In its recent Chatrie v. United States decision, the Supreme Court held that obtaining a person’s Google location history through a geofence warrant falls within the Fourth Amendment’s protections. The 6-3 decision chips away at the third-party doctrine, a rule that has allowed the government to bypass particular warrants to access sensitive information people share with private companies.
But even after Chatrie, the Fourth Amendment’s protections remain narrow. Many of the ways the government gets our data never cross a judge’s desk. The strongest privacy protection, it turns out, isn’t a warrant: It’s when our data is never collected into a single vault. Yet lawmakers keep forcing companies to build them.
The rule at issue
The Supreme Court’s ruling stems from a 2019 bank robbery in Virginia. Because investigators did not have a specific suspect, they used a geofence warrant. Instead of targeting a known individual, this type of warrant requires a company like Google to search its location database and identify every device near a crime scene during a specific timeframe. Using this method, police identified Okello Chatrie, whose phone was one of 19 located near the robbery.
While this case moved through the court system, Google changed how it stores location history. In 2023, the company moved the data from its central servers directly to individual users’ devices. This change meant Google could no longer respond to geofence warrants. By the time the Supreme Court ruled on the case, Justice Samuel Alito noted in his dissent that the majority was weighing in on a procedure that was already obsolete.
To understand the impact of the Chatrie ruling, it is important to look at the legal rule the government used to request this data: the third-party doctrine. Born from two 1970s Supreme Court cases, United States v. Miller and Smith v. Maryland, the third-party doctrine determined that information and data collected by businesses as part of our voluntary interactions with them, like dialed numbers or bank records, carry no reasonable expectation of privacy and can be obtained by police and other government authorities without a warrant.
But technology has evolved, and today no one gets through a day without their phones, computers, other tech devices, and even their vehicles handing companies their locations, search queries, and private messages. The Supreme Court acknowledged this issue in 2018 in Carpenter v. United States, ruling that individuals have a privacy interest in “the whole of their physical movements.” In Carpenter, the court ruled that obtaining cell-tower phone records constitutes a search under the Fourth Amendment, even if it’s a phone company, and not the citizen targeted by police, who holds the data.
Chatrie extends Carpenter’s logic to location history. The majority reasoned this data is vastly more precise than cell-site location information (CSLI), capable of identifying the exact floor of a building a user has been on. And because location data is an unavoidable byproduct of phone use rather than a genuinely “shared” file, its collection lacks the “voluntary disclosure” the third-party doctrine was built on.
While the majority technically confined its holding to location data, Chatrie’s reasoning reaches further. If location history requires a warrant, it’s worth asking whether the same protection should extend to the rest of the data on our phones.
Alito pressed this point further, asking where the boundary lies between location data and other traditionally unprotected records like digital purchases, search histories, and payment logs. The court may not be explicitly protecting those records yet, but Chatrie sets a precedent, and the era of using the third-party doctrine to justify warrant-free surveillance may be slowly coming to an end.
The “panopticon” problem and how Google dismantled it
But even if the Supreme Court overturned the third-party doctrine tomorrow, the core privacy concerns would remain. Justice Elena Kagan noted that the government can draw on an “all-encompassing database” of people’s movements, “a virtual panopticon with which to scrutinize its citizens’ activities.” Justice Ketanji Brown Jackson echoed this in her concurrence, noting that only Google’s pushback, not the law, stopped police from gathering data on everyone swept up in the Chatrie geofence.
Ultimately, a company’s decision to eliminate a database offered more practical privacy protection than the Fourth Amendment. Google’s decision was valuable and important for its users’ privacy, but there are still thousands of other apps that stockpile our sensitive data. Various government agencies have found a way to collect our private data from them, bypassing the Fourth Amendment entirely.
The purchase loophole
The easiest workaround for the government is simply buying the data. Data brokers harvest location data from ordinary apps and sell it to anyone, including the government, and the Chatrie decision does not protect this information from collection.
The Constitution is designed to stop the government from forcing its way into your private life without due process. But because the government isn’t forcing the broker to hand over the information, it doesn’t need a warrant. Instead, the law treats the government just like any ordinary paying customer.
This loophole betrays the Fourth Amendment’s underlying intent. America’s founders banned “general warrants” specifically to stop the government from indiscriminately rummaging through people’s private lives to monitor their beliefs, habits, and associations.
Today, federal agencies buy Americans’ data and acknowledge it can reveal as much as data obtained via a warrant. The military bought location data from a Muslim prayer app, allowing them to track and profile a specific religious group without cause. Homeland Security violated its own policies to buy phone-tracking data. Local police use cheap subscriptions to special search engines to browse billions of location pings without legal process. After Roe v. Wade was overturned by Dobbs v. Jackson Women’s Health Organization, one broker even sold data to enable tracking visits to abortion clinics.
When the government demands businesses maintain the panopticon for them
But there is a more systemic problem underlying all of this: The government often mandates the creation of the very databases it later exploits. For 50 years, the Bank Secrecy Act of 1970 has required banks to record customers’ transactions and report anything suspicious. In fact, the records in Miller, the case that created the third-party doctrine, existed only because this law demanded them. And to this day, federal agencies use this exact system to comb through Americans’ finances without warrants.
Smith followed the same blueprint: The phone records in that case existed solely because FCC regulations mandated telecom companies to retain them. When regulators later tried to scrap the rule, the Justice Department intervened, admitting the data was “essential” for investigations. Both founding cases of the third-party doctrine rest on the government explicitly ordering the records kept, then using them without a warrant.
The most recent and alarming expansion is the aggressive push at both the state and federal levels to mandate online age verification. By requiring websites to collect government IDs, lawmakers are forcing private companies yet again to build massive new databases of highly sensitive identity documents.
For decades, security experts have warned that mandating these massive, centralized data vaults creates a liability that compromises everyone’s safety. The government must stop forcing these databases into existence and rely on traditional individualized warrants, freeing companies to delete the data they no longer need.
Google’s decision to move location history onto individual devices proves that companies can, in fact, choose to decentralize our data. There is a clear business incentive: When consumers grow tired of being tracked, privacy sells. But we cannot rely on corporate goodwill alone, nor can we wait for the court to solve the problem: Chatrie took seven years, and by the time it was decided, the technology it judged was already obsolete.
The ultimate responsibility lies with lawmakers, and it mostly requires restraint. They must stop legislating massive data vaults into existence and forcing companies to retain records they would rather delete. If we truly want to protect our digital lives, let companies hold less, and stop ordering them to hold more.