Home Reviews About
Twenty of Time

Why Police Departments Are Buying Your Social Media Data Directly

Police investigations have always depended on information gathered outside the station. Witness statements, public records, telephone logs, and surveillance footage have gradually been joined by a vast digital trail: posts, likes, location signals, advertising identifiers, contact networks, and the inferred interests attached to a device or account.

Some police departments now obtain parts of this material from private companies instead of requesting it directly from a social network. Data brokers, intelligence contractors, advertising technology firms, and specialist search platforms package online activity into products marketed for investigations. The transaction may look like an ordinary business purchase, even when the information reveals intimate details about people who are not suspected of a crime.

This practice matters because it can bypass safeguards that normally apply to government searches. A department may be able to buy information that would require a subpoena, warrant, or court order if officers asked a platform for it directly. The result is a blurry boundary between public information, commercial surveillance, and state power.

The Commercial Trail Behind A Social Account

“Social media data” is broader than the text and images visible on a profile. It can include public posts, deleted content preserved by a service, usernames, associated email addresses, device identifiers, approximate location, browsing behavior, advertising segments, and connections inferred from repeated interactions. A person may never publish their home address, yet several datasets can make that address easy to predict.

Companies collect these signals for advertising, fraud prevention, audience measurement, identity verification, and risk scoring. They may obtain information from mobile applications, websites, loyalty programs, public records, data partnerships, or software development kits embedded in apps. The resulting profiles are often sold to businesses, but government agencies can become customers as well.

Police access does not always come from a department signing a contract with a major social network. It may come through an intermediary that searches multiple sources or licenses access to a commercial database. Some vendors advertise “open-source intelligence,” while others offer identity resolution, link analysis, facial recognition, geofencing, or real-time alerts. The language is technical, but the practical effect is simple: private companies turn scattered traces into searchable intelligence.

That process can expose people who never chose to participate in a police investigation. A friend who appears in a tagged photograph, a protest attendee whose phone was near an event, or a person connected to a monitored account may enter an investigative system without notice.

Why Agencies Prefer A Purchase

Buying data can be faster than using formal legal procedures. A request to a platform may require a warrant, a subpoena, a lengthy review, or cooperation from a company that limits law-enforcement access. A vendor, by contrast, can deliver a dashboard designed for rapid searches. Speed is especially attractive when agencies describe a matter as urgent, even though urgency does not automatically mean that a person’s privacy rights have disappeared.

Cost also encourages the market. Police departments already purchase software for records management, license-plate recognition, body-camera storage, and predictive analysis. A social intelligence subscription can be presented as another operational tool, funded through an existing technology budget or a federal grant. Once the system is installed, its use can become routine before elected officials or the public understand what it does.

The legal theory behind the purchase is often that the data came from a private company rather than from government surveillance. This invokes the idea that information voluntarily shared with a third party carries fewer constitutional protections. Yet commercial tracking complicates that assumption. People may technically agree to a long privacy policy while having no meaningful understanding that their location, contacts, or online behavior could later be sold to investigators.

The distinction between “public” and “private” is equally unstable. A public post may be visible to anyone, but a database that stores years of posts, maps relationships, assigns risk categories, and links multiple identities creates a far more revealing picture than any individual post. Aggregation changes the character of information.

The Legal Gap Between Access And Oversight

The strongest concern is not that police can view public material. Journalists, researchers, and ordinary users can often do that too. The concern is that government agencies can acquire sensitive, persistent, or indirectly collected information through a commercial channel that avoids meaningful judicial scrutiny.

The Supreme Court has recognized that certain forms of digital tracking deserve stronger protection. In Carpenter v. United States, the Court held that accessing historical cell-site location records generally requires a warrant because the records provide an unusually detailed account of a person’s movements. The decision did not settle every question involving purchased data, but it challenged the idea that all information held by a third party is automatically fair game.

The data-broker loophole remains difficult. If a broker collects location signals under a consumer consent model and sells them to a government contractor, the individual may have no practical way to contest the transfer. The agency may argue that it did not compel the information and therefore did not conduct the same kind of search as it would have through a direct request. Civil liberties groups dispute that reasoning, especially when the purchase is designed to evade a warrant requirement.

Rules also vary by jurisdiction. Some states regulate sensitive data brokers, restrict the sale of precise location information, or require public reporting about surveillance technology. Others have limited controls. Department policies may require supervisor approval, but internal policies are not a substitute for enforceable law, and they may be changed quietly.

The same problem appears in ordinary consumer technology. A useful analysis of location-hungry transit apps shows how everyday services can normalize continuous location collection. When that information enters a resale ecosystem, a convenience feature can become an investigative resource far removed from its original purpose.

Data source What it can reveal Why police may want it Main privacy risk
Public posts and profiles Opinions, affiliations, routines, relationships, and events Finding leads, identifying participants, and monitoring public activity Context can be misread, and old material can be treated as current
Advertising identifiers App use, device activity, inferred interests, and movement patterns Linking devices to people or locating a person of interest Individuals may not know the data is retained or sold
Location data from apps Visits, travel routes, recurring places, and proximity to events Reconstructing movements or identifying devices near a scene Innocent bystanders can be swept into an investigation
Data broker identity graphs Names, addresses, phone numbers, relatives, and online accounts Connecting anonymous accounts to real-world identities Errors can spread across multiple databases
Social connections and engagement data Networks, communities, conversations, and shared interests Mapping associations or finding witnesses Association may be mistaken for involvement
Facial or image databases Possible identity matches and appearance histories Searching photographs or video for suspects False matches can trigger questioning or surveillance
Commercial monitoring dashboards Alerts, keyword matches, risk scores, and trend summaries Automating surveillance at scale Opaque systems make challenge and correction difficult

The People Caught Outside The Investigation

A person does not need to be a suspect to be affected. Social platforms are networks, so an investigation aimed at one account can pull in friends, followers, coworkers, family members, and people who interacted with the account years earlier. Location searches are even broader. Anyone whose device was near a place may become part of a digital list.

This creates particular dangers for political organizers, journalists, minority communities, and people seeking sensitive services. Monitoring keywords related to protests, immigration, reproductive healthcare, religion, or labor organizing can chill lawful expression. Even if an agency never makes an arrest, the possibility of being cataloged can cause people to avoid events, private groups, or controversial speech.

Automated systems add another layer of uncertainty. A vendor may rank a person as connected to a target because of shared contacts, similar movements, or a mistaken identity match. Investigators may treat the output as a lead, but the person affected may experience it as an accusation. Errors can be copied into police records, intelligence reports, or other databases long after the original mistake.

Retention makes the harm durable. A post written during a temporary crisis, a visit to a clinic, or attendance at a demonstration can remain searchable years later. Data that was collected for advertising can acquire a second life in an investigative system, with different consequences and far fewer opportunities for correction.

Why Transparency Often Fails

Police departments frequently describe surveillance purchases in broad categories such as “investigative software” or “information services.” Procurement records may reveal a vendor’s name but not the specific datasets, search rules, retention period, or agencies allowed to access the system. Contracts can contain technical language that conceals the practical reach of the tool.

Public records requests may help, but exemptions for active investigations, security, trade secrets, or confidential sources can limit what becomes visible. Some departments share data across regional task forces, making it difficult to determine which agency initiated a search or how many people were affected. A city council may approve a budget without realizing that a subscription supports continuous social media monitoring.

Oversight is also weakened when vendors insist that their methods are proprietary. A person harmed by a false match may be unable to inspect the algorithm or discover where the underlying information came from. Police may say that a vendor’s score is only an investigative lead, while investigators still give it weight that is invisible to courts, defense lawyers, and the public.

Individual privacy practices cannot solve an institutional problem, but they can reduce the amount of commercially available data. Blocking trackers and limiting app permissions are practical steps; a detailed ad blocker review can help explain how browser tools reduce some forms of advertising surveillance. These tools will not prevent every form of monitoring, especially when information is public or held by a service provider, but they make passive collection less effortless.

What Meaningful Safeguards Would Require

A serious policy response should begin by treating purchased information as government access, regardless of whether a private intermediary collected it first. If a search would require legal process when directed to a platform, routing it through a broker should not remove that requirement. Courts and lawmakers need rules that address the substance of the search rather than the identity of the seller.

Departments should disclose the vendors they use, the categories of data involved, the legal authority for access, and the number of searches performed. Policies should define acceptable purposes, require documented approval, prohibit searches based solely on protected activity, and establish short retention periods. Independent audits should test whether officers follow those rules and whether vendors deliver inaccurate or unlawfully collected information.

People also need a way to challenge serious mistakes. Notice may be delayed during an active investigation, but indefinite secrecy makes accountability impossible. Individuals should eventually be able to learn when sensitive data contributed to a government decision, request correction, and seek a remedy when an agency relied on inaccurate or improperly obtained information.

The broader issue is the privatization of surveillance. Businesses collect information to predict what people will buy, where they will go, and how likely they are to respond. Police departments can then repurpose those predictions and records to determine whom to watch, question, or investigate. The commercial origin of a dataset does not make its consequences commercial.

Privacy is therefore a public issue, even when the first collection happens through a phone app, browser tracker, or social platform. Follow the reporting and commentary at Twenty of Time to keep examining how ordinary technology choices become systems of power, and support transparency measures that place enforceable limits on government access to personal data.