Off topic, but recently I've been devastated to learn that every single address I (a US resident) ever lived at, my roommates, even my month and year of birth are available on sites like spokeo and fastpeoplesearch. I just don't know where this info is coming from and I want to stop it. Maybe the Equifax breach?
It comes from a lot of places. Voter records is actually a big source, but also I believe some of the various breaches have made it in. And all of those sites continuously crawl each other and trade databases as well.
I had my identity stolen and after a lot of research I determined they were able to gather the info from all of these public sources. I have been trying to scrub myself from them for 3 years now. It's like playing whack-a-mole. Some are quick to delete, only to pop right back up again months later. Some just don't respond. Some require physical mailed requests. A few are openly hostile. You need to submit forms with google to get search results cache updated for each page.
You also need to clear "associates" such as spouse, parents, children because your info appears on their profiles as well. Tedious process!
I believe the best defense is to have a common name or create a ton of spoof info to confuse them.
> It comes from a lot of places. Voter records is actually a big source, but also I believe some of the various breaches have made it in. And all of those sites continuously crawl each other and trade databases as well.
I wouldn't be surprised if a lot of it comes from customer lists (either sold directly by the collecting company for a little extra profit or bought in bankruptcy/liquidation proceedings).
Lots of googling your own name and email address. Finding all the hits and searching for "remove" or "opt out" links (search "sitename+opt out" etc). Repeating the process for close associates, phone number, address.
Then closely monitor. Submit search results cache removal as soon as it changes (https://www.google.com/webmasters/tools/removals). I've found it's best to do one giant wave of removals to avoid propagating from one site to another.
I think many agents are in place since many years tracking everyone, accumulating information leaked from different breaches.
I believe it is widespread today at least in several countries their intelligence really have a kind of "global human database" where everyone is tracked and all digital traces are carefully collected and can be used at appropriate moments for different interventions (like elections, policy change, trade agreements, etc.)
This stuff was always public information. These sites collected it and charged to access it in detail. They basically replaced people who did this professionally. Gumshoe as a service.
You can opt out, but it's a grueling, site-by-site process and they don't make it easy - often you have to do it several times. See https://inteltechniques.com/book7.html for some strategies. It's tortuous and should not be this way - we should really have national privacy legislation, but all the companies who are based on (or just get extra profit from) surveillance capitalism will fight such a thing tooth and nail.
> You can opt out, but it's a grueling, site-by-site process and they don't make it easy - often you have to do it several times. See https://inteltechniques.com/book7.html for some strategies. It's tortuous and should not be this way
I totally agree with you about how unreasonably burdensome the process is (it probably took at least a solid 40 hours of effort for me to get my results mostly scrubbed from publicly accessible sites a few years ago).
However, I think you have to put an asterisk next to "opt-out." In a lot of cases, your data might still be accessible in premium or specialized products (like those for law enforcement). I know of no law besides the California-specific CCPA that actually regulates opting-out, and a lot of these sites like like they're operated by sketchy people.