$1.24B
ZoomInfo's FY2025 revenue, per its own filings
4
US states now requiring data broker registration
$29.55M
ZoomInfo's 2024 privacy class-action settlement

All figures sourced individually below. Where industry estimates vary significantly between research firms, that variance is stated rather than hidden.

A large, fast-growing, and largely unaccountable industry

Estimates of the global data broker market's size vary dramatically depending on who's measuring and what they count as "data brokering". Figures from market research firms in 2026 range from under $4 billion to well over $500 billion, spanning everything from narrow B2B contact-data resale to the entire consumer data-analytics economy. That inconsistency is itself worth noting: this is an industry large and fragmented enough that even professional analysts can't agree on its basic size. What's harder to dispute is that the FTC's own study, over a decade ago, found a single data broker holding more than 700 billion data elements and adding upward of 3 billion new data points to its database every month, and the industry has only grown since, with more states now moving to regulate it than ever tried to before.

ZoomInfo and Apollo aren't just sales tools: they're legally recognized data brokers

This is easy to verify directly: both ZoomInfo Technologies LLC and Apollo.io appear in California's official CPPA Data Broker Registry, registered under the state's data broker law alongside hundreds of other companies. That's not an outside label. It's each company's own required legal self-identification.

California is one of now four U.S. states (joined by Texas, Oregon, and Vermont) that require data brokers to register annually and disclose their practices, with Connecticut set to become the fifth once its law takes effect in 2027. California's registration regime is the most developed: as of January 2026, the state's Delete Act put a centralized tool live (the Delete Request and Opt-out Platform, or DROP) letting a California resident submit one deletion request that every registered broker in the state must honor. The fact that regulators felt a single-request, all-broker deletion tool was necessary infrastructure says something about how unmanageable broker-by-broker opt-outs had become for ordinary people.

Apollo's own privacy policy confirms it discloses annual deletion and opt-out request volumes as required under California's data broker law. Reporting on that disclosure has put Apollo's reported 2024 California deletion-request count at 18,610. From one state, in one year, for one company. That's a meaningful number of people who found out they were in the database and actively asked to be removed.

How your information gets in there: usually without you ever agreeing

Neither company primarily asks you directly. Publicly reported sourcing methods across the industry include:

  • Web and profile scraping. Apollo has publicly described scraping information from LinkedIn, company websites, and event attendee lists.
  • Contributor plugins. Free browser or inbox tools are offered in exchange for scanning a user's email activity. Meaning if you've ever emailed someone who installed one, your contact details may have been harvested without your knowledge.
  • Cross-broker data partnerships, which extend coverage well beyond what any single company's own collection could reach.

The legal record so far

In 2024, ZoomInfo agreed to pay $29.55 million to settle a class action (Ramos et al.) covering California, Illinois, Indiana, and Nevada residents, who alleged the company used their personal information on public preview pages to advertise subscriptions without consent. ZoomInfo did not admit wrongdoing. A separate class action followed in Washington state in September 2024 alleging similar conduct under that state's Personality Rights Act, and ZoomInfo's own 2026 quarterly filing discloses a further class action, filed in March 2025 in the Superior Court of Quebec, raising comparable allegations under Canadian law. In other words: this isn't a single settled incident. It's a pattern of overlapping legal challenges across three separate jurisdictions in under two years.

Fair counterpoint: the industry's own defense

It's worth stating the other side plainly, since none of this happens in a legal vacuum. Data brokers and their trade groups generally argue that the underlying information is legally sourced from public or business-context sources, not stolen; that the industry has real, legitimate uses beyond sales prospecting. Fraud detection, credit risk assessment, and identity verification among them; and that opt-out mechanisms exist and are, in the states that require it, legally mandated. ZoomInfo itself points to concrete customer outcomes as its value proposition, the company's own 2024 results cite a 91% improvement in customer connect rates and 32% average pipeline growth, framed as productivity gains for the sales teams who buy access. And it's true that no comprehensive federal privacy law currently prohibits this business model in the U.S. It operates within the legal bounds that presently exist, however contested those bounds are at the state level.

That's a real argument, and a blanket ban on data brokering generally would have genuine trade-offs for fraud prevention and other uses unrelated to cold sales outreach. The case here is narrower and more specific: the sales-lead segment of this industry. The part that puts a working professional's name, direct email, and phone number into a resellable database without ever asking that person first, doesn't need the whole data-broker apparatus to justify itself. It needs the individual's cooperation, which is exactly the transaction Moniker is built to put back in the buyer's hands.

Where this leaves you as a buyer

There's no federal ban coming imminently, four to five state registries are only as good as a person's awareness that they need to file a request, and even a successful opt-out at one company doesn't touch a colleague's contributor-plugin install putting you right back into someone else's database tomorrow. Waiting for regulation to fully solve this isn't a strategy. It's what's already been tried for over a decade since that first FTC report, without a comprehensive fix.

The more durable answer is not participating in the exposure in the first place: engaging vendors through a verified identity you control, that can be reset entirely, with no real database anywhere still holding your actual details because you filled out one demo form in 2024.

See how Moniker works →

This article reflects public filings, court records, and industry reporting available as of July 2026, cited individually throughout. It is not legal analysis. Where settlements are referenced, the companies involved did not admit wrongdoing unless explicitly noted otherwise.

Stop being a row in someone else's database.

getmoniker.id