
How do cold callers get my number?
Key Facts
- A 2025 database built from five state registries identified more than 750 data brokers operating in the U.S. alone, according to Privacy Rights Clearinghouse.
- One data broker's investigation traced a single person's data through a chain reaching at least 50 other companies.
- An Australian data scientist still received roughly three unwanted calls per day despite her number being on a Do Not Call register holding over 12 million numbers, her Guardian investigation found.
- California's Delete Act imposes fines of $200 per consumer per day for ignored deletion requests, per Privacy Rights Clearinghouse.
- The FTC's Telemarketing Sales Rule requires two-year recordkeeping of verifiable authorizations and restricts calling to 8 a.m.–9 p.m., according to FTC guidance.
- A broker claimed its data came from a 2014 marketing campaign but had no records proving consent was ever given, the Guardian investigation documented.
- Deleted data can reappear when a broker reacquires your information from another source, removal testing shows.
The Data Broker Pipeline: How Your Number Ends Up on a Calling List
Your phone number didn't leak by accident. It traveled a well-worn commercial pipeline — one that starts with your own everyday activity and ends on a cold caller's dialing list, often with no record of how it got there.
Phone number data flows through four main channels: public records, telecommunications providers, online directories, and data brokers, according to industry analysis of phone data providers. The broker channel is the engine. These companies collect, aggregate, and sell personal information about people they have no direct relationship with — and a 2025 unified database built from five state registries identified more than 750 of them operating in the U.S. alone.
What feeds them is mundane. Every app sign-up, loyalty program enrollment, retailer email capture, and sweepstakes entry can carry fine-print consent buried in a service agreement, as the National Cybersecurity Alliance explains. Public records like property ownership, voter registration, and bankruptcy filings add more. Some pipelines are stranger still — caller-ID app Truecaller crowdsources phone number data from its own users' contact lists.
- App sign-ups and Mobile Advertising IDs that track device activity across apps
- Loyalty programs and retailer data sharing
- Public records: property, voter registration, court filings
- Crowdsourced contact lists from other consumers' phones
- Purchases from other data brokers, compounding the chain
The resale problem is where traceability dies. A documented Guardian investigation traced one person's data through a broker chain: collected by Eight Dragons Digital in 2014, passed to Smrtr in 2016, then to CoreLogic by 2023. The original broker had likely shared the data with at least 50 other companies. When pressed, Eight Dragons Digital claimed the data came from a marketing campaign — but had no records to verify the campaign or prove consent was ever given.
That missing consent record is not an anomaly; it's the norm in brokered data. Lists get sold, licensed, combined, and resold until no one can say who originally agreed to what. Data often moves "unmasked" — names and numbers fully visible — and can end up with overseas telemarketers beyond the reach of local privacy law.
This is exactly why list source vetting exists as a discipline. Expert guidance to businesses is blunt: "Don't buy sketchy data lists. Check where consumer data comes from and require clear proof of its source." At My AI Call Center, that question comes first — every campaign begins with a review of list source and consent records, and bought lists without clear permission records are flagged or declined before a single dollar is spent.
The stakes of skipping that step are rising. California's Delete Act now carries penalties of $200 per consumer per day for ignored deletion requests, and the FTC's Telemarketing Sales Rule extends liability to companies that substantially assist violating telemarketers. A cheap list with no consent lineage isn't a shortcut — it's a liability with a dialing plan.
Why the Registry Alone Doesn't Stop the Calls
If you're on the Do Not Call list and the calls keep coming, you're not imagining it — and you're not alone. The registry works, but only on the people who follow the rules.
Here's the honest breakdown. The Do Not Call Registry is genuinely one of the best tools for stopping spam calls, and legitimate telemarketers face real obligations under the FTC's Telemarketing Sales Rule, including DNC compliance and record-keeping requirements. But the registry only constrains callers who check it. A documented investigation by an Australian data scientist found she was still receiving roughly three unwanted calls per day — despite being registered on a national Do Not Call list holding more than 12 million phone numbers.
Why doesn't registration stop the calls? Three reasons stand out:
- Brokers and resellers aren't telemarketers. Data brokers compile and sell your number through opaque chains — one investigation traced a single person's data through at least 50 companies — and the callers at the end of those chains often operate outside your country's laws entirely.
- Consent records are frequently missing. In the documented case, a broker claimed the data came from a 2014 marketing campaign but had no records to verify the campaign or prove consent was ever given.
- Opted-out data can resurface. Even after your number is removed, removal testing shows that deleted data can reappear when a broker reacquires your information from another data source.
That last point matters more than most people realize. Once your number enters the broker ecosystem, it gets sold, licensed, and recombined across companies, making it nearly impossible to trace or permanently delete. Your DNC status travels with you; the copies of your data do not.
This is also why list discipline matters on the business side. When companies buy cheap, recycled lists, they inherit exactly these problems — stale numbers, unverifiable consent, and people who already opted out somewhere else. That's the failure mode My AI Call Center screens for before any campaign launches: list source and consent records are reviewed first, and bought lists without clear permission records are flagged and, in most cases, declined. If the list won't support the campaign, clients hear that plainly before spending anything.
The registry is still worth joining — it raises the cost of calling you legally. But treating it as a complete solution misunderstands how your number actually circulates. The real fix, for consumers and for businesses that call consumers, is knowing where every number came from and proving permission before the first ring.
The Consent Gap: Why Bought Lists Are a Compliance and Quality Risk
When a broker sells your number, the buyer rarely knows — or asks — whether you ever agreed to be called. That's the consent gap, and it sits at the center of why bought lists are both a legal risk and a quality problem for any business that dials them.
The gap is well documented. In one investigation, a data broker claimed a consumer's details came from a 2014 marketing campaign but had no records to verify the campaign or prove consent was ever given. That same broker's data likely passed to at least 50 other companies, each layer further removed from any original permission.
For businesses, this creates two intertwined problems. The first is compliance: under the FTC's Telemarketing Sales Rule, companies must comply with Do Not Call Registry requirements, restrict calls to 8 a.m.–9 p.m., and keep records — including verifiable authorizations — for two years. If your list came from a broker who can't produce consent records, you can't meet that standard no matter how careful your own process is.
The second is quality. Brokered lists are resold and recycled, so numbers go stale, get reassigned, and reappear even after people opt out — removed data can pop back up when a broker reacquires it from another source. Lead-generation mills deliberately buy cheap lists, which is why the same consumer gets repeated calls from multiple vendors. And the risk isn't just annoyance: scammers can sometimes access data sold by data brokers, meaning a purchased list can carry reputational exposure along with legal risk.
Enforcement is escalating fast. California's Delete Act imposes fines of up to $200 per consumer per day for deletion violations — a broker ignoring a million deletion requests could face roughly $200 million in potential fines per 45-day cycle. The state also launched a Data Broker Enforcement Strike Force in late 2025, fining and shutting down unregistered brokers.
The good news: legitimate calling paths exist. The TSR expressly permits calls based on established business relationships and written permission to call. That's why list discipline matters before a single dial:
- Ask where the list came from and require clear proof of its source
- Screen against DNC status and TCPA/TSR obligations as a quality gate
- Log explicit consent for contact information and sharing
- Treat bought lists without permission records as a decline, not a discount
This is how My AI Call Center approaches every campaign: list source and consent records are checked before launch, and if a list won't support the campaign, we tell you plainly — before you spend anything. Structured calls to permissioned contacts aren't just safer; they perform better, because the person on the other end actually expects to hear from you.
List Discipline: How Responsible Outbound Calling Works Instead
The good news: businesses don't have to feed this machine. Expert guidance for anyone running outbound campaigns is blunt — "Don't buy sketchy data lists. Check where consumer data comes from and require clear proof of its source." That single habit separates disciplined calling from the cold-call noise consumers dread.
List discipline starts with consent lineage. Before any list is approved, the practical questions are simple: Where did these numbers come from? Can the seller show records proving each person agreed to be contacted? In one documented investigation, a broker claimed its data came from a 2014 marketing campaign but had no records to verify the campaign or prove consent was ever given. If a vendor can't produce that proof, the list should be flagged — and in most cases declined.
Vetting isn't a paperwork exercise; it's a quality gate. A disciplined pre-launch review looks like this:
- Documented consent lineage checked before launch, not after complaints arrive.
- Bought lists without permission records flagged or declined outright.
- Do Not Call screening run as a gate — the FTC's Telemarketing Sales Rule requires DNC compliance, restricts calling to 8 a.m.–9 p.m., and mandates two-year recordkeeping of verifiable authorizations.
- Calls placed only inside approved windows, with opt-outs honored immediately and carried across every future campaign.
- An honest assessment of whether the list can actually support the campaign — before any money is spent.
That last point matters more than most businesses realize. Broker-sourced data decays and resurfaces: removal services report that deleted information can pop back up when a broker reacquires it from another source, and data that has been sold "may remain in circulation" even after sharing stops. A list built on borrowed consent is a compliance liability and a wasted dial.
The stakes are rising, too. California's Delete Act imposes fines of $200 per consumer per day for deletion violations, and enforcement against unregistered brokers is already producing shutdowns and five-figure penalties. The TSR also extends liability to companies that provide "substantial assistance or support" to violating telemarketers — meaning a business can be on the hook for its list vendor's sins.
This is the standard My AI Call Center applies to every campaign. Lists are approved, permissioned, or reviewed — never indiscriminate. List source and consent records are checked before launch, bought lists without clear permission records are flagged and usually declined, and clients are told plainly if a list won't support the campaign before they spend anything. Structured calling against properly sourced data isn't just the compliant path — it's the one that actually reaches people willing to talk.
Managed outbound calling campaigns for approved, permissioned lists start at 9¢ per connected minute.
What to Ask Before Any Campaign Launches
A bought list can look clean on a spreadsheet and still be radioactive. Before any outbound campaign launches, run through a short set of questions — the same ones that separate legitimate calling from the broker-fed pipeline described above.
1. Where did this list come from? This is always the first question. Expert guidance on the data broker ecosystem is blunt: "Don't buy sketchy data lists. Check where consumer data comes from and require clear proof of its source." If the answer traces back to a lead vendor who can't name the original collection point, treat that as a stop sign, not a yellow light.
2. What consent records exist — and can anyone produce them? In one documented investigation, a data broker claimed a consumer's number came from a marketing campaign but had no records to verify the campaign or prove consent was ever given. Ask for the same proof in writing: when consent was captured, what language was used, and where the record lives.
3. What is your relationship to these contacts? The FTC's Telemarketing Sales Rule permits calls based on established business relationships and written permission — past customers, active members, recent applicants. Those relationships are your strongest legal and practical foundation, and they define which campaign types make sense.
4. What regulated-area flags apply? Industry, location, contact type, and consent status all change the rules. The TSR alone restricts calling windows to 8 a.m.–9 p.m. and mandates two-year recordkeeping including verifiable authorizations. Healthcare, financial services, and multi-state campaigns each add their own layers, and requirements vary — get appropriate legal guidance before launch.
5. What happens if the answer is "not sure"? "Not sure" is not a launch blocker, but it is a review trigger. At My AI Call Center, the Plan My Campaign intake captures your goal, list volume and relationship, consent records, and regulated-area flags — and any "not sure" answer routes the campaign to manual review before a single dial is made.
Here is the checklist in one place:
- Name the original source of every contact on the list
- Produce written consent records, not verbal assurances
- Map each contact to a real business relationship
- Flag industry, state, and consent-status constraints upfront
- Route every "not sure" to manual review before spending anything
The stakes for skipping this are rising. California's Delete Act now carries penalties of $200 per consumer per day for deletion violations, and regulators have launched a dedicated data broker enforcement strike force. A list you cannot defend is a list you cannot afford to call.
This is also why list discipline is a quality issue, not just a legal one. Brokered data decays, recirculates, and re-emerges even after removal — removed records can pop back up when brokers reacquire them from other sources. A permissioned, first-party list simply outperforms.
If you are planning outbound calling and want the list questions answered before you commit a dollar, start with a free campaign review. My AI Call Center runs managed outbound calling campaigns for approved, permissioned lists — from 9¢ per connected minute, with the full number quoted before launch. We will tell you plainly if your list will not support the campaign, before you spend anything.
Frequently Asked Questions
How do cold callers actually get my phone number in the first place?
I'm on the Do Not Call Registry — why am I still getting calls?
Can data brokers prove I actually agreed to be called?
If I opt out or request deletion, does my number actually stay off the lists?
What risks does a business take when buying a cold-call list from a broker?
How does My AI Call Center make sure the lists you call are legitimate?
The Bottom Line: Your Number Has a History — Your List Should Too
Cold callers get your number through a sprawling broker ecosystem: fine-print consents, loyalty programs, public records, and resale chains that stretch through dozens of companies and erase any trace of original permission. The Do Not Call Registry helps, but it only constrains callers who check it — and once your number enters the pipeline, it can resurface even after removal. The lesson for businesses is the same as for consumers: a list you can't trace is a list you can't defend, especially with penalties like $200 per consumer per day under California's Delete Act. That's why list discipline comes first at My AI Call Center — every campaign starts with a review of list source and consent records, and bought lists without clear permission records are flagged or declined before a single dollar is spent. If you're planning outbound calling, start with a free campaign review. Managed campaigns for approved, permissioned lists run from 9¢ per connected minute, and you'll hear plainly if your list won't support the campaign — before you spend anything.