Overview
- A joint investigation published on June 2 by Bayerischer Rundfunk and netzpolitik.org found that at least two Landeskriminalämter, including Mecklenburg‑Vorpommern and Brandenburg, accessed commercially sold smartphone location datasets for investigations, with Mecklenburg‑Vorpommern confirming limited past use and saying it will not continue.
- Legal scholars say using app‑derived movement profiles is likely unlawful because those data were collected for advertising rather than policing and their reuse violates the GDPR principle of purpose limitation.
- Mecklenburg‑Vorpommern’s state data protection officer, Sebastian Schmidt, opened a formal Prüfverfahren against the LKA after the reports and none of Germany’s 16 state data protection authorities could point to a concrete legal basis for police purchases of such data.
- When queried, five Landeskriminalämter explicitly denied using brokered location data while nine declined to answer citing secrecy or police‑tactical reasons, leaving the scale, costs and exact uses of any purchases unclear.
- The disclosures highlight a growing global market—so‑called ADINT—where advertising firms sell meter‑accurate movement profiles that have been used by foreign agencies and that raise risks of mass surveillance, extortion, foreign‑intelligence exposure and calls from politicians and experts for legal limits or bans.