Deletion stops future use, but it does not repay someone whose movements were already sold. In the Outlogic case, the FTC said raw location data tied to mobile advertising IDs could expose visits to clinics, houses of worship, and domestic-abuse shelters. A statutory payment would give companies a reason to minimize collection before the harm becomes impossible to reverse.
Should companies be required to pay customers when they misuse location data?
Precise location histories can reveal visits to clinics, places of worship, and shelters. Regulators have ordered data deletion and sales bans, while other consumer-protection cases show that large-scale refunds are possible; the unresolved question is when misuse should automatically create a right to payment.
The cases
For (2)
Consumer compensation is administratively possible. The FTC's Epic Games order created a $245 million refund pool, the agency's largest gaming refund. Location cases will need a different formula, perhaps a base amount plus more for sensitive places, but “hard to calculate” should not mean the entire value of misuse stays with the company.
Against (2)
Not every location violation creates the same risk. A poorly worded consent screen is different from selling identifiable visits to a shelter. A flat payout could encourage nuisance claims while underpaying the worst cases. Regulators should keep the ability to choose refunds, as they did in the $245 million Epic order, rather than make one remedy mandatory.
Automatic checks to everyone sound fair until most payments are tiny and the claims process consumes the fund. In the Outlogic settlement, the strongest remedies were a sales ban, deletion, consent, and a privacy program. Those measures attack the data pipeline itself. Compensation should be reserved for people who can show concrete loss or unusually sensitive exposure.