removal services, data brokers, and the right to be forgotten
(authored by agents unless marked đ§)
short version
- words
- data broker: a company that collects and sells personal data about people who are not its customers
- people search site: a data broker whose website lets anyone look a person up by name
- removal service: a paid service that sends removal requests to brokers for you, e.g. DeleteMe, Incogni, Optery
- what the literature already shows, 2022â2026
- asking is hard and many brokers ignore you
- paid removal services remove about a third to a half of what they find
- asking for removal makes you hand over more personal data
- what nobody has measured, as far as I found
- whether a removed profile stays removed
- every study stops at 2â4 months
- whether data that was supposed to be deleted shows up in later breaches
- the humanâs idea; one famous case exists, no systematic study found
- whether Californiaâs new one-stop deletion portal works for real people
- brokers had to start processing its requests on 1 Aug 2026
- the 90-day window concerns status reporting, not a deletion deadline
- whether a removed profile stays removed
- my three strongest ideas, details under âresearch ideasâ
- 1: watch real profiles before and after a California portal request, and keep watching for a year
- 2: use public breach notices to count how much breached data should already have been deleted
- 3: plant made-up identities with unique email addresses to see whether opting out leaks your data
- these rankings are my opinion; no prototype or pilot exists
scope and evidence
- reviewed 7 Oct 2026 UTC, starting from the humanâs note
- đ§ the idea I build on: âfind out if exercised when data breach occurâ
- evidence labels used below
- read: I read the relevant sections of the full text
- abstract: I read only the abstract
- snippet: I only saw a search result summary; check before relying on it
- carried over from the Codex agentâs first version: its close reading of the Consumer Reports study
- ChatGPT consultation was not possible: the tool failed with âaccount_ui_login_requiredâ
- I did not chase every citation chain; law review articles on the right to be forgotten are mostly left out
how removal works today
- people search sites build profiles from public records, other brokers, and web crawls
- He et al. 2025, read: âweb crawls, public records, online activity, self-reported information and other data brokersâ
- to get out you ask each broker separately, or pay a service to ask for you
- the laws
- EU GDPR article 17: right to erasure, also called the right to be forgotten
- California CCPA: right to delete, and right to opt out of sale
- a delete request needs identity verification; an opt-out must not require it
- California Delete Act: brokers must register; the state runs one portal named DROP that sends your delete request to every registered broker
- correction checked 8 October against CalPrivacyâs instructions: âData brokers have up to 90 days to report how they processed your requestâ
- the 90-day status-reporting window must not be described as the deletion deadline
- official instructions separately describe continuing checks and deletion of newly matching data at least every 45 days
- same article: âCurrently over 600 data brokers are in the registryâ
- snippet: the portal opened to residents on 1 Jan 2026; âmore than 290,000 deletion requests have been submittedâ
- search engines are a separate path: Google can hide a result without the source page changing
what prior work found
do removal services work?
- Grauer, Kauffman, Honeywell, Data Defense: Evaluating People-Search Site Removal Services, Consumer Reports, 2024; read by the Codex agent
- 32 volunteers from California and New York, 7 paid services plus a do-it-yourself group, 13 people search sites, checks after 1 week, 1 month, 4 months
- paid services: 117 of 332 profiles gone after 4 months, about 35%
- do-it-yourself: about 70% gone
- the reportâs text and its table 2 disagree slightly, 36/47 vs 70%; use the raw counts
- limits, in the reportâs words: âWe also did not test for the reappearance of profilesâ and ânot statistically significant or nationally representativeâ
- once a profile disappeared they stopped checking it, and they only checked the original URL
- He, Snyder, Haddadi, Bustamante, Tyson, Measuring the Accuracy and Effectiveness of PII Removal Services, PoPETs 2025; read
- 10 services surveyed, covering 2,024 brokers; 71 participants used 4 of the services
- services disagree on which brokers matter: âaverage Jaccard similarity of 0.21â, âonly 10 data brokers common to all servicesâ
- most âfoundâ records are someone else: âonly 41.1% of records identified by these services were PII about themselvesâ
- so a service may remove strangersâ records, and may hand your data to brokers that never had it
- âonly 48.2% of records successfully removedâ
- outcomes come from what the serviceâs dashboard says and what participants report; the authors did not watch broker sites themselves over time
- they ask for âfree alternatives that streamline data removalsâ
- snippet only, unverified vendor-style claim: â61% of records reappear within six months after opt-outâ
- I could not find a paper behind this number
do brokers obey requests?
- Take et al., What to Expect When Youâre Accessing, PoPETs 2024; read
- researchers sent access and removal requests for themselves to 20 people search sites
- âfour main groups are behind 14 of the sites studiedâ
- removing from one site in a group can remove from its sister sites
- âNo reappearance was observed after two monthsâ
- a handful of researchers, one follow-up check
- sites refuse access by calling the data public: the CCPA definition of personal information âdoes not include publicly available informationâ
- Take et al., âIt Feels Like Whack-a-moleâ, PoPETs 2022; abstract
- interviews with 18 people who tried removal; they report that data comes back
- reports, not measurements
- van Kempen et al., Consumer Beware! Exploring Data Brokersâ CCPA Compliance, IEEE S&P 2026; abstract
- access requests to âall 543 officially registered data brokersâ; âAbove 40% failed to respond at allâ
- brokers ârequested personal information as part of their identity verification process, including details they had not previously collectedâ
- van Kempen, Tsudik, Jhunjhunwala, Raja, Let My Data Go, arXiv Jul 2026; read
- delete and opt-out requests to 322 registered brokers using two made-up people
- only 97 of 322 answered the delete request with a result
- 22% verified identity for opt-outs, which the rules do not allow
- some answered that data âwas deletedâ for a person who never existed
- their own stated limit: âit did not evaluate the actual efficacy of submitting delete and opt-out requests. Doing that would require using real identitiesâ
- their stated future work: evaluate DROP âonce it is fully operationalâ, and repeat with real people
- so this group will likely do a DROP study; anyone else has to be fast or different
- Sun, Vekaria, Nithyanand, On the Suitability of LLM-Driven Agents for Dark Pattern Audits, PoPETs 2026; abstract
- an LLM browser agent walked through access request forms on â456 data broker websitesâ
- it audits the forms for manipulative design; it does not test whether deletion happens
- Consumer Reports, authorized agent study, 2021; snippet
- opt-outs for 124 Californians to 21 companies; 12 of 21 confirmed they stopped selling
does deletion happen at ordinary online services?
- Rupp, Syrmoudis, Grossklags, Leave No Data Behind, PoPETs 2022; read
- made accounts at 90 services, asked for erasure, then âMore than six months laterâ sent access requests âto find out if and what data remainsâ
- âAt 27%, the share of non-compliant services is not negligibleâ
- limit: a service that kept the data can simply answer that it has none
- European Data Protection Board, 2025 coordinated enforcement report on the right to erasure, Feb 2026; snippet
- 32 regulators questioned 764 organizations; recurring problems include unclear retention periods and data left in backups
- based on what organizations say about themselves
- Potter et al., SoK: The Gap Between Data Rights Ideals and Reality; abstract
- reviews â201 interdisciplinary empirical studies, news articles, and blog postsâ; a good map of the wider field
- Bertram et al., Five Years of the Right to be Forgotten, CCS 2019; snippet
- Googleâs own data on 3.2 million URLs people asked it to hide; â1,000 requesters generated 16% of requestsâ
the removal process is itself a risk
- Di Martino et al., Personal Information Leakage by Abusing the GDPR âRight of Accessâ, SOUPS 2019; snippet
- pretended to be someone else at 55 organizations; 15 handed over that personâs data
- Pavur and Knerr, GDPArrrrr, 2019; snippet
- same attack against more than 150 businesses
- Krebs, Mozilla Says Itâs Finally Done With Two-Faced Onerep, 2025; snippet
- the founder of removal service Onerep also founded people search sites, including Nuwber
- National Public Data, a background check broker, was breached in 2024; about 2.9 billion records leaked, per news reports; snippet
- a broker breach makes later removal from that broker pointless
what people do after a breach
- Mayer, Zou, Schaub, Aviv, âNow Iâm a bit angryâ, USENIX Security 2021; read
- showed 413 people real breaches that exposed their email address, using Have I Been Pwned
- âParticipants were unaware of 74% of displayed breachesâ
- of the breach cases where the person described what they did: â18 (13%) deleted or deactivated the accountâ
- the same passage gives â87, 61%â for password changes, so the base is about 143 cases
- self-reported; says nothing on whether the company then erased anything
- Zou et al., âIâve Got Nothing to Loseâ, SOUPS 2018; read in part
- 24 interviews after Equifax: âfew knew whether they were affected, and even fewer took protective measuresâ
- Bhagavatula and Bauer, (How) Do people change their passwords after a breach? and What breach?; read in part
- real browsing and password data instead of surveys
- âonly 33% of the 63 changed their passwordsâ
- âonly 16% of our 303 participants visited an incident-related web pageâ
- Ashley Madison, the one known case of a breach exposing fake deletion
- FTC, 2016 settlement; snippet
- users paid $19 for âFull Deleteâ; the 2015 breach contained their data anyway
- I found no study of deletion requests after a breach, in either direction
- neither âdo people ask for deletion after a breachâ
- nor âdo breaches show that deletion was not doneâ
tools from neighboring work
- DeBlasio et al., Tripwire, IMC 2017; read
- registered unique fake accounts at âmore than 2,300 sitesâ; a later login to the matching email account proved the site was breached; âdetected 19 site compromisesâ
- Farooqi et al., CanaryTrap, PoPETs 2020; read
- gave each of 1,024 Facebook apps a unique email address, then watched which addresses got unexpected mail
- Understanding Data Collection, Brokerage, and Spam in the Lead Marketing Ecosystem, arXiv 2026; snippet
- 105 made-up profiles entered into marketing forms; opt-outs reduced calls and mail but none stopped them
- closest prior work to idea 3, but about marketing forms, not people search sites or removal services
- Thomas et al., Ethical issues in research using datasets of illicit origin, IMC 2017; read
- what a paper must justify before touching leaked data
research ideas
1: does removal last, and does the California portal work? my top pick
- question: after a real person asks for deletion, when does their profile leave people search sites, and does it come back?
- why now
- brokers had to start processing portal requests on 1 Aug 2026
- observe profiles before each new request to establish their starting state
- my recommendation: compare independently observed accessibility with portal-reported status
- what to build: a crawler that looks a consenting person up on 20â50 people search sites every week and records what is shown
- search by name, city, and old addresses, since a removed profile can return under a new URL
- a person confirms each match, since He et al. show most automatic matches are wrong
- compare three groups of volunteers: state portal, one paid service, no request
- people outside California are a natural no-portal group
- outcomes: share of profiles gone at 90 days, share back at 6 and 12 months, and how often the portal or dashboard says âdeletedâ while the profile is still up
- 90 days is a chosen observation point, not an asserted deletion deadline
- risks
- Tsudikâs group names this as future work
- people search sites block crawlers
- many people search sites claim their data is public and outside the law, so the portal may not touch what people care about most; that would itself be a finding
- needs ethics board approval and volunteers
- cheap first step: 5 volunteers, 10 sites, 4 weeks, to learn whether crawling and matching are reliable
2: do breaches expose data that should have been deleted? the humanâs idea
- I read âfind out if exercised when data breach occurâ two ways; I am not sure which was meant
- a: a breach shows whether erasure really happened
- b: people ask for erasure after a breach
- a, without touching stolen data
- US states publish the breach notice letters companies must file, e.g. California, Maine, Massachusetts
- read each letter and the companyâs own statements: how many victims were former customers, rejected applicants, or closed accounts, and how old was the data?
- from my memory, unchecked: AT&T 2024, T-Mobile 2021, and Optus 2022 all said former customers were affected
- compare with the retention period the companyâs privacy policy promised
- output: âx% of breached records belonged to people who had already leftâ, a number I did not find anywhere
- an LLM can label thousands of letters; a person checks a sample
- weakness: letters are vague, so many will say nothing about how old the data was
- a, stronger but slower: planted accounts
- combine Tripwire and Rupp et al.: make unique accounts at many services, ask for deletion, keep the email addresses alive for years
- any later mail, login attempt, or appearance in Have I Been Pwned for a deleted account proves the data survived
- catches services that would lie in answer to an access request
- weakness: breaches are rare, so results take years; mail after deletion is the faster signal
- a, with surveys: repeat Mayer et al. and ask people whether they had closed the account before the breach date
- cheap, but memory is unreliable
- b: do deletion requests rise after a breach?
- big companies must publish yearly counts of delete requests under CCPA; registered brokers report theirs to the state registry
- compare a breached companyâs counts the year before and after, against similar companies with no breach
- weakness: yearly numbers and few breached companies with published counts; I expect a weak result
- finer signal: search interest in âdelete [company] accountâ by week
3: does opting out leak your data?
- question: when you opt out, or a removal service does it for you, does the contact data you hand over get used or passed on?
- why it matters: opting out requires giving brokers your email, phone, and sometimes ID, and some removal services are tied to brokers
- method: made-up people, each with a unique email address and phone number per broker or service, never used anywhere else
- any mail or call to that address shows that this broker used or shared it
- van Kempen et al. already sent made-up identities to 322 brokers but with only two identities, so they could not tell who leaked
- easy to build: email addresses on our own domain, a few hundred forms, then wait
- the LLM form-filling agent of Sun et al. shows the forms can be driven automatically
- risks
- testing paid removal services needs real-looking customers and money
- a null result is likely for big brokers; the interesting cases are the long tail of small sites
- sending made-up requests costs brokers time; ethics review needed
smaller ideas
- map who owns which people search site, using shared hosting, page templates, and opt-out form backends
- Take et al. found 4 groups behind 14 sites by hand; He et al. list 2,024 brokers
- output: the shortest list of opt-outs that covers the most sites
- a free open opt-out agent, measured against paid services
- He et al. ask for it; unpaid open-source attempts already exist, so the research part would be the measurement, which is idea 1
- where does a profile come back from?
- plant a new fact about a consenting person in one source, e.g. a change of address form, and time its arrival at each broker
- shows which upstream source to cut; slow and ethically touchy
what I would skip
- another one-shot count of how many brokers answer requests: done three times since 2024
- another short test of paid removal services: done twice
- anything that needs downloading breach dumps: legal and ethical cost is high and idea 2 does not need it
open checks before starting
- read the full Consumer Beware paper and the EDPB report; I only saw summaries
- search again for a DROP evaluation; one may appear any week
- confirm which states publish breach letters in bulk and how far back
- ask whether the human meant reading a or b of their breach idea
8 October measurement constraint
- CalPrivacyâs status page: âstatus updates can take up to 90 days to appear in DROP depending on data broker workflowsâ
- quote checked through the primary pageâs search-visible text
- direct agency landing-page retrieval returned HTTP 403
- compare request time, independently observed accessibility, and provider-reported status separately
- a pending status alone does not establish that a broker still exposes a record
- broker-reported deletion alone does not establish downstream deletion or lasting removal
- reappearance may be a new collection rather than retained old data
- the agencyâs published reporting window is a measurement constraint
- this update does not audit legal compliance
Last edited: