Skip to main content

Morning Overview

A data broker was banned from selling records of the clinics and shelters phones visit

A federal judge in Idaho signed a binding order on June 25 banning data broker Kochava and its subsidiary from selling location records that reveal when a person’s phone visits a reproductive health clinic, a domestic violence shelter, a place of worship, or several other categories of sensitive site. U.S. District Judge B. Lynn Winmill entered the stipulated order to close a Federal Trade Commission lawsuit first filed against Kochava in August 2022, after the agency alleged the Idaho-based company sold precise location data pulled from hundreds of millions of mobile devices. The Commission had voted 2-0 in May to approve the settlement terms before sending them to the court for final sign-off.

The order does not just cover future sales. It requires Kochava and its subsidiary, Collective Data Solutions, to either delete or strip identifying detail from historical location data collected without a consumer’s affirmative express consent, within 90 days of the order taking effect, unless the companies can produce records proving consent was actually given.

Reproductive Clinics and Domestic Violence Shelters Were the Alleged Targets

When the FTC first sued Kochava in 2022, the agency said the company’s data feeds could be used to track a phone from a reproductive health clinic to a person’s home address, identify which place of worship someone attends, and flag mobile devices that spent the night at a shelter serving people fleeing domestic violence. “Where consumers seek out health care, receive counseling, or celebrate their faith is private information that shouldn’t be sold to the highest bidder,” Samuel Levine, then the director of the FTC’s Bureau of Consumer Protection, said when the original complaint was filed.

The signed order formalizes those categories into a legal definition of “Sensitive Locations”: medical facilities, religious organizations, places that predominantly serve minors through education or childcare, shelters providing temporary housing or social services to homeless people or domestic violence survivors, and military or federal law enforcement buildings. Any precise location data tied to those places now falls under the sale ban unless a consumer has directly and knowingly consented.

Collective Data Solutions Inherited the Data Broker Business

Kochava’s subsidiary, Collective Data Solutions, has taken over the parent company’s data broker operations, and the order places most of the ongoing compliance burden on that subsidiary specifically. Within 90 days of the order’s entry, Collective Data Solutions has to stand up a formal Sensitive Location Data Program, complete with a designated privacy officer who reports to its board, a written list of sensitive locations reassessed at least every three months, and documented testing to verify the company is not still selling the data it is now barred from selling.

A separate Supplier Assessment Program requires the company to confirm, supplier by supplier, that consumers actually consented before their location data entered Kochava’s pipeline in the first place, and to stop using any location feed where that consent cannot be documented. Neither company admitted wrongdoing as part of the settlement, a standard term in FTC consent orders of this kind, though both agreed to the injunction’s terms and waived their right to appeal it.

A Judge in the District of Idaho Made the Ban Enforceable

The Commission’s May vote approved the order’s terms, but the order itself only became legally binding once Judge Winmill signed it in the U.S. District Court for the District of Idaho, the same court where the FTC filed its original 2022 complaint and two subsequent amended versions. The order runs for 10 years from the date of entry, meaning the sale ban and the compliance programs built around it stay in force through June 2036 unless a court modifies them.

The FTC’s Bureau of Consumer Protection, whose lead attorneys on the matter included Jennifer Rimm, Erik Jones, Mike Sherling, Elizabeth C. Scott and Julia Horwitz, retains authority to interview Kochava and Collective Data Solutions staff and demand compliance reports for the life of the order, and can pose as a consumer or supplier to test whether the companies are actually following it.

Consumers Can Now Ask Who Bought Their Location

The order gives affected consumers a right they did not have before: they can demand that Collective Data Solutions disclose the identity of any recipient that bought, licensed or otherwise received their precise location data, and the company must provide a clear way to submit that request. A separate provision lets consumers request deletion of their location history outright, with a 30-day deadline for the company to comply once a verified request comes in.

Those consumer-facing tools only work if someone knows to ask, and the order does not require Kochava or Collective Data Solutions to proactively notify every person whose data was previously sold to a sensitive location. For now, the mechanism the order relies on to reach affected consumers is a requirement that both companies send a copy of the order to any customer that received location data from them within the past two years, putting the burden on those business customers, not on the FTC, to pass the news along.


More from Morning Overview

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.