Resale of personal data
In plain terms
Why you get contacted after an ordinary purchase: your details were passed on, often under a box you agreed to without reading.
Definition
Resale of personal data is the transfer, for payment or not, of contact and behavioral files to commercial third parties. It's lawful when it rests on validly obtained consent and on informing the people concerned; it accounts for a large share of the solicitations people receive, and the circulation it creates is what makes other methods described on this site possible.
How it works
The starting point is ordinary: a purchase, a sign-up, a sweepstakes, a quote request, a loyalty card. A checkbox agrees to sharing with "partners," a term whose scope isn't visible at the moment of signing. The data then joins actors whose business this is, who enrich it through cross-referencing — an age, a household makeup, an inferred interest — and resell it in segments. The same address ends up circulating among actors with no connection to the original company, which explains two frequent observations: solicitation arrives long afterward, and opting out with one doesn't do anything with the others. What falls within this site's scope is what comes next: an old, well-informed commercial database is also what makes a fraudulent message credible, because it knows a real purchase, a contract number, or a date.
Warning signs
- Solicitation about a topic tied to a recent purchase, from a company unrelated to the seller
- Marketing emails from actors you've never done anything with
- Calls where the caller knows your name, address, and sometimes your contract
- An email address dedicated to a single service starts receiving other things
- A pre-checked box or a "partners" clause in a form you just signed
How to verify
Use a different email address for each important service: when a dedicated address starts receiving other things, you know exactly who passed on the file. Ask a caller where they got your details — you're entitled to that information, and the answer, or the discomfort it causes, is already telling.
What to do
Uncheck the boxes for sharing with partners, provide only what's necessary for the service, and register on the do-not-call list. Be aware, though: that scheme governs lawful solicitation, and by design has no effect on fraudulent calls.
If it already happened
Exercise your rights with each actor involved: access to the data held, erasure, objection to marketing. The request for the origin is particularly useful, since it lets you trace the chain of transfers back. Refer the matter to the CNIL if there's no response. Also treat well-informed solicitation for what it enables: a caller who knows your contract isn't legitimate because of that, and that knowledge is exactly what a fake advisor exploits.
Frequently asked questions
- How did they get my number?
- Usually through a transfer you agreed to without seeing it, in an old form. A dedicated address per service is the simplest way to pin it down going forward: it identifies the source beyond doubt.
- Does the do-not-call list protect against scams?
- No, and it's important to know that: this scheme binds companies that follow the law. Someone calling to scam you doesn't check any list. A call received despite being registered should heighten your attention rather than relax it.
- Can I get my data removed from all these files?
- Actor by actor, yes, by exercising your right to erasure. There's no single process that covers all of them, which is why prevention — unchecked boxes, minimal data, a dedicated address — is more effective than after-the-fact repair.
Related attacks
Official sources
This article is part of the Data and digital identity family. Last updated: 2026-09-03.