The Digital Whale

Privacy and security

What your digital footprint contains

Most of a personal data trail is assembled by firms the person never contacted, and little is known about whether deletion requests are honoured.

A digital footprint is mostly not made of things people posted. It is assembled by data brokers who buy, merge and infer, and the only government study with compelled disclosure into that industry is from 2014. Deletion rights exist in Europe and California and their outcomes are essentially unmeasured: no regulator publishes how many erasure requests are completed, verified or passed down the supply chain, and the European Data Protection Board's 2026 sweep reported qualitative failures rather than a success rate. Search delisting is documented, because Google published its own numbers, and delisting is not deletion. The one thing observable directly is that breached data accumulates and does not shrink. For a concrete commercial example of the monitoring category discussed here, see this guide.

The footprint is assembled by firms nobody contacted

The scale of the brokerage industry was documented once under compulsion, and nothing since has matched that.

2014

One broker held over 1.4 billion consumer transactions and 700 billion data elements, while another added more than 3 billion new data points to its database each month.

Direction: Increase. Strength of evidence: Mixed.

Federal Trade Commission, "Data Brokers: A Call for Transparency and Accountability", 2014Compulsory-process responses from nine US data brokers

Caveat Twelve years old and covering nine firms; it is still cited because it remains the only US government study with compelled disclosure.

Registry counts are the closest thing to a census, and they count only firms that chose to register. Registered data brokers in California rose from 459 in June 2025 to over 575 by February 2026, with unregistered brokers facing fines of $200 a day (California Privacy Protection Agency via IAPP, 2026). The agency runs a Data Broker Enforcement Strike Force because non-registration is widespread, so the registry measures compliance rather than size.

Deletion rights exist and their outcomes are unmeasured

California now operates one mechanism that forwards a deletion request to every registered broker.

2026

More than 242,000 Californians had submitted deletion requests through the state's DROP platform, 18,000 in the first 48 hours after launch, with brokers required to process requests from 1 August 2026 and check the platform every 45 days.

Direction: Increase. Strength of evidence: Strong.

California Privacy Protection Agency, 2026California DROP platform submissions to 2026

Caveat 242,000 is a tiny fraction of roughly 39 million Californians, and no data exists on completion or verification, so request volume is not an outcome.

Europe's regulators examined the same question and reported what went wrong, not how often it worked.

2026

Across 32 European authorities, 764 controllers responded on erasure practice and the EDPB identified seven recurring failures, including absent internal procedures, weak anonymisation used instead of deletion, and inability to delete from backups.

Direction: Decrease. Strength of evidence: Strong.

European Data Protection Board, Coordinated Enforcement Framework report on the right to erasure, 2026764 controllers responding across 32 European data protection authorities

Caveat Findings are qualitative — the report gives no percentage of requests honoured or deadlines met, so it cannot support any numeric success rate.

Penalties in California have been small: $1.35 million against Tractor Supply, $632,500 against American Honda, $345,178 against Todd Snyder and $56,600 against ROR Partners, all settlements rather than adjudicated findings (CPPA, 2025). Against the industry's revenue these are trivial, the same pattern visible in the gap between European and American privacy enforcement.

Delisting is not deletion

The best-documented removal mechanism is the EU right to be forgotten, documented by the company adjudicating requests against itself.

2019

Google delisted 45% of requested URLs in the first five years of the EU right to be forgotten, with 84% of requests coming from private individuals.

Direction: Decrease. Strength of evidence: Mixed.

Bertram, Bursztein et al. (Google), "Five Years of the Right to be Forgotten", ACM CCS, 20193.2 million URL requests from about 502,000 requesters, May 2014 to May 2019

Caveat Commercially interested — authored by Google about its own decisions — and delisting removes EU search results without deleting the underlying page.

The requests are not evenly spread. Just 1,000 requesters generated 16% of all requests, and 17% to 21% of removals related to the requester's legal history (Bertram, Bursztein et al., 2019) — shaped partly by reputation-management firms filing on clients' behalf. "Requesters" and "individuals" are not the same population.

Employers do look, and the measurement is a decade old

The best evidence on employer screening is a field experiment, not a survey — which matters, because the circulating survey figures are marketing.

2020

Between 10.3% (lower bound) and roughly 28.8% (likely) of employers searched for candidates' social media profiles online.

Direction: Increase. Strength of evidence: Strong.

Acquisti & Fong, "An Experiment in Hiring Discrimination via Online Social Networks", Management Science, 20204,173 job applications sent to US employers, fieldwork in 2013

Caveat Fieldwork in 2013, limited to technical and managerial roles, with search rates inferred from AdWords and LinkedIn analytics rather than observed.

The same experiment found that what employers saw changed outcomes, in one subgroup.

2020

A Muslim candidate received callbacks at 6.25% against 22.58% for an otherwise identical Christian candidate in Republican-leaning counties.

Direction: Decrease. Strength of evidence: Mixed.

Acquisti & Fong, Management Science, 2020Subgroup of the 4,173-application field experiment, Republican-leaning counties

Caveat The national effect was not significant, no discrimination was found against the gay candidate, and county political lean is only a proxy for the hiring manager.

A real effect in a small subgroup, a null result nationally: both halves belong in any account of whether an online presence changes hiring.

Breached data accumulates and does not expire

2026

Have I Been Pwned indexes 17,777,627,763 breached account records, an accumulating public record that does not shrink over time.

Direction: Increase. Strength of evidence: Mixed.

Have I Been Pwned (Troy Hunt), site totals, 20261,025 breached websites indexed, retrieved August 2026

Caveat Counts records rather than people — one person appears many times — and covers only breaches published and submitted.

That total is the closest available proxy for persistence. It shows that data released once stays released, but it does not measure any individual's exposure, and it is a lower bound given how much of the breach record goes undisclosed.

The short version

  • The only US government study of data brokers with compelled disclosure covered nine firms in 2014; one held 700 billion data elements.
  • California's registered broker count rose from 459 in mid-2025 to over 575 by February 2026, but a registry counts registrants, not the industry (CPPA, 2026).
  • Over 242,000 Californians had filed deletion requests through the state platform, and nothing is published on how many were completed (CPPA, 2026).
  • Google delisted 45% of URLs requested under the EU right to be forgotten in its first five years, by its own count, and delisting leaves the page online (2019).
  • Employer social media screening has been measured once, in 2013 fieldwork, so current rates are unknown and the widely quoted 70% figure is a marketing survey.