2 min read

The FTC just proved a settlement can end a data broker's harm without ending its punishment- 235

The FTC just proved a settlement can end a data broker's harm without ending its punishment- 235

May 4, 2026

The Federal Trade Commission has settled with Kochava, a data broker the agency had accused of quietly reshaping the boundary between legal advertising analytics and mass surveillance — selling precise, near-real-time geolocation data accurate to within 10 meters, including consumers' visits to houses of worship and health care clinics, without their knowledge or consent. The settlement bars future violations and imposes new compliance obligations, but notably carries no fine, closing a legal battle that began under a very different FTC than the one that just resolved it.

The case traces back to a 2022 lawsuit filed while Lina Khan, appointed by the Biden administration, chaired the agency — itself a relatively rare instance of the FTC choosing to litigate against a data broker rather than settle quietly or decline to pursue the matter at all. The underlying 2023 complaint described a company harvesting far more than advertising identifiers: consumers' yearly incomes, mobile device IDs, granular app usage patterns, and geolocation data precise enough to reconstruct where someone worships or seeks medical care, all sold onward without the explicit consent the FTC argued the law required. That combination — location precision fine enough to infer sensitive personal circumstances, paired with a business model built on reselling it to unnamed third parties — is precisely the pattern privacy researchers and national security analysts alike have flagged as a structural vulnerability: data that would require a warrant to obtain through traditional surveillance channels can instead simply be purchased on the open commercial data market, available to any buyer with the funds, foreign intelligence services included.

The settlement itself is more incremental than transformative, since Kochava had already agreed, as part of a separate class-action settlement in November, to stop selling sensitive location data and to build a consumer opt-out mechanism. What the FTC agreement adds is procedural infrastructure: a sensitive-location-data cataloguing program designed to flag data that should never be sold, a "supplier assessment" regime meant to verify that consumer consent was actually obtained before data changes hands, a requirement to alert the FTC if a third party violates the settlement's terms, and a data retention schedule mandating deletion within a defined timeframe. Kochava must also disclose to consumers, on request, which specific businesses or individuals purchased their precise location data — a transparency requirement that, if actually enforced, would represent one of the more concrete accountability mechanisms yet imposed on the commercial data-broker industry.

What the case leaves unresolved is the broader question it was never really equipped to answer: a settlement against one broker does not address the dozens of others operating the same business model, nor does it change the underlying legal reality that selling aggregated, "anonymized," or consent-adjacent location data remains largely permissible in the U.S. absent sector-specific legislation. For an industry built on exactly the kind of bulk behavioral data that intelligence services, stalkers, and authoritarian governments abroad have all been documented purchasing when direct surveillance access isn't available, a company-specific consent decree — however detailed its compliance terms — treats the symptom of one bad actor while leaving the market structure that produced it fully intact.