Your Tax Dollars Are Buying Your Browsing History: How State Governments Spy on You Without a Warrant
You might assume that if a government agency wanted to see what websites you've been visiting, they'd need to go before a judge, make a case, and get a warrant. That's how it works in the movies, anyway.
In reality, across much of the United States, government agencies — including state and local ones — have found a much easier path. They just buy the data. No judge. No warrant. No probable cause required. Just a contract with a data broker and a government credit card.
This practice has been flying under the radar for years, but investigative reporting and public records requests have started to pull back the curtain on just how widespread it is. What's been revealed is equal parts unsurprising and alarming.
The Legal Loophole That Makes It All Possible
Here's the core issue: the Third-Party Doctrine. This is a legal principle, established in Supreme Court cases from the 1970s, that says you lose your Fourth Amendment privacy protections for any information you voluntarily share with a third party. When you share something with a company — your browsing habits, your location data, your purchase history — you're considered to have given up any reasonable expectation of privacy in that information.
In the 1970s, that meant your bank records. In 2024, it means everything. Every app on your phone that sells location data, every website that runs ad-tracking scripts, every data broker that aggregates your digital footprint — all of that sits in a legal gray zone where government agencies can purchase access without ever touching the warrant requirement.
The result is what privacy researchers call the data broker loophole: law enforcement agencies at every level, including state and local governments, routinely purchase commercially available data packages that would have required a court order to obtain directly.
Which States Are Most Active?
The picture isn't uniform across the country. Some states have passed laws restricting government use of commercially purchased data. Others have done the opposite — actively expanding their agencies' access to it.
California presents an interesting contradiction. The state has some of the strongest consumer privacy laws in the country (the California Consumer Privacy Act being the marquee example), but investigative reporting has found that California law enforcement agencies have still purchased location data and other commercially available information from brokers. The CCPA regulates what companies can do with your data — it doesn't prevent government agencies from buying data that was legally collected.
Texas has seen its state agencies, including the Department of Public Safety, use commercially purchased data in immigration enforcement contexts. Federal agencies operating within Texas have also been documented purchasing location data to track individuals without warrants.
Florida law enforcement agencies, particularly at the local level, have been active purchasers of data broker products. Some Florida counties have contracts with companies that aggregate phone location data, social media activity, and financial records into searchable databases.
Virginia and Maryland agencies, partly due to their proximity to federal intelligence infrastructure, have been documented using commercial data purchases as part of surveillance programs targeting protest activity and political organizing — a use that has drawn significant civil liberties scrutiny.
Missouri, Indiana, and Tennessee have been identified in public records requests as having minimal oversight requirements for government data purchases, making them among the least regulated states when it comes to this practice.
On the more protective end, Montana passed legislation in 2023 explicitly requiring a warrant for government access to location data, including commercially purchased data. Maine has similarly strong protections. These states are the exception, not the rule.
What Data Is Actually Being Collected?
The breadth of what's available on the commercial market — and therefore available to state agencies with a budget — is genuinely staggering.
Location data is the most commonly purchased category. Your phone's GPS, combined with data from apps that sell location permissions, can reconstruct a detailed log of everywhere you've physically been — your doctor's office, your place of worship, political rallies, gun shops, addiction treatment centers. All of it.
Browsing and app activity is increasingly available through data brokers who purchase it from mobile advertising networks. This can include the websites you've visited, the apps you've used, and even the search queries you've made.
Financial transaction data — not your bank account directly, but aggregated purchase patterns sold by payment processors and retail loyalty programs — can reveal a surprising amount about your lifestyle, health conditions, and political leanings.
Social graph data maps out your connections: who you communicate with, how frequently, and in what contexts. This is particularly valuable for investigations targeting organizations or communities rather than individuals.
Why This Should Concern Ordinary People
It's tempting to think "I have nothing to hide, so this doesn't affect me." But that framing misses the point.
The problem with warrantless mass data collection isn't just that it catches criminals without due process. It's that it creates infrastructure for profiling entire communities — people who attended a protest, people who visited a particular clinic, people who belong to a certain religious organization. History gives us plenty of examples of how that kind of infrastructure gets misused, and not all of those examples are ancient history.
There's also the chilling effect: when people know or suspect they're being watched, they change their behavior. They self-censor. They don't attend the meeting, don't make the search, don't visit the website. That's a cost to free society even when no specific harm occurs.
What You Can Actually Do About It
The good news is that the same tools that protect you from commercial surveillance also protect you from government agencies that rely on commercial data purchases. If your data doesn't end up in the broker's database, the government can't buy it.
Use a reputable VPN consistently. This prevents your ISP from logging and selling your browsing activity, and it hides your real IP address from the sites you visit. Free options exist — just make sure you're using one with a verified no-logs policy.
Audit your app permissions aggressively. Location data is the most commercially valuable thing on your phone. Go through your app permissions and revoke location access for anything that doesn't genuinely need it. Set location permissions to "while using" rather than "always" wherever possible.
Opt out of mobile advertising IDs. Both iOS and Android allow you to reset and limit your advertising identifier — the key that links your activity across apps. On iPhone, go to Settings > Privacy > Tracking and disable "Allow Apps to Request to Track." On Android, look for "Ads" in your Google account settings.
Use privacy-focused search and browsers. DuckDuckGo, Brave, and Firefox with privacy extensions significantly reduce the behavioral data that ends up in broker databases.
Submit opt-out requests to major data brokers. Sites like DeleteMe (paid) or manual opt-out guides for brokers like Acxiom, LexisNexis, and Spokeo can reduce your commercial data footprint over time. It's tedious, but it works.
Stay informed about your state's laws. The Electronic Frontier Foundation and the ACLU both maintain updated resources on state-level surveillance legislation. Knowing what protections you do and don't have is the first step to advocating for better ones.
The warrant requirement was supposed to be a meaningful check on government power. The data broker loophole has quietly hollowed it out. Until Congress or the courts close that gap, the most effective protection is keeping your data out of commercial hands in the first place.