Home  /  Blog  /  Digital discretion
Founder’s analysis · Part 8 of the series

How to remove yourself from data broker databases and stay off them

  ·  6 min read  ·  8 min listen
Robert Václavík — Bodyguard Group ®
Listen to the articleaudio version0:00 / 8:08

Anyone who thinks their personal data sits in just one system is usually wrong. I see it much as I did in the instalment on home networks: a house with several side doors, where you lock one and another stays open. That is why getting removed from broker databases is not a matter of a single click but an ongoing, disciplined process.

First find your own trail, or you are cleaning up blind

Whether I am starting with a client or with myself, the first step is not an erasure request. I begin by mapping where the data actually turns up. I search for the name, the name plus the city, the phone number and the email address, including exact-phrase searches in quotation marks. Without that map, you are simply hoping something is disappearing without knowing what.

As I define it, a data broker is a company that collects and sells personal data about people it has no direct relationship with. It is not an online shop where you are a customer. It is someone who has gathered your trail from other sources and turned it into a commodity. People-search sites are the public shop window of this business, where anyone can look the data up.

Typically this means your name, addresses, date of birth, phone number, email address, family connections, employment, property records, purchasing behaviour and inferred profiles. In the US, a Social Security number is often included as well. The more of these fragments that gather around you, the easier it becomes for someone to piece together the full picture.

In Europe, your defence rests on Article 17 of the GDPR, not on a single button

If you are in the Czech Republic, or anywhere else in the EU, Article 17 of the GDPR gives you an enforceable right to erasure of your personal data, although that right is not absolute. I do not oversell it as a miracle cure, but it is a strong legal tool. The controller must respond without undue delay and within one month at the latest; in more complex cases, that deadline can be extended by a further two months.

In practice, this means a short request sent to the company’s data protection contact, or submitted through a form on its website. I state that I am exercising my right to erasure under Article 17 of the GDPR and ask them to confirm exactly what they will delete. The shorter and more factual the request, the less room there is for fudging.

It is worth being blunt, though: the right to erasure is not absolute. There are exceptions, such as freedom of expression, compliance with a legal obligation and the public interest. Data from public registers, court files, the land registry or licensed professional directories is much harder to remove, if it can be removed at all. Here it pays to have sober expectations rather than illusions.

Deal with each people-search site separately, or you will go round in circles

In the EU, there is no central point where you can file one request and have everything disappear at once. In practice, you have to approach each broker and each people-search site individually. Each has its own form, its own verification and its own deadline. It is tedious, but that is the reality.

On the large people-search sites, such as Whitepages, Spokeo, BeenVerified, Radaris and Intelius, opting out is usually free, but the process differs every time. These sites mainly cover US records, so they are chiefly worth tackling if you live, own property or do business in the United States. Whitepages, for example, requires phone verification, which means handing over your number there and then. If you do not want to leave yet another trace, use a separate or disposable number.

I think of it as a service entrance. If I have to go through it, I do not want to open up the whole house in the process. It pays to keep a record of whom you wrote to, what they asked of you and when the next check is due. Without that discipline, erasure becomes a one-off exercise with nothing to show for it.

How to remove yourself from data broker databases and stay off them
Without a record of the requests sent and their deadlines, erasure is never seen through.

Erasure is not a one-off job but maintenance that has to be repeated

The biggest mistake is to think that one request settles the matter for good. It does not. Brokers acquire the data again from public and commercial sources and republish it in their databases. That is why services that repeat the erasure in cycles, roughly every 60 to 90 days, make sense.

Paid bulk removal services can send opt-out requests to dozens or even hundreds of brokers on your behalf. Some work manually, others automatically. The main differences tend to be how many sites they cover and whether they let you submit your own erasure requests beyond their list of brokers. I do not see them as a substitute for thinking, but as ongoing maintenance.

Even these services are not 100 per cent effective. They will not cover every broker, they will not reach new or foreign sites outside their list and they will not solve the problem overnight. To put it simply, they are a better lock, not walls reaching to the sky. You still need to know what you actually have under control.

The key is to cut off the supply of new data before anyone can collect it

When I help someone reduce their data broker trail, I do not only look backwards at erasure. Closing off new sources matters just as much: fewer public profiles, caution with loyalty schemes, competitions and forms, and separate email addresses and phone numbers for different purposes. The less data you release, the less anyone can collect.

A physical analogy works well for me here. It is like not wanting the service door left ajar all day. Locking a single door is not enough; you have to watch where fresh traffic is getting in. Data is no different: removal without limiting collection only puts you back where you started.

That is why I also recommend regular reviews. Set yourself a reminder and check again: every three months if no service is handling erasure for you on an ongoing basis, otherwise twice a year is enough. Not because it is dramatic, but because that is how maintenance works. Just as you check your locks, your digital trail needs to be kept under watch.

Conclusion: you can keep your trail under control without drama, but not without discipline

In short, you will not erase yourself from the brokers once and for all, but you can shrink your trail considerably. I would start with the map, move on to GDPR requests, then work through the people-search sites and finally set up regular maintenance. It is a process built on order, not on impressions.

California’s Delete Act, and the central DROP platform it set up, are often cited as a sign of where legislation is heading abroad. For a reader in Europe, however, only one thing matters: it is an example of the direction regulation is taking elsewhere, not a tool you can use on this side of the Atlantic. For you, the GDPR and individual opt-outs remain what counts.

If you wish, I can help you go through your specific trail and put together a plan, with no wasted words. I call it digital housekeeping. It is not a one-off intervention but sensible maintenance that gives you back control over what remains out there about you.

“Getting removed from broker databases is not a one-off trick. It is regular maintenance of your own trail.”— Robert Václavík

Part of the digital discretion series

Step by step, we are looking in depth at everything raised in the opening Digital Exposure test. Published so far:

Found this useful?Share it
Share on Facebook

Would you like to discuss your digital discretion face to face?

For yourself, your family or your company, discreetly and tailored to your situation. The first consultation is confidential and without obligation.