Pentagon updates policy, says DoD personnel must disable geolocation features on devices and in apps when deployed in locations designated as operational areas
Ryan Browne / CNN :
Context & Ripple Effects
This 2018 policy order reads differently after the decade of reporting that followed it. The Pentagon was moving early against a threat later documented in detail: a Wall Street Journal examination of how geolocation harvested from common apps on phones belonging to intelligence officers and military personnel creates targeting risk (risks of app-harvested geolocation on military phones), and an unclassified memo showing Defense Intelligence Agency analysts themselves mined commercial location databases to track Americans without warrants.
The throughline is that the same commercial location-data market cuts both ways. By 2026, US Central Command was telling Congress it had received [[a:1169826|threat reports of adversaries exploiting commercial location data to target US personnel in war zones]] — meaning the exposure the 2018 order tried to shut down at the device level persisted at the data-broker level.
First-order effects
- DoD personnel deployed to designated operational areas must disable geolocation features on their devices and inside apps, shifting enforcement onto unit commanders and making location hygiene a condition of deployment rather than personal choice.
- App developers and commercial location brokers lose access to real-time location signals from US troops in operational areas, degrading one input into the very datasets the military's own analysts were shown to purchase.
Second-order effects
- Because the DIA memo showed US agencies buying the same commercial location data they now forbid troops to emit, the policy forces an internal contradiction into the open: the government is simultaneously the largest defender against and customer of the brokered-location market.
- Adversaries who lose device-level signals can fall back on historical and third-party location data — exactly the exploitation channel Central Command's later threat reports describe — pushing the Defense Department toward policing data supply chains, not just endpoints.
Third-order effects
- If commercially harvested location data remains a proven targeting vector for state adversaries, pressure builds for regulation of the data-broker market itself, reframing consumer privacy law as an operational-security issue for the Pentagon rather than a civil-liberties question alone.
- The pattern points toward location data being treated as a contested battlespace asset: doctrine, procurement, and counterintelligence all reorganizing around the assumption that any commercially routable signal about US personnel is potentially adversary-readable.
The trend: Commercially harvested smartphone location data is hardening into a national-security battleground, with militaries forced to govern the data-broker ecosystem they also exploit.