Data broker breaches have cost US consumers more than 20.8 billion dollars in identity theft losses since 2017, according to a Joint Economic Committee report released February 27, 2026. The figure comes from an analysis of four major data broker breaches, Equifax, Exactis, National Public Data, and TransUnion, that together exposed 651 million records. No single government agency tracks how many data brokers exist or how much money the industry moves, so the clearest picture comes from piecing together state registries, congressional investigations, and independently audited removal-service data.

How much have data broker breaches actually cost consumers?

Data broker breaches cost US consumers over 20.8 billion dollars in identity theft losses $20.8B in identity theft losses tied to fourdata broker breaches (JEC, Feb 2026)

The Joint Economic Committee, chaired by Senator Maggie Hassan, calculated the 20.8 billion dollar figure by combining the number of people affected by four data broker breaches with published identity-theft rates and a 200 dollar median loss per theft, a standard methodology also used by the Federal Trade Commission in prior consumer-harm estimates. The investigation was triggered by earlier reporting from CalMatters and The Markup on data brokers quietly blocking search engines from indexing their opt-out pages.

The committee's staff contacted five major data brokers directly as part of the investigation. Four made changes, including removing "no-index" code that had been hiding their opt-out pages from search engines, after congressional staff raised the issue. One broker, Findem, declined to engage or change its practices, which the report singled out as a specific compliance concern. If your business collects and shares any personal data with third parties, a privacy policy that discloses those data flows in plain terms is the first thing a regulator or a consumer will check when something goes wrong.

Records exposed in the four breaches behind the $20.8B loss estimate (millions) 075150225300M270National Public Data(2023)230Exactis (2018)147Equifax (2017)4TransUnion (2025)

Figure 1: The four breaches the Joint Economic Committee used to calculate its 20.8 billion dollar consumer-loss estimate. Source: Joint Economic Committee, "Data Brokers Report" (February 27, 2026).

How many data brokers actually exist?

There is no federal registry and no single authoritative count. The most rigorous public estimate comes from Privacy Rights Clearinghouse, which combined five state data broker registries in an April 2025 review and identified 750 unique data brokers that had registered in at least one state. That figure only counts companies that registered somewhere; it does not include brokers operating entirely outside every state's registration framework, so it is a floor, not a ceiling.

Figure 2: Registry age against registered-broker count, using the two states with published counts (California, Vermont) alongside the two newest registries. Source: state registry statutes and CPPA/Vermont Secretary of State data, 2026.

Privacy Rights Clearinghouse's central finding was not the total count but the gap: hundreds of companies that had registered as data brokers in one state had not registered in others where the same law applied to them, which the report described as a significant compliance gap across every state registry it reviewed. Widely repeated figures like "4,000 data brokers operate in the United States" could not be traced back to any primary source with a disclosed methodology during this review, so that number is not used here.

Which states require data brokers to register, and how many have signed up?

Six states now require data brokers to register: Vermont, California, Texas, Oregon, Connecticut, and New Jersey. Vermont was first, in 2018, and its registry remains the most complete because it has run the longest.

StateRegistry establishedRegistered brokersSource
Vermont2018283VT Secretary of State, 2025-2026 cycle
California2020 (CPPA-run since 2024)600+CPPA registration framework, 2026
Oregon2024Not separately publishedOR Division of Financial Regulation
Texas2024Not separately publishedTX Secretary of State

Vermont's registry, run by the Secretary of State's office, lists 283 registered data broker companies as of the 2025-2026 filing cycle, a number that has held roughly steady over the past year even as more states have adopted similar laws. California's registry, now run directly by the California Privacy Protection Agency after taking over from the Attorney General's office, had more than 600 registered brokers heading into 2026, per the agency's own registration framework. One data point does not extrapolate cleanly to another because each state defines "data broker" slightly differently, which is exactly the disclosure gap that makes cross-state comparisons hard for regulators and journalists alike.

Figure 3: Six states now require data broker registration, spread across eight years of lawmaking. Source: state registry statutes as compiled by DataGrail and the California Lawyers Association, 2026.

What is California's DROP platform, and is it working?

California's Delete Request and Opt-Out Platform, known as DROP, is a free state-run system that lets a resident submit one deletion request that reaches every registered data broker in the state at once, rather than contacting each broker individually. It launched for consumer submissions on January 1, 2026, under the state's 2023 Delete Act.

Figure 4: How a single DROP request is supposed to move through California's data broker system. Source: California Privacy Protection Agency, Delete Act enforcement framework, 2026.

More than 260,000 deletion requests were sitting in the DROP queue as brokers approached the state's August 1, 2026 enforcement deadline, the date brokers became legally required to check the platform at least once every 45 days and begin processing every queued request or face a 200 dollar-per-consumer, per-day fine. That penalty structure means a broker sitting on 10,000 unprocessed requests for even a single day is exposed to a theoretical 2 million dollar daily fine, which is the kind of number that tends to get compliance departments moving.

How much of your data do brokers actually hold, and can you get it back?

Academic research into what brokers advertise for sale has consistently found categories most people would not expect to be for sale at all. A 2021 Duke University review of ten major data brokers found listings advertising political-party affiliation, real-time GPS location history, and records tied to current and former US military personnel, a finding that predates most of the state registries covered above and has not been repeated at the same depth since, so treat it as a snapshot of practices at that time rather than a current industry-wide figure.

Removing your own data manually is possible but slow. Incogni, a commercial data-removal service, estimates that manually opting out of the brokers most likely to hold a given person's data takes roughly 304 hours, an internal company estimate rather than an independently verified figure. What is independently verified is the scale of the removal problem itself: an August 2025 Deloitte assurance report, prepared under the ISAE 3000 standard, confirmed that Incogni alone covered more than 420 data broker websites and private databases and had processed more than 245 million removal requests on behalf of customers since January 2022.

One audited removal service processed more than 245 million requests since January 2022 245M removal requests processed sinceJan 2022, independently audited (Deloitte)

Figure 5: Independently audited removal volume from a single service, illustrating the scale of ongoing broker relisting. Source: Deloitte Lietuva UAB, ISAE 3000 Independent Limited Assurance Report on Incogni (August 2025).

Most brokers also do not delete data permanently once removed. Public-record and marketing-list brokers commonly re-collect and relist a person's information within 60 to 90 days, which is why compliant removal services and the DROP platform both build in recurring, not one-time, deletion cycles rather than a single sweep.

The Bottom Line

Data brokers operate with no single federal registry, no agreed industry-wide count, and, per the Joint Economic Committee's February 2026 report, a documented 20.8 billion dollar consumer cost from just four breaches. The 750 brokers Privacy Rights Clearinghouse found registered somewhere are almost certainly an undercount, since the same report found hundreds of companies registered in one state and not another. California's DROP platform and its August 2026 enforcement deadline are the first real test of whether a single-request deletion system can outpace an industry that has historically relied on fragmented, state-by-state compliance to avoid full accountability. For any business that collects personal data and shares it with third parties, even indirectly through analytics or advertising partners, this is also the moment to check that your own privacy policy names third-party data sharing specifically rather than relying on vague boilerplate that would not survive the same scrutiny data brokers are now facing.

Frequently Asked Questions

How much have data broker breaches cost consumers? More than 20.8 billion dollars in identity theft losses, according to a Joint Economic Committee report published February 27, 2026, based on four major data broker breaches spanning 651 million exposed records since 2017.

How many data brokers actually exist in the United States? There is no single official count. Privacy Rights Clearinghouse identified 750 unique data brokers registered across five state registries as of April 2025, and hundreds of additional companies registered in one state were found not registered in others.

How many data brokers are registered in California? More than 600 data brokers were registered with the California Privacy Protection Agency heading into the state's August 1, 2026 DROP enforcement deadline, according to the agency's own registration framework.

How much does it cost to remove your data from data brokers yourself? Manual removal is free but time-consuming. Incogni, a paid removal service, estimates the average person would need roughly 304 hours to manually opt out of the data brokers most likely to hold their information.

Where the Numbers Come From

  1. United States Joint Economic Committee. (2026). "New Report: Senator Hassan Finds That Data Broker Breaches Cost U.S. Consumers More Than $20 Billion." Published February 27, 2026, based on four breaches totaling 651 million exposed records.
  2. Privacy Rights Clearinghouse. (2025). "Why Are Hundreds of Data Brokers Not Registering with States?" 750 unique data brokers identified across five state registries, review conducted April 2025, published June 20, 2025.
  3. Vermont Secretary of State registry, as compiled by RecordingLaw. (2026). "Vermont Data Privacy Laws: Data Broker Registry and Consumer Rights." 283 registered data brokers, 2025-2026 filing cycle, last reviewed June 21, 2026.
  4. California Privacy Protection Agency. (2026). "Information for Data Brokers" and DROP enforcement framework. More than 600 registered brokers and over 260,000 queued deletion requests ahead of the August 1, 2026 enforcement deadline.
  5. Deloitte Lietuva UAB. (2025). "ISAE 3000 Independent Limited Assurance Report" on Incogni Inc. More than 420 data broker sites covered and 245 million-plus removal requests processed since January 2022, dated July 18, 2025 and announced August 13, 2025.
  6. Duke University Technology Policy Lab. (2021). "Data Brokers and Sensitive Data on U.S. Individuals." Review of ten major data brokers and the sensitive data categories they advertised for sale.

Note: All figures verified as of July 2026. State registry counts change with each annual filing cycle and are refreshed at least twice a year; California's DROP enforcement figures in particular should be expected to shift materially after the August 1, 2026 enforcement deadline takes effect.