Yes and no, but mostly no.

Once again, there’s no black-and-white, yes-or-no answer.
These services do remove some of your information from the internet. But it’s impossible to remove everything, no matter what their marketing materials imply.
Troy Hunt, of Have I Been Pwned fame, recently published Swimming Pools, Pee, and Trying to Delete Your Data From the Internet. I want to share some of his insights.

Data removal services: yes or no?
You can pay someone to remove some of your personal data from the internet, but not all of it. Legitimate data brokers might listen, but hackers and shady sites won’t. Once your data leaks, you can’t undo it. Vigilance and skepticism are the only solutions.
The core issue
It’s an attention-grabbing, if somewhat icky, metaphor: putting information anywhere on the internet is kinda like peeing in a swimming pool. You know it’s in there, but removing it isn’t realistic.
The complication (which the metaphor doesn’t really address) is that some of your information can be removed from certain corners of the internet.
The question is, is that enough? The answer, much like pee in a pool, is: probably not. Certainly not enough to be comfortable.
Data removal services tend to underemphasize that and focus on the things they claim they can remove.
Help keep it going by becoming a Patron.
How data removal works
The premise is simple.
- A variety of data brokers have your data. This is quite true, and there are many, ranging from legitimate companies like credit reporting services to less-than-legitimate companies that will take and sell data to and from anyone.
- Data removal companies have a long list of data brokers that they ask to remove your data.
This is where things break down in two ways:
- This relies on the cooperation of the data brokers. Some might remove your data, but many ignore the request.
- The list of data brokers is, by definition, incomplete.
While #1 is annoying, #2 is more concerning. Data removal services ask all the “legitimate” data brokers to remove your data, but they have no way to ask all the various shady information brokers to do so. There are just too many, and they’re constantly changing. In many cases, the data is “out there” for the taking without a record of who has a copy.
There’s no undoing a breach
Legitimate data brokers get data in legitimate ways.1 These are the services that are most likely to respond to requests to remove your data.
Hackers? Not so much.
If your data is exposed in a breach:
- Most of the time, there’s no way to contact the parties responsible.
- Even if you can, they’re likely to ignore requests to remove your data from what they’ve stolen.
- Even then, your data has likely already been copied to multiple places, many of which are outside anyone’s direct knowledge or control.
To quote Hunt discussing his wife’s data being part of the “ShinyHunters” leak,
Because we’re talking about digitised data posted publicly, it replicates like crazy. There will be tens of thousands of copies of my wife’s personal info floating around between personal stashes, Telegram channels and public hacking forums. That genie is never going back in the bottle…
So, are data removal services lying?
For the most part, no. I’m sure some lie, but the majority are legitimate. If you read what they promise carefully, you’ll see they don’t promise everything their marketing might imply.
So what we’re left with is data removal services being effective for legally operating brokers who honour legitimate requests, whilst being completely useless against the worst kinds of sites that replicate and abuse your data. In other words, you may be able to opt out of some marketing material or content that’s way too specifically targeted to you, but you can’t stop the bad guys trying to steal your identity or extort you…
Honest people will be honest and play by the rules, but bad actors will always be out of your grasp or the grasp of data removal services, no matter what they promise or imply.
These paid removal services aren’t a scam, but they can’t really do what people want or think they’re paying for: they can’t undo a data breach.
Do this
My take is that data removal services are ineffective at removing the data we really want removed, and thus not worth it. If you feel that removing your data from legitimate data brokers is worth it, then it might be. It’s not something I would personally prioritize.
The real takeaway here is that you have to assume your data is “in the wild” and act accordingly. What does that mean? More than anything else, it means being skeptical. Your data can be used to create amazingly realistic phishing attempts. And of course, watch your bank and credit card statements. Ideally, get notifications on all transactions, but if you can’t, check regularly for transactions you don’t recognize.
Yes, it’s very unfortunate and frustrating that we’re in this situation, but all we can do is be aware and take control of what we can.
Subscribe to Confident Computing! Less frustration and more confidence, solutions, answers, and tips in your inbox every week.
Podcast audio
Footnotes & References
1: You might not agree with or like the data collection, but technically, it’s all part of the terms of service that you agreed to when using an online service.




Always interesting to get your take, Leo.
Have you any thoughts yet about the new California state-run Delete Request and Opt-out Platform (DROP) that will start removing CA residents’ data starting August 1, 2026?
I should have noted CA residents have to request their data be removed.
The infamous* GDPR in the EU has a policy which mandates the removal of news stories and search results about criminals who have “paid their debt to society”. There was a famous murder case which was scrubbed from search engines in Europe. I was struck by the Streisand Effect and wanted to see what was being hidden. I fired up my VPN and googled the name and it came up. And don’t forget The Wayback Machine from The Internet Archive. I once reconstructed a website using the Wyback Machine.
*GDPR is actually a series of important prvacy protections, but most people see them as the morons that gave us those annoying idiotic cookie warnings.
Excellent article. This is why I always answer “no” when asked online for various permissions (notifications, etc.), especially to “Remember me?” requests.
“Remember me” doesn’t store extra personal information on the website. What it actually does is place a persistent login cookie in your browser. That cookie lets the site keep you logged in across visits, even after you close the browser.
When you return to the site, it sees the cookie and restores your logged‑in session. No additional profile data is saved—just the token that proves you already authenticated. So it’s safe to have your browser remember you.
My daughter recently found, with a simple search of her name, that USPhoneBook publicly posted all her addresses over the past 5-10 years, including her current address in NYC. No other info was included. She is concerned about her personal safety. She subscribed to DeleteMe. She received a report in a few days that her info was scrubbed from some brokers but USPhoneBook did not have a record of having her information.
A difficulty with many companies is that there is no phone # or “live” customer relations. Email is the only way to contact the company. She emailed and sent a screenshot showing that the information existed on the web with a citation indicating the information was from USPhonebook. She has not yet received a reply.
I’m 80 years young and didn’t even know these types of services existed. However, what you are saying makes perfect sense Leo – i.e. personal data can be removed from legit data brokers, but good luck with the bad guys!
My mantra to help folks to stay safe online, and especially for seniors, is to treat everything with skepticism and a good dose of caution.
Ask yourself, if any service were going to remove your personal information from the web, how would they do it? These companies don’t have magic powers or technology – they just search the web and send out requests. So, to do their job, they would need your personal information. That means you are giving some “company” all your personal information to be stored in yet another database. Clever. The same is true with the “monitoring services”. The only way they can monitor your financial data is if you give them all your financial data to start with. Brilliant.
Data is today’s currency. These types of companies are in the business of collecting data (besides collecting subscription fees). No sane company is going to give up (permanently delete) their data just because someone asked. The “deleted data” will reappear on the web within weeks (because data brokers are always collecting data and updating their lists).
My approach to my data being ‘out there’ is very simple and, in my opinion direct and pragmatic:
1. Anything I post on the Internet is simply ‘Out There’, and so can never be called back.
It’s the same as the concept that ‘A bell can never be unrung’.
2. Data breaches are inevitable because there will forever be those miscreants who are willing to do whatever it takes to get ‘something for nothing’ without compunction over potential legal ramifications or consequences, or guilt over what effect their actions have on their victims.
3. The result of items 1 and 2 above, I have absolutely no control over what’s already ‘out there’ so I accept that fact and move on.
What follows is my response to items 1 through 3 above:
A. When posting anything, I’m careful to communicate using generalities where possible, never mentioning specifics like names or ages of my family, friends or others.
B. I’ve frozen six credit bureau accounts because, at my age, it’s unlikely that I need to open a credit card, or take out a loan, and if that should change going forward, I can ask the lender which agency they will use so I can temporarily unfreeze that account to permit them access.
C. I’m forever skeptical about the motives of anyone I encounter on the Internet because, until I can satisfactorily confirm their identity, I have no way of estimating what their motives are. Even when it comes to friends or family on the Internet, via email, or on my phone, I trust nothing until I can make direct contact to confirm that it truly was them who contacted me. Even though I’ve not yet been victimized by such a scam, I know the possibility exists.
D. I regularly check my banking accounts, 1. To confirm that recurring bills are paid on time and, 2. for any unfamiliar transactions. To my recollection I’ve encountered three such transactions. I immediately contacted my bank’s customer service department to challenge each one, and to request a replacement debit card with a different number. Due to the promptness of my reaction, all three challenges have been approved. The transactions were cancelled/refunded to my account, and I received a replacement debit card in the mail within a few days.
I suppose the bottom line here is similar to all personal security rules: Never react in panic. Always verify the reality of any threat/issue before taking action. Then, and only then, determine the best course of action. I hope what I’ve described here helps others,
Ernie
While complete removal of your personal information is always uncertain, especially if compromised in a medial or credit related breach outside of your control, getting it off of current sites and resources that openly provide it is quite doable and free if you do it yourself. Following the shooting and protests of Mike Brown in St. Louis, MO many of those in law enforcement experienced their information being compromised by anti-police groups and the like, including myself. A list of resources at the time was provided to us to begin the process of making yourself less visible. Yes it took several hours to muddle your way through all the loopholes, many emails, many online removal requests and even a few phone calls, but it absolutely worked. The personal information I found on myself through many of these various companies, firms, etc. is no longer on display. Yes, they may still have it lurking behind the scenes stored somewhere, but you simply can’t find me online by searching my name, address or phone number any more. Some of the biggies include Lexis Nexis, Spokeo, Radaris, DOBsearch.com, BeenVerified, PeopleSmart, and Instant Checkmate. It was totally worth the effort and also eliminated nearly all spam calling on both my phone numbers. All these years later, I still have almost no spam calls, no soliciting calls and junk mail dropped considerably as well. I’m also cautious in providing my information online unless absolutely necessary. People are their own worst enemies when it comes this topic, especially with all these apps, online discount rackets, and click here for more information catches.
Thanks for the list of companies. Can you post the instructions for how to accomplish what you accomplished?
It’s been quite a few years and I’m not sure where that master list intelligence gave us is tucked away. Basically, you have to go to each site displaying your name, address, phone, etc. and look for their “opt out” link and follow the instructions. Some of them want you to fill out an online form and submit it, others request an email with a reasoning to be sent to specific email addresses, and others it just a simple 3 second request to opt out. There were even some that allowed for a mailed in request. It’s totally worth the effort. And, it may take more than one time out. I found most complied without a 2nd request. The only thing I can even find myself listed under anymore is previous address I lived at one year with my parents in 2002 following college and it’s just my name as a past resident which really means nothing.
Thank you for this information. If nothing else, it may help to reduce the amount of spam I receive.