The Location Data Broker Industry
A reviewed dataset flags 80 California-registered data-broker records as reporting location data. 12 of those records also report reproductive-health-adjacent or minors’ data. The page summarizes four selected FTC location-data cases from 2024–2025, plus source-specific request guidance.
Location records flagged
80
Selected FTC cases (2024–2025)
4
Also reporting sensitive data
12
Selected FTC location-data cases (2024–2025)
These are selected FTC complaint and final-order records, not a complete count of every location-data enforcement matter. An FTC order resolves or addresses the facts and allegations in that proceeding; it is not automatically a legal precedent for every provider or practice.
X-Mode Social / Outlogic
2024-04Final order prohibiting sharing or selling sensitive location data
The FTC finalized an order after alleging that X-Mode/Outlogic sold precise location data that could track visits to sensitive locations. The order includes restrictions on sharing or selling sensitive location data and related privacy-program requirements.
Mobilewalla
2025-01Ban on selling sensitive location data; restrictions on ad-auction data use
The FTC finalized an order after alleging that Mobilewalla sold sensitive location data without taking reasonable steps to verify consent. The order also restricts collecting consumer data from real-time bidding auctions for unrelated purposes.
InMarket Media
2024-05Prohibition on selling precise location data
The FTC finalized a settlement after alleging that InMarket collected and used location data for advertising without fully informing consumers or ensuring informed consent through third-party apps using its SDK.
Gravy Analytics / Venntel
2025-01Final order restricting sensitive-location data use and sale
The FTC finalized an order after alleging that Gravy Analytics and Venntel sold sensitive location data and collected or used location data without verifiable consent. The order restricts sensitive-location data use and requires a sensitive-data location program.
Official records: X-Mode/Outlogic, InMarket, Mobilewalla, and Gravy Analytics/Venntel.
80 California-registered records flagged for location data
These records are based on reported disclosures in the California Privacy Protection Agency registry dataset used by The Markup and CalMatters. They describe a reviewed snapshot, not a live determination of what a provider currently collects. Click a recorded route to verify its current destination before submitting anything.
"repro" = record reports reproductive-health-adjacent data · "minors" = record reports data on minors · "hiding" = reviewed snapshot found a noindex/robots.txt signal on the recorded opt-out route
Generate requests in under 60 seconds
Generate opt-out requests for location-data brokers for $9
FAQ
What is a location data broker?+
A location data broker may collect, aggregate, license, or sell information about where a person or device is or has been, including signals supplied through mobile apps or other data sources. Depending on precision, identifiers, consent, and use, location data can reveal or help infer visits to health, religious, reproductive-health, military, or other sensitive places; not every record has those properties. Examples discussed in the selected FTC cases include X-Mode/Outlogic, Mobilewalla, InMarket, and Gravy Analytics/Venntel.
How do location data brokers get my location?+
One documented route is an SDK (software development kit) embedded in a mobile app. If the app and its SDK receive location access or another permitted signal, data may be sent to the SDK provider or another recipient under the relevant app and privacy disclosures. The exact source, precision, retention, and sharing path vary by app, device, provider, and jurisdiction.
Is this legal?+
Legality depends on the data, source, consent, purpose, provider, and jurisdiction. The selected FTC cases on this page involved allegations and orders addressing particular practices involving precise or sensitive location data; they are not a complete enforcement census. Washington’s My Health My Data Act includes consumer-health-data disclosure and consent requirements, sale-authorization rules, and geofence restrictions around health-care facilities. California’s CCPA gives covered residents rights that can include opting out of sale or sharing and limiting certain uses of sensitive personal information. Under the GDPR, precise location is not automatically an Article 9 special category by itself, but Article 9 may apply when processing reveals or concerns a listed category such as health or religious data. This page is general information, not legal advice.
How do I stop location data brokers from tracking me?+
Three layers. (1) iOS/Android: revoke location permissions for apps that don’t need them; use "only while using the app" everywhere; enable "Ask next time" regularly. (2) Advertising identifier: reset and limit ad tracking (iOS: Settings > Privacy > Tracking; Android: Settings > Privacy > Ads). (3) Direct opt-out: send deletion requests to each broker. OfflistMe covers major location brokers in the $9 run.
Does "incognito" or VPN stop location brokers?+
Usually not by themselves. Incognito mode mainly changes local browser-history behavior, and a VPN can change the apparent network address without changing app permissions or every device-level location signal. Revoking unnecessary location access, reviewing advertising-identifier settings, and using provider-specific privacy requests can reduce particular collection or retention paths, but no single step guarantees that all copies or inferences have been removed.
Can I sue a location data broker?+
A private claim depends on the facts, the data involved, the defendant, and the law that applies. Illinois BIPA provides a private right of action for a person aggrieved by a BIPA violation, with statutory damages of $1,000 for a negligent violation or $5,000 for an intentional or reckless violation, subject to the statute and case law; location data alone is not automatically biometric data. Washington’s My Health My Data Act makes violations subject to the state Consumer Protection Act, but whether a particular person has a viable claim requires a fact-specific legal analysis. Other issues may be pursued through a state attorney general, regulator, or the FTC. This is not legal advice.
