11.4 Privacy Risks and Impacts of Location Tracking

Key Takeaways

  • Location can be derived from GPS, cell-tower timing, Wi-Fi probe requests, Bluetooth beacons, and IP addresses; MAC address randomization limits passive Wi-Fi tracking.

  • Four spatio-temporal points were enough to identify about 95 percent of people in a large mobile location dataset, so pseudonymous location traces are rarely anonymous.

  • In Chatrie v. United States (June 29, 2026), the Supreme Court held that obtaining two hours of a person's Google Location History is a Fourth Amendment search requiring a warrant.

  • The FTC's 2024 orders against X-Mode/Outlogic, InMarket, Gravy Analytics, and Mobilewalla restricted the sale of sensitive location data such as visits to clinics and places of worship.

  • Obfuscation options include coordinate truncation, geohash grids, trajectory k-anonymity, geo-indistinguishability using planar Laplace noise, and dummy queries.

Last updated: October 2026

11.4 Privacy Risks and Impacts of Location Tracking

Quick Summary: A record of where someone goes reveals where they live, work, worship, seek medical care, and protest. Location data is gathered from GPS, cell networks, Wi-Fi, Bluetooth beacons, and IP addresses, and it is sold through a large broker market. The BoK asks technologists to understand these risks; the engineering response is to collect location only at the precision and frequency a feature needs, keep it briefly, never sell or share sensitive visits, and apply obfuscation techniques when location must be analyzed.

Location is one of the few data types that is both highly identifying (a few points single out most people) and highly sensitive (it reveals health, religion, and associations). Many privacy laws now classify precise geolocation as sensitive data; under the CCPA, "precise geolocation" means data that locates a consumer within a circle with a radius of 1,850 feet.


Location Surveillance Mechanisms

Location data provides a granular map of an individual's life. Revealing an individual's physical coordinates over time exposes intimate details: home address, workplace, medical clinics visited, religious institutions attended, and political rallies participated in.

1. Physical Location Tracking Vectors

  • GPS / GNSS Trilateration: Satellites broadcast high-precision timestamps. A device measures the Time of Arrival (TOA) from at least 4 satellites to resolve latitude, longitude, elevation, and clock drift. Accuracy: 3 to 10 meters outdoors. GPS is passive (the device receives satellite radio signals without transmitting back to space), but client apps report coordinates back to servers.
  • Cell Tower Triangulation and Timing Advance: Mobile base transceiver stations (BTS) log device connections. Cellular carriers record Cell Global Identity (CGI) and Timing Advance (TA)—the round-trip signal propagation delay between the handset and tower. By combining signal strengths from multiple adjacent cell towers (Angle of Arrival [AoA] and Observed Time Difference of Arrival [OTDOA]), carriers calculate device coordinates within 50 to 300 meters without client GPS cooperation. Data is logged in carrier Call Detail Records (CDRs).
  • Wi-Fi MAC Address Probe Request Sniffing: When Wi-Fi is active, devices periodically transmit IEEE 802.11 probe request frames to discover known networks (SSIDs). Probe frames include the device's hardware 48-bit MAC address. Retail analytics companies install physical Wi-Fi sniffers throughout stores and cities to log probe requests, tracking consumer footpaths and store dwell times.
    • Operating System Defenses: Modern operating systems (iOS, Android, Windows) implement MAC Address Randomization. The OS generates a randomized, rotating pseudo-MAC address with the "locally administered" bit set (b1 = 1) whenever scanning for networks, preventing static physical beacon tracking.
  • Bluetooth Low Energy (BLE) Beacons: Small transmitters broadcasting identifiers (UUID, Major, Minor) via iBeacon or Eddystone protocols. When a smartphone running a partner app passes within range, the app detects proximity (ranging from <0.5m to 10m) based on Received Signal Strength Indication (RSSI), logging exact indoor positioning.

2. Geofence Warrants and Reverse Searches

A geofence warrant (or reverse location warrant) inverts traditional law enforcement investigative procedures:

Traditional Search Warrant                      Geofence (Reverse Location) Warrant
+---------------------------------------+       +---------------------------------------+
| 1. Establish probable cause on a      |       | 1. Define physical geographic boundary|
|    KNOWN SUSPECT                      |       |    and time window (e.g., crime scene)|
| 2. Request data relating to that      |       | 2. Compel database provider (e.g.,    |
|    named individual.                  |       |    Google Sensorvault) to search all  |
|                                       |       |    devices present in that geofence.  |
|                                       |       | 3. Sift through thousands of innocent |
|                                       |       |    bystanders to identify suspects.   |
+---------------------------------------+       +---------------------------------------+

Geofence warrants divided the federal appeals courts until the U.S. Supreme Court decided Chatrie v. United States on June 29, 2026. In a 6–3 opinion by Justice Kagan, the Court held that obtaining even two hours of a person's Google Location History is a Fourth Amendment search, extending Carpenter v. United States (2018): location history is not truly "shared" with a provider just because a phone generates it. The Court did not decide whether the three-step geofence warrant used in the case satisfied probable cause and particularity, and remanded that question. Engineering choices also shape what can be compelled: after Google moved Google Maps Timeline data to on-device storage (announced December 2023), it no longer holds a central Location History database that a geofence warrant could search.


Location Obfuscation Engineering

Privacy technologists implement mathematical techniques to protect location privacy while preserving application functionality.

1. Spatial Cloaking and Precision Truncation

Spatial cloaking reduces coordinate granularity before data leaves the device:

  • Coordinate Truncation: Truncating latitude and longitude decimal places:
    • 6 decimal places ≈0.11 meters\approx 0.11\text{ meters} (identifies an individual chair).
    • 4 decimal places ≈11 meters\approx 11\text{ meters} (identifies a house or store).
    • 2 decimal places ≈1.1 kilometers\approx 1.1\text{ kilometers} (identifies a neighborhood or city district).
  • Geohashing and Grid Aggregation: Mapping coordinates into coarse geographic bounding boxes (e.g., Geohash precision 5, covering ≈4.9 km×4.9 km\approx 4.9\text{ km} \times 4.9\text{ km}). Applications such as weather forecasts require only coarse city-level resolution and should never capture high-precision decimal coordinates.

2. Trajectory k-Anonymity

An individual's sequence of spatio-temporal coordinates (a trajectory) forms a unique fingerprint. Studies show that just 4 spatio-temporal points are sufficient to uniquely identify 95% of individuals in a mobile location dataset.

Trajectory kk-Anonymity ensures that for every reported path, there exist at least k−1k-1 other individuals whose spatio-temporal trajectories are indistinguishable within the same spatial-temporal corridor. Systems achieve this by suppressing rare trajectory points, swapping trajectory segments, or clustering overlapping routes.

3. Geo-Indistinguishability and Planar Differential Privacy

To provide formal mathematical privacy guarantees, researchers developed Geo-Indistinguishability—the adaptation of ϵ\epsilon-differential privacy to geographic coordinates. Geo-indistinguishability ensures that an adversary observing an obfuscated location cannot determine the user's actual location within a privacy radius rr with high confidence.

Systems implement geo-indistinguishability by adding planar Laplace noise to coordinates in polar form:

PDF(r,θ)=ϵ22πre−ϵrPDF(r, \theta) = \frac{\epsilon^2}{2\pi} r e^{-\epsilon r}

  • The angle θ\theta is chosen uniformly at random from [0,2π)[0, 2\pi): θ∼Uniform(0,2π)\theta \sim \text{Uniform}(0, 2\pi)
  • The noise radius rr is drawn from a Gamma distribution Γ(2,ϵ)\Gamma(2, \epsilon): r=−1ϵ(W−1(p−1e)+1)r = -\frac{1}{\epsilon} \left( W_{-1} \left( \frac{p - 1}{e} \right) + 1 \right) (where W−1W_{-1} is the Lambert WW function and p∼Uniform(0,1)p \sim \text{Uniform}(0, 1))

The perturbed coordinate z=(xactual+rcos⁡θ,yactual+rsin⁡θ)z = (x_{\text{actual}} + r\cos\theta, y_{\text{actual}} + r\sin\theta) is transmitted to the location-based service provider. The privacy parameter ϵ\epsilon controls the privacy-utility tradeoff: smaller ϵ\epsilon values inject larger noise radii, providing stronger privacy guarantees at the cost of spatial accuracy.

4. Dummy Query Generation

When querying a location-based service (e.g., searching for nearby restaurants), the client generates m−1m - 1 synthetic, realistic "dummy" locations alongside the true user coordinate, transmitting all mm queries simultaneously. The server returns results for all mm locations, and the client discards the dummy responses locally. An external eavesdropper or untrusted server cannot determine which of the mm queries represents the user's authentic location, reducing identification probability to 1m\frac{1}{m}.


The Location Data Broker Problem

Much location data reaches third parties through software development kits (SDKs) embedded in ordinary apps (weather, games, prayer, and coupon apps) and through real-time ad bidding. Brokers aggregate it into datasets that can be searched by place: who visited a clinic, a shelter, a place of worship, or a protest.

The U.S. Federal Trade Commission has treated the sale of sensitive location data as an unfair practice:

  • X-Mode Social / Outlogic (January 2024): the first FTC order banning a data broker from selling or sharing sensitive location data, such as visits to medical facilities, places of worship, and domestic-violence shelters.
  • InMarket Media (January 2024): banned from selling or licensing precise location data.
  • Gravy Analytics and Mobilewalla (December 2024): orders restricting the collection and sale of sensitive location data, including data harvested from real-time ad auctions.
  • Kochava: an FTC lawsuit filed in 2022 alleging that selling precise location data exposed visits to sensitive places.

Controls for Teams That Collect Location

ControlExample
Ask only when neededRequest "while using the app" permission at the moment a location feature is used, not at install
Prefer approximate locationiOS 14 and Android 12 let users grant approximate location; design features to work with it
Reduce frequencySample only when the user acts, not continuously in the background
Process on deviceCompute "near a store" on the phone and send only the result
Short retentionKeep raw traces for hours or days, then aggregate or delete
Sensitive-place filteringDrop points near clinics, shelters, and places of worship before any analysis or sharing
No sale, careful sharingDo not sell location data; contractually ban SDK partners from reselling it, and test what SDKs transmit
Law-enforcement request processAfter Chatrie (2026), require a warrant for location history and minimize what is stored so less can be compelled

These controls follow the same minimization logic as the rest of the CIPT: the safest location record is one that was never collected at full precision or was deleted soon after use.

Test Your Knowledge

A mobile ride-sharing platform needs to aggregate driver and passenger location coordinates for traffic analysis without revealing individual pickup points or compromising spatial utility. Which privacy engineering technique injects calibrated two-dimensional planar Laplacian noise to provide mathematical geo-indistinguishability?

A

Truncating GPS coordinate floating points to exactly seven decimal places to disguise residential addresses.

B

Transmitting location coordinates exclusively over cleartext UDP packets to prevent connection state tracking.

C

Applying differential privacy noise to polar coordinates where the noise radius is drawn from a Gamma distribution and the angle is chosen uniformly at random.

D

Rotating the server database encryption keys every 24 hours while retaining unmasked latitude and longitude values for analysis.

Test Your Knowledge

A weather app requests continuous background GPS access and shares raw coordinates with an advertising SDK partner. Which redesign best reduces the privacy risk while keeping the forecast feature?

A

Encrypt the coordinates before sending them to the SDK partner, which then decrypts them on its own servers for ad targeting.

B

Raise the GPS sampling rate so forecasts are more accurate.

C

Request foreground-only approximate location, round it on the device, and stop sharing it with the ad SDK.

D

Keep the design but publish a more detailed privacy policy.

Test Your Knowledge

Which statement best reflects the U.S. Supreme Court's June 2026 decision in Chatrie v. United States?

A

Getting even two hours of Location History is a search needing a warrant; the geofence warrant's validity was left open.

B

Geofence warrants are always unconstitutional general warrants and can never be used.

C

Location data stored by a technology company is not protected by the Fourth Amendment because users voluntarily shared it with a third party.

D

The decision applies only to cell-tower records held by telephone carriers, not to app-based location history.

Sections you finish are checked off in the contents.