ISP Browsing Data in 2026: What “Legal” Does Not Tell You
People often ask a very direct question: can my internet provider sell my browsing history?
The honest answer is less tidy than a yes or no. Rules depend on where you live, which provider you use, what data is involved, and whether the provider is acting directly or sharing data through an advertising partner. But there is a simpler point worth keeping in mind: your ISP sits between your device and the internet. That position gives it useful information about your connection.
HTTPS helps, but it does not make the connection invisible
Most websites now use HTTPS. That is good. It means your ISP generally cannot read the contents of a secure page, such as the message you type into a form or the article you are reading.
It can still see other clues. Depending on your setup, those can include the sites or services your device connects to, the time of a connection, the amount of data moved, your IP address, and rough location information tied to the account. A single clue is not always meaningful. A long pattern can be.
This is why “they cannot see the page” is not the same as “they cannot learn anything.” The FTC's report on major ISPs describes providers as gateways that can collect locational, behavioral, and usage data. That does not mean every provider uses every kind of data in the same way. It does mean the privacy policy is worth reading.
Why the legal answer varies
In the US, federal broadband privacy rules adopted by the FCC in 2016 were repealed before they took effect. Since then, consumer protections have been a mix of general federal enforcement, sector-specific rules, provider policies, and state laws. There is no single, plain nationwide rule that makes every browsing-data practice easy to understand.
Some state laws give people stronger rights. California residents, for example, can ask covered businesses to stop selling or sharing personal information and can use a Global Privacy Control signal in supported browsers. Those rights matter, but they are not a substitute for checking the policy that applies to your account.
Look for clear answers to three questions: what does the provider collect, who can receive it, and how can you opt out or delete it? If the policy uses broad phrases such as “service improvement” or “partners” without explaining the data involved, slow down.
What a VPN changes, and what it does not
A VPN encrypts traffic between your device and the VPN server. Your ISP can still see that you are connected to a VPN and how much data is moving, but it has less visibility into the destinations your traffic reaches after that encrypted first hop.
A VPN does not make you anonymous, erase data held by websites, or replace browser privacy settings. It also moves some trust to the VPN provider, which is why a specific no-log policy and a simple business model matter.
For everyday browsing, the practical approach is not complicated: use HTTPS, keep your software updated, review your ISP privacy controls, and use a VPN when you want to reduce what the local network and your ISP can learn from your connection. If you want a straightforward WireGuard setup, start with 99¢ VPN Basic.
Written by the person who runs 99¢ VPN. This is practical privacy guidance, not legal advice.