The Data Broker Loophole: How the Government Surveils Innocent Americans Without a Warrant
The Fourth Amendment is supposed to be simple: before the government searches your private life, it needs a warrant signed by a judge. But across the country, federal agencies and local police have found a way around that bedrock protection. They don't break down your door. They open their wallet.
Instead of getting a warrant, the government is buying your most sensitive personal information—your location history, your movements, your associations—directly from the same data brokers that sell your profile to advertisers. The Constitution requires probable cause. The data broker market only requires a purchase order. This is the data broker loophole, and three recent reports make clear it has moved from the shadows into a routine tool of warrantless mass surveillance.
At Priwall by mePrism, we remove your personal information from 700+ data brokers for exactly this reason: the data that fuels government surveillance is the same data we help you erase.
What Is the Data Broker Loophole?
The logic is disturbingly straightforward. A landmark Supreme Court ruling, Carpenter v. United States (2018), held that the government needs a warrant to obtain your historical cell phone location data because those records reveal the "privacies of life"—where you sleep, who you visit, what church, clinic, or protest you attend.
But Carpenter was about data the government demands from your phone carrier. It said nothing explicit about data the government simply buys on the open market. So agencies argue that the warrant requirement doesn't apply when they purchase the same location trails from a commercial data broker instead of subpoenaing your carrier.
As the Brennan Center for Justice describes it, the data is "effectively laundered through a middleman." Phone and internet companies are barred from selling sensitive data directly to the government under the Electronic Communications Privacy Act. So they sell it to data brokers, and the brokers sell it to the government for a profit. The constitutional protection survives on paper while collapsing in practice.
The American Civil Liberties Union puts it bluntly: "The government should not be allowed to purchase its way around bedrock constitutional protections against unreasonable searches of our private information. There should be no end run around the Fourth Amendment."
How Your Phone Becomes a Government Tracking Device
To understand why this matters, you have to understand where the data comes from. It comes from you—or, more precisely, from the apps on your phone.
Thousands of mobile apps—weather, games, prayer apps, dating apps, navigation tools—quietly harvest your location and sell it into the advertising ecosystem. Each device carries a Mobile Advertising ID (also called a MAID or AdID), a unique alphanumeric code that follows your phone everywhere it goes. Data brokers vacuum up these location pings, stitch them together into detailed movement histories, and sell access to whoever pays.
That "whoever" increasingly includes the government.
According to NPR, the same brokers that sell location data to advertisers also supply "massive quantities of mobile location data" to law enforcement and federal authorities—enough to uncover the most private aspects of Americans' lives without ever seeing a judge. As an Electronic Frontier Foundation technologist explained to NPR, the available tools let law enforcement monitor a device's movements, including where it stays overnight and where it goes during work hours.
The ACLU's FOIA documents reveal that ICE bought access to a surveillance system, first reported by 404 Media, that can monitor a single city block for mobile phones, track movements over time, and follow people from work to home. This is not targeted investigation of a suspect. It is a dragnet over everyone who happens to be carrying a phone.
The Government's Flimsy Legal Justification
How does a federal agency justify buying data it would normally need a warrant to access? The ACLU obtained the answer in a two-page legal memo from ICE—the most detailed look yet at the government's reasoning.
The memo argues that purchased location data is somehow different from the data in Carpenter because it's tied to Mobile Advertising IDs rather than to phone numbers or names. In other words: because your tracking data is labeled with a device code instead of your name, the agency claims it isn't really tracking you.
The ACLU's response: "That is a distinction without a difference." AdIDs are routinely enriched with personal and historical information, and a DHS Privacy Officer in the same documents flagged the concern that AdIDs become "linked to an individual" and retained alongside personally identifiable information. The technical fig leaf doesn't survive contact with how the technology actually works. As the ACLU notes, "What you do and where you do it defines who you are," and "Nobody expects that by carrying a phone, they are somehow consenting to let the government make a record of their every move."
A Pattern Across the Federal Government
This isn't one rogue agency. Public reporting and FOIA litigation show the data broker loophole has been used across the federal government:
Customs and Border Protection entered into contracts with the data broker Venntel in 2019 and 2020 totaling over two million dollars, and a nearly three-million-dollar renewal with Babel Street, tracking phones to "locations of law enforcement interest" and monitoring "travel patterns." (ACLU)
The Secret Service signed a 12-month contract with Babel Street worth over $600,000, with internal emails describing how the tool could identify mobile devices near border crossings and pull up their location history for the preceding months. (ACLU)
ICE signed up with the surveillance vendor Penlink for its Webloc program, which can track phone movements and identify phones that have visited specific locations. (NPR)
The FBI confirmed the practice at the highest level. When Senator Ron Wyden asked FBI Director Kash Patel during a Senate hearing whether he would commit to not buying Americans' location data, Patel declined, saying the FBI "uses all tools" and that "we do purchase commercially available information." (FedScoop)
DHS announced in 2024 that it was ending its contracts for bulk cell phone location data—but, as the ACLU reports, recent reporting indicates the agency is "getting back into the business of mass tracking Americans' phones." The brief pause was just that: brief.
When Surveillance Targets Protected Speech
The most alarming dimension of warrantless surveillance isn't just that it happens—it's who it targets. Increasingly, the answer is people exercising their First Amendment rights.
In a striking example reported by The Intercept, a confidential law enforcement bulletin from the Delaware Valley Intelligence Center—a fusion center housed inside the Philadelphia Police Department—warned that Americans criticizing AI data centers on social media could be a threat. The bulletin explicitly listed "disruptive First Amendment activity" as an "indicator" of risk from "Domestic Violent Extremists."
Let that sink in. Among the "short-term indicators" the bulletin flagged were "online calls for action to boycott and or protest local AI data centers" and "extensive criticism of higher utility bills resulting from AI data centers." Boycotts, protests, and complaints about your electric bill—all activities squarely protected by the Constitution—were treated as warning signs of extremism. The bulletin was distributed nationally through the fusion center network of state, local, and federal police.
Paul Hetznecker, a longtime Philadelphia civil rights lawyer, told The Intercept the report reflects "a very dangerous attempt to characterize that protected First Amendment activity—activity which is fundamental to our democracy—as something other, something more dangerous, a breeding ground for something more sinister." He warned it could "chill the appropriate dialogue that needs to occur on the impact of data centers on local communities."
This is not new behavior for fusion centers, which have previously subjected Black Lives Matter demonstrators and pipeline protesters to suspicion and surveillance. But combine that surveillance mindset with a commercial data market that can map every protester's movements—purchased without a warrant—and the chilling effect becomes a machine.
NPR reports that ICE is already intensifying surveillance not only of immigrants slated for deportation but of "individuals who document federal agents and protesters." The National Association of Criminal Defense Lawyers warns that purchased data reveals "engagement with protests and social causes," along with race, political beliefs, sexuality, immigration status, and reproductive health care needs—precisely the categories most vulnerable to abuse.
The AI Accelerant
There's a reason this issue is reaching a boiling point now: artificial intelligence has supercharged what the government can do with all that purchased data.
It's one thing to buy billions of location pings. It's another to have a machine that can instantly analyze them. Anthropic CEO Dario Amodei cautioned that government-obtainable records could be used by AI to build "a comprehensive picture of any person's life automatically and at massive scale." That warning has put Anthropic in direct conflict with the Pentagon after the company refused to allow its technology to be used for domestic mass surveillance and autonomous weapons. The Pentagon argues a private company shouldn't be able to dictate how the government uses its tools. (NPR)
As one surveillance-reform advocate told NPR, AI can "harvest and analyze the data in ways that humans never could and do it remarkably quickly." A coalition of roughly 130 civil society groups warned Congress that the loophole could be used to "enhance AI-driven surveillance." The combination of bulk commercial data and AI analysis opens what advocates call a "Pandora's box"—pattern recognition at a scale no human analyst could ever achieve, applied to the private movements of innocent people.
Congress Has a Window to Close the Loophole
The good news is that the data broker loophole is fixable, and a rare bipartisan coalition wants to fix it.
The centerpiece is the Fourth Amendment Is Not For Sale Act, which would prohibit law enforcement and intelligence agencies from purchasing sensitive information—including geolocation data—from third-party brokers without a warrant. The bill passed the House in 2024 with strong bipartisan support, as EPIC documented, but ultimately stalled in the Senate.
Reform advocates see the reauthorization of FISA Section 702 as the best vehicle to finally close the gap. As Sean Vitka of Demand Progress told NPR, "This is likely the only chance Congress has this year to vote for substantial privacy protections." The issue scrambles the usual partisan lines. Representative Warren Davidson (R-Ohio), who co-sponsored bipartisan reform legislation, put it plainly: "This is one of those issues that really transcends party lines," adding, "governments are purchasing their way around the Fourth Amendment, and we need to close that off."
States aren't waiting. Montana has already passed related legislation, and other states are poised to follow. The ACLU urges state legislatures to act "to ensure that state and local police can't pay their way to pervasive location surveillance."
Why This Matters Even If You're Not a Protester
You might think this doesn't affect you. You're not an activist, you're not under investigation, you have "nothing to hide." But the entire point of warrantless mass surveillance is that it doesn't single you out—it sweeps you in.
Geofence and bulk-purchase tools identify every device in a given area. If you walked past a protest, attended a rally, visited a clinic, worshipped at a particular mosque or church, or simply lived in a neighborhood under watch, your AdID and movement history are in the same database the government can buy. The protections of the Fourth Amendment were designed precisely so that ordinary, innocent people would not have their lives catalogued by the state without cause. The data broker loophole erases that protection for everyone at once.
And the data brokers feeding this system are the same ones that expose you to scams, identity theft, and stalking. The phone number, home address, and behavioral profile a broker sells to an advertiser is the same record that ends up in a government surveillance tool. Reducing your exposure to data brokers is no longer just about avoiding spam—it's about shrinking the digital dossier the government can purchase about your life.
How to Protect Yourself From Data Broker Surveillance
You can't single-handedly pass federal legislation. But you can dramatically reduce the personal data available to be bought, sold, and surveilled. Here's where to start:
Audit your app permissions. Revoke location access for any app that doesn't genuinely need it. Most location data sold to brokers originates from apps quietly tracking you in the background.
Reset or limit your Mobile Advertising ID. Both iOS and Android let you reset your AdID or opt out of ad tracking, which makes it harder to build a continuous movement profile tied to your device.
Use the California Delete Act if you qualify. Starting in 2026, California's DROP platform lets residents send a single deletion request that registered data brokers must honor, as CalPrivacy explains.
Remove your data from data brokers at scale. The hardest and most important step. There are hundreds of brokers, most don't make opting out easy, and they repopulate your information months after removal—which is exactly why automated, continuous removal matters.
Take Back Control of Your Data
The data broker loophole works because your information is sitting in hundreds of commercial databases, waiting to be bought. The fewer brokers that hold your profile, the less there is for anyone—advertisers, scammers, or government agencies—to acquire.
At Priwall by mePrism, we help you take back control. Our platform scans the internet and 700+ data brokers to uncover where your personal information is exposed and sold, then uses automation and legal intervention to remove it. We don't stop after one removal—we continuously monitor the web and remove your data whenever it reappears. Priwall also lets you lock down social media privacy settings across Google, Facebook, LinkedIn, and X, addressing the source platforms that feed the broker ecosystem in the first place.
Warrantless surveillance starts with data that should never have been for sale. Closing the loophole is Congress's job. Shrinking your exposure is something you can start today.
Ready to try Priwall by mePrism yourself?
If you are an individual executive evaluating personal coverage outside an employer-funded program, you can start with a free exposure scan.
Sign up for Priwall by mePrism coverage.By Thomas Daly, CEO, mePrism Privacy. Thomas leads mePrism Inc., the company behind Priwall by mePrism, and writes regularly on consumer privacy regulation and the B2B economics of data-broker removal.