Attorney Generals Target Location-Data Brokers, Amicus Publishes Geolocation Opt-Out Sequence By Vendor

_8d36f887-f489-4ab5-a6d0-d338dfb94756

Vancouver, Canada — In 2025, a coalition of state attorneys general is escalating investigations into the opaque and often controversial location-data broker industry, targeting companies that collect, aggregate, and sell precise geolocation information from mobile devices, connected vehicles, and smart wearables. These enforcement actions are reshaping the debate over who controls movement data, how it may be sold, and what rights consumers have to remove themselves from commercial tracking systems.

Amicus International Consulting, a global advisory firm specializing in privacy compliance, legal identity transformation, and multi-jurisdictional data minimization strategies, has responded to this shifting regulatory environment by publishing its most detailed Geolocation Opt-Out Sequence by Vendor to date. This structured guide provides individuals, families, and businesses with a vendor-prioritized roadmap for lawfully requesting the removal of location data from commercial databases and preventing its resale.

Why Attorneys General Are Targeting Data Brokers

Location-data brokers operate in a lucrative but legally fragmented marketplace. By sourcing raw location points from mobile apps, vehicle telematics, and connected devices, brokers build detailed movement profiles on millions of individuals. These profiles can reveal sensitive patterns, including home addresses, workplace locations, healthcare visits, religious attendance, and social activities.

Over the last two years, investigative reports have shown that some brokers sell data to buyers with no meaningful due diligence, including advertisers, political intelligence firms, and, in some instances, entities with government contracts that may provide indirect law enforcement access.

Recent enforcement actions have cited the following violations:

  • Lack of Consent — Collecting or selling location data without obtaining explicit, informed consent from consumers.

  • Misleading Anonymization Claims — Promising that location data is anonymized when, in fact, unique movement patterns make re-identification possible.

  • Failure to Honor Deletion Requests — Ignoring or delaying consumer opt-out and deletion requests beyond statutory timelines.

  • Unauthorized Resale — Selling location data to third parties not disclosed in privacy policies.

State-by-State Enforcement Landscape in 2025

Several states are now using their consumer protection laws and new privacy statutes to bring cases against data brokers:

  • California — The Attorney General has filed multiple CCPA enforcement actions against brokers for selling precise GPS data without proper notice and opt-out mechanisms. Settlements have included multimillion-dollar penalties and mandated third-party audits.

  • New York — Leveraging deceptive practices laws, the state has focused on companies misrepresenting the extent to which location data is anonymized.

  •  Massachusetts — The AG’s office is targeting brokers who failed to respond to deletion requests within the 45-day statutory period under state privacy law.

  • Texas — A multi-case investigation is underway into brokers allegedly selling data to bounty hunters and private investigators without adequate contractual restrictions.

  • Oregon — State authorities have issued cease-and-desist orders to smaller brokers found reselling sensitive location data of political demonstrators.

Historical Context: How the Location-Data Industry Grew

The commercial location-data industry evolved alongside the smartphone revolution. Initially, location sharing was framed as a convenience feature for navigation, ride-hailing, and local recommendations. Over time, the advertising technology sector realized that location was one of the most valuable behavioral indicators available.

By the mid-2010s, thousands of apps integrated third-party software development kits (SDKs) that collected GPS coordinates in the background, often continuing after the app was closed. This data was then funneled to brokers who could stitch together months or years of movement history. The industry operated mainly in the shadows, with little consumer awareness and minimal regulation.

The introduction of state-level privacy laws like the CCPA and VCDPA began to create legal friction for these practices. However, the fragmented nature of U.S. privacy law means that compliance standards vary dramatically between states, creating opportunities for brokers to shift operations toward less restrictive jurisdictions.

The Privacy Risks in Real-World Terms

While the sale of anonymized data is often presented as low risk, multiple academic studies have shown that location trails can be re-identified with startling ease. For example, knowing just a few visited locations can be enough to match an anonymous dataset to a named individual.

Risks include:

  • Revealing attendance at political protests or labor organizing meetings.

  • Identifying visits to mental health clinics or addiction treatment centers.

  • Mapping children’s school routes and recreational activities.

  • Tracking movements of domestic violence survivors seeking safety.

Amicus’s Geolocation Opt-Out Sequence by Vendor

Amicus’s new guide organizes more than 150 location-data brokers into a sequence designed for maximum impact and efficiency. The process is divided into three tiers:

  1. Tier One — High-Volume Aggregators
    These brokers have the largest market share and tend to source from a wide variety of app categories. Removing your data from this tier can immediately reduce overall exposure.

  2. Tier Two — Industry-Specific Brokers
    These companies focus on particular verticals, such as automotive telematics, retail analytics, or event marketing. Opt-outs here reduce targeted data flows linked to specific behaviors.

  3. Tier Three — Secondary Resellers
    These entities often buy from primary brokers and resell to niche markets. They may re-acquire deleted data if upstream sources are not addressed.

The guide includes:

  • Direct opt-out links and submission instructions.

  • Required identification and verification procedures.

  • Notes on vendors that require mailed or notarized requests.

  • Recommended timelines for resubmitting deletion requests to prevent re-collection.

Case Study 1: Healthcare Professional

A nurse practitioner in New York City regularly traveled between multiple clinic locations. Concerned that patient-related travel patterns could be inferred from her movements, she engaged Amicus to implement the opt-out sequence. Within 90 days, over 70 percent of commercial location records tied to her devices were deleted. Ad targeting related to healthcare dropped sharply, and follow-up audits showed no resale of her data by primary brokers.

Case Study 2: Cross-Border Commuter Family

A Vermont family with daily work commutes into Quebec discovered that multiple brokers were selling location data from vehicle telematics systems and smartphone apps. Amicus applied the opt-out sequence, combined with device-level location permission reviews, reducing cross-border data exposure by over half in the first 60 days.

Case Study 3: Public Figure

A California state legislator sought to restrict public access to travel patterns associated with official meetings. Using the opt-out sequence, Amicus targeted high-volume aggregators first, then narrowed the focus to political intelligence brokers. This approach reduced the number of commercially available data points tied to the legislator’s official vehicle by more than 80 percent.

Consumer Rights Under State Privacy Laws

In states with comprehensive privacy laws, consumers generally have rights to:

  • Request deletion of personal data, including geolocation.

  • Request disclosure of categories and specific pieces of data collected.

  • Opt out of the sale or sharing of personal data.

  • Receive a response within statutory timeframes, typically 30 to 45 days.

However, the rights only apply to covered entities meeting certain thresholds (e.g., revenue or data volume), and many brokers operate in gray areas. Enforcement by attorneys general is currently the primary mechanism for ensuring compliance.

Enforcement Patterns and Penalties

Recent settlements have included:

  • Monetary fines ranging from $500,000 to $5 million.

  • Mandatory implementation of consent management platforms.

  • Prohibitions on selling specific categories of location data.

  • Third-party compliance audits for up to five years.

International Comparisons

The European Union’s General Data Protection Regulation (GDPR) treats geolocation as personal data, requiring explicit consent for processing and granting strong deletion rights. Canada’s proposed Bill C-27 would similarly classify precise location data as sensitive, subject to heightened consent requirements. These models provide a more uniform framework than the current U.S. patchwork.

Amicus’s Strategic Recommendations Beyond Opt-Outs

  • Audit mobile app permissions quarterly to ensure only necessary apps have location access.

  • Use operating system privacy features to block background collection.

  • Prefer apps with clear, narrow privacy policies that prohibit data resale.

  • Where lawful, consider location randomization tools to obscure precise coordinates.

Looking Ahead

Amicus anticipates that as more attorneys general pursue enforcement, brokers will consolidate and adopt more standardized consent and deletion systems. However, without federal legislation, consumers will still need to navigate state-specific rights and procedures. The firm will continue to update its Geolocation Opt-Out Sequence quarterly to reflect enforcement outcomes, new vendor entries, and changes in opt-out procedures.

Conclusion

Location-data brokerage has shifted from an invisible background process to a significant front in the privacy rights debate. State enforcement actions are reshaping industry practices, but immediate protection still depends on consumer initiative. Amicus’s vendor-prioritized opt-out sequence equips individuals and organizations to take practical, lawful steps toward reclaiming control over their movements in the commercial data economy.

Contact Information
Phone: +1 (604) 200-5402
Email: [email protected]
Website: www.amicusint.ca

Anton Stravinsky

Anton Stravinsky

Anton Stravinsky is an associate correspondent for Tri-City News, BC. CanadaStravinsky focuses on international finance, banking, and asset management trends across Europe and Asia for Markets.Before his current role, Stravinsky completed Bloomberg's journalism fellowship, contributing stories to Bloomberg's digital and broadcast platforms. He originally joined Bloomberg as a summer intern covering financial markets and global economies in 2017.Stravinsky’s prior experience includes internships with Reuters' business desk in London, CNBC's Squawk Box Europe, and The Financial Times' editorial team.He earned a bachelor's degree in economics and journalism from New York University, where he served as senior editor for the university’s independent news outlet, Washington Square News.