Advertising Brokers. The Industry No One Sees

Part One — Who They Are

You never see them, but they know everything about you.

Name. Address. Income. Health. Political views. Sexual orientation. Religion. Financial difficulties. Family problems. Fears. Desires. Weaknesses.

They’ve never met you. You never gave them permission. But they have a profile on you — detailed, accurate, constantly updated. And it’s for sale. Right now. While you’re reading this.

These are advertising data brokers. Data brokers. And this is one of the largest industries in the world that ordinary people know almost nothing about.

Today we change that.

Let’s start with a question that seems simple.

Have you ever wondered where targeted ads come from?

Most people think something like this. Google saw I searched for sneakers — it shows me sneaker ads. Facebook sees I follow travel pages — it shows me flight ads. Logical. Understandable. One service, one platform, my data stays inside it.

Reality is structured differently. Fundamentally differently.

Behind every ad you see stands an entire ecosystem. Dozens of companies that have never interacted with you directly — but that collected, processed, enriched, and sold information about you. Before you ever saw that banner.

Advertising brokers are the intermediaries in this ecosystem. The invisible link between your data and those who want to reach you.

But calling them simply intermediaries is a significant oversimplification. Because they long ago outgrew the role of intermediary. They’ve become an independent industry with its own logic, its own products, its own clients — and its own power over the lives of billions of people.

Acxiom. The company that knows you better than you think.

Let’s start with the oldest and largest player.

Acxiom was founded in 1969 in the US state of Arkansas. Originally — a direct-mail company. It helped businesses send advertising letters to the right people. Ordinary direct marketing of that era.

But the founders had an insight that turned out to be prophetic. The value isn’t in the letters — it’s in the lists. Not in the advertising — in the data about the people it’s addressed to.

Over the following fifty years, Acxiom built the largest consumer database in the world.

Today the numbers look like this.

Acxiom holds data on approximately 2.5 billion people worldwide. That’s a third of the planet’s population. On average, 1,500 individual data points per person in the database. The company processes roughly 50 trillion data transactions a year. Its annual revenue exceeds $1.5 billion.

What exactly is stored in those 1,500 data points?

Acxiom publicly discloses some of its data categories — because the law requires it in a number of jurisdictions. The list is impressive.

Demographics — age, gender, marital status, number of children, their ages, education, occupation, income, housing type, owned or rented, property value, car ownership and makes.

Purchasing behavior — purchase history by category, brand preferences, price sensitivity, tendency toward impulse buying, loyalty-program participation, coupon use.

Interests and hobbies — sports, travel, books, music, cooking, gardening, pets, charity, religious activity.

Financial profile — credit cards, loans, investments, insurance, financial difficulties, bankruptcy history, court debt judgments.

Health — chronic conditions inferred from pharmacy purchases and search patterns, pregnancy, having a child with special needs, elderly relatives requiring care.

Psychographics — values, beliefs, political views, risk tolerance, anxiety level, openness to novelty versus preference for the familiar.

And that’s just what they disclose publicly. The real list is broader.

An important detail few people know. In 2013, under pressure from regulators, Acxiom launched AboutTheData.com, where Americans could view part of their profile. People who visited described it as a shock. The data was accurate. Sometimes frighteningly accurate. Including things they had never told anyone.

The service ran for a few years. Then it quietly shut down.

Experian. The company that decides whether you’ll get a loan.

Everyone knows Experian — as a credit bureau. But most people don’t know that the credit bureau is only one part of the business.

Experian was founded in the UK. It operates in 45 countries. Annual revenue — around $6 billion. It’s one of the world’s three largest credit bureaus — together with Equifax and TransUnion, they control the global credit-scoring market.

What is credit scoring, and why does it matter?

Every time you apply for a loan, a mortgage, a credit card, or an installment plan — the bank or financial institution pulls your credit score. A number from 300 to 850 in the American FICO system, with comparable scales in European systems. This number determines whether you get credit, and at what rate.

The score is calculated from your credit history. The history is held at the bureau. The bureau collects data from every financial institution you’ve ever dealt with.

But here’s what’s important to understand. Credit history is only Experian’s base product. Its additional business is far more interesting.

Experian sells marketing data. Consumer financial profiles. Behavioral analytics. Predictive models — who is likely to take out a loan in the next three months, who is experiencing financial difficulties, who is ready for a major purchase.

Experian also sells data to insurance companies. To employers, in jurisdictions where this is permitted. To government agencies.

And here’s what makes Experian especially influential. Unlike Acxiom, whose data is used predominantly for advertising, Experian’s data directly affects a person’s financial life. The score an algorithm calculates determines whether you get a mortgage. At what rate. Whether your credit card is approved. Whether you get hired — because in a number of countries, employers check credit history.

An error in Experian’s database — and errors happen — can cost a person years of a ruined financial reputation. Studies in the US show that around 25% of credit reports contain errors serious enough to affect the score. One in four.

People don’t know about these errors — until they get a loan denial.

Oracle Data Cloud. The corporate monster no one sees.

Oracle is a name most people associate with corporate databases and business software. A boring B2B company. Something for the IT departments of large corporations.

That’s exactly the impression Oracle wants to make on ordinary people. Because Oracle Data Cloud — the division dealing with consumer data — is one of the industry’s largest and least publicly visible players.

Oracle built its data division through a series of acquisitions. It acquired Datalogix — a company specializing in linking online behavior to offline purchases. It bought BlueKai — the largest data management platform for advertising. It absorbed AddThis — the “share” button service that sat on millions of websites and quietly collected data on visitors.

The last one is especially telling. The “share on Facebook,” “share on Twitter” buttons found on news sites, blogs, and online stores don’t just let you share content. They’re trackers. Every visit to a page with such a button is recorded. Even if you never clicked it.

AddThis was on two million sites. Through this division, Oracle saw an enormous share of all internet traffic.

What does Oracle Data Cloud sell?

Audience segments. These are ready-made sets of profiles grouped by some characteristic. “People planning to buy a car in the next 90 days.” “Parents of children aged 3 to 6.” “Above-average-income people interested in investing.” “People experiencing financial difficulties.”

An advertiser buys access to the segment they need — and their ads are shown to exactly those people. On any sites and platforms where Oracle has a partnership. And Oracle has partnerships everywhere.

You see the ad. You don’t see Oracle. Oracle sees you.

Quantcast. The very one I found in the traffic.

Remember the review of the Ehituse ABC site? 1,448 requests to three Quantcast domains simultaneously. A company not mentioned in the store’s privacy policy. A company that hasn’t responded to official GDPR requests for over 30 days.

This isn’t a random example. It’s the typical picture.

Quantcast was founded in 2006 in San Francisco. It specializes in audience measurement and targeted advertising. The company’s technology — so-called direct measurement — means Quantcast installs its own code directly on partner sites and collects data first-hand, without intermediaries.

This gives Quantcast a very detailed picture of user behavior — not aggregated statistics, but individual patterns.

Quantcast claims to cover more than 100 million sites and apps. It claims to see more than 100 million unique users monthly in the US alone. Its global reach is an order of magnitude larger.

Three simultaneous domains on an Estonian hardware store’s site is a standard Quantcast configuration. One domain for collecting behavioral data. A second for static resources. A third for synchronizing identifiers with other advertising platforms.

Identifier synchronization is a separate topic worth explaining.

Every advertising platform has its own identifier for each user. Quantcast has one. Google has another. The Trade Desk has a third. For these platforms to work together, they need to match up their identifiers. To learn that quantcast_id_12345 is the same person as google_id_67890.

This is called cookie syncing or ID syncing. It happens automatically, invisibly, constantly. The moment any page with advertising loads.

The result — your profile is combined across all platforms. Quantcast knows what you did on sites where its code is present. Google knows what you searched for. The Trade Desk knows what you looked at on other sites. Through synchronization, all of it gets merged into a single profile.

And you don’t see a single one of these data exchanges. You never gave separate consent to any of them.

Why aren’t they mentioned in privacy policies.

This is a question I hear constantly. If this is a lawful activity, why hide it?

The answer is uncomfortable. Because if they wrote the truth, no one would click “accept.”

Imagine a privacy policy that honestly said the following: “When you visit our site, your data is automatically transmitted to 47 companies. Here’s the full list. Each of them builds a profile of you. The profiles are sold to other companies. We don’t control what happens to the data after transfer. Some of these companies are located in the US and have no valid legal basis for receiving European users’ data.”

No one would write a policy like that. Because then they’d have to either obtain genuinely informed consent — which most people wouldn’t give — or admit to violations.

Instead, they write: “We work with trusted partners to improve your experience and show relevant advertising.”

Trusted partners. Improved experience. Relevant advertising. Three phrases that legally say nothing — but sound harmless.

The GDPR requires disclosure of the list of data recipients. Most companies either list categories — “advertising partners” — instead of specific names. Or they provide a link to a list that’s updated every few weeks and contains several hundred entries. Formally, the requirement is met. In practice, the information is inaccessible to an ordinary person.

This isn’t an accident. It’s a design.

A scale that’s hard to grasp.

Let me try to give a sense of scale through concrete numbers.

The global data-broker market is valued at roughly $300 billion a year. For comparison — that’s larger than the GDP of many European countries.

The US has more than 4,000 companies that can be classified as data brokers. In Europe, fewer, because of the GDPR — but still hundreds.

The average American appears in the databases of approximately 2,500 data brokers. A European — fewer, but still in the hundreds.

Data about the average person is sold, on average, 376 times a year. That’s roughly once a day. Every single day, someone is buying information about you from someone else.

The price of a complete profile of a person ranges from a few cents to a few dollars. Sounds like a small amount. But multiply it by billions of people and hundreds of transactions a year, and you get that same $300 billion.

And here’s the most important thing about these numbers.

Not a single cent of that money reaches you. Your data — your life, your decisions, your habits, your weaknesses — is sold again and again. You get nothing. You never gave consent. You don’t know who’s buying. You don’t know what for.

This is an industry built on a resource that belongs to you — but that no one ever asked you for.

Where they get their data. The full picture.

The last thing to understand in this post is where what they sell actually comes from.

There are many sources. And they work simultaneously.

Public registries. In most countries, a huge amount of information about citizens is public by law. Real-estate registries — who owns what. Court rulings — debts, bankruptcies, criminal cases. Company registries — who is a director or founder. Voter rolls — in a number of countries these are public and contain names and addresses. Brokers systematically collect all of it.

Loyalty programs. A supermarket discount card. A pharmacy bonus program. Airline miles. Behind each of them — a database of purchases. This data is sold. This is exactly why loyalty programs exist — not to make you loyal, but to get data about your purchases in exchange for a small discount.

Websites and apps. A huge part of the internet runs on an advertising model. Every visit is data the site can sell. Every app you install and grant permissions to is a potential data source for brokers.

Other brokers. Brokers buy data from each other. One specializes in financial profiles. Another in behavioral data. A third in demographics. By exchanging and buying from each other, they enrich their own databases.

Leaks. No one says this out loud — but part of the data in brokers’ databases has questionable origins. Leaked databases end up on darknet forums. From there, they reach intermediaries. Intermediaries sell them to brokers — not always with a full understanding of the source.

Social networks. Public profiles, public posts, public photos — all of this is scraped automatically. Algorithms crawl the public portion of social networks and collect what people made public themselves — not always understanding what that means.

As a result, the profile built about you draws on dozens of sources. You never interacted directly with a single broker. But every time you did something in the physical or digital world, another box somewhere got checked in your file.

What’s next.

In the next post — what your profile in a broker’s database actually looks like. What categories. What labels. What these labels mean in practice — what decisions get made based on them.

And something brokers prefer not to talk about. Categories of data they collect but officially deny. Labels attached to people — which they never see.

Because what you don’t know about your profile is precisely their main competitive advantage.

Advertising Brokers. Part Two — What Your Profile Looks Like from the Inside

Last time we met the players. Acxiom, Experian, Oracle, Quantcast. Who they are, where they get their data, the scale of this industry.

Today we open the file. We look at exactly what’s written there. In what words. In what categories. What these categories mean in practice — and why some of them change a person’s life in ways they never expected.

Because a profile in a broker’s database isn’t just a set of facts about you. It’s an interpretation. It’s conclusions. It’s labels someone attached — and that now follow you around.

Let’s start with what a profile looks like technically.

Picture a table. Rows — people. Columns — attributes. Thousands of columns. In each cell — a value. A number, a category, a flag — yes or no.

This is a simplified representation. In reality, a profile is a graph. A connected structure where each piece of data links to others. A purchase links to a location. A location links to a time. A time links to a behavioral pattern. A behavioral pattern links to a psychographic inference.

But for now, think of it as a table.

The first layer — what you reported yourself.

Name. Date of birth. Address — current and previous. Email — often several. Phone. Marital status. Number of children. Education. Occupation. Employer.

This is the base layer. It’s built from site registrations, loyalty-program questionnaires, public registries. It seems harmless — after all, these are just facts.

But it’s only the foundation. Beyond it, the real story begins.

The second layer — what was observed.

Purchase history. Not just “shopped at a supermarket.” In detail — which product categories, which brands, at what time of day, how regularly, average basket size, discount sensitivity, purchase impulsiveness.

Search and browsing history — for brokers with partnerships with search engines and sites. What was searched. How long they read. What was opened and closed without finishing. What they lingered on.

Location. Where they regularly go. Routes. Time spent in different places. Frequency of visits to medical facilities — inferred from location data, without a single medical document.

Financial transactions — aggregated data from banks and payment systems. Not always specific amounts — but patterns. Recurring payments. Irregular large expenses. Late payments.

The third layer — what was inferred.

And here is where things get most interesting. And most dangerous.

Brokers don’t just store facts. They draw conclusions. They build models. They assign categories a person would never have assigned to themselves.

These inferences go by various names. Inferences. Predictions. Scores. Segments. But the essence is the same — an algorithm decided you belong to a particular category. And that category is now part of your profile.

Categories that exist. That you’ve never seen.

In 2019, researchers from Brown University and a number of other organizations conducted a large-scale analysis of the data categories used by major brokers. They studied publicly available taxonomies — classification systems that brokers disclose to advertisers so they can select the audience they need.

The results were published. And they showed something important.

Here are real categories that exist in data-broker systems. Not invented — documented.

Health-related categories.

“Likely has diabetes” — inferred from pharmacy purchases, search queries, food purchases, location near medical facilities. Without a single medical document.

“Likely pregnant” — a classic example we’ve mentioned before. A change in purchasing pattern, certain search queries, purchase of specific products.

“Mental health issues” — inferred from search queries, nighttime social media activity, purchases of certain medication categories at the pharmacy, content-consumption patterns.

“Struggling with addiction” — a combination of behavioral signals, location, search queries.

“Cancer diagnosis” — frequent visits to medical facilities of a certain specialty, search queries, purchases.

Finance-related categories.

“Financially vulnerable” — late payments, certain search queries, a spending pattern indicating a shortfall by month’s end.

“Prone to gambling” — behavioral patterns, history of visits to certain sites, location.

“High default risk” — a predictive model based on dozens of variables.

“Recently lost job” — change in spending pattern, certain search queries, change in location.

Personal-life categories.

“Recent divorce” — change of marital address, certain legal search queries, purchase pattern.

“Grieving” — behavioral signals, search queries, location near funeral homes or cemeteries.

“Lonely” — location pattern, activity at certain times of day, purchases.

Political and religious categories.

“Conservative political views.” “Liberal political views.” “Religiously active.” “Attends church.” “Supports certain political movements.”

All of this is real categories. Real labels. Which are really sold to real buyers.

Now stop for a second.

Think about a person battling a cancer diagnosis. They told no one about it except their closest circle. It’s private. It’s their right to decide who to tell.

But a label sits in a broker’s database. And that label is for sale. To insurance companies recalculating their rate. To employers using the data in hiring. To financial institutions assessing risk.

The person never said anything. An algorithm decided. The label sits there. Consequences follow.

Or a person going through a divorce. A difficult period. A vulnerable moment. In the broker’s database — flags for “recent divorce” and “financially vulnerable.” This profile is bought by law firms specializing in divorce, financial advisors pushing dubious products, payday-loan companies.

The system sees vulnerability. And sells access to a vulnerable person to those who want to profit from it.

These aren’t hypothetical scenarios. These are documented practices.

Scores you don’t know you have.

Beyond categories, profiles contain scores. Numerical ratings across various parameters. There are dozens of them. Sometimes hundreds.

Here are a few real types of scores sold by brokers.

Purchase-propensity score. The probability you’ll buy a specific product category in the next 30, 60, or 90 days. Calculated separately for each category. Cars, real estate, electronics, clothing, travel.

Response score. How likely you are to respond to advertising — to click, to click through, to buy. People with a high response score cost more at the ad auction.

Brand-loyalty score. How devoted you are to particular brands. Companies are willing to pay more for people who could be lured away from a competitor.

Financial-risk score. Probability of default, late payments, financial difficulties. Used not just by banks — by insurance companies, landlords, employers.

Health score. Predicted medical expenses for the coming year. Insurance companies are very interested in this number.

Influence score. How much you influence other people’s purchasing decisions — through social media, through recommendations, through social connections. Influencers with a high influence score cost more.

Vulnerability score. This is the darkest product. How susceptible a person is to certain types of advertising manipulation. People in difficult life situations — under heavy debt pressure, going through personal tragedies, struggling with addiction — have a high vulnerability score. And this score is bought by companies that specialize precisely in such people.

This isn’t speculation. In 2014, the US Senate investigated the data-broker market. The official report documented that a number of brokers sold lists of people labeled things like “financially vulnerable,” “desperately in need of money,” “fraud victims” — to companies engaged in predatory lending and fraudulent schemes.

People at the hardest moments of their lives were sold to those who wanted to make those moments even harder.

How data gets enriched. A process that happens continuously.

A profile isn’t static. It’s alive. It’s continually updated — sometimes in real time.

There’s a process called data enrichment. When one broker combines its data with another broker’s data, and gets a fuller profile.

Here’s how it works in practice.

Broker A has demographic data and offline-store purchase history. Broker B has data on online behavior. Broker C has financial data from a credit bureau.

All three brokers sell and buy data from each other. Through identifier synchronization — which we discussed last time — the profiles get merged. The result — a profile containing data from all three sources.

This enriched profile costs more. It’s sold at a higher price. It’s used for more precise targeting.

And here’s what’s important. When you gave data to Broker A, you didn’t know it would reach Broker B and C. You didn’t know enrichment would happen. You never gave consent to it.

Under the GDPR, every such data transfer requires a legal basis. Consent or legitimate interest. In practice, most such transfers occur on the basis of “legitimate interest,” interpreted as broadly as possible.

This is exactly why I litigate against brokers. Not because I want to shut the industry down. Because the industry operates in a gray zone — and that zone needs to be illuminated.

Special categories of data. The red line they cross.

The GDPR carves out a special category — special categories of personal data. Article 9. This is data requiring heightened protection because its leak or unlawful use can cause serious harm.

What falls under special categories?

Racial or ethnic origin. Political opinions. Religious or philosophical beliefs. Trade-union membership. Genetic data. Biometric data used for identification. Health data. Data concerning sex life or sexual orientation.

Processing special categories is prohibited by default. Permitted only with explicit consent, or in strictly defined statutory cases.

Now look back at the list of categories we broke down above.

“Likely has diabetes” — that’s health data. A special category.

“Mental health issues” — health data. A special category.

“Conservative or liberal political views” — political opinions. A special category.

“Religiously active” — religious beliefs. A special category.

Brokers process special categories. Not directly — they’ll never say “we process health data.” They’ll say “we make predictive inferences based on behavioral data.”

Inference — a conclusion. Technically, that’s not health data. It’s a supposition about health based on behavior.

Courts in various countries are gradually beginning to recognize that such a distinction is a legal fiction. If an inference concerns health, it is health data, regardless of what it’s called.

But while these cases wind through the courts, brokers keep operating.

What happens when a profile gets it wrong.

Algorithms make mistakes. That’s a fact. And when an algorithm makes a mistake in a profile, the person bears the consequences.

Several documented types of errors.

Identification error. Data from different people with the same name gets merged into one profile. A father and son with the same name. Namesakes in the same city. The result — one person’s profile picks up another person’s data. A stranger’s debts. A stranger’s criminal record. A stranger’s medical history.

Inference error. The algorithm draws a wrong conclusion from correct data. A person regularly buys baby food — not because they have a child, but because they care for an elderly relative. The algorithm assigns the label “parent of a young child” — and the person starts getting diaper and children’s-product ads. That’s a harmless example. There are non-harmless ones too.

Stale-data error. A person had financial difficulties ten years ago. Long since resolved. But in the broker’s database — the old label. Which still affects decisions about them.

Bias error. The algorithm is trained on historical data that reflects existing inequality. The result — it reproduces and amplifies that inequality. People from certain neighborhoods get a higher financial-risk score, not because they personally are unreliable, but because historically there were more defaults from those neighborhoods. The circle closes.

What do all these errors have in common?

The person doesn’t know about them. They don’t see their profile. They don’t know what labels have been attached. They find out about the error only when it materializes — as a loan denial, an inflated insurance rate, a hiring rejection.

And then a long path begins of trying to prove the algorithm got it wrong.

A point worth understanding about the power of this data.

There’s a concept I want to explain, because it changes how you relate to this topic.

It’s called information asymmetry.

This is a situation where one party in a relationship knows significantly more than the other. And uses that knowledge in their own interest.

A classic example — a used-car salesman knows everything about the car. The buyer knows almost nothing. The salesman uses that advantage.

In a person’s relationship with advertising brokers, the asymmetry is absolute.

The broker knows 1,500 characteristics about you. Dozens of scores. Hundreds of labels. Years of history. Predictions about your future.

You know nothing about the broker. You don’t know it exists. You don’t know it has your profile. You don’t know what’s written in it. You don’t know who it sells it to.

This asymmetry is the foundation of the business model. It’s not accidental. It’s deliberate. Because if you saw your profile, you’d want to change it. Or delete it. Or file a complaint.

As long as you don’t see it, the system operates unhindered.

The GDPR is a tool that reduces this asymmetry. The right of access, the right to erasure, the right to object — these are tools that give you information about what’s known about you.

But a tool only works when it’s used.

What’s next.

In the next post — the most practical of the three. How to get out of brokers’ databases. What actually works. What doesn’t work despite pretty promises. Why this is harder than it seems — and why it’s still worth trying.

And something I know from personal experience — what happens when you start demanding your rights from a company used to no one ever bothering it.

Because their reaction is very telling.

Advertising Brokers. Part Three — How to Get Out of the Databases. And Why They Don’t Want to Let You Go

Two posts ago, we met the players in this industry. Last time, we opened the file and saw what’s inside. Today — the most important conversation.

What to do with this knowledge.

I won’t promise easy solutions. Because there aren’t any. A $300-billion industry didn’t build a business model with a convenient “delete me” button. Every step toward getting out of their databases meets resistance — sometimes passive, sometimes active.

But that doesn’t mean there’s nothing to do. It means you need to know what actually works. And what’s an illusion of control.

Let’s start with an honest conversation about why it’s hard to get out.

A problem few people fully understand

When people learn about data brokers, the first impulse is understandable. Delete everything. Get out of every database. Become invisible.

Sounds like a plan. In practice, it’s like trying to catch water in a sieve.

Here’s why.

You don’t know exactly which databases you need to get out of. We talked about four major brokers. The real number of companies holding data on an average European is in the hundreds. Possibly thousands. Each has its own opt-out process. Its own requirements. Its own form. Its own timelines.

Even if you go through the whole process and the data gets deleted, it will come back. Because the sources that feed brokers’ databases — public registries, loyalty programs, sites with trackers — keep operating. The broker deleted your data today. Three months later, it bought an updated database from a partner — and you’re back in there.

Opt-out processes are designed to be as inconvenient as possible. This isn’t paranoia — it’s a documented fact. A US Federal Trade Commission study found that most brokers require you to provide more personal data in order to delete data about you. Name, address, date of birth, a copy of an ID. To delete data about yourself, you need to hand over more data about yourself.

Appreciate the irony.

Some brokers only allow opt-out via postal mail. In 2024. A physical letter, on paper. This isn’t a technical necessity. It’s a barrier.

Some accept the request — but don’t delete the data, only flag the profile “do not use for advertising.” The data stays. It’s sold for other purposes.

Understanding this shouldn’t demotivate you. It should set realistic expectations. The goal isn’t total disappearance — that’s unachievable. The goal is a significant reduction of your footprint and the use of lawful pressure on the system.

What actually works. Level one — prevention

The most effective thing is to keep data from ever entering the databases in the first place. Prevention is cheaper than treatment.

Browser and search.

Switch search engines. Google is a data-collection machine with a search interface. DuckDuckGo doesn’t track queries or build a profile. Brave Search — likewise. Startpage shows Google’s results but without transmitting data about you.

That’s one change that instantly removes one of the most informative streams of data about you.

Install the Firefox browser with the uBlock Origin extension. It’s an ad and tracker blocker. Free. Effective. After installing, visit any site and look at how many trackers get blocked. On an average news site — 20 to 50. That’s 20-50 companies that no longer get data about your visit.

The Brave browser is an alternative. Built-in tracker and ad blocking, no extra setup needed. It shows a counter of blocked trackers — pretty sobering when you see the numbers.

Cookie banners.

Always click “reject all” or “necessary only.” Always. Even if the button is hidden and you need three clicks to find it.

The “I don’t care about cookies” extension automatically rejects cookie banners on most sites. Installs in a minute. Runs in the background.

The Consent-O-Matic extension — similar, developed by Danish researchers. Open source. Verifiable behavior.

Email.

Don’t use your main email for site registrations. Set up a separate address for anything non-essential. Or use temporary-address services — SimpleLogin, AnonAddy. They create aliases that forward mail to your real address. The site gets the alias — not your real email.

When the alias starts getting spam, you know exactly who sold your data. The alias can be disabled in one click.

Phone.

Check the permissions of every app. Go to Settings → Apps → Permissions. Location, microphone, camera, contacts, calendar. Revoke anything that isn’t functionally necessary for the app to work.

Maps and navigation need location. A flashlight doesn’t. A calculator doesn’t need a microphone. The logic is simple.

Loyalty programs.

This is a hard choice — and I won’t tell you what’s right for you. But you should know the price you’re paying for the discount.

A supermarket loyalty card is a trade. You get a 2-5% discount. The store gets a detailed history of all your purchases. Which it sells. Repeatedly.

If you participate in loyalty programs, use a separate email. Where possible, give the minimum of personal data at registration.

What actually works. Level two — GDPR requests

This is a tool you already have, right now. Legally binding. Free. And surprisingly effective — because companies used to silence respond differently to official requests.

Step one. Find the brokers that hold your data.

Start with the major ones. Acxiom, Experian, Oracle Data Cloud, Quantcast, Epsilon, Equifax, TransUnion, LexisNexis, CoreLogic.

Go to each site. Find the Privacy or Data Privacy or GDPR section. There should be a process for filing a data subject request, or DSR.

If there’s no such section, look for the Data Protection Officer’s email address. Under the GDPR, every company processing significant volumes of data must have such an officer, and their contact details must be publicly available.

Step two. Send the right request.

Here’s a detail most people don’t know — and that fundamentally changes the quality of the response.

When you write a request giving only your name and email, the system doesn’t recognize you. Not because it doesn’t want to. Because the system doesn’t know you by name. It knows you by code.

A long numeric code. A string of characters. That’s exactly what you exist as in their database. To the algorithm, your name is secondary. The code is primary.

Here’s what these codes actually look like — so you can recognize them when you encounter them.

Cookie ID — the most common identifier. Stored in the browser. Assigned on first visit:

_ga=GA1.2.1234567890.1698765432

_fbp=fb.1.1698765432123.1234567890

mc=8f3a2b1c-4d5e-6f7a-8b9c-0d1e2f3a4b5c

uuid=550e8400-e29b-41d4-a716-446655440000

Device fingerprint — computed from your device and browser characteristics. Clearing cookies doesn’t remove it — it gets recalculated and matches every time:

fp=a1b2c3d4e5f6789012345678901234567890abcd

Advertising ID on smartphones — a persistent identifier visible to every app with tracking permission:

GAID: 38400000-8cf0-11bd-b23e-10b96e40000d (Android)

IDFA: A1B2C3D4-E5F6-7890-ABCD-EF1234567890 (iPhone)

Third-party cookie ID — set by advertising platforms for cross-site tracking:

IDE=AHWqTUmKjL3n5XvP8wZ2qR9sY4kM7pN1oE6tB0cF (Doubleclick)

TDID=7a8b9c0d-1e2f-3a4b-5c6d-7e8f9a0b1c2d (Trade Desk)

uid=McqThZRPGpz8AAAA (Criteo)

localStorage identifiers — stored not in a cookie but in the browser’s local storage. Clearing cookies doesn’t remove them. This is deliberate:

tt_chain_token: AbCdEfGhIjKlMnOpQrStUvWxYz1234567890==

line_user_id: U1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d

_pxvid: 1a2b3c4d-5e6f-7a8b-9c0d-1e2f3a4b5c6d

Brokers’ internal IDs — stored on their servers, you don’t see them in the browser, but these are exactly what you need to demand in a request:

AbiliTec_ID: ACX-7834521-US-20190847362 (Acxiom)

BlueKai_ID: bk-uid-8f3a2b1c4d5e6f7a (Oracle)

RampID: Rm1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c (LiveRamp)

ConsumerView_ID: EXP-C-1234567890-EU (Experian)

Where to find your own codes right now. Open your browser. Go to any major site. Press F12 or Ctrl+Shift+I. The Application tab. On the left — Cookies, Local Storage, Session Storage. There — dozens of rows. Cryptic keys. Long values. That’s exactly what the system knows you by. Not by your name. By this.

Now — a request that shows you understand the system from the inside:

Under Article 15 of the GDPR, I request access to all personal data you process about me. In particular, I ask that you disclose all technical identifiers under which I am processed in your systems, including but not limited to:

— Cookie ID and all associated identifiers

— Device fingerprint or its hash

— Advertising ID (GAID/IDFA), if applicable

— Your system’s internal user ID

— Identifiers obtained via cookie syncing or ID syncing with partners

— Identifiers in localStorage or sessionStorage

— Any other technical identifiers associated with my device, browser, or behavior. I also request that you specify all recipients to whom these identifiers were transferred, and the legal basis for each such transfer.

The difference between this request and a standard one is fundamental.

A standard request — “give me my data” — a company can answer with a name and email. Formally, requirement met.

This request — you explicitly name what you want to see. Cookie ID, fingerprint, internal identifiers, a list of recipients with the legal basis for each transfer. Now the company is obligated to respond to each point — or explain why it can’t.

This isn’t aggression. It’s literacy. This is exactly what it looks like to talk on equal footing with a system used to silence.

Step three. Wait. Document.

The company must respond within one month. Article 12(3) GDPR. If the request is complex, they may ask for an extension of up to two more months. But they must notify you of this within the first month.

If a month has passed with no response, that’s a violation. A recorded, documented violation.

Step four. Use what you get.

If a response arrives with data — study it carefully. What exactly do they hold. What categories. Where did they get it. Who did they share it with.

If the data is inaccurate, send a rectification request. Article 16. If you want it deleted, send an erasure request. Article 17. If you want to stop processing for advertising purposes, send an objection. Article 21.

Each of these requests is a separate letter. A separate response deadline. A separate record.

What happens when they stay silent. From personal experience

I’m handling 15 active cases against advertising brokers. Let me tell you what happens in practice.

When you send the first request — most often, silence. Companies expect a person to send the letter and forget about it. Or to get tired of waiting. Or not know what to do next.

Most people really do get tired. That’s exactly what they’re counting on.

When you send a reminder stating that the response deadline has passed and that you’re recording a violation of Article 12(3), the reaction changes. Not always. But often. Because the words “I am recording a violation” tell them the person knows what they’re talking about.

Quantcast did not respond to me for more than 30 days. This is documented. The date the request was sent is on record. The date the deadline expired is on record. This is ready-made material for a complaint.

When you file a complaint with AKI — Estonia’s Data Protection Inspectorate — a company that stayed silent for three months suddenly finds a way to respond. A remarkable coincidence. Because it’s harder to stonewall a regulator than an ordinary person.

That’s exactly the mechanism. Not every person needs to see it through to the end. But when enough people start using this tool, the system changes. The regulator sees a pattern. The company faces reputational and financial risk. It changes its practices.

Every complaint isn’t just your personal matter. It’s data for a system that’s supposed to work in people’s interest.

Services that help. And their limitations

There are services that automate the process of removing data from brokers’ databases. DeleteMe, Kanary, Incogni, Privacy Bee. Paid — from €10 to €15 a month.

Here’s how they work. You give them your data. On your behalf, they send opt-out requests to broker databases they have a partnership or an established process with. They monitor for your data reappearing. They periodically re-send the requests.

This genuinely helps — within its limits.

Limitations you should know about

These services work with a limited list of brokers. DeleteMe, for example, works with a few dozen large American brokers. But there are thousands of brokers. Those not on the list aren’t covered.

The European market is covered much worse than the American one. Most of these services are focused on the US. For residents of Estonia, Latvia, Lithuania, Finland — the coverage is smaller.

Data comes back. The services are honest about this — that’s exactly why they charge a monthly subscription rather than a one-time fee. It’s not a solution — it’s ongoing maintenance.

You give these services your data — so that they’ll delete your data from other databases. The irony is that now they have your data. You need to read their privacy policy carefully — what do they do with the information you provided them.

My conclusion. These services are useful as a supplement to your own actions — especially for large American brokers. But not as a substitute for understanding the issue and active GDPR requests.

The European market’s specifics. What works here

For EU residents, and Estonia in particular, the GDPR gives you real tools that Americans don’t have. Use them.

First. The right of access works better here than almost anywhere. European companies know the regulator exists and that fines are real. Getting a response to a GDPR request in Estonia is easier than getting an opt-out from an American broker.

Second. AKI — Andmekaitse Inspektsioon — is a genuinely functioning regulator. Not just an organization with a nice website. They review complaints. They issue orders. They fine.

To file a complaint — aki.ee. An online form. In Estonian or English. Free. You need to describe the situation, attach correspondence, and specify which right was violated and how.

Third. For brokers operating in the Estonian market — including those I found in local sites’ traffic — AKI is exactly the competent authority. Quantcast operates on Estonian sites — which means AKI can handle violations involving Estonian users.

Fourth. If the broker is located in another EU country, you can file the complaint either with AKI or directly with the supervisory authority in the country where the company is registered. EU regulators cooperate with each other.

Fifth. If the company is outside the EU — for example, an American broker without a European office — the situation is harder. The GDPR formally applies if the company processes data belonging to European residents. But compelling an American company with no European presence is technically difficult. This is where cooperation among regulators at the international level matters.

A realistic picture. What can actually be achieved

I want to be honest. Because inflated expectations are worse than realism.

Fully disappearing from the databases is impossible. As long as public registries, loyalty programs, and advertising trackers on sites exist, data will keep reappearing. That’s not a reason to give up. It’s a reason to understand the real goal.

The real goal isn’t invisibility. It’s control

Control over what goes into the databases — through changing your browser, search engine, app permissions. Control over what’s stored — through GDPR requests and the right to erasure. Control over how it’s used — through the right to object to advertising-related processing.

And informational control — you know what’s happening. You’re not living under the illusion that none of this concerns you.

That’s already a different stance. A fundamentally different one.

A person who understands what’s happening makes different decisions. They don’t automatically click “accept all.” They don’t send a passport scan to a service they don’t trust. They don’t install an app without looking at its permissions. They send a request when a company violates their rights — instead of quietly swallowing it.

There are more and more such people. And the system feels it.

What happens when a lot of people get involved

I want to end on this. Because it matters more than the technical tips.

The GDPR was adopted because enough people — journalists, activists, lawyers, ordinary citizens — started speaking up about what was happening. Cambridge Analytica became a public scandal because the people who knew about it told others. The fines against Meta, Google, and Amazon became possible because someone filed the first complaint. Then a second. Then a thousandth.

The system doesn’t change when one person does something. The system changes when a critical mass of people starts doing it regularly.

Every GDPR request you send isn’t just your personal business. It’s a signal. The company receives the request and understands people have started paying attention. The regulator receives the complaint and sees a pattern. The pattern becomes an investigation. The investigation becomes a fine. The fine becomes a precedent. The precedent changes industry practice.

It’s slow. It’s not obvious. It doesn’t produce an instant result.

But it’s the only thing that works at the systemic level.

I’m handling 15 cases not because I expect to personally defeat a $300-billion industry. I’m handling them because every case is a documented fact. Every documented fact is a brick in the foundation of change that happens slowly but inevitably.

Because an industry that operates in the dark changes when someone starts shining a light on it.

This text is one of those lights.

The next one is in your hands.

← All journal entries