Digital Identity, Device Fingerprinting & Advertising Identifiers
How mobile advertising IDs, app SDK data, device fingerprints, hashed identifiers, device graphs, identity-resolution systems, and commercial location intelligence can connect an apparently anonymous device to places, behaviors, accounts, households, and people—and why investigators must understand provenance, accuracy, consent, warrants, privacy regulation, and vendor claims before relying on the data.
What this explainer does
Modern advertising and analytics systems routinely assign or observe identifiers associated with phones, tablets, smart televisions, browsers, applications, vehicles, and households. Those identifiers can be combined with precise location, app activity, IP addresses, account information, hashed emails, purchase data, Wi-Fi information, and other signals.
A commercial platform may then use those signals to infer that several identifiers belong to the same person or household, to reconstruct where a device has traveled, or to connect an apparently pseudonymous identifier with a real-world identity.
The central investigative question is not merely “can this vendor identify the device?” It is what identifier is being used, where the underlying data came from, how the identity association was created, how accurate it is, what legal authority permits governmental access, and what independent evidence confirms the vendor's conclusion.
California's privacy agency now specifically identifies Mobile Advertising IDs as personal information that consumers can use in the state's DROP data-broker deletion system. The agency explains that MAIDs can be used to connect app activity, location, and behavior across commercial databases.
In June 2026, the FTC finalized its Kochava settlement restricting disclosure of sensitive location data. These developments reinforce a basic point for public safety agencies: commercial availability is not the same as legal, accurate, or risk-free governmental use.
1. Overview
Digital identity systems transform scattered technical identifiers into conclusions about devices, people, places, and relationships.
The advertising ecosystem was designed primarily to measure audiences, personalize advertising, attribute transactions, and understand consumer behavior. Mobile apps, advertising exchanges, analytics companies, data brokers, and identity-resolution vendors can generate enormous quantities of information without using a person's name at every stage.
That does not make the information anonymous. A device that repeatedly sleeps at one residence, travels to one workplace, connects to one IP address, and appears with one set of account identifiers may be readily associated with a particular person.
2. Common Digital Identifiers
| Identifier | What It Is | Important Limitation |
|---|---|---|
| Mobile Advertising ID (MAID) | User-resettable operating-system advertising identifier associated with a mobile device | May change, be unavailable, or be restricted by device privacy settings |
| IDFA | Apple's Identifier for Advertisers | Access is constrained by Apple's tracking-permission framework |
| Google Advertising ID / GAID | Android advertising identifier used for advertising and measurement | Can be reset or restricted and should not be treated as a permanent hardware serial number |
| IP Address | Network-layer address associated with an internet connection | May represent a household, business, VPN, carrier gateway, hotspot, or dynamic assignment rather than one person |
| Hashed Email / Phone | Cryptographic transformation of contact information used for matching | Hashing does not necessarily anonymize predictable identifiers; vendors may match known inputs |
| Cookie / Browser ID | Browser- or site-associated identifier used for session, analytics, or advertising purposes | Can be deleted, blocked, partitioned, or shared among users of a device |
| Connected-TV ID | Identifier associated with a smart television or connected-TV environment | Usually indicates a device or household environment, not necessarily an individual viewer |
| Vehicle Identifier | VIN or connected-service identifiers associated with a vehicle | Vehicle ownership and actual driver identity can differ |
| Vendor Device ID | Identifier created internally by an app, analytics system, or data broker | Meaning and persistence depend on undocumented or proprietary vendor logic |
3. Mobile Advertising IDs Are Tracking Keys
A MAID is a unique advertising identifier associated with a device rather than a person's legal name.
California's privacy agency describes MAIDs as unique identifiers assigned to devices such as smartphones or tablets and explains that data brokers can use them to connect app activity, location, and behavioral information. Apple historically refers to its advertising identifier as IDFA, while Google's Android ecosystem uses a Google Advertising ID.
Because a MAID can recur across many commercial data points, it can allow a vendor to group those events into a longitudinal record associated with one device.
4. App SDKs and Advertising Infrastructure Can Generate the Data
Many mobile applications incorporate third-party software development kits, or SDKs, for analytics, advertising, crash reporting, location services, attribution, engagement measurement, or monetization. Depending on permissions and architecture, an SDK may receive device identifiers, timestamps, location, app events, IP addresses, or other information.
The FTC's Mobilewalla enforcement action is especially instructive because the agency alleged that Mobilewalla collected consumer information from online real-time bidding advertising exchanges and used precise location information beyond the immediate purpose of participating in ad auctions.
An application or embedded SDK observes a device event or location.
Identifiers and metadata may move through measurement, advertising, bidding, or analytics systems.
A data broker may purchase or combine records from multiple commercial sources.
Additional household, demographic, location, or identity attributes may be attached.
Vendor systems may infer that multiple identifiers belong to one device, person, or household.
The resulting product may be licensed to advertisers, analytics firms, businesses, or government users.
5. Device Fingerprinting Does Not Require One Official Identifier
A device fingerprint is an inferred identifier created from combinations of technical characteristics. Depending on the environment, a fingerprinting system may consider browser properties, operating system information, fonts, screen configuration, IP information, language, hardware characteristics, software characteristics, or other signals.
The purpose is often to recognize a device even when cookies or advertising identifiers are absent, changed, or blocked. Because fingerprinting can be probabilistic, a “match” may express a vendor's confidence that two observations relate to the same device rather than prove a fixed hardware identity.
6. Device Graphs Link Identifiers Across Devices and Contexts
A device graph is a structured set of relationships among identifiers. A vendor may infer that a phone, tablet, laptop, smart television, IP address, hashed email, cookie, and household address are associated with the same person or household.
Some relationships are deterministic—for example, a user logs into the same account on two devices. Others are probabilistic—for example, two devices repeatedly appear at the same home network overnight and move together during the day.
7. Identity Resolution Connects Pseudonymous Data to People
Identity resolution is the process of linking identifiers that appear in different databases to a common person, household, device, or account. Commercial providers may use names, addresses, email addresses, phone numbers, IP addresses, advertising IDs, account IDs, transaction information, and other signals.
A vendor might infer that MAID A belongs to a person because the device is repeatedly observed at a specific residence, because another dataset connects the device to a hashed email, or because an identity graph links the device to account information.
8. Advertising Identifiers Can Become Location Intelligence
Precise coordinates paired with a persistent identifier can create a chronological movement history. Repeated observations can support inferences about home, workplace, religious attendance, medical visits, travel, associates, political activity, or other sensitive behavior.
The FTC has repeatedly emphasized that advertising-ID-associated location data is not necessarily anonymous. Its X-Mode and Mobilewalla actions describe data capable of linking devices with the locations they visited. In the Kochava litigation, location datasets were alleged to contain enormous volumes of coordinates associated with mobile advertising identifiers.
Repeated overnight observations can suggest a residence.
Longitudinal data can reveal routines that no single observation establishes.
Visits to medical, religious, correctional, political, military, or other sensitive locations can reveal highly private information.
9. A Defensible Investigative Sequence
10. Device Attribution Is Not Person Attribution
| Inference | Why It Can Fail | Needed Corroboration |
|---|---|---|
| Device = suspect | Phones are shared, borrowed, sold, lost, stolen, or carried by others | Account records, possession evidence, communications, witnesses, forensic extraction |
| Home = owner | Device may belong to guest, family member, tenant, employee, neighbor, or visitor | Residence records, utilities, surveillance, interviews, subscriber/account information |
| Coordinate = exact position | Commercial location accuracy varies by source, permissions, device, and environment | Vendor accuracy fields, source documentation, corroborating location evidence |
| Same identifier = same device forever | Advertising IDs can be reset or restricted | Time-bounded identifier history and additional linking evidence |
| Device graph = known relationship | Vendor graph may rely on probabilistic inference | Graph methodology and independent confirmation |
| No record = no presence | App not active, permission denied, phone off, data not sold, dataset incomplete | Understand collection coverage before drawing negative inference |
11. Carpenter Changed the Constitutional Treatment of Digital Location History
In Carpenter v. United States, 585 U.S. 296 (2018), the Supreme Court held that the government's acquisition of the historical CSLI at issue constituted a Fourth Amendment search. The Court rejected automatic application of the traditional third-party doctrine to an extensive, retrospective record of a person's movements.
Carpenter involved cellular-carrier records, not commercially purchased advertising data. But its reasoning matters whenever technology creates comprehensive, retrospective, highly efficient location surveillance.
12. Chatrie v. United States: The Supreme Court Extends Location Privacy
On June 29, 2026, the Supreme Court held in Chatrie v. United States, 609 U.S. ___ (2026), that law enforcement conducted a Fourth Amendment search when it acquired Chatrie's Google Location History.
The decision is significant because the Court did not treat third-party possession of precise digital location history as eliminating Fourth Amendment protection. The case involved Google Location History and a geofence-warrant investigation—not a MAID broker product—but the constitutional direction is highly relevant to commercial location intelligence.
13. Does Buying Data Avoid the Warrant Requirement?
Some commercial products have historically been marketed to government agencies on the theory that information available for purchase does not require legal process because the vendor acquired it in the commercial marketplace.
That proposition is increasingly risky. The Fourth Amendment question is not necessarily answered by the purchase agreement. Carpenter and Chatrie emphasize privacy in revealing digital location information despite third-party possession.
DHS's Office of Inspector General reported that CBP, ICE, and Secret Service used commercial telemetry data derived from advertising identifiers and found privacy and oversight deficiencies in the Department's management of the technology.
14. California Agencies Must Consider CalECPA
California's Electronic Communications Privacy Act—CalECPA—creates state statutory protections for electronic information and generally limits governmental access to specified electronic-device and electronic-communication information absent a warrant or another statutory authorization.
The application of CalECPA can depend on the exact information, provider, device, acquisition method, and exception involved. California agencies should not assume that commercially sourced location or identifier data falls outside the statute simply because it was obtained from a broker rather than a traditional telecommunications provider.
15. California Treats Precise Geolocation and Unique Identifiers as Privacy-Sensitive Data
The California Consumer Privacy Act defines personal information broadly and treats precise geolocation as sensitive personal information. California's privacy agency separately recognizes mobile advertising IDs and other unique identifiers in its consumer privacy resources.
California's Delete Request and Opt-out Platform—DROP—allows consumers to supply MAIDs, connected-TV identifiers, vehicle identifiers, email addresses, phone numbers, and other information to help registered data brokers locate and delete records. Data brokers began processing DROP requests in August 2026.
The state's 2026 Data Broker Registry also requires disclosures concerning categories of personal information collected and certain disclosures involving law enforcement.
16. FTC Enforcement Shows How Sensitive the Ad-Tech Data Can Be
FTC restrictions addressed sale and use of sensitive location information associated with mobile advertising identifiers.
The FTC alleged collection and sale of sensitive location information and restricted use of data obtained through real-time bidding.
In 2026, the FTC finalized an order restricting disclosure of sensitive location data without affirmative express consent.
These are consumer-protection enforcement matters, not Fourth Amendment criminal cases. They nevertheless provide important evidence about how commercial location markets operate and why claims that location datasets are “anonymous” or benign deserve scrutiny.
17. Data Provenance May Be the Most Important Vendor Question
Investigators should be able to explain where a record came from before asking a court, prosecutor, jury, supervisor, or public to rely on it.
Which app, SDK, exchange, provider, broker, device, or commercial relationship generated the original event?
What location, tracking, or privacy permission existed when the data was collected?
Was the identifier directly observed, hashed, resettable, inferred, or vendor-created?
Was the coordinate filtered, rounded, clustered, enriched, modeled, or inferred before delivery?
How did the vendor connect the pseudonymous identifier to a person or household?
How far back does the database extend, and are old identifiers merged with new identifiers?
What devices, apps, operating systems, populations, or geographic areas are missing?
Does each point contain source, accuracy, confidence, timestamp precision, or other quality metadata?
How many entities handled or transformed the data before it reached the government?
18. Drafting Warrants for Advertising-Identifier and Commercial Location Data
Where a warrant is sought, the affidavit should explain the commercial technology rather than treating the vendor as a black box.
Name the vendor, product, database, and category of underlying commercial records.
Describe whether investigators seek a known-device history, area search, identity resolution, or another function.
Use a defensible period tied to probable cause rather than open-ended historical access.
Limit area searches to locations and boundaries supported by the investigation.
Describe what the MAID or other identifier represents and how it will be used.
Explain whether the vendor will identify a person or whether separate process will be used for subscriber information.
19. Evidence, Authentication, and Discovery
| Record | Why It Matters |
|---|---|
| Search parameters | Reconstructs exactly what investigators asked the system to find. |
| Raw vendor export | Preserves underlying results independently from analyst-created maps or summaries. |
| Vendor legend / schema | Explains each field, identifier, accuracy value, timestamp, confidence measure, or source code. |
| Identity-resolution output | Shows whether attribution was deterministic, probabilistic, vendor-generated, or externally sourced. |
| Analyst notes | Separates vendor output from investigator inference and documents narrowing decisions. |
| Contract / product documentation | May establish data sources, retention, limitations, permitted use, and vendor claims. |
| Version information | Documents material platform changes affecting reproducibility or interpretation. |
| Corroborating evidence | Tests whether commercial data agrees with independent investigative sources. |
20. Governance Framework for Commercial Digital Identity Tools
Define approved investigative purposes before granting access to a commercial identity or location platform.
State when a warrant, court order, consent, exigency, or other authority is required for each function.
Require case number, user, date, search type, identifier, time range, geographic scope, and legal authority.
Require vendors to disclose collection sources, transformation steps, identity-resolution methods, and meaningful limitations.
Test location accuracy, identifier persistence, graph associations, attribution, and known failure modes.
Prohibit treating commercial identity resolution as final proof of device possession or person location.
Define restrictions involving medical, religious, political, correctional, military, residential, and other sensitive places.
Apply heightened review to area searches or queries returning large numbers of uninvolved devices.
Require notice when sources, algorithms, retention, interfaces, ownership, or privacy practices materially change.
Preserve vendor outputs, documentation, contracts, search histories, analytical steps, and validation information.
Review searches for legal authority, policy compliance, misuse, unusual volume, and sensitive-location access.
Reassess policy as Chatrie, state privacy laws, FTC enforcement, and commercial surveillance technology evolve.
21. Questions Every Agency Should Answer Before Using the Technology
22. What Comes Next
Platform privacy changes will push the advertising ecosystem toward alternate identifiers and probabilistic matching.
Vendors will increasingly connect devices, households, accounts, vehicles, connected TVs, IP addresses, and transactions.
Machine-learning systems may make increasingly complex identity associations that are difficult for investigators to independently reconstruct.
Data-broker registries, deletion systems, sensitive-data rules, and government-access restrictions are likely to expand.
Courts will confront whether government purchase of commercial location and identity data can bypass traditional judicial process.
Agencies, prosecutors, courts, and defense counsel will increasingly demand to know how commercially acquired digital evidence was created.
23. Key Terms
24. Related ShieldPST.ai Resources
Review the broader commercial-data ecosystem, government acquisition, location analytics, privacy, and procurement.
Open explainer →Compare commercial identifier tracking with government-installed and other electronic location tracking.
Open explainer →Compare advertising-derived location information with telecommunications-provider records.
Open explainer →Review location-based reverse searching and the constitutional issues raised when many unknown devices are initially swept into an investigation.
Open explainer →Explore another commercial ecosystem in which identifiers, location, accounts, and behavior can be linked.
Open explainer →Connect commercial identity tools to Fourth Amendment, privacy, procurement, evidence, cybersecurity, and oversight.
Open resource →25. Selected Authoritative and Primary Sources
Foundational Fourth Amendment decision addressing governmental acquisition of extensive historical cell-site location information.
Review Carpenter
June 29, 2026 decision holding that law-enforcement acquisition of Google Location History constituted a Fourth Amendment search.
Review Chatrie
FTC action restricting sale, sharing, or disclosure of sensitive location data without affirmative express consent under the settlement terms.
Review FTC v. Kochava
FTC action addressing collection and sale of sensitive location data and use of information obtained through online real-time bidding advertising exchanges.
Review Mobilewalla order
FTC enforcement concerning sensitive precise location information associated with mobile advertising identifiers and other commercial sources.
Review X-Mode order
California explanation of MAIDs, IDFA, GAID, device tracking, and the role advertising identifiers can play in data-broker matching and deletion.
Review California MAID guidance
Current California data-broker registration and disclosure framework, including reporting regarding categories of identifiers and specified law-enforcement disclosures.
Review California Data Broker Registry
California consumer guidance concerning mobile advertising IDs, connected-TV IDs, VINs, and other unique identifiers used for data-broker deletion matching.
Review unique identifiers
Official California guidance describing personal information and sensitive personal information, including precise geolocation.
Review CCPA guidance
Government documentation describing advertising identifiers, commercial telemetry data, how vendors obtain AdID-related location information, and government evaluation of commercial datasets.
Review DHS PIA
Inspector General review of DHS component use of commercial telemetry data derived from advertising identifiers and associated privacy/oversight controls.
Review DHS OIG report
Civil privacy litigation describing commercial location databases that associate geolocation coordinates with mobile advertising identifiers.
Review Murphy v. Kochava
26. Key Takeaways
- A mobile advertising identifier is pseudonymous, not truly anonymous, and can function as a persistent key connecting many commercial records.
- Advertising IDs, app SDK data, IP addresses, hashed identifiers, browser IDs, connected-TV identifiers, and other signals can be combined into identity graphs.
- Device fingerprinting may infer a persistent identity even when one formal advertising identifier is unavailable.
- Identity-resolution systems may combine deterministic evidence with probabilistic inference; investigators should know which type supports a vendor conclusion.
- A device identifier does not prove who physically possessed or used the device at a particular time.
- Precise location paired with a recurring identifier can reveal home, work, associations, habits, sensitive visits, and patterns of life.
- Carpenter establishes that extensive digital location history can receive Fourth Amendment protection despite third-party possession.
- The Supreme Court's 2026 Chatrie decision reinforces that highly revealing platform-held location history can constitute a Fourth Amendment search.
- Commercial purchase should not be assumed to eliminate a warrant requirement that would otherwise apply.
- California agencies must separately evaluate CalECPA, state privacy law, and controlling constitutional doctrine.
- FTC enforcement involving X-Mode, Mobilewalla, and Kochava shows that advertising-derived location data can be extraordinarily sensitive and capable of identifying real-world behavior.
- Data provenance is critical: investigators should know where each record originated, how it was transformed, and how identity was inferred.
- Commercial maps and identity-resolution results require independent corroboration before enforcement decisions are made.
- The governing question should be: what does this identifier actually represent, how did the vendor connect it to this person, and what lawful and reliable evidence supports that conclusion?