Is Your ISP Selling Your Browsing Data? What Legal Really Means
Most people hear “your ISP can sell your browsing history” and picture a spreadsheet with every page they visited, neatly labeled with their name. The real answer is messier than that. It is also still worth caring about.
Your internet service provider sits at the first hop between your device and the rest of the internet. That means it can see a lot of connection data before any website, app, or ad network gets involved.
HTTPS changed the old scary version of this story. Your ISP usually cannot read the contents of a secure page. It should not see the exact article you read, the password you typed, or the checkout form you filled out on a site using HTTPS.
But “cannot read the page” is not the same as “knows nothing.”
What your ISP can still see
Even with HTTPS everywhere, your ISP can often see the domain names you connect to, when you connect, how long the session lasts, roughly how much data moves, and which device or account is tied to the connection.
That sounds boring until you think about patterns. A domain list can reveal which bank you use, which health site you visit, which messaging app opens every morning, which streaming service runs at night, and which work tools your house depends on.
DNS can add more detail if it is not encrypted. DNS is the lookup your device makes when it turns a name like example.com into an IP address. If those lookups go through your ISP, they can become a pretty readable map of your day.
The Federal Trade Commission has already said the quiet part out loud. In a 2021 staff report, the FTC found that many internet service providers collect large amounts of personal data, combine it across product lines, use browsing and app data for ad targeting, and often give users limited choices to restrict that use.
So is selling it legal?
In the United States, there is no single simple federal privacy law that says, “your ISP may never monetize browsing-related data.” The FCC had broadband privacy rules that would have required clearer opt-in consent for sensitive data, including web browsing and app usage history. Congress repealed those rules in 2017 before they fully took effect.
That does not mean ISPs can do anything they want. The FTC can still go after unfair or deceptive privacy practices. State privacy laws may give you rights to opt out of some targeted advertising or data sales. Company privacy policies still matter because misleading promises can create legal risk.
But the practical point is this: the default system is not built around minimizing what your ISP learns. It is built around providing internet access, running a network, selling bundles, measuring behavior, and in many cases advertising.
Where a VPN helps
A VPN changes what your ISP sees at the first hop. Instead of seeing separate connections to lots of domains, your ISP sees encrypted traffic going to one VPN server. The websites you visit then see the VPN server’s IP address instead of your home IP address.
That does not make you anonymous. You can still log into accounts. Websites can still use cookies. Apps can still collect data inside their own systems. A VPN is not a magic privacy force field.
It does solve one simple problem: it stops your ISP and local network from getting an easy, readable list of where your device is connecting.
For normal people, that is the win. You are not trying to disappear from the internet. You are trying to reduce how much one company can learn just because it happens to provide the pipe into your house.
If you want that basic first-hop privacy without paying streaming-service prices, 99¢ VPN is $11.88/year for one WireGuard device. Turn it on, leave it on, and make your ISP’s view of your browsing a lot less useful.
Written by the person who runs 99¢ VPN. Not legal advice. Just the plain-English version of what your ISP can see and why a VPN still helps.