What Your ISP Is Selling About You Right Now — And How to Cut Them Off
Photo: Stealth Communications, CC BY-SA 3.0, via Wikimedia Commons
Most Americans assume their internet provider is just the company that keeps the lights on — a utility, basically. You pay your bill, they deliver the bandwidth, everyone goes home happy.
That's not quite how it works.
Your ISP — whether that's Comcast/Xfinity, AT&T, Verizon, Spectrum, or one of the regional players — sits in an extraordinarily privileged position on your network. Every request your device makes has to pass through their infrastructure before it reaches the internet. That means they can see, log, and in many cases monetize a detailed picture of your digital life.
And unlike the websites you visit, which can be blocked or avoided, you can't really opt out of your ISP seeing your traffic. Not without help, anyway.
What ISPs Are Legally Allowed to Collect
Let's start with the regulatory landscape, because it explains a lot about why this problem exists.
In 2016, the FCC under the Obama administration passed broadband privacy rules that would have required ISPs to get explicit consent before collecting and sharing customer data. The rules never took effect. In March 2017, Congress voted to repeal them before they were implemented, and President Trump signed the repeal into law.
That repeal didn't create new surveillance powers — it removed the rules that would have limited existing ones. ISPs had always been able to collect this data. The 2016 rules would have restricted that. The 2017 repeal made sure those restrictions never happened.
More recently, the FCC under the Biden administration attempted to restore some of those protections and reclassify broadband as a Title II telecommunications service (which would subject ISPs to stricter oversight). That effort faced legal and political headwinds, and under the current regulatory environment, ISPs continue to operate with significant latitude over customer data.
So what does that actually mean for you?
The Specific Data Your ISP Can See
Here's what your internet provider can observe and potentially sell:
DNS queries. Every time you type a website address, your device sends a DNS request to translate that address into an IP. Unless you're using encrypted DNS, that request goes through your ISP's servers — giving them a running log of every domain you've looked up.
Unencrypted HTTP traffic. Any website that still uses plain HTTP (not HTTPS) is fully readable to your ISP. They can see the full content of those pages. The good news is that most major websites now use HTTPS. The bad news is that plenty of smaller ones still don't.
Connection metadata. Even for HTTPS sites, your ISP can see which IP addresses you're connecting to and when. They might not be able to read the content of your Amazon order, but they can see that you connected to Amazon's servers at 11 PM on a Tuesday.
App traffic patterns. Streaming Netflix? Your ISP knows. Gaming on PlayStation Network? They know that too. The metadata around your app usage builds a surprisingly detailed profile of your habits and interests.
Location data. Mobile ISPs can tie your data activity to your physical location. This is part of why mobile carrier data is so valuable to data brokers.
How That Data Gets Monetized
ISPs don't just collect this data for fun. There's real money in it.
AT&T has run programs allowing advertisers to target customers based on browsing behavior. Verizon was fined $1.35 million by the FCC in 2016 for using so-called "supercookies" — tracking identifiers inserted into customer traffic without consent — to enable targeted advertising. Comcast's Xfinity has offered lower-priced internet tiers in exchange for customers consenting to data collection and targeted ads.
Data brokers are also in the mix. ISPs can legally sell aggregate and sometimes individual data to third-party data brokers, who combine it with information from other sources to build the kind of comprehensive consumer profiles that power the modern ad economy.
How to Tell If You're Being Tracked
The honest answer is that it's difficult to catch your ISP in the act, because the data collection happens at the infrastructure level, not on your device. But there are some indicators worth looking for:
- Check your ISP's privacy policy. Look specifically for language about "sharing with third parties," "marketing partners," or "interest-based advertising." If those phrases appear, your data is likely being used commercially.
- Look for opt-out options. Some ISPs bury opt-out mechanisms deep in their account settings or privacy dashboards. AT&T, Verizon, and Comcast all have some form of advertising opt-out — it's rarely prominently advertised, but it exists.
- Monitor for targeted ads that seem suspiciously accurate. If you're seeing ads for things you researched at home that don't appear in your browser history or social media activity, your ISP data may be in the mix.
Practical Steps to Limit What Your ISP Sees
This is where things get actionable.
Use a VPN — but understand what it actually does. A VPN encrypts your traffic before it leaves your device, which means your ISP sees only that you're connected to a VPN server. They can't see which sites you're visiting or what you're doing. This is probably the single most effective technical countermeasure available to regular users. Free VPN options exist and can work well for basic ISP traffic shielding, though premium services generally offer more reliable performance and stronger no-log policies.
Switch to encrypted DNS. Even without a full VPN, switching from your ISP's default DNS servers to an encrypted DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) provider like Cloudflare (1.1.1.1) or NextDNS cuts off your ISP's view of your DNS queries. Firefox and Chrome both support DoH natively in their settings.
Use HTTPS everywhere. Modern browsers default to HTTPS where available, but browser extensions like HTTPS Everywhere (now largely built into browsers) can enforce this more aggressively.
Opt out of ISP advertising programs. It won't stop data collection, but it limits how that data is used commercially. Log into your ISP account and look for privacy or advertising settings. Comcast's opt-out is at xfinity.com/privacy, AT&T's is in your myAT&T account settings, and Verizon's is accessible through your My Verizon account.
Consider a router-level VPN. For households with multiple devices, configuring your VPN at the router level means every device on your network is protected automatically — including smart TVs, gaming consoles, and IoT devices that can't run VPN software themselves.
The Bigger Picture
The ISP data problem is a structural one. Until federal privacy legislation catches up — and there are ongoing conversations in Congress about a national privacy law, though nothing comprehensive has passed yet — your ISP operates in a largely permissive regulatory environment.
That doesn't mean you're helpless. The combination of a trustworthy VPN, encrypted DNS, and proactive opt-outs puts a significant dent in what your provider can observe and monetize. It's not a perfect solution, but it's a meaningful one.
Your internet connection is a product you're paying for. It's worth making sure you're not also paying with your data.