Bruce Schneier told Congress: Deleting Broker Data Is a matter of National Security
Schneier to Congress: Deleting Broker Data Is Security
By Tom Daly, Founder and CEO, Priwall by mePrism · October 2026
Key takeaways
-
A national-security warning since 2017. Bruce Schneier told Congress that limiting, securing and deleting broker-held personal data is a matter of national security.
-
Employee data creates enterprise exposure. Broker listings containing addresses, phone numbers and family details can help attackers impersonate employees and executives.
-
California's DROP is progress, not a complete solution. It enables residents to request deletion from registered brokers but does not provide company-wide exposure monitoring or removal verification.
-
Removal can be measured. An independent agreed-upon procedures engagement recalculated Priwall's reported enterprise removal rates at greater than 92% after 30 days and greater than 99% after 90 days.
On November 1, 2017, Bruce Schneier submitted testimony to a House Energy and Commerce subcommittee about the Equifax breach. Officially the hearing was about credit data. Schneier used it to make a bigger point, one he put in a single line: "Equifax is more than a credit reporting agency. It's a data broker."
A few pages later he wrote the sentence I keep coming back to:
“In a world where foreign governments use cyber capabilities to attack US assets, requiring data brokers to limit collection of personal data, securely store the data they collect, and delete data about consumers when it is no longer needed is a matter of national security.”
Bruce advises Priwall now, so I'll say that up front. My point here isn't that he agrees with us. He put this in writing to Congress nine years ago, and most companies still treat broker data as somebody else's problem.
The testimony is specific about the harm. Of the names, Social Security numbers, birth dates and addresses taken from Equifax, he wrote that this "is exactly the sort of information criminals can use to impersonate victims to banks, credit card companies, insurance companies, cell phone companies and other businesses vulnerable to fraud." He estimated there were 2,500 to 4,000 brokers at the time, "almost all of them companies you've never heard of and have no business relationship with." His list of what they collect reads like a pretexting kit: names, addresses, phone numbers, email addresses, household members, profession, income, property.
Consumer data is an enterprise problem
Schneier framed his testimony around consumers, which made sense at an Equifax hearing. But consumers go to work. When a CFO's home address and spouse's name show up on a people-search site, that's the profile a wire-fraud crew uses to impersonate her. When a help-desk lead's cell number is for sale, that's the number an attacker calls before asking for an MFA reset. Every employee profile a broker sells saves an attacker a step of research.
So I take the national-security framing literally, and I think security teams should too. When the attacker is a foreign intelligence service, the logic goes like this: brokers collect the data, attackers buy or harvest it, and removing it shrinks the target. When the attacker is a ransomware affiliate working through your org chart, the logic is exactly the same.
The testimony also explains why you can't leave this to each employee. "In general, options to 'opt-out' don't work with data brokers," Schneier wrote. "Data brokers will still collect data about consumers who opt out." He put it more bluntly elsewhere in the same document: "We can't remove our data from their databases." In 2017 that was close to literally true. People had no practical way to see what hundreds of brokers held about them, and a single opt-out rarely lasted.
What has changed, and what hasn't
Some of that has changed. California's Delete Act created DROP, a state platform that sends a single deletion request to every registered data broker. Brokers had to begin processing those requests on August 1, 2026, and must check for new matches at least every 45 days (California Privacy Protection Agency). As of this week, brokers report deleting more than 60 million consumer profiles, and about two-thirds of the roughly 650 registered brokers have accessed the system (Bloomberg Law). It's real progress, and it supports Schneier's central point that deletion is the thing that works.
It doesn't solve the enterprise problem, though. DROP is for California residents, it reaches registered brokers, and every employee has to sign up on their own. It doesn't tell a security team which executives are exposed, on which sites, or whether a removal held. A company with people in many states can't wait for the rest of the country to build its own version.
Getting this done for a workforce means doing what Schneier described, on your employees' behalf: find the records, delete them, and keep checking that they stay deleted. That's the job Priwall was built for. We locate employee and executive records across hundreds of U.S. data broker and people-search sites and file the removals, including as an authorized agent where the law allows. We rescan and resubmit when records reappear, and we give the security team proof of removal.
Removal-rate claims in this category are easy to make and hard to check. So we asked Sensiba to recalculate our reported rates under an AICPA AT-C 215 agreed-upon procedures engagement. For a representative sample of Priwall enterprise customers, the signed practitioner report found removal rates greater than 92% at 30 days and greater than 99% at 90 days, with a four-day median to first confirmed removal. It's an independent recalculation of what we report, not an audit or certification, and we describe it that way.
Schneier's testimony also warned that, unless brokers put the public interest ahead of profits, "the security of this industry will never improve without government regulation." Nine years later, some of that regulation has arrived. Your employees' data is still out there in the meantime, and deleting it is something a security team can start this quarter.
If your organization’s employee data has been exposed, or you want to know how easily someone can find your leadership team’s personal information, talk to us about Priwall by mePrism.
Frequently asked questions
What did Bruce Schneier tell Congress about data brokers?
In written testimony to the House Energy and Commerce Subcommittee on Digital Commerce and Consumer Protection on November 1, 2017, Bruce Schneier said that requiring data brokers to limit collection, secure stored data, and "delete data about consumers when it is no longer needed is a matter of national security." Describing the data stolen from Equifax, which he called a data broker, he also testified that it "is exactly the sort of information criminals can use to impersonate victims."
Why is data broker exposure a cybersecurity risk for businesses?
Data brokers sell employees' home addresses, phone numbers, family members, and other personal details. Attackers use that information to impersonate executives, target help desks, and make phishing and wire-fraud attempts more convincing. Removing employee records from brokers takes that research away from attackers.
Does California's DROP platform solve the problem for employers?
DROP lets California residents send one deletion request to registered data brokers, and brokers began processing requests on August 1, 2026. It applies to California residents, relies on each person enrolling individually, and doesn't give employers visibility into which employees are exposed or whether removals hold.
How does Priwall remove employee data from data brokers?
Priwall by mePrism finds employee and executive records across hundreds of U.S. data broker and people-search sites and files removals, including as an authorized agent where permitted. It rescans and resubmits when records reappear and gives security teams proof of removal. A Sensiba AT-C 215 agreed-upon procedures report found removal rates greater than 92% at 30 days and greater than 99% at 90 days for a representative sample of Priwall enterprise customers.
Ready to try Priwall by mePrism?
If you're a company protecting at-risk employees, or an individual concerned about your digital footprint, start your privacy removal today at mePrism.com
Because your data shouldn’t be a roadmap for violence.