The clearest FTC location data broker ruling on the books is the January 2025 order against Gravy Analytics and its subsidiary Venntel. It bans two companies from selling something almost nobody remembers agreeing to sell: a record of where their phone has been, precise enough to show a visit to a clinic, a church or a shelter. The order was finalized on January 14, 2025, and the standard it set (that visits to certain kinds of places are sensitive data no matter how they were collected) has since been applied again, most recently in the FTC's May 2026 settlement with Kochava. If you have wondered whether your phone's location history is sitting in a company's database somewhere, these cases are the closest thing to a confirmed answer.
What the FTC location data broker case against Gravy Analytics alleged
The FTC's complaint, announced on December 3, 2024, accused Gravy Analytics and Venntel of violating the FTC Act two separate ways: selling sensitive location data unfairly, and collecting and using that data without verifiable consumer consent. Both companies sold to commercial customers and to government customers.
The scale is what makes the case notable. Gravy Analytics claimed to collect, process and curate more than 17 billion location signals a day from around a billion mobile devices. It did not gather those signals itself. The complaint says it bought them from data suppliers who offered vague confirmation, or none, that the people behind the devices had agreed to anything, and that Gravy kept using the data after learning that consent was missing.
Gravy Analytics and Venntel then used geofencing to turn that raw feed into sellable lists. They drew virtual boundaries around specific physical locations and identified every device that had crossed into them. The FTC says the companies used this to sell lists of people who had visited healthcare facilities and places of worship, plus data products that tied identifiable consumers to medical conditions, religious practices, political activity, and racial or ethnic background.
How your location gets to a broker without you handing it over
Almost nobody sits down and decides to sell their movements to a data broker. The pipeline does not need them to.
When you open a free weather app or a mobile game, that app usually does not build its own ad system. It embeds a software development kit (an SDK) from an ad or analytics vendor. That SDK requests ads, and to do that it can pass your device's location to an ad exchange so advertisers can bid, in milliseconds, on showing you something relevant to where you are. Dozens or hundreds of these auctions run per day for anyone using apps that carry such SDKs.
The companion case the FTC announced the same day, against Mobilewalla, spells out how a broker harvests from that stream. Mobilewalla collected precise location paired with more than 500 million advertising identifiers between January 2018 and June 2020, much of it from real-time bidding exchanges, and it kept the location from bid requests even when it lost the auction, which the exchanges' own terms prohibit. The weather app developer probably never meant to be a link in a location-data supply chain. The location left your phone as a by-product of loading an ad.
Geofencing is the next step, and it is simpler than it sounds. A company draws a boundary on a map, around a hospital campus or a specific church or an addiction treatment center, and queries its database for every device that pinged inside that boundary during a given window. Do that across enough places and enough devices and you get what the FTC alleged Gravy Analytics was selling: rosters of real people tied to real places they visited, built without anyone being asked.
Why clinics, churches and shelters get special treatment
The FTC did not treat all location data the same, and the distinction matters. A ping at a grocery store is mundane. A ping at a reproductive health clinic, a domestic violence shelter or a methadone clinic reveals something about a person's life that they never chose to disclose, inferred entirely from where their phone happened to be.
This is where the stakes stop being about annoying ad targeting and start being about physical safety. A geofenced list of shelter visitors is, functionally, a list that could expose people fleeing abusive partners. A list built around a clinic exposes patients making private medical decisions. A list tied to a military installation adds a national security problem on top of the personal one, and a list around a place of worship can expose someone's religion to people who might use it against them.
The order treats sensitivity as a property of the place itself. The categories the FTC listed when it announced the case: medical facilities, religious organizations, correctional facilities, labor union offices, schools and childcare, services for homeless people, domestic abuse survivors and refugees, and military installations.
What the January 2025 order requires
The Commission voted 5-0 to finalize the consent order on January 14, 2025. Four things follow from it.
Gravy Analytics and Venntel are barred from selling, disclosing or using sensitive location data in any product, with a narrow carve-out for national security and law enforcement uses. That is a near-total ban on the business line the complaint was built around.
They have to run a sensitive location data program: keep a list of sensitive location categories and screen data against it before anything is licensed or sold, rather than selling first and answering questions later.
They have to delete the historic location data they collected without consent, along with any products derived from it. Most summaries of the case leave this out, and it matters: the order does reach back in time, at least for the data still in these two companies' hands.
And they have to assess their suppliers, to check whether the people whose data they buy actually consented to its collection.
What has happened since: a hack, Mobilewalla and Kochava
Three developments since the order was proposed put it in context.
Days before the order was finalized, Gravy Analytics itself was breached. NBC News reported on January 10, 2025 that attackers claimed to have taken 17 terabytes from the company's cloud storage, and that a sample showed roughly 30 million tracked locations, including visits to government buildings, health clinics and places of worship. Gravy's parent company, Unacast, notified Norway's data protection authority of unauthorized access. In other words, a dataset the FTC had just described as unlawfully collected was, at the same moment, in criminal hands.
Mobilewalla's order was finalized the same day as Gravy's, January 14, 2025, on a 4-1 vote. It bans the company from selling sensitive location data and from collecting location out of ad auctions for any purpose beyond the auction itself, the first time the FTC had called that bid-stream harvesting an unfair practice.
Then on May 4, 2026, the FTC settled its lawsuit against Kochava, the Idaho broker it sued in August 2022 over location data from hundreds of millions of devices. The stipulated order, approved 2-0 and filed in the District of Idaho, bars Kochava and its subsidiary Collective Data Solutions from selling or sharing sensitive location data without affirmative express consent, and requires a sensitive location data program, supplier assessments, a way for consumers to see which businesses received their data and withdraw consent, and retention schedules that force deletion. The court entered the order on June 26, 2026, closing a case that had run almost four years. The template built in the Gravy case is now the FTC's standard remedy, and the agency kept using it across a change of administration.
What an FTC location data broker order doesn't fix
An order against a named company does not reach sideways into the rest of the industry.
It does not tell you whether your own location history was ever in Gravy's or Kochava's database. There is no lookup tool and no notice requirement. The deletion provisions apply to the companies' own copies; nothing recalls what customers bought before the orders, and nothing recovers what the Gravy hackers took.
It also does not touch the other location brokers running the same SDK-to-auction pipeline. Gravy, Venntel, Mobilewalla and Kochava are four names, bound by their own orders. When we pulled California's data broker registry CSV on September 1, 2026, 115 of the 603 registered brokers answered yes to collecting consumers' precise geolocation, 55 said they had sold or shared data with the federal government in the past year, and 26 said they had shared it with a foreign actor. Those are self-reported answers from one state's registry, from companies that bothered to register.
What you can do
Two levers exist, and they work on different layers.
Upstream, audit which apps hold location permission and set them to "while using" or off; that stops future contribution to the auction stream and nothing else. If you live in California, one DROP request reaches every registered broker, including the 115 that admit to collecting precise geolocation.
Downstream, the layer where location data turns into something a stranger can act on is the people-search site. Those sites do not sell ad-tech location pings; they publish address history, which is location data with the timestamps stretched to years. In our removal work, a free preview page on a site like PeopleSearchNow shows current and past addresses and relatives before any payment, and PeopleConnect's suppression tool asks for your date of birth and then sends a verification code to a phone number it already holds for the record, which is often years stale. Our data broker opt-out guide covers the sites one by one, and our guide to where brokers get your information explains why the listings come back after removal.
Delist My Data is being built for that downstream layer: filing removals across the people-search sites and re-filing when a listing regenerates. We're in pre-launch; join the waitlist for founding-member access.
Sources
- FTC takes action against Gravy Analytics, Venntel for unlawfully selling location data tracking consumers to sensitive sites (December 3, 2024)
- FTC finalizes order prohibiting Gravy Analytics, Venntel from selling sensitive location data (January 14, 2025)
- FTC case file: Gravy Analytics, Inc., In the Matter of
- FTC takes action against Mobilewalla for collecting and selling sensitive location data (December 3, 2024)
- NBC News: Location data broker Gravy Analytics was seemingly hacked, experts say (January 10, 2025)
- FTC to ban Kochava and subsidiary from selling sensitive location data (May 4, 2026)
- FTC case file: FTC v. Kochava, Inc. (stipulated order entered June 26, 2026)
- FTC finalizes order banning Mobilewalla from selling sensitive location data (January 14, 2025)
- California Privacy Protection Agency: Data Broker Registry