TL;DR
- A Colorado class action filed June 4, 2026 accuses credit bureau Equifax of listing the cell phone numbers of thousands of Colorado residents in its for-sale commercial directories without ever asking for permission.
- The lawsuit says this violates Colorado’s Prevention of Telemarketing Fraud Act, which since 2005 has banned knowingly listing a cell number in a commercial directory without the person’s affirmative consent.
- Equifax operates at least six products named in the suit that package and sell people’s phone numbers to paying business customers as part of its core data-broker model.
- The complaint argues the practice strips residents of both their statutory privacy rights and the real economic value of their own data, while exposing them to stalking, scams, and fraud targeting the elderly.
- Colorado law allows statutory damages of $300 to $1,000 per violation, and the class is described as at least thousands of people.
The complaint quotes a bill sponsor saying most people expect a ringing cell phone to be someone who matters; Equifax allegedly sold that expectation to anyone with a subscription.
Equifax Sold Coloradans’ Cell Numbers Without Ever Asking
Your cell phone number was supposed to be yours. In Colorado, the law has said so since 2005. A new class action alleges Equifax turned that private number into inventory and put it up for sale.
The Non-Financial Ledger
The harm here is quiet and invisible until it is not. According to the complaint, Robert Clark had no reasonable way to even discover that Equifax had listed his personal cell number in its commercial directories until shortly before he filed suit. His number was moving through a marketplace he never entered, sold to buyers he never met, by a company he had no relationship with.
The complaint frames this as the theft of an expectation. It quotes a bill sponsor describing how people treat their cell numbers: they hand them out to friends, family, and a few colleagues, and when the phone rings, they expect it to matter. That expectation is what the lawsuit says Equifax quietly dismantled for thousands of Coloradans at once.
The complaint stresses who absorbs the sharpest edge of this. It cites federal findings that the elderly are deliberately targeted by fraudulent telemarketers because they are often home, isolated, and holding cash reserves. Once a person is marked as receptive to one scam, the complaint notes, they get bombarded with more.
Legal Receipts
The complaint builds its case on the plain text of the statute and the words of the people who wrote it.
“On or after September 1, 2005, a person commits an unlawful telemarketing practice if the person knowingly: (I) Lists a cellular telephone number in a directory for a commercial purpose unless the person whose number has been listed has given affirmative consent, through written, oral, or electronic means, to such listing[.]”
- This is the exact prohibition Equifax is accused of breaking, and it sets a clear “knowingly” standard the complaint says Equifax meets because it identifies these numbers as belonging to Colorado residents.
- The rule requires affirmative consent up front; silence or the absence of an opt-out does not count.
“[M]ost people view their cell phones as private. They give out the number to friends and family and some colleagues. When their cell phone rings, they expect it to be important.”
- Attributed in the complaint to former State Representative Mark Cloer, a prime sponsor of the 2005 amendment, establishing the privacy purpose behind the law.
- It shows the legislature intended to protect exactly the kind of number Equifax allegedly sold.
“Defendant is literally selling Plaintiff’s and Class Members’ cell phone numbers and accompanying information to its customers.”
- The complaint asserts the conduct is not incidental to Equifax’s business; it is the business.
- This directly ties the alleged violation to Equifax’s revenue rather than to a stray error.
“[P]eople search products can be used to facilitate harassment, or even stalking, and may expose domestic violence victims, law enforcement officers, prosecutors, public officials, or other individuals to retaliation or other harm.”
- Drawn from the FTC’s 2014 Data Brokers report, this establishes the concrete physical danger the complaint attaches to the listings.
- It reframes the case from a technical privacy dispute into a documented safety risk.
Profit-Maximization at All Costs
The complaint’s central claim is that the alleged privacy violation is inseparable from how Equifax makes money. The company is described as a data broker whose entire model depends on packaging and reselling personal contact data.
- The complaint names at least six Equifax products that list Coloradans’ cell numbers: BusinessConnect for Marketing, Contact and Locate, Digital Identity Trust, FirstSearch, Marketing Identity Elements, and TargetPoint Alerts.
- Each product is described as sold through subscriptions, credits, or per-record charges, meaning every listed number is a unit of inventory that generates revenue.
- The complaint cites that consumer data feeds a $26 billion-per-year online advertising industry in the United States, and quotes the FTC that “data is currency.”
- The complaint says Equifax profits “handsomely” from the listings while doing so “at the expense of Coloradans’ statutory privacy rights.”
- Marketing Identity Elements is described as providing “raw consumer Personally Identifiable Information,” including current and prior phone numbers, addresses, dates of birth, and names.
Public Deception: Consent That Was Never Sought
The complaint’s core factual charge is a gap between what the law required and what Equifax did about consent.
- The statute requires affirmative consent through written, oral, or electronic means before listing a cell number for commercial purposes.
- The complaint states Equifax “never requests nor receives any consent whatsoever, affirmative or otherwise, to list cell phone numbers.”
- It alleges Equifax lists the numbers of Coloradans it “has never engaged with, has had no connection to, and who are unaware of its existence.”
Societal Impact Mapping
Public Health and Safety
The complaint links the alleged listings to concrete safety dangers drawn from federal and consumer-protection sources.
- People search products can facilitate harassment and stalking, and may expose domestic violence victims to retaliation, per the FTC report the complaint cites.
- Bundled, easily accessible personal data lets cybercriminals build detailed profiles to craft convincing scams and commit identity theft.
- The complaint says the elderly are the deliberate targets of fraudulent telemarketers because they are often home, reliant on delivery services, and lonely.
- Once a consumer is marked as receptive to one scam type, they are “bombarded with similar fraudulent offers from a host of scam artists.”
Economic Inequality
The complaint argues residents are stripped of the measurable market value of their own data while Equifax captures it.
- The complaint states the practice deprives residents “of the real, quantifiable value of such data.”
- It cites a 2014 Harris Interactive survey for TRUSTe finding 89 percent of consumers avoid businesses they believe do not protect their privacy.
- The same survey found 80 percent of smartphone users avoid apps they do not believe protect their privacy, underscoring the value people place on control of their data.
- The complaint notes companies now pay people to monetize their own data, establishing that this data has a real market price Equifax allegedly took for free.
The Cost of a Life Metric
The Settlement Isn’t Justice
No settlement exists yet; this is a freshly filed complaint. But its structure exposes why statutory damages exist in the first place.
- The complaint explains that each individual class member “may lack the resources to undergo the burden and expense of individual prosecution,” which is why a class mechanism is necessary at all.
- Colorado’s fixed statutory damages of $300 to $1,000 per offense exist precisely because the individual harm of a single listed number is hard to price and easy to ignore.
- The requested relief includes an injunction requiring Equifax to actually comply with the PTFA, signaling that damages alone are not treated as sufficient to stop the conduct.
This Is the System Working as Intended
The complaint describes a business model in which harvesting and selling private numbers without consent is not a glitch but the product itself.
- The complaint states that selling class members’ cell numbers “is Defendant’s entire business model,” meaning the alleged violation is structural, not accidental.
- The complaint notes Equifax “generally does not openly advertise the precise prices of its products,” a lack of transparency that makes it harder for the people being sold to know it is happening.
- The plaintiff “had no reasonable ability to discover Defendant’s use of his personal information until shortly before filing suit,” showing the harm is designed to be invisible to its victims.
- The law banning this has existed since September 1, 2005, yet the complaint alleges thousands of Coloradans remained listed without consent, illustrating how long a clear prohibition can go unenforced against a large data broker.
What a Legitimate Fix Looks Like
This case exposes a core failure: a data broker allegedly treating consent as optional because the entire market runs on the assumption nobody will notice. The following is editorial analysis, not a finding of the source document.
Regulatory Track
- State consumer-protection regulators should require data brokers that list cell numbers to prove affirmative consent on a per-record basis before a number enters a commercial directory.
- As a general industry standard, mandatory third-party audits of broker data-sourcing pipelines would test whether consent claims are real rather than assumed.
- Brokers should be required to disclose when and how a specific person’s number was acquired, closing the discovery gap the complaint describes.
Legislative Track
- Colorado’s PTFA cell-number provision should be paired with a mandatory notification duty so residents learn when their number is listed for sale.
- Statutory damages should scale with a broker’s revenue from the listings so penalties cannot be absorbed as a cost of doing business.
- Lawmakers should establish an accessible opt-out and deletion right enforceable against brokers regardless of where the company is headquartered.
Corporate Governance Track
- Equifax should be required to implement a documented consent-verification checkpoint before any cell number enters a saleable product.
- Executive compensation tied to data-product revenue should be conditioned on verified compliance with state privacy statutes.
- An internal compliance function with authority to block noncompliant records from sale should report independently of the revenue-generating divisions.
What Now?
Direct your attention to Equifax Inc., the Georgia data broker named as defendant, and to the Colorado agencies with power over consumer privacy.
- Watch the Colorado Attorney General’s office, which enforces the state’s consumer-protection statutes including the PTFA.
- Watch the FTC, whose Data Brokers report the complaint relies on and which oversees data-broker conduct nationally.
- If you live in Colorado, check whether your number appears in broker directories and document what you find; you may be part of the class described in this suit.
- Support local digital-privacy and consumer-rights organizing that pushes for broker notification and deletion rights at the state level.
- Share consent tools and opt-out knowledge within your own community, especially with elderly neighbors the complaint identifies as prime targets.
The source document for this investigation is attached below.
Explore by category
Product Safety Violations
When companies sell dangerous goods, consumers pay the price.
View Cases →Financial Fraud & Corruption
Lies, scams, and executive impunity that distort markets.
View Cases →


