Skip to content
← Data brokers: who sells your life

Lesson 3 of 4 · 9 min

Your rights and how to opt out

What the EU, France, California and the US federal government actually let you ask a data broker to do — and the realistic limits of each option.

The rights available to you depend heavily on where you live. This lesson covers four concrete, official routes: the EU’s GDPR access and erasure rights, France’s CNIL guidance on exercising them, California’s new Delete Request and Opt-out Platform, and the more limited, sector-specific approach in US federal law.

The EU: access and erasure under the GDPR

The European Commission’s official citizen guidance summarises two rights that apply to any organisation processing your personal data in the EU, including data brokers. First, the right of access: you can “request access to the personal data a company or organisation has about you” and are entitled to “a copy of your data, free of charge, in an accessible format”, with a reply required within one month. Second, the right to erasure, often called the right to be forgotten: “if your personal data is no longer needed or is being unlawful then you can ask for your data to be erased”, a right that extends to asking search engines to delist pages about you under certain conditions. The guidance is honest about a real limit: some data may not be erased where doing so would conflict with other rights, such as freedom of expression, or a genuine public interest in information about a public figure.

France’s data protection authority, the CNIL, describes the same family of rights in practice: the right of access, the right to have incorrect data corrected, the right to object to processing, and the right to erasure. Its guidance is direct about how to start: contact the organisation holding your data yourself; if it does not respond adequately, you can bring the matter to the CNIL, which can investigate and, if warranted, sanction the organisation. In practice, exercising this against a data broker usually means identifying which broker holds your data and sending a written request, since no single portal covers every company at once.

California: a single request to hundreds of brokers at once

California has built something the EU has not: a state-run tool aimed specifically at data brokers. The California Privacy Protection Agency’s Delete Request and Opt-out Platform, DROP, lets a California resident “send one request to over 600 registered data brokers” asking them to delete the personal information they hold and stop selling it, without having to contact each broker individually. Under the agency’s published timeline, the platform launched on 1 January 2026, brokers began processing requests from 1 August 2026, and by November 2026 all registered brokers must have completed their first cycle and be deleting matched data on a recurring basis — the agency states data must be deleted every 45 days. Verification runs through California’s Identity Gateway, and the agency notes that “you do not need to create a California Identity Gateway account, and your information is not retained by DROP.” This is a California-resident tool: it does not reach brokers who never registered with the state, and it does not extend rights to people outside California.

The United States federally: narrower, and mostly manual

The US has no single federal law giving a general right to access or delete data held by any broker, the way the GDPR does. The FTC’s consumer guidance on people search sites — a visible category of broker — is candid about what this means in practice: you can generally “do it on your own, one by one, for free, or pay a service to opt out for you”, searching for your name on each site and following that site’s own removal process. The same guidance warns that even a successful opt-out “might not fix all your privacy concerns”, since your information can still appear in reports built around your relatives. Separately, the FTC does offer a genuinely useful narrower tool: its guidance on stopping unwanted mail explains that consumers can opt out of prescreened credit and insurance offers, built from lists supplied by the major credit bureaus, for five years or permanently through the dedicated optoutprescreen.com service — though it also notes plainly that this “will not stop all unsolicited offers”, since other lists exist outside that system.

Where you areWhat you can ask forRealistic limit
EU (GDPR)Free access to your data within one month; erasure where data is unnecessary or unlawfully heldErasure can be refused where another right, like free expression, applies
France (CNIL)Access, correction, objection and erasure, enforced by the CNIL if a company does not complyYou generally contact each organisation yourself before escalating
California (DROP)One request reaching over 600 registered brokers to delete and stop selling your dataOnly covers brokers registered with California, and only for California residents
US federallyOpt out of prescreened credit/insurance offers; ask people search sites individually to remove youNo general federal right to access or delete broker data; opt-outs are per-site

Key takeaways

  • Under the GDPR, you can request a free copy of your data within one month, and ask for erasure, though some data can be legally retained.
  • CNIL guidance recommends contacting the organisation directly first, then escalating to CNIL if it does not respond adequately.
  • California’s DROP platform lets residents send one deletion request to over 600 registered data brokers, but only covers brokers registered in California.
  • The US has no general federal right to access or delete broker data; people search site opt-outs are done one site at a time.
  • Opting out reduces future exposure; it does not retroactively remove data a broker already sold to someone else.

Check yourself

  1. 1. Under the GDPR, how long does an organisation generally have to respond to an access request?

    • One week
    • One month — Right.
    • One year
    • There is no deadline

    The European Commission’s official guidance states organisations must reply to an access request within one month.

  2. 2. What does California’s DROP platform let a resident do?

    • Sue a data broker directly
    • Send one deletion and opt-out request to over 600 registered data brokers at once — Right.
    • Force every company worldwide to delete their data
    • Only view which brokers exist, without contacting them

    DROP is designed so a single request reaches all data brokers registered with California at once, rather than contacting each one individually.

  3. 3. Why might opting out of a people search site not fully protect your privacy, according to the FTC?

    • Because opting out is illegal
    • Because your information may still appear in reports connected to your relatives — Right.
    • Because opt-outs are processed instantly with no gaps
    • Because people search sites do not use public records

    The FTC notes that removing your own listing does not necessarily remove references to you that appear in relatives’ reports.

  4. 4. What does the FTC’s prescreened offer opt-out (optoutprescreen.com) actually stop?

    • All marketing mail from every company
    • Prescreened credit and insurance offers based on major credit bureau lists — Right.
    • Data brokers from operating
    • Text message marketing

    The FTC is explicit that this opt-out only covers offers built from credit bureau lists, not every unsolicited offer.

Do it with FireAI

Put this lesson into practice on your own Mac.

Sources

Put it into practice on your Mac

Try every feature free for 17 days, no card needed.

Download for Mac Docs