PREAMBLE: FROM STATIC PROFILE TO DYNAMIC MOVEMENT MAP

Facebook Places launched in August 2010, introducing the check-in feature that allowed users to broadcast their real-time location by checking in at venues. But the critical surveillance element went beyond what users voluntarily posted. The feature also allowed friends to tag you when they checked in somewhere together. This meant you could be location-tracked even when you didn’t actively participate.

Privacy advocates immediately flagged the problem. The service could reveal users’ whereabouts to their entire Facebook network. Fears emerged about non-authorized check-ins that could be used to track individuals without explicit consent. The design created a situation where one person’s participation could expose another person’s location history without their knowledge or permission.

This represented a significant escalation from the static profile data Facebook collected initially. Check-ins weren’t just demographic information—they were temporal movement records. Your home location, workplace, social gatherings, medical appointments, religious services, political rallies—all became searchable metadata points tied to your identity.

BACKGROUND GPS TRACKING (2014 ONWARDS)

Starting around 2014, Facebook’s mobile apps began collecting GPS location data whenever users granted the operating system Location Services permission. This wasn’t about check-ins anymore. This was continuous background tracking that occurred regardless of whether you opened the app or posted anything.

The company stored this data in what they called Location History archives. Users could technically view and delete this data in the app’s settings, but very few knew the option existed. Most users had no idea their phone was transmitting continuous location data to Facebook servers even when they weren’t actively using the application.

The 2015 privacy policy update stated Facebook could gather precise location for purposes including ad targeting, feed ranking and Nearby Friends features. While the company claimed this collection was optional and disabled by default, the reality was different. Many users granted location permissions without reading fine print. Some granted it for map features within Facebook. Others didn’t understand the permission extended beyond Facebook’s own app to track them across other applications and websites.

This created a comprehensive movement profile. Not just where you checked in, but every place your device transmitted location data while Facebook had permission. Commutes to work, visits to doctors, attendance at protests, trips to stores, meetings with friends—all logged in Facebook’s database with timestamps and coordinates.


CELL TOWER TRIANGULATION (CSLI)

Every cell phone continuously communicates with nearby cell towers to maintain network connection. This communication generates Cell Site Location Information automatically. Carriers like Verizon, AT&T, and Sprint retained this data for periods ranging from 12-24 months depending on the provider and data type. CSLI provided rougher location estimates than GPS—typically 500 meters to several miles of accuracy—but it worked indoors where GPS signals failed and it operated continuously without requiring user permissions.

Between 2010 and 2015, courts issued a patchwork of rulings on whether law enforcement needed warrants to access CSLI. The 2013 Third Circuit decision in In re United States for Historical Cell Site Data held that subpoenas under the Stored Communications Act were sufficient—no warrant needed. State courts moved toward greater protection: New Jersey’s 2013 decision required warrants under the state constitution, and Florida’s 2014 Bennett decision required warrants for prospective CSLI. The Fourth Circuit’s 2015 Graham decision reversed earlier precedent and held that both historical and prospective CSLI are protected by the Fourth Amendment, requiring warrants supported by probable cause. By 2015, the prevailing trend in federal courts favored warrant requirements, a position solidified nationally by the Supreme Court’s 2018 Carpenter ruling.

Until that final ruling, law enforcement agencies accessed cell tower data through subpoenas, administrative orders, and emergency requests far less stringent than traditional warrants.


GOVERNMENT ACCESS PATTERNS

From 2010 through 2020, Meta received approximately 81,064 total government data requests in the United States. Approximately 35,617 were search warrants. 14,520 were subpoenas. Remaining requests comprised NSLs, emergency requests, FISA orders, and other inquiries. Overall compliance rate hovered around 88 percent.

In 2022, the number exploded. Meta received over 450,000 government data requests globally covering more than 800,000 users. The US ranked first with requests filed on 236,000 users. Meta complied in 88 percent of US cases.

Emergency requests often bypassed notification requirements. When police claimed exigent circumstances—emergencies threatening life or safety—they could obtain location data without warrants and users often never knew their data had been accessed. This created a loophole where emergency exceptions became routine investigative tools.


SYNTHESIS

The check-in feature represented a critical psychological shift in surveillance acceptance. Before Places, continuous location tracking would have seemed invasive and dystopian. But Facebook framed check-ins as social features—ways to share experiences with friends and discover local businesses. The marketing positioned location sharing as connection rather than surveillance.

Once users accepted voluntary check-ins, continuous background tracking felt like a minor expansion of existing functionality. The normalization had occurred. What seemed unacceptable in 2009 became routine by 2015. Each incremental step made the next one seem reasonable.

The infrastructure now captured three layers of location data: voluntary check-ins that users actively posted, friend-tagged check-ins that exposed location without user participation, and background GPS tracking that occurred continuously when permissions were granted. Government access to all three layers happened through warrants, subpoenas, emergency requests and national security orders.

Those who joined Facebook with check-in capabilities had their entire geographic existence mapped. Their movements became legible to algorithms, advertisers and law enforcement alike. The panopticon wasn’t just watching anymore—it was tracking, logging, analyzing and storing every place you went.


“The check-in feature was the gateway to comprehensive movement surveillance. It established the precedent that users would voluntarily surrender location data for social connectivity. Once that precedent was set, the background tracking and government access followed naturally.”