Personal Data Tracking Is Everywhere: Why Privacy Protection Remains Uneven

Your data is a commodity. Image: Gerd Altmann, on Pixabay.

 

By Mariana Meneses

The growth of digital tracking has created a privacy issue where users often have limited visibility of and control over what is collected, legal protections do not always treat extensive tracking as an actionable harm to users, privacy rules can be shaped by powerful platforms with their own commercial interests, and insecure tracking technologies can expose highly sensitive data at scale. Privacy risks emerge at several points in the tracking ecosystem, from collection to repurposing, and current safeguards are uneven across all of them. 

Personal Data Tracking

According to Gene Petrino, Security Advisor for Security.org, major tech companies collect large amounts of personal, usage, behavioral, and attitudinal data to build detailed user profiles, personalize services and advertising, and in some cases sell information to data brokers. This data can include identity and device information, browsing and purchase history, messages, interactions, location or navigation patterns, and consumer preferences. Petrino’s comparison finds that Google collects the broadest range of user data, followed by Meta and X.  

 

Chart of your data collected by Google. Besides personal information, companies extract and repurpose data on unique identifiers, as well as location information, device activity, and more. Gene Petrino, Security.org .

 

Data-driven personalization supports the free-service business model of many platforms but can also create privacy risks. Privacy Bee notes that data collection takes place across many everyday digital services, including smart-home devices, fitness and health apps, online retailers, messaging platforms, mobile games, travel services, streaming platforms, navigation apps, payment services, and educational technologies. The main privacy concern is the lack of transparency and user control over how extensively this information is collected, shared, sold, or repurposed. 

This widespread use of tracking technologies is also becoming a major source of privacy litigation. According to Baker Donelson, a well-known and large U.S. law firm, in August a California federal court dismissed a lawsuit against UnitedHealthcare despite allegations that its website used 155 third-party tracking tools. The court found that the plaintiff had not shown a concrete privacy injury because the trackers were not alleged to have collected sensitive information: she had entered only her ZIP code and browsed publicly available Medicare plan information. The case underscores a legal distinction between the extent of online tracking and the sensitivity of the data collected: under the court’s reasoning, even extensive tracking may not amount to a legally recognized privacy injury if the information gathered is not considered private or sensitive. 

Reporting for Reuters, Sam Tobin shows that efforts to restrict tracking can create legal disputes of their own. Apple is facing a £2 billion ($2.7 billion) UK lawsuit over its App Tracking Transparency system, introduced in 2021 to let users decide whether apps can track their activity across other companies’ apps and websites. The developers behind the case argue that Apple imposed stricter rules on third parties than on its own services, giving its advertising business an unfair advantage, while Apple says it follows the same requirements as other developers. The system has faced years of scrutiny from European competition authorities, including in Germany, France, Italy, and Poland, as well as criticism from publishers, advertisers, app developers, and Meta, whose businesses like Facebook and Instagram rely on advertising tracking. The case highlights concerns about privacy rules being applied selectively by dominant technology platforms that also have commercial interests in the markets affected by those rules. 

 

Cellphone use is data. Gerd Altmann, on Pixabay.

Privacy risks also emerge from the security of devices designed to track people in the first place.

Security researchers Vangelis Stykas and Felipe Solferini demonstrated how vulnerabilities in a low-cost children’s smartwatch could allow an attacker to track, photograph, and listen to someone remotely without any visible sign that the device had been compromised. When the watch’s GPS failed, the researchers were still able to estimate a WIRED reporter’s location using nearby Wi-Fi identifiers, and they could remotely activate the device’s camera and microphone. 

 

Smartwatches can provide notifications, calls and messaging, GPS/navigation, contactless payments, music, apps, alarms, and smart-home controls. They can also track fitness and health metrics such as steps, workouts, heart rate, sleep, blood oxygen, temperature, ECG, and safety features like fall detection and emergency SOS. Image: Mohd Masihullah, Vecteezy.

 

The problem extended well beyond a single watch. After examining more than 70 GPS-enabled smartwatches and vehicle trackers, the researchers found that many apparently different brands relied on a small number of shared platforms and backend systems. Three major supply chains supported tens of millions of devices and were affected by vulnerabilities including weak or missing authentication, SQL injection, unauthorized access to location and account data, location spoofing, interception of messages, changes to emergency contacts, and remote activation of microphones and cameras.  

Because many inexpensive connected devices are sold under different brand names while relying on the same underlying software and servers, a weakness in one backend can potentially affect large numbers of products at once. 

Similar problems in children’s smartwatches and GPS trackers have been documented for years, yet some vulnerabilities have persisted. The researchers said they notified the companies months before presenting their findings at Black Hat; SETracker later said it had fixed the vulnerability affecting its system, while flaws in other platforms reportedly remained exploitable. The investigation points to a broader challenge for consumers: they may have little visibility into which companies and backend systems handle sensitive information such as a child’s location, or how securely that infrastructure is maintained. 

Limits on AI-Based Tracking and Profiling

Since 2 August 2026, the European Commission’s AI Office and national authorities have been enforcing the EU AI Act, alongside new transparency requirements for certain AI systems. Chatbots and other interactive systems must inform users when they are interacting with AI, while deepfakes and other AI-generated or altered content must be labelled and carry machine-readable markers that make their artificial origin easier to detect. The rules are intended to reduce deception and manipulation, clarify compliance obligations for businesses, and help users identify AI-generated material. More than 180 organizations have signed the Commission’s Code of Practice designed to support implementation of these transparency requirements, among which are Google, Meta and Microsoft. 

Beyond transparency rules, the AI Act also prohibits several uses of AI closely related to tracking and profiling. These include “biometric categorization systems” that infer sensitive attributes such as race, political opinions, religion, trade union membership, sex life, or sexual orientation; “social scoring” based on social behavior or personal traits when it leads to harmful or disproportionate treatment; “compiling facial recognition databases” through untargeted scraping of images from the internet or CCTV; and “inferring emotions in workplaces or educational institutions,” except for medical or safety reasons.  The Act also generally prohibits “real-time remote biometric identification” in publicly accessible spaces for law enforcement, with limited exceptions such as finding missing or trafficked people. 

 

Humans are data. Image: Gerd Altmann, on Pixabay.

Rules on paper, however, may not translate into uniform enforcement

An April 2026 SSRN preprint (i.e., not yet peer-reviewed) by John P. Lalor, from the University of Notre Dame, and co-authors, entitled “When Uniform Data Privacy Regulation Meets Local Realities: A Theory of Distributed Regulatory Decoupling in the Case of GDPR”, examines how the EU’s GDPR has been enforced across countries. Analyzing 1,446 fines issued between 2018 and 2022, together with information on national governance, economic conditions, culture, and data protection authorities, the authors find systematic differences in both the size and pattern of penalties. Even countries with similar structural characteristics sometimes imposed very different fines, including in areas such as consent, surveillance, security, health data, and transparency. 

The authors describe this as “distributed regulatory decoupling”: a common EU-level rule can be applied differently by national regulators. They distinguish structural decoupling – where resources, governance capacity, and other national conditions shape enforcement –from discretionary decoupling, where regulators give greater priority to some kinds of violations than others. Their findings suggest that privacy protection can depend not only on what the law prohibits, but also on how national authorities interpret and enforce those rules. The authors argue that similar patterns may emerge in other multi-level regulatory systems. 

Different privacy laws reflect different priorities.

The rules governing personal data differ across jurisdictions, including whether consent is primarily opt-in or opt-out, and what rights, obligations, and penalties accompany data collection.  

In “Navigating Privacy: A Global Comparative Analysis of Data Protection Laws”, published in the Wiley journal IET Information Security, in 2025, Sungjin Lim, from Korea University, and Junhyoung Oh, from the Seoul Women University, compared privacy laws in the EU, California, China, Japan, and South Korea, finding growing agreement on basic protections but persistent differences in consent, individual rights, corporate duties, and penalties. For instance, the EU, China, Japan, and South Korea mainly favored opt-in consent, while California relied more heavily on opt-out, and the jurisdictions differed in areas such as data portability, automated decision-making, privacy officers, impact assessments, and sanctions. 

The authors link these differences to each jurisdiction’s broader priorities and argue that all five systems still need further reform and greater international alignment. They characterize the EU as emphasizing individual privacy, California consumer control, China national security, Japan transparency and safety, and South Korea legality and fairness. 

 

Everything is data. Image: Gerd Altmann, on Pixabay.

Digital tracking has become pervasive.

Companies collect and repurpose large amounts of personal data, but users often lack visibility and control, and courts may not recognize extensive tracking as a privacy injury unless the data that was collected is considered sensitive. Dominant platforms can create and enforce privacy rules while having commercial interests in the same markets, and insecure tracking devices can expose highly sensitive information. Although the EU AI Act prohibits some forms of tracking and profiling, we should note that even common rules such as GDPR are enforced differently across countries and, beyond enforcement, jurisdictions themselves define consent, rights, duties, and penalties differently. 

As digital tracking expands across platforms, devices, and AI systems, privacy protection remains uneven because safeguards differ in what they cover, who designs them, how they are enforced, and which kinds of data or harms they recognize.


Craving more information? Check out these recommended TQR articles.

Enjoyed this? Help us improve.

☞ complete our Short survey

 

Have we made any errors?

Spotted an error or want to contribute your expertise? We’d love to hear from you — reach us at info@thequantumrecord.com. The Quantum Record exists to bring researchers and curious minds together around science and technology that matters.

Leave a Reply

Your email address will not be published. Required fields are marked *

The Quantum Record is a non-profit journal of philosophy, science, technology, and time. The potential of the future is in the human mind and heart, and in the common ground that we all share on the road to tomorrow. Promoting reflection, discussion, and imagination, The Quantum Record highlights the good work of good people and aims to join many perspectives in shaping the best possible time to come. We would love to stay in touch with you, and add your voice to the dialogue.

Join Our Community