What a data broker knows about your work-from-home day
When your home becomes your office, the data trail you leave behind changes shape. Remote work doesn’t just shift where you sit — it shifts what gets collected, who collects it, and what can be inferred from the patterns. Data brokers have built an industry on exactly this kind of information, and the remote work boom has handed them a richer dataset than ever before.
Most of what’s documented here comes from reporting by the Brennan Center for Justice and the Duke Tech Policy Lab, alongside investigations from outlets like Vice, The Guardian, and Ars Technica. The picture they paint is worth sitting with for a moment.
Data PrivacyRemote Work SecurityDigital FootprintWFH Surveillance
✦
What a data broker knows about your work-from-home day
Data brokers collect, aggregate, and sell information about individuals — often without their knowledge or consent. A 2021 report from the Duke Tech Policy Lab describes US data brokerage as “a virtually unregulated practice.” The industry is valued somewhere around $200 billion, and the information traded ranges from the mundane to the deeply personal.
For a remote worker, that means a broker could know:
- Your home address and how many hours you spend there each day (location data from mobile apps)
- What time you typically start and stop work (browsing patterns, app usage)
- Which collaboration tools you use and how often (browser data, device fingerprints)
- What home office equipment you bought, and from where (purchase history, loyalty programs)
- Your estimated income and professional licenses (public records, commercial data)
- Health conditions that may affect your work patterns (health-related browsing, prescription data)
According to the FTC’s 2014 report on data brokers, the industry is so opaque that consumers face serious difficulty understanding or controlling how their data is used. That was over a decade ago. The data points collected per person now routinely exceed 1,500, per industry estimates.
What makes the remote worker’s profile especially valuable is the overlap. When you work from home, your personal and professional lives share the same digital and physical space. A broker doesn’t need to buy separate datasets for “employee at Company X” and “person who lives at 123 Main Street” — they get both from the same sources.
The collection pipeline you didn’t opt into
Data reaches brokers through a web of channels that most users never see. Cell phone companies, internet service providers, social media platforms, and app developers collect information — often without meaningful disclosure. The US relies on a “notice and consent” privacy model, which New America’s Open Technology Institute argues fails because consent is buried in terms nobody reads and framed as take-it-or-leave-it.
Mobile apps are a major pipeline. The FTC filed a complaint against data broker InMarket for collecting location data from apps downloaded to over 390 million devices. InMarket analyzed that information to group users into audience segments like “Christian church goers,” “wealthy and not healthy,” and “parents of preschoolers.” Those segments were then sold to advertisers and other buyers.
For a remote worker, the apps on your phone — weather, fitness, navigation, even a simple flashlight — can feed location and usage data into this pipeline. Your work laptop isn’t immune either. Browser cookies, browser fingerprinting, and even the Wi-Fi networks you connect to can reveal patterns about when and where you work.
The surveillance economy thrives because most people never see it working. A Wired investigation found that ad buyers used Google’s DV360 platform to target “decision makers” at US national security agencies, alongside people with chronic illnesses or financial struggles. Those audience segments were sold by third-party data brokers and tied to mobile device IDs. If that kind of targeting exists for national security personnel, remote workers in less sensitive roles are not harder to reach.
The Electronic Communications Privacy Act — which limits how telephone and email providers share certain customer information with government agencies — was enacted in 1986 and has not been meaningfully updated to cover mobile apps or commercial data brokers. As the Brennan Center notes, this creates a legal loophole: a company can sell information to a data broker without restriction, and the broker can then sell the same information to a government agency, effectively bypassing the court-order requirement that would apply if the company sold it directly.
Who’s buying your work habits
The customer list for brokered data is longer than most people realize. Advertisers are the most visible buyers, but they are far from the only ones.
Government agencies purchase personal data from brokers to sidestep constitutional surveillance limits. A 2024 Brennan Center analysis found that agencies including the Department of Defense and local law enforcement routinely buy location and behavioral data this way. A Vice investigation in 2020 revealed that the Defense Department purchased location data collected by broker Outlogic (formerly X-mode) from popular prayer apps to monitor Muslim communities. Police departments have purchased information to track racial justice protesters, as The Guardian reported.
Employers can purchase data about their own workforce — or potential hires — without the employee’s knowledge. Nothing in current US law broadly prohibits this. A Fast Company investigation previously documented how Equifax’s “The Work Number” database, originally designed for employment and income verification, became a commercial data source sold to lenders and others. The same infrastructure can feed broker dossiers.
Health insurers and **financial institutions** can purchase data that reveals health conditions, prescription histories, and financial behaviors. The Duke Tech Policy Lab report notes that virtually nothing in current US law limits data brokers from selling to insurance firms or hedge funds.
The US government is itself a top customer of data brokers. Agencies can purchase data that would otherwise require a warrant, court order, or subpoena. This isn’t hypothetical — the Pentagon, ICE, and local police departments are confirmed buyers. For remote workers, this means that location data from a work-from-home day could end up in a government database without any judicial oversight, simply because a broker sold it.
Foreign actors are also in the market. A 2025 UK government report warned that foreign adversaries can easily purchase sensitive data on citizens, infrastructure, and political targets using data brokers as middlemen. US law does not stop them — there is no oversight board or notification requirement unless the buyer is from one of six officially designated adversary countries. The Cambridge Analytica scandal, in which Facebook data was harvested to build psychographic voter profiles, demonstrated that most of the data used came from brokers, not directly from the platform.
What’s at stake that isn’t obvious
The most immediate risk is data breaches. Nearly 1,600 data breaches were reported in the first half of 2024, a 14% increase over the same period in 2023, and over 1 billion sensitive data points were leaked in 2024 alone. When a data broker is breached, the exposed information can include medical history, financial struggles, and personal habits — the kind of data that’s difficult to reset.
But there’s a less visible layer. President Biden’s executive order on AI acknowledges that artificial intelligence makes it easier to “extract, re-identify, link, infer, and act on sensitive information about people’s identities, locations, habits, and desires.” As the Brennan Center notes, the proliferation of AI models reliant on vast datasets will likely intensify the overcollection of data and trafficking of personal information. For remote workers, that means the already detailed profile a broker holds could become even more revealing — and harder to control — as AI tools get better at connecting disparate data points.
Discrimination is another risk. Brokered data can influence loan eligibility, insurance rates, and employment decisions without transparency or recourse. A ProPublica investigation previously documented how Facebook’s advertising platform allowed discrimination in housing ads; the same data pipelines feed into algorithmic decisions across industries.
What actually helps (and what doesn’t)
Complete digital erasure is nearly impossible, but there are steps that meaningfully reduce exposure. The key is knowing what each step actually accomplishes.
Use privacy-focused browsers and tools
Browsers like Brave and Firefox Focus block trackers by default, reducing the amount of browsing data that reaches brokers. VPNs can anonymize your IP address and encrypt your connection, though they don’t stop all forms of tracking. Proton, Signal, and other privacy-first services build their models around protecting user data rather than monetizing it.
Review and reduce app permissions
Many apps request location, contacts, and camera access that aren’t needed for their core function. On both iOS and Android, you can review which apps have access to what and revoke permissions that aren’t essential. For remote workers, this is especially relevant for productivity and wellness apps that may track location or browsing data.
Use data broker opt-out processes
Many brokers offer opt-out mechanisms, though finding and completing them is time-consuming. State laws like California’s CCPA and Virginia’s CDPA give residents the right to request data deletion from brokers. California’s newer DROP law, which took effect January 2026, allows residents to submit a single deletion request that goes to all registered brokers — a significant improvement over the previous system, where fewer than 1% of Californians exercised their rights because it required filing separate demands with each of hundreds of brokers.
Vet your tools and vendors
For remote workers who choose their own tools — or have influence over workplace tool decisions — reviewing privacy policies and terms for transparency around data collection, storage, and sharing matters. Ask direct questions about whether a vendor sells or shares data with third parties. Vague policies are a red flag.
It’s worth noting what doesn’t work as well as advertised. Third-party services that claim to handle data broker opt-outs vary in effectiveness. And no single action removes your footprint entirely — reducing exposure is a cumulative process, not a one-time fix. The FTC’s 2014 report observed that the industry’s opacity makes it genuinely difficult for consumers to understand or control how their data is used, and that observation still holds.
The legal picture — progress and gaps
The US has no comprehensive federal law regulating data brokers, unlike Europe’s GDPR. The result is a patchwork of state laws with varying reach and enforcement. California’s CCPA and Virginia’s CDPA provide some consumer rights, but they don’t cover everyone and have significant loopholes.
Several federal bills have been proposed but remain stalled. The Fourth Amendment Is Not For Sale Act would prohibit law enforcement and intelligence agencies from purchasing certain communications-related information and location data that would otherwise require a warrant. But as the Brennan Center notes, the bill is tied to outdated categories of communications service providers from the 1980s and would not cover similar information collected by health and fitness apps, nor would it cover health, financial, or biometric data.
The American Data Privacy and Protection Act is a more comprehensive federal privacy bill that would restrict collection to only what is necessary to provide a service and place additional limits on data transfers. But it has multiple exceptions allowing government agencies to obtain significant amounts of personal data, and it has not passed.
California’s DROP law is the most recent and arguably strongest state-level action, but its effect is limited to California residents. As Ars Technica noted in its coverage, the law binds only one state, and other states may follow California’s lead — but for now, the majority of Americans have no equivalent protection.
The Consumer Financial Protection Bureau recently scrapped a proposed rule that would have forced data brokers to follow basic transparency and fairness standards, as Wired reported. So the regulatory direction, at the federal level, is not clearly forward.
✦
The data broker economy exists because it is profitable, largely invisible, and mostly legal. That doesn’t mean individual action is pointless — it means the problem is bigger than any single opt-out form or privacy setting. For remote workers, the practical takeaway is to treat your digital footprint the way you’d treat a physical office door: lock what you can, know who has keys, and assume that some information is already in circulation.
What makes this moment different from five years ago is that the conversation has shifted from “should data brokers be regulated” to “how do we build effective controls.” State laws like California’s DROP create a template. The Fourth Amendment Is Not For Sale Act, stalled as it is, represents a bipartisan acknowledgment that the warrant loophole needs closing. None of this solves the problem overnight, but it does mean the terrain is shifting — and the more people understand what’s being collected about them, the harder it becomes to keep the system invisible.