Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections

Electronic Frontier Foundation
Published
Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections

The short version

  • Last year, we published our rubric for what comprehensive and protective location privacy laws should look like…
  • Since then, state lawmakers across the country have begun responding to calls like these, with Connecticut , Maryland , New Jersey , Oregon…
  • Yet, even as these states move the ball forward to restrict location tracking, most of their laws leave significant gaps that still must be filled.
  • Other states – and Congress – need to get into the game, too, and ensure protection of everyone.
  • Why Location Privacy Is Important Imagine spending a couple of hours in a coffee shop, a friend's house, or a healthcare clinic…

The story

Regulating commercial location tracking has reached a turning point. Last year, we published our rubric for what comprehensive and protective location privacy laws should look like, outlining the baseline standards states should meet to shield individuals from pervasive location surveillance. Since then, state lawmakers across the country have begun responding to calls like these, with Connecticut, Maryland, New Jersey, Oregon, and Virginia enacting new consumer privacy restraints on an industry that profits off our physical movements.

Yet, even as these states move the ball forward to restrict location tracking, most of their laws leave significant gaps that still must be filled. Other states – and Congress – need to get into the game, too, and ensure protection of everyone.

Why Location Privacy Is Important

Imagine spending a couple of hours in a coffee shop, a friend's house, or a healthcare clinic, only to discover yourself under police investigation because your cell phone’s location data exposed your presence there.

This is the reality of geofence warrants for location data, the controversial surveillance technique recently scrutinized by the U.S. Supreme Court in Chatrie v. United States. Through geofencing, tech companies and law enforcement can map everyone who was present within a specific area over a certain window of time, inverting standard constitutional protections by turning every innocent bystander into a potential suspect. While the Supreme Court's ruling in Chatrie established that accessing location data via geofencing constitutes a Fourth Amendment search requiring constitutional protections, law enforcement demands via these warrants are only part of the problem. That same geolocation tracking is used by commercial data brokers operating in a largely unregulated market. These brokers regularly harvest, aggregate, and sell physical location data to anyone with a credit card (including government agencies, which are among their regular clients). Especially for individuals seeking reproductive or gender-affirming care, attending a protest, or visiting an immigration law clinic, this pervasive commercial location surveillance represents an immediate threat.

In Part 1 of this series, we urged lawmakers to protect people from the growing harms of location tracking tools across all areas of public life. The real-world consequences of this unregulated market impact us all. An anti-LGBTQ+ advocacy group spent millions of dollars buying app location data to track priests across multiple dioceses and used app-harvested location data to “out” a priest after purchasing his Grindr location signals. Privacy advocates posing as private investigators gained access to Locate X, a location-tracking tool developed by Babel Street, and demonstrated how the tool tracked a device traveling from Alabama, where abortion is banned, to an abortion clinic in Florida, where access is less restricted. Data brokers like Near Intelligence have sold precise location data of reproductive health clinic visitors directly to political groups. Location data has been used to locate U.S. military personnel in war zones. Law enforcement and private entities have also weaponized location tracking directly against political protesters: surveillance contractors and authorities have utilized location data derived from real-time bidding ad networks to track individuals attending demonstrations.

The unregulated sharing of location data has created an ever-larger funnel for data brokers to capture and monetize our movements. For example, a recent EFF investigation identified several advertising Software Development Kits (SDKs) in Android apps that by default collect and share users' location data whenever app-level location permissions are granted. These advertising libraries automatically feed users' location data into ad systems that location data brokers have used to track people. Because defaults direct real-world outcomes, app developers who fail to carefully scrutinize the third-party SDKs they use, and disable unnecessary data collection, could inadvertently expose their users’ movements to commercial data brokers.

State Legislative Progress

Last year, we outlined six essential core principles that any meaningful location privacy law must contain:

  • Strong definitions,
  • Clear rules,
  • Affirmation that all precise geolocation data is sensitive,
  • Empowerment of consumers through a strong private right of action,
  • Prohibition of “pay-for-privacy” schemes, and
  • Transparency through clear privacy policies.

While the bills we highlighted from California, Illinois, and Massachusetts are yet to pass into law, a new wave of state location privacy legislation has taken effect across Connecticut, Maryland, New Jersey, Oregon, and Virginia.

These five laws represent progress, and share two strong features.  First, all five of these states ban the sale of precise geolocation data. This will remove a strong incentive to collect and store this information in the first place. Other types of privacy laws have likewise banned the sale of sensitive types of data, like the Illinois Biometric Privacy Act (BIPA), which bans the sale of biometric information such as face scans.

Second, all five states broadly define the protected data to include all kinds of locations across the board within a particular distance of a person or their device, rather than protecting just narrowly-defined “sensitive” locations. This all-locations protection sets these laws apart from California’s A.B. 45 of 2025, for example, which only restricts location tracking within 1,850 feet of a family planning center. Protecting location data only near specific locations (like health care facilities) is insufficient: if an individual travels across state lines for care, a data broker can still track their route right up to the boundary of a protected zone and pick it up immediately upon departure, making it easy to infer their destination.

These five laws vary regarding whether, on top of the ban on sale, they require consent and/or minimization for other kinds of processing of precise geolocation data. Maryland’s Online Data Privacy Act (MODPA) requires strict minimization. Specifically, a data controller cannot collect, use, store, or disclose a consumer’s precise geolocation data (or other sensitive data) unless doing so is “strictly necessary to provide or maintain a specific product or service requested by [that] consumer.” Minimization is an important privacy protection because it imposes a duty where it belongs: on the company processing a person’s data. Maryland requires doubly strong minimization. First, the data processing must be “strictly necessary,” and not just “necessary,” or even worse, “reasonably necessary.” Second, the necessity of data processing must be tied to what the particular consumer requested, and not to what a generic customer might hypothetically have thought was reasonable, or the company’s own purposes, or whatever the company buried in its own long-winded legalese.

Connecticut requires both strong consent and weak minimization. Specifically, it forbids a data controller from collecting, using, storing, or disclosing a consumer’s precise geolocation data (among other sensitive data) “without first obtaining [that] consumer’s consent”. Connecticut has a strong definition of consent: “a clear affirmative act signifying freely given, specific, informed and unambiguous agreement,” which is absent from “agreement obtained through the use of dark patterns.” On top of this strong consent, Connecticut also requires a weak form of minimization: the data processing must be “reasonably necessary in relation to the purposes for which such sensitive data are processed”. But this does not weaken Connecticut’s strong consent rule.

New Jersey requires consent to collect, use, store, or disclose a person’s precise geolocation data (and other sensitive data).

Virginia protects location data with both minimization and consent, but only for one kind of people (known children) and only for one kind of data processing (collection). Under Virginia’s minimization rule, a data controller cannot collect such data from such people unless doing so “is reasonably necessary for the controller to provide an online service,” and in such cases, “only … for the time necessary” to do so. This would be a much stronger rule if the authors struck the modifier “reasonably” before the word “necessary,” or better yet, substituted the modifier “strictly.”

Beyond its ban on sale, Oregon does not limit the processing of precise geolocation data.

Gaps in Current Legislation

While these enacted bills mark steps in the right direction, major loopholes remain that leave users vulnerable.

The Enforcement Void: Why Every Law Needs a Private Right of Action

A privacy law without a Private Right of Action is a law "without teeth”.

None of these five state statutes expressly empower consumers to directly sue companies that violate their location privacy rights. Relying exclusively on state Attorneys General or specialized regulatory agencies creates a critical bottleneck, since no regulatory agency possesses the staffing or budget required to investigate every data privacy violation. Additionally, government enforcement priorities shift across administrations, leaving enforcement vulnerable to political pressures and corporate lobbying.

The best way to ensure effective enforcement is a free-standing, explicit Private Right of Action written directly into the privacy statute. Some legislative privacy proposals instead attempt to provide remedies by piggybacking on state laws against unfair, deceptive, or abusive practices (UDAP). But this is often hit-or-miss depending on each state’s specific UDAP law, including who must have what kind of injury to have standing to bring a private action, and the scope of remedies. For instance, while Maryland’s MODPA provides that a violation of the statute constitutes a banned UDAP, it appears that the new law’s enforcement mechanics were drafted in a way that provides only government enforcement through the Attorney General’s Consumer Protection Division, rather than granting consumers a private right of action.

Any a private right of action should come complete with statutory liquidated damages to remedy non-economic harm, and prohibitions against mandatory arbitration. This ensures that compliance isn't optional. Until corporate bad actors face direct accountability from the very people whose personal location data they unlawfully exploit, state privacy laws will rely on overworked regulators to police an industry that profits off our every move.

The "Pay-for-Privacy" Trap

Privacy is a fundamental right, not a luxury tier. So EFF opposes pay-for-privacy schemes, in which companies charge a higher price to people who exercise their privacy rights. To prevent these schemes, data privacy legislation must prohibit companies from retaliating against consumers who exercise their statutory privacy rights, including by charging a higher price. For example, if a statute bars a company from processing a person’s data absent their consent, and that person withholds consent, the statute must bar the company from responding by charging a higher price.

Unfortunately, all three of these states that require consent to process precise geolocation information (Connecticut, New Jersey, and Virginia) have only weakly limited pay-for-privacy schemes. While all three prohibit discrimination against customers who withhold consent, all three also have a wide loophole: for discount programs. To make matters worse, none of these three states prevent the discount programs from selling customer data to third parties. But people should not have to surrender their data privacy to join a discount club for regular customers. Thus, the far better approach is to eschew this loophole, as in the ban on pay-for-privacy in last year’s location data privacy bills in Illinois and Massachusetts.

These exceptions allow companies to charge higher prices or downgrade service quality for users who exercise their privacy rights. In practice, this converts privacy into a privilege for those who can afford it, forcing economically vulnerable communities to trade away their sensitive location movements in exchange for essential discounts or services.

Dark Patterns

Any law that requires consent also needs to ban company techniques that subvert consent. These are often called dark patterns, predatory design, and manipulative user interface (UI/UX) practices.

Connecticut’s definition of “consent” excludes “dark patterns,” as noted above. That state defines dark patterns as “a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making, or choice,” including any practice that the FTC refers to as a dark pattern. Other consent-based privacy rules must do so, too.

Conclusion

The recent wave of state legislation demonstrates that momentum is building against location surveillance. However, state leaders must go further.

To build privacy protections that withstand corporate workaround attempts, future bills must apply to all locations universally, give individuals the legal standing to enforce their own rights in court, and fully prohibit pay-for-privacy. Until comprehensive data privacy legislation with real teeth is enacted nationwide, users can consult EFF's Surveillance Self-Defense Guide to learn practical steps for reducing location tracking on their personal devices.

Read the full story at Electronic Frontier FoundationOriginal

Related Markets

All Markets
View full chart →
View Full Chart

Market data may be delayed. Not financial advice.

Powered by Gab AI

The Story At A Glance

Reading this article now — analysis appears below

Reading the article

💡 AI analysis provides alternative perspectives on current events

More to read

Recent stories from across the outlets Alto indexes.

Questions Alto can answer

From this story — each link opens a live data page or a tool already filled in.

  1. Who represents Connecticut in Congress?House and Senate members
  2. How does Connecticut rank on taxes and cost of living?Taxes, wages, cost of living
  3. What's the forecast for Connecticut?Forecast and severe alerts
  4. What does gas cost in Connecticut right now?Current statewide average
  5. What are Connecticut's voter ID rules?ID rules and deadlines
  6. What is $100 from 1990 worth today?CPI-adjusted dollars — result on the next page
  7. Where does $75,000 rank in Connecticut?Census percentile — national and state
  8. What's Alto covering on the Censorship desk?Latest headlines on this beat
  9. What else is Alto tracking on Big Tech Censorship?Topic hub with related coverage
  10. What else is Alto tracking on Flock Safety?Topic hub with related coverage

All toolsAll topicsSource directoryStory timelinesHeadline comparisonSearchMost read

From Gab Shop

Official merchandise. Every order funds free speech infrastructure.

Shop all products

Install Alto on your phone

Add Alto to your home screen for breaking news — no app store, no account.

  1. Step 1Open alto.gab.com in SafariMust be Safari — not Chrome or in-app browsers
  2. Step 2Tap the Share buttonSquare with an arrow, at the bottom of Safari
  3. Step 3Tap "More"If you don’t see Add to Home Screen yet
  4. Step 4Tap "Add to Home Screen"Scroll the share sheet if you need to
  5. Step 5Tap "Add"Alto appears on your home screen like any other app.
gab

The Platform They Tried to Deplatform

Banned from app stores, dropped by banks, still online. Gab is where the deplatformed went.

What Makes Gab Different

We're not just another social network. We're a platform built on principles that matter.

Freedom of Speech & Reach

All First Amendment protected speech is welcome. No algorithmic throttling or shadow banning.

Family-Friendly Platform

We maintain a clean environment. Explicit adult content is strictly prohibited.

Western Nations Only

Third-world IPs are blocked. No scammers, no spam farms. Built for Western civilization.

Funded By Users

Our users are our investors and customers. You're not the product being sold.

Battle Tested

A decade of standing strong. Banned from app stores, banks—and still here.

American Owned & Operated

We reject foreign censorship demands. Built by Americans, for free people.

Support Alto & Gab

Alto is funded entirely by readers like you. Your donation helps us continue delivering curated news from a right-wing Christian Nationalist perspective, powered by Gab AI.