Telecommunications

The industry files

A monthly contract starts with a credit check, and the check itself becomes a record at the credit agency. The network logs your approximate location with every call, text and data session. Much of the file is kept for years after you leave, tied to the window for bringing a legal claim.

The read at a glance

Tracking priority High

The network logs your position whenever the phone is switched on.

If it leaks High

A leak exposes who you called, when, and where you were at the time.

Expect it kept Years

Call and location metadata is retained for months to years under communications law.

Identity demanded ID documents

A contract requires identity verification: ID document and a credit check.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

If it leaks

Call records show who you speak to and location shows where you sleep. That pair has already been sold down a chain of buyers and used to track named individuals.

What repeats in the policies

At signup

A credit check is the price of the contract

A monthly plan commonly starts with a credit check. Your personal and financial details go to a credit reference agency, and the search itself becomes a record there. That record stays at the agency, up to six years in the UK, on a file the carrier never holds and cannot clear for you.

On the network

Location comes with the signal

Every call, text, and data session records your approximate location, down to the nearest cell tower. Policies frame this as a technical need to connect you, not a choice, so the consent controls don't reach it. Those controls are kept for precise or optional location features; the everyday cell-level trail is treated as the cost of a working phone.

When you leave

The file outlives the contract by years

Closing the account doesn't clear the file. Policies commonly keep it for years after you go: often two years, and in the UK as long as seven years, tied to legal-claim windows, tax, fraud, and winning you back. Where a policy gives no number, it keeps the file 'as long as necessary,' which is their judgement, not a limit.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileIdentity DocumentsBrowsing & ActivityMessagesLocationFinancial Purchases · maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Where you go Highly likely

Cell-tower logs track your movements minute by minute.

Who matters to you Highly likely

Call and message records map everyone you know.

What lawfully stays after you leave

Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.

Communications metadata Law sets it up to 12 months

Data-retention notices can require call and connection logs.

Fraud-prevention markers They set it about 2 to 6 years

To flag suspected fraud, often on a shared industry database you cannot reach through the company.

Tax and accounting records Law sets it about 6 years

Tax and company law makes them keep billing and payment records.

Records tied to a live or potential dispute They set it the limitation period of the claim

They can keep records to defend a live or possible legal claim.

Who wants this data

Carrier location has a resale market. US regulators found the four largest wireless carriers sold access to customers' location to data aggregators, who passed it down a chain of buyers; one trail reached a sheriff tracking people through a prison-phone vendor. The carriers pushed the job of getting your consent onto those buyers, so in many cases it was never obtained. The fines came to nearly 200 million dollars.

Sold or shared Likely

Aggregate location and usage data has an established resale market.

AI training Moderate

Network and usage patterns train models; location is the sensitive part.

Even anonymised, this can still be you

Mobile location data is the exact kind of dataset the research used: four time-and-place points single out 95% of people (de Montjoye et al., Scientific Reports, 2013).

Name, date of birth, postcode Typical

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces Typical

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns Typical

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

Browsing fingerprint Typical

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

Who you know Typical

The shape of who a person connects with re-identifies accounts across networks with no other data (Narayanan and Shmatikov, 2009).

The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)·De-anonymizing Social Networks (IEEE Symposium on Security and Privacy, 2009)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.

The move An objection tells them to use your data to run the service and nothing more.

“we do not sell your personal information”

“we do not sell your personal information”

Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.

The move Use the do-not-sell switch where there is one, and put an objection in writing as well.

“service providers, partners, and affiliates”

“service providers, partners, and affiliates”

This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.

The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.

“aggregated or de-identified information”

“aggregated or de-identified information”

Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.

The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

“retained as long as necessary, or as required by law”

They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.

The move Which reasons apply to you, and how long each runs, is a request of its own.

“you grant us a licence to use your content”

“you grant us a licence to use your content”

This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.

The move Their terms say whether the licence ends when the account does. Close the account and log the date here.

“held in case a legal claim is bought under the limitation act 1980”

“held in case a legal claim is bought under the limitation act 1980”

Keeps the whole account, billing, and payment file for six to seven years after you leave, tied to the window for bringing a civil claim rather than to any service you still use. This is the clause that makes a closed account outlive the contract by years in the UK.

The move Which parts of that file are still held, and under what reason, is theirs to answer.

“we do not sell information that identifies who you are”

“we do not sell information that identifies who you are”

Denies selling your data with a denial scoped only to information that names you. Usage and location streams that have been aggregated or stripped of your name sit outside that promise and can still be shared as 'insights.'

The move What they build from de-identified data, and where it goes, is theirs to answer.

“in case you decide to use our services again”

“in case you decide to use our services again”

Keeps your contact and account details for an unstated 'reasonable period' after the contract ends, for winning you back rather than serving you. The same wording turns up word for word across unrelated carriers, standard template language for post-contract retention.

The move How long that period runs, and what it holds, is theirs to answer.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply.