The Supreme Court ruled 6-3 in Chatrie v. United States that police need a warrant to obtain Google location history through geofence warrants, marking a significant erosion of the third-party doctrine that has let authorities access sensitive information held by private companies without particular warrants. A new commentary from the Reason Foundation argues that despite this victory, Fourth Amendment safeguards remain limited because most government data collection never reaches a judge. The strongest defense against surveillance isn't judicial oversight but preventing data from being gathered into centralized databases—yet legislators continue requiring companies to build exactly those vaults.
The case originated from a 2019 Virginia bank robbery where investigators, lacking a specific suspect, deployed a geofence warrant that compelled Google to scan its location database and flag every device near the crime scene during a set window. Police identified Okello Chatrie after his phone appeared among 19 devices located near the robbery. By 2023, Google had shifted location history storage from central servers to individual users' devices, making it impossible for the company to fulfill geofence warrants—a change Justice Samuel Alito noted in his dissent made the majority's ruling apply to a procedure already rendered obsolete. The decision builds on the Court's 2018 Carpenter v. United States ruling, which found that individuals hold a privacy interest in the totality of their physical movements and that obtaining cell-tower phone records constitutes a Fourth Amendment search. The majority reasoned that location history is far more precise than cell-site location information, capable of pinpointing the exact floor of a building, and because location data is an unavoidable consequence of phone use rather than a genuinely shared file, its collection lacks the voluntary disclosure the third-party doctrine was founded on.
The commentary notes that federal agencies routinely purchase Americans' data from brokers who harvest location information from everyday apps and sell it to anyone, including the government, without needing a warrant because the Constitution is designed to prevent the government from forcing its way into private lives but doesn't restrict it from acting as an ordinary paying customer. According to the report, the military purchased location data from a Muslim prayer app to track and profile a specific religious group without cause, Homeland Security violated its own policies to buy phone-tracking data, and after Roe v. Wade was overturned, one broker sold data enabling tracking of visits to abortion clinics. The Bank Secrecy Act of 1970 has required banks to record customer transactions and report suspicious activity for 50 years, and the records in United States v. Miller—the case that created the third-party doctrine—existed only because this law mandated them, with federal agencies still using this system to examine Americans' finances without warrants. The report emphasizes that both founding cases of the third-party doctrine rest on the government explicitly ordering records kept, then using them without a warrant, and the most recent expansion is the aggressive push at state and federal levels to mandate online age verification, which forces websites to collect government IDs and compels private companies to build massive new databases of highly sensitive identity documents.
The commentary argues that even if the Supreme Court overturned the third-party doctrine entirely tomorrow, the core privacy concerns would persist because the government often mandates creation of the very databases it later exploits. Google's decision to decentralize location data onto individual devices offered more practical privacy protection than the Fourth Amendment, proving that companies can choose to avoid stockpiling sensitive information—and there's a clear business incentive when consumers grow tired of being tracked. But the report cautions that we can't rely on corporate goodwill alone, nor can we wait for courts to solve the problem: Chatrie took seven years, and by the time it was decided, the technology it judged was already obsolete. The ultimate responsibility lies with lawmakers, and it mostly requires restraint—they must stop legislating massive data vaults into existence and forcing companies to retain records they'd rather delete, because if we truly want to protect our digital lives, the answer is letting companies hold less and stopping orders that make them hold more.

