Your Phone’s Ad Data Is Giving Your Location to Border Patrol — and It’s Perfectly Legal

CBP has been purchasing Americans' location data from ad-tech brokers, bypassing warrant requirements. The EFF's latest report details how the targeted advertising supply chain feeds government surveillance — and why the industry bears responsibility.
Your Phone’s Ad Data Is Giving Your Location to Border Patrol — and It’s Perfectly Legal
Written by Dave Ritchie

Customs and Border Protection has been buying your location data from advertising companies. Not through warrants. Not through court orders. Through the commercial ad-tech pipeline that tracks your phone every time an app pings your GPS coordinates. The Electronic Frontier Foundation laid this out in a detailed March 2026 report, and the implications for privacy — and for the ad industry — are serious.

Here’s how it works. Every time you open an app that serves targeted ads, a real-time bidding process kicks off. Your device broadcasts a bid request containing your approximate or precise location, device identifiers, and sometimes demographic information to dozens or hundreds of potential advertisers. Most of those advertisers don’t win the bid. But they still get the data. That data gets aggregated, repackaged, and sold by data brokers to anyone willing to pay — including U.S. government agencies.

CBP has been a willing buyer.

The EFF’s report traces how CBP contracted with commercial data brokers like Venntel (now part of Gravy Analytics) to obtain bulk location data harvested from ordinary smartphone apps. This isn’t speculative. Government contracts, FOIA documents, and prior reporting from The Wall Street Journal and Vice’s Motherboard have documented these purchases going back years. What the EFF adds is a sharper picture of how the ad-tech supply chain makes this not just possible but trivially easy.

No warrant required. That’s the part that should bother everyone in this industry.

The Fourth Amendment protects against unreasonable government searches. The Supreme Court’s 2018 Carpenter v. United States decision established that the government generally needs a warrant to access historical cell-site location information from carriers. But CBP and other agencies have argued — successfully, so far — that purchasing commercially available data doesn’t count as a search. The logic: if you’ve already “shared” your location with an app, and that app shared it with ad exchanges, and those exchanges shared it with brokers, then the government is just buying what’s already on the open market.

It’s a loophole big enough to drive a surveillance apparatus through.

The EFF argues this end-run around Carpenter is exactly the kind of thing the ruling was supposed to prevent. Location data reveals where people sleep, where they worship, who they visit, whether they’ve been to a protest or a clinic. The granularity is staggering — often accurate to within a few meters. And the volume is massive. Gravy Analytics and similar firms collect billions of location pings daily from hundreds of thousands of apps.

So who’s affected? Practically everyone with a smartphone. But the EFF’s report focuses on how CBP has used this data specifically for immigration enforcement — tracking people near the southern border, monitoring movement patterns, and identifying individuals at shelters and sensitive locations. Communities already under heightened surveillance bear the heaviest burden.

The ad industry’s role here isn’t incidental. It’s structural. Real-time bidding was designed to share user data as widely as possible to maximize ad revenue. Privacy was never a design constraint. The entire system operates on the assumption that more data flowing to more parties produces better ad targeting and higher CPMs. Government surveillance is an externality that the industry has shown little interest in addressing on its own.

Some things have changed. Google has moved to restrict advertising IDs on Android, and Apple’s App Tracking Transparency framework, introduced in 2021, gave iPhone users the ability to opt out of cross-app tracking. But opting out isn’t the default everywhere, and plenty of apps still collect and transmit location data through SDKs embedded deep in their code. The data broker market remains enormous and largely unregulated at the federal level.

Congress has noticed, at least intermittently. The Fourth Amendment Is Not For Sale Act, reintroduced multiple times, would prohibit government agencies from purchasing data that would otherwise require a warrant. It has bipartisan support in theory. In practice, it hasn’t passed. The EFF and other civil liberties organizations have pushed for its passage, but momentum stalls against national security arguments and industry lobbying.

And the FTC? It’s taken some action. In 2024, the agency brought an enforcement action against Gravy Analytics and Venntel for collecting and selling sensitive location data, including data linked to healthcare facilities, religious sites, and military installations. But enforcement actions against individual brokers don’t fix the underlying architecture. The pipes are still open.

For industry professionals — product managers, ad-tech engineers, app developers — this report is a direct challenge. If your app collects location data and participates in programmatic advertising, your users’ movements may end up in a government database. Not hypothetically. Demonstrably. The EFF’s documentation makes the chain of custody clear enough that ignorance isn’t a credible defense anymore.

What can be done? The EFF recommends legislative action to close the data broker loophole, stronger FTC enforcement, and technical changes to the bidding process that minimize data leakage. On the individual level, they suggest disabling location services for apps that don’t need them and using ad blockers. But individual action can only go so far when the system itself is designed to extract and distribute personal data at scale.

This isn’t a new problem. But the EFF’s latest reporting crystallizes something that’s been true for years: the advertising industry built a global surveillance infrastructure, and governments are happy to rent access. The question is whether anyone with the power to change that actually will.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us