Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Privacy & Compliance

Ad Network InMobi Settles FTC Charges Over Location Tracking

Singapore-based mobile ad network InMobi will pay $950,000 after it was charged by the U.S. Federal Trade Commission (FTC) for tracking the location of millions of users without their consent.

Singapore-based mobile ad network InMobi will pay $950,000 after it was charged by the U.S. Federal Trade Commission (FTC) for tracking the location of millions of users without their consent.

According to the FTC, InMobi told users that their location would only be tracked if they opted in, but in reality consumers were tracked even if apps using the company’s software had not requested permission to do so. Moreover, the software tracked their location even if they specifically denied access to location data.

InMobi, whose advertising network has reached over one billion devices through thousands of popular applications, allows its customers to serve location-based ads. This service relied on geolocation information collected from individuals who offered consent, but it also leveraged the data to determine the physical location of the wireless networks they had been using. By knowing the location of the wireless networks, the company could track users who had disabled location features on their devices based on the networks they were near.

The FTC also accused InMobi of violating the Children’s Online Privacy Protection Act (COPPA) by collecting location data from apps designed for children.

“InMobi tracked the locations of hundreds of millions of consumers, including children, without their consent, in many cases totally ignoring consumers’ express privacy preferences,” said Jessica Rich, director of the FTC’s Bureau of Consumer Protection. “This settlement ensures that InMobi will honor consumers’ privacy choices in the future, and will be held accountable for keeping their privacy promises.”

InMobi should have received a $4 million penalty for its deceptive practices, but the FTC agreed to lower the amount to $950,000 due to the company’s finances. In addition to paying the penalty, the mobile ad network will also have to delete all the information it collected from children and adults who did not offer consent, and implement a privacy program that will undergo independent audits every two years over the next two decades.

Advertisement. Scroll to continue reading.

Contacted by SecurityWeek, InMobi has provided the following statement:

With best intentions to adhere to COPPA requirements, InMobi implemented a process to exclude any publisher’s site or app identified as a COPPA app from interest-based, behavioral advertising. During the investigation by FTC, InMobi discovered that there was a technical error at InMobi’s end that led to the process not being correctly implemented in all cases. As a result, some COPPA sites were served with interest-based campaigns on the InMobi Network. InMobi promptly notified the FTC of this issue as soon as it was discovered and has made it clear from the outset that this was by no way means deliberate. Any family safe ads that may have formed part of targeted campaigns would have been undertaken to target the adult owner of the device.

 

In certain instances, InMobi has inferred user location through the Wifi identifier as part of the SDK integration with publisher apps without express election by an user. While InMobi was not fined by the FTC for this practice, to implement best practices, going forward InMobi will only use WiFi information when serving location based targeted advertising campaigns when an app user has authorized the app to collect and transmit the same. The errors were corrected in Q4 2015, and since then, InMobi has been fully compliant with all COPPA regulations. InMobi operates across several countries and continents, and intend to adhere to the best practices related to the data and privacy requirements of all the countries.

*Updated with statement from InMobi

Related Reading: Oracle Settles FTC Charges Over Java Security Updates

Related Reading: Asus Settles FTC Charges Over Router Security

Related Reading: Identity Theft Security Firm Fined $100 Million for Lapses

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

BlueVoyant has appointed Ravi Subramanian as CFO and Jamie Coleman as CCO.

Solana Foundation has appointed Michael Coates as Chief Information Security Officer.

Michael Sikorski has joined Coinbase as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.