⚠️ Educational Purpose
This page explains corporate collection so you can defend against it. The aim is your own threat modeling and self-OSINT: understanding what companies can gather and sell about you, then reducing it. Nothing here is a how-to for targeting other people. Capabilities are described at the level needed to defend, and every factual claim links to a primary source.
TL;DR: Corporations are the third adversary tier, and the one that supplies all the others. Data brokers, ad-tech firms, people-search companies, camera and license-plate networks, facial recognition vendors, insurers, and employers gather personal data at industrial scale. One broker alone held 3,000-plus data points on nearly every US consumer. A camera network scans 20 billion vehicles a month. A face database holds 30 billion-plus scraped images. The key point: these companies do not just collect, they sell the capability, feeding individuals and organized groups below and nation-states above. You cannot out-run this tier by staying quiet, but you can opt out, reduce your browser fingerprint, and check which databases hold you.
The individual watches you by hand. The organized group pools effort. A corporation does something different in kind: it aggregates data on hundreds of millions of people at once, turns that data into a product, and sells the product to everyone else on this ladder. Understanding this tier is less about any single company and more about a supply chain, an industry that manufactures the raw material of surveillance and puts it on the market.
What a corporation can collect about you
No single firm does all of the following, but between them the industry covers your records, your devices, your movements, your face, and your workday.
Data brokers and the thousand-point profile
Data brokers buy, scrape, and merge public records, court filings, property deeds, voter files, loyalty-card purchases, warranty registrations, and app data into unified profiles. The scale is the point. A 2014 Federal Trade Commission study of nine major brokers found that one of them, Acxiom, held information on 700 million consumers worldwide, with more than 3,000 data segments compiled for nearly every US consumer.[1] That is not a dossier a person builds by hand. It is an assembly line, and it runs whether or not you have ever heard the company's name.
Browser fingerprinting and ad-tech
You do not need an account to be tracked across the web. Ad-tech firms identify browsers from their configuration alone: fonts, screen resolution, time zone, language, and installed plug-ins combine into a signature that persists even after you clear cookies. In the foundational 2010 study behind the EFF Panopticlick project, researcher Peter Eckersley found that 84 percent of nearly half a million tested browsers were unique and identifiable, rising to 94 percent among browsers with Flash or Java enabled.[2] A profile assembled without your name still follows you from site to site, and can later be matched back to you.
Cameras and license-plate networks
Automated license-plate readers (ALPRs) photograph passing cars, read the plate, and log the time and place. Stitched into a network, those logs become a searchable history of where vehicles go. Flock Safety, one of the largest operators, reports scanning more than 20 billion vehicles per month across over 5,000 US communities in 49 states.[3] A single reader captures a moment; a national grid captures a pattern of life, sold as a service to whoever subscribes.
Facial recognition at scale
Facial recognition companies scrape public photos to build searchable face databases. By its own account, Clearview AI's database had grown to more than 30 billion scraped images by late 2023.[4] Regulators have pushed back, with mixed and unfinished results. In 2022 the UK Information Commissioner's Office fined Clearview £7,552,800 and ordered it to delete UK residents' data, though that penalty is not final: it has moved through the UK tribunals and, as of late 2025, remains in active litigation.[5] The same year, a settlement under Illinois biometric privacy law permanently barred Clearview from selling or giving paid or free access to its face database to most private companies and individuals nationwide.[6] Italy's data protection authority separately fined the company €20 million and ordered it to delete Italians' data and stop processing it.[7] The technology exists at scale; the legal limits on it are patchy and still being fought over.
Bossware at work
Employers now run surveillance on their own staff. Monitoring software, often called bossware, records keystrokes, screenshots, application use, location, and automated productivity scores. In a 2024 nationally representative survey, more than two-thirds (68 percent) of US workers reported being subject to at least one form of electronic monitoring on the job.[8] The same survey linked constant monitoring to harm: workers whose productivity was tracked all the time were roughly three times more likely to report working faster than is healthy or safe (46 percent) than workers who reported no electronic monitoring at all (15 percent).[8]
Your car and your location for sale
Modern cars and phones both emit sellable data. In 2024, reporting revealed that General Motors had shared detailed driving behavior (hard braking, rapid acceleration, speeding) collected through its Smart Driver program with the brokers LexisNexis and Verisk, who packaged it into reports sold to insurers that used it to raise some drivers' premiums; GM ended the program after the reporting.[9] Phones are worse. The FTC's 2024 order against the location broker X-Mode Social and its successor Outlogic found the company sold precise location data that revealed visits to sensitive places, including medical facilities, houses of worship, and businesses serving LGBTQ+ communities, and that it kept collecting some users' locations even after they had opted out.[10] A separate 2024 FTC order against InMarket Media described an advertising SDK that received location pings from roughly 100 million unique devices a year and sorted people into nearly 2,000 targeted-advertising segments.[11]
What resources add over an organized group
An organized group pools what its members can find. A corporation works at a different order of magnitude, and it does not only gather data: it packages and sells the capability itself. That is the detail that ties every tier on this ladder together. The same industry that profiles you also runs the storefront that arms everyone else, in both directions.
At the retail end are people-search products, the consumer-facing face of the broker industry. The FTC warned in its 2014 report that these products can be used to "facilitate harassment, or even stalking," which is exactly the capability the individual and organized-group tiers depend on.[1] A stalker does not need skill when a company will sell an address for a small fee.
At the wholesale end are bulk sales that reach governments. When the Consumer Financial Protection Bureau proposed a 2024 rule to bring data brokers under the Fair Credit Reporting Act (a rule the agency later withdrew in 2025), it described the harm in blunt terms: "countries of concern, like China and Russia, can purchase detailed personal information about military service members, veterans, government employees, and other Americans for pennies per person."[12] The same proposal pointed to the 2020 murder of a federal judge's son by an attacker who had bought the judge's home address through a data broker.[12] The proposed rule is gone, but the harm chains the CFPB documented are not.
The scale of the supply side is hard to fully map, because the industry resists being counted. An EFF analysis in 2025 found that at least 750 data brokers had registered in at least one US state registry, yet many that register in one state skip others: 291 firms that registered elsewhere never registered in California, and 309 skipped Vermont.[13] Even the transparency laws undercount the field, which means the real number of companies trading your data is larger than any single list shows.
Run this on yourself
The most direct way to understand this tier is to read the same signals a corporation reads. Two of this site's tools do that with no account and no login.
- Run the browser fingerprint test to see how identifiable your specific browser configuration is, the same signature ad-tech firms use to track you without cookies.
- Run the browser privacy audit to check what your browser leaks and where the easy fixes are.
- Search your own name on a few people-search sites. What comes back (addresses, relatives, phone numbers, past cities) is the broker profile that anyone else can buy.
Seeing your own result is more persuasive than any statistic. It shows you which parts of your footprint are already on the market.
How these techniques work
Each capability on this page has a deeper explainer. Read these to understand the mechanism, then use the defenses below.
- How data brokers build your profile: the pipeline that turns public records, purchases, and app data into a sellable dossier.
- License plate readers and vehicle OSINT: how ALPR networks turn passing cars into a searchable movement history.
- Location data brokers: how your phone's location is collected, packaged, and sold, and what regulators found.
- Workplace surveillance and bossware: what employer monitoring records and how common it has become.
Defend against corporate collection
You cannot delete this industry, but you can shrink your exposure and make yourself harder to profile.
- Opt out of people-search sites and data brokers. Work through our people-search opt-out master list to remove yourself from the major brokers, and repeat it, because profiles get rebuilt from fresh public records.
- Reduce your browser fingerprint. Use the fingerprint test and browser audit to find what makes you identifiable, then harden or switch your browser to blend into a larger crowd.
- Check which surveillance databases hold you. Follow the guide to checking surveillance databases to find out whether you appear in facial recognition, ALPR, and broker systems.
- Automate the recurring removals. Doing broker opt-outs by hand is slow, so paid services exist to run them continuously. See our reviews of Optery and Incogni to weigh whether one fits your situation.
💰 Resources can buy up a tier
The corporation is the pivot point of the whole ladder, and the money flows both ways. Anyone with a credit card can buy the people-search reports and location data these companies produce, which is how a lone individual or an organized group punches above its natural weight. Reach the other way and the same data is bought, subpoenaed, or compelled by governments, which is how a nation-state avoids doing the collection itself. When you model your own threat, treat the corporate tier not as one adversary but as the marketplace that supplies the rest. The next page up the ladder, the nation-state, is largely a story about who can pay for or force access to everything on this one.
Frequently Asked Questions
What is a data broker?
A data broker is a company that collects personal information from public records, purchase histories, app tracking, and other sources, then compiles it into profiles that it sells or licenses to advertisers, other brokers, employers, insurers, and government agencies. The Federal Trade Commission found in 2014 that one broker alone held data on 700 million consumers, with more than 3,000 data segments for nearly every US consumer.
Can I remove myself from data broker and people-search sites?
Often yes, though it takes ongoing effort. Most people-search sites and brokers offer an opt-out process, and several US states now run data broker registries and deletion mechanisms. Because brokers re-scrape public records, removals are not permanent and need to be repeated. Automated removal services such as Optery and Incogni handle recurring opt-outs for a fee.
Does clearing cookies stop browser fingerprinting?
No. Browser fingerprinting identifies you from configuration details such as fonts, screen size, and installed plug-ins rather than from stored cookies. Research behind the EFF Panopticlick project found that 84 percent of tested browsers were uniquely identifiable, rising to 94 percent among browsers with Flash or Java, so clearing cookies alone does not prevent it.
Is corporate facial recognition legal?
It depends on the jurisdiction. Under Illinois biometric privacy law, a 2022 settlement permanently barred Clearview AI from selling access to its face database to most private entities nationwide. Regulators in the UK and Italy issued penalties against the same company, though the UK fine remains in active litigation. Many US states still have no specific biometric privacy law at all.
What is bossware?
Bossware is workplace monitoring software that tracks employee activity such as keystrokes, screenshots, application use, location, and productivity scores. A 2024 nationally representative survey found that 68 percent of US workers reported at least one form of electronic monitoring on the job.
Sources
- Federal Trade Commission. "Data Brokers: A Call for Transparency and Accountability." May 2014. ftc.gov
- Electronic Frontier Foundation. "Web Browsers Leave 'Fingerprints' Behind as You Surf the Net." May 17, 2010. eff.org
- NBC News. "Flock police cameras scan billions per month, sparking protests." November 1, 2025. nbcnews.com
- Clearview AI. "Clearview AI Wins Appeal Against UK Information Commissioner Office ICO Fine." October 19, 2023. clearview.ai
- Information Commissioner's Office. "ICO fines facial recognition database company Clearview AI Inc more than £7.5m and orders UK data to be deleted." May 23, 2022. ico-newsroom.prgloo.com
- American Civil Liberties Union. "In Big Win, Settlement Ensures Clearview AI Complies With Groundbreaking Illinois Biometric Privacy Law." May 9, 2022. aclu.org
- TechCrunch. "Italy fines Clearview AI €20M and orders data deleted." March 9, 2022. techcrunch.com
- Washington Center for Equitable Growth (Alexander Hertel-Fernandez). "Estimating the prevalence of automated management and surveillance technologies at work and their impact on workers' well-being." October 1, 2024. equitablegrowth.org
- Forbes (Roger Dooley). "Your Driving Data May Be Sold To Insurers, General Motors Reveals." March 12, 2024. forbes.com
- Federal Trade Commission. "FTC Order Prohibits Data Broker X-Mode Social and Outlogic from Selling Sensitive Location Data." January 9, 2024. ftc.gov
- Federal Trade Commission. "FTC Order Will Ban InMarket from Selling Precise Consumer Location Data." January 18, 2024. ftc.gov
- Consumer Financial Protection Bureau. "CFPB Proposes Rule to Stop Data Brokers from Selling Sensitive Personal Data to Scammers, Stalkers, and Spies." December 3, 2024. consumerfinance.gov
- Electronic Frontier Foundation. "Why Are Hundreds of Data Brokers Not Registering with States?" June 24, 2025. eff.org