Privacy
Data brokers and the market for personal information
How personal information is collected, combined, scored and resold, and where practical limits on collection begin.
What a data broker does
A data broker is an organisation whose business model involves collecting, combining, analysing, licensing or selling information about people. The information may come from public records, commercial transactions, apps, advertising systems, loyalty programmes, location data or other brokers. The important point is not the label. It is the chain: one record that looks harmless can become identifying when it is joined to several others.
The broker may not know your name at first. A device identifier, advertising identifier, hashed email address, household address, purchase pattern or location trail can still act as a join key. Pseudonyms reduce direct exposure in some systems, but they do not automatically make the data anonymous.
What you can realistically control
You cannot opt out of every public record or make every organisation forget a lawful transaction. You can reduce the amount of information that is generated and the number of places it is copied:
- Do not give a real phone number or address to a service that has no reason to need it.
- Turn off advertising identifiers and unnecessary location access.
- Avoid signing in to unrelated services with the same identity when separation matters.
- Delete old accounts and revoke third-party app access.
- Use access and deletion rights where the applicable law gives you one.
The last step is maintenance, not magic. A deletion request to one company does not remove a copy held by another company, a public record, or a derived score.
A useful threat-model question
Ask what decision the data could influence. The risk is not limited to embarrassing disclosure. Location history, inferred health interests, household composition and financial behaviour can be used to target, rank, deny, manipulate or surveil people.
Topics
Sources
- Data brokers Accessed
- Data and Goliath Accessed
Related archive entries
-
Archive research papers
Unique in the Crowd: The privacy bounds of human mobility (Archive)
A study of how few location points may be needed to identify people in a mobility dataset.
Related guides
-
Guide Introductory
Metadata Explained (Guide)
A worked primer on data about data: what leaks even with perfect encryption, and the measures that actually reduce it.
-
Guide Intermediate
Mobile Device Privacy (Guide)
What a phone knows that a laptop does not, which platform settings matter, and the limits of user control.
-
Guide Introductory
Define Your Threat Model (Guide)
Work out who you are protecting something from before you install anything, using a written, revisable model.