The Fair Credit Reporting Act, passed in 1970, is one of the older privacy statutes still doing real work. It regulates the "consumer report": information bearing on your creditworthiness, credit standing, capacity, character, or general reputation, when used to decide about credit, insurance, employment, or housing. If something is a consumer report, it can only be sold for a permissible purpose, you have a right to see it, and you have a right to dispute what is in it.
The argument that carved out the header is narrow and durable. Your name and address say nothing about whether you pay your bills. Therefore, the reasoning goes, header data is not a consumer report, and the FCRA's restrictions do not attach to it. The three nationwide credit bureaus hold identity records on effectively every adult in the country who has ever had a credit relationship, and that carve-out has let them license the identifying layer of those records into a separate market.
Where it ends up
The buyers are the people-search and risk-assessment products: skip tracing tools used by debt collectors, identity verification services, fraud scoring, background check platforms, investigative databases sold to law enforcement and private investigators. When one of these can tell you that a person with a given name lived at a specific address between 2014 and 2019 and previously used a maiden name, credit header data is a common source of that continuity.
This is why deleting an account or moving house does so little. The record is not built from what you posted. It is built from the administrative trail that follows a person: credit applications, address changes reported by lenders, phone numbers given to creditors. You never opted into it because it was generated as a byproduct of ordinary financial life.
Most privacy advice targets data you disclose. Credit header data is data about you, generated by third parties, sold under a rule that says it is not the regulated product. No amount of careful posting affects it, and the consent model that governs most of the internet was never involved.
What happens when the gate is weak
Because header data sits outside the FCRA's permissible-purpose regime, the checks on who may buy it are largely contractual. Vendors verify their customers, review use cases, and audit access. When that vetting fails, it fails at scale.
The clearest documented case ran from roughly 2007 to 2013. A Vietnamese national named Hieu Minh Ngo built a service selling lookups of Americans' Social Security numbers, dates of birth and addresses. He obtained access by posing as a US private investigator and contracting with an aggregator called Court Ventures, which was acquired by Experian in 2012 while the arrangement was live. Ngo resold queries to over a thousand customers. He was arrested in 2013 and sentenced to thirteen years in 2015, and the episode produced congressional hearings on how a fraudster came to be a paying customer of an identity database.
The mechanism failed exactly where you would expect. The data was not stolen. It was sold, through a channel designed to sell it, to a buyer whose paperwork looked adequate.
The regulatory attempt, and its withdrawal
In December 2024 the Consumer Financial Protection Bureau proposed a rule that would have addressed this directly, treating data brokers that sell identifying information derived from credit files as consumer reporting agencies, and treating credit header data as a consumer report. Under that rule, selling header data would have required a permissible purpose, which would have removed the market's foundation.
The bureau withdrew the proposal in May 2025. Whatever position you take on the merits, the practical situation as of today is unchanged: the carve-out stands, and the market operates as it did.
State law has moved on a separate track. California's Delete Act, signed in 2023, requires the state privacy agency to build a single deletion mechanism that registered data brokers must check and honour, with the statute setting the agency's build deadline in January 2026 and broker compliance beginning in August 2026. It reaches registered brokers operating in California rather than the credit bureaus' underlying files, which is a real limit, but a one-request-to-many-brokers channel is a structural improvement over filing individually with hundreds of companies.
What the available controls actually reach
| Control | What it stops | What it does not |
|---|---|---|
| Security freeze (free at all three bureaus) | New credit being opened in your name without your PIN | Header data continuing to be compiled and sold |
| Prescreen opt-out (optoutprescreen.com) | Firm offers of credit and insurance based on your file | Identity lookups, skip tracing, background products |
| Broker-by-broker deletion | The specific copy that broker holds, for a while | Repopulation from upstream sources at the next refresh |
| State deletion mechanisms | Registered brokers in that state, in one request | The bureaus' own files and unregistered downstream holders |
| Address minimisation | New entries linking you to a physical location | Everything already recorded |
What is worth doing anyway
Nothing here amounts to removal, and it would be misleading to suggest otherwise. What follows reduces the rate at which the file grows and limits its usefulness to someone who buys it.
- Freeze all three bureaus and keep them frozen. Free by federal law since 2018, and it blocks the most damaging use of your identity file even though it does not stop the trade in it. See our guide to freezes.
- Opt out of prescreened offers. One phone call or one web form, permanent if you mail the confirmation. It removes a category of mail that is itself a theft vector.
- Use the state mechanism if you have one. California residents in particular should use the single deletion channel rather than filing individually. Elsewhere, the broker-by-broker process is still the route, and it needs repeating.
- Break the linkage where you can. A forwarding address, a dedicated phone number for financial accounts, and per-service email aliases reduce how confidently new records join to old ones. Records already written stay written.
- Exercise access rights where they exist. Several of the large investigative databases will provide a copy of what they hold on request, and reading yours tends to be more motivating than any article about it.
Why this belongs in a threat model
For most people the credit header market is an abstraction. For people who are being looked for, it is the mechanism. Domestic abuse survivors, people who have left a controlling community, journalists working on organised crime, anyone with a motivated adversary: the standard first step is a commercial lookup, and address history is the product. It is worth reading alongside the location broker trade, which supplies the movement layer over the same identity spine.
There is also a lesson about where privacy law actually binds. Encryption protects the content of what you say, and metadata resistance protects the pattern of who you say it to. Neither touches a dossier assembled from mortgage applications and utility connections. That is a legal problem, and it gets solved by changing what may be sold, not by choosing a better app. Both kinds of work matter, and they are not substitutes.