Home Reviews About
Twenty of Time

I Requested My Data from Seven Ad Brokers—Here’s What They Knew

I expected the replies to be disappointing. Data brokers are built to observe people at a distance, assemble profiles from scattered signals, and sell access to audiences that advertisers hope will behave in predictable ways. Still, there is a difference between understanding that business model in theory and opening a folder containing an approximation of yourself.

I sent personal data access requests to seven companies involved in advertising, audience measurement, identity resolution, or lead generation. The requests relied on my rights under European data protection law, chiefly the right to know whether personal data was being processed and to receive a copy of it. I was interested in the practical question behind the legal language: what could these companies actually connect to me?

The results were uneven. Some companies returned extensive profiles, others supplied only policy documents or fragments, and at least one response was difficult to interpret without technical knowledge. Yet the combined picture was revealing. The brokers did not possess one complete secret dossier. They held overlapping pieces: demographic guesses, household details, inferred interests, device information, location signals, and labels designed to make me commercially legible.

The Request Was Easier Than the Investigation

I began by identifying companies that either openly offered an access process or appeared in the ecosystem through advertising, data enrichment, and consumer profiling. The distinction matters because “ad broker” is not always a formal category. A company may describe itself as a marketing platform, data intelligence provider, identity graph operator, or audience solutions business while performing a similar function.

Each request included the information needed to identify me without sending more than necessary. I used an email address associated with online services, my name, and a postal address where required. Some companies requested a copy of an identity document. I declined to provide excessive information where possible and redacted details that were irrelevant to verification.

The legal deadline did not guarantee a useful answer. Several replies arrived as compressed files containing spreadsheets, JSON exports, or long explanations of processing purposes. Others offered a portal where I could view categories but not download the underlying records. One company initially treated the request as a marketing preference inquiry rather than an access request, requiring a follow-up before the distinction was recognized.

This is a familiar problem with data rights. The law gives people a route into the system, but the route is not designed for ordinary reading. A person should not need to understand identity graphs, hashed identifiers, cookie synchronization, and retention schedules to determine whether a company has made a consequential guess about them.

Seven Companies, Seven Different Versions of Me

The most striking feature was inconsistency. The firms did not agree on my age, interests, household status, or purchasing power. Some records were current enough to suggest recent collection, while others looked stale or copied from a commercial database that had not been corrected for years.

One profile identified me through basic contact information and linked me to a household segment. Another attached broad lifestyle categories that were plausible but unsupported. A third had a list of web activity labels, expressed as audience interests rather than a readable history of individual visits. These labels were less intimate than a diary, but they were still consequential because they could determine which adverts, offers, or political messages reached me.

The records also showed how data travels. A company might have received a postal address from a business directory, an email identifier from a publisher, and an interest category from an advertising partner. The final profile then appeared to be a unified observation, even though it had been assembled from unrelated encounters.

Information category What appeared in the responses How certain it seemed
Identity and contact Name, email address, postal address, regional location High when recently supplied
Demographics Approximate age range, gender or household labels Mixed and sometimes inferred
Commercial segments Income bands, homeowner status, purchasing propensity Frequently estimated
Interests Technology, news, finance, travel, shopping categories Broad and difficult to verify
Device and online signals Identifiers, browser or advertising IDs, activity classifications Dependent on partner data
Location Country, region, city, and occasionally a more precise area Usually derived rather than confirmed
Data origins Partners, public sources, customer records, or modeled attributes Often vague

The table makes the information seem tidy, but the underlying files were not. A “homeowner” label might be presented beside a confidence score, while an “interest in finance” category had no clear explanation of what action produced it. The profile was a mixture of facts, assumptions, and administrative leftovers.

The Most Valuable Data Was Often an Inference

People tend to imagine surveillance as a record of actions: a website visited, a product purchased, a location observed. Those records matter, but the commercial value often lies in what a company concludes from them. An inferred income bracket or “likely to move” label can be used even when the inference is wrong.

Several responses contained categories that were not direct statements I had made. They were predictions about me. Some appeared to be generated from location, household composition, age, or purchasing data. Others may have originated with an external provider whose methods were not described in enough detail to reconstruct.

An inferred attribute can be more difficult to challenge than a factual error. If a broker stores the wrong postal address, the correction is straightforward. If it assigns someone to a vulnerable consumer segment, a debt-related audience, or a health-adjacent interest category, the person may never know the label exists. The company can call it a probability rather than a fact, while an advertiser treats it as a targeting instruction.

This is why access rights are more than a personal privacy exercise. They expose a form of social sorting. The system does not need to know everything about everyone. It needs enough signals to classify people into groups that can be priced, prioritized, excluded, or persuaded.

The Identifiers Were the Hidden Glue

Names and addresses were familiar, but the less visible identifiers explained how separate databases could refer to the same person. The responses mentioned hashed email addresses, advertising identifiers, browser-related signals, household IDs, and partner-specific reference numbers. Hashing may obscure an email from casual inspection, but it does not make the underlying relationship anonymous when the same hashed value is used to match records.

This matching layer allows a broker to recognize continuity across services without displaying a conventional name in every file. A publisher, an analytics vendor, and an advertising exchange may each hold a different identifier while relying on an intermediary to connect them. The result is a market in which identity is modular: one company does not need the complete profile if it can reliably request the relevant segment.

The distinction between content and metadata is also less comforting than it sounds. A broker may not have the text of a message, but it can still hold an identifier, timestamp, device type, approximate location, or category derived from activity. For a useful comparison, my review of encrypted messaging protections looks at how message content and surrounding account data can be treated differently under legal requests. The same principle applies here: protecting the substance of an interaction does not erase the surrounding traces.

Some identifiers were easy to opt out of, at least in theory. Others were attached to retention statements that left open the possibility of suppression rather than deletion. A company might stop using a record for advertising while keeping a limited copy to document the request. That distinction is legitimate in certain circumstances, but it means “I deleted my data” is rarely as simple as pressing a button.

Retention Made the Past Commercially Useful

The files included old associations that I would not have expected to remain relevant. A former address, an outdated interest, or an old device relationship can persist because databases are designed to preserve usefulness, not personal context. Data becomes an asset when it can improve matching, even if it no longer describes the person accurately.

One broker explained that information might be obtained from public records, commercial partners, websites, surveys, or data supplied by clients. This broad sourcing language is common, but it does not tell an individual which source created a specific attribute. Without that detail, correcting the record becomes difficult. I can dispute a label, but I cannot always identify the chain that produced it.

The responses also revealed a practical tension between deletion and accuracy. A broker may remove a record after an erasure request, yet a partner can later submit the same information again. Another company may retain a suppression entry so it knows not to contact me, which means some representation of me must remain. Privacy rights operate inside systems that have competing obligations and incentives.

People often focus on the dramatic possibility of a single sensitive fact being exposed. The quieter risk is accumulation. A slightly wrong age range, a stale address, a device identifier, and a set of weak interests may appear harmless separately. Together, they create a durable commercial shadow that can follow someone across websites and campaigns.

Small Privacy Habits Change the Data Trail

The exercise did not make online anonymity seem realistic. It did make the value of reducing unnecessary exposure clearer. Advertising systems rely on repetition: the same email address used everywhere, the same browser profile retained for years, the same account connected to shopping, reading, entertainment, and communication.

I started treating identifiers as resources rather than neutral conveniences. Separate email addresses for different purposes, fewer loyalty programs, restrictive browser settings, and regular permission reviews reduce the number of links available to data brokers. None of these measures creates a sealed private life, but each can make automated matching less confident.

The broader lesson resembles the practical discipline discussed in habits of successful people: consistent small actions tend to matter more than occasional bursts of effort. Privacy works the same way. A one-time cleanup helps, but a routine of checking permissions, rejecting unnecessary tracking, and reading access notices has a greater cumulative effect.

Home networks deserve attention too. Internet service providers can observe connection metadata, and poorly configured routers may expose devices or management interfaces. My guide to securing a home router covers a different part of the privacy stack, but the principle is connected: protect the points where data leaves your control, not just the accounts where you notice it.

What an Access Request Can Change

The immediate benefit of a request is knowledge. I learned which companies recognized me, which categories they attached to me, and which parts of their explanation were vague. That information changed how I evaluated consent banners and “relevant advertising” claims. Personalization became less abstract when I could see the labels that powered it.

The second benefit is correction. If a profile contains an incorrect address, an inappropriate category, or an identifier that should no longer be active, an access request creates an opportunity to challenge it. The process may require patience, but the written record is useful. It turns a general concern about surveillance into a specific dispute about processing.

The requests also expose the limits of individual control. A broker can disclose its own file while withholding information about a partner, a protected trade secret, or another person. A company may claim it cannot identify a person from a particular dataset, even when its business model depends on matching records at scale. These boundaries should be examined by regulators, not quietly accepted as the natural shape of privacy.

If you live in a jurisdiction with access rights, a request can be a modest but meaningful act of inspection. Keep copies of every message, note deadlines, ask for the source and retention period, and request explanations for inferred categories. The goal is not to produce a perfect map of the advertising industry. It is to make the invisible profile visible enough to question.

A Practical Privacy Routine

The seven responses did not reveal a hidden biography. They revealed something more ordinary and, in some ways, more unsettling: a collection of guesses that had become operationally useful. The system knew enough to place me in audiences, connect me to identifiers, and preserve fragments of my past. It did not need to understand me as a person.

That is the central finding. Commercial surveillance is often built from incomplete data, but incomplete does not mean harmless. A wrong label can still influence what appears on a screen, which offer is extended, or which opportunity is never shown. Requesting your data is one of the few times the machinery has to explain itself in terms that can be challenged.

Send an access request to one company that may hold your information, save the response, and read it as evidence rather than paperwork. The first file may be confusing, but it can show where your digital trail has become someone else’s product.