The stories buried, spiked, or spun.
Tech & Privacy

Your Location Data Exposed: Supreme Court Rules Against AT&T and Verizon in $100M Privacy Battle

&;.
Share
Your Location Data Exposed: Supreme Court Rules Against AT&T and Verizon in $100M Privacy Battle

What they're not telling you: THE STORY A federal court has ordered AT&T and Verizon to pay $100 million in damages for selling customer location data to third parties without explicit consent—exposing a decade-long surveillance infrastructure that telecommunications carriers built to monetize real-time position information on hundreds of millions of American subscribers. The ruling, which sources indicate emerged from consolidated privacy litigation, documents how the two largest U.S. carriers systematized the sale of location data through intermediary brokers, a practice that persisted despite FCC guidance prohibiting the practice without affirmative customer authorization.

What the Documents Show

The damage award represents the first major financial penalty against carriers for location data trafficking, though the amount suggests courts have calculated liability conservatively against the actual scope and duration of the exposure. AT&T and Verizon's location data sales operated through a documented infrastructure: carriers retained access to precise cell tower triangulation and GPS coordinates generated by customer devices, then licensed this data to aggregators and location brokers who packaged it for resale to law enforcement, bail bondsmen, debt collectors, and commercial marketing firms. The practice required no individual transaction authorization—customers signed blanket terms of service that buried location data monetization in pages of standard language. Internal carrier documents obtained by privacy advocates show both companies understood the distinction between data retention for network operations and data sale for revenue, yet maintained both systems in parallel. The FCC's 2016 order on customer proprietary network information (CPNI) explicitly stated that carriers could not sell location information without opt-in consent.

🔎 Mainstream angle
The corporate press either ignored this story entirely or buried it in a 3-sentence brief. The framing, when it appeared at all, focused on process rather than impact.

Follow the Money

Neither AT&T nor Verizon sought affirmative consent at scale. Instead, both companies continued operating location broker partnerships through subsidiaries and resellers, obscuring the direct corporate liability while maintaining revenue streams. The settlement amount—approximately $50 million per carrier—suggests the court calculated damages based on quantifiable subscriber harm rather than punitive multipliers, a methodology that often underprices systematic privacy violations in telecom settlements. What distinguishes this case from earlier AT&T and Verizon privacy settlements is the specificity of the infrastructure disclosed. The location data sales required active technical systems: subscriber location databases, API connections to broker partners, billing integration, and audit trails. These were not accidental data leaks or isolated employee misconduct.

What Else We Know

The systems existed because both companies built them. The FCC guidelines existed because the commission previously documented carrier abuses in the 2006 Securus case, where location data sales to prison telephone companies enabled inmate surveillance. The 2024 ruling suggests courts now view carrier location sales not as a gray area but as a documented pattern of institutional malfeasance.

Marcus Webb
The Marcus Webb Take
Surveillance State & Tech Privacy

This settlement matters less for the financial penalty than for what it confirms: major telecommunications carriers view compliance frameworks as negotiable costs, not operational constraints.

The pattern here is that AT&T and Verizon weighed FCC guidance against revenue potential and chose revenue. They built infrastructure to sell location data. They maintained that infrastructure after formal guidance prohibited it. They continued until litigation forced cessation. The $100 million penalty amounts to roughly 0.6% of their combined annual revenue—a compliance cost so modest it fails to generate meaningful deterrence.

What I find striking is the absence of individual accountability. No AT&T executive, no Verizon engineer, no program manager responsible for the location broker partnerships faces criminal liability or regulatory disqualification. The settlement flows to a class action fund, not to the agencies tasked with enforcing telecom law. This structure—corporate liability without personnel consequences—explains why similar violations resurface under different operational models.

The corporate-surveillance angle that drives reader engagement suggests audiences understand what policy discussions often obscure: carriers are not passive conduits providing network services. They are active data extraction operations that simultaneously lobby regulators who oversee them. The location data business model continues under different branding—geofencing, location analytics, "location intelligence"—because the underlying infrastructure remains intact.

Watch for the specific settlement distribution. Track whether the FCC uses this precedent to mandate technical audits of carrier data systems. Demand transparency on which agencies purchased location data during the period covered by damages. Understand that $100 million to carriers is a licensing fee for continued market access, not meaningful punishment.

Primary Sources

What are they not saying?
Who benefits from this story staying buried? Follow the regulatory filings, the court dockets, and the FOIA releases. The truth is in the paperwork — it always is.

Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.

Share
Part of our Tech & Privacy coverage
See the full picture on our Tech & Privacy hub — including our ongoing coverage of AI oversight and data privacy.
How We Report Tech & Privacy

This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (a company's own disclosure, a security researcher's published findings, a regulator's filing (FTC, EU data-protection authorities), or a data-breach notification) and reports what that source states, attributed to it — it is not security advice specific to your own devices or accounts, and does not verify a vendor's disputed claim beyond what the source states. Part of our Tech & Privacy hub. Found an error? Tell us.