What the FTC’s Kochava order means for location-data privacy
A stipulated order filed in federal court in the Federal Trade Commission’s Kochava case sets detailed limits on how Kochava Inc. and its subsidiary, Collective Data Solutions, LLC, may handle sensitive location information. The FTC’s case page still lists the matter as pending, so the June 25, 2026 filing should not be described as a later court-approved permanent injunction unless the docket confirms that status.
The order was filed in the U.S. District Court for the District of Idaho on June 25. The FTC’s case timeline records it as a June 26 development. It resolves the matters in dispute through agreed obligations, but the defendants neither admit nor deny the complaint’s allegations except where the order specifically says otherwise.
What data and places are covered
The order focuses on “Precise Location Data,” including information that may reveal a mobile device’s or consumer’s location through GPS coordinates, cell-tower information, Wi-Fi identifiers or Bluetooth signals. It also covers persistent identifiers, such as mobile advertising identifiers, when combined with that location information.
“Sensitive Locations” are locations in the United States associated with medical facilities; religious organizations; places held out as primarily providing education or childcare services to minors; temporary shelters or social-service locations for homeless people or survivors of domestic violence; and military or federal law-enforcement installations, offices or buildings.
The order excludes data that reveals only coarse location, such as a ZIP code or census-block location with a radius of at least 1,850 feet. It also excludes location information used for defined security purposes, federal national-security purposes and law-enforcement responses to an imminent risk of death or serious bodily harm.
The central restriction
The order generally bars Kochava and Collective Data Solutions from selling, licensing, transferring, sharing or disclosing sensitive-location data associated with sensitive locations identified through the required program.
There is a narrow exception. The restriction does not apply when the company has a direct relationship with the consumer related to the data, the consumer has provided affirmative express consent, and the data is used to provide a service the consumer directly requested.
That exception is narrower than a general permission to sell location data. The order ties the activity to a direct consumer relationship, a defined consent process and a service the consumer specifically requested.
What counts as valid consent
“Affirmative Express Consent” must be freely given, specific, informed and unambiguous. Before agreeing, the consumer must receive a clear and conspicuous disclosure identifying the categories of information collected, the purposes for collection, use or disclosure, the types of entities receiving the information and an easily located way to withdraw consent.
The disclosure must be separate from a privacy policy, terms of service, terms of use or similar document. The order also says consent cannot be inferred from hovering over, muting, pausing or closing content. A user interface that subverts or impairs consumer autonomy, decision-making or choice cannot be used to obtain consent under the order.
Compliance programs and supplier checks
Within 90 days of the order’s entry, Collective Data Solutions must establish and maintain a written Sensitive Location Data Program. The program must identify a senior officer, such as a chief privacy or compliance officer, who is approved by and reports to the board or principal executive officer.
The program must develop a comprehensive list of sensitive locations, document how locations are identified, assess and update the list at least every three months, and consider whether newly identified categories should be added. The companies must also maintain policies and technical controls to prevent prohibited disclosures and test those controls at least quarterly. The program itself must be evaluated at least annually.
The order separately requires a Supplier Assessment Program for location data obtained from third parties. The program must assess suppliers initially and annually, when applicable, to confirm that consumers consented to the collection and use of the supplied location data. If consent cannot be confirmed, the companies must stop using, selling, licensing, transferring, sharing or disclosing that data.
Deletion, de-identification and incident reporting
For covered sensitive-location data associated with locations on the required list, the companies must begin deleting the data or rendering it non-sensitive within two days after determining that consent has not been confirmed. The process generally must be completed within 30 days. Documented extensions may add 30-day periods, up to a total of 90 days, and the data cannot be used or disclosed while that process is underway.
The order also addresses historical location data collected before the order without affirmative express consent. Within 90 days of the order’s entry, the defendants generally must de-identify or render that historical data non-sensitive, unless they have records showing that consumers consented to its collection, use and disclosure.
Consumers must receive a clear way to request the identity of any known recipient of their precise location data. The order allows an alternative process in which the companies provide a way to request deletion from recipients, require or instruct those recipients to honor the requests, seek written confirmation and provide the consumer with written confirmations no later than 90 days after receiving the request.
Consumers must also have a simple, easily located way to withdraw consent. After receiving notice through that process, the defendants generally must stop using and disclosing precise location data associated with the device within 30 days.
For previously collected precise location data held by Collective Data Solutions, the order requires a clear deletion-request process and generally requires deletion within 30 days of the request. This is an obligation arising from this specific order, not a general federal right for every consumer to delete all data held by every company.
If a third party shares the defendants’ precise location data in violation of a contractual requirement, the company must report the incident to the FTC within 30 days after determining that it occurred. The report must include available information about the timing, affected data, number of consumers and steps taken to limit further exposure.
What consumers can do now
- Review app permissions. Limiting location access may reduce future collection, but changing a phone setting does not necessarily remove historical data already collected or shared.
- Look for specific consent language. A broad privacy-policy statement is not the same as the affirmative express consent described in this order.
- Save consent and withdrawal records. Keep screenshots or confirmation emails if an app or service provides them.
- Ask about recipients or deletion. The order requires covered companies to provide a clear process for recipient-identity requests and precise-location deletion requests, subject to the order’s verification and alternative-deletion provisions.
- Watch for later court-record updates. The FTC case page currently lists the case as pending, so later docket entries may clarify the order’s status or implementation.
The June filing is a significant enforcement development because it puts detailed consent, location-screening, supplier-review, deletion, access and incident-reporting requirements into a court-filed order. But consumers should not assume that everyone whose data may have been handled by Kochava automatically receives money, a notice or a private legal claim.
Sources
- Stipulated Order for Injunction and Other Relief, FTC v. Kochava Inc.
- The Record: FTC bans data broker Kochava from selling sensitive location info
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.