Privacy & Compliance · Study deck
Mobile Location Privacy
Before requesting a coordinate stream, inspect @fig-mobile-location-minimization to test whether the feature can operate on a coarser, shorter-lived decision instead.
Privacy Priya is your guide for this deck.
After studying this chapter
Learning objectives
You will be able to:
- choose the smallest location access (precise, coarse, or none) that still supports a feature
- explain how location signals accumulate into an identity-revealing trail
- review a location feature against the smallest-access standard
- Explain: This ordered reduction interrupts the self-writing diary described in the chapter: the system keeps the bounded decision without accumulating a reusable movement trail.
Major section
A Location Trail Tells a Story
This ordered reduction interrupts the self-writing diary described in the chapter: the system keeps the bounded decision without accumulating a reusable movement trail.
- Location data is any signal that places a device, and through it a person, somewhere in space and time.
- The core idea is that a single coordinate is rarely the whole risk.
- The risk is what a sequence of locations reveals over time: where someone sleeps, works, studies, receives medical care, worships, exercises, or meets others.
Major section
Choose the Smallest Location Access That Works
The practical job is to make a deliberate, written decision for each feature that touches location, rather than requesting broad access and sorting it out later.
- Apple's Core Location separates "while in use" from "always" authorization and lets a user share reduced accuracy.
- Regulation can run the other way, too.
- The strongest location design removes raw coordinates from the system path as early as possible.
Major section
How Location Signals Become Identity
The deeper layer explains why the simple rule above matters so much.
- Cell registration alone can be revealing enough on its own.
- Older cellular technology can add a second exposure on top of this, because the network interface itself has been shown to allow listening attacks on some networks.
- None of this depends on an app; it follows from staying registered with the network at all.
Major section
Minimise a School-Run Location Trail
The app can request foreground location while guidance is visible, round an analytics point to a wider area, and delete raw coordinates after producing an aggregate.
- Those choices do not make location harmless.
- They reduce how much of the family’s routine exists in one recoverable mobile trail.
- Repeated place labels can still reveal the same routine.
Deck summary
Key takeaways
This ordered reduction interrupts the self-writing diary described in the chapter: the system keeps the bounded decision without accumulating a reusable movement trail.
- The practical job is to make a deliberate, written decision for each feature that touches location, rather than requesting broad access and sorting it out later.
- The deeper layer explains why the simple rule above matters so much.
- The app can request foreground location while guidance is visible, round an analytics point to a wider area, and delete raw coordinates after producing an aggregate.
Retrieval practice
Recall check 1 of 3

Privacy Priya says: answer from memory, then check your reasoning.
Q1Why is a month of someone's location history considered sensitive even after their name has been removed?
Show answer
Answer: A A person's pattern of places, such as where they sleep and work, is nearly as identifying as a name, so removing the name does not make a location trace anonymous.
Retrieval practice
Recall check 2 of 3

Privacy Priya says: answer from memory, then check your reasoning.
Q2A mobile IoT setup screen needs to show nearby devices during active onboarding. It does not need exact coordinates after setup ends. Which location design is the best first choice?
Show answer
Answer: A The feature is active, visible, and does not need exact coordinates or any access after setup ends.
Retrieval practice
Recall check 3 of 3

Privacy Priya says: answer from memory, then check your reasoning.
Q3A team plans to share a location dataset for analytics and removes all names and device IDs first. Why might individuals still be exposed, and what reduces the risk?
Show answer
Answer: C Home-work routines and other distinctive patterns can identify people even after names and device IDs are removed, so reducing precision, aggregating before sharing, and limiting retention lower re-identification risk.
Print reference
Answers
Answer key.
- A · A person's pattern of places, such as where they sleep and work, is nearly as identifying as a name, so removing the name does not make a location trace anonymous.
- A · The feature is active, visible, and does not need exact coordinates or any access after setup ends.
- C · Home-work routines and other distinctive patterns can identify people even after names and device IDs are removed, so reducing precision, aggregating before sharing, and limiting retention lower re-identification risk.