Data Brokers

Credit Header Data: The Identity File You Never Applied For

July 28, 2026 8 min read Haven Team

Pull your credit report and look at the top section before the accounts start. Your legal name, every variation of it you have ever used, your current and previous addresses, phone numbers, date of birth, Social Security number. In the United States that block is called the credit header, and for decades the industry position has been that it is not part of the credit report at all. That distinction is why an investigator can type your name into a commercial database and get your last five addresses.


The Fair Credit Reporting Act, passed in 1970, is one of the older privacy statutes still doing real work. It regulates the "consumer report": information bearing on your creditworthiness, credit standing, capacity, character, or general reputation, when used to decide about credit, insurance, employment, or housing. If something is a consumer report, it can only be sold for a permissible purpose, you have a right to see it, and you have a right to dispute what is in it.

The argument that carved out the header is narrow and durable. Your name and address say nothing about whether you pay your bills. Therefore, the reasoning goes, header data is not a consumer report, and the FCRA's restrictions do not attach to it. The three nationwide credit bureaus hold identity records on effectively every adult in the country who has ever had a credit relationship, and that carve-out has let them license the identifying layer of those records into a separate market.

Where it ends up

The buyers are the people-search and risk-assessment products: skip tracing tools used by debt collectors, identity verification services, fraud scoring, background check platforms, investigative databases sold to law enforcement and private investigators. When one of these can tell you that a person with a given name lived at a specific address between 2014 and 2019 and previously used a maiden name, credit header data is a common source of that continuity.

This is why deleting an account or moving house does so little. The record is not built from what you posted. It is built from the administrative trail that follows a person: credit applications, address changes reported by lenders, phone numbers given to creditors. You never opted into it because it was generated as a byproduct of ordinary financial life.

The structural point

Most privacy advice targets data you disclose. Credit header data is data about you, generated by third parties, sold under a rule that says it is not the regulated product. No amount of careful posting affects it, and the consent model that governs most of the internet was never involved.

What happens when the gate is weak

Because header data sits outside the FCRA's permissible-purpose regime, the checks on who may buy it are largely contractual. Vendors verify their customers, review use cases, and audit access. When that vetting fails, it fails at scale.

The clearest documented case ran from roughly 2007 to 2013. A Vietnamese national named Hieu Minh Ngo built a service selling lookups of Americans' Social Security numbers, dates of birth and addresses. He obtained access by posing as a US private investigator and contracting with an aggregator called Court Ventures, which was acquired by Experian in 2012 while the arrangement was live. Ngo resold queries to over a thousand customers. He was arrested in 2013 and sentenced to thirteen years in 2015, and the episode produced congressional hearings on how a fraudster came to be a paying customer of an identity database.

The mechanism failed exactly where you would expect. The data was not stolen. It was sold, through a channel designed to sell it, to a buyer whose paperwork looked adequate.

The regulatory attempt, and its withdrawal

In December 2024 the Consumer Financial Protection Bureau proposed a rule that would have addressed this directly, treating data brokers that sell identifying information derived from credit files as consumer reporting agencies, and treating credit header data as a consumer report. Under that rule, selling header data would have required a permissible purpose, which would have removed the market's foundation.

The bureau withdrew the proposal in May 2025. Whatever position you take on the merits, the practical situation as of today is unchanged: the carve-out stands, and the market operates as it did.

State law has moved on a separate track. California's Delete Act, signed in 2023, requires the state privacy agency to build a single deletion mechanism that registered data brokers must check and honour, with the statute setting the agency's build deadline in January 2026 and broker compliance beginning in August 2026. It reaches registered brokers operating in California rather than the credit bureaus' underlying files, which is a real limit, but a one-request-to-many-brokers channel is a structural improvement over filing individually with hundreds of companies.

What the available controls actually reach

Control What it stops What it does not
Security freeze (free at all three bureaus) New credit being opened in your name without your PIN Header data continuing to be compiled and sold
Prescreen opt-out (optoutprescreen.com) Firm offers of credit and insurance based on your file Identity lookups, skip tracing, background products
Broker-by-broker deletion The specific copy that broker holds, for a while Repopulation from upstream sources at the next refresh
State deletion mechanisms Registered brokers in that state, in one request The bureaus' own files and unregistered downstream holders
Address minimisation New entries linking you to a physical location Everything already recorded

What is worth doing anyway

Nothing here amounts to removal, and it would be misleading to suggest otherwise. What follows reduces the rate at which the file grows and limits its usefulness to someone who buys it.

Why this belongs in a threat model

For most people the credit header market is an abstraction. For people who are being looked for, it is the mechanism. Domestic abuse survivors, people who have left a controlling community, journalists working on organised crime, anyone with a motivated adversary: the standard first step is a commercial lookup, and address history is the product. It is worth reading alongside the location broker trade, which supplies the movement layer over the same identity spine.

There is also a lesson about where privacy law actually binds. Encryption protects the content of what you say, and metadata resistance protects the pattern of who you say it to. Neither touches a dossier assembled from mortgage applications and utility connections. That is a legal problem, and it gets solved by changing what may be sold, not by choosing a better app. Both kinds of work matter, and they are not substitutes.

Try Haven free for 15 days

Encrypted email and chat in one app. No credit card required.

Get Started →