Skip to main content
    All Blog articles
    Data & Privacy
    15 min read

    LiveRamp: 2.5 Billion People in One Database

    After Cambridge Analytica, Acxiom spun off its marketing arm and renamed it LiveRamp. It now has profiles on 2.5 billion people, tracks 14 billion devices, and operates a marketplace selling segments on military personnel, religious minorities, and the financially vulnerable.

    Author
    By Catherine “Cat” Karow
    Published
    Published December 27, 2025
    Updated
    Updated May 10, 2026
    Data & Privacy

    ZoraSafe Blog

    LiveRamp: 2.5 Billion People in One Database

    The Rename

    In 2018, the world learned how Cambridge Analytica had harvested data on 87 million Facebook users to manipulate American voters in the 2016 presidential election.

    Among the companies caught in the fallout was Acxiom—one of the world's largest data brokers, and one of the companies that had allegedly provided data to Cambridge Analytica.

    Acxiom had a problem. Its brand was toxic. Facebook was cutting ties with third-party data brokers. New privacy laws like GDPR were threatening the entire business model.

    So Acxiom did what any billion-dollar surveillance company would do.

    It rebranded.

    In July 2018, Acxiom sold its marketing solutions division to ad giant IPG for $2.3 billion. Then it took its remaining technology platform—the part that connected everyone else's data—and renamed itself.

    The new name? LiveRamp.

    The old Acxiom databases went to IPG. LiveRamp kept the infrastructure. The pipes. The identity resolution technology. The ability to connect any piece of data about any person across any platform.

    Seven years later, LiveRamp has built something even larger than what Acxiom ever was.

    And hardly anyone knows it exists.


    The Scale

    Let me give you the numbers from the class action lawsuit filed against LiveRamp in January 2025:

    700 million consumers tracked worldwide

    250+ million Americans profiled (that's virtually every adult in the country)

    14 billion devices linked to real identities

    2.5 billion people with detailed profiles

    3,000+ data points on each person

    $2.2 billion market capitalization

    LiveRamp doesn't just collect data. It's the switchboard for the entire data broker industry.

    According to the lawsuit, LiveRamp operates "a massive identity surveillance system that assigns every American a proprietary, permanent identifier—the equivalent of an online social security number."

    That identifier is called a RampID.


    How RampID Works

    Here's what makes LiveRamp different from other data brokers:

    Most data brokers collect information and sell it. LiveRamp does something more powerful—it connects information.

    Think of it like this: When you buy something at a store with a credit card, that transaction creates a data point. When you browse a website, that creates another data point. When you download an app, another. When you walk past a cell tower, another.

    All of these data points exist in different databases owned by different companies. They're fragments. Puzzle pieces.

    LiveRamp's technology—built on something called AbiliTec—takes all those fragments and connects them to a single identity: you.

    The process works in three steps:

    Step 1: Collection

    LiveRamp collects and purchases data from countless sources—both online and offline. This includes:

    • Names, addresses, phone numbers, email addresses
    • Browser cookies and mobile device IDs
    • Connected TV IDs (yes, your smart TV)
    • "Custom IDs" from platforms like Google and Facebook
    • Purchase histories
    • Location data
    • And much more

    Step 2: Resolution

    Using their AbiliTec identity graph (which contains data spanning 50 years, going back to 1973), LiveRamp matches all these fragments together. They claim to tie an average of 12 different identifiers to each person in their graph.

    The result? A single, persistent RampID that follows you across every device, every platform, every interaction.

    Step 3: Monetization

    LiveRamp sells access to these identities through their Data Marketplace. Any company can buy "segments" of people based on incredibly specific criteria.

    The Capitol Forum obtained a list of more than 500,000 audience segments available for sale.


    What's For Sale

    According to the class action lawsuit and Capitol Forum investigation, here are some of the segments available on LiveRamp's Data Marketplace:

    Health conditions:

    • People with cancer
    • Individuals seen at clinics/hospitals while unemployed

    Religion and ethnicity:

    • Muslims
    • Jewish people
    • African Americans
    • Hispanic individuals
    • Country of origin data

    Financial vulnerability:

    • "Poor people"
    • "Payday loan prospects"
    • People experiencing financial distress

    Sexual orientation:

    • Users of LGBT dating apps like Grindr

    Behavior:

    • Online gamblers
    • Union members

    Military and National Security:

    • Active-duty military members (broken down by service branch)
    • Residents of Fort Bragg (home to U.S. Army Special Operations Command)
    • Residents of other military bases
    • "Employee devices at companies that manufacture military equipment"
    • Individuals "known to work" at defense contractors like Lockheed Martin, Northrop Grumman, and Raytheon
    • People who work at the U.S. Department of Defense
    • "Mobile ad IDs collected at US Military Bases"
    • Individuals who have "physically entered Boeing Distribution locations in the last 120 days"
    • Homeowners with VA loans (available only to veterans and service members)

    Let me repeat that last section: You can buy targeting data on people who work at military bases and defense contractors.


    The National Security Risk

    A NATO Strategic Communications Centre of Excellence report specifically cited Acxiom (now LiveRamp) as "one of the world's leading data brokers" and a reference point for understanding the scale of the industry.

    The report warned that data brokers pose a direct threat to national security.

    Here's how:

    Foreign adversaries can:

    • Identify where service members work
    • Use health or financial information to bribe or blackmail personnel
    • Track service members' movements
    • Impersonate personnel online or in email
    • Map patterns of movement within military bases
    • Bypass biometric security systems (photos showing fingertips can be used to recreate fingerprints)
    • Create psychological operations to influence behavior and decision-making
    • Gather intelligence on military equipment capabilities

    As the U.S. Naval Institute Proceedings journal noted:

    "Adversaries who purchase service members' information can reap the benefits of significant intelligence while avoiding the costs of intelligence operations. This is not limited to operations overseas or during armed conflict—in fact, this information is likely more useful to U.S. adversaries during 'peacetime.'"

    LiveRamp's Data Marketplace makes all of this possible. And there's virtually no regulation stopping foreign governments from buying these segments.


    The Wiretapping Lawsuit

    In January 2025, Christina Riganian of Southern California filed a class action lawsuit against LiveRamp in federal court.

    When she obtained the data LiveRamp had compiled on her, she found several thousand pieces of information. The materials showed her data had been disclosed to at least 62 third parties, including:

    • Pharmaceutical companies
    • Publishers
    • Advertisers
    • Ad tech companies (Google, Amazon, Microsoft)
    • Other data brokers (who can resell it further)

    Riganian never directly interacted with LiveRamp. She never signed up for their service. She never consented to being tracked.

    The lawsuit alleges LiveRamp violated:

    • The California Constitution's right to privacy
    • The California Invasion of Privacy Act (CIPA)
    • The federal Wiretap Act
    • Common law intrusion upon seclusion
    • Unjust enrichment

    The key allegation: LiveRamp uses "event listeners" that intercept communications while they're in transit—essentially wiretapping.

    In July 2025, Judge Jon Tigar of the Northern District of California denied LiveRamp's motion to dismiss on five of six claims.

    The court rejected LiveRamp's argument that making profit from surveillance somehow makes it legal:

    "This Court is not persuaded that commercially exploiting unlawfully obtained information is 'licit' merely because it is profitable. Put simply, committing a tort and seeking a profit are not mutually exclusive (if anything, the latter is often the reason for the former)."

    The case is proceeding.


    "Anonymization Is Functionally Meaningless"

    LiveRamp has tried to defend itself by claiming its data is "anonymized" or "pseudonymized."

    The court didn't buy it.

    Here's why: LiveRamp offers a feature called "Attribute Enrichment." Any LiveRamp customer can take a person's name, address, or email and receive back all the segments associated with that person—health conditions, financial status, religious affiliations, and more.

    As the court noted, this renders any anonymity "functionally meaningless."

    You can't claim data is anonymous when anyone with a name and address can look up exactly who it belongs to.

    LiveRamp also argued that its practices are publicly disclosed, so users should have expected them.

    The court rejected this too:

    "[T]he plaintiffs 'were not aware of LiveRamp's conduct at all... so LiveRamp's disclosures have no effect on their reasonable expectations of privacy.'"

    Translation: You can't consent to something you don't know exists.


    The Real-Time Surveillance

    According to the Cracked Labs research report on LiveRamp, the company maintains:

    • Population-scale identity databases on 700 million people globally
    • 45 million people in the UK
    • 25 million people in France
    • Data spanning 50 years (since 1973)
    • 4 billion records including 2.5 billion email addresses
    • Real-time tracking across 14 billion devices

    The report describes LiveRamp's system as enabling "pervasive identity surveillance for marketing purposes."

    But here's the critical point: Once this infrastructure exists, it's not just for marketing.

    LiveRamp's technology allows:

    • Real-time tracking of individuals across devices
    • Linking online behavior to offline identity
    • Building comprehensive profiles on virtually any person
    • Targeting based on the most sensitive aspects of people's lives

    This is surveillance infrastructure. And it's available to anyone willing to pay.


    UK Government Websites

    In 2020, the privacy browser Brave published a report finding that over 400 UK local council websites had allowed private companies to track visitors.

    6.9 million British citizens were being tracked on government websites by a company called LiveRamp.

    These are websites people visit to access services for:

    • Addiction treatment
    • Disability benefits
    • Poverty assistance
    • Housing support

    As Brave's Chief Policy Officer Johnny Ryan said:

    "It is inexcusable that people seeking help for addiction, disability, and poverty on council websites can be profiled by private companies."

    LiveRamp—formerly part of Acxiom, which had provided data to Cambridge Analytica—was tracking the most vulnerable citizens through their own government's websites.


    The Family Safety App Scandal

    In August 2025, The Capitol Forum reported that Life360—an app marketed as a "family safety" tool used by millions to track their children's locations—was selling user data through LiveRamp's marketplace.

    Despite promising in 2022 to stop selling precise geolocation data, Life360 had created thousands of audience segments based on users' location visits.

    The segments included:

    • Users' age, gender, household income, and parental status
    • Millions of users recorded visiting specific retail locations
    • People who visited "spas and lingerie stores"

    All linked to RampIDs. All for sale.

    Parents who downloaded Life360 to keep their kids safe were having their family's data sold through LiveRamp to whoever wanted to buy it.


    The Pattern

    Let's review what we know:

    1. Acxiom was allegedly involved with Cambridge Analytica in the 2016 election manipulation scandal
    2. Acxiom rebranded as LiveRamp to escape the toxic association
    3. LiveRamp built an even larger surveillance system, now tracking 700 million people across 14 billion devices
    4. LiveRamp's marketplace sells segments on military personnel, defense contractors, and national security-sensitive locations
    5. LiveRamp's marketplace sells segments on religious minorities, ethnic groups, LGBT individuals, and the financially vulnerable
    6. LiveRamp was caught tracking citizens on UK government websites for addiction, disability, and poverty services
    7. Family safety apps are selling location data through LiveRamp's marketplace
    8. A federal court ruled that LiveRamp's practices may constitute illegal wiretapping
    9. LiveRamp claims anonymization while offering features that let anyone look up a person's profile by name

    And through all of this, LiveRamp has remained largely invisible to the public. A $2.2 billion company that knows everything about everyone, hiding in plain sight behind a meaningless corporate name.

    This is what successful rebranding looks like.


    What You Can Do

    1. Check if you're in LiveRamp's system

    California residents can submit a data access request under CCPA. Go to LiveRamp's privacy page and request your data.

    2. Opt out

    LiveRamp offers an opt-out process, though its effectiveness is questionable. Visit: https://liveramp.com/opt_out/

    3. Review your apps

    Check what permissions you've granted to apps like Life360. Consider whether "family safety" features are worth the surveillance trade-off.

    4. Use privacy tools

    • Brave browser (which exposed the UK government tracking)
    • Privacy-focused email providers
    • VPN services
    • Ad blockers that specifically target tracking pixels

    5. Support the lawsuit

    The Riganian class action is still proceeding. Its outcome could set important precedents for the entire data broker industry.

    6. Demand legislation

    The American Data Privacy and Protection Act stalled in Congress. Contact your representatives and demand they pass comprehensive privacy legislation that actually restricts data brokers—not just requires disclosures.


    The Bottom Line

    Cambridge Analytica was the scandal that was supposed to change everything.

    Instead, it just taught data brokers to rebrand.

    Acxiom became LiveRamp. The databases got bigger. The surveillance got more sophisticated. And hardly anyone noticed.

    LiveRamp isn't just a data broker. It's the infrastructure that makes the entire data broker ecosystem work. The identity graph. The marketplace. The pipes that connect every piece of data about every person across every platform.

    Seven years after Cambridge Analytica, we didn't get privacy reform.

    We got LiveRamp.


    Cat Karow is the CEO of ZoraSafe, an AI-powered cybersecurity platform protecting families and seniors from scams and digital threats. She has 20+ years in cybersecurity, including roles at Apple, the White House OCIO, and GuidePoint Security. Follow The Shield Blog for more investigations into the companies that profit from your data.


    Sources:

    • Riganian v. LiveRamp Holdings, Inc., Case No. 4:2025cv00824 (N.D. Cal.)
    • The Capitol Forum, "LiveRamp: Company Hosts Marketplace Selling Datasets that Target Millions of Americans Based on Sensitive Information, Military Status" (June 2025)
    • The Capitol Forum, "Life360: Family Safety App Selling Datasets Based on Users' Personal Information on LiveRamp's Data Marketplace" (August 2025)
    • Consumer Finance + Privacy Counsel, "Data Broker's Motion to Dismiss Privacy and Wiretapping Claims Denied" (July 2025)
    • Cracked Labs, "Pervasive identity surveillance for marketing purposes" (LiveRamp analysis)
    • Local News Matters / Bay City News, "Identity crisis: Lawsuit alleges tech company violated privacy laws by reselling client data" (January 2025)
    • Decrypt, "Google rival Brave uncovers mass surveillance of UK citizens" (February 2020)
    • Harvard Digital Innovation and Transformation, "LiveRamp (formerly Acxiom) – selling you – without owning your data" (April 2020)
    • U.S. Naval Institute Proceedings, "Data Brokers Are a Threat to National Security" (December 2022)
    • NATO Strategic Communications Centre of Excellence, "Data Brokers and Security" (January 2021)
    • Axios, "IPG to acquire most of Acxiom for $2.3 billion" (July 2018)
    • AdExchanger, "LiveRamp Launches Identity Resolution For First-Party Data" (May 2021)
    • LiveRamp technical documentation and Data Marketplace policies

    Share this article

    Share: