Data Broker Removal Tools

  • DNS Benchmark v2 Release 5 with Consultant License
    Guest:
    If you own any earlier release of our DNS Benchmark you may immediately download its release #5 replacement. Running an earlier release will detect the new release and help you upgrade.

    Although this release is cosmetic, appearance matters and affects ease of use. The biggest change, as seen in the image above, is that the DNS Benchmark now has a traditional Windows application menu to more fully expose its many features. This release is also "Consultant License Aware" and GRC will now issue a Consultant version when owners have previously purchased four "Personal Use" licenses. If you have previously purchased four DNSB licenses, or if you wish to upgrade your "Personal Use" license to Consultant, GRC's purchase process will direct you through that process.
    /Steve.
  • Be sure to checkout “Tips & Tricks”
    Dear Guest Visitor → Once you register and log-in please checkout the “Tips & Tricks” page for some very handy tips!

    /Steve.
  • BootAble – FreeDOS boot testing freeware

    To obtain direct, low-level access to a system's mass storage drives, SpinRite runs under a GRC-customized version of FreeDOS which has been modified to add compatibility with all file systems. In order to run SpinRite it must first be possible to boot FreeDOS.

    GRC's “BootAble” freeware allows anyone to easily create BIOS-bootable media in order to workout and confirm the details of getting a machine to boot FreeDOS through a BIOS. Once the means of doing that has been determined, the media created by SpinRite can be booted and run in the same way.

    The participants here, who have taken the time to share their knowledge and experience, their successes and some frustrations with booting their computers into FreeDOS, have created a valuable knowledgebase which will benefit everyone who follows.

    You may click on the image to the right to obtain your own copy of BootAble. Then use the knowledge and experience documented here to boot your computer(s) into FreeDOS. And please do not hesitate to ask questions – nowhere else can better answers be found.

    (You may permanently close this reminder with the 'X' in the upper right.)

Adam-F

Well-known member
Sep 25, 2020
65
7
UK
Hi All,

I have been thinking of using a data broker removal tool, but I am not sure which one will be best suited for a UK user.

How safe are these services to use?

I believe delete me is a sponser to Security Now, but I would like some impartial advise on the subjet.

I don't want to go down the Incogni route as they are owned by Nord VPN which is also owned by Surf Shark. (Correct me if I am gone here)

Optery at a glance, looks like the best option, as they have a free plan to get users started, by the user putting in manual removal requests with each broker that is found.

Any advice is much appreciated.

Thanks
 
Q: Google, What is the right to be forgotten on the Internet?

A: The "right to be forgotten" is a legal concept that allows individuals to request the removal or delinking of their personal information from online platforms and search results under certain conditions.

This right, officially known as the "right to erasure" under the European Union's General Data Protection Regulation (GDPR), enables people to ask that data be removed if it is inaccurate, inadequate, irrelevant, or no longer necessary for the purpose it was collected.

It is not an absolute right, and it must be balanced against other rights, such as freedom of expression, and is not recognized uniformly across all countries. [1, 2, 3, 4, 5, 6, 7]

How it works

  • Request for removal: An individual can request that a data controller, such as a search engine or a company, erase their personal data.
  • Grounds for request: The request can be made if the data is no longer necessary, consent for processing is withdrawn, or the individual objects to the processing (especially for direct marketing).
  • Data controller's obligation: The data controller must erase the data without undue delay, provided there are no overriding legitimate grounds for keeping it.
  • Search engine delisting: A key aspect is the right to ask search engines to delist links to personal data that appear in search results for a person's name, especially if the information is considered outdated or irrelevant. [1, 2, 3, 4, 8, 9]
Limitations and exceptions
  • Not an absolute right: The right to be forgotten is not absolute and is often balanced against other rights, such as the right to freedom of expression and information, or the public interest in the data remaining available.
  • Exceptions apply: Organizations are not obligated to erase data if it is needed to comply with a legal obligation or for tasks performed in the public interest. [2, 5, 7]
International context
  • EU origin: The concept was popularized by a 2014 European Court of Justice ruling and later codified into the GDPR in 2018.
  • Global application: While the EU has a strong legal framework for this right, its global application is complex. Some countries, like Russia and Canada, have similar laws or are considering them, but there is no uniform approach across all nations.
  • California's CCPA: In the United States, some states, such as California, have passed similar provisions in their privacy laws, notes Varonis. [1, 2, 3, 9, 10]
[1] https://etradeforall.org/news/right...out-them-be-removed-internet-how-does-it-work
[2] https://joindeleteme.com/glossary/right-to-be-forgotten/
[3] https://www.varonis.com/blog/right-to-be-forgotten
[4] http://www.dataprotection.ie/en/individuals/know-your-rights/right-erasure-articles-17-19-gdpr
[5] https://www.weforum.org/stories/2023/11/eu-right-to-be-forgotten-online-data/
[6] https://www.igniyte.co.uk/personal-reputation-management/right-to-be-forgotten/
[7] https://illinoislawreview.org/print/volume-2017-issue-1/the-right-to-be-forgotten/
[8] https://support.google.com/legal/answer/10769224?hl=en
[9] https://support.google.com/legal/answer/10769224?hl=en-GB
[10] https://www.privacyengine.io/resources/glossary/right-to-be-forgotten/
 
delete me
There are two companies that use this name, one is American and one is European. If you are choosing based on the advertising on the TWiT network, make sure you're choosing the right one. I have no experience with the services themselves to offer any useful opinion otherwise. It does, however, seem like the market is filled with shady types on both sides, and it seems like if you ever start paying you're going to end up paying for life or just accept the second you stop paying all your data will magically reappear out of the ether.
 
  • Like
Reactions: tadpole256
There are two companies that use this name, one is American and one is European. If you are choosing based on the advertising on the TWiT network, make sure you're choosing the right one. I have no experience with the services themselves to offer any useful opinion otherwise. It does, however, seem like the market is filled with shady types on both sides, and it seems like if you ever start paying you're going to end up paying for life or just accept the second you stop paying all your data will magically reappear out of the ether.
Thanks for the reply, so based off what you have said would I be best off using Optery free account and manually removing my data myself?

Also what is the European version of Delete Me (URL) please?

As I am in the UK so I need a service that indexes European data broker.
 
Q: Google, What is the right to be forgotten on the Internet?

A: The "right to be forgotten" is a legal concept that allows individuals to request the removal or delinking of their personal information from online platforms and search results under certain conditions.

This right, officially known as the "right to erasure" under the European Union's General Data Protection Regulation (GDPR), enables people to ask that data be removed if it is inaccurate, inadequate, irrelevant, or no longer necessary for the purpose it was collected.

It is not an absolute right, and it must be balanced against other rights, such as freedom of expression, and is not recognized uniformly across all countries. [1, 2, 3, 4, 5, 6, 7]

How it works

  • Request for removal: An individual can request that a data controller, such as a search engine or a company, erase their personal data.
  • Grounds for request: The request can be made if the data is no longer necessary, consent for processing is withdrawn, or the individual objects to the processing (especially for direct marketing).
  • Data controller's obligation: The data controller must erase the data without undue delay, provided there are no overriding legitimate grounds for keeping it.
  • Search engine delisting: A key aspect is the right to ask search engines to delist links to personal data that appear in search results for a person's name, especially if the information is considered outdated or irrelevant. [1, 2, 3, 4, 8, 9]
Limitations and exceptions
  • Not an absolute right: The right to be forgotten is not absolute and is often balanced against other rights, such as the right to freedom of expression and information, or the public interest in the data remaining available.
  • Exceptions apply: Organizations are not obligated to erase data if it is needed to comply with a legal obligation or for tasks performed in the public interest. [2, 5, 7]
International context
  • EU origin: The concept was popularized by a 2014 European Court of Justice ruling and later codified into the GDPR in 2018.
  • Global application: While the EU has a strong legal framework for this right, its global application is complex. Some countries, like Russia and Canada, have similar laws or are considering them, but there is no uniform approach across all nations.
  • California's CCPA: In the United States, some states, such as California, have passed similar provisions in their privacy laws, notes Varonis. [1, 2, 3, 9, 10]
[1] https://etradeforall.org/news/right...out-them-be-removed-internet-how-does-it-work
[2] https://joindeleteme.com/glossary/right-to-be-forgotten/
[3] https://www.varonis.com/blog/right-to-be-forgotten
[4] http://www.dataprotection.ie/en/individuals/know-your-rights/right-erasure-articles-17-19-gdpr
[5] https://www.weforum.org/stories/2023/11/eu-right-to-be-forgotten-online-data/
[6] https://www.igniyte.co.uk/personal-reputation-management/right-to-be-forgotten/
[7] https://illinoislawreview.org/print/volume-2017-issue-1/the-right-to-be-forgotten/
[8] https://support.google.com/legal/answer/10769224?hl=en
[9] https://support.google.com/legal/answer/10769224?hl=en-GB
[10] https://www.privacyengine.io/resources/glossary/right-to-be-forgotten/
Thanks for this, I will now go through all the links you provided.
 
Also what is the European version of Delete Me (URL) please
I assume it would be what you would find if you google. Again, I honestly have no experience, I just know that Leo constantly warns about people getting the wrong one because of the name confusion. (They are not related, so the ads you hear Leo give are for the US company he's making sure people don't get confused, as was I trying to do for you so that you make your best choice. I don't know the history of how the name collision occurred, but if one of them caused it to steal the business of the other, that would be a pretty clear sign to avoid one, no?)

would I be best off
I honestly don't know what would leave you best off. It would be nice to feel like you were in control, and I think it's A LOT of work if you don't have the agreements and automation these companies most likely have. On the other hand, I guess, I would ask if it's really a solvable problem, or if you're only spit polishing the surface, while the corruption remains deep down under. If you have the money to spend (maybe it's an investment, maybe it's just frivolous spending) then I suppose there's no harm in finding out what's possible, but I simply advise you that it may be the case when you stop spending, it very quickly will all unravel and then I question what it is you got for all that money.
 
There are a couple of other ways to deal with this, especially if your aim is to stop spam email.

Under GDPR, marketing mails should have an "unsubscribe" link. Whilst some people argue that all that does is confirm that your email is valid, some companies do honour it.

I also forward spam messages to spamcop.net. They identify the real source of spam mail, and send an automated complaint to the ISP. In UK, you can also send phishing emails to "report@phishing.gov.uk" which gets them to the CyberSecurity people at Cheltenham.
 
Would it sill be worth creating an Optery free account, just to see what it initially finds out?
 
You might have already solved this but your skepticism about Incogni being owned by Nord is completely justified. Handing your data over to a massive aggregator defeats the entire purpose of privacy. I gave the manual removal process a shot with Optery for a while but dealing with broker websites intentionally hiding their opt out buttons got incredibly annoying.

To deal with it I signed up for protectmydata.com to handle the automated takedowns because I lacked the patience to keep verifying my identity with spammers. Run your email through HaveIBeenPwned first to see exactly which data brokers have already leaked your details.
 
Last edited:
I did some digging into this subject about a year ago. First, I identified about a dozen places where I found my personal information and put the URLs into a spreadsheet. Next, I bought an Incogni subscription for a month, intending to follow up and see what they got rid of. After some time, little, if anything, was disappearing. As I recall, Incogni's user interface left a lot to be desired, and I found it very hard to tell if it was doing me any good or not. Eventually, I found a list of all the data broker sites that they target, and most of the ones I had found my info on were NOT on that list.

So I did some more searching, and among other things, found the "Big Ass Data Broker List":

BigAssDataBrokersList

Which is a huge list of known data brokers as well as URLs and instructions for how to successfully opt out of each one. Using that, I was able to manually get my info removed from all 12 sites where it had been found, all within just a few weeks. The actual work I did was maybe an hour, max. So far, none of them have re-surfaced.

I also found that EasyOptouts had on their target list nearly all of the sites that had my info. I sent them a couple of questions, and got well-written responses in a short time. I felt like I was dealing with one guy, or a very small company (which I like).
https://www.easyoptouts.com. At $20/year, they're WAY cheaper than all the others. I have not yet signed up with them, though, as none of my personal info has resurfaced on the web.

Google also has a free service where they'll notify you if any of your personal information shows up in any of their search results. They send you an email when they do, and you go to the "Results About You" link, review what they found, and request them to remove any or all of them. They usually respond within a day, almost always with "Removal Request Approved", and indeed the offensive URL is no longer found by searching google for your personal info. They don't actually remove the website with your info, just the search results, but I've had great luck going to each URL and explicitly requesting removal of my info, and I think it's been 100% successful.

Here's a Clark Howard article where I found out about Google's "Results about you":
Clark Howard

FWIW, www.deleteme.com is NOT the one Leo (and others) are talking about. That site does appear to do personal data removal, but it looks like they charge $99 for EACH ONE they get removed! The one they really mean is joindeleteme.com. I'm baffled about why Leo (and others) never bother mentioning the URL for the correct one. First time I tried to find them, I found deleteme.com and saw the insane pricing, and just set the whole idea aside.

I hope this has been helpful.
 
  • Like
Reactions: hyperbole
I'm baffled about why Leo (and others) never bother mentioning the URL
Every time I've heard an ad (usually in the live show as I don't actually consume the podcasts, just attend live) in the last year or more Leo has been extra careful to mention to go to the URL he mentions because there is this confusion out there. He even frequently mentions the other company is about Europe and their specific info deletion approach.
 
Every time I've heard an ad (usually in the live show as I don't actually consume the podcasts, just attend live) in the last year or more Leo has been extra careful to mention to go to the URL he mentions because there is this confusion out there. He even frequently mentions the other company is about Europe and their specific info deletion approach.
Ah, ok. It's probably because I listen to the commercial-free version of Security Now, and I only hear them talking about it. Well, I'm glad to know that much anyway. But I have heard Deleteme promoted in at least one other context where they also failed to give a URL. I can't recall where that was - it was several years ago.