Can Your ISP Still Sell Your Browsing Data?
Your internet provider sits in a weirdly powerful spot. Before your traffic reaches a website, an app, or a VPN server, it goes through the company you pay for access. That means your ISP can learn more from your connection than most people expect.
That does not mean someone at the cable company is reading your Gmail. Most major sites use HTTPS, so the contents of a page are usually encrypted. But privacy is not only about page contents. Domains, DNS lookups, device identifiers, location data, app usage, timing, and traffic patterns can still say a lot.
The Federal Trade Commission said as much in its ISP privacy report. It found that many internet providers collect and share large amounts of personal data, sometimes combining browsing data, app usage, location data, and advertising profiles across different parts of their business.
The short legal answer
In the US, the clean federal rule people often imagine does not really exist anymore. The FCC passed broadband privacy rules in 2016 that would have required ISPs to get stronger permission before using or sharing sensitive customer information. Congress repealed those rules in 2017 before they fully took effect.
So the answer is not a simple “yes, they can sell everything” or “no, they cannot sell anything.” It is messier. ISPs still have privacy obligations. The FTC can go after unfair or deceptive practices. State privacy laws can give you rights to access, delete, or opt out of certain data sales. California’s privacy law, for example, can cover broadband providers if they meet the law’s business thresholds.
But for a normal person trying to browse privately, the practical takeaway is simple: your ISP may be allowed to collect, use, share, or monetize more connection data than you would choose if you were asked clearly.
What your ISP can usually see
Even with HTTPS, your provider can often see:
- The sites and services you connect to. HTTPS hides the page content, not always the fact that you visited a domain.
- DNS requests. If your DNS is not encrypted or routed through a VPN, those lookups can reveal the websites your device asks for.
- Timing and volume. A provider can see when you are online, how much data you move, and what kinds of patterns your connection has.
- Location and account data. Mobile providers and home ISPs already know where service is delivered and which account is attached to it.
That data can be valuable for advertising, analytics, fraud scoring, market research, and “personalization.” The annoying part is that the privacy choices are usually buried in account portals and long policy pages.
Where a VPN helps
A VPN does not erase your online life. You still log into accounts. Websites can still track you with cookies, pixels, and account history. If you sign into YouTube, YouTube knows it is you.
What a VPN changes is what your ISP sees. Instead of seeing a long list of sites and services your device connects to, your provider sees an encrypted connection to one VPN server. Your DNS requests can go through that tunnel too, which makes the local network and ISP view much less useful.
That is the real value. Not magic invisibility. Not spy-movie anonymity. Just moving the first hop of trust away from the company that already knows your name, address, billing history, and connection habits.
If you want a cheap, simple way to do that, 99¢ VPN gives you WireGuard for one device at $11.88/year. No giant bundle. No “limited-time” renewal game. Just an encrypted tunnel between your device and the open internet.
The bottom line: your ISP probably cannot see every word you read online. But it can still see enough metadata to build a pretty good picture. If that feels like too much, a VPN is one of the simplest ways to make that picture blurrier.
Written by the person who runs 99¢ VPN. Not a lawyer. Just someone who thinks basic network privacy should be cheap and understandable.