Your Gateway, Their Gold Mine: How ISPs Are Profiting From Every Website You Visit
There is a quiet irony embedded in the way most Americans think about online privacy. Millions of people install ad blockers, clear their cookies, and meticulously manage app permissions on their smartphones — all while their internet service provider watches every packet of data flow through its pipes with virtually unimpeded visibility. The ISP is not a passive conduit. For the major carriers operating in the United States, the network itself has become a revenue-generating intelligence platform.
Understanding how that platform operates — and why existing regulations have failed to neutralize it — is essential for anyone serious about digital privacy in 2024.
The Structural Advantage No App Can Match
When you open a browser, launch a streaming service, or send a message, that traffic must first traverse your ISP's infrastructure. Unlike a website that only sees what you do on its own domain, or a social media platform that only tracks behavior within its walled garden, the ISP sees the full picture: every domain you query, every server your device contacts, and the timing and frequency of those connections.
This positional advantage is not theoretical. AT&T, Verizon, Comcast, and other major carriers have developed sophisticated data analytics divisions that transform raw traffic logs into structured behavioral profiles. These profiles can indicate political affiliation, health concerns, financial stress, religious practice, and purchasing intent — derived not from anything you explicitly shared, but from the aggregate pattern of domains your devices contacted over weeks and months.
Critically, this surveillance extends to every device connected to your home network. Your smart television, your children's tablets, your security cameras — all of them contribute to the behavioral dataset your ISP assembles under your account.
What the 2017 Regulatory Rollback Actually Meant
In 2016, the Federal Communications Commission under the Obama administration finalized broadband privacy rules that would have required ISPs to obtain opt-in consent before selling sensitive customer data, including browsing history. The rules never took effect. In March 2017, Congress voted to nullify them under the Congressional Review Act, and President Trump signed the repeal into law.
The practical consequence was significant: ISPs became subject to the Federal Trade Commission's comparatively weaker framework rather than the FCC's sector-specific rules. The FTC operates primarily through after-the-fact enforcement against deceptive or unfair practices — it does not establish proactive consent requirements for data collection. For ISPs, this means that detailed disclosures buried in service agreements can legally authorize the collection and commercial use of browsing data that most customers would never knowingly approve.
The FCC under the Biden administration attempted to restore broadband privacy protections, proposing new rules in 2023. Those proposals remained contested and incompletely implemented, leaving a durable regulatory gap that carriers have shown little inclination to voluntarily close.
The Data Broker Pipeline
ISP-derived data does not simply remain within the carrier's own advertising systems. A well-documented pipeline connects major telecoms to the broader data-brokerage industry, where behavioral profiles are aggregated, repackaged, and sold to marketers, insurers, political campaigns, and — in documented cases — law enforcement agencies operating without warrants.
Companies such as Verizon's Precision Market Insights division and AT&T's former Data Patterns analytics program have illustrated how directly carriers can convert network visibility into commercial products. Third-party data brokers then layer ISP-sourced intelligence on top of purchase history, location data, and social media signals, producing profiles of remarkable granularity.
For the average American household, this means that the same company billing them $80 a month for internet access may simultaneously be generating additional revenue by licensing intelligence derived from that household's online behavior to parties the customer has never interacted with and cannot identify.
Why DNS Privacy Is Not a Complete Solution
A common recommendation in privacy circles is to switch from your ISP's default DNS resolver to a privacy-focused alternative such as Cloudflare's 1.1.1.1 or the DNS-over-HTTPS service offered by NextDNS. These services encrypt DNS queries so that your ISP cannot read the specific domain names you are resolving.
This is a meaningful improvement, but it addresses only one layer of a multi-layer problem. Even with encrypted DNS, your ISP can still observe the IP addresses your device contacts. Because many major websites and content delivery networks use dedicated IP ranges, correlating IP-level traffic with domain names remains technically feasible for a carrier with sufficient analytical resources. Additionally, the Server Name Indication field in TLS handshakes has historically exposed destination hostnames even over encrypted connections — a problem that Encrypted Client Hello is designed to address but that is not yet universally deployed.
Privacy-focused DNS reduces ISP visibility but does not eliminate it.
VPNs: Genuine Protection With Real Limitations
A properly configured virtual private network is currently the most effective consumer-grade tool for limiting ISP surveillance. By routing all traffic through an encrypted tunnel to a VPN server, you replace your ISP's view of your browsing destinations with an opaque stream of encrypted data directed at a single IP address — the VPN endpoint.
However, several caveats apply. First, the VPN provider itself now occupies the privileged surveillance position your ISP previously held. Selecting a provider with a verified no-logs policy — ideally one that has undergone independent third-party audits — is essential. Providers based outside US jurisdiction and not subject to National Security Letters or FISA orders offer additional structural protections, though no arrangement is entirely immune to legal compulsion.
Second, VPN protection is only as strong as its consistent use. Many users disable VPNs for streaming services or when experiencing performance issues, creating gaps in coverage that ISPs can log. Split-tunneling configurations that exempt certain applications from the VPN tunnel can inadvertently expose traffic that users assume is protected.
Third, VPNs do not address data already collected. If your ISP has been logging your traffic for months prior to VPN adoption, that historical dataset persists.
Practical Steps for US Readers
Given the regulatory environment and the technical realities described above, a layered approach to ISP privacy is more effective than any single measure.
Begin by selecting a reputable, audited VPN provider and configuring it at the router level rather than on individual devices — this ensures all household traffic, including smart-home devices that do not support VPN clients, is routed through the encrypted tunnel. Pair this with a privacy-focused DNS-over-HTTPS resolver as a secondary measure.
Review your ISP's privacy policy and opt out of any data-sharing programs it discloses. Carriers are required to offer some level of opt-out for non-sensitive data sharing; these mechanisms are typically obscured within account dashboards, but they exist. Document when you submitted opt-out requests.
Consider filing comments with the FCC during open rulemaking periods on broadband privacy. Regulatory outcomes in this space are genuinely responsive to demonstrated public interest, and the current framework remains subject to revision.
Finally, support legislative efforts at the state level. Several states, including California, have enacted consumer privacy frameworks that impose stricter requirements on data brokers than federal law currently demands. These state-level protections, while imperfect, represent the most active frontier of ISP accountability in the current political environment.
The Surveillance You Pay For
The relationship between American consumers and their internet providers has always involved an implicit exchange: reliable connectivity in return for a monthly fee. What has changed is that the fee now subsidizes a secondary business model that most customers do not know they are funding.
The ISP is not merely the road your data travels — it is, increasingly, the tollbooth operator recording every destination on your itinerary and selling that record to the highest bidder. Until federal privacy legislation establishes enforceable opt-in consent requirements for sensitive data, the burden of limiting that exposure falls on individual users who are willing to invest in the tools and knowledge required to push back.