In this episode of the Shawn Ryan Show, Byron Tau examines how corporations collect vast amounts of consumer data through everyday devices, apps, and services—and how government agencies purchase this data to conduct surveillance without warrants. Tau explains the mechanisms behind data collection, from loyalty programs and smart home devices to mobile apps and license plate readers, and reveals how data brokers compile comprehensive profiles that are sold on a largely unregulated market.
The conversation explores how U.S. agencies exploit a legal loophole by purchasing commercial data instead of obtaining warrants, effectively bypassing Fourth Amendment protections. Tau discusses the security risks posed when foreign adversaries buy American data on the open market and addresses why privacy laws have failed to keep pace with surveillance technology. The episode concludes with practical strategies for protecting personal privacy in an era of pervasive digital tracking.

Sign up for Shortform to access the whole episode summary along with additional materials like counterarguments and context.
Byron Tau and Shawn Ryan explore the extensive ways corporations collect, store, and monetize consumer data through devices, apps, and services—while government agencies increasingly tap into these datasets with minimal public oversight.
Grocery stores and retailers track purchases through loyalty programs, collecting phone numbers, addresses, emails, and buying habits that are then sold to data brokers. Even paid memberships at stores like Costco result in detailed purchase history collection. Retailers also scan driver's licenses during returns, ostensibly for fraud prevention, but these scans provide strong identity anchors and are likely stored indefinitely.
Modern smart TVs use screen-capture technology to monitor what viewers watch, subsidizing lower prices by monetizing this data. Robot vacuums map homes and capture images, with some footage reviewed by contractors or potentially accessible to foreign companies. Smart speakers contain always-on microphones vulnerable to hacking by criminals or nation-states, while connected cars transmit location and driving data that's sold to insurers, brokers, and law enforcement.
Apps collect geolocation data tied to anonymized identifiers, but correlating nighttime and daytime locations can re-identify users. Apps often request permissions far exceeding their function—accessing contacts, calendars, photos, and location unnecessarily. Even vehicle tire pressure systems emit detectable identifiers that enable tracking when license plates change.
Data brokers aggregate property records, voting histories, browsing data, and purchase information to create detailed dossiers. Shopping sites track behavior and sell emails to brokers, while health wearables collect physiological data that could be weaponized by intelligence agencies to identify vulnerable recruitment moments.
Companies like Flock, Vigilant, and Recore have deployed thousands of license plate reader cameras nationwide, offering subscription access to law enforcement. These aggregated snapshots form rich timelines of vehicle movements, with law enforcement pressuring towns to join national surveillance networks.
U.S. agencies increasingly purchase commercial data for surveillance and intelligence work, bypassing traditional legal protections.
Tau explains that the Department of Defense purchases phone location data from apps to track overseas targets for counterterrorism, using it for recruiting intelligence sources and kinetic targeting operations.
The Department of Homeland Security operates within a 100-mile zone from borders, airports, and coasts—encompassing major cities—gathering data on American movements. DHS tracks entries, visa risks, visitor activities, and uses commercial location data to monitor border crossings and locate undocumented immigrants without warrants.
Local police departments buy commercial data to monitor social media, track vehicles, and identify suspects based on driving patterns—often without probable cause or warrants.
Tau highlights a legal loophole: while obtaining 30 days of cell carrier data requires a warrant, the government can simply purchase the same information from weather apps or other sources. The Fourth Amendment doesn't cover private transactions, allowing agencies to bypass legal protections.
Tau references Pentagon reports showing Iranian operatives used U.S. commercial data to target American soldiers. Foreign intelligence from China, Russia, and Iran can easily purchase U.S. data on the open market, posing serious security threats to military personnel and families.
The data brokerage industry operates largely unregulated, with middlemen connecting private sector collectors to government and foreign buyers.
Companies establish shell entities that appear legitimate but funnel data to intelligence agencies. For instance, Sierra Nevada Corporation owns a Virginia marketing company that publicly claims innocuous clients but actually contracts with the intelligence community.
The global ecosystem encompasses thousands of companies collecting and trading personal information. Starting in the market costs only a few thousand dollars, with marketplaces like DataRaid accepting credit cards for data purchases. Larger government contracts easily reach six figures.
Specialized brokers harvest data from public platforms like Twitter, semi-private platforms like Facebook, and private channels like Telegram, infiltrating private groups to collect messages and membership data for government sale.
Data retention policies allow indefinite storage of behavioral records, while contractors use shell firms to mask recipients. Foreign governments routinely purchase American data through shell companies and intermediaries, evading export restrictions.
Surveillance technology has advanced rapidly while privacy laws lag far behind, creating significant protection gaps.
America remains the only major industrial democracy without comprehensive privacy law. Tau and Ryan note that congressional inaction stems from lack of technical expertise, low staff salaries, insufficient oversight, and intense lobbying pressure from the trillion-dollar data industry.
While Congress historically regulated telecommunications with wiretap warrants and protected health and credit data, it failed to extend protections to internet-era data collection. Modern surveillance methods have rendered Fourth Amendment protections largely obsolete.
Congressional restrictions on data sales to Iran, North Korea, China, and Russia can be easily bypassed through shell companies and intermediaries. The U.S. lacks data residency requirements that China and Europe enforce, allowing corporations to transfer data internationally freely.
Companies like Palantir now offer tools for merging disparate datasets across sectors, dissolving protective barriers between previously siloed information. This threatens to enable comprehensive tracking across multiple life facets without updated legal safeguards.
Strong encryption through features like Advanced Data Protection, ProtonMail, and Signal shields sensitive information. Users can limit app permissions for location, contacts, and photos without sacrificing functionality, and can manually enter addresses instead of granting GPS access.
Burner phone numbers from services like Glacier and proxy email addresses prevent real contact information from being distributed or resold, allowing users to dispose of compromised contacts.
VPNs can obscure traffic from ISPs but redirect trust to the provider—many owned by foreign companies. Secure DNS providers like 9.9.9.9 minimize data broker exposure by preventing interception of domain lookups.
Connected devices introduce significant privacy risks, exposing users to potential recruitment attempts or data mining by intelligence agencies. As consumer demand for privacy grows, subscription-based privacy products emerge as alternatives to data-monetized services, with success depending on consumers' willingness to pay for security.
1-Page Summary
Byron Tau and Shawn Ryan detail the vast array of ways in which corporations collect, store, and monetize consumer data via devices, apps, and services, while noting the growing government interest in these datasets and the low level of public discussion or oversight.
Companies collect as much customer information as possible: the details of purchases, interests, and willingness to pay drive advertising and pricing strategies.
Grocery stores and retailers track everything customers buy through membership and loyalty programs. Signing up for these programs means consumers receive discounts or access while giving up data—phone numbers, email addresses, home addresses, and purchasing habits. This information is regularly packaged and sold to data brokers, who in turn inform major brands what customers buy, forming a lucrative data market. Even when consumers pay for memberships at stores like Costco—sometimes with no discounts provided—the store collects every detail of their purchase history.
Retailers such as Home Depot often scan the customer’s driver’s license during returns, supposedly for anti-fraud purposes. However, collecting the license provides a strong identity anchor, and most adults comply when asked. These scans are likely stored, adding another layer of personal and transactional data to retailer records.
Household technologies increasingly function as surveillance devices, monitoring user activity and the environment, often subsidized by the monetization of gleaned data.
Modern smart TVs have built-in screen-capture technology that monitors what is watched and when. These data streams allow TV makers to subsidize lower product prices—consumers trade privacy for affordability. Some TVs possess or may adopt cameras to detect viewing presence, further expanding the collection of in-home behavioral data.
Robot vacuums use onboard cameras and sensors to create maps of homes and sometimes capture images. There have been scandals involving vacuums recording highly private moments, with human contractors reviewing the footage for machine learning. Some vacuum brands are Chinese-owned, raising the risk that images and house layouts may be available to foreign companies or governments. While foreign intelligence agencies might not be interested in all homes, a unique individual could be targeted.
Smart speakers contain always-on microphones that companies claim are only activated by commands, but accidental triggers do occur, sending conversations into the cloud for AI training. These microphones are vulnerable to hacking, making the devices attractive to criminals seeking financial information, or to nation-states interested in espionage or recruitment. Thermostats and other smart home devices with microphones pose similar risks; even if features are disabled, hackers might reactivate them.
Connected cars routinely collect and transmit driver data—including location, driving habits, and in-car activity—often as part of “free” services offered by manufacturers. Enabling features such as roadside assistance or phone pairing gives access to location and behavioral data, which is sold to insurers, shared with law enforcement, or provided to data brokers. The prevalence of built-in cellular chips in new vehicles makes it difficult to avoid this surveillance, and driving data can be used to adjust insurance rates based on behaviors such as hard braking.
Apps and mobile operating systems continuously harvest data about user locations, habits, and contacts, often under the guise of improving services or convenience.
Numerous apps—weather, games, shopping—collect geolocation data tied to anonymized identifiers rather than names or phone numbers. Despite apparent anonymization, correlating nighttime and daytime locations can re-identify users, linking device patterns to real identities and precise movements.
Permissions requested by apps may far exceed the function of the app itself, opening up access to calendars, contacts, photos, and precise location even when such data isn’t necessary. Apple and Google have now implemented more visible controls, alerting users to frequent tracking attempts, but data collection remains pervasive and valuable, especially for advertising and retail analytics.
Vehicle tire pressure monitoring systems emit radio signals with unique identifiers as the car drives. This allows for tracking even when license plates are swapped, as these tire-based signals persist and can be detected with highway sensors, creating an additional surveillance vector for tracking vehicles.
The various data streams converge into deep, cross-referenced consumer profiles, shaping both corporate strategy and government surveillance opportunities.
Data brokers aggregate property records, voting histories, email addresses, phone numbers, magazine subscriptions, browsing history, and purchase data fr ...
How Corporations Collect Data Via Consumer Devices, Apps, and Services
U.S. agencies increasingly buy commercially available digital data to conduct surveillance and intelligence work, bypassing traditional legal protections and raising substantial privacy, legal, and security concerns.
Byron Tau explains that the Department of Defense (DOD) purchases large quantities of commercially available data—including phone location data harvested by apps on the open market—ostensibly for counterterrorism operations. Military and intelligence agencies, which usually focus on overseas operations, use commercially available data to track foreign targets, mirroring the kind of data collected on Americans.
Military and intelligence agencies use this location data for spotting, assessing, and recruiting foreign intelligence sources. The data assists in understanding behaviors of key individuals in foreign countries and is even used to identify and “kinetically” target people. Such practices allow for detailed intelligence gathering without traditional oversight or the need for a warrant.
Tau describes how the Department of Homeland Security (DHS) uses similar data but focuses inward on border security and internal monitoring. DHS has authority in a 100-mile zone extending from any border—including land borders, airports, and coasts—which encompasses many major American cities. Within this area, DHS routinely collects and analyzes the movements of people, seeking to understand immigration and goods flows, as well as general activities in the region.
DHS is interested in who is entering the U.S., who is applying for visas, and what people do once they arrive. The agency tracks the movements of visitors, who they travel with, whether they pose risks to aviation, and other indicators of suspicious travel.
Beyond its border authority, DHS uses commercial location data to track unlawful border crossings and to locate undocumented immigrants in the country’s interior—all without judicial oversight, public discussion, or the requirement for a warrant. These practices have quietly expanded, with little transparency and few safeguards.
Local police departments also purchase and use commercially collected digital data in their crime-solving efforts. Police analyze what’s being said about local politicians and school boards on social media and use data to track where cars travel, monitor travel patterns to downtown areas or known drug trafficking spots, and spot other potentially suspicious activity.
Police can use these detailed geolocation records to identify patterns and possible suspect vehicles, sometimes doing so without probable cause or a warrant. This expansive use of commercial data often occurs with little oversight, increasing the risk of abuses and mistaken targeting.
Byron Tau highlights a legal loophole: If law enforcement wants 30 days of a person’s cellphone location data from their carrier, they must first obtain a judge’s warrant. However, if a consumer has opted into sharing location data through, for exa ...
How U.S. Agencies Use Commercial Data For Warrantless Surveillance
The data brokerage industry is defined by its vast, largely unregulated trade in American personal and behavioral information, facilitated by middlemen who connect private sector data collectors to government and foreign buyers.
Data brokers collect and sell extensive personal data, including property, mortgage, and contact information of Americans. Companies are able to set up shell entities or subsidiaries that resemble legitimate business operations but are in fact established to funnel data to intelligence and Department of Defense agencies. For instance, Sierra Nevada Corporation, a U.S. defense contractor, owns a small Virginia-based marketing company called N context. Publicly, this company claims innocuous clients and marketing campaigns, but government procurement websites reveal it contracts with the intelligence community, suggesting it serves as a shell for transferring large volumes of commercial advertising data to U.S. government agencies.
The global commercial data ecosystem encompasses thousands—possibly tens of thousands—of companies collecting, aggregating, and trading personal information. Major advertising platforms like Google’s AdX and Meta’s ad networks not only serve ads but partner with many other companies, allowing business partners access to data about people’s online activities. Many smaller ad networks and companies, often invisible to consumers, participate in the same ecosystem. Getting started in the data brokerage market is not prohibitively expensive; a few thousand dollars is sometimes sufficient to access or sample mobility, internet, or point-of-sale data on the open market. There are marketplaces, such as DataRaid, where a credit card is enough to purchase different data streams. For higher stakes, a contractor can provide detailed movement tracking of an individual’s phone for a few thousand dollars. Larger transactions, such as whole-country feed access for government purposes, easily amount to six-figure deals, with contractors reselling data to government agencies at a markup.
Specialized data brokers increasingly target data from social media, including information from public platforms like Twitter, semi-private platforms like Facebook, and private communication channels such as Telegram or large group chats. These companies sometimes infiltrate private online groups, collect messages and membership data, and then sell these details to government agencies. The result is a tiered system of access—public data is broadly available, but more closed or private community data is harvested through subterfuge or exploitation of platform weaknesses and then monetized in specialized government markets.
The data retention policies in this ecosystem allow for the indefinite storage of behavioral and movement records, assuming the customer pays the necessary storage costs and has a need for historical analysis. For clients, including government agencies, who see value in years of historical mobility or other behavioral data, vendors offer long-term storage services. The merging and aggregation of disparate data points can create holistic dossiers on individuals, though practical and technical constraints prevent the full unification of all available information into a single government or corporate megadatabase. Instead, personal data remains partitioned across a fragmented commercial landscape, sometimes providing a measur ...
Unregulated Data Marketplace and Middlemen Facilitating Data To Government and Foreign Entities
Surveillance technology in the United States has advanced rapidly, while privacy laws have lagged far behind, creating significant gaps in protection for consumer data and posing new challenges for lawmakers, regulators, and citizens alike.
The United States remains the only major industrial democracy without a comprehensive privacy law that applies uniformly across digital services. Instead, Americans rely on a patchwork of state laws and sporadic executive orders primarily focused on national security, such as attempts to halt certain data flows overseas. Byron Tau and Shawn Ryan note that the lack of a unified, strong privacy regulation leaves decisions about data collection and surveillance largely in the hands of what consumers will tolerate and what companies can get away with. This results in weak and uneven protections for consumer data at the federal level.
The failure to enact comprehensive privacy legislation is tied to several systemic issues in Congress. Tau highlights that congressional staff are often young, underpaid, and quickly lured away by better-paying opportunities in the lobbying sector. This lack of technical expertise and turnover means Congress is ill-equipped to analyze and address complex digital issues. The tremendous financial incentives in the data broker and advertising markets, which form a trillion-dollar global industry, ensure that lobbying pressures are intense. As a result, lawmakers lack the resources and incentive to prioritize or even sufficiently understand digital privacy matters.
Historically, Congress legislated effectively around privacy for telecommunications, requiring wiretap warrants and restricting the release of health and credit information. However, as the internet arose, lawmakers failed to apply similar protections to digital data. There has been no meaningful update of privacy legislation to cover the realities of massive internet-era data collection and use.
As modern surveillance capabilities have evolved, constitutional protections have become obsolete in many contexts. Data collected by private companies falls outside Fourth Amendment protection. Both Tau and Ryan note that it now often feels as if Americans have lost meaningful Fourth Amendment safeguards, as new surveillance technologies have outstripped legal frameworks intended to protect privacy.
Congress has attempted to curtail the flow of data to adversarial nations by restricting the sale of certain information to countries such as Iran, North Korea, China, and Russia. However, Tau points out that these measures are largely ineffective. Foreign adversaries can easily bypass restrictions by purchasing U.S. data through shell companies or intermediaries in other countries, rendering the intended protections largely meaningless. The only effect is an increase in compliance costs for law firms, while data continues to flow abroad.
The realities of global internet infrastructure make data residency enforcement difficult. Corporate data frequently shuttles across national boundaries for efficiency, with files sometimes stored overseas as dictated by server logistics. Companies argue that strict data localization or export restrictions would disrupt commerce and the functioning of the global economy, making any attempts to restrict international data flows politically and economically contentious.
Un ...
Surveillance Tech Vs. Outdated Privacy Laws Gap
Keeping communications and files private begins with strong encryption. Built-in device features such as Advanced Data Protection on Apple phones encrypt communications and files, shielding sensitive information from prying eyes. Third-party platforms like ProtonMail and Tutanota offer encrypted email services, while encrypted drive providers and messaging apps like Signal offer robust privacy for communications. Both WhatsApp and Apple's iMessage encrypt messages, ensuring that companies like Meta cannot access their content, though they may still collect metadata about users and their contacts.
Limiting smartphone app permissions is a powerful privacy measure. Users can decline permissions for location, contacts, calendar, and photo library access; most apps perform adequately without these privileges. When using location-based services like Uber or DoorDash, consumers can manually enter their address or use map pins, bypassing the need to grant backend access to precise GPS data and reducing long-term tracking.
Consumers increasingly use proxy information to foil unwanted data aggregation. Burner numbers, such as those provided by Glacier, offer a way to share a temporary phone number with businesses, political campaigns, hotels, or nonprofits. When spam or privacy risks become evident, users can dispose of the old number and generate a new one—choosing from any U.S. area code. Similarly, proxy email addresses forward messages to a main email account but can be turned off if spam arises or privacy is compromised. This approach prevents real contact information from being widely distributed or resold.
Virtual Private Networks (VPNs) can obscure internet traffic from Internet Service Providers (ISPs) or mobile carriers, but they redirect trust to the VPN provider itself. Many VPNs are owned by foreign companies from countries like China, Russia, or Israel that may collect data, requiring careful evaluation of which poses a lower risk. Some VPNs accept cash and create minimal identity links, which can be valuable for privacy-conscious users. It's important to research providers, as ownership and privacy practices can change due to buyouts or company closures.
Configuring phones to use secure DNS providers, like 9.9.9.9 from Switzerland, minimizes exposure to data brokers. Secure DNS prevents applications and brokers from inferring browsing habits by intercepting unencrypted domain lookups. Selecting a trustworthy DNS provider is essential, since they can still access query patterns ...
Strategies For Privacy in Digital Surveillance
Download the Shortform Chrome extension for your browser
