Tired of ads? Enjoy an ad-free experience by signing up.
Meghna Rao · · 3 min read

InMobi sued for collecting location data without consent

Photo credit: Pixabay.

Photo credit: Pixabay.

InMobi will pay a US$950,000 fine to the US Federal Trade Commission (FTC) in response to a complaint filed against it on Wednesday.

According to the complaint, the adtech startup has been collecting cellphone users’ location data without their consent.

InMobi ties up with apps to get access to user information. It then feeds that info back into its database to help companies send out more relevant ads.

But if what the FTC says is true, not all of this data was collected openly.

Instead, it’s been going something like this: a user will give an app that InMobi is working with permission to access their geolocation services. InMobi adds the user to its large database of consumers – the FTC cites 1 billion phones – and uses that info to pick up on the unique addresses of wifi networks in the area.

Then, even if another user hasn’t given an InMobi-partnered app location access, it can still tap local wifi signals to pinpoint where that person is.

This is problematic for several reasons. First, it takes advantage of users who have shared their location data – and invades the privacy of those who haven’t consented at all.

It also puts app developers in an uncomfortable position. They’re required to provide a list of permissions that users can agree to before downloading an app, but none of what InMobi does is explicitly stated.

Data is oil in adtech and InMobi is desperate to get it.

“InMobi tracked the locations of hundreds of millions of consumers, including children, without their consent, in many cases totally ignoring consumers’ express privacy preferences,” said Jessica Rich, director of the FTC’s Bureau of Consumer Protection in a public statement.

That bit about children is perhaps the most problematic of InMobi’s tactics. It violated the Children’s Online Privacy Protection Act, which states that companies can only collect information from children under 13 with the explicit consent of their parents.

According to an email statement InMobi sent this morning, though, the child protection laws were broken due to a “technical error”. It was most probably an oversight – but a costly one.

The FTC has also asked the startup to delete all the info it collected from children and unconsenting adults. InMobi will implement a new privacy program that will be checked every two years for the next twenty years.

Mo money mo problems

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Meghna Rao

From New York, in Bangalore for now.