Skip to main content
When Government Asks for Location DataPrivacy Governance & Design
5 min readFor Privacy Officers

When Government Asks for Location Data

Your legal team just forwarded you an email with the subject line: "Urgent: Government data request." A public health authority wants aggregated location data from your mobile app to model population movement during an outbreak. They're citing public interest. The board meets in two hours.

You're not just responding to a data request. You're setting a precedent that will outlive the emergency.

Telecommunications companies in Germany, Brazil, and China granted governments access to cellphone location data during COVID-19. The Dutch supervisory authority called for emergency legislation before any sharing occurred. Canadian Prime Minister Justin Trudeau said no outright. Each choice reflected different considerations about risk, legal cover, and long-term consequences.

Privacy officers who treated these requests as purely legal questions missed the point. The question wasn't "can we?" but "should we, under what constraints, and what happens after?"

What You Need Before Starting

Don't walk into that boardroom with only Article 6 printed out. You need:

A data inventory that answers specifics. What location data do you actually hold? GPS coordinates? Cell tower triangulation? IP-derived city-level approximations? Retention periods? Associated identifiers? If you're saying "we'd need to check," you're already behind.

Your existing lawful basis documentation. You collected this data under a specific lawful basis for specific purposes. Pull that documentation now. Article 5(1)(b) limits you to compatible further processing. Public health might qualify under Article 9(2)(i) for special category data, but you'll need to articulate why this request fits within your original scope or constitutes a compatible new purpose.

Your processor agreements. If you're sharing data that a processor collected on your behalf, you're still the controller. Check whether your agreements permit disclosure to government authorities and under what terms. If they don't, you're potentially in breach of Article 28 obligations before you even respond to the request.

Contact details for your supervisory authority. The Dutch supervisory authority's call for emergency legislation wasn't academic caution. It was a roadmap. Before you agree to anything, know whether your authority has issued guidance on public health data sharing and whether they expect advance consultation.

Step-by-Step Implementation

Step 1: Characterize the request precisely. Write down exactly what they're asking for. Not "location data" but: raw coordinates or aggregated heatmaps? Identifiable or anonymized? Real-time or historical? For what geographic scope and time period? What's the stated purpose, and is it tied to specific legal authority?

If the request is vague, send it back. You can't assess necessity and proportionality against "whatever you've got."

Step 2: Identify your legal pathway. You have three realistic options:

Legitimate interests (Article 6(1)(f)). Public health is a legitimate interest, but you still need to document why this specific disclosure is necessary and proportionate, and whether data subjects' rights override it. Draft a legitimate interests assessment that addresses: could anonymized data serve the same purpose? Could aggregation achieve the goal without individual tracking? What safeguards limit misuse?

Legal obligation (Article 6(1)(c)). This only applies if domestic law specifically compels disclosure. A government request isn't a legal obligation unless it's backed by statute or regulation. If your jurisdiction hasn't passed emergency legislation, this basis doesn't apply.

Public interest (Article 6(1)(e)). This requires that processing is necessary for a task carried out in the public interest or in the exercise of official authority. Again, this needs a lawful basis in member state law. Without it, you're guessing.

Step 3: Draft the board memo. Your executive team needs to understand three things: the legal risk, the reputational risk, and the precedent risk.

Legal risk: If you share without adequate lawful basis, you're exposed to enforcement action. Frame this as "we would be processing personal data outside our documented purposes without clear legal authority." Don't say "we might get fined." Say "we would be in breach of Article 5 and Article 6, creating regulatory exposure."

Reputational risk: How will your customers react? If you're a health app, they might expect you to contribute to public health efforts. If you're a social network, they might see it as surveillance. Test the message: "We shared location data with [authority] to support pandemic response" needs to land well with your user base.

Precedent risk: This is where privacy officers earn their seat at the table. If you agree now, what's the limiting principle? Does this create an expectation that you'll share data for any declared emergency? Does it establish that aggregated data is fair game without individual consent? Write down what you're not agreeing to, not just what you are.

Step 4: Negotiate constraints. If you're proceeding, don't just hand over data. Insist on:

  • A written agreement specifying purpose, retention period, and deletion obligations
  • Aggregation or anonymization where technically feasible
  • Restrictions on secondary use or onward sharing
  • Regular reporting on how the data's being used
  • A defined end date tied to the emergency, not open-ended access

The Dutch supervisory authority wanted emergency legislation because it creates these constraints by default. Without legislation, you need to build them contractually.

Step 5: Document everything. Your Article 30 processing register needs a new entry. Your transparency obligations under Articles 13 and 14 likely require updated privacy notices. If you're relying on legitimate interests, your assessment goes in the file. If a supervisory authority asks in six months why you shared data, "we thought it was the right thing to do" isn't adequate documentation.

Validation

You've made the decision. Now verify you've actually protected the organization:

Run the data through your anonymization process if you've committed to anonymized sharing. Test whether re-identification is feasible given the granularity and any auxiliary data the authority might hold.

Confirm the data extract matches what you agreed to provide. No accidental inclusion of special category data beyond what's authorized. No identifiers you promised to strip.

Check that your privacy notice update is live before data moves. Article 14 gives you a month if informing data subjects is impossible or involves disproportionate effort, but if you can update your website today, do it.

Maintenance and Ongoing Tasks

Set a calendar reminder for the agreed end date. When the emergency ends, data sharing ends. If the authority requests an extension, treat it as a new request requiring fresh assessment.

Monitor how the data's being used. If you agreed to monthly reporting, enforce it. If the authority publishes research or dashboards using your data, verify it matches the agreed purpose.

Review your processor agreements. If this exposed gaps in your ability to respond to government requests, fix them now. Future requests will come, and you won't always have two hours' notice.

Update your internal playbook. What did you learn about your data inventory gaps? Where did your documentation fall short? The next privacy officer facing this question should find a clearer path because you documented this one.

The emergency will end. The precedent won't.

You Might Also Like