Wolfie Christl
Public-interest researcher https://crackedlabs.org | Tech and society. Tracking, surveillance, consumer data, platform power, algorithmic decisions, datafication of work.
At least one German state-level criminal police department (LKA) purchased location data from digital advertising for surveillance, despite lacking a lawful basis, prompting an investigation by the state's data protection authority.
Highly problematic on many levels:
https://netzpolitik.org/2026/daten-schwarzmarkt-deutsche-polizei-nutzt-offenbar-rechtswidrig-databroker/
Last week, we at The Citizen Lab and VSquare exposed Hungarian intelligence’s use of Webloc, an ad-based surveillance system based on mobile app data.
Update: The Hungarian GDPR regulator told us it's launched an investigation into the matter. A great first step.
I hope Hungary's new govt secures the mandate and independence of its regulator.
Other European data protection authorities must follow and investigate ad-based surveillance firms and their data supply chains:
@wchr@mastodon.social
"Burger King is launching an AI chatbot that will live in the headsets used by employees [and will] evaluate their interactions with customers for 'friendliness,' ... recogniz[ing] certain words and phrases, such as 'welcome to Burger King,' 'please,' and 'thank you.' ... the company is 'iterating' on capturing the tone of conversations as well"
Horrible. At least the latter is probably illegal under the EU's AI act.
https://www.theverge.com/ai-artificial-intelligence/884911/burger-king-ai-assistant-patty
The Austrian Ministry of the Interior bought social media surveillance software Tangles from Cobwebs/Penlink and refuses to tell the public whether they also bought the intrusive geolocation tracking add-on Webloc, which relies on the mass collection of personal data from digital advertising and mobile apps.
Public record on the €900k Tangles contract:
https://ted.europa.eu/en/notice/-/detail/17316-2025
German-lang article by @suka_hiroaki@chaos.social:
https://www.derstandard.at/story/3000000309258/innenministerium-nutzt-ueberwachungssoftware-von-zwielichtiger-firma-will-nicht-darueber-reden
Summary on the Citizen Lab site:
https://citizenlab.ca/austrian-interior-ministry-using-cobwebs-surveillance-software/
"Companies are offering law enforcement agencies the ability to track smartphone users through advertising data gathered on their devices. Le Monde attended confidential presentations of these new surveillance tools ... According to Le Monde's analysis, around 15 companies, at least, now propose such services"
...feat Penlink, RCS, Wave Guard, Rayzone, Cognyte:
https://www.lemonde.fr/en/pixels/article/2026/01/22/how-surveillance-companies-track-smartphone-users-through-advertising-data_6749674_13.html
Last week, we published a Citizen Lab report on the ad-based location surveillance system Webloc, its capabilities and its customers (https://citizenlab.ca/research/analysis-of-penlinks-ad-based-geolocation-surveillance-tech/).
Webloc obtains data from consumer apps installed on phones. How? We don't know.
But the ad targeting segments shown in this 2021 Webloc screenshot caught my eye:
We briefly investigated two other Cobwebs products:
-
Lynx, which helps facilitate undercover ops on the web and manage fake accounts
-
Trapdoor, which appears to help trick people into revealing information. Our analysis leads us to believe that it can help facilitate the deployment of malware on devices
We do not know whether Trapdoor and Lynx are still being sold by Penlink.
"Microsoft Edge sends a request to bingapis .com with the full URL of nearly every page you navigate to"
Microsoft secretly tracks people across myriads of websites/apps via pixel. Now it was caught tracking them directly in the browser, by default. Wild.
https://www.theverge.com/2023/4/25/23697532/microsoft-edge-browser-url-leak-bing-privacy
More broadly:
-
The consumer data ecosystem, from mobile apps to digital advertising, is out of control, and needs to be fixed. (rather than the law, as suggested by EU deregulation advocates)
-
GDPR enforcement is broken at several levels and needs to be improved (rather than abandoned)
Under the GDPR, the lawfulness of using this data is controversial even for targeted advertising purposes.
It's unlikely that apps, intermediaries and surveillance firms have a legal basis under the GDPR to share the data with governments for surveillance:
- I think that mobile app vendors, intermediaries and surveillance firms cannot rely on valid consent, because no app obtains specific and informed consent for sharing the data for government surveillance purposes.
-
In addition to purpose limitation, the data processing likely also violates proportionality, fairness and other GDPR principles.
-
Even if such a system is used to track only a few individuals, it still processes personal data on a large number of data subjects, and retains it for months or years.
-
Such a system performs extensive profiling and almost certainly processes special category data inferred from location records.
-
Our report shows that such as system is used for identification. Location records reveal homes, workplaces, associates and more. The use of pseudonymous IDs doesn't mitigate the risks; quite the opposite, as ad IDs are widely linked to names, email etc across the industry.
-
It's unlikely that vendors can rely on any other legal basis than consent. The only other way to legitimize their processing would require govts imposing far-reaching legal obligations to share the data for surveillance.
"A security researcher has identified 287 Chrome extensions that allegedly exfiltrate browsing history data for an estimated 37.4 million installations"
Recipients include data brokers like Similarweb, roughly 1% of Chrome users affected. Just don't use browser extensions 😢
Article:
https://www.theregister.com/2026/02/11/security_researcher_287_chrome_extensions_data_leak/
Original report:
https://github.com/qcontinuum1/spying-extensions/blob/main/report.pdf
So, after trying to bankrupt Hondoras by suing the country for $11 billion because of their extraterritorial private city project, Thiel and other oligarchs now want the Trump/Musk regime to create tax-exempt 'freedom cities' in the US where "clinical trials, nuclear reactor startups [etc] can proceed without having to get prior approval from agencies like the Food and Drug Administration, the Nuclear Regulatory Commission, and the Environmental Protection Agency":
https://www.wired.com/story/startup-nations-donald-trump-legislation/
Former OpenAI researcher Zoë Hitzig is of course right to worry about the fate of the stated 'principles' of ads not interfering with responses etc in the next iteration.
Even more remarkable, she quotes German worker co-determination as inspiration for a possible solution: https://www.nytimes.com/2026/02/11/opinion/openai-ads-chatgpt.html
ICE "agents are tapping into a database, built by the data analytics company Palantir, that combines government and commercial data to identify real-time locations for individuals they are pursuing, the current and former officials said"
https://www.nytimes.com/2026/01/30/technology/tech-ice-facial-recognition-palantir.html
"Man wird das Gefühl nicht los, dass die Fokussierung auf spekulative, entfernte Zukünfte vor allem einen Zweck erfüllt: von den vielschichtigen, schwierig zu lösenden Gegenwartsproblemen abzulenken"
@ANosthoff@mastodon.social und @fmaschewski@mastodon.social über das "Doomsday-Marketing" der KI-Industrie, die Finanz- und Diskursmacht rechter Tech-Bros und die ganz realen sozioökonomischen und gesellschaftlichen Risiken:
https://www.republik.ch/2023/10/11/apokalypse-als-businessmodell

