Seven ways to keep a location away from data brokers

A translation of Databroker Files: Sieben Wege, um deinen Standort vor Databrokern zu schützen by Sebastian Meineck and Ingo Dachwitz, netzpolitik.org, 15 January 2025, published under CC BY-NC-SA 4.0 and translated here under the same licence. The original is in German and there is no English edition. Settings paths and organisations are as the authors described them at the time.

Data brokers sell the phone location data of millions of people worldwide. Tens of thousands of apps are affected, as publications by netzpolitik.org and research partners in six countries show. Here is what a person can do to protect themselves.

Experts speak of a complete loss of control, and the people affected have had enough. The location data of millions of phone users worldwide is for sale. Data brokers collect it in multi-billion record packages. They even give it away as a preview of paid subscriptions. Our Databroker Files research documents this, work that began at a national level and now describes the worldwide trade as well.

In our new dataset of 380 million location records from 137 countries there are large differences in accuracy. Many of the traded records are vague by several kilometres. Others are accurate to the metre. In 2024 we analysed a dataset of 3.6 billion highly accurate location records from Germany alone. Data like this can reveal where a person lives and works, where they take their children to nursery, where they go for psychotherapy, or to a brothel.

Location data is not all that circulates. A great deal else can be captured: which phone somebody uses, which network operator, which apps, which websites they have visited. On that basis people are also sorted into categories, meant to mark them out as a supposedly “fragile senior” or a “shopping-obsessed mum”.

Anyone using their phone without particular protective measures, as most people do, is very probably affected. Many paths lead through apps and websites into the maw of the data brokers. Here we summarise some simple steps phone users can take to protect themselves.

1. Switch off the mobile advertising ID

The mobile advertising ID (MAID) is a sort of numberplate. Most phones generate this advertising ID quietly in the background. Devices running iOS are affected, meaning Apple’s phones and tablets, as are most ordinary phones running Google’s Android operating system.

The advertising ID makes our devices, and so ourselves, uniquely recognisable to the advertising industry. It is often attached when apps disclose our location to data traders or serve personalised advertising.

The advertising ID can be switched off in the system settings. The exact path can differ by operating system and version.

  • Google-based Android: Settings, Google (Google services), All services, Ads.

  • iOS: Settings, Privacy, Tracking, and disallow tracking for apps.

2. Withdraw location access from apps

Many apps want access to a device’s precise location. Anyone wanting protection from this form of tracking does not allow it, or allows it only in the few cases where a location is genuinely wanted, or where the app needs it for its core function. Being guided in real time by a navigation app, for instance.

Most other apps can safely be refused access to location data. Weather apps sometimes want access to the precise device location. It is not necessary. Often a person can simply type in the city whose weather they want.

Location access can be checked and changed afterwards in the system settings, app by app, on both Android and iOS.

3. Switch off location technologies

A device’s location can be determined through several sources: GPS, the mobile network, Bluetooth or wifi. Anyone wanting to lower the tracking risk switches on only what is actually needed at the time.

4. Limit location by IP address

A rough location can also be derived from the public IP address. It comes from the internet access provider. It is transmitted automatically when a person uses apps and websites, and is technically necessary for communication. At first glance an IP address has no direct connection to a location. Unlike access to the GPS location, apps do not have to ask separately for the IP address.

Locations can nonetheless be derived from IP addresses, and our research shows that this happens on a mass scale. Providers such as the American data broker MaxMind specialise in assigning specific locations to IP addresses. They gather clues for this from public databases on internet infrastructure, among other sources. The assignment is not always correct, but a rough location to within a few kilometres is sometimes possible.

There are several ways to protect against this.

  • VPN services can disguise the actual IP address from apps and websites, which then see only the VPN provider’s IP address. On the other hand, the VPN provider then has to be trusted in this scenario, since it can see the real public IP address.

  • Tracking and advertising blockers take a more fundamental approach, as the privacy expert Mike Kuketz explains on his blog. Using blocklists, they stop a device from connecting to known tracking services in the first place and transmitting all sorts of data in the process. These blocklists need regular updating, though, and can be patchy. Manual corrections are sometimes necessary, for instance specifically for the apps a person wants to use.

  • There are tracking and advertising blockers at browser level too. These blockers are limited to websites visited in the browser, so they do not affect tracking by apps.

  • Tracking can equally be suppressed through special DNS servers. DNS is one of the most important services on the internet, translating domain names into IP addresses. Anti-tracking DNS servers come with additional filter lists, which hold known addresses that put users at risk through tracking. Communication with those addresses is blocked.

5. Refuse tracking wherever possible

For websites and apps, tiresome though it is: refuse cookie banners and similar tracking requests consistently.

The relevant dialogues are often deliberately confusing, or refusing tracking is not possible at all. Then all that remains is reaching for alternatives.

6. Switch to tracking-free alternatives

Many of the apps, websites, services and platforms of everyday digital life are built on tracking, and therefore on the surveillance of their users. Not for everything, but for a great deal, there are data-frugal alternatives. Does a weather, navigation or shopping app really need hundreds of “advertising partners”?

There is a further difficulty: data can also flow out without the knowledge or consent of the app’s operators, for example because software packages embedded from third parties do not only do what they are supposed to. The risk is higher with bloated or outdated software, with closed-source software, and with anything otherwise questionable.

Switching completely to data-frugal alternatives overnight can quickly become overwhelming. But a person can proceed step by step. Recommendations for data-frugal apps can be found at mobilsicher.de or on Mike Kuketz’s blog, for instance. Operators of non-commercial software are often glad of donations.

There are options at operating-system level as well. It does not always have to be iOS or Google-based Android. Providers of Google-free Android versions have made it their task to offer alternatives to the tracking-based mainstream. That often comes at the cost of convenience, though work continues on making them usable by more than nerds.

7. Push for political solutions

Anyone who attends carefully to their own digital self-defence can reduce the danger from tracking considerably. Among friends, colleagues and family a person can share suggestions and offer help. For most people, though, the many necessary tricks of digital self-defence are hardly reasonable to expect: they simply have other worries. And many want to take part in the tracking-riddled digital life that whole generations have long since grown used to.

Mass surveillance through phone data is a problem whose solution cannot be offloaded onto consumers. That is why many have been calling for political solutions for years, such as a ban on tracking and profiling for advertising purposes. Data that is never collected in the first place cannot reach data brokers either. The federation of German consumer organisations calls for this, as does the federal consumer protection ministry. The ball is with the EU, whose efforts most recently failed against corporate lobbying. The EU’s planned Digital Fairness Act could be an opportunity for a fresh attempt. Those interested could approach their elected representatives, or organise with NGOs that work on digital policy as part of civil society.

Anyone wanting to go further can invoke their rights under the General Data Protection Regulation and send access requests to data traders. The companies are obliged to answer, and to say what data they hold about a person. Even when nothing happens for a long time, and companies outside the EU are often hard to reach, requests make visible that users have a problem. Anyone who feels something is amiss can then turn to the competent data protection authority.

Where these pages cover the same ground

The advertising ID from step 1 has its own runbook. Tracker blocking from step 4 sits in the blocking playbook, and the access requests from step 7 in the data subject request runbook. The trade this guide defends against is documented in the Databroker Files case.

Last reviewed: 2026-08-13.