Can Your ISP Still Sell Your Browsing Data in 2026?
Short answer: in the US, your internet provider can still learn a lot about your browsing, and the rules around how that data gets used are weaker than most people assume.
This is one of those privacy topics that sounds dramatic until you look at the boring legal history. In 2017, Congress overturned FCC privacy rules that would have required internet service providers to get clear opt-in permission before using or sharing sensitive browsing information. NPR and CNBC covered it at the time because it changed who had to ask before turning your internet habits into ad data.
That does not mean every ISP is printing out your browser history and selling it by name. It does mean the default protection is not as simple as "my internet company is not allowed to track me." The real answer depends on what data is collected, how it is packaged, what state you live in, and what the provider says in its privacy policy.
What your ISP can actually see
HTTPS made the web much safer. When you visit a secure site, your ISP usually cannot read the exact page contents, your password, or the message you typed into a form.
But your ISP can still see useful metadata. That includes the IP addresses you connect to, the timing of your activity, how much data moves, and often the domains you request through DNS unless you use encrypted DNS. Even without seeing the page text, patterns can say a lot.
A search for a hospital, then a specialist clinic, then an insurance portal tells a story. A few visits to job boards during work hours tells another. That is why the FTC's 2021 staff report on major ISPs mattered: it found that many providers collect large amounts of personal data, including web browsing data, and may combine it with other information for advertising and profiling.
What "selling browsing data" usually means
When people say ISPs sell browsing history, they often picture a spreadsheet with your name and every site you visited. The ad business is usually messier and more indirect than that.
Data may be grouped, inferred, anonymized, aggregated, or used to place you into ad categories. That can still be invasive. If a company can label someone as interested in debt help, fertility clinics, political content, gambling, or a medical condition, the privacy problem is not solved just because the raw URL list is not sitting in a public file.
Some states have stronger privacy laws than others. Some providers offer opt-outs. Some promises are buried in privacy policies that take patience to read. The point is simple: your ISP sits at the front door of your internet connection, so it has a privileged view.
Where a VPN helps
A VPN changes the first hop. Instead of your ISP seeing a long list of sites and services, it sees an encrypted connection to the VPN server. The websites you visit see the VPN server's IP address instead of your home IP.
That does not make you anonymous. You can still log into Google, Facebook, Amazon, your bank, or anything else. Those companies still know it is you. A VPN also does not fix bad browser privacy settings or stop every tracker on the web.
But it does reduce what your ISP can learn from your connection. That is the practical privacy win. You are moving trust away from the company that already sells you internet access and toward a VPN provider whose main job is to carry encrypted traffic.
If you want a simple option, 99¢ VPN is $11.88/year for one device. It uses WireGuard, takes a few minutes to set up, and keeps your ISP from getting the easy first-hop view of your browsing.
The bottom line: your ISP probably cannot read every secure page you open, but it can still learn more than most people think. If that makes you uncomfortable, a VPN is a reasonable, boring, low-cost layer to add.
Written by the person who runs 99¢ VPN. Not legal advice. Just the plain-English version of how ISP privacy works.