Supreme Court Rejects Verizon Appeal, Solidifying FCC Power Over Location Data Privacy

The Supreme Court has declined to hear Verizon's challenge to a $47 million FCC fine, cementing a regulatory precedent that holds telecom carriers strictly liable for safeguarding user location data.

Julia Romero Julia Romero
3 min read
Supreme Court Rejects Verizon Appeal, Solidifying FCC Power Over Location Data Privacy

The Supreme Court's refusal to hear Verizon's appeal of its $46.9 million FCC fine marks a decisive end to a multi-year legal battle over the unauthorized sale of real-time user location data. The high court's denial leaves intact a lower court ruling that affirmed the Federal Communications Commission's authority to penalize carriers for failing to protect customer proprietary network information. This regulatory action, which originally targeted the nation's largest wireless carriers with combined penalties exceeding $200 million, establishes a critical legal precedent for mobile privacy. It signals that carriers cannot outsource their statutory privacy duties to third-party aggregators.

The dispute traces back to the FCC's enforcement actions, which found that Verizon, AT&T, and T-Mobile sold access to their customers' real-time location data to location aggregators without consent. These aggregators subsequently resold the data to commercial entities, including bail bondsmen, bounty hunters, and private investigators. Under Section 222 of the Communications Act, telecommunications carriers are legally obligated to protect the confidentiality of proprietary information relating to their customers. Verizon contended that its reliance on contract terms requiring aggregators to obtain customer consent shielded it from liability, arguing that the FCC's interpretation was retroactively punitive.

In its petition to the Supreme Court, Verizon argued that the FCC's fine violated due process because the agency had not previously articulated that carriers could be held liable for the unauthorized disclosures of independent third parties. The carrier maintained that it had taken reasonable steps by securing contractual promises of consent. However, the FCC and the U.S. Court of Appeals for the District of Columbia Circuit rejected this defense. The courts affirmed that a carrier's duty to safeguard highly sensitive location data is non-delegable, meaning that contractual clauses cannot absolve a telecom giant of its direct statutory responsibilities.

This legal defeat for Verizon comes amid intensifying scrutiny of the location data ecosystem. For years, mobile carriers operated lucrative programs that allowed external services—ranging from roadside assistance to financial fraud detection—to ping subscriber locations. However, the systemic abuse of these APIs revealed a vast, unregulated secondary market where precise coordinate data was traded with minimal oversight. Although the major carriers pledged to wind down these aggregator programs, the FCC's fines served as a retroactive reckoning for years of systemic compliance failures that left millions of mobile users vulnerable to unauthorized tracking.

The Supreme Court's decision to bypass the case solidifies a major shift in how federal regulators police the telecom sector. Historically, carriers operated under the assumption that notice-and-consent frameworks, even when buried in lengthy terms of service, provided sufficient legal cover. By upholding the FCC's strict liability approach, the judiciary has signaled that actual, verifiable consent is required for the dissemination of sensitive telemetry. This aligns with a parallel crackdown by the Federal Trade Commission against data brokers, indicating a coordinated federal effort to dismantle the unauthorized surveillance economy from multiple regulatory angles.

For the broader technology sector, the ruling establishes a key precedent for any platform that monetizes user telemetry through middleman APIs. Software developers, ad networks, and operating system vendors must now re-evaluate their liability exposure when sharing location data with third-party software development kits and advertising libraries. If the legal standard of non-delegable duty spreads from telecommunications to general consumer internet platforms, companies will no longer be able to blame third-party partners for data leaks. The burden of active verification will fall squarely on the primary data collector.

Moving forward, the focus shifts to how the FCC will enforce these standards in the era of 5G and satellite-to-device connectivity. Next-generation networks generate even more precise spatial data, often tracking users down to specific rooms inside buildings rather than general cell tower sectors. With the Supreme Court declining to curb the FCC's enforcement power under Section 222, the agency is well-positioned to apply these strict privacy mandates to emerging communication technologies. Industry players will need to implement robust auditing mechanisms to ensure that no user location data is exposed without explicit consent.

Sources

  1. 01 Supreme Court rejects Verizon bid for $47 million refund of FCC fine — Ars Technica
  2. 02 Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy — EFF Deeplinks
#fcc #verizon #supremecourt #privacy #telecom