Information acquired from a number of sources, including working in the data industry (a decade or two back), privacy advocacy, working in Web space, research of my own, stories over beers, legal experiences, etc.
There's a large information-brokerage industry. If you want to find it, investigating the question from the consumption side (as in: who will sell me this information) should turn up the larger players, most of whom are already listed in this thread. https://news.ycombinator.com/item?id=13804795
The big players are much of the business: Power laws work here as anywhere else, and heading off the larger sources is pretty effective.
The value of individual data isn't all that great. Which leads to one of the major PITAs of this industry: there's a lot of invalid, false, or stale data around. The incentives to fix it simply don't exist.
The now-defunct Internet Junkbuster used to have a print-your-own set of letter templates which could be sent to various marketing organisations. Doing that in the early 2000s dropped my own junk-mail volumes tremendously, and for years afterward. I suspect SafeShepherd operates somewhat similarly. Finding and hitting the direct marketing association(s) was a big part of that.
Putting a fraud hold on your credit reports (TansUnion, EquiFax, Experian) is useful.
Any account-based activities or activities in which you are specifically identified are fodder for capture. Credit cards, checks (Luddite! ... hang in there), "loyalty" cards. Gyms and pizza, as noted.
Facebook, which should go without saying. LinkedIn profiles.
Any online information service which has ever been hacked. (For safety, assume all of them.)
Online purchases. Through both the marketplace and your credit card.
Court and other public records are manually reviewed and entered.
Various school and alumni associations. Organisations such as Classmates.com, MyLife, etc., front-ended to skip-tracing and similar organisations (info via direct communications).
Your auto smog testing station. There's an outfit known as ISO, Insurance Services Office, who has a unit that tracks down odometer mileage data. They glean that by buying the state smog check data, which is indexed by VIN and drivers license in mose cases. The notion is that miles driven is an excellent proxy for insurance risk.
https://en.m.wikipedia.org/wiki/Insurance_Services_Office
The US Post Office NCOA (change of address) form, as noted. File a temporary COA to avoid getting listed.
Used to be you could submit a "pornographic materials" request to the USPO to have circulars and such removed from your delivery. Though online sources suggest it's possible to block 3rd class mail (Yahoo answers). That's more an annoyance than privacy issue.
Magazine subscriptions.
Request of any organisations you do business that they not share your information. Use telltales to determine which do (additions to your address, name, etc.).
And, if the state of affairs bothers you, get on your government representatives to do something about it. Data are liability, and there's far too much of it floating around. The US in particular has taken an exceptionally piecemeal approach to the problem (video store rental records are protected, bookstore and pharmacy records are not).
Request comprehensive data privacy regulations, with teeth.