July 23, 2026 · 4 min read

Can Your ISP Sell Your Browsing Data? The Plain-English Answer

Short answer: in the United States, your internet provider has more room to use browsing-related data than most people expect. The exact rules depend on what data we are talking about, where you live, and how your ISP writes its privacy policy.

That is the annoying legal answer. The practical answer is simpler: your ISP sits between your house and the internet. Unless you change that first hop, it can learn a lot from the traffic leaving your modem.

This does not mean your provider is reading your private messages like an open book. HTTPS protects the contents of most modern websites. But HTTPS does not hide everything.

What your ISP can usually see

Your ISP can normally see that your connection reached a domain, when it happened, how much data moved, and which device or account was tied to that connection. If your DNS requests are not encrypted, those can be visible too.

That creates a pretty detailed pattern. Maybe not the exact article you read, but the fact that you visited a bank, a medical site, a job board, a betting site, a political forum, or a streaming service. Over weeks or months, patterns are the point.

That kind of data can be used for network management, security, billing, analytics, advertising, or sharing with partners depending on the provider and the law that applies. Some data may be aggregated or de-identified. Some may still be personal enough to make people uncomfortable.

Why people still talk about the 2017 repeal

In 2016, the FCC approved broadband privacy rules that would have required internet providers to get stronger consent before using or sharing sensitive customer information. In 2017, Congress and the President rolled those rules back before they took effect.

That repeal is why you still see headlines saying ISPs can sell browsing history. The reality is a little less clean than the headline, but the concern is real: broadband providers have a broader view of your internet activity than a single website or app.

There are still limits. General consumer protection rules, state privacy laws, telecom privacy rules, contract promises, and privacy policies all matter. California's CCPA, for example, gives many consumers the right to opt out of sale or sharing of personal information. Other states have their own privacy laws too.

Plain-English rule: privacy laws can give you rights after data is collected. A VPN changes what your ISP can see in the first place.

What a VPN changes

When you use a VPN, your ISP sees an encrypted connection to the VPN server. It can still see that you are online. It can still see timing and total data volume. It can still see that you are using a VPN.

But it should not see the individual websites and apps inside that tunnel. Your DNS requests can go through the VPN too, which closes one of the easiest ways to build a browsing profile.

A VPN does not make you invisible. The VPN provider becomes the party handling that first hop, so you still need one with a clear privacy policy and a business model that makes sense. It also does not stop websites from tracking you with logins, cookies, browser fingerprinting, or ad pixels.

Still, for normal people, it is a useful shift. Your home ISP no longer gets the easy list of where your traffic is going. Coffee shop WiFi does not get it either. Hotel networks, airport WiFi, and campus networks see less too.

If you want the simple version without paying big-VPN prices, 99¢ VPN is $11.88/year for one WireGuard device. It is built for people who just want their connection encrypted without a giant bundle.

The bottom line: your ISP probably cannot read every page you open, but it can still learn plenty from the connection itself. A VPN is not a magic privacy shield. It is just a practical way to stop your internet provider from being the default observer of your browsing patterns.


Written by the person who runs 99¢ VPN. Not legal advice. Just a plain-English read on ISP privacy and what a VPN actually changes.