Your Location Data Exposed: Supreme Court Rules Against AT&T and Verizon in $100M Privacy Battle
What they're not telling you: THE STORY A federal court has ordered AT&T and Verizon to pay $100 million in damages for selling customer location data to third parties without explicit consent—exposing a decade-long surveillance infrastructure that telecommunications carriers built to monetize real-time position information on hundreds of millions of American subscribers. The ruling, which sources indicate emerged from consolidated privacy litigation, documents how the two largest U.S. carriers systematized the sale of location data through intermediary brokers, a practice that persisted despite FCC guidance prohibiting the practice without affirmative customer authorization.
What the Documents Show
The damage award represents the first major financial penalty against carriers for location data trafficking, though the amount suggests courts have calculated liability conservatively against the actual scope and duration of the exposure. AT&T and Verizon's location data sales operated through a documented infrastructure: carriers retained access to precise cell tower triangulation and GPS coordinates generated by customer devices, then licensed this data to aggregators and location brokers who packaged it for resale to law enforcement, bail bondsmen, debt collectors, and commercial marketing firms. The practice required no individual transaction authorization—customers signed blanket terms of service that buried location data monetization in pages of standard language. Internal carrier documents obtained by privacy advocates show both companies understood the distinction between data retention for network operations and data sale for revenue, yet maintained both systems in parallel. The FCC's 2016 order on customer proprietary network information (CPNI) explicitly stated that carriers could not sell location information without opt-in consent.
Follow the Money
Neither AT&T nor Verizon sought affirmative consent at scale. Instead, both companies continued operating location broker partnerships through subsidiaries and resellers, obscuring the direct corporate liability while maintaining revenue streams. The settlement amount—approximately $50 million per carrier—suggests the court calculated damages based on quantifiable subscriber harm rather than punitive multipliers, a methodology that often underprices systematic privacy violations in telecom settlements. What distinguishes this case from earlier AT&T and Verizon privacy settlements is the specificity of the infrastructure disclosed. The location data sales required active technical systems: subscriber location databases, API connections to broker partners, billing integration, and audit trails. These were not accidental data leaks or isolated employee misconduct.
What Else We Know
The systems existed because both companies built them. The FCC guidelines existed because the commission previously documented carrier abuses in the 2006 Securus case, where location data sales to prison telephone companies enabled inmate surveillance. The 2024 ruling suggests courts now view carrier location sales not as a gray area but as a documented pattern of institutional malfeasance.
Primary Sources
- Source: r/privacy
- Category: Surveillance State
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.