Privacy & Data

Data broker removal (including California's DROP platform), privacy regulators, privacy laws, direct company privacy-request portals, and recent data breaches — for the US and UK, with EU and Australia coverage limited to what supports our existing privacy generators.

← All free resources

Privacy problems split into genuinely different questions — is your data listed by a data broker, do you need to complain to a regulator, what does the law actually require, how do you reach a specific company's own privacy team, or has your data already been exposed in a breach? This directory keeps those apart deliberately. Some organizations (the FTC, the ICO) appear more than once because they serve a different purpose in each section, not because of a duplicate.

Regulator coverage is primarily US and UK. EU and Australia entries are limited to what supports the jurisdiction branches of our existing privacy generators, not a full EU/AU directory.

Need to act in writing right now? Use our free GDPR Rights Request Generator (EU/UK), GDPR Violation Report Generator (EU/UK), or Privacy Complaint Letter Generator (Australia).

Where your information is listed for sale, and how to get it taken down. Removal is not permanent — most listings can reappear within 3-6 months as brokers re-aggregate public records, so treat this as ongoing maintenance, not a one-time fix.

See which data brokers are registered in California

California Privacy Protection Agency — Data Broker Registry cppa.ca.gov/data_broker_registry →

What: The official public list of every data broker registered to operate in California, filterable by what data they collect and who they sell it to.

When to use: To see the scale of the data broker industry, or to check whether a specific broker you've found is actually registered.

Submit one deletion request that reaches every registered California data broker

California DROP (Delete Request and Opt-Out Platform) privacy.ca.gov/drop →

What: This is genuinely the highest-value entry in this section. DROP has been live since 1 January 2026 and lets California residents submit a single deletion request that reaches every data broker registered in the state — over 600 of them — instead of opting out one by one. Brokers are required to process requests every 45 days starting 1 August 2026. Verify your residency through the California Identity Gateway, create a profile, and submit one request; status updates can take up to 90 days to appear. The actual request tool is at consumer.drop.privacy.ca.gov.

When to use: If you're a California resident, start here before opting out of individual broker sites one at a time.

Remove a specific listing from Whitepages

Whitepages — Suppression Requests whitepages.com/suppression-requests →

What: Whitepages' own removal form. Submit the exact URL of your listing (not a search-results page) and complete phone verification; most listings come down within 24-48 hours.

When to use: When your specific listing appears on Whitepages and you have the exact profile URL to submit.

Remove a specific listing from Spokeo

Spokeo — Opt Out spokeo.com/optout →

What: Spokeo's official opt-out page. No account or payment required — submit the listing URL and confirm by email; processed within 24-48 hours.

When to use: When your specific listing appears on Spokeo. Each listing needs its own separate opt-out.

Remove a specific listing from BeenVerified

BeenVerified — Opt Out beenverified.com — opt-out search →

What: BeenVerified's opt-out flow — search for your listing, request removal, then confirm via the verification email. Typically processed within 24-72 hours.

When to use: When your specific listing appears on BeenVerified.

Remove a specific listing from TruePeopleSearch

TruePeopleSearch — Removal truepeoplesearch.com/removal →

What: Copy the exact URL of your listing, submit it on the removal page, and confirm via the emailed link within 24 hours; removal follows within 72 hours.

When to use: When your specific listing appears on TruePeopleSearch.

Remove a specific listing from Radaris

Radaris — Privacy Controls radaris.com/control/privacy →

What: Submit your name, city, state, and profile URL to request removal, then confirm via the emailed link; typically removed within 24 hours of confirmation.

When to use: When your specific listing appears on Radaris.

Remove your personal information from Google search results

What: Official free Google tool that monitors whether your phone number, home address, or email appears in search results and lets you request removal directly.

When to use: If you search your own name and find your mobile number or address publicly visible in results — a different problem from a data broker profile, since Google isn't the original source.

Want to know more? Read our full guide →

Check whether your email or data has appeared in a known breach first

Have I Been Pwned haveibeenpwned.com →

What: Also covered in Section 5 below, but worth checking here too — useful context before you start broker removal, since a breach can be a separate source of exposure from what data brokers have aggregated.

Want to know more? Read our full guide →

Who to complain to when a company has mishandled your data — mapped to the jurisdiction branches of our privacy generators below (US, UK, EU-by-country, Australia).

Report a US company for violating its own privacy policy or federal privacy rules

Federal Trade Commission (FTC) ftc.gov →

What: The FTC handles complaints about companies that violate US privacy laws, including unauthorized data sharing and deceptive data practices — under its Section 5 authority (see Section 3 below).

When to use: When a US company has misused your personal data or violated its own stated privacy policy.

Want to know more? Read our full guide →

File the actual complaint with the FTC

FTC Complaint Assistant reportfraud.ftc.gov →

What: The FTC's own complaint portal. The FTC doesn't resolve individual complaints directly, but reports feed its enforcement priorities.

When to use: After you've identified the issue and want it on record with the FTC.

Report a GDPR data protection violation in the UK

ICO — Information Commissioner's Office ico.org.uk →

What: The UK's data protection regulator. Accepts complaints about GDPR violations, unlawful data processing, and companies that ignore data deletion requests.

When to use: When a company has mishandled your data, refused a deletion request under your right to erasure, or failed to notify you of a breach.

Want to know more? Read our full guide →

Australian Privacy Complaint & Data Removal Resources

OAIC, Google Removal & the eSafety Commissioner (Australia) oaic.gov.au →

What: The three Australian paths for a privacy problem — the OAIC for a formal complaint against a company, Google's form for removing personal information from search results, and the eSafety Commissioner for image-based abuse.

When to use: Use this when a company has mishandled your personal data, your information appears in Google search results, or you need to report non-consensual imagery or serious cyberbullying. These are not equivalent legal mechanisms: the OAIC path is a formal legal complaint process under the Privacy Act 1988; Google's removal form is a discretionary company policy, not a legal right in Australia; and the eSafety Commissioner has genuine statutory takedown power for image-based abuse.

Official pathways:
OAIC — Lodge a Privacy Complaint (legal complaint) →
Google — Personal Information Removal Request (discretionary policy) →
eSafety Commissioner — Report Image-Based Abuse (statutory takedown power) →

Not sure which path? Run the free checklist → Want to know more? Read our full guide → Want to know more? Read our full guide → Generate the OAIC pre-complaint letter →

EU GDPR Rights & Data Protection Authority Resources

European Data Protection Board (EDPB) — Member DPAs Directory edpb.europa.eu — member DPAs →

What: The official EU pathways for enforcing GDPR rights — the EDPB directory listing every national Data Protection Authority (you always file with your own country's DPA, which coordinates with the company's lead authority via the One-Stop-Shop), plus direct links to major national DPAs: Spain's AEPD, France's CNIL, and Italy's Garante.

When to use: Use this to file a GDPR complaint, find your national Data Protection Authority, exercise your rights of access or erasure, or report a serious GDPR violation as a whistleblower.

Official pathways:
EDPB — Member DPAs Directory →
AEPD (Spain) →
CNIL (France) →
Garante (Italy) →

Not sure which DPA, or whether your deadline actually passed? Run the free checklist → What data does a company hold on you? (Right of Access) — Read our full guide → Ask a company to delete your data (Right to Erasure) — Read our full guide → File a GDPR complaint, step by step — Read our full guide → Which Data Protection Authority to contact — Read our full guide → Report a GDPR violation (whistleblowers & consumers) — Read our full guide → Generate a GDPR access/erasure request → Generate a GDPR violation report →

Cross-cutting reference material for the whole block — the underlying legal text, kept brief and factual rather than tied to a specific tool.

Read the GDPR itself

General Data Protection Regulation (Regulation (EU) 2016/679) eur-lex.europa.eu — CELEX:32016R0679 →

What: The official full text of the GDPR via EUR-Lex, the EU's own legal database — used consistently across this site as the reference source for GDPR's actual text.

UK's version of GDPR

UK GDPR / Data Protection Act 2018 legislation.gov.uk/ukpga/2018/12 →

What: The official UK legislation that retained and adapted GDPR after Brexit, alongside the UK's own data protection framework.

California's privacy law, explained by the state itself

California Consumer Privacy Act (CCPA) / CPRA oag.ca.gov/privacy/ccpa →

What: The California Attorney General's official CCPA/CPRA page — covers the right to know, delete, opt out of sale/sharing, correct, and limit use of sensitive data. CPRA amends the CCPA; it isn't a separate law.

The law behind the DROP tool in Section 1

California Delete Act (SB 362) leginfo.legislature.ca.gov — SB-362 →

What: The 2023 law requiring data brokers registered in California to implement an accessible, single-request deletion mechanism — this is what DROP (Section 1) actually implements.

The US federal authority behind FTC privacy enforcement

FTC Act, Section 5 — Unfair or Deceptive Acts or Practices ftc.gov — privacy & security enforcement →

What: The FTC's own page explaining how it uses Section 5's prohibition on unfair or deceptive practices as its core authority over privacy and data security — the general federal backstop since the US has no single comprehensive federal privacy law.

Check if your state has its own privacy law

IAPP — US State Privacy Legislation Tracker iapp.org/resources/article/us-state-privacy-legislation-tracker →

What: Independent, frequently updated tracker of all US state comprehensive privacy laws — which states have one, what rights they grant, and current status.

When to use: To check whether your state gives you rights to access, correct, or delete your data beyond what CCPA gives California residents.

Want to know more? Read our full guide →

Request any company to delete all your personal data

What: Under UK/EU GDPR, a company must delete all personal data it holds about you within one month of a written request (extendable to three for complex requests). Under CCPA, California residents have a comparable right.

When to use: To remove your data from any company's database — send a written request stating you are exercising your right to erasure.

Want to know more? Read our full guide →

The direct privacy-request portal for each company — not a generic help center — so you don't have to search for it. Verified as of 29 August 2026; a company is listed here only when its actual data-request page could be confirmed.

Request your data or exercise privacy rights with Meta (Facebook/Instagram)

Meta Privacy Rights Request Form help.meta.com/support/privacy →

What: Meta's dedicated privacy-rights request channel covering Facebook, Instagram, and Messenger — access, deletion, correction, and opt-out of targeted advertising.

Download or manage your Google data

Google Account — Data & Privacy myaccount.google.com/data-and-privacy →

What: Google's own account section for downloading your data (via Google Takeout) or deleting specific activity and data — requires signing in.

Request your personal information from Amazon

Amazon — Request Your Personal Information amazon.com — request your data →

What: Amazon's direct data-request page — select the information you want, confirm via email, then download it through a secure link.

Manage your Microsoft privacy data

Microsoft Privacy Dashboard account.microsoft.com/privacy →

What: Microsoft's account privacy dashboard for viewing and clearing cloud-saved data. For requests beyond what the dashboard covers, Microsoft's privacy support form is at aka.ms/privacyresponse.

Request a copy of your Apple data

Apple — Data & Privacy privacy.apple.com →

What: Apple's dedicated portal (launched for GDPR) to download a copy of the personal data Apple holds — sign in with your Apple ID and two-factor authentication.

Download your LinkedIn account data

LinkedIn — Get a Copy of Your Data linkedin.com/psettings/member-data →

What: LinkedIn's direct data-export settings page — select specific data categories (delivered within minutes) or your full archive (within 24 hours).

Exercise a privacy request with TikTok

TikTok — Privacy Rights Request tiktok.com/legal/report/privacy →

What: TikTok's dedicated privacy request channel — access, correction, or deletion of the data it holds, plus a direct link to download your data from within the app.

Download your data archive from X (Twitter)

X — Download an Archive of Your Data x.com/settings/download_your_data →

What: X's direct settings page for requesting a full archive of your account data — confirm your password, request the archive, and download it within 7 days of the email arriving.

Scope note: this section is not a complete historical record and covers only the most recent, significant breaches — roughly the last 6-12 months as of this page's last update (29 August 2026). It needs periodic review; a breach that happened after that date won't yet appear here.

Check if your email or password was stolen in a data breach

Have I Been Pwned haveibeenpwned.com →

What: The primary consumer tool for this entire section. Free database by security researcher Troy Hunt — enter your email or phone number to see if it appeared in any known breach.

When to use: After a suspicious login email, or every 6 months as a routine check. If your email appears, change that password immediately.

Want to know more? Read our full guide →

Browse every breach loaded into Have I Been Pwned

Have I Been Pwned — Who's Been Pwned haveibeenpwned.com/PwnedWebsites →

What: A browsable, searchable list of every breach HIBP has loaded, including the data types exposed in each.

Suno (AI music platform) — ~55.3 million accounts

What: A breach that occurred in November 2025 but was only publicly disclosed and loaded into HIBP on 20-21 July 2026, exposing 55.3 million accounts. Exposed data included phone numbers and, for some users, Stripe purchase records with names, addresses, and partial payment card details (card type, expiry, last 4 digits). An attacker used compromised employee credentials to reach internal systems.

RingCentral — ~1.6 million accounts

What: The ShinyHunters extortion group breached RingCentral in July 2026 via a voice-phishing (vishing) attack on an employee, then published data on roughly 1.6 million accounts — names, email addresses, physical addresses, and phone numbers — after an extortion attempt, with disclosure in mid-August 2026.

Panera Bread — 5.1 million email addresses among 14 million exposed records

What: Occurred in January 2026, also attributed to ShinyHunters, via a compromised Microsoft Entra single-sign-on code. 14 million records were stolen — but that figure counts records, not unique individuals; HIBP confirmed 5.1 million unique email addresses were actually exposed, along with names, phone numbers, and physical addresses.