The categories that surface someone's personal information rarely get itemised clearly, which makes removal feel harder than it actually is once the actual sources are identified.
The main categories
- People-search aggregators. Sites that compile public records, social data and other sources into a single searchable profile, typically monetised through a paywall to reveal full details — often the most visible and most addressable category.
- Marketing and lead-generation databases. Data compiled and sold for marketing purposes, frequently sourced from data breaches, public registries, or scraped social profiles.
- Regional aggregators. Smaller, Singapore or Southeast Asia-specific sites that compile ACRA filings, property data, and other regional public records into searchable form.
- Breach-data indexes. Sites cataloguing what's included in historical data breaches — different in nature since the underlying breach already happened, but the aggregation itself is still often addressable.
How removal actually works
Most people-search and marketing aggregators maintain an opt-out process, though it's often deliberately unpromoted. Where a direct opt-out isn't offered or is ignored, a formal request citing Singapore's Personal Data Protection Act — specifically the absence of a legitimate basis for continued processing — carries more weight than an informal request and gets a materially higher response rate.
A polite request gets ignored more often than a request that cites the specific legal basis for removal.
Why this needs to be recurring, not one-time
Aggregators re-scrape their source data on their own schedules — a successful removal from a people-search site can quietly reappear months later when the site re-indexes the same public records it originally pulled from. Treating this as a single project rather than an ongoing process is the most common reason executives find themselves "re-discovering" exposure they thought was already handled.
A realistic approach
Start with the highest-visibility, highest-traffic aggregators rather than attempting exhaustive coverage of every possible site — a small number of major aggregators account for most of the actual exposure.
Prioritise anything tied to a residential address over less sensitive categories, given the personal safety dimension beyond pure reputation.
Set a recurring review cadence, quarterly at minimum, rather than treating removal as complete after the first pass.
This sits alongside the broader monitoring discipline covered in our guide to what to actually track — data broker exposure is one specific, addressable category within a wider ongoing programme.