Kochava Inc., a mobile measurement and data analytics company that brokers consumers' precise GPS location data collected from mobile apps, was charged by the Federal Trade Commission with engaging in an unfair trade practice by selling location data from which consumers' visits to sensitive locations — including reproductive health clinics, addiction and substance use disorder treatment facilities, mental health providers, domestic violence shelters, and places of worship — could be identified, without consumers' knowledge or meaningful consent, to data purchasers who could use the location histories for purposes directly harmful to the individuals the data described.DOCUMENTED
Precise GPS location data collected from mobile devices represents one of the most sensitive categories of consumer information, because a person's movements over time reveal intimate details of their life — their medical appointments, their religious practices, their relationships, their political activities, and the personal struggles they are navigating privately. When this data is collected by mobile apps, aggregated into historical movement profiles, and sold to third parties, the individuals whose movements are being described typically have no idea their location history is a commercial commodity or that it is being purchased by parties whose purposes they have not been informed of.REVIEWED
- Kochava purchased raw GPS location data from mobile data suppliers and sold it through its data marketplace to advertising, analytics, and research customers
- The data was precise enough to identify specific building-level visits — regulators demonstrated it could identify visits to specific reproductive health clinics, addiction treatment centers, and other sensitive facilities
- Kochava sold data in bulk without restrictions on the purposes for which purchasers could use information derived from sensitive location visits
- The data was collected by mobile apps through permission requests that consumers did not understand would result in their location history being sold to data brokers
- The consent order prohibits Kochava from selling precise location data associated with sensitive categories of location without demonstrably informed consumer consent
The Data Collection Pipeline
Kochava did not collect location data directly from consumers — instead, it purchased location data from suppliers who had obtained it from mobile applications that had requested location permission from device users. When a consumer grants location permission to a weather app, a navigation app, or a retail store app, they are typically thinking about that specific app using their location for its stated purpose. They are generally not aware that the location data is being transmitted to a data broker network or that their precise location history — timestamped GPS coordinates over days, weeks, or months — is being compiled into a commercial data product sold to third parties.REVIEWED
The supply chain for location data typically involves the mobile app passing location information to an advertising or measurement SDK embedded in the app's code; that SDK transmitting the data to a data aggregator; and the aggregator selling cleaned, timestamped location histories to commercial data marketplaces including Kochava. Each step in this chain involves a data transfer that the consumer did not specifically consent to when they granted location permission to the original app — a series of uses far removed from the context in which the consumer shared their location.DOCUMENTED
The Sensitive Location Problem
Location data that reveals visits to sensitive facilities creates specific and serious risks for the individuals described. A location history showing visits to an abortion clinic can be used by private parties to identify abortion seekers in states where abortion is restricted — for purposes including legal action, harassment, or targeted anti-abortion messaging. Location data showing visits to addiction treatment programs can be used to discriminate in employment or insurance. Location data showing domestic violence shelter visits can endanger people who are hiding their location from an abuser. Religious institution visit data can reveal religious affiliation in contexts where that information could lead to discrimination or harm.DOCUMENTED
Regulators demonstrated specific harms by purchasing a sample of Kochava's location data through its commercial marketplace and showing that the data could be used, without sophisticated analysis, to identify which mobile device identifiers had visited specific named sensitive facilities during specific date ranges — creating a deanonymizable record that, combined with other commercially available data about the device identifier's owner, would allow a determined actor to identify specific individuals by name and associate them with sensitive location visits.DOCUMENTED
Regulators purchased a sample of Kochava's location data from its own marketplace and demonstrated they could identify which specific mobile devices had visited named abortion clinics, addiction treatment centers, and domestic violence shelters during the previous months — creating a privacy vulnerability that no consumer who shared their location with a weather app or navigation tool had contemplated or consented to.
The Consent Order
The consent order prohibits Kochava from selling or using precise location data associated with a list of sensitive location categories without obtaining demonstrably informed consent from the consumer whose location is being used — consent that goes beyond a general location permission granted to a mobile app and that specifically addresses the commercial sale of location data linked to the identified sensitive location types. The company is also required to establish a deletion mechanism allowing consumers to request deletion of their location data from Kochava's systems and from any data products the company has assembled from that location history.DOCUMENTED
Consumers who are concerned about their location data being included in commercial data products have limited practical ability to prevent it under current law — the opt-out mechanisms available at the app level are uneven and not always honored through the full data supply chain. The most effective protection is to grant location permission only to apps that genuinely require it for their core function, and to use the "while using the app" option rather than "always" when location permission is required. Disabling advertising identifiers on mobile devices limits the ability of data brokers to link location histories to a persistent identifier associated with the device owner.REVIEWED
How Location Data Flows From Your Phone to Data Brokers
Understanding the pathway through which your location data reaches commercial data brokers can help you make more informed decisions about which apps receive location permission. When you grant location access to an app — even on a limited "while using the app" basis — that app's code may include third-party advertising or analytics SDKs that transmit your location data to the companies that operate those SDKs. Those companies may aggregate location data from many apps and sell it to data brokers. The entire chain — from your location permission to the commercial data broker product — may involve multiple handoffs that the original app's privacy policy did not clearly describe. Checking the App Store or Play Store privacy nutrition labels for apps before downloading provides a summary of the data types the app collects. For apps that request location access and are not navigation or location-dependent service apps, declining location permission entirely and checking whether the app's core functionality still works without it is often an effective approach.
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.