US data protection

The FTC's Kochava Settlement Shows the Location-Data Fix Is Consent Architecture, Not an Ad-Tech Ban

An EFF report on default location-sharing SDKs strengthens the case for FTC-style consent gates on sensitive data, not a ban on mobile advertising.

Default Location Sharing at Ad-SDK Scale People of Internet Research · US 2B+ InMobi user reach Users reachable via apps embedding… 1.5B / 10K+ HyBid users and apps Verve's HyBid claims 1.5 billion u… 85,000+ Petal Ads app footprint Number of apps worldwide embedding… 5 Sensitive site categories protected Location categories covered by the… peopleofinternet.com
Default Location Sharing at Ad-SDK Sca… People of Internet Research · US 2B+ InMobi user reach 1.5B / 10K+ HyBid users and apps 85,000+ Petal Ads app footprint 5 Sensitive site categories prote… peopleofinternet.com

Key Takeaways

A Real Harm, Documented in Detail

An Electronic Frontier Foundation report published August 4, 2026 found that four widely embedded Android advertising SDKs — InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads — collect and forward users' precise location by default whenever the host app already holds location permission. Scale matters here: InMobi is embedded in apps reaching over 2 billion users, HyBid claims 1.5 billion users across more than 10,000 apps, BidMachine reports 600 million direct SDK users, and Petal Ads ships in more than 85,000 apps worldwide. EFF documented two representative cases — a QR Scanner app with 50 million-plus downloads and a GPS Speedometer app with 10 million-plus downloads — where location data flowed to advertising networks with no separate disclosure to the user.

The consequences EFF cites are not abstract. The report ties advertising-sourced location data to ICE investigations, global surveillance tooling, the outing of a gay priest, tracking of union organizers, and tracking of U.S. military personnel. This is the steelman case for aggressive intervention, and it deserves to be taken seriously: a data pipeline built for ad targeting has become a de facto surveillance infrastructure that reaches well beyond any purpose a user consented to, and it does so precisely because consent was never meaningfully obtained. App-level location permission — the toggle a user actually sees — was never designed to authorize a chain of downstream sharing with brokers who resell to buyers a user will never know about.

Why This Is a Defaults Problem, Not an Advertising Problem

The mechanism EFF describes is specific: SDKs inherit whatever permission the host app already has, set location-sharing on by default, and bury the opt-out in developer documentation most app publishers never read. Financial incentives compound this — SDKs advertise higher ad revenue when location targeting is enabled, so the default that benefits the SDK vendor is the default that ships. That is a design and disclosure failure, not an indictment of location-based advertising as a category.

The distinction matters because the federal government's own recent enforcement record shows the proportionate fix already working. On May 4, 2026, the FTC announced a settlement with data broker Kochava and its subsidiary Collective Data Solutions banning the sale of sensitive location data — location tied to medical facilities, religious organizations, schools and childcare providers, domestic violence shelters, and military or federal law enforcement installations — unless the company obtains a consumer's affirmative express consent tied to a service the consumer actually requested. The order also requires a consent-verification program, incident reporting to the FTC, and a consumer right to learn who received their data. That settlement followed the FTC's January 2024 actions against X-Mode Social and InMarket — the agency's first outright bans on selling precise location data — and its December 2024 actions against Gravy Analytics (Venntel) and Mobilewalla over sales of location data tied to sensitive sites such as reproductive health clinics and places of worship.

Four enforcement actions in under two years, each targeting the same failure mode: sensitive location data changing hands without a consumer ever affirmatively agreeing to it.

The Case for Targeted Rules Over a Behavioral-Advertising Ban

EFF's report goes further than documenting the problem — it also calls for banning behavioral advertising outright. That is where the proportionate-regulation case diverges from EFF's. A blanket ban on behavioral advertising would eliminate the business model funding the free apps, including the very ones cited in the report, in order to fix a problem that is narrower and more precisely targetable: default settings and consent design for a specific category of sensitive data. The FTC's Kochava, X-Mode, and Gravy Analytics orders demonstrate that Section 5's existing unfairness authority can force default-off, opt-in-only handling of sensitive location categories without touching the broader ad-supported internet.

The honest gap is that FTC enforcement is case-by-case, reaching one data broker or platform at a time, while the underlying SDK layer EFF examined operates industry-wide and largely below the FTC's current caseload. Comprehensive federal privacy legislation — most recently the American Privacy Rights Act, whose civil-rights provisions were stripped in June 2024 markup before the bill lapsed with the 118th Congress and was never reintroduced — would let Congress codify the Kochava standard (affirmative express consent for sensitive location categories) as a baseline applying to every SDK vendor, not just the ones the FTC happens to sue. Absent that, app publishers who embed InMobi, BidMachine, HyBid, or Petal Ads should treat the EFF findings as a compliance flag now: California, Colorado, and other state comprehensive privacy laws already impose sensitive-data consent requirements that these SDK defaults likely violate, FTC precedent notwithstanding.

The policy lesson isn't that mobile advertising is incompatible with privacy. It's that a consent chain running from a phone's location toggle through an SDK to a data broker to whoever pays for access has too many silent links. Congress and the FTC have already found the fix — force affirmative, purpose-specific consent at the sensitive-data layer. The next step is applying it to the SDK vendors themselves, not to the ad-supported internet as a whole.

Sources & Citations

  1. EFF: Mobile Ad Software Encourages Location Data Sharing (press release)
  2. EFF: Developers, Beware of Ad Libraries That Betray Users' Location Privacy
  3. FTC: Ban Kochava and Subsidiary from Selling Sensitive Location Data
  4. TechCrunch: Android app developers may be unwittingly sharing location data