More than a dot on a map
A single location fix says where a device was at one moment. A location record holds more: a series of places, each with a time, and it may be tied to an account or a device identifier. Put together, those points describe a life.
The US Federal Trade Commission put it plainly in a January 2024 action against a data broker. Its chair said that geolocation data “can reveal not just where a person lives and whom they spend time with but also, for example, which medical treatments they seek and where they worship.” The complaint concerned precise location data that the FTC said could be used to track visits to sensitive locations such as medical and reproductive health clinics, places of religious worship and domestic abuse shelters.
The FTC also described how that data stayed personal. The raw location data was associated with mobile advertising IDs, unique identifiers tied to each device, and the FTC said it was not anonymised and could match an individual’s device with the places it visited.
A few points can single someone out
In 2013, de Montjoye and colleagues published “Unique in the Crowd” in Scientific Reports. According to its abstract, they studied fifteen months of mobility data for one and a half million people and found that human mobility traces are highly unique. In a dataset where each person’s location was recorded hourly, at the resolution of the carrier’s antennas, four spatio-temporal points were enough to uniquely identify 95% of the individuals.
The authors then coarsened the data in space and time. They found that the uniqueness of mobility traces decays approximately as the 1/10 power of their resolution, and concluded that even coarse datasets provide little anonymity.
The lesson is that the trace itself is the identifier. A name is not needed when the pattern of where someone sleeps, works and spends weekends matches only one person.
Why anonymising location is hard
The European Data Protection Board reached the same view in its 2020 guidelines on location data. It describes location data as notoriously difficult to anonymise and says mobility traces are inherently highly correlated and unique, so they can be vulnerable to re-identification.
The guidelines go further:
- A single data pattern tracing someone’s location over a significant period cannot be fully anonymised.
- That can remain true if the precision of the coordinates is not lowered enough, if details of the track are removed, and even if only the places where the person stays for substantial amounts of time are kept.
- Anonymisation applies to datasets as a whole. Encrypting or transforming a single person’s pattern is at best pseudonymisation, and pseudonymised data stays within the scope of the GDPR.
The Board judges anonymisation against three risks: singling out one person, linking records about the same person, and inferring unknown information about them.
Precision is a setting
Phones let people choose how much precision an app gets. Android distinguishes two levels. Approximate location is accurate to within about 3 square kilometres when it comes from the platform’s location providers. Precise location is usually within about 50 metres, and sometimes within a few metres or better. If the user grants only approximate location, the app gets only approximate location, whatever it requested. Apple has a similar split: an app can be authorised for full accuracy or reduced accuracy.
Coarser data is better, but given the 2013 finding it is not a complete answer. Time matters as much as place, because every point in a trace is both a place and a time.
Designing with location data
If your product records location, a few habits follow from the sources above:
- Collect the least precision the feature needs. Android asks apps to keep working when the user grants only approximate location.
- Coarsen time as well as place. Hourly points were enough in the 2013 study.
- Keep records for as short a time as you can, and let people withdraw consent and delete them. The FTC’s proposed order required both a data retention schedule and a simple way to withdraw consent and delete data.
- Get informed consent. The FTC charged that the broker failed to ensure apps obtained informed consent for access to sensitive location data.
- Treat public records as permanent. Data written to a public blockchain cannot be withdrawn. In Offline Protocol’s Proof of Location, which runs on Ethereum Sepolia testnet, a geohash at precision 5, approximately a 5 km cell, and each task’s time remain public, and its docs note that public location and timing can still reveal information. They ask developers to obtain informed consent before submitting data that cannot be deleted from the chain.
Features such as geofencing produce location records too, as lists of arrivals and departures. The same care applies to them.