Court orders Kochava and subsidiary to stop collecting, selling sensitive user data

By Zach Hagadone
Reader Staff

After four years of litigation, a lawsuit brought by the Federal Trade Commission against Sandpoint-based Kochava has reached its conclusion, with a district court order finding that the tech company and its subsidiary “participated in unfair acts or practices in violation of Section 5 of the FTC Act … in the use and disclosure of data gathered from consumers’ mobile devices and other sources without consumers’ knowledge or consent.”

In addition, the order issued June 25 and signed by Idaho U.S. District Court Judge B. Lynn Winmill bars Kochava and its data broker business Collective Data Solutions “from selling, sharing or disclosing sensitive location data without consumers’ affirmative express consent to settle allegations the companies sold location data from hundreds of millions of mobile devices that could be used to trace the movements of individuals.”

In a news release dated May 4 from the FTC, the agency recounted its allegations first made in August 2022 that consumers “had no way of avoiding the harm resulting from its collection and disclosure” of precise location data that “invaded consumers’ privacy by revealing their movements, including visits to sensitive locations such as health facilities and places of worship.”

In its original complaint filed in U.S. District Court in Idaho, the FTC alleged that specific geolocation data made available as a sample set by Kochava through the Amazon Web Services Marketplace until June 2022 could be used to disclose and trace people to sensitive areas such as abortion clinics, homeless and domestic violence shelters, and addiction recovery facilities. 

Kochava’s headquarters in Sandpoint. Photo by Ben Olson

Additionally, the agency stated, that kind of data could be used to infer LGBTQ+ identification and it could be combined with latitude and longitude coordinates, timestamps and a device’s “mobile advertising identifier” (MAID) to reveal the identity of its owner, making it possible to associate them with a physical home address.

“The FTC alleges that by selling data tracking people, Kochava is enabling others to identify individuals and exposing them to threats of stigma, stalking, discrimination, job loss and even physical violence,” the agency stated in an announcement of the complaint in 2022. “The FTC’s lawsuit seeks to halt Kochava’s sale of sensitive geolocation data and require the company to delete the sensitive geolocation information it has collected.”

At the time of the initial complaint, Kochava purchased mobile device location data from third parties, then aggregated it for sale to clients in customized feeds in order to track and assess the efficacy of targeted marketing campaigns. That data was also used by purchasers to track the success of translating advertising into foot traffic at physical locations and gauging the success of billboard ads.

However, the FTC stated in its 2022 complaint, “[I]n just the data Kochava made available in the Kochava Data Sample, it is possible to identify a mobile device that visited a women’s reproductive health clinic and trace that mobile device to a single-family residence.

“The data set also reveals that the same mobile device was at a particular location at least three evenings in the same week, suggesting the mobile device user’s routine,” the agency added. “The data may also be used to identify medical professionals who perform, or assist in the performance, of abortion services.”

In a news release in August 2022, Kochava stated that it purchased that data from mobile operating systems like Apple iOs and Google Android, along with other apps and websites — all of which required users’ consent.

According to the FTC’s news release in May, “consumers were unaware of and did not consent to this data sharing [by the defendants].” 

Kochava representatives did not respond to a request for comment by press time, though in 2022 told the Reader in a statement that the FTC’s complaint was “a fundamental misunderstanding” of how data brokering works.

According to a 2022 report in the Idaho Statesman, Kochava contended that it did not “collect, then subsequently sell data compilation that allows one to track a specific individual to a specific individual.” Instead, it paired encrypted email and IP addresses with MAID information, ensuring it stayed anonymous.

“Even if an injury to the consumer did indeed occur, it is reasonably avoidable by the consumer themselves by way of the opt-out provision to allow the data collection,” Kochava stated at the time, according to the Statesman.

In addition to barring Kochava and CDS from brokering sensitive location data without the express consent of consumers, the June 25 order puts in place a long list of requirements, including:

Creating a program to identify sensitive locations and stop precise data tied to those locations from being sold, shared or disclosed.

Performing checks to make sure customers gave express permission before their location data was collected or used by the companies.

Reporting to the FTC whenever the companies find that a third party has improperly shared consumers’ precise location data in violation of their agreements.

Giving consumers a way to find out who received their precise location data and make it easy for them to withdraw consent for future sales of that data.

Setting explicit rules for how long location data can be kept and requiring it to be deleted after a specified period.

The order also stipulates that the sensitive location data program has to be established and implemented — with a specific written plan submitted to FTC along with how it will be maintained — no later than 90 days from the date of the order. A senior officer such as a chief privacy or chief compliance officer must be identified and report to corporate leadership at least every 12 months.

On top of that, and among other compliance requirements, customers who received precise location data within the past two years must be provided with a copy of the order within 90 days of its entry, and a report has to be filed to the FTC within 30 days of any determination that a third-party incident has occurred.

Commenting on the case in a May 26 post on its “Data Decoded” blog, multinational San Francisco-based law firm Morrison Foerster analysts wrote, “The terms of the settlement agreement highlight a trend toward more prescriptive data privacy and security requirements.”

Other companies such as General Motors and OnStar have been similarly found to run afoul of FTC regulations by collecting and selling sensitive location data to third parties, and also been required to put in place much more robust data handling policies and procedures.

The trend goes back to the Biden administration, and included FTC actions against Mobilewalla, Inc. and Gravy Analytics Inc. and subsidiary Venntel Inc. for handling location data.

“[T]he Kochava and Gravy Analytics orders share similar stringent measures, including the requirement for quarterly assessments of sensitive location lists, quarterly testing of related controls and proactive notice to the FTC for suppliers’ contractual violations,” MoFo analysts wrote.

“These developments reflect bipartisan scrutiny not only of location-data practices, but more broadly of how companies collect, share and monetize sensitive consumer information, including data that may not appear sensitive on its face, but can still reveal sensitive insights when analyzed or combined with other data sources,” the analysts added. “Against this backdrop, it continues to be imperative that companies maintain a comprehensive understanding of the data they collect, the parties with whom they share it, and how it is ultimately used, both internally and downstream.”

Find a pdf of the full court order at bit.ly/KochavaOrder.

Want to support independent local journalism?

The Sandpoint Reader is our town's local, independent weekly newspaper. "Independent" means that the Reader is locally owned and operated by people who were born and raised in Sandpoint. The Reader is owned by Publisher Ben Olson, Editor-in-Chief Zach Hagadone and Senior Writer Soncirey Mitchell. Sandpoint Reader LLC is a completely independent business unit; no big newspaper group or corporate conglomerate or billionaire owner dictates our editorial policy. And we want the news, opinion and lifestyle stories we report to be freely available to all interested readers - so unlike many other newspapers and media websites, we have NO PAYWALL on our website. The Reader relies wholly on the support of our valued advertisers, as well as readers who voluntarily contribute. Want to ensure that local, independent journalism survives in our town? You can help support the Reader for as little as $1.

You may also like...