Also on CyberFence: compare CyberFence to other VPNs side-by-side · check your public IP and geolocation .

Home internet router on desk with laptop in background, warm ambient lighting

The short answer is yes — in the United States, your internet service provider can legally collect your browsing history, package it with other data about you, and sell it to advertisers, data brokers, and other third parties. Most people are surprised to learn this. Many assume that what they do online is private unless they're specifically being targeted by law enforcement. That is not how it works.

This post explains exactly what ISPs collect, what the legal framework currently looks like, who buys the data, and what you can do about it.

What Your ISP Can See

Your internet service provider routes all of your internet traffic. That structural position gives them visibility into significant amounts of data about your online activity:

  • Every domain you visit — the hostnames (e.g., nytimes.com, webmd.com, bankofamerica.com) are visible to your ISP through DNS queries even when the actual page content is encrypted with HTTPS
  • When you connected — timestamps for every session and request
  • How long you stayed — duration of connections to each destination
  • How much data you transferred — file sizes and bandwidth usage patterns by destination
  • Your IP address history — which IP addresses your device was assigned over time
  • Device identifiers — MAC address data, device types, and in some cases app-level metadata for mobile connections

What they typically cannot see is the specific content of HTTPS-encrypted pages — the actual text of articles you read, what you searched for within a site, or the content of secure messages. But the metadata alone is substantial. Knowing that you visited webmd.com, cancer-related health sites, a specific hospital's patient portal, and a pharmaceutical company's site — even without seeing the page content — creates a detailed picture of your health situation. The same applies to financial sites, legal services, political content, and religious or lifestyle sites.

The Legal History: How ISPs Got the Right to Sell Your Data

The situation in the US is the result of a specific regulatory rollback. In 2016, the FCC under the Obama administration passed broadband privacy rules requiring ISPs to get customers' opt-in consent before sharing or selling sensitive data, including browsing history. Those rules never took effect.

In March 2017, Congress passed and President Trump signed a resolution under the Congressional Review Act that repealed the FCC's broadband privacy rules before they could take effect. The resolution also prohibited the FCC from issuing substantially similar rules in the future. The repeal passed on partisan lines — 50-48 in the Senate and 215-205 in the House.

The practical effect: ISPs are not subject to the same opt-in consent requirements that apply to websites under the FTC's framework. Major ISPs — AT&T, Comcast/Xfinity, Verizon, T-Mobile — all operate data programs that monetize customer data, including browsing behavior.

What ISPs Actually Do With Your Data

ISPs have built significant advertising and data businesses on top of their network infrastructure. Some documented practices include:

Targeted Advertising Programs

Comcast operates an advertising unit (Effectv) that uses customer data including viewing habits and internet usage to enable targeted advertising across its platforms. Verizon's Custom Experience program, which customers must opt out of rather than into, uses data from app usage, website visits, and location to customize experiences and advertising. AT&T's advertising subsidiary uses network-level data to build audience segments sold to advertisers.

Data Broker Sales

Beyond direct advertising, ISPs sell or license data to data brokers — companies whose entire business model is aggregating and reselling personal data. Once your browsing history enters the data broker ecosystem, it can be purchased by insurers, employers, landlords, and anyone willing to pay for it.

Aggregate and Anonymized Data

ISPs also sell what they describe as "anonymized" or "aggregate" data to market research firms and advertisers. Research has consistently shown that so-called anonymized internet data can frequently be de-anonymized when combined with other data sources — a person's browsing pattern is often distinctive enough to re-identify them even without a name attached.

State-Level Privacy Laws: A Partial Patchwork

In the absence of federal broadband privacy rules, some states have enacted their own protections:

  • California: The California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), give California residents the right to know what data is collected about them, the right to opt out of data sales, and some right to deletion. ISPs serving California customers must comply with these rules.
  • Other states: As of 2026, over a dozen states have enacted consumer privacy laws with varying levels of protection for browsing and internet data. However, coverage is uneven and enforcement is limited.
  • Federal preemption question: Any future federal privacy law could preempt state rules in both directions — either providing stronger or weaker protections depending on the final text.

For most Americans outside of states with strong privacy laws, the legal framework still permits ISP data collection and sale without opt-in consent.

Block your ISP from seeing your browsing history

CyberFence encrypts all traffic with AES-256-GCM before it leaves your device. Your ISP sees only that you're connected to a VPN — not what sites you visit, when, or for how long. Zero logs. US-operated. Web Shield DNS blocking included.

Try CyberFence Free

Does Incognito Mode Protect You From Your ISP?

No. Incognito or private browsing mode prevents your browser from saving local history, cookies, and form data on your device. It does nothing to prevent your ISP from seeing which domains you visit. Your DNS queries still route through your ISP's infrastructure, and your traffic still flows through their network. From the ISP's perspective, incognito mode is invisible — they see the same data either way.

This is a widespread misconception. Google's own disclosures for Chrome's Incognito mode explicitly state that "your activity might still be visible to... your internet service provider."

Does HTTPS Protect You From Your ISP?

Partially, but not completely. HTTPS encrypts the content of your connection to a website — the specific pages you load, what you type, what you see. But HTTPS does not encrypt the domain name you're connecting to. Your ISP can see you connected to webmd.com even if they cannot read the specific article you read on webmd.com.

There is also a mechanism called SNI (Server Name Indication) in the TLS handshake process that historically transmitted the target domain in plain text, allowing additional visibility at the network layer. Encrypted Client Hello (ECH), a newer protocol feature, addresses this — but adoption is still not universal, and ISPs operate at the DNS layer regardless.

Does a VPN Stop ISPs From Selling Your Browsing History?

Yes, effectively. A VPN works by encrypting all traffic from your device before it leaves for the internet, then routing it through a VPN server. From your ISP's perspective, they see only that you're sending encrypted traffic to the VPN server's IP address. They cannot see:

  • Which websites you're visiting
  • Your DNS queries (when using a VPN with encrypted DNS, like CyberFence's Web Shield)
  • How long you spend on specific sites
  • The volume of data exchanged with specific destinations

What they can see is that you're using a VPN, roughly how much data you transfer in total, and the IP address of the VPN server. That's it. There is no browsing history data available to collect, package, or sell.

The critical caveat: this protection transfers trust from your ISP to your VPN provider. You need a VPN with a genuine zero-logs policy — one that doesn't log your browsing activity and cannot produce records of what you visited even if compelled to. CyberFence operates on a zero-logs basis, meaning neither we nor your ISP can see or sell your browsing history.

What About Your Mobile Carrier?

The same analysis applies to your mobile carrier when you're using cellular data (LTE/5G). Verizon, AT&T, and T-Mobile have all operated data monetization programs using mobile internet activity. The 2017 FCC rule repeal covered mobile broadband as well as fixed home internet.

When you connect through cellular data without a VPN, your carrier has the same level of visibility into your browsing activity as a home ISP does over Wi-Fi. A VPN running on your phone protects against mobile carrier data collection the same way it protects against home ISP collection.

The Bottom Line

In the United States, your ISP legally can collect your browsing history and sell it. The regulatory protections that would have required opt-in consent were repealed in 2017, and federal replacements have not materialized. State laws provide some protection in California and a handful of other states, but the patchwork is incomplete.

Incognito mode and HTTPS do not prevent ISP collection. The most direct and reliable technical countermeasure is a VPN with AES-256-GCM encryption and a legitimate zero-logs policy, which removes the browsing data from your ISP's visibility entirely.

Your ISP can't sell what it can't see

CyberFence encrypts all traffic before it leaves your device — on Wi-Fi or cellular — so your ISP only sees encrypted data going to our servers. Zero logs means we don't track it either. Available for Windows, macOS, iOS, and Android.

Monthly $7.99/mo or Annual $88.21/yr ($7.35/mo, save 8%).

Start Your Free Trial

Want to go deeper? Read the CyberFence competitor comparison hub , our free IP address checker , or the CyberFence DNS leak test .