Can Data Brokers Sell Your Data to China?
No, not legally, if the data is sensitive and the buyer is in one of four countries. A 2024 law called the Protecting Americans' Data from Foreign Adversaries Act makes it unlawful for data brokers to sell, license, or provide access to Americans' personally identifiable sensitive data to China, Russia, Iran, or North Korea, or to entities those countries control. Unusually, there is no volume threshold: a single record is enough to break the rule. In February 2026 the Federal Trade Commission wrote to data brokers reminding them of exactly this. But read that opening sentence again and notice how many conditions it contains. Each one is a door left open, and most of your personal information walks through them.
What does the law actually prohibit?
Signed in April 2024 as part of a national security package and effective that June, the law bars data brokers from transferring personally identifiable sensitive data about US individuals to foreign adversary countries or entities controlled by them, generally meaning at least twenty percent ownership. The definition of sensitive data is genuinely broad: health information, financial data, genetic and biometric information, precise geolocation, information about sexual behavior, account and device login credentials, government identifiers such as Social Security, passport, and driver's license numbers, and even private communications, photographs, and videos. Enforcement sits with the Federal Trade Commission.
It has a companion. The Department of Justice runs a separate data security program, built on an executive order and effective from 2025, which restricts bulk transfers of sensitive American data. That program covers all US entities rather than just brokers, and adds Cuba and Venezuela to the list of countries of concern. The two overlap but are not the same rule.
Is anyone enforcing it?
Cautiously, and later than some expected. The FTC sent warning letters in February 2026 reminding data brokers of their obligations, with the director of its Bureau of Consumer Protection stating the agency is committed to enforcing the law. Commissioners have signalled it is a priority. But the agency has faced public criticism from privacy scholars for moving slowly, and as of the most recent reporting no public enforcement action has been brought under it. Warning letters are a real signal of intent. They are not the same as a penalty, and the practical deterrent so far rests more on the DOJ program than on this law.
The gaps that matter to you
This is where the framing matters, because it is easy to read a headline and conclude your data is now protected. What the law actually does is much narrower:
- It restricts buyers, not selling. The prohibition is about four specific countries. Selling the same data to a buyer in the United States, or in dozens of other nations, is untouched by it.
- It covers sensitive categories, not ordinary identity data. Your name, home address, phone number, age, and relatives, the exact material people-search sites publish, are not what this law was written to stop.
- It applies to data brokers as defined, with carve-outs including service providers and media entities, so plenty of companies handling your data fall outside it.
- It is a national security measure, not a consumer privacy law. Its purpose is keeping American data away from adversary governments, not giving you control over the commercial trade in your information.
Put plainly, a law can be working exactly as intended and still leave your address published on forty websites. Both things are true at once. The absence of a general federal privacy law, covered in does the US have a federal data privacy law, is why the only national rules touching data brokers arrived through the national security door rather than the consumer protection one.
Does a law like this even stop the leak?
Not entirely, and there is a recent illustration. Earlier in 2026, data from a major biomedical research database was found advertised for sale on Chinese e-commerce platforms. It did not get there through a broker transaction that a regulator could point at. It got there because institutions with legitimate, contracted access to the data broke the terms of that access, as we covered in what the UK Biobank leak reveals about anonymous data.
That is the structural problem with regulating data flows by destination. Rules govern the front door, the lawful sale from a company that can be identified and fined. Data also moves through side doors: contract violations, resale chains that obscure the original source, breaches, and scraping. A prohibition on selling to a country cannot reach information that was copied by someone already permitted to hold it.
What is actually within your control?
Not the geopolitics, and not which governments obtain which datasets. Those are policy questions decided well above the level of any individual. What you can affect is how much of your information is sitting in the commercial pool that all of these rules are arguing over.
Every one of these frameworks assumes a large, active market in personal data and tries to police its edges. The material that people-search sites publish about you, name, current and past addresses, phone numbers, age, relatives, is the most freely available part of that market and the least regulated, precisely because it is treated as public. Removing it will not change what any government can obtain, and no honest service would claim so. It reduces what is trivially available to anyone, which is a smaller but real and achievable goal. It also needs repeating, because brokers rebuild profiles from fresh public records. Consumer Reports found that opt-outs handled by hand or by automation cleared only about 27 percent of exposed listings, while removals run by real people who monitor and refile reached roughly 70 percent.
Laws police the edges of the market. You can shrink your share of it.
No removal service changes what governments can buy, and we will not pretend otherwise. What we do is take your name, address, and phone off the people-search sites that publish them to anyone. A free scan shows where you appear, and our team of real people removes it and keeps checking as it returns.
Run my free scan Start free trialFrequently asked questions
Which countries does the law cover?
China, Russia, Iran, and North Korea, along with entities they control. The Department of Justice's parallel program covers a slightly wider list that also includes Cuba and Venezuela. Sales to buyers elsewhere in the world are not restricted by either framework.
Is my home address covered as sensitive data?
Precise geolocation is treated as sensitive, but the ordinary identity information published by people-search sites is a different category and is not what this law targets. That gap is one reason your listings can remain freely available while national security rules tighten around other data.
Has anyone been penalized under it yet?
Based on the most recent public reporting, no enforcement action had been brought under this particular law, though the FTC issued warning letters in February 2026 and has signalled it is a priority. Enforcement posture can change quickly, so it is worth checking current news if this matters to you.
Should I worry about my data specifically going overseas?
For most people the everyday risks, scams, identity fraud, and being easy to locate, come from data circulating domestically rather than from foreign transfers. Those are also the risks you can act on directly, which makes them the more practical focus.