Location and proof of location

What can a location record reveal?

A location record can reveal far more than where a device was at one moment. A series of places and times can point to where someone lives, whom they spend time with, which medical treatments they seek and where they worship, and a 2013 study of human mobility data found four spatio-temporal points enough to uniquely identify 95% of the individuals in it. Removing names does not make such data anonymous, and the same study concluded that even coarse datasets provide little anonymity.

Learning objectives

After reading this article you will be able to:

  • Explain why a few places and times can uniquely identify a person
  • Describe why European regulators treat location traces as hard to anonymise
  • List design habits that reduce what recorded location data can reveal

More than a dot on a map

A single location fix says where a device was at one moment. A location record holds more: a series of places, each with a time, and it may be tied to an account or a device identifier. Put together, those points describe a life.

The US Federal Trade Commission put it plainly in a January 2024 action against a data broker. Its chair said that geolocation data “can reveal not just where a person lives and whom they spend time with but also, for example, which medical treatments they seek and where they worship.” The complaint concerned precise location data that the FTC said could be used to track visits to sensitive locations such as medical and reproductive health clinics, places of religious worship and domestic abuse shelters.

The FTC also described how that data stayed personal. The raw location data was associated with mobile advertising IDs, unique identifiers tied to each device, and the FTC said it was not anonymised and could match an individual’s device with the places it visited.

A few points can single someone out

In 2013, de Montjoye and colleagues published “Unique in the Crowd” in Scientific Reports. According to its abstract, they studied fifteen months of mobility data for one and a half million people and found that human mobility traces are highly unique. In a dataset where each person’s location was recorded hourly, at the resolution of the carrier’s antennas, four spatio-temporal points were enough to uniquely identify 95% of the individuals.

The authors then coarsened the data in space and time. They found that the uniqueness of mobility traces decays approximately as the 1/10 power of their resolution, and concluded that even coarse datasets provide little anonymity.

The lesson is that the trace itself is the identifier. A name is not needed when the pattern of where someone sleeps, works and spends weekends matches only one person.

Why anonymising location is hard

The European Data Protection Board reached the same view in its 2020 guidelines on location data. It describes location data as notoriously difficult to anonymise and says mobility traces are inherently highly correlated and unique, so they can be vulnerable to re-identification.

The guidelines go further:

  • A single data pattern tracing someone’s location over a significant period cannot be fully anonymised.
  • That can remain true if the precision of the coordinates is not lowered enough, if details of the track are removed, and even if only the places where the person stays for substantial amounts of time are kept.
  • Anonymisation applies to datasets as a whole. Encrypting or transforming a single person’s pattern is at best pseudonymisation, and pseudonymised data stays within the scope of the GDPR.

The Board judges anonymisation against three risks: singling out one person, linking records about the same person, and inferring unknown information about them.

Precision is a setting

Phones let people choose how much precision an app gets. Android distinguishes two levels. Approximate location is accurate to within about 3 square kilometres when it comes from the platform’s location providers. Precise location is usually within about 50 metres, and sometimes within a few metres or better. If the user grants only approximate location, the app gets only approximate location, whatever it requested. Apple has a similar split: an app can be authorised for full accuracy or reduced accuracy.

Coarser data is better, but given the 2013 finding it is not a complete answer. Time matters as much as place, because every point in a trace is both a place and a time.

Designing with location data

If your product records location, a few habits follow from the sources above:

  • Collect the least precision the feature needs. Android asks apps to keep working when the user grants only approximate location.
  • Coarsen time as well as place. Hourly points were enough in the 2013 study.
  • Keep records for as short a time as you can, and let people withdraw consent and delete them. The FTC’s proposed order required both a data retention schedule and a simple way to withdraw consent and delete data.
  • Get informed consent. The FTC charged that the broker failed to ensure apps obtained informed consent for access to sensitive location data.
  • Treat public records as permanent. Data written to a public blockchain cannot be withdrawn. In Offline Protocol’s Proof of Location, which runs on Ethereum Sepolia testnet, a geohash at precision 5, approximately a 5 km cell, and each task’s time remain public, and its docs note that public location and timing can still reveal information. They ask developers to obtain informed consent before submitting data that cannot be deleted from the chain.

Features such as geofencing produce location records too, as lists of arrivals and departures. The same care applies to them.

Frequently asked questions

Is location data anonymous if it has no names attached?

Not necessarily. The European Data Protection Board says mobility traces are inherently highly correlated and unique, and that location data thought to be anonymised may in fact not be. Data that can still be linked to a person through reasonable effort has not been anonymised.

Does using approximate location solve the problem?

It reduces it, but does not remove it. The 2013 study found that the uniqueness of mobility traces decays approximately as the 1/10 power of their resolution, and concluded that even coarse datasets provide little anonymity.

Sources

Build it with Offline Protocol

The Proof of Location introduction states what remains public on Ethereum Sepolia testnet, a coarse geohash and each task's time, and asks developers to obtain informed consent before submitting data that cannot be deleted from the chain.

Read the Proof of Location introduction