July 5, 2026 · 4 min read

Can Your ISP Legally Sell Your Browsing Data?

The short answer is uncomfortable: in the US, your internet provider can collect a lot of information about your connection, and the privacy rules are not as simple as most people assume.

That does not mean your ISP is printing out your browser history and handing it to a random advertiser. It does mean the company that connects you to the internet is sitting in a very useful spot. It can see your account, your home address, your device connection, your IP address, the times you are online, and many of the domains your devices talk to.

HTTPS hides the actual page contents on most modern sites. Your ISP should not see the exact article you read or the password you typed into your bank. But it may still see that you connected to a bank, a medical site, a political site, a shopping site, or an app service. Patterns add up.

What changed with the ISP privacy rules

In 2016, the FCC approved broadband privacy rules that would have required internet providers to get clearer consent before using or sharing sensitive customer information, including browsing history. Those rules were rolled back by Congress in 2017 before they fully took effect.

That repeal is why this topic still feels confusing. A lot of people heard, "ISPs can sell your browsing history now," which is a little too simple. The more accurate version is: there is no broad federal opt-in rule that treats ISP browsing history the way the 2016 FCC rule would have.

The FTC can still police unfair or deceptive practices. State privacy laws can add rights for some people. ISPs still have privacy policies. But that is not the same as saying your browsing metadata is automatically off limits.

What your ISP can learn

The FTC's own staff report on major internet providers found that many ISPs collect large amounts of personal data, and that users often have limited ways to restrict how it is used. That included web browsing data, app usage data, location data in mobile contexts, and advertising segments based on sensitive traits.

In plain English, your ISP may be able to build a picture like this:

That is not always the same as "selling your browser history" in the scary headline sense. But it is still personal. And once data becomes an advertising profile, it can move far away from the simple internet bill you thought you were paying.

What a VPN changes

A VPN changes the first hop of trust. Instead of your ISP seeing every domain your device contacts, it sees an encrypted connection to a VPN server. The websites you visit see the VPN server's IP address instead of your home IP.

That does not make you invisible. You can still log into Google, Instagram, Amazon, or your bank, and those services know it is you. A VPN also does not fix bad browser tracking, sketchy apps, or oversharing on social media.

But it does reduce what your internet provider can learn from your connection. It turns a detailed map of your traffic into something much less useful: encrypted traffic going to one VPN endpoint.

If that is the main thing you want, you do not need a giant security bundle. You need a simple VPN that you can leave on without thinking about it. 99¢ VPN is $11.88 for a year, uses WireGuard, and is built for that basic job: making your ISP and local network see less.

The practical rule is simple. Assume your ISP can learn more than you would casually tell a stranger. Use HTTPS, keep your apps updated, and use a VPN when you do not want your internet provider turning your connection into a profile.


Written by the person who runs 99¢ VPN. Not legal advice. Just the plain-English version of why your internet provider is not the same thing as a private tunnel.