Posted on

Data brokers that assemble profiles from many unrelated sources

The unsettling thing about a data broker is that you may never have visited its website.

You may never have installed its app.

You may never have created an account.

The broker can still have a file about you.

That is possible because the business model begins where many of the previous Surveillance Economy articles end: somebody else already collected the fragments.

The FTC documented the assembly line years ago

The Federal Trade Commission’s major 2014 report on data brokers found that brokers obtained information from commercial sources, government records, publicly available sources, websites, and other data brokers. The report said the companies studied combined small pieces from many places into much more detailed composite profiles.

See the FTC’s Data Brokers: A Call for Transparency and Accountability and the agency’s summary of its findings.

The FTC found that brokers could collect purchase information, browsing activity, warranty registrations, public records, and other everyday data. It also found that brokers frequently bought information from other brokers, making the original source difficult for a consumer to reconstruct.

That structure remains important even as the specific companies and technologies change.

The value comes from combination

Suppose five separate systems know five separate things:

  • a retailer knows what you bought,
  • a public record contains an address,
  • an advertising system knows what device visited certain sites,
  • a location provider has observations tied to an advertising ID,
  • a people-search service has old phone numbers and relatives.

None of those datasets necessarily contains a complete person.

A broker’s value comes from matching them.

Names, addresses, emails, phone numbers, device IDs, household identifiers, probabilistic matches, and other linking fields can turn fragments into a composite.

Combination also combines errors

Profiles do not become true merely because they are large.

A broker can inherit an outdated address from one source, a mistaken household member from another, a purchase made for somebody else, or a device incorrectly assigned to the same person.

Once records are merged, the error can become part of a more authoritative-looking profile.

The FTC’s consumer guidance on people-search sites notes that these services may compile information from other brokers, public social-media profiles, and federal, state, and local public records. See What To Know About People Search Sites That Sell Your Information.

Direct consent can disappear several hops ago

A person may have knowingly given an address to a retailer or installed an app with location permission.

That does not mean the person understands every later broker-to-broker transfer.

The FTC’s 2024 X-Mode/Outlogic case is a concrete example of location data moving through an ecosystem that included third-party apps, SDKs, aggregators, and hundreds of clients. See the FTC’s final order announcement.

This is where the Surveillance Economy stops looking like one tracker following one browser.

The final profile may be assembled by a company the person has never heard of, from records created by companies that never saw the final profile.

No single source has to know everything.

The broker’s product is knowing how to put the pieces together.

Posted on

Location histories collected through embedded mobile software kits

You install one app.

That does not mean only one company is inside it.

Mobile apps commonly include third-party software development kits, or SDKs, that provide analytics, advertising, crash reporting, maps, authentication, payments, and other functions the app developer does not want to build from scratch.

If an app receives device location and passes it to one of those SDKs, the location can move beyond the company whose icon the user recognizes.

That is where a simple permission can turn into a supply chain.

The X-Mode case made the pipeline unusually visible

In 2024, the Federal Trade Commission finalized an order against location-data broker X-Mode Social and its successor Outlogic. The FTC said the companies obtained precise location information from third-party apps that incorporated the company’s SDK, from its own apps, and from other brokers and aggregators. The data was associated with mobile advertising IDs and sold or licensed to hundreds of clients.

See the FTC’s final X-Mode/Outlogic order announcement and case page.

The FTC said the raw data could reveal visits to sensitive places such as medical clinics, houses of worship, and domestic-abuse shelters. The order restricted the sale or sharing of sensitive location data and imposed additional safeguards.

The important architectural point is broader than one company.

The app can be the collector the user sees.

The SDK can be the recipient the user does not.

One permission can serve several relationships

A weather app may have a legitimate reason to request location.

So might a navigation app, ride service, delivery app, or local-events app.

But the fact that the app needs location for its visible feature does not answer every downstream question:

  • Which embedded libraries receive the coordinates?
  • Are they given precise or approximate location?
  • Is an advertising identifier attached?
  • How often is the event sent?
  • How long is it retained?
  • Is it sold, licensed, or shared onward?

The permission dialog alone cannot answer those questions.

A point becomes a history through repetition

One coordinate says where a device was once.

A sequence can reveal routines.

Repeated observations can suggest where a person sleeps, works, shops, worships, exercises, receives medical care, or spends evenings. Even when a dataset begins with a pseudonymous device identifier rather than a name, repeated movement can make the profile easier to associate with a real person or household.

That is why the evidentiary chain matters.

Seeing a location permission does not prove a broker received the data.

Finding an SDK in an app does not prove every capability was used.

A stronger investigation needs network traffic, SDK documentation, privacy disclosures, contractual records, regulator findings, or other evidence showing that location actually moved from the device to a particular recipient.

The Surveillance Economy is often built from layers the user never sees.

The map pin is collected in the app.

The history may be assembled somewhere else.