Dear Mr. Gildea:
We are investigating the collection and sale of sensitive mobile phone location data that reveals the precise movements of millions of American adults, teens, and even children. We seek information about your company's provision of consumer location data to federal government agencies for law enforcement purposes without a warrant and for any other purposes, including in connection with the response to the coronavirus crisis.
The vast majority of Americans carry cell phones with apps capable of collecting precise location information 24 hours a day, 7 days a week. This location-tracking raises serious privacy and security concerns. As Chief Judge Roberts wrote in the Carpenter opinion, "when the Government tracks the location of a cell phone it achieves near perfect surveillance, as if it had attached an ankle monitor to the phone's user."1 This location data can reveal where we go and with whom we associate, tracking us in our homes, at the doctor, or at church.2
With Americans installing contact-tracing apps as part of the effort to limit the spread of COVID-19, it has become increasingly important to make sure that the American public has a full understanding of who is collecting their location data, how it may be provided to the government, and what the government is doing with it.
It was recently reported that a contact-tracing app recommended to residents by the governors of North Dakota and South Dakota was sending location data to a third party--in violation of promises made to users.3 According to that third party, the data was not used; nevertheless, this example shows that Americans may increasingly be unwittingly handing over their location data to unknown third party data brokers such as Venntel. There are limited restrictions on how this data may be sold to and used by the federal government.
In February, the Wall Street Journal reported that Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP) purchased consumers' location data from Venntel and used it without a warrant to identify, locate, and arrest migrants.4 According to the report:
The Trump administration has bought access to a commercial database that maps the movements of millions of cellphones in America and is using it for immigration and border enforcement. The location data is drawn from ordinary cellphone apps, including those for games, weather and e-commerce, for which the user has granted permission to log the phone's location.5
Federal spending records indicate that the Drug Enforcement Agency (DEA), Federal Bureau of
Investigation (FBI), and Internal Revenue Service (IRS) also may have obtained data or data services from your company.6 Furthermore, federal, state, and local governments reportedly are
using or considering the use of cell phone location data to track the spread of the coronavirus.7
The Supreme Court has held that the government must obtain a warrant before agencies can obtain location data from wireless phone companies and technology companies like Facebook and Google. By acting as an intermediary in the sale of this data, your company may be selling data to the government that it otherwise would need a warrant to compel, impacting the privacy of millions of people, including vulnerable populations like children.8
Consumers often do not understand that popular apps for weather, travel, shopping, and other purposes--which may have legitimate needs for location data--may be selling this data to brokers.
9 An investigation in 2018 by the New York Times uncovered 75 companies that were buying and selling mobile app-derived location data.10 Location-targeted advertising sales are predicted to reach an estimated $27 billion this year.11
The scale of this data collection is staggering. For example, Venntel's reported parent company, Gravy Analytics,12 has revealed that it collects location data from software "embedded within tens of thousands of apps."13 According to its website, Gravy Analytics "processes billions of pseudonymous mobile location signals every day from millions of mobile devices."14 Despite claims that anonymization protects privacy, computer scientists and journalists repeatedly have demonstrated the ease with which individuals in purportedly anonymized data sets may be identified.15
Reports also indicate that location data is vulnerable to hacking and that this data could lead to individuals being targeted for commercial or political purposes, stalking, or discrimination.16 In 2017, the Massachusetts Attorney General reached a settlement with a company that targeted advertisements to "abortion-minded women" entering reproductive health facilities and methadone clinics in multiple states.17 Media reports have also identified companies targeting advertisements to people in emergency rooms18 and dialysis centers.19 In 2019, the Los Angeles City Attorney brought a lawsuit against the Weather Channel and its parent company, IBM, which sell data collected from the Weather Channel app's 45 million users. The City Attorney alleged the companies deceptively collected, shared, and profited from the location information of millions of American consumers.20
In February 2020, the Federal Communications Commission (FCC) fined the four major wireless carriers, Verizon, AT&T, T-Mobile, and Sprint, for selling location data without the knowledge or consent of their subscribers. In issuing the fines, the FCC described the sensitivity of location data and its potential for abuse:
The precise physical location of a wireless device is an effective proxy for the precise physical location of the person to whom that phone belongs at that moment in time. Exposure of this kind of deeply personal information puts those individuals at significant risk of harm--physical, economic, or psychological. For consumers who have job responsibilities in our country's military, government, or intelligence services, exposure of this kind of information can have serious national security implications.21
For all of these reasons, please provide the following information and documents by July 8, 2020, for the period from January 1, 2016, to the present:
1. For each provision of goods or services to a federal agency by your company:
a. documents sufficient to show the nature and purpose of the product or service provided and any use case or justification provided by the purchasing agency;
b. documents sufficient to show any actions that Venntel or its suppliers take to obtain the consent of the individuals whose location and other data is provided to or accessed by the agency;
c. all documents relating to any restrictions on how the agency may use the product or service, including whether the agency may share information with other federal or state government agencies and whether Venntel and the agency entered into a nondisclosure agreement regarding the agency's use of Venntel's services;
d. documents sufficient to show Venntel's revenue from the sale or provision of the goods or services;
e. copies of all contracts or agreements relating to the sale or provision of the goods or services;
2. All correspondence between Venntel and any employee, official, or representative of any federal department, federal agency, or executive branch office;
3. A list of all customers who purchase, license, or access location data from Venntel or any Venntel subsidiary. For each customer, please provide the following:
a. documents sufficient to show the nature and purpose of the product or service provided;
b. documents sufficient to show any actions that Venntel or its suppliers take to obtain the consent of the individuals whose location and other data is provided to or accessed by the customer;
c. all documents relating to any restrictions on how the customer may use the product or service;
d. copies of all contracts or agreements relating to the sale or provision of the goods or services;
e. for any foreign entity, detail the steps Venntel has taken to seek and obtain export licenses for these sales;
4. A description of any COVID-19 related efforts that Venntel is involved in, including:
a. any COVID-19-related apps from which Venntel collects or has collected data;
b. any documents related to the provision of goods or services to federal agencies, state governments, local law enforcement, and foreign entities, related to monitoring or mitigating the COVID-19 pandemic; and
5. Documents sufficient to show the specific location data that Venntel collects, other information it collects (e.g., Advertising ID, wireless information, web search history, phone or demographic information), and how is it paired or combined with location data;
6. Documents sufficient to show the number of individuals from whom Venntel collects location data;
7. Information indicating how long Venntel keeps user data, regardless of whether it is anonymized;
8. Documents sufficient to identify all sources from which Venntel and its upstream suppliers have received consumer location and other data which it provides to any government agency, and the specific type of data collected from each source. For each source, please provide documents sufficient to show the following:
a. the amount paid by Venntel to receive location data from that source;
b. copies of all contracts or written agreements with that source;
9. Documents sufficient to show all measures Venntel or its upstream suppliers take, if any, to ensure the anonymity of users whose data is collected by Venntel;
10. Documents sufficient to show all steps Venntel takes, contractually or otherwise, to ensure that its customers do not attempt to re-identify anonymized data provided to them;
11. A description of how Venntel ensures that all data it buys and sells, licenses, or provides access to was obtained from individuals who consented to the collection of, use of, sale of, or sale of access to their data, including to federal agencies and law enforcement agencies;
12. A description of any data security practices and policies Venntel uses to ensure that location data is not accessed without authorization;
13. A description of each instance in which Venntel's location data has been breached or accessed without authorization; and
14. Copies of all policies and procedures related to the collection, use, license, or sale of location data, including with respect to data security, data privacy, user consent, and anonymization.
The Committee on Oversight and Reform is the principal oversight committee of the House of Representatives and has broad authority to investigate "any matter" at "any time" under House Rule X.
An attachment to this letter provides additional instructions for responding to this request. If you have any questions regarding this request, please contact Committee staff at (202) 225-5051, Senator Warren's staff at (202) 224-4543, or Senator Wyden's staff at (202) 224-5244.
Thank you for your attention to this important matter.
Sincerely,