Last updated: 2026-10-02
On June 25, 2026, Judge B. Lynn Winmill of the US District Court for the District of Idaho signed the stipulated order for injunction in FTC v. Kochava, Inc., No. 2:22-cv-00377-BLW, which resolves the Federal Trade Commission's lawsuit against Idaho-based Kochava, filed on August 29, 2022. Under the Kochava FTC settlement, Kochava Inc. and its subsidiary Collective Data Solutions, LLC (CDS) "must not sell, license, transfer, share, or disclose" location data tied to medical facilities, religious organizations, shelters and other sensitive locations, unless the defendants have a direct relationship with the consumer, the consumer gave "Affirmative Express Consent", and the data is used for a service the consumer requested (Provision II). The order contains no money payment, and the defendants "neither admit nor deny any of the allegations in the Complaint" (Finding 3).
The FTC announced the proposed settlement on May 4, 2026, after a 2-0 Commission vote. The entered order is Document 138, dated and filed June 25, 2026; the FTC case page lists it under June 26, 2026. Its definitions and provisions match the text of the proposed order, Document 137-1, except for spacing and one typo. Kochava and CDS signed the proposed order on March 2, 2026. The order terminates 10 years after entry (Provision XVIII).
What did the FTC allege against Kochava?
The Second Amended Complaint of July 15, 2024 alleges that Kochava "acquires consumers' precise geolocation data from other data brokers" and "does not, itself, interact directly with individual consumers" (paragraph 28). It alleges that each pair of timestamped coordinates in Kochava's feed is linked to a "device_id_value", the phone's mobile advertising ID (MAID), and quotes Kochava's marketplace listing: "94B+ geo transactions per month, 125 million monthly active users, and 35 million daily active users" (paragraphs 32 and 33). The court denied Kochava's motion to dismiss the first amended complaint on February 3, 2024.
From the FTC's May 4, 2026 release: "The FTC alleged that because consumers were unaware of and did not consent to this data sharing, consumers had no way of avoiding the harm resulting from its collection and disclosure." The release also states that CDS "has taken over Kochava's data broker business". These are the FTC's allegations.
What does the Kochava settlement order require?
Most obligations bind CDS from entry, and bind Kochava once it sells, uses or discloses precise location data.
| Provision | Obligation | Binds | Deadline from entry |
|---|---|---|---|
| II | No sale, license, transfer, sharing or disclosure of Sensitive Location Data, except with a direct relationship, Affirmative Express Consent and a service the consumer requested | Kochava and CDS | Applies to locations CDS lists within 90 days |
| III | Sensitive Location Data Program: a list of Sensitive Locations, reassessed every three months; data without confirmed consent deleted or "rendered non-sensitive" in a process started within 2 days and completed within 30, extendable to 90 | CDS; Kochava before it sells or discloses Precise Location Data | 90 days |
| IV | A copy of the order to every customer that received Precise Location Data in the past two years | Kochava and CDS | 90 days |
| VI | Supplier Assessment Program: confirm that consumers consented to all Supplier-Provided Location Data; stop using data where consent is unconfirmed | CDS; Kochava before it sells or uses that data | 90 days; each supplier within 30 days, then yearly |
| VII to IX | Consumers can ask which Recipients got their data and withdraw consent; use of that device's data stops within 30 days of withdrawal | CDS; Kochava if it sells or uses Precise Location Data | Ongoing |
| X | Deletion of a device's Precise Location Data within 30 days of a consumer request | CDS; Kochava on the same condition | Ongoing |
| XII | Historical Location Data deidentified or "rendered non-sensitive", unless consent records under Provision VI exist | Kochava and CDS | 90 days |
| XIII | A comprehensive privacy program for Covered Information | Kochava and CDS | 90 days |
Source: the entered order, pages 9 to 24. Provision V requires a report to the FTC within 30 days after a defendant determines that a third party shared its Precise Location Data in breach of contract, and Provision XI requires a public data retention schedule within 60 days.
Provision XII requires historical data to be deidentified or made non-sensitive; the FTC release describes the Provision XI retention schedule as one that "will require the deletion of data on an established timeframe".
Which locations are sensitive, and what is precise location data?
"Sensitive Locations" are US locations associated with "(1) medical facilities; (2) religious organizations; (3) locations of entities held out to the public as predominantly providing education or childcare services to minors; (4) locations held out to the public as providing temporary shelter or social services to homeless, or survivors of domestic violence; or (5) military or federal law enforcement installations, offices, or buildings" (Definition M).
"Precise Location Data" includes GPS coordinates, cell tower information, location "inferred from basic service set identifiers (BSSIDs), WiFi Service Set Identifiers (SSID) information, or Bluetooth receiver information, and any unique persistent identifier combined with any such data, such as a mobile advertising identifier (MAID) or identifier for advertisers (IDFA)" (Definition G). Data that reveals only "coarse location data (e.g., zip code or census block location with a radius of at least 1,850 feet)" is excluded. Definition O, "Supplier-Provided Location Data", uses the same wording and the same 1,850-foot exclusion.
Affirmative Express Consent requires a disclosure "separate from any 'privacy policy,' 'terms of service,' 'terms of use,' or other similar document", and consent obtained "through a user interface that has the effect of subverting or impairing user autonomy, decision-making, or choice" does not count (Definition A).
Two other sources set a distance close to the order's 1,850 feet. Connecticut's sale ban defines precise geolocation data at 1,750 feet. In EFF's August 2026 ad SDK study, covered in the post on the EFF study, Verve said its HyBid SDK limits location "to an accuracy radius of no less than 1,850 feet", and EFF found the code rounds coordinates to two decimal places. One degree of latitude is about 364,000 feet (USGS, at 38 degrees north), so a coordinate rounded to two decimal places is within about 1,820 feet of the true point north to south, and one rounded to three decimal places within about 182 feet.
Does the Kochava order cover the Kochava SDK?
The words "SDK" and "software development kit" appear nowhere in the order. Its location provisions address data the defendants sell or disclose and data they obtain from suppliers. Provisions XI and XIII apply to "Covered Information", defined as information "from or about an individual consumer", including "a mobile device ID" (Definition C).
The complaint names the SDK. It alleges that Kochava's Free App Analytics SDK is installed in at least "10,000 apps globally" and that app developers grant Kochava a "perpetual, irrevocable, worldwide, transferrable unrestricted license" to consumer information collected through it (paragraphs 62 and 63).
Kochava's own SDK Data Privacy and Safety page lists the datapoints its SDK transmits: on Android, the Google Advertising ID and Google App Set ID; on iOS, the IDFA, "automatically redacted as of iOS 14.5 if ATT authorization has not been granted"; and, among device state datapoints, "Network SSID" and "Network BSSID", which the page states are used for analytics, reporting and fraud detection. Definition G of the order covers location inferred from SSID and BSSID information. Kochava's page lists what the SDK sends and is silent on whether Kochava infers location from those fields. The order's text leaves open whether SDK-collected data is Precise Location Data.
The same page lists 13 Kochava-owned backup domains the SDK "is capable of calling", among them kochava.com, akisinn.me and dewrain.life. Kochava's Android integration guide records that the SDK "package name was renamed from com.kochava.tracker to com.kochava.measurement.base" with the move to the 6.x release, so builds from before and after the rename contain different class names.
What does a CITT scan show for an app with the Kochava SDK?
When I scan an app, the report lists the SDKs found in the binary, including Kochava classes under either package name, the location and Wi-Fi permissions the app declares, and the consent flow on screen. The network capture from test devices records each request sent to kochava.com and to the backup domains: the host, the field names, and whether an advertising ID was sent in the same request as coordinates or SSID and BSSID values. It also records the decimal precision of any coordinates, for comparison with the order's 1,850-foot line, and whether each request was sent before or after the consent prompt or the iOS App Tracking Transparency prompt. Every static finding cites its file and line; every traffic finding cites its capture.
A Kochava class in the binary shows the code is there; only a capture shows what was sent. What Kochava does with a request after it arrives is outside any app capture. What a scan checks and the limits of a scan are on the methodology page.
I run these investigations for lawyers and for researchers working with lawyers, on one app or on a list of apps in bulk. Sign up for a CanITrustThat (CITT) account to run your own research, let us run an investigation for you, or browse the scanned apps.