Table of Contents
Data Brokers Have Your Child's Info — Here's How to Remove It
Data brokers collect personal information on minors including names, addresses, and school data. Learn which brokers are biggest and how to opt out under COPPA and state laws.
Search your child’s name on Spokeo. Pause before you do — because what you find might genuinely alarm you. For a child who has ever appeared in a school directory, a sports roster, a neighborhood newsletter, or whose parent has a mortgage on a property, there’s a reasonable chance a data broker has compiled a profile containing the child’s name, approximate age, home address, names of relatives, and possibly the school they attend.
Data brokers are companies whose business model is aggregating, packaging, and selling personal information. They collect data from public records (property records, court documents, voter registrations), from apps that sell user data, from marketing databases, from social media scrapers, and from other brokers. The resulting profiles are sold to background check services, marketers, debt collectors, private investigators, and — in documented cases — stalkers and predators who pay the same fees as legitimate customers.
Children are not exempt from this system. COPPA (Children’s Online Privacy Protection Act) restricts online services from collecting data directly from children under 13 without parental consent. But data brokers largely operate through public record aggregation and third-party data purchases that exist in COPPA’s blind spots. A profile built from your county’s property records, your state’s voter rolls (which list household members), and a school directory PDF posted on a PTA website doesn’t violate COPPA — and it tells a stranger a great deal about your child.
Key Takeaways
- Data broker profiles on minors are common and legal under current federal law in most cases; COPPA’s protections apply narrowly to direct data collection from children online.
- The five largest people-search brokers — Spokeo, WhitePages, BeenVerified, Intelius, and MyLife — all have opt-out processes, but each requires separate requests.
- Automated removal services like DeleteMe, Privacy Bee, and Kanary cost $100–$200/year and handle dozens of brokers; manual opt-outs are free but time-consuming.
- California (CCPA/CPRA), Virginia (CDPA), Colorado (CPA), and Connecticut (CTDPA) give residents stronger rights to request deletion and opt out of data sales.
- Removal is not permanent: brokers re-aggregate data over time, so opt-outs need to be renewed or monitored on an ongoing basis.
What Data Brokers Actually Collect on Your Child
The depth of a data broker profile depends on how long a child has been findable in public records and how many data sources have referenced them. A typical profile on a minor may include:
- Full name (sometimes including middle name)
- Age or birth year
- Current address and previous addresses
- Names of parents, siblings, and other household members
- Schools attended (from school directory data, athletic rosters, honor roll announcements)
- Social media handles (from public profiles)
- Photos (scraped from public social media or news sources)
- Email addresses (if the child has ever signed up for a service using a school email or family-linked address)
Some brokers, particularly those focused on background checks, also pull juvenile court records in states where those are public, academic awards mentioned in local news, and youth sports league memberships published on public websites.
The Electronic Privacy Information Center (EPIC) has documented how data broker profiles on children can facilitate stalking, targeted harassment, and online grooming — a predator who knows a child’s name, school, sports team, and home neighborhood has a substantial social engineering advantage before the first contact is ever made.
The Major Brokers and How to Opt Out
Each broker requires a separate opt-out request. There is no single “remove me from all brokers” registry in the US. Here are the largest by traffic and the opt-out process for each:
| Broker | What They Show | Opt-Out Method | Time to Process |
|---|---|---|---|
| Spokeo | Name, address, relatives, phone | spokeo.com/opt_out/new | 24–48 hours |
| WhitePages | Name, address, age, relatives | whitepages.com/suppression_requests | 24 hours |
| BeenVerified | Full profile + criminal records | beenverified.com/opt-out/ | 24–48 hours |
| Intelius | Reverse phone, address history | intelius.com/opt-out | 72 hours |
| MyLife | Reputation score, relatives | mylife.com/privacy/remove-my-information.pubview | 3–5 days |
| PeopleFinder | Address, relatives, age | peoplefinders.com/manage | 24–48 hours |
| Radaris | Full profile | radaris.com/ng/privacy | 24–48 hours |
| Pipl | Professional + personal data | Email opt-out only | 5–7 days |
| Truthfinder | Background report | truthfinder.com/opt-out/ | 48–72 hours |
| Spokeo (Images) | Scraped photos | Separate image opt-out form | 72 hours |
The general opt-out process requires you to:
- Search for your child’s name on the broker’s site.
- Locate the specific listing for your child.
- Navigate to the opt-out or suppression request form.
- Submit identifying information (name, address, sometimes email) to verify which record to remove.
- Confirm via email in most cases.
A critical note: some opt-out forms ask you to create an account to submit the request. Don’t. Creating an account on a data broker site provides them with confirmed, verified data about you — which they can then re-aggregate. Submit opt-out requests as a guest wherever possible, and use a dedicated email address (not your primary) for confirmation emails.
Manual vs. Automated Removal Services
Manual opt-outs are free but require significant time. A thorough manual removal across 30–50 data brokers takes 4–6 hours initially and requires follow-up every 3–6 months as data is re-added.
Automated removal services send opt-out requests on your behalf to dozens or hundreds of brokers and monitor for re-addition:
- DeleteMe (~$129/year for one person): Covers 750+ broker sites; sends quarterly reports showing which records were found and removed. joindeleteme.com
- Privacy Bee (~$197/year): Broader broker coverage, includes dark web monitoring.
- Kanary (~$149/year): Includes social media data removal requests.
- Optery (~$99/year for basic): Tiered pricing; lower tiers require you to click through opt-out processes they identify.
For families with children, the cost-benefit calculation depends on how concerned you are about your child’s exposure. For families dealing with an active safety concern (a custody dispute, a stalking situation, or a child who has experienced harassment), a paid service is the more practical option.
COPPA Protections and Their Limits
COPPA (15 U.S.C. §§ 6501–6506) restricts online services from collecting, using, or disclosing personal information from children under 13 without verifiable parental consent. The FTC enforces COPPA and has levied significant fines: Google/YouTube paid $170 million in 2019 for COPPA violations, and Epic Games (Fortnite) paid $275 million in 2022.
However, COPPA has important limitations for the data broker context:
COPPA applies to “operators” of websites and online services. A data broker that builds profiles primarily from public records and third-party data purchases — rather than from direct child interaction on their platform — may operate outside COPPA’s core requirements.
COPPA’s verifiable parental consent requirement applies at collection. Data that was collected from a parent’s account, a public document, or a purchase made on a non-COPPA-covered service is not covered by COPPA’s consent requirement.
COPPA does not give parents a universal right to demand deletion from all databases. It gives parents the right to review and delete information that a covered operator collected directly from their child.
For a deeper look at how COPPA intersects with your family’s digital footprint, see our guide on kids’ online privacy and what COPPA actually covers.
State Privacy Laws: Stronger Rights in Some States
If you live in California, Virginia, Colorado, or Connecticut, state privacy laws give you rights that go beyond COPPA:
California (CCPA/CPRA): Businesses that collect personal information on California residents must honor “Do Not Sell or Share My Personal Information” requests. For children under 16, businesses must get opt-in consent before selling data (16–under-13 requires parent opt-in). The California Privacy Protection Agency (CPPA) at cppa.ca.gov is the enforcement body.
Virginia (CDPA): Parents of children under 13 can exercise data rights on behalf of their child, including the right to access, correct, delete, and opt out of sale of personal data.
Colorado (CPA): Similar rights; also requires businesses to conduct and document data protection assessments for processing that poses heightened risk, including processing children’s data.
Connecticut (CTDPA): Went into effect July 2023; includes specific provisions for children under 13.
If you are in a covered state and a data broker ignores your opt-out request, you can file a complaint with your state attorney general. California residents can also file with the CPPA. These complaints have real teeth — Virginia fined Chegg $4 million in 2023 partly for inadequate data practices affecting students.
How to File a COPPA Complaint
If you believe a website, app, or online service has collected your child’s data without proper consent:
- Document the violation: screenshot the profile, save the URL, note what data is shown.
- File a complaint at ftc.gov/complaint — select “Children’s Privacy” as the issue category.
- You can also report to your state attorney general’s consumer protection division.
The FTC does not resolve individual complaints (they use complaint data to identify patterns for enforcement), but complaints contribute to investigations that lead to enforcement actions. NCMEC’s CyberTipline is the appropriate reporting channel if the data exposure is connected to potential exploitation.
Reducing Future Data Collection
Removing existing records is the reactive step. Reducing the volume of data that enters broker databases in the first place requires ongoing attention:
- Review what your school publishes publicly. Many COPPA violations traced to data brokers originate from school directories, athletic rosters, and honor roll lists published on public-facing school websites. Request that your child’s information be omitted from public listings.
- Opt out of “people search” data collection from your phone carrier. Major carriers sell aggregated location and usage data; all four major US carriers have opt-out programs.
- Use a PO box or alternate mailing address for non-essential registrations. Property records (which include home addresses) are a major source of household data for brokers.
- Check what your child’s apps share. Apps rated for children that monetize through data sharing often sell usage data that ends up in broker databases. Review permissions and privacy policies of apps your child uses regularly.
For more on protecting your child’s overall digital footprint, our guide on social engineering and how scammers manipulate children online covers how bad actors use publicly available information to build trust with minors.
What to Watch For Over the Next 3 Months
The FTC is expected to release updated COPPA Rule guidance in late 2026 that would expand coverage to include data brokers more explicitly, following the FTC’s 2024 report on commercial surveillance practices. The American Data Privacy and Protection Act (ADPPA) has been reintroduced in Congress; if passed, it would create a federal right to opt out of data broker sales regardless of state residency. Monitor ftc.gov/privacy for updates. California’s “Delete Act” (SB 362, effective 2026) will require data brokers to register with the CPPA and honor deletion requests submitted through a single centralized portal — the first of its kind in the US.
Frequently Asked Questions
Is it legal for data brokers to have information about my child?
In most cases, yes. Data brokers operating primarily from public records and third-party data purchases operate legally under current federal law. COPPA restricts direct collection from children under 13, but public record aggregation is a legal gray area. State laws in California, Virginia, Colorado, and Connecticut offer stronger protections.
How long does a data broker opt-out stay in effect?
Opt-outs are generally not permanent. Most data brokers will re-add a record when they pull updated data from their source databases — which happens every few months to a year. This is why ongoing monitoring (either manual or through a paid service) is necessary for sustained protection.
Can data brokers have information on very young children?
Yes, though depth varies. A child born into a household that owns property will have their name potentially linked to their parents’ address from the day the property record is updated with household composition data. Children who appear in local news, school announcements, or sports rosters from an early age can accumulate substantial profiles by age 10.
What’s the best starting point if I want to do this manually?
Start with the five biggest: Spokeo, WhitePages, BeenVerified, Intelius, and MyLife. Removing from these five eliminates the profiles most likely to appear in the first page of search results. Then work through PeopleFinder, Radaris, and Truthfinder. Spend no more than 15 minutes per broker — each opt-out is a simple form submission.
About the author Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.
Sources
- Federal Trade Commission. “Complying with COPPA: Frequently Asked Questions.” ftc.gov/tips-advice/business-center/guidance/complying-coppa-frequently-asked-questions
- Electronic Privacy Information Center. “Data Brokers and the Right to Privacy.” epic.org/data-brokers/
- California Privacy Protection Agency. “CPPA Enforcement.” cppa.ca.gov
- FTC. “Commercial Surveillance and Data Security Rulemaking.” ftc.gov, 2024
- National Center for Missing & Exploited Children. “Online Safety.” missingkids.org
- Pew Research Center. “Americans and Privacy: Concerned, Confused and Feeling Lack of Control Over Their Personal Information.” pewresearch.org, 2019
- Internet Society. “Data Broker Ecosystem: How Data Is Collected, Aggregated, and Shared.” internetsociety.org