Reduce everyday tracking · Part 2 of 3 · 5 min read
How data brokers build a picture of you.
Follow the connection between advertising, location data, and physical surveillance, with dated evidence.
The business that has your file.
↳ starting with a number nobody can actually supportYou will see the data-broker industry described as worth two hundred billion dollars, or two hundred and fifty. Nobody credibly knows what it is worth. Those figures trace back to commercial market research rather than to any regulator, court or peer-reviewed source. The only government-audited figure is from a 2014 FTC study of nine brokers, and it should not be extrapolated either.
What can be counted is companies. California’s official data-broker registry listed 581 registered brokers as of June 2026, its highest count ever. That is a floor, since it only includes the ones that registered.
When the FTC studied nine data brokers in 2014, it found one holding 3,000 data segments on nearly every US consumer, and another adding three billion records a month. Published segment names included “Expectant Parent,” “Diabetes Interest,” “Financially Challenged,” and two, “Urban Scramble” and “Mobile Mixers,” that the FTC noted concentrated low-income Latino and Black consumers.
That report is old. The bridge to the present is the FTC’s 2024 complaint against InMarket Media, which described roughly 2,000 audience segments including “parents of preschoolers,” “Christian church goers,” and “wealthy and not healthy.” The categories did not get less intimate in the intervening decade.
X-Mode Social and Outlogic, finalized April 2024, was the first-ever ban on selling sensitive location data. The order’s definition of sensitive locations expressly includes religious organizations, LGBTQ+ venues and protest sites. The company’s SDK had been in more than 300 apps, with no sensitive-location policies at all until May 2023. InMarket Media followed in May 2024 with the first outright ban on selling precise location.
Mobilewalla, December 2024, is the most quotable: it collected bid-request data even when it did not have a winning bid, pairing more than 500 million advertising IDs with precise location. Gravy Analytics and Venntel were finalized in January 2025. Kochava is now concluded: the FTC announced the settlement in May 2026, and the stipulated order was signed and filed in the District of Idaho on 25 June 2026. Kochava and its subsidiary may not sell, license or share sensitive location data without a consumer’s affirmative express consent, must give consumers a way to ask who received their precise location data and to request its deletion from recipients’ commercial databases, and the order runs for ten years.
As of 1 September 2026, we found no monetary penalty in any of these orders, which is worth knowing. But the enforcement did not stop with a change of administration: Mobilewalla and Gravy in January 2025, GM and OnStar in January 2026, Match and OkCupid in March 2026, Kochava in June 2026.
California built a single delete button.
The Delete Request and Opt-Out Platform has been live since 1 January 2026, and more than 300,000 Californians signed up in its first five months. You verify identity through Login.gov or the state’s identity gateway, and the minimum you supply is name, date of birth and ZIP. Since 1 August 2026, registered brokers have been required to check it and process deletion requests at least every 45 days.
Enforcement against brokers who ignore it has begun. We have seen specific fine amounts reported for individual brokers in August 2026, but as of 16 August 2026 we could not locate the underlying CPPA orders, so we are not printing the figures here.
Two limits, both important. It is for California residents only. And it reaches registered brokers, which is to say not the ones being fined for never registering. Vermont also maintains a registry; Texas and Oregon have registry laws whose public portals we could not verify, so we are not linking them.
Location data can travel beyond the app.
An app's location feature and its advertising or analytics integrations are separate questions. Review both the device permission and the service's explanation of sharing. A useful feature does not establish that every downstream recipient needs the data.
Repeated location points can reveal routines and visits to sensitive places. Replacing a name with an identifier does not necessarily prevent a dataset from being linked back to someone.
What to check
- Does this app need precise location, or would approximate location work?
- Does it need access in the background, or only while you use it?
- Which advertising, analytics, and data-sharing options can you disable?
- Can you use the service without the app or without a persistent login?
Permission changes reduce future collection through that route. They do not retrieve data already shared, and they do not stop every other way of estimating location.
For documented enforcement examples and the conduct alleged in specific cases, see the FTC's privacy and security resources. Do not infer from one case that every app shares the same data or that every dataset has the same source.
Physical spaces can add another layer.
Cameras, license-plate readers, and identity checks operate differently from the permissions on a phone. Changing an app setting does not control those systems.
Where a service offers a choice, ask what information is collected, whether an alternative is available, who receives the data, and how long it is kept. An airport checkpoint, a store, and an employer may have different procedures and legal obligations.
Before travel, consult the agency's current instructions rather than relying on a universal promise that a particular screening technology is optional. For a device search, use the travel and phone-search guide, which distinguishes that question from routine screening.
Edited September 29, 2026. Research and source dates are retained; this edit is not a fresh review of every statistic or legal development.
