Our Methodology
How we research data brokers, document opt-out procedures, and build tools for privacy protection.
Data Broker Research
PrivacyFix researches data brokers through direct examination of their public-facing websites, privacy policies, and opt-out procedures. Our broker profiles are built from:
- Direct website review: We visit each data broker's site to document what data types they collect, sell, or display.
- Opt-out testing: We test opt-out procedures for difficulty, time required, and effectiveness.
- Privacy policy analysis: We review each broker's privacy policy to understand data sources, use cases, and consumer rights.
- State regulatory filings: For states with data broker registration requirements (Vermont, California, Texas), we reference official registries.
- Consumer reports: We track publicly reported experiences from privacy advocates, journalists, and researchers.
Difficulty Ratings
Each broker's opt-out difficulty is rated on a 1–5 scale based on:
- Process complexity: Number of steps required, account creation requirements, form complexity.
- Verification burden: Whether the broker requires email verification, identity verification, or physical mail.
- Time investment: Estimated minutes to complete a single opt-out.
- Re-opt-out frequency: How often the opt-out must be renewed (some brokers re-populate removed records).
Privacy Audit Tool
The Privacy Audit questionnaire creates a personalized action plan by asking about your public profile size, the sensitivity of your information, and your threat model. The recommendations are based on documented opt-out effectiveness for each data broker category and the estimated effort-to-impact ratio for different actions.
No personal information entered into the audit is stored or transmitted. All processing happens in your browser.
Opt-Out Tracker
The Opt-Out Tracker stores your progress data locally in your browser using localStorage. No account is required. Your tracker data never leaves your device.
State Rights Database
State privacy rights information is researched from enacted state legislation (CCPA/CPRA, VCDPA, CPA, etc.) and state attorney general guidance documents. We update this database when new state laws take effect or when significant amendments are enacted.
Research Methodology
Our broker research follows a structured process. For each data broker, a researcher visits the broker's public-facing website to document what data categories they collect and sell, then navigates the opt-out process to document each step, time required, and any verification barriers. Privacy policies are read in full to identify data sources, sharing practices, and consumer rights disclosures. For brokers operating in states with registration requirements (Vermont's Act 171, California's Delete Act), we cross-reference official state registries to verify the broker's registration status and any disclosed data categories. This multi-source approach produces profiles that reflect real consumer experience rather than marketing claims.
Update Schedule
We review and update broker profiles on a rolling basis. High-profile brokers and those with frequently changing opt-out procedures are reviewed more often. State privacy rights information is updated when new state laws take effect or when significant amendments are enacted. Each broker profile and state rights entry includes a "last verified" date so users can assess data freshness.
Corrections and data issues
If a broker opt-out URL, difficulty score, method string, or state-rights count looks wrong, email hello@getprivacyfix.com or use the data-corrections contact route. Include the page URL, the field you believe is incorrect, and a link to the broker's current policy or registry entry when you have one.
We aim to acknowledge reports within a few business days. Confirmed fixes are applied at the source layer when the catalog or state table is involved, then republished. Material published changes are listed on the public data changelog - we record only changes we can corroborate from git or documented editorial action, never backfilled entries.
Limitations
- Data broker opt-out procedures change frequently, guides may become outdated between update cycles.
- Effectiveness of opt-outs varies, some brokers reliably honor removals, others re-populate records from other sources.
- New data brokers emerge constantly. PrivacyFix's listed catalog currently covers 101 brokers with a published opt-out URL (vintage July 2026). That is this catalog, not a census of every US data broker.
- State privacy laws evolve rapidly, verify current law with official state sources for legal purposes.
- Difficulty ratings are subjective assessments based on our testing experience; individual experiences may vary.
Editorial Workflow
Content on PrivacyFix is compiled by our editorial process from official source data. Structured data (broker registries, state statute references, opt-out step counts, FTC enforcement case IDs) is ingested and normalized programmatically; narrative framing, opt-out walkthroughs, guide text, and rankings commentary are drafted and reviewed by our editorial team before publication. We follow Google Search Central guidance (Danny Sullivan, February 2023; reaffirmed 2024) on disclosed editorial workflow. The templates, methodology and written guides are human-reviewed before publication; the generated data pages are not reviewed one by one, and we would rather say so than imply a level of individual review that a corpus this size does not receive. We do not accept payment from any data broker, privacy service, VPN provider, or other covered entity for coverage, placement, or rankings - "difficulty" ratings and service comparisons are computed from our own opt-out testing and public documentation.
Listed-broker catalog CSV
The same listed-broker table that powers /statistics is published as a free CSV at /data/privacyfix-broker-catalog.csv (CC0). Rows are one catalog entry each with category, difficulty score, estimated form time, opt-out method, published opt-out URL, and whether PrivacyFix has a dedicated guide. Counts are this catalog, not a market census. When reusing the table, name PrivacyFix as the compiler.
Not Affiliated
PrivacyFix is not affiliated with any data broker, privacy service provider, state attorney general's office, or government agency. We are an independent privacy education and tools portal.
Revenue diversification readiness
This section documents what is productized today for reuse or licensing, how affiliates may appear if activated, and which alternative monetization paths are paperwork-ready. It is a readiness assessment only; nothing here activates new revenue without operator sign-off.
Downloadable and citable assets today
- Listed-broker catalog CSV at /data/privacyfix-broker-catalog.csv (CC0-1.0). One row per catalog entry with category, difficulty, method, opt-out URL, and guide link.
- Dataset JSON-LD on the homepage, methodology, statistics, about, and research pages declares the same catalog extract with
isBasedOnpointing here. - CiteThis boxes on home, rankings, guides, research, and tools hubs for one-click attribution of specific pages.
- Not yet productized: no bulk API endpoint, no embeddable chart iframe product, no paid data-licensing terms page. [operator] must approve pricing, API keys, and partnership terms before any launch.
Attribution ask: when reusing the CSV or citing a table, name PrivacyFix as the compiler and link to the source page or methodology. The CC0 license does not require permission, but attribution supports honest reuse.
YMYL-safe affiliate placement rules (if activated)
PrivacyFix is a consumer-privacy (M-YMYL) portal. If the operator ever enables affiliate units beyond the existing disclosure prose:
- Allowed page types: rankings comparison pages (VPN, password managers) and paid-vs-DIY guides where the user is already evaluating a purchase, never adjacent to step-by-step opt-out instructions, state-rights legal explainers, or breach-check results.
- Labeling: every paid link carries a visible affiliate disclosure; no disguised buttons inside procedural steps.
- Density: same Module 36 ceilings as display ads, with no affiliate block above the first actionable opt-out step on guide pages.
- Editorial firewall: affiliate relationships do not change difficulty scores, broker coverage, or DIY-first recommendations (already stated in the editorial workflow above).
Alternative ad-network eligibility (paperwork only)
- Google AdSense: portal is in
GETTING_READYreview queue; no manual ad slots are enabled pre-approval. - Mediavine Journey: requires ~1,000 real sessions per 28-day window. PrivacyFix measured 6 real / 21 raw sessions in the latest GA4 real-traffic snapshot (2026-08-31), so it is not eligible today. Re-check when real sessions cross the threshold. [operator] applies to network enrollment.
- Data licensing / API: CSV + Dataset schema are the passive product surface; any commercial API or white-label embed requires [operator] pricing, terms of use, and legal review before publication.
Frequently Asked Questions
Where does PrivacyFix's data broker information come from?
Each broker profile is built from firsthand research: a member of our team visits the broker's public-facing site, walks through the opt-out process end-to-end, and documents every step, verification requirement, and time delay. Where states maintain official data broker registries (Vermont Act 171, California's Delete Act registry), we cross-reference the broker's registered status, data categories, and opt-out contact of record. FTC enforcement actions and state attorney general privacy settlements are pulled from the agencies' public case databases.
How often are opt-out guides updated?
Data brokers change their opt-out processes frequently, sometimes within weeks. We review high-profile brokers (Spokeo, Whitepages, BeenVerified, Intelius, MyLife, Radaris, TruePeopleSearch, FastPeopleSearch, USPhonebook, PeopleFinders) on a rolling basis and re-verify steps whenever a reader reports a broken procedure. Each guide includes a "last verified" date; if a broker has revised their flow since then, the underlying logic of the guide still applies but the exact button labels may differ.
Does PrivacyFix earn money when I use a paid privacy service?
Some links to paid privacy services (DeleteMe, Incogni, Optery, etc.) are affiliate links, which means PrivacyFix may receive a commission if you subscribe, at no additional cost to you. Affiliate relationships do not influence which services we cover, how we rate them, or whether we recommend DIY over paid. Our default recommendation across the site is the free DIY path; paid services are presented as an alternative for users who prefer to outsource the work.
Is PrivacyFix legal advice?
No. PrivacyFix explains how U.S. state privacy rights work (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, and newer state laws) and documents procedures for exercising those rights, but we are not attorneys and PrivacyFix does not provide legal advice. For legal questions, particularly around deceased-relative records, business-purpose data sales, or disputes with a data broker that refuses an opt-out, consult a licensed attorney in your state or contact your state attorney general's privacy unit.