Skip to content
All Resources
Privacy 12 min read

Prepared by GSDSI Regulatory Content Team

Last updated

General information, not legal advice.

Editorial standardsTrust Center

FTC Sensitive Location Thresholds: A 2026 Buyer Guide

FTC location-data orders bind the companies named in them, not every buyer, but they show how the FTC defines sensitive location. Treat sensitive places as a pass or fail gate, with geofence proofs run during the pilot rather than cleaned up after launch. Affirmative express consent is the baseline for commercializing precise location, and deletion evidence belongs in writing.

Relationship disclosure: X-Mode and its successor Outlogic, InMarket, and Mobilewalla are referenced here as subjects of FTC consent orders finalized in 2024 and 2025. GSDSI has no supplier, partner, or reseller relationship with any of them.

How to use this article

Read the checklist here, then use the linked hub and product pages for procurement citations.

The FTC's location-data orders bind the companies named in them, along with their officers, agents and anyone acting in concert with them who has notice, not every buyer of mobility or POI data, but they show how the FTC defines sensitive location and what it expects from a data seller. Consent orders against X-Mode/Outlogic (final April 2024), InMarket (final May 2024), and Mobilewalla (final January 2025) restrict selling or using location data tied to sensitive places such as medical and religious sites, and require deleting historic location data, subject to exceptions written into each order, with written confirmation to the FTC. In these orders, about 1,850 feet marks what counts as Location Data, the orders' defined term, not what counts as sensitive: data that reveals only a coarse location, such as a ZIP code or census block with a radius of at least 1,850 feet, is excluded, while sensitive location data is Location Data associated with a place on the order's list of sensitive locations. A visit attributed to a named clinic can fall into that category when the clinic matches the order's definition. Teams licensing global mobility or POI geofencing should document exclusions before activation in audience targeting or smart cities programs. Pair technical tests with sourcing methodology and /trust/data-broker-registrations.

What the FTC Orders Changed

The FTC's business guidance on privacy and security reinforces that unexpected use of location data is unfair. Buyers should map actual activation to notices and orders, not to generic MSA privacy clauses.

The X-Mode/Outlogic order (announced January 2024, final April 2024) was the FTC's first settlement with a data broker over the collection and sale of sensitive location information, and it prohibits selling or sharing sensitive location data. The InMarket order (announced January 2024, final May 2024) prohibits selling or licensing location data. It requires deleting the historic location data collected through its own apps, unless the consumer gives affirmative express consent to keep it, and deleting, deidentifying or rendering non-sensitive the historic data collected from third parties, each confirmed to the FTC in writing. The Mobilewalla order (final January 2025) restricts selling or using sensitive location data and requires deleting historic location data and the data products built from it, each confirmed to the FTC in writing. In December 2024 the FTC also announced a separate order against Gravy Analytics and Venntel (issued January 13, 2025), which uses the same 1,850-foot coarse-location exclusion and requires deleting historic location data within 60 days, unless within 90 days the companies hold records showing consumer consent, or have deidentified the data or rendered it non-sensitive. The FTC's lawsuit against Kochava, filed in 2022, ended in a stipulated federal court order filed June 25, 2026. It requires deidentifying historical location data or rendering it non-sensitive within 90 days of entry, unless the defendants hold records showing consumer consent, and reporting a third-party incident to the FTC within 30 days of determining that one happened. Together they signal that downstream buyers cannot assume "industry standard" geofences from 2022 RFPs still suffice.

Procurement should read data brokers post-FTC consent orders alongside vendor panel audits. Ask whether the vendor's public privacy policy describes sensitive-location exclusions that match feed prep scripts: agents and regulators compare them.

Orders also elevated affirmative express consent language for precise location commercialization: passive app permissions or buried toggles are insufficient in FTC's framing. Map consent artifacts to each device ID in your seed, not only to the publisher's generic policy URL. When vendors cite IAB Transparency & Consent strings, decode purpose IDs relevant to location resale before signing global mobility schedules.

The ~1,850-Foot Line and Coarse vs. Precise

The X-Mode, InMarket, Mobilewalla and Gravy orders use about 1,850 feet to separate Location Data, their defined term, from coarse location, and the Kochava order draws the same line for its own term, Precise Location Data: the FTC's analysis of the InMarket order describes it as limited to location data that identifies a consumer within an area no larger than a circle with a 1,850-foot radius. Census block or ZIP centroids may qualify as coarse in isolation, but combining coarse cells with timestamps, venue labels, or home-work inference can re-identify individuals. Buyers should not treat "aggregated mobility" as automatically safe without reviewing field-level precision and join keys.

Night-time home inference from mobility streams remains a flashpoint: even coarse cells can reveal residence when paired with 90-day histories. Many vendors now suppress night pings or jitter coordinates; verify those transforms on seed devices you control, not only on vendor attestations.

Venue snap-to-POI logic can reintroduce sensitivity even when raw GPS is coarse: a visit attributed to a clinic name is more sensitive than a dot on a map. Test venue labels in the sample, not only lat/long precision. For POI geofencing programs, require polygon source provenance and banned-category lists versioned in the contract.

  • Request stated horizontal accuracy and whether coordinates are raw GPS, geohash centers, or venue snaps.
  • Test whether visits can be inferred to named sensitive POIs despite coarse grid labels.
  • Document retention and lookback: long histories increase re-identification risk.
  • Align DMP exclusion rules with vendor feed prep: mismatches create activation liability.

Tests to Run on a Mobility Sample Before License

Run these on a matched seed before production: mirror enterprise pilot checklist gates. Legal should sign off before engineering connects to production IDs.

Document who ran the test, seed size, date, and polygon version in the procurement record. Re-run after vendor panel refresh events, because panel changes can shift device composition. Compare results to public sourcing methodology statements; discrepancies trigger renegotiation or termination rights.

  1. Sensitive-venue geofence: block or flag visits inside hospital, worship, shelter, reproductive health, and similar polygons.
  2. Precision audit: confirm coordinate precision claims vs. stated coarse thresholds on the same devices.
  3. Consent chain: map publisher CMP / IAB TCF strings to your permitted use in contract.
  4. Refresh and decay: document cadence and device churn. See device graph decay.
  5. Deletion drill: submit test opt-out and verify removal from vendor export within SLA.

Activation, Measurement, and POI Overlap

Advertisers using location for cross-channel measurement should align exclusion polygons with POI geofencing products: brand-safe retail geofences can still intersect sensitive sites if polygon libraries are stale. Require versioned polygon changelogs from vendors. For CTV ACR plus mobility fusion, document whether household graphs amplify location sensitivity.

Cross-link diligence to AI search readiness only insofar as public marketing claims match tested samples: inflated precision language on the web becomes evidence in disputes.

Ad platforms should import the same exclusion polygons the vendor uses in feed prep: mismatches create activation liability when the buyer's DMP allows visits the vendor claims to suppress. Store polygon WKT or GeoJSON hashes in the contract appendix so drift is detectable.

Contract Clauses and Ongoing Monitoring

The clauses in this section are operational recommendations for buyers, not FTC requirements. MSAs should codify: (1) sensitive-location definition by reference to FTC orders or stricter state law, (2) vendor obligation to update polygons when facilities open/close, (3) buyer audit rights on exclusion scripts, and (4) termination rights if a new FTC order affects the panel source. Annual re-review should repeat seed tests: panels drift.

Include incident notification when a vendor discovers sensitive-venue leakage in production feeds, with a fixed deadline. The FTC orders do not require this clause of buyers, but they show what a deadline looks like: the Kochava order gives the company 30 days from determining that a third-party incident happened to report it to the FTC. Cap indemnity carve-outs for sensitive-location violations, and confirm whether your insurance covers surveillance-data claims; both are commercial protections, not FTC requirements. Finance buyers using alternative data should align trading compliance with the same polygon evidence marketing uses.

Vendors with strong posture publish exclusions in sourcing methodology and registration indexes without waiting for buyer prompts: that reduces cycle time for risk management teams under board scrutiny.

Each of these orders requires the company to give the written sensitive location data program, and any updates, to its board or governing body, or to its principal executive officer where there is no board, at least every twelve months. Buyers can ask a vendor for a one-page summary of the equivalent controls, referencing the polygon version, consent chain, and last seed test date; that is a diligence practice, not an FTC requirement. Link the summary from /trust/data-broker-registrations if your trust center is the diligence front door.

Healthcare and faith-based buyers may impose stricter polygons than FTC orders: contract for custom exclusion lists rather than assuming vendor defaults cover mission requirements. Document overrides in the schedule, not email footers.

Law enforcement and national-security buyers still need commercial mobility for pattern-of-life analytics in some programs: segregate those use cases in separate contracts with enhanced audit clauses; do not reuse consumer marketing geofence decks for mission datasets.

Retail analytics teams should separate foot-traffic measurement from individual tracking in data specs: buying visit counts by store week is a different privacy posture than device-level paths. Specify the grain in the schedule and test the sample at that grain only.

International buyers importing US mobility into EU campaigns need GDPR transfer tools plus FTC-style geofence discipline: the stricter geography wins for activation, not the looser vendor default.

Maintain a vendor attestation registry listing polygon version, consent chain version, and last seed test ID: update the registry when vendors refresh panels after FTC orders. Attach registry rows to procurement portal attachments.

Escalate to termination when a vendor cannot reproduce geofence results on a blind seed you provide: reproducibility matters more than marketing polygon counts.

Document children's venue exclusions separately from adult sensitive categories: the FTC location orders list places predominantly providing education or childcare services to minors as sensitive locations, and COPPA is a separate regime with its own requirements.

Frequently Asked Questions

Is ZIP-level mobility always safe?
Not automatically. Coarse geolocation is less likely to be treated as sensitive in isolation, but combined with timestamps, venue labels, or home-work inference it can still re-identify individuals. Evaluate holistically on a seed, not from the product name alone.
Does the FTC define sensitive locations the same as state laws?
No. State health-privacy laws may use geofence radii (for example ~1,750 feet around facilities). Washington and other states add sectoral rules. Map the strictest rule in your activation geography and document which polygon library version you used.
Where should legal sit in the pilot?
Before seed delivery. Use the enterprise pilot checklist and pilot process so governance gates precede engineering joins to production MAIDs or households.
Do FTC orders bind buyers directly?
Orders bind the named respondents, but they establish agency expectations that flow into vendor contracts and industry practice. Buyers who activate non-compliant feeds risk Section 5 unfairness theories and reputational harm even without being order parties.
How does sensitive location relate to GDPR?
GDPR treats location as personal data; special-category data may arise when location reveals health or religious life. US FTC orders emphasize commercial surveillance harms. EU buyers need both GDPR Art. 14 transparency and FTC-style geofence discipline for US-sourced panels.

✓ Opt-Out Request Honored via Global Privacy Control