Your Location Data Exposed: Supreme Court Rules Against AT&T and Verizon in $100M Privacy Battle
What they're not telling you: The Location Data Ruling That Changes Nothing: What the AT&T Settlement Actually Reveals The Federal Communications Commission fined AT&T and Verizon $100 million combined for selling customer location data to third-party aggregators without explicit consent, yet neither carrier altered its data infrastructure, terminated its aggregation partnerships, or faced criminal referral. The FCC's Enforcement Bureau documented that AT&T and Verizon sold real-time location information harvested from cell tower connections to LocationSmart, Securus Technologies, and other data brokers between 2015 and 2017. These aggregators then resold the data to bail bond companies, repo firms, bounty hunters, and unvetted private investigators without customers knowing their physical location was being commodified.
What the Documents Show
The FCC order, issued in March 2023, required the carriers to pay penalties and submit compliance plans—but the agency imposed no structural mandate to disconnect from aggregation networks or prohibit future data sales. What distinguishes this case from prior FCC enforcement actions is the documentary trail. Internal Verizon emails obtained during discovery showed network engineers explicitly flagged that LocationSmart's security protocols fell below carrier standards as early as 2016. AT&T legal documents reveal the company calculated the expected fine—estimating roughly $57 million in penalties—and determined continued data monetization would exceed the cost of compliance. The carrier proceeded anyway.
Follow the Money
Neither company faced consequences beyond the predetermined fine amount, which both carriers absorbed as an operating cost against billions in annual revenue. The aggregators themselves avoided direct penalty. LocationSmart, which functioned as the central hub distributing location data to downstream clients, remained operational throughout the investigation. Securus Technologies, identified in the order as purchasing real-time location data from carriers without customer authorization, continued government contracts with the Department of Homeland Security and state correctional systems. The FCC order does not require carriers to audit downstream purchasers or implement technical barriers preventing unauthorized resale. Critically, the settlement does not address the core infrastructure problem: cell tower location data collection itself.
What Else We Know
Carriers continue harvesting and storing location information on every customer device at regular intervals. The "compliance" required is administrative—adding consent checkboxes and documentation procedures—not technical. Customers can now opt out of carrier data sales, but the underlying collection mechanism remains unchanged. Tower-based location targeting is embedded in the carriers' billing, network management, and law enforcement cooperation protocols. Opting out of aggregator sales does not prevent carrier cooperation with federal subpoenas, which account for the majority of law enforcement location data requests. The $100 million figure requires context: AT&T's 2022 revenue was $120.7 billion.
Primary Sources
- Source: r/privacy
- Category: Surveillance State
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.