The Data Brokers: Mobilewalla
The FTC says Mobilewalla collected sensitive location data through ad tech systems, used it to build audience segments, and allowed the data to move through downstream sales, including to government customers.
Series: The Data Brokers | The Shield Blog
Reading time: 14 minutes
The Report
In late May and June 2020, large demonstrations took place across the United States following the killing of George Floyd. Many people attended protests expecting that being part of a large crowd would offer practical anonymity.
Reporting and public records later showed that some data and analytics firms analyzed mobile location signals connected to protest areas.
Mobilewalla, a consumer data and analytics company, published a press release on June 18, 2020 describing a report that estimated demographic characteristics of people present at protest locations in four cities. The press release stated that the report analyzed data associated with nearly 17,000 mobile devices and included charts estimating characteristics such as age range, gender, and race.
Mobilewalla described the report as an analysis exercise based on data it had access to through commercial sources.
IMPORTANT:
Even when a dataset is presented as aggregated, the underlying collection often begins with device-level identifiers and location histories. That upstream collection is what creates privacy and safety risk.
The Business
Mobilewalla, founded in 2010 and headquartered in Georgia, has described itself as a consumer analytics company that helps clients model and predict consumer behavior.
According to the Federal Trade Commission, Mobilewalla collected large volumes of consumer data by participating in the digital advertising ecosystem. The FTC’s complaint alleges that, between January 2018 and June 2020, Mobilewalla obtained more than 500 million unique mobile advertising identifiers paired with location data.
The FTC described Mobilewalla’s data sources as including:
Real-time bidding (RTB) exchanges
Automated ad auctions that occur when apps and websites request ads. These auctions can distribute device identifiers and related signals to multiple parties during bidding.Third-party data suppliers
Vendors that provide data feeds within the data broker ecosystem.SDKs embedded in apps
Software components integrated into apps that may collect and share location and identifier data.
The FTC alleged that the data included mobile advertising identifiers (MAIDs), precise latitude and longitude coordinates, and timestamps. These elements can enable persistent tracking of devices over time.
Audience Segments
Mobilewalla did not only sell or analyze location data as raw coordinates. The FTC alleged the company also created products that categorized devices into groups or “audience segments” based on visits to specific locations or inferred attributes.
According to the FTC, Mobilewalla’s segments included categories associated with:
- Religious worship and affiliation
- Health-related conditions or visits
- LGBTQ+ associated locations
- Labor-related gatherings such as union activity
- Political gatherings, rallies, or protests
The FTC described the company’s use of geofencing, a technique that draws a virtual boundary around a physical location and identifies devices that appear within that boundary during a time window.
IMPORTANT:
Geofencing does not require an individual to check in, post publicly, or self-identify. A device’s presence can be inferred from commercial location signals.
Examples Cited in the FTC Complaint
The FTC complaint described several examples of how location data and geofencing-based products could be used by customers. The examples below are presented as allegations and excerpts from the FTC’s filing.
Example 1: Recruiting healthcare workers
The FTC described a request in which a client sought geofencing and targeting connected to healthcare workers and facilities, including targetin
