Categories
Privacy & Consent

Consented Location Data: What Consent Actually Requires

Almost every location data vendor says their data is consented. Very few can show what that consent actually covered, who obtained it, or what happens when someone withdraws it. Those are different claims, and only the second one survives diligence.

What consent has to be under GDPR

The GDPR sets a specific bar. Consent must be:

  • Freely given — not a condition of using an app that has no need for location.
  • Specific — covering a named purpose, not bundled into a general permission.
  • Informed — the person understands what is collected and who receives it.
  • Unambiguous — a clear affirmative action, never a pre-ticked box or silence.
  • Withdrawable — as easily as it was given.

An OS-level location permission is not, on its own, consent for commercial data sharing. It grants the app access. Whether the person agreed that their movements could be collected, aggregated and sold is a separate question, and it is the one that matters.

The chain consent has to survive

Location data typically passes through several hands between the person and the buyer:

  1. A person installs an app and grants location permission.
  2. An SDK inside that app collects position data.
  3. The SDK operator aggregates data across many apps.
  4. A platform or broker packages it.
  5. A buyer uses it for analysis or advertising.

Consent is obtained at step one. Every later step relies on it remaining valid and accurately described. If the disclosure at step one never mentioned onward sharing, everything downstream is built on a permission that was never given.

This is why provenance matters more than volume. A large panel assembled from sources that cannot evidence their consent is a liability, not an asset.

What to ask a supplier

Question What a good answer looks like
Where does the data originate? Named SDK or first-party sources, not “a network of partners”
What were people actually told? The disclosure wording, not a summary of it
How is withdrawal propagated? A described mechanism reaching downstream recipients, with a timeframe
Are consent records auditable? Evidence per source, retrievable on request
How are opt-outs honoured? Handling of platform signals and direct requests
What happens on a deletion request? A working process, tested, not a policy page

Where it usually goes wrong

Consent for one purpose reused for another. Permission for maps inside a navigation app does not extend to selling movement patterns to advertisers.

Withdrawal that stops at the first hop. If someone opts out and that signal never reaches the parties already holding their data, the withdrawal is cosmetic.

Provenance that dissolves under questioning. A supplier who cannot name their sources cannot evidence consent for them either.

Treating anonymisation as a cure. Location histories are famously re-identifiable; a handful of visit patterns can single out an individual. Removing an identifier does not automatically place the data outside GDPR.

Why this is a data quality issue, not only a legal one

It is tempting to file consent under compliance and move on. In practice the two track together. A supply chain that can explain its provenance can usually also explain its accuracy, its panel composition and its refresh rate. One that cannot evidence consent generally cannot evidence methodology either, because both require knowing where the data came from.

Diligence on consent is, in effect, free diligence on quality.

Common questions

Is location data personal data?

Usually yes. A position history singles out an individual even without a name attached, because it reveals where someone lives, works and spends time. Regulators have consistently treated it as identifying.

Does an app permission count as consent?

Not by itself. It grants the app technical access. GDPR-valid consent for onward commercial use requires a specific, informed and unambiguous agreement to that use.

What is the difference between consented and anonymised data?

They address different things. Consent concerns whether collection and use were permitted. Anonymisation concerns whether an individual can still be identified. Anonymising data does not retrospectively supply consent that was never obtained.

Who is liable if a supplier’s consent is invalid?

Under GDPR, controllers carry responsibility for the lawfulness of the data they process — including data acquired from third parties. Buying from a supplier does not transfer that obligation, which is why diligence sits with the buyer.

Next steps

Consent is not a checkbox in a procurement form. It is a property of a supply chain, and it can be evidenced or it cannot.

Our data transparency pages set out how Tamoco sources consented location data and what we can evidence about it.

By James Ewen

James is the head of marketing at Tamoco