The FTC settled charges with data broker Kochava, Inc. and its subsidiary Collective Data Solutions (CDS) over allegations that they sold precise location data from hundreds of millions of mobile devices without consumer consent, enabling tracking of visits to sensitive locations like reproductive health clinics and places of worship. The settlement prohibits the companies from selling or sharing sensitive location data without affirmative express consumer consent, and imposes compliance requirements including a sensitive location data program, supplier consent assessments, incident reporting, and data retention schedules. No monetary penalty was imposed.
Kochava and CDS are banned from selling, licensing, transferring, sharing, or disclosing sensitive location data without consumers’ affirmative express consent, and only if the data is used to provide a consumer-requested service. The companies must implement a sensitive location data program to identify and block sale of data from sensitive locations, a supplier assessment program to verify consumer consent for all location data, submit incident reports to the FTC when third parties violate data sharing contracts, provide consumers with the ability to request the names of entities that purchased their data and withdraw consent, and establish a data retention schedule requiring deletion of data on a set timeline.
In-house legal teams at companies that collect, process, or share precise geolocation data—including mobile app providers, ad tech vendors, and data brokers—should review vendor and data processing agreements to ensure they require affirmative express consumer consent for the collection, sale, or sharing of precise location data, and explicitly prohibit the disclosure of sensitive location data (e.g., health facilities, places of worship) without consent. Vendor agreements with data brokers must include clauses mandating supplier assessment programs to verify consumer consent for all location data, incident reporting obligations for unauthorized third-party data sharing, and enforceable data retention schedules requiring timely deletion of location data. Customer-facing agreements and privacy policies should be updated to disclose location data collection practices, provide consumers with easy mechanisms to withdraw consent, and outline third-party data sharing. All contracts involving location data should also include audit rights and requirements to comply with applicable FTC enforcement orders.
Entity
Kochava, Inc. and Collective Data Solutions (CDS)
Industry
Data Broker"Kochava and its subsidiary, Collective Data Solutions (CDS), which has taken over Kochava’s data broker business"
"May 4, 2026"
"Federal Trade Commission"
"to settle allegations"
"sold location data from hundreds of millions of mobile devices that could be used to trace the movements of individuals"
"collection, use and disclosure of precise location data invaded consumers’ privacy by revealing their movements, including visits to sensitive locations such as health facilities and places of worship"
The FTC issued a policy statement abandoning disparate-impact liability, stating it will no longer bring claims based on this theory. It also modified compliance obligations for several companies based on past decisions.
The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.
$300K
The FTC alleged that Elite Events and Tickets LLC, doing business as Smart Scalpers, violated the Better Online Ticket Sales Act by circumventing security measures to bypass ticket purchase limits for over 2,400 events, reselling tickets at a profit. The proposed order requires payment of $300,000 (with a total penalty of $10.7 million partially suspended) and permanently prohibits the company and its owners from engaging in such circumvention tactics.
$45.9M
The FTC permanently banned Dennise Merdjanian from the debt relief industry and telemarketing after she and Superior Servicing LLC allegedly ran a student loan forgiveness scam that took more than $45.9 million from consumers. The proposed stipulated order imposes a partially suspended monetary judgment and resolves the FTC's litigation against the remaining defendants.
$16.5M
The FTC charged the founders of Celsius Network with deceiving consumers by falsely promising that cryptocurrency deposits were safe and always available. The founders agreed to pay $16.5 million and are banned from marketing or selling products that can be used to deposit or withdraw assets, among other restrictions.
$750K
The FTC finalized a settlement with Vanilla Chip LLC (doing business as TruHeight) and its principals over allegations that they deceptively advertised height-enhancing supplements for children and teenagers without competent and reliable scientific evidence. The FTC also alleged that TruHeight used fake social media bot profiles and relied on reviews written by employees, vendors, or consumers who received free products or discounts for 5-star reviews. Under the final order, TruHeight must pay $750,000 and is barred from making unsupported health claims or misrepresenting reviews.