Is Your ISP Selling Your Browsing Data?
Your internet provider sits in a weirdly powerful spot. Every time your phone, laptop, TV, or game console goes online, that traffic starts by passing through them.
That does not mean an employee is sitting there reading your Gmail. Most modern websites use HTTPS, so the contents of the page are encrypted. But your ISP can still see a lot: the domains you connect to, when you connect, how much data moves, what device is talking, and patterns that say more than you think.
So the uncomfortable question is fair: can your ISP sell your browsing data?
The short answer
In the United States, the answer is basically: they can collect a lot, they can use a lot, and the rules are patchy.
In 2016, the FCC approved broadband privacy rules that would have required internet providers to get opt-in consent before using or sharing sensitive data like precise location, financial information, health information, and web browsing history. In 2017, Congress and the president wiped those rules out before they took effect.
That does not mean ISPs have no limits at all. The FTC can still go after companies for unfair or deceptive practices. Some states have their own privacy laws. Providers also have privacy policies that say what they collect and share.
But that is the problem. You are mostly relying on a mix of policy language, enforcement after the fact, and state-by-state protection. That is not the same as a simple national rule that says, “do not sell my browsing history without asking me first.”
What your ISP can actually know
The FTC looked at major internet providers and said many of them collect “troves” of personal data. That includes browsing information, app usage, location data, device data, and demographic information. Some providers also combine that with data from advertising networks, data brokers, TV viewing, mobile service, and smart home products.
Even when HTTPS hides the exact page, the domain still matters. Visiting bankofamerica.com, plannedparenthood.org, reddit.com, or a job search site says something. The timing says something. Repeated patterns say something.
And because your ISP is the company that connects your home to the internet, switching is not always easy. In a lot of neighborhoods, you have one or two realistic options. That makes “just choose a privacy-friendly provider” pretty weak advice.
What a VPN changes
A VPN does not make you invisible. It does not erase tracking cookies. It does not stop Google, Meta, Amazon, or the sites you log into from knowing what you do on their services.
What it does is simple: it moves the first hop of trust away from your ISP.
When your VPN is on, your ISP sees an encrypted connection to the VPN server. It can see that you are online. It can see how much data is moving. But it no longer gets the easy list of domains your device is contacting through normal DNS and browsing traffic.
That is useful at home, and it is even more useful on public WiFi, hotels, airports, and shared networks. You are not trying to become a spy. You are just closing a data leak that most people forget exists.
The best version of this is boring. Turn it on, leave it on, and stop giving your internet provider a clean window into your browsing habits.
If you want a simple option, 99¢ VPN is $11.88/year for one device. It uses WireGuard, takes a couple minutes to set up, and keeps your ISP from seeing the sites you visit through the tunnel.
Your ISP is not automatically evil. But it is in a position to see more than most companies, and US privacy law still leaves too much of that relationship up to fine print.
A VPN is not a complete privacy plan. It is one practical layer. It keeps your provider from turning your browsing habits into an easy product.
Written by the person who runs 99¢ VPN. Sources checked include the FTC staff report on ISP data collection, FCC broadband privacy history, and state broadband privacy summaries.