Can ISP sell your data: 2026 Guide

Can ISP sell your data: 2026 Guide

Elena Ross
April 23, 2026· 7 min read

Can your ISP sell your data is a question without one global answer. It depends on the laws where you live, your provider's privacy policy, the type of data involved, and whether "selling" is described as sharing, transferring, advertising cooperation, or aggregated analytics.

One point is clear: an ISP sits at the entrance to your network connection, so it can naturally see more connection information than an ordinary website. A 2021 FTC report said many ISPs collect and share data beyond what consumers expect, including internet traffic and real-time location data, while giving consumers limited ways to restrict that use.[1]

If you first want to understand what an ISP can see, read what your ISP can see in your browsing history.

If you want to see how ISPs, websites, advertisers, and data brokers fit together, start with our complete digital privacy guide for 2026.

Key Takeaways

  • Whether an ISP can sell or share data depends on local law and its privacy policy.
  • Even when a provider says it does not sell personal information, it may still use data for ads, partners, or aggregated reports.
  • HTTPS hides page content, but an ISP may still see domains, connection times, traffic volume, and network device information.
  • A VPN can reduce what your ISP sees about destination sites, but it does not make you anonymous to every service.

What can an ISP usually see?

Without a VPN, your ISP may be able to see:

  • which IP addresses or domains you connect to;
  • connection times and durations;
  • the amount of data transferred;
  • device and network identifiers;
  • DNS queries;
  • rough location or cell tower information;
  • unencrypted HTTP page content.

If a site uses HTTPS, your provider usually cannot see the exact page content, form passwords, or shopping cart details, but it can still see a lot of metadata.

Information typeCan HTTPS hide it?Can a VPN reduce ISP visibility?
Page bodyUsuallyYes
Login passwordUsuallyYes
Visited domainNot completelyUsually
Connection timeNoISP still sees you connected to a VPN
Traffic volumeNoISP still sees total traffic

Do ISPs really sell data?

A more accurate question is whether providers collect, share, transfer, or monetize data through advertising.

The FTC's study of several U.S. ISPs found practices that included cross-service collection, location data use, advertising, and third-party sharing. It also found that users had a hard time understanding or limiting those practices.[1]

So even if a policy says it does not sell personally identifiable information, keep reading for:

  • sharing with affiliates;
  • targeted advertising use;
  • sale of aggregated or de-identified reports;
  • third-party partner use;
  • location data used for marketing;
  • opt-out choices that are disabled by default or hard to find.

How do U.S., EU, and China rules differ?

United States

The United States does not have one single federal privacy law covering all ISP data use. The FTC report specifically criticized ISP data collection and the lack of meaningful user choice.[1]

That means users have to consider state law, provider policy, FTC enforcement, and the specific service terms together.

European Union

The EU's GDPR requires a lawful basis for processing personal data and emphasizes data minimization, purpose limitation, and transparency.[2] That puts stronger constraints on how ISPs process and share personal data.

China

China's Personal Information Protection Law requires personal information processing to have a clear and reasonable purpose and to stay within the minimum scope needed for that purpose. Sensitive personal information is subject to stricter conditions.[3]

For ordinary users, the practical steps remain the same: read the privacy policy, reduce unnecessary permissions, encrypt connections, and avoid tying too much identity to one place.

What is ISP data used for?

Common uses include:

  • network operations and troubleshooting;
  • billing and customer support;
  • security and fraud prevention;
  • advertising;
  • audience profiling;
  • location analytics;
  • sharing with partners;
  • responding to legal requests.

Not every use is the same as "selling data." From a privacy perspective, the core questions are whether you knew, whether you can refuse, and whether you have a real alternative.


How can you reduce the data your ISP can see?

1. Use HTTPS websites

HTTPS is the baseline. Do not enter passwords, identity numbers, bank cards, or admin information on HTTP sites.

2. Use a trustworthy VPN

A VPN encrypts your network connection to the VPN server, making it harder for your ISP to directly see the exact sites you visit.

But remember: the VPN provider becomes a new trusted party. Choose a service with a clear no-logs policy and transparent privacy documentation.

3. Use encrypted DNS

DoH or DoT can reduce exposure from plaintext DNS queries. Without a VPN, however, an ISP may still infer destinations from connection IPs, SNI, and other signals.

4. Turn off ISP ad personalization

Log in to your provider account and look for:

  • privacy settings;
  • ad preferences;
  • location data sharing;
  • CPNI or marketing permissions;
  • data sale or sharing opt-outs.

The FCC also reminds broadband users to review provider privacy policies to understand how ISPs collect, use, and share information.[4]

5. Avoid tying identity too tightly to network behavior

Separate email aliases, fewer unnecessary real-name registrations, cleaned-up ad IDs, and tighter app permissions can all reduce cross-platform profiling.

Can a VPN stop your ISP from selling your data?

It can reduce some data sources, but it cannot make your ISP know nothing.

After you use a VPN, your ISP can still see:

  • that you connected to a VPN server;
  • connection time;
  • total traffic volume;
  • your billing and account information;
  • cell tower and plan information on mobile networks.

It becomes harder for the ISP to directly see:

  • the exact websites you visit;
  • unencrypted DNS queries;
  • specific page paths;
  • page content.

Summary

  • Whether an ISP can sell data depends on law, policy, and data type.
  • Even "no sale" language may still allow sharing, advertising, aggregated analytics, and affiliate use.
  • HTTPS protects content, while a VPN reduces ISP visibility into destination sites.
  • Check privacy settings inside your provider account; defaults may not favor users.
  • Do not treat a VPN as a universal anonymity tool. It is one layer for reducing ISP visibility.

FAQ

Can my ISP see the exact pages I browse?

If a site uses HTTPS, it usually cannot see the exact page content or passwords. It may still see domains, connection times, traffic volume, and other metadata.

Does private browsing stop ISP tracking?

No. Private browsing mainly affects local browser history. It does not stop your ISP from seeing network connections.

Does a VPN make me completely invisible to my ISP?

No. Your ISP still knows you are using the network, that you connected to a VPN server, and the total amount of traffic.

Can a free VPN protect me from ISP tracking?

Be careful. Free VPNs may monetize through ads, data analytics, or bandwidth resale. Review the privacy policy and business model before trusting one.

What is the difference between encrypted DNS and a VPN?

Encrypted DNS mainly protects domain lookups. A VPN encrypts a broader network path. They can complement each other, but they are not the same tool.

How are ISP data sales related to data brokers?

ISPs may connect directly or indirectly with ad tech, analytics, or data broker ecosystems. You can continue with what a data broker is.


Disclaimer This article provides general privacy information and does not constitute legal advice. Rules on ISP data processing, VPN use, and personal information protection vary by country and region.

AethoVPN supports the VPN substep in “Can ISP sell your data: 2026 Guide”; service and account rules still apply.

Sources

[1]FTC ISP Privacy Staff Report [2]GDPR Article 5 Principles [3]中国个人信息保护法 [4]FCC Broadband Consumer Privacy

Sources checked 8 May 2026.


Related Articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

Can ISP sell your data: 2026 Guide | AethoVPN