests.
See also: Data brokers and removal · GDPR Article 17 · Check known data breaches



