Your Carrier Was Fined $57 Million for Mishandling Your Location Data. You Were Not a Party, and Minnesota Law Will Not Let You Be One.

June 10, 2026 · David J.S. Madgett · Updated October 1, 2026

The Federal Communications Commission hit AT&T for roughly $57 million and Verizon for $47 million over how they handled customer location data — the record of where their subscribers’ phones physically were. The carriers paid, then went after the process on constitutional grounds. On June 4, 2026, the Supreme Court ruled against them, 8–1.

Why they lost matters. It’s the same reason none of that money has anything to do with the people whose locations were being sold.

The jury-trial argument

Two years earlier, in SEC v. Jarkesy, the Court held that when a federal agency seeks civil penalties for fraud, the Seventh Amendment entitles the defendant to a jury trial in an Article III court. That put a big question mark over every administrative penalty program in the federal government. The carriers made the obvious next move. The FCC’s forfeiture process assesses substantial money penalties through an agency proceeding, with no jury anywhere in sight. Under Jarkesy, they said, that’s unconstitutional.

Chief Justice Roberts, writing for the Court, said the FCC’s setup is different, and the difference is in how it’s built. An FCC forfeiture order issued under 47 U.S.C. § 503(b)(4) doesn’t definitively resolve anyone’s legal obligations. The Commission’s factual findings aren’t conclusive. If the party doesn’t pay, the government has to go to federal district court to collect, and there the party is entitled to a full de novo jury trial before it can be made to pay anything.

That’s the holding. Because a jury is still available before liability is finally imposed, the Commission may issue forfeiture orders without one. Jarkesy doesn’t say agencies can never assess penalties. It says the jury right has to exist somewhere before the money actually changes hands.

Justice Thomas dissented alone, and his objection is the sharpest thing in the case. He agreed an agency may collect a penalty only after a de novo court adjudication. His point was that AT&T and Verizon never really got that protection. The forfeiture orders worked in practice as commands to pay, and the carriers paid under protest instead of testing them.

Follow the money. It never reaches you.

Put the constitutional question to one side and look at what actually happened. Wireless carriers handled the location data of a very large number of Americans in a way the FCC concluded broke the law. The consequence was a penalty paid to the United States Treasury.

The people whose location histories were involved weren’t parties to that proceeding. They got no notice of it, had no role in it, and got none of the money. Nothing in the forfeiture process would ever send it their way.

The FCC did what its statute lets it do. I don’t fault it. But I think this is the most important fact in the case: American privacy law is enforced almost entirely by governments, on behalf of the public in general, and almost never by the people whose data got mishandled.

Minnesota’s own privacy statute is built the same way.

What did Minnesota actually give you?

The Minnesota Consumer Data Privacy Act, codified at Minn. Stat. ch. 325M, took effect July 31, 2025. It’s one of the more consumer-friendly state privacy laws in the country, and in my experience most Minnesotans don’t know they have it.

Who it covers. Entities doing business in Minnesota or targeting products and services to Minnesota residents that, in a calendar year, control or process the personal data of 100,000 or more consumers (excluding data processed solely to complete a payment transaction), or derive over 25% of gross revenue from the sale of personal data while controlling or processing data of 25,000 or more consumers.

What you can demand. The usual set — the right to access the personal data a company holds about you, to correct it, to delete it, and to get a portable copy. Plus opt-out rights for the sale of your data, for targeted advertising, and for profiling in furtherance of decisions with legal or similarly significant effects.

Then Minnesota added two provisions most states didn’t. These are the ones I’d actually use:

  • A right to obtain a list of the specific third parties to which a controller has disclosed your personal data.
  • A right, where you are subject to a consequential profiling decision, to question the result, review the personal data used to reach it, and — if inaccurate data drove the outcome — have the decision reevaluated. In an era of automated underwriting, tenant screening, and AI-assisted hiring, that is a genuinely forward-looking right.

Minnesota also makes controllers honor universal opt-out mechanisms — the browser- or device-level signal that broadcasts your preference automatically, so you aren’t clicking through a consent banner on every site one at a time. And it adds extra protections for consumers under 16.

Now the catch. Enforcement is exclusively governmental. The Minnesota Attorney General’s Office enforces the MCDPA. There’s no private right of action. If a covered business ignores your deletion request, you don’t sue. You file a report with the Attorney General, through the office’s intake at PrivacyMN.com. The office added attorneys and an investigator for the work. The statute’s initial cure period ran through January 31, 2026, and during it businesses got 30 days to fix violations before enforcement action.

So Minnesota built the FCC case all over again, one level down. Real rights. A real enforcer. And no seat at the table for the person whose data it was.

Where can you still sue?

You aren’t out of luck. The private remedies just live in other statutes, and knowing which one is the whole game.

  • Credit reporting. The Fair Credit Reporting Act has an express private right of action against bureaus and furnishers, with actual damages, statutory and punitive damages for willful violations, and attorney fees. If the data problem shows up on your credit file, you’re in a much stronger legal position than if it shows up anywhere else. I wrote about that route here.
  • Identity theft and account takeover. Different statutes, different remedies, and often a contract layer with the bank or card issuer.
  • Government access to location data. A whole separate question — and one where Minnesota has been ahead of the federal courts since 2014, as I covered when the Supreme Court reached geofence warrants in Chatrie.

Before you decide you have no remedy — or that you obviously do — figure out which body of law your particular harm falls under. In my practice that sorting step decides more cases than anything that comes after it.

Five things worth doing this week

  1. Use the rights you have. Send access and deletion requests to the data brokers, ad-tech firms, and platforms that hold your information. They’re free, and companies over the threshold have to respond.
  2. Turn on a universal opt-out signal. Minnesota requires controllers to honor it. One setting, everywhere, beats a hundred cookie banners.
  3. Ask for the third-party list. It’s one of the most useful and least-used provisions in the statute, and the answer is often startling.
  4. Report violations instead of stewing about them. The Attorney General is the only enforcer, so the office’s docket is built from consumer reports. A complaint nobody files is a violation nobody counts.
  5. If the harm turned financial, look at the credit file first. That’s where private remedies with real teeth live.

On paper, FCC v. AT&T is a case about the Seventh Amendment and how far Jarkesy reaches. In practice, it’s a reminder that in American privacy law the person who got hurt and the one who enforces the law are almost never the same. Minnesota gave its residents a strong set of privacy rights in 2025 and then handed the keys to the Attorney General. That’s a defensible choice. Individual suits are expensive, inconsistent, and easy for deep-pocketed defendants to outlast. But it means the rights are only as alive as the people who use them. They’re your rights. You just can’t enforce them yourself.

If your personal information has been misused and you’re trying to figure out whether you have a private claim — under the FCRA, identity-theft statutes, or otherwise — the answer turns on where the data went and what it cost you. Send us a message or call 612-470-6529.


Sources: FCC v. AT&T Inc., 608 U. S. 531 (2026) (Roberts, C. J.), Nos. 25–406 & 25–567 (consolidated with Verizon Communications, Inc. v. FCC), decided June 4, 2026 (Thomas, J., dissenting); 47 U.S.C. § 503(b)(4), § 504(a); SEC v. Jarkesy, 603 U.S. 109 (2024); Minnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M (effective July 31, 2025); Minnesota Attorney General’s Office, “New Minnesota law creates stronger privacy protections for residents” (July 28, 2025) (enforcement by the Attorney General; consumer reporting at PrivacyMN.com; cure period through January 31, 2026); 15 U.S.C. §§ 1681n, 1681o. Reported FCC forfeiture amounts of approximately $57 million (AT&T) and $47 million (Verizon) are as described in contemporaneous public reporting on the Commission’s orders. This article is general commentary on published decisions and statutes, not legal advice, and reading it does not create an attorney–client relationship. No outcome is promised or implied.

Get new guides by email

Plain-English guides to Minnesota law, sent when a new one is written. No schedule, nothing for sale.

Used only to send these guides. Unsubscribe from any email. This is attorney advertising — subscribing does not create an attorney–client relationship.

← All news & articles