Checklist for data broker opt-out with identifiers, confirmation, and monitoring steps. Data broker search, identity proof, opt-out, confirmation, suppression, monitoring, and record checklist
Image: Privacy Notes

Maintenance

Part of Data broker privacy guide: collection, profiles, people search, marketing lists, risk, opt-outs, and monitoring

Data broker search, identity proof, opt-out, confirmation, suppression, monitoring, and record checklist

Work a broker opt-out like a case file: proof of identity under NIST concepts, a numbered request record, California DROP routing, and 30/90-day checks.

What to take away

  • Give every request an ID you assign yourself, so a confirmation email is never the only proof you filed.
  • Ask what proof of identity is actually required before sending a document; the minimum is usually an email or listing ID already on file.
  • In California, requests to registered data brokers can be routed through DROP rather than the broker's own form.
  • Recheck high-risk listings at 30 and 90 days; reappearance is common and usually arrives under a new profile ID.

Start with the request ID, not the form

Data broker search, identity proof, opt-out, confirmation, suppression and monitoring all start with a number you assign yourself. Format it as YYYYMMDD-broker-slug-01, for example 20260915-acmepeople-01. The date is the day you submit, the slug is the broker's domain without the suffix, and the counter tracks repeat attempts against the same broker.

Request ID format and placement

  1. Assign ID before opening broker site
  2. FormatYYYYMMDD-broker-slug-01
  3. Date = submission day
  4. Slug = broker domain without suffix
  5. Counter tracks repeat attempts
  6. Place in log, request, filenames

The ID goes in three places: your own log, the subject line or free-text field of the request, and the filename of every document you save. When a broker replies six weeks later with no reference number of its own, your ID is what ties the reply back to the request.

Build the identifier set you will search with

Search only with identifiers you are willing to see in a result. A signed-out browser session and a small number of deliberate combinations beat a broad sweep.

Identifier search checklist

  • Current and former legal names, initials, misspellings
  • Current and former cities or ZIP codes
  • Current and retired email addresses
  • Current and recycled phone numbers
  • Known listing IDs and profile URLs
  • No passwords, codes, or full account numbers

Work from a short list of identifiers. Personal: full name, prior names, current and former cities, ZIP code, phone numbers, email addresses, and usernames. Records: county property and voter files, court dockets, and business registrations. Breach checks: an email lookup on a service such as Have I Been Pwned.

People-search listings turn up on Spokeo, Whitepages, BeenVerified, Radaris, TruthFinder and Intelius. Larger consumer data brokers such as Acxiom, LexisNexis and Epsilon rarely appear in a web search. California's Data Broker Registry lists the brokers registered in that state.

Record the direct result URL, the date, the visible fields, and how confident you are in the match. Mark anything you cannot confirm with two non-secret fields as Possible, not Confirmed. Merged records, recycled numbers, and shared addresses are the usual causes of a false match.

Judge the identity proof before you send it

Identity evidence creates its own exposure. NIST's identity-proofing guidance sets out the concepts worth borrowing when you question a broker's process: resolution, evidence validation, verification, protected channels, and data minimization. A private broker is not obliged to follow that standard, and nothing here says what you must hand over.

Ask the broker four things in writing before uploading anything:

Questions before sending identity proof

  • Is email, phone, or listing ID enough?
  • Which document types and fields are required?
  • Can non-essential fields be masked or redacted?
  • What are purpose, access, retention, deletion terms?
  1. Which document fields do you need, and what will you compare them against?
  2. How long will you keep the copy, and how will you delete it?
  3. Which staff and contractors can see it, and who else receives it?
  4. What alternative verification do you accept if I decline to send a document?

If the answers are vague, ask for an alternative verification route. Keep the minimum proof, and delete working copies within 30 days of the final reply.

Route the request through the right channel

California publishes instructions for submitting a privacy request that cover preparing the request, submitting to the business, reviewing the response, and the complaint options if it stalls. The same page identifies DROP, the Delete Request and Opt-Out Platform, as the route for requests to data brokers registered in California.

Choose request channel

Is the person in California?

Yes

Use DROP for registered brokers

No

Use broker form or email

DROP matters because it removes one failure point: you are not relying on each broker's own form to accept your request. The page applies to California rights and processes, and it does not create the same rights in other jurisdictions. Confirm the person's jurisdiction and the governing rules before choosing a route.

The confirmation record

Keep one row per request. The numbered columns are the ones that make the record usable a year later.

#FieldWhat goes in it
1Request IDYour own ID, for example 20260915-acmepeople-01.
2Submission dateThe date, your time zone, and the channel's own reference.
3ChannelBroker form, DROP, email, or post, with the address or URL used.
4Action requestedAccess, correction, deletion, suppression, or opt out of sale and sharing.
5Proof sentWhat you uploaded, which fields were masked, and the date.
6ResponseThe broker's wording, the date it arrived, and any reference number.
7OutcomeRemoved, partly removed, refused, ignored, or still open.
8Recheck datesThe 30 day check, the 90 day check, and the next date you set.

Confirmation record fields

  • Request IDYYYYMMDD-broker-slug-01
  • Date and time submitted, with time zone
  • Channelbroker form, email, or DROP
  • Destination domain or address
  • Evidence supplieddocument types and fields
  • Broker reference number, if any
  • Stated response period
  • Statuspending, completed, partial, not found, denied, appealed

State the requested action precisely: access, correction, deletion, suppression, or opt out of sale and sharing. Include the listing URL or internal record ID. Ask whether the request covers future recollection of the same record, and avoid unsupported legal claims in the body of the request.

Test the outcome, then test it again

Open the direct listing URL in a fresh session. Repeat the original search. Check the aliases and old cities you listed at the start.

Outcome recheck schedule

  1. Immediately
    Open listing URL in fresh session
  2. Immediately
    Repeat original search and aliases
  3. 30 days
    Recheck high-risk results
  4. 90 days
    Recheck high-risk results
  5. Longer interval
    Set based on exposure level

Distinguish a real removal from a login wall, a broken link, a changed snippet, or a paywall. Note which fields disappeared and which remain, and whether the listing came back under a new profile ID.

Recheck high-risk results at 30 and 90 days, then set a longer interval based on how exposed the person is. Watch for new aliases, numbers, addresses, and profile IDs. Where you have authority over an upstream record, correcting it at the source reduces how often the listing regenerates.

Protect the archive itself

The log becomes a second copy of the person's identifiers. Encrypt it or put it behind access control. Remove redundant screenshots and ID copies on a written schedule.

A typical schedule: delete identity document images within 30 days of the final reply, keep masked evidence for 12 months, and keep the log for 12 months past the last recheck. Treat those numbers as typical, not as a legal rule.

For a stalking, harassment, identity theft, or fraud concern, move the matter to a safety response rather than an ordinary request queue. Report fraud to local police in the United States, and to the Canadian Anti-Fraud Centre in Canada, the second market this site covers.

For a legal question about what a broker owes you, ask a licensed lawyer. In Canada, the second market this site covers, the Office of the Privacy Commissioner and the relevant provincial commissioner take those questions.

For distress about an exposure, speak with a physician or registered clinician.

Common questions

Must I complete every item?

No. Choose what fits the risk, the jurisdiction, and the product. Safety procedures and legal steps can add requirements this list does not carry.

Can I mask a document before uploading it?

Only if the broker's verified process accepts a masked copy. Ask which fields are necessary, then follow the official instructions rather than sending a full document on the assumption it is expected.

What does "not found" mean?

It means the broker matched nothing against the information you supplied. It does not prove the broker holds no other record, and it does not prevent one arriving later.

How long should I keep the log?

Long enough to verify outcomes and to support a repeat request or a complaint, which is typically 12 months past the last recheck. After that, delete identity evidence within 30 days and keep only the record of what was asked and answered.

More in Maintenance

Latest from Guides Desk