<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>data brokers &#8211; WithoutCensorship</title>
	<atom:link href="https://withoutcensorship.com/tag/data-brokers/feed/" rel="self" type="application/rss+xml" />
	<link>https://withoutcensorship.com</link>
	<description>Free access to knowledge and truth without borders.</description>
	<lastBuildDate>Tue, 28 Jul 2026 18:59:37 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://withoutcensorship.com/wp-content/uploads/2026/07/cropped-withoutcensorship-logo-32x32.png</url>
	<title>data brokers &#8211; WithoutCensorship</title>
	<link>https://withoutcensorship.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Hardening your browser in an afternoon</title>
		<link>https://withoutcensorship.com/hardening-your-browser-in-an-afternoon/</link>
					<comments>https://withoutcensorship.com/hardening-your-browser-in-an-afternoon/#respond</comments>
		
		<dc:creator><![CDATA[Pavel Kadlec]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 12:33:53 +0000</pubDate>
				<category><![CDATA[Guides]]></category>
		<category><![CDATA[data brokers]]></category>
		<category><![CDATA[surveillance]]></category>
		<guid isPermaLink="false">https://withoutcensorship.com/?p=27457</guid>

					<description><![CDATA[<img width="150" height="150" src="https://withoutcensorship.com/wp-content/uploads/2026/07/guide-hardening-your-browser-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="Cover image for the guide Hardening your browser in an afternoon" decoding="async" />You do not need to become a security expert. A handful of settings, one content blocker and a single afternoon will remove most of the tracking that follows you around the web.]]></description>
										<content:encoded><![CDATA[<img width="150" height="150" src="https://withoutcensorship.com/wp-content/uploads/2026/07/guide-hardening-your-browser-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="Cover image for the guide Hardening your browser in an afternoon" decoding="async" />
<p class="wp-block-paragraph"><strong>You do not need to become a security expert to stop most of the tracking that follows you around the web. You need one afternoon, a handful of settings, and the willingness to leave a few things switched off.</strong></p>


<p class="wp-block-paragraph">Almost every guide to browser privacy starts by handing you a list of twenty extensions. This one does the opposite. Most of the work is done by four or five decisions, and the rest is noise that will slow your browser down and break the sites you use every day.</p>


<h2 class="wp-block-heading">What &#8220;hardening&#8221; actually means</h2>


<p class="wp-block-paragraph">Hardening is not making yourself invisible. It is reducing the number of companies that get a copy of what you do, and reducing the amount they can join together. Think of it as closing the windows rather than moving house.</p>


<p class="wp-block-paragraph">Before you change anything, spend two minutes on your <a href="https://withoutcensorship.com/glossary/#threat-model">threat model</a> &#8212; who you are actually worried about. Someone avoiding advertising surveillance needs different settings than someone whose ex-partner has physical access to their laptop. If you skip this, you will spend the afternoon fixing the wrong problem.</p>


<h2 class="wp-block-heading">Step 1: Pick a browser you trust</h2>


<p class="wp-block-paragraph">The single biggest decision is which browser you open in the morning. Any of the well-maintained ones will do: Firefox, Safari on Apple devices, or a Chromium browser that is not built by an advertising company. What matters more is that it updates itself automatically and that you actually keep using it. A hardened browser you abandon after a week protects nobody.</p>


<p class="wp-block-paragraph">Whatever you choose, turn on automatic updates and restart the browser when it asks. Most real-world attacks use holes that were patched months ago.</p>


<h2 class="wp-block-heading">Step 2: One content blocker, not five</h2>


<p class="wp-block-paragraph">Install a single, reputable content blocker and stop there. A good blocker removes trackers and ads in one pass; stacking three of them on top of each other mostly produces broken pages and a browser that feels slow, and it makes you <em>more</em> identifiable rather than less.</p>


<p class="wp-block-paragraph">Expect to whitelist two or three sites &#8212; your bank, a work tool, a video player. Learn where the &#8220;pause on this site&#8221; button is on day one, so that the first broken checkout page does not make you uninstall everything.</p>


<h2 class="wp-block-heading">Step 3: Turn off third-party cookies</h2>


<p class="wp-block-paragraph">Third-party cookies are the classic way one company recognises you across hundreds of unrelated sites. Every major browser can now block them, and in most of them it is a single switch in the privacy settings. Turn it on.</p>


<p class="wp-block-paragraph">You will barely notice the difference. The sites you log into use their own cookies, which keep working. What stops working is the invisible handshake between a news site and the ad networks and <a href="https://withoutcensorship.com/glossary/#data-broker">data brokers</a> behind it.</p>


<h2 class="wp-block-heading">Step 4: HTTPS-only and a better DNS</h2>


<p class="wp-block-paragraph">Switch on HTTPS-only mode. Your browser will then refuse to load pages over an unencrypted connection without warning you first. On the modern web this breaks almost nothing, and it removes a whole family of problems on public Wi-Fi.</p>


<p class="wp-block-paragraph">Then consider encrypted DNS. Every time you visit a site, something has to translate the name into a number, and by default your internet provider does it and can see the list. Encrypted DNS moves that lookup to a provider you pick, over an encrypted connection. Be honest about the trade: you are choosing who sees your browsing list, not making it disappear.</p>


<h2 class="wp-block-heading">Step 5: Separate profiles for separate lives</h2>


<p class="wp-block-paragraph">This is the step people skip and later wish they had not. Use one browser profile for your logged-in life &#8212; email, banking, work &#8212; and a second one for general reading and searching. Two profiles cost you nothing and break the easiest way to link your identity to your browsing.</p>


<p class="wp-block-paragraph">If your browser supports container tabs, the same logic applies inside one window: the social network in one container cannot see what you do in another. Whichever mechanism you use, the rule is the same &#8212; the profile where you are logged in as yourself should not be the profile where you browse everything else.</p>


<h2 class="wp-block-heading">Step 6: Decide what survives closing the window</h2>


<p class="wp-block-paragraph">Now choose how much your browser remembers. The comfortable setting is to clear cookies and site data when you quit, while keeping your history and bookmarks. The stricter setting clears everything. Either is fine; what matters is that you decided rather than accepting the default.</p>


<p class="wp-block-paragraph">If you clear cookies on exit, you will log in more often, so use a password manager &#8212; and for a start the one already built into your browser or phone (Apple, Google) is perfectly good, because anything is better than reusing one password everywhere. Private windows are a different tool: they forget locally, but the sites and networks you visit still see you.</p>


<h2 class="wp-block-heading">Step 7: The address bar and your default search</h2>


<p class="wp-block-paragraph">Two small settings with a surprisingly large effect. First, turn off the suggestions that send everything you type in the address bar to a search engine as you type it &#8212; including the half-finished thoughts you never pressed enter on. Second, change your default search engine to one that does not build a profile of you. You can always run a single query on the big engine when you need it.</p>


<h2 class="wp-block-heading">Fingerprinting, honestly</h2>


<p class="wp-block-paragraph">Even with cookies gone, sites can guess who you are from the combination of your screen size, fonts, language, time zone and graphics hardware. This is fingerprinting, and it is the part of this guide where the honest answer is: you can reduce it, not eliminate it.</p>


<p class="wp-block-paragraph">Anti-fingerprinting features in mainstream browsers help against lazy tracking. Anything stronger means accepting real inconvenience &#8212; a browser that lies about your screen, blocks fonts, and looks broken. If you need that level of protection, you are in the territory of <a href="https://withoutcensorship.com/glossary/#tor">Tor</a> rather than a hardened everyday browser, and it is worth knowing where that line is before you cross it.</p>


<h2 class="wp-block-heading">Your phone, in ten minutes</h2>


<p class="wp-block-paragraph">Phones deserve their own afternoon, but three settings cover most of it: install a browser that supports content blocking and set it as your default, turn off the advertising identifier in the system privacy settings, and go through the list of apps that have location permission and set most of them to &#8220;while using the app&#8221; or never. Ten minutes on the phone is often worth more than an hour on the laptop.</p>


<h2 class="wp-block-heading">The afternoon, in order</h2>


<ul class="wp-block-list"><li>Update your browser and turn on automatic updates.</li><li>Install one content blocker. Just one.</li><li>Block third-party cookies.</li><li>Switch on HTTPS-only mode; set up encrypted DNS if you are comfortable with it.</li><li>Create a second profile: logged-in life in one, everything else in the other.</li><li>Decide what gets cleared when you quit, and set up a password manager.</li><li>Fix the address bar suggestions and your default search engine.</li><li>Do the three phone settings.</li></ul>


<p class="wp-block-paragraph">That is the whole list. If a step fights you, skip it and come back &#8212; a browser you can live with beats a perfect configuration you abandon on Tuesday.</p>


<h2 class="wp-block-heading">What this doesn&#8217;t solve</h2>


<p class="wp-block-paragraph">A hardened browser does not protect your messages once they leave the browser; for that, see our guide to <a href="https://withoutcensorship.com/encrypted-messaging-without-the-myths/">encrypted messaging without the myths</a>. It does not hide your traffic from your employer if you are on a managed device, it does nothing about what you voluntarily post, and it will not stop a company you have an account with from collecting what you do while logged in.</p>


<p class="wp-block-paragraph">What it does do is make you a much harder target for the routine, industrial-scale tracking that treats every reader as a data point. That is a realistic goal, and you can reach it before dinner.</p>

]]></content:encoded>
					
					<wfw:commentRss>https://withoutcensorship.com/hardening-your-browser-in-an-afternoon/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to read a privacy policy in ten minutes</title>
		<link>https://withoutcensorship.com/how-to-read-a-privacy-policy-in-ten-minutes/</link>
					<comments>https://withoutcensorship.com/how-to-read-a-privacy-policy-in-ten-minutes/#respond</comments>
		
		<dc:creator><![CDATA[Pavel Kadlec]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 20:18:44 +0000</pubDate>
				<category><![CDATA[Guides]]></category>
		<category><![CDATA[data brokers]]></category>
		<category><![CDATA[transparency]]></category>
		<guid isPermaLink="false">https://withoutcensorship.com/?p=27422</guid>

					<description><![CDATA[<img width="150" height="150" src="https://withoutcensorship.com/wp-content/uploads/2026/04/data-privacy-2026-protection-guide-150x150.png" class="attachment-thumbnail size-thumbnail wp-post-image" alt="data privacy 2026 concept showing digital protection and secure personal data" decoding="async" />You do not have to read a privacy policy — you have to search one. A repeatable ten-minute method using nothing but your browser’s find function: the words to look for, what the standard phrases actually mean, and an honest account of what reading a policy can never tell you.]]></description>
										<content:encoded><![CDATA[<img width="150" height="150" src="https://withoutcensorship.com/wp-content/uploads/2026/04/data-privacy-2026-protection-guide-150x150.png" class="attachment-thumbnail size-thumbnail wp-post-image" alt="data privacy 2026 concept showing digital protection and secure personal data" decoding="async" loading="lazy" />
<p class="wp-block-paragraph">Nobody reads privacy policies. That is not a moral failing — the average policy runs to several thousand words of deliberately elastic legal language, and you are usually asked to accept it while standing in a queue or setting up a new phone. The good news is that you do not have to read one. You have to search one.</p>



<p class="wp-block-paragraph">With your browser’s find function and a fixed list of words, you can pull the five things that actually matter out of almost any policy in about ten minutes. More importantly, you can do it the same way every time, which means you can compare one service against another instead of just feeling vaguely uneasy about all of them.</p>



<p class="wp-block-paragraph">This guide assumes no legal training. It works best on a laptop with Ctrl+F (Cmd+F on a Mac). On a phone, use <em>Find in page</em> from the browser’s share or menu sheet.</p>



<h2 class="wp-block-heading">What you are actually looking for</h2>



<p class="wp-block-paragraph">A privacy policy is not a promise to behave well. It is a disclosure document — a list of the things the company has reserved the right to do. Reading it tells you the outer boundary of what may happen to your data, not what is happening today. That distinction is the whole reason a ten-minute reading is worth anything: you are mapping the boundary, not auditing the behaviour.</p>



<p class="wp-block-paragraph">Five questions do almost all the work. What do they collect? Why do they say they need it? Who else receives it? How long do they keep it? And what can you actually switch off or take back? Everything else in the document is scaffolding.</p>



<h2 class="wp-block-heading">Minutes 1–2: make sure you have the right document</h2>



<p class="wp-block-paragraph">Companies rarely keep everything in one file. Expect a privacy policy, a separate cookie or tracking notice, the terms of service — which sometimes contains the data clauses that matter most — and increasingly a set of regional supplements: a section for the EEA and the UK, another for California, another for Brazil or Japan. The supplement that names your region usually grants you more than the main text does, so find it before you read anything else.</p>



<p class="wp-block-paragraph">Two things to check immediately. First, the <em>last updated</em> date at the top. A policy that has not been touched in three years on a service that has just added an AI assistant is out of date, and that is useful information in itself. Second, whether the page you are on is a friendly summary with a link to the real version. Summaries are written by the marketing department; read the one written by the lawyers.</p>



<h2 class="wp-block-heading">Minute 3: the sharing words</h2>



<p class="wp-block-paragraph">Search for: <strong>third part</strong>, <strong>share</strong>, <strong>sell</strong>, <strong>partner</strong>, <strong>affiliate</strong>, <strong>service provider</strong>, <strong>vendor</strong>. Truncate the words as shown — searching for <em>third part</em> catches both <em>party</em> and <em>parties</em>.</p>



<p class="wp-block-paragraph">Pay particular attention to the sentence <em>we do not sell your personal information</em>. Under several data-protection laws, selling means an exchange for money, so a company can hand your data to advertising partners in return for services and still say, truthfully, that it does not sell anything. California’s law added the separate word <em>share</em> precisely to close that gap. This is why <em>share</em> tells you more than <em>sell</em> does.</p>



<p class="wp-block-paragraph"><em>Affiliates</em> is the other word worth slowing down for. It means other companies inside the same corporate group, and in a large group that can be hundreds of entities in dozens of countries. A policy that permits sharing with affiliates for the purposes described has permitted quite a lot.</p>



<h2 class="wp-block-heading">Minute 4: the purpose words</h2>



<p class="wp-block-paragraph">Search for: <strong>legitimate interest</strong>, <strong>consent</strong>, <strong>personalis</strong> and <strong>personaliz</strong>, <strong>advertising</strong>, <strong>improve our services</strong>, <strong>research</strong>, <strong>train</strong>, <strong>model</strong>.</p>



<p class="wp-block-paragraph"><em>To improve our services</em> is the most flexible phrase in the genre and can cover anything from crash reports to product design. What you want to know is whether your content — messages, documents, photographs, search queries — is used to train machine-learning models, and whether that use is opt-in, opt-out, or neither. If the policy mentions training, search nearby for <em>opt out</em> and see what you find.</p>



<p class="wp-block-paragraph"><em>Legitimate interests</em> is a lawful basis under the GDPR that does not require your consent. It is legal and often reasonable, but it must come with a right to object, so search for <strong>object</strong> as well. If a policy leans on legitimate interests and never explains how to object, that is a gap worth noting.</p>



<h2 class="wp-block-heading">Minute 5: retention</h2>



<p class="wp-block-paragraph">Search for: <strong>retain</strong>, <strong>retention</strong>, <strong>how long</strong>, <strong>delete</strong>.</p>



<p class="wp-block-paragraph">You are looking for a number — thirty days, twelve months, seven years. <em>For as long as necessary for the purposes described in this policy</em> is not a number; it means indefinitely, at the company’s discretion. Note also whether backups and logs are carved out of the retention rules, because they usually are, and whether deleting your account deletes your data or only your ability to log in. Those are very different things, and good policies say which one they mean.</p>



<h2 class="wp-block-heading">Minute 6: the controls, and how much friction they carry</h2>



<p class="wp-block-paragraph">Search for: <strong>your rights</strong>, <strong>opt out</strong>, <strong>request</strong>, <strong>download</strong>, <strong>portab</strong>, <strong>withdraw</strong>.</p>



<p class="wp-block-paragraph">Then ask the practical question, which the text will usually answer: how do you actually exercise these rights? A toggle in the settings screen is a real control. An e-mail address is a slower one. A web form that requires you to upload identity documents is a deterrent — and occasionally the identity check collects more data than the request removes. If the policy gives a response deadline, write it down; thirty days and forty-five days are the common ones, and knowing the deadline is what makes a follow-up e-mail possible.</p>



<h2 class="wp-block-heading">Minute 7: who, and where</h2>



<p class="wp-block-paragraph">Find the name of the legal entity, not the brand, and the country it sits in. That is the company you would be dealing with if something went wrong, and it may not be the one whose logo is on the app.</p>



<p class="wp-block-paragraph">Then search for <strong>transfer</strong>, <strong>adequacy</strong> and <strong>standard contractual clauses</strong> to see where data goes once it leaves your region. Finally, search for <strong>Data Protection Officer</strong> and <strong>representative</strong>. A named contact means there is somewhere to send a complaint that is not a support ticket, and many policies also name the supervisory authority you can escalate to. That single line is often the most immediately useful sentence in the whole document.</p>



<h2 class="wp-block-heading">Minute 8: the escape hatches</h2>



<p class="wp-block-paragraph">Search for: <strong>may</strong>, <strong>at our discretion</strong>, <strong>material change</strong>, <strong>business transfer</strong>, <strong>merger</strong>, <strong>aggregate</strong>, <strong>de-identif</strong>, <strong>anonymis</strong>.</p>



<p class="wp-block-paragraph">Two of these deserve real attention. A business-transfer clause means your data is treated as a company asset that moves if the business is sold, merged or wound up, and the buyer may operate under a different policy than the one you agreed to. And once data is described as aggregated, de-identified or anonymised, most policies stop treating it as personal data at all — which means the protections in the rest of the document no longer apply to it. Re-identifying supposedly anonymous datasets is a well-documented field of research, so read that word as a boundary line rather than a guarantee.</p>



<p class="wp-block-paragraph">It is also worth noticing how often <em>may</em> appears. A document built on <em>we may</em> has reserved everything and committed to nothing.</p>



<h2 class="wp-block-heading">Minutes 9–10: write down three lines</h2>



<p class="wp-block-paragraph">Open a plain text file and keep one entry per service: the name, the date you read the policy, what it collects, who receives it, what you can switch off, and one sentence saying whether you are willing to accept that. Three lines is enough.</p>



<p class="wp-block-paragraph">This is the step people skip and it is the one that pays. After five services you have a comparison rather than an impression, and you can see which company is unusual. When a policy changes — and you will get an e-mail saying it has — you can check your own note in twenty seconds instead of re-reading eight thousand words.</p>



<h2 class="wp-block-heading">The two-minute version</h2>



<p class="wp-block-paragraph">If you have two minutes instead of ten, search four words: <strong>share</strong>, <strong>retain</strong>, <strong>opt out</strong> and <strong>train</strong>. Who gets it, how long they keep it, what you can switch off, and whether you are feeding a model. That is not a complete picture, but it is enough to decide whether the service deserves the other eight minutes.</p>



<h2 class="wp-block-heading">What this doesn’t solve</h2>



<p class="wp-block-paragraph">This method reads a document. It cannot tell you what a company actually does. A policy is a statement of permissions, and there is no way to verify compliance from the text — that takes regulators, auditors, leaks and lawsuits, which is why enforcement decisions are often more informative than any policy.</p>



<p class="wp-block-paragraph">It also tells you nothing about what the software technically does on your device. Apps ship with advertising and analytics components whose behaviour is not described in any policy in a way you could check; seeing that requires inspecting network traffic, which is a different job and a different guide.</p>



<p class="wp-block-paragraph">Reading the policy does not give you leverage. In most cases the offer is accept or leave, and for the services that matter most — your bank, your employer, your government, your child’s school — leaving is not on the table. Understanding what you have agreed to is still worth something, but do not mistake it for a choice.</p>



<p class="wp-block-paragraph">Nor does any of this protect you from a breach. A company with an exemplary policy can still lose your data to an attacker, and the policy will contain a paragraph explaining that no method of transmission is completely secure. That paragraph is accurate.</p>



<p class="wp-block-paragraph">Two further limits. A policy only covers data you hand over yourself; it does not govern what other people upload about you, which is how contact lists, photographs and tags put you into databases you never touched. And this is not legal advice: your local law may give you rights the policy does not mention, and where the two conflict, the law wins — a policy cannot sign away a statutory right, however confidently it is worded.</p>



<p class="wp-block-paragraph">Ten minutes gets you a map, not a verdict. The point is that ten minutes is repeatable, and a habit you can keep beats a thorough reading you will never do twice.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://withoutcensorship.com/how-to-read-a-privacy-policy-in-ten-minutes/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Protect Your Privacy with California&#8217;s DROP Tool</title>
		<link>https://withoutcensorship.com/protect-your-privacy-with-californias-drop-tool/</link>
					<comments>https://withoutcensorship.com/protect-your-privacy-with-californias-drop-tool/#respond</comments>
		
		<dc:creator><![CDATA[EFF (republished)]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 14:54:07 +0000</pubDate>
				<category><![CDATA[Guides]]></category>
		<category><![CDATA[data brokers]]></category>
		<category><![CDATA[North America]]></category>
		<category><![CDATA[US policy]]></category>
		<guid isPermaLink="false">https://withoutcensorship.com/?p=27252</guid>

					<description><![CDATA[<img width="150" height="150" src="https://withoutcensorship.com/wp-content/uploads/2026/07/data-privacy-lock-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="A padlock linked to a smartphone displaying a lock icon, symbolizing personal data privacy protection" decoding="async" loading="lazy" />Are you a California resident? Then we&#8217;ve got exciting news for you: there&#8217;s a tool just for you that lets you take a single, relatively easy step to protect your privacy.  It&#8217;s called a DROP request. (That&#8217;s Delete Request and Opt-out Platform, if you&#8217;re fancy). This one bit of paperwork lets you tell every data [&#8230;]]]></description>
										<content:encoded><![CDATA[<img width="150" height="150" src="https://withoutcensorship.com/wp-content/uploads/2026/07/data-privacy-lock-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="A padlock linked to a smartphone displaying a lock icon, symbolizing personal data privacy protection" decoding="async" loading="lazy" /><div class="field field--name-body field--type-text-with-summary field--label-hidden">
<div class="field__items">
<div class="field__item even">
<p><span>Are you a California resident? Then we&#8217;ve got exciting news for you: there&#8217;s a tool just for you that lets you take a single, relatively easy step to protect your privacy. </span></p>
<p><span>It&#8217;s called a DROP request. (That&#8217;s Delete Request and Opt-out Platform, if you&#8217;re fancy). This one bit of paperwork lets you tell every data broker registered in the state of California that you&#8217;d like them to delete your information from their databases and request they stop selling and sharing your information. </span></p>
<p><span>Here are some things to know about DROP. </span></p>
<p><em>(Don’t want all the details and want to just learn how to file a request? <a href="https://www.eff.org/rss/updates.xml#Filing" target="_blank" rel="noopener">Skip to this section</a>.)</em></p>
<h2><b>What does a request do?</b></h2>
<p><span>Filing a request on the DROP will send a request to delete and opt-out of sale to all the data brokers in California&#8217;s registry. Data brokers are companies that collect information about people, repackage that information, and sell it. As of time of writing, a single DROP request reaches 614 brokers.</span></p>
<p><span> After August 1, once data brokers receive a request, they will have 45 days to address the request. </span></p>
<p><span>DROP officially launched on Jan. 1 of this year, but companies have until Aug. 1 to begin complying with requests. That means if you file a request now, you&#8217;ll be in on the ground floor.</span></p>
<h2><b>Didn&#8217;t I hear about this before?</b></h2>
<p><span>If you pay attention to EFF, you sure did. With your help, we advocated for the law creating the DROP tool, </span><a href="https://www.eff.org/deeplinks/2023/08/californias-delete-act-protects-us-data-brokers" target="_blank" rel="noopener"><span>the Delete Act.</span></a><span> As we said then, we needed the DROP because Californians have</span><a href="https://oag.ca.gov/privacy/ccpa#sectiond" target="_blank" rel="noopener"> <span>a right to request</span></a><span> that companies delete information collected about them, and a right to opt-out of having businesses sell information about them. Yet, in reality, making those requests is an incredibly time-consuming and tedious process. Filing each request is hard. Plus, because data brokers buy, sell, and exchange information with so many companies (and each other) people may not even know who to file a request with. By linking a request to California&#8217;s data broker registry, DROP cuts this process down considerably.</span></p>
<p><span>We advocated for DROP and the Delete Act because it makes our privacy law more user-friendly, which gives us better control over our data and reduces the risks that the uncontrolled collection and sale of personal information creates in our everyday lives. </span></p>
<h2><b>What&#8217;s in it for me?</b></h2>
<p><span>Filing a request benefits you in a few ways. For one, data brokers are often how spammers (or companies that act like spammers) get your email address, phone number, and other ways of contacting you. Removing yourself from data broker lists could lead to a decrease in these kinds of messages. Second, reducing the number of companies that have your personal information also improves your personal cybersecurity, as it decreases the number of firms with your information who could be hacked. Third and finally, it gives you an opportunity to exert more control over how your personal information is collected and used—an important element of privacy. </span><span>Unless you opt out, data brokers can sell your private information to </span><a href="https://www.businessinsider.com/how-marketers-use-big-data-to-prey-on-the-poor-2013-12" target="_blank" rel="noopener"><span>predatory companies</span></a><span>, </span><a href="https://www.forbes.com/sites/steveweisman/2026/03/01/data-brokers-fuel-scams-senate-report-on-billions-of-consumer-losses/" target="_blank" rel="noopener"><span>scammers</span></a><span>, </span><a href="https://www.lawfaremedia.org/article/people-search-data-brokers-stalking-and-publicly-available-information-carve-outs" target="_blank" rel="noopener"><span>stalkers</span></a><span>, </span><a href="https://www.nytimes.com/2024/03/11/technology/carmakers-driver-tracking-insurance.html" target="_blank" rel="noopener"><span>insurance companies</span></a><span>, and </span><a href="https://www.eff.org/deeplinks/2021/04/tell-congress-support-fourth-amendment-not-sale-act" target="_blank" rel="noopener"><span>law enforcement</span></a><span>.</span></p>
<h2><b>What kinds of information will (and won&#8217;t) be deleted?</b></h2>
<p><span>The California Privacy Protection Agency, which administers the DROP, has a </span><a href="https://privacy.ca.gov/drop/personal-information-and-data-brokers/#yourPI" target="_blank" rel="noopener"><span>great resource</span></a><span> explaining what data are and are not included in a request. But in summary, a request will often deal with identifying information such as: social security number, precise geolocation, browsing history, email address, and phone numbers. It will also enter a request to delete guesses that data brokers may have made about you based on identifying information, such as political views, inferences about your health—inferences about pregnancy or chronic illness, for example, that may be based on purchases or browsing history.</span></p>
<p><span>Not all information will be deleted. Some information, such as vehicle or real estate ownership, contains information that is a matter of public record. </span></p>
<p><span>If there is a specific data broker you&#8217;d like to be able to retain and continue selling your data, the system also gives you a way to remove them from the list of brokers that get any given request. </span></p>
<h2><b><a></a>How do I file?</b></h2>
<p><span>Head to the California Privacy Protection Agency&#8217;s </span><a href="https://consumer.drop.privacy.ca.gov/" target="_blank" rel="noopener"><span>DROP website</span></a><span> to start your request. Before you start, there are a few pieces of information you may want to gather for your request, such as your </span><a href="https://www.eff.org/deeplinks/2022/05/how-disable-ad-id-tracking-ios-and-android-and-why-you-should-do-it-now" target="_blank" rel="noopener"><span>advertising ID</span></a><span> or your VIN number, if you want this information to be deleted from data broker databases. </span></p>
<p><span>The agency does ask to collect some personal information—name, address, phone number, email address, etc.—in order to fulfill a request. (Yes, there is an irony to this.) This is to verify that you&#8217;re the right person asking for your deletion and opt-out request in any given database, and the agency itself is bound to its terms of service that say they won&#8217;t sell or share it for other purposes.  </span></p>
<p><span>If you&#8217;re interested in filing a request for someone else, such as an elderly relative drowning in junk mail, you can also do that but will need to attest that you&#8217;re filing for someone else who is a resident of California. </span></p>
<p><span>Once you&#8217;ve filed, you will get a DROP ID, which you can use to check in on your request. If you lose this ID, you can contact the agency to recover it, but keep it in a safe place if you want to check in on the status of your request.  </span></p>
<h2><b>If I file once, am I done forever?</b></h2>
<p><span>Unfortunately, no. While the opt-out of sale request should last indefinitely, California&#8217;s privacy law still allows companies to collect information without asking for permission first in most cases. That means data brokers are likely to continue to collect information for profiles of you—but they will will have less data and be limited in how they use it after an opt-out request. New data brokers may also register with the state after you file your request. And DROP won&#8217;t stop companies who aren&#8217;t registered data brokers, like Google, from collecting and sharing your personal information.</span></p>
<p><span>Two things can be true. DROP is a fantastic tool to help more people exercise their California privacy rights. We also still need even stronger privacy laws to make things more fair for everyday people. </span></p>
<p><span>That fact shouldn&#8217;t undercut the power of this tool, but it does mean that you may want to make updating your request a regular part of a broader plan to <a href="https://ssd.eff.org/module/how-to-manage-your-digital-footprint" target="_blank" rel="noopener">manage your digital footprint.</a> For example, might we suggest doing it as a part of </span><a href="https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security" target="_blank" rel="noopener"><span>Opt-Out October</span></a><span>—</span><span>a thing we totally made up but also totally stand behind?</span></p>
<h2><b>What if I&#8217;m not in California?</b></h2>
<p><span>Also unfortunately for those who don&#8217;t live in California, this tool only works for California residents. But it&#8217;s not all bad news. Versions of the Delete Act have been introduced around the country, and many regulators are monitoring how California&#8217;s system works to see whether a similar system might work in their own states. </span><span>Residents of all states can use </span><span>EFF’s </span><a href="https://www.eff.org/deeplinks/2025/09/opt-out-october-daily-tips-protect-your-privacy-and-security" target="_blank" rel="noopener"><span>Opt-Out October</span></a><span> guide to bolster their online privacy and limit the ways that data brokers harvest their personal data</span><span>. </span></p>
</div>
</div>
</div>
<p>  Deeplinks. Original article: <a href="https://www.eff.org/deeplinks/2026/07/what-you-need-know-about-californias-drop-tool" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>
<p><em>This article was originally published by the Electronic Frontier Foundation (EFF) on July 20, 2026. Republished under Creative Commons CC BY 4.0. Read the original article: <a href="https://www.eff.org/deeplinks/2026/07/what-you-need-know-about-californias-drop-tool" target="_blank" rel="noopener nofollow">https://www.eff.org/deeplinks/2026/07/what-you-need-know-about-californias-drop-tool</a>.</em></p>

<p><em>Featured image: “Data security privacy lock password” by Book Catalog, via Wikimedia Commons, licensed under <a href="https://creativecommons.org/licenses/by/2.0" target="_blank" rel="noopener">CC BY 2.0</a>.</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://withoutcensorship.com/protect-your-privacy-with-californias-drop-tool/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The EU is about to sell our most sensitive data to the US for visa-free travel</title>
		<link>https://withoutcensorship.com/the-eu-is-about-to-sell-our-most-sensitive-data-to-the-us-for-visa-free-travel/</link>
					<comments>https://withoutcensorship.com/the-eu-is-about-to-sell-our-most-sensitive-data-to-the-us-for-visa-free-travel/#respond</comments>
		
		<dc:creator><![CDATA[EDRi (republished)]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 14:53:34 +0000</pubDate>
				<category><![CDATA[Digital Rights]]></category>
		<category><![CDATA[border surveillance]]></category>
		<category><![CDATA[data brokers]]></category>
		<category><![CDATA[EU policy]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[series: papers, please]]></category>
		<guid isPermaLink="false">https://withoutcensorship.com/?p=27251</guid>

					<description><![CDATA[<img width="150" height="150" src="https://withoutcensorship.com/wp-content/uploads/2026/07/passport-border-control-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="Passports being checked at airport immigration control, illustrating cross-border travel data sharing" decoding="async" loading="lazy" />The European Commission is currently finalising negotiations with the Trump administration to conclude an “Enhanced Border Security Partnership” (EBSP) Framework Agreement allowing border control authorities to screen travellers against biometric databases and profile them for security concerns. The leaked draft text suggests that the Commission significantly caved in to US’s excessive demands for unfettered information [&#8230;]]]></description>
										<content:encoded><![CDATA[<img width="150" height="150" src="https://withoutcensorship.com/wp-content/uploads/2026/07/passport-border-control-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="Passports being checked at airport immigration control, illustrating cross-border travel data sharing" decoding="async" loading="lazy" /><p>The European Commission is currently finalising negotiations with the Trump administration to conclude an “Enhanced Border Security Partnership” (EBSP) Framework Agreement allowing border control authorities to screen travellers against biometric databases and profile them for security concerns. The leaked draft text suggests that the Commission significantly caved in to US’s excessive demands for unfettered information access, exacerbating travel surveillance and putting our fundamental rights at risk.</p>
<p>The post <a href="https://edri.org/our-work/the-eu-is-about-to-sell-our-most-sensitive-data-to-the-us-for-visa-free-travel/" target="_blank" rel="noopener">The EU is about to sell our most sensitive data to the US for visa-free travel</a> appeared first on <a href="https://edri.org/" target="_blank" rel="noopener">European Digital Rights (EDRi)</a>.</p>
<p>  European Digital Rights (EDRi). Original article: <a href="https://edri.org/our-work/the-eu-is-about-to-sell-our-most-sensitive-data-to-the-us-for-visa-free-travel/" target="_blank" class="feedzy-rss-link-icon" rel="noopener">Read More</a></p>
<p><em>This article was originally published by European Digital Rights (EDRi). Republished under Creative Commons CC BY 4.0. Read the original article: <a href="https://edri.org/our-work/the-eu-is-about-to-sell-our-most-sensitive-data-to-the-us-for-visa-free-travel/" target="_blank" rel="noopener nofollow">https://edri.org/our-work/the-eu-is-about-to-sell-our-most-sensitive-data-to-the-us-for-visa-free-travel/</a>.</em></p>

<p><em>Featured image: “Passports bangkok airport” by Jarcje, via Wikimedia Commons, licensed under <a href="https://creativecommons.org/licenses/by-sa/3.0" target="_blank" rel="noopener">CC BY-SA 3.0</a>.</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://withoutcensorship.com/the-eu-is-about-to-sell-our-most-sensitive-data-to-the-us-for-visa-free-travel/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The FCC&#8217;s Spam Call Proposal Is Just a Data Collection Scheme</title>
		<link>https://withoutcensorship.com/the-fccs-spam-call-proposal-is-just-a-data-collection-scheme/</link>
					<comments>https://withoutcensorship.com/the-fccs-spam-call-proposal-is-just-a-data-collection-scheme/#respond</comments>
		
		<dc:creator><![CDATA[EFF (republished)]]></dc:creator>
		<pubDate>Mon, 20 Jul 2026 20:44:07 +0000</pubDate>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[data brokers]]></category>
		<category><![CDATA[North America]]></category>
		<category><![CDATA[series: watching the watchers]]></category>
		<category><![CDATA[US policy]]></category>
		<guid isPermaLink="false">https://withoutcensorship.com/?p=27195</guid>

					<description><![CDATA[<img width="150" height="150" src="https://withoutcensorship.com/wp-content/uploads/2026/07/mobile-privacy-eff-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="Illustration of mobile devices and surveillance eyes representing phone privacy" decoding="async" loading="lazy" />The Federal Communications Commission wants to require telecommunications providers to collect vast amounts of personal information from every person who wants a phone number in the name of combatting scam and spam calls. This plan will fail to combat the deluge of unwanted calls people in the United States receive every day while giving untrustworthy [&#8230;]]]></description>
										<content:encoded><![CDATA[<img width="150" height="150" src="https://withoutcensorship.com/wp-content/uploads/2026/07/mobile-privacy-eff-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="Illustration of mobile devices and surveillance eyes representing phone privacy" decoding="async" loading="lazy" /><p>The Federal Communications Commission wants to require telecommunications providers to collect vast amounts of personal information from every person who wants a phone number in the name of combatting scam and spam calls. This plan will fail to combat the deluge of unwanted calls people in the United States receive every day while giving untrustworthy companies a gold mine of information that would harm everyday consumers&#8217; privacy, access to communications, and ability to speak freely.</p>
<p>The requirement to provide ID and an address would completely cut off the ability to have an anonymous phone line, which would mean many people in the most precarious situations imaginable—domestic violence and human trafficking survivors, unhoused people, and children without stable homes—would not be able to gain access to a crucial lifeline. EFF, along with ACLU, has submitted comments advising the FCC to abandon this proposal entirely.</p>
<p>Requiring phone providers to collect consumers&#8217; information will not appreciably decrease or eliminate unwanted calls. The FCC itself confesses in its own rulemaking that &#8220;the most effective way to prevent unwanted calls from reaching American consumers is by ensuring they never enter the network.&#8221; The Federal Trade Commission has found that a significant proportion of unwanted robocalls originate from overseas—collecting the personal information of everyone who wants to make a phone call will not put a dent in fraudulent calls.</p>
<p>Mass data collection of individuals does not address unwanted calls, but it does make us all less safe online. The telecommunications industry has proven time and again that they&#8217;re poor stewards of personal information, having been at the center of several large-scale data breaches in recent years, including incidents affecting tens of millions of AT&#038;T and Comcast customers, and the Salt Typhoon attacks on the nation&#8217;s CALEA wiretapping infrastructure.</p>
<p>Anonymity in calls provides people the safety they may require to organize themselves, speak freely, and seek services. Anonymous phone calls give people the courage to participate in politics, reach out to a suicide or sexual-assault hotline, an addiction-recovery sponsor, seek medical care, or seek escape from a violent and coercive situation. Not everyone has the government-issued identification or stable home address the FCC&#8217;s proposal would require, which would shut many vulnerable people out of phone service entirely.</p>
<p>The FCC&#8217;s proposal will not decrease the amount of unwanted calls. All it will do is set up a data collection regime that harms everyday, law-abiding Americans, strips away the right to anonymous speech in calls, and disconnects those already at the margins. EFF recommends the FCC discard this proposal in its entirety.</p>
<p><em>This article was originally published by the Electronic Frontier Foundation (EFF). Republished under Creative Commons CC BY 4.0. Read the original article: <a href="https://eff.org/deeplinks/2026/06/fccs-spam-call-proposal-just-data-collection-scheme" target="_blank" rel="noopener nofollow">https://eff.org/deeplinks/2026/06/fccs-spam-call-proposal-just-data-collection-scheme</a>.</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://withoutcensorship.com/the-fccs-spam-call-proposal-is-just-a-data-collection-scheme/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
