Your Carrier Was Fined $57 Million for Mishandling Your Location Data. You Were Not a Party, and Minnesota Law Will Not Let You Be One.

June 10, 2026 · David J.S. Madgett · Updated July 30, 2026

The Federal Communications Commission assessed roughly $57 million against AT&T and $47 million against Verizon over the mishandling of customer location data — the record of where their subscribers’ phones physically were.

The carriers paid, and then challenged the process on constitutional grounds. On June 4, 2026, the Supreme Court ruled against them, 8–1.

It is worth understanding why they lost, because the reason is also the reason that none of that money has anything to do with the people whose locations were being sold.


The Seventh Amendment argument

Two years earlier, in SEC v. Jarkesy, the Court held that when a federal agency seeks civil penalties for fraud, the Seventh Amendment entitles the defendant to a jury trial in an Article III court. That decision put a large question mark over every administrative penalty regime in the federal government.

The carriers made the obvious next move: the FCC’s forfeiture process assesses substantial monetary penalties through an agency proceeding, with no jury anywhere in sight. Under Jarkesy, they argued, that is unconstitutional.

Chief Justice Roberts, writing for the Court, said the FCC’s regime is different — and the difference is structural.

An FCC forfeiture order issued under 47 U.S.C. § 503(b)(4) does not definitively resolve anyone’s legal obligations. The Commission’s factual findings are not conclusive. If the party does not pay, the government must go to federal district court to collect, and in that proceeding the party is entitled to a full de novo jury trial before it can be made to pay anything.

That is the holding. Because a jury remains available before liability is finally imposed, it does not offend the Constitution for the Commission to issue forfeiture orders without one.

Jarkesy is not a rule that agencies may never assess penalties. It is a rule that the jury right has to exist somewhere before the money actually changes hands.

Justice Thomas dissented alone — and his objection is worth noting, because it is the sharpest thing in the case. He agreed that an agency may collect a penalty only after a de novo court adjudication. His point was that AT&T and Verizon never actually got that protection: the forfeiture orders operated in practice as commands to pay, and the carriers paid under protest rather than test them.


The part nobody is discussing

Set the constitutional question aside and look at the structure of what happened.

Wireless carriers handled the location data of a very large number of Americans in a way the FCC concluded violated the law. The consequence was a penalty paid to the United States Treasury.

The people whose location histories were involved were not parties to that proceeding. They did not receive notice of it, they had no role in it, and they received none of it. There is no mechanism in the forfeiture process by which they would.

This is not a criticism of the FCC, which did what its statute authorizes. It is an observation about the architecture of privacy law in this country: it is enforced almost entirely by governments, on behalf of the public in the abstract, and almost never by the individuals whose data was mishandled.

Minnesota’s own privacy statute is built the same way.


What Minnesota actually gave you

The Minnesota Consumer Data Privacy Act, codified at Minn. Stat. ch. 325M, took effect July 31, 2025. It is one of the more consumer-protective state privacy laws in the country, and most Minnesotans do not know they have it.

Who it covers. Entities doing business in Minnesota or targeting products and services to Minnesota residents that, in a calendar year, control or process the personal data of 100,000 or more consumers (excluding data processed solely to complete a payment transaction), or derive over 25% of gross revenue from the sale of personal data while controlling or processing data of 25,000 or more consumers.

What you can demand. The standard suite — the right to access the personal data a company holds about you, to correct it, to delete it, and to obtain a portable copy. Plus opt-out rights for the sale of your data, for targeted advertising, and for profiling in furtherance of decisions with legal or similarly significant effects.

Two provisions Minnesota added that most states did not.

  • A right to obtain a list of the specific third parties to which a controller has disclosed your personal data.
  • A right, where you are subject to a consequential profiling decision, to question the result, review the personal data used to reach it, and — if inaccurate data drove the outcome — have the decision reevaluated. In an era of automated underwriting, tenant screening, and AI-assisted hiring, that is a meaningfully forward-looking right.

Minnesota also requires controllers to honor universal opt-out mechanisms — the browser- or device-level signal that broadcasts your preference automatically, so you are not clicking through a consent banner on every site individually. And it imposes heightened protections for consumers under 16.


And here is the catch

Enforcement is exclusively governmental. The Minnesota Attorney General’s Office enforces the MCDPA. There is no private right of action. If a covered business ignores your deletion request, you do not sue — you file a report with the Attorney General, through the office’s dedicated intake at PrivacyMN.com. The office added attorneys and an investigator for the work.

The statute’s initial cure period ran through January 31, 2026, during which businesses got 30 days to fix violations before enforcement action.

So the same shape as the FCC case, one level down: a real set of rights, a real enforcement mechanism, and no seat at the table for the individual whose data it was.


Where individual remedies do still exist

None of this means Minnesotans are without private recourse. It means the recourse lives in other statutes, and knowing which is the whole game.

  • Credit reporting. The Fair Credit Reporting Act has an express private right of action against bureaus and furnishers, with actual damages, statutory and punitive damages for willful violations, and attorney fees. If the data problem shows up on your credit file, you are in a materially stronger legal position than if it shows up anywhere else. We wrote about that route here.
  • Identity theft and account takeover. Different statutes, different remedies, and often a contractual layer with the bank or card issuer.
  • Government access to location data. A separate question entirely — and one where Minnesota has been ahead of the federal courts since 2014, as we covered when the Supreme Court reached geofence warrants in Chatrie.

The practical instruction is to identify which body of law your particular harm falls under before assuming you have no remedy — or assuming you do.


What to actually do

  1. Use the rights you have. Send access and deletion requests to the data brokers, ad-tech firms, and platforms that hold your information. They are free, and companies over the threshold must respond.
  2. Turn on a universal opt-out signal. Minnesota requires controllers to honor it. One setting, applied everywhere, is worth more than a hundred cookie banners.
  3. Ask for the third-party list. It is one of the most useful and least-used provisions in the statute, and the answer is frequently startling.
  4. Report violations rather than stewing about them. Since the Attorney General is the only enforcer, the office’s docket is built from consumer reports. A complaint that is never filed is a violation that is never counted.
  5. If the harm became financial, look at the credit file first. That is where private remedies with real teeth actually live.

The through-line

FCC v. AT&T is formally a case about the Seventh Amendment and the reach of Jarkesy. Functionally, it is a reminder that in American privacy law the wronged party and the enforcing party are almost never the same entity.

Minnesota gave its residents a genuinely strong set of privacy rights in 2025 and then handed the keys to the Attorney General. That is a defensible design — individual suits are expensive, inconsistent, and easy for well-resourced defendants to outlast. But it does mean the rights are only as active as the people who invoke them.

They are your rights. You just cannot enforce them yourself.


If your personal information has been misused and you are trying to determine whether you have a private claim — under the FCRA, identity-theft statutes, or otherwise — that analysis turns on where the data went and what it cost you. Send us a message or call 612-470-6529.


Sources: FCC v. AT&T Inc., 608 U. S. ___ (2026) (Roberts, C. J.), Nos. 25–406 & 25–567 (consolidated with Verizon Communications, Inc. v. FCC), decided June 4, 2026 (Thomas, J., dissenting); 47 U.S.C. § 503(b)(4), § 504(a); SEC v. Jarkesy, 603 U.S. 109 (2024); Minnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M (effective July 31, 2025); Minnesota Attorney General’s Office, “New Minnesota law creates stronger privacy protections for residents” (July 28, 2025) (enforcement by the Attorney General; consumer reporting at PrivacyMN.com; cure period through January 31, 2026); 15 U.S.C. §§ 1681n, 1681o. Reported FCC forfeiture amounts of approximately $57 million (AT&T) and $47 million (Verizon) are as described in contemporaneous public reporting on the Commission’s orders. This article is general commentary on published decisions and statutes, not legal advice, and reading it does not create an attorney–client relationship. No outcome is promised or implied.

← All news & articles