What's Happening?
US Senator Ron Wyden (D-OR) and Rep. Pat Harrigan (R-NC) have called for an investigation by the Defense Department Inspector General into why location data tied to US military personnel remains commercially available, despite efforts to prevent such
tracking. In May, the lawmakers, along with a bipartisan group, revealed how commercially purchased location data, often collected by mobile apps and advertising SDKs, could be used to identify and target US military personnel. The Department of Defense (DoD) has been aware of this threat since at least 2016. While several military branches, including the Army, Air Force, Navy, Marine Corps, and Special Operations Command, have confirmed they now disable advertising IDs on government-issued devices, reports indicate that location data pinpointing troop movements is still accessible. The lawmakers are seeking to understand why current DoD policies have not fully mitigated this risk, speculating that some components may have only recently disabled advertising identifiers, that disabling these identifiers may no longer be sufficient, or that the data is originating from personal devices of DoD personnel and contractors.
Why It's Important?
The continued availability of location data for US military personnel poses significant national security risks. Adversaries could exploit this data to track, target, and potentially harm service members and their families, especially those deployed in combat zones or sensitive locations. This issue highlights a critical vulnerability in the digital privacy and security protocols surrounding military operations. The reliance on mobile advertising identifiers (MAIDs) as 'join keys' to link different datasets means that even if government-issued devices are secured, personal devices brought into DoD facilities or overseas could still be broadcasting sensitive location information. The fact that data brokers sell this information to virtually anyone with a credit card, and that foreign ad tech vendors in countries like Russia and China may also be collecting this data, underscores the urgency of the congressional inquiry. This situation could compromise operational security, endanger personnel, and potentially reveal classified movements or locations, thereby undermining military effectiveness and national defense.
What's Next?
The Defense Department Inspector General is expected to launch an investigation into the efficacy of current DoD policies regarding location data and advertising identifiers. This investigation will likely examine the extent to which location data of military personnel is still being collected and sold, the sources of this data (government-issued vs. personal devices), and the effectiveness of measures taken by various military branches. Lawmakers may push for stricter policies, potentially including mandatory disabling of advertising identifiers on all personal devices brought into DoD facilities or overseas, and increased pressure on tech companies like Google and Apple to reform their mobile advertising ID practices. The findings of the Inspector General's report will likely inform future legislative actions and DoD cybersecurity directives aimed at enhancing the privacy and security of military personnel in the digital realm.
Beyond the Headlines
This issue extends beyond immediate security concerns, touching upon broader ethical and legal implications of data privacy in the digital age, particularly for individuals in sensitive roles. The commercial ecosystem of data brokers and ad tech companies, which routinely collect and sell granular location data, presents a systemic challenge to privacy that impacts not only military personnel but also the general public. The lack of effective regulation over data brokers and the global reach of ad tech networks mean that personal data, once collected, can be exploited by various actors, including foreign adversaries. This situation highlights the need for comprehensive data privacy legislation that addresses the collection, sale, and use of location data, especially when it pertains to national security interests. It also raises questions about the responsibility of technology companies in designing systems that inherently facilitate such widespread data collection and the potential for misuse.











