There is a particular kind of surveillance story that never involves a warrant, a court, or a wiretap. It involves a purchase order.
In December 2025, Immigration and Customs Enforcement issued open-ended contracts to 13 private companies for “skip tracing services nationwide.” The ceiling on those contracts is $1.2 billion over two years. Analysis published through mid-2026 has filled in what that money buys, and the shape of it matters more than the number.
What skip tracing actually is
Skip tracing is the debt-collection industry’s term for finding someone who does not want to be found. The trade is old and unglamorous: you take whatever identifying information you have — a name, a date of birth, a last known address, a phone number — and you run it against everything commercially available until the person’s current location falls out.
“Everything commercially available” in 2026 is an enormous category. Credit header data. Utility connection records. Vehicle registration and insurance databases. Rental applications. Phone carrier records resold through intermediaries. Voter files. Property records. Social media. Automatic license plate reader networks. Location data harvested from mobile apps and resold through advertising exchanges. Facial recognition run against scraped image collections.
None of this requires a warrant, because none of it is a search in the constitutional sense. It is a purchase.
The scale
The contract terms are the part worth sitting with. Each of the 13 companies may receive up to 50,000 cases per month. That is a per-vendor ceiling, not a program total.
The Intercept’s estimate — that up to 1.5 million people could be targeted through this program — follows from arithmetic rather than speculation. Thirteen vendors, tens of thousands of cases each, running continuously for two years.
Contractors are handed the personal data to start with: names, dates of birth, addresses, contact information. The instruction, per reporting on the contract language, is to first exhaust all available technology before escalating. When the databases don’t produce an answer, contractors can move to physical, in-person surveillance.
So the pipeline is: government hands a name to a private company → private company queries the commercial data economy → if that fails, a person is dispatched to watch a house.
Where the AI comes in
Reporting through 2026 has consistently described contractors leaning harder on artificial intelligence to close the gap between “we have a name” and “we have an address.” That means automated correlation across data sets — matching partial records, resolving identities across sources that don’t share a common key, ranking candidate addresses by confidence.
It also means facial recognition, applied to social media images and other scraped photo collections.
The ethical problem here is not subtle and it is not new: these systems are not fool-proof. Identity resolution across messy commercial data produces false matches. Facial recognition produces false matches, and does so at meaningfully different rates across demographic groups. In a debt-collection context, a false match means an annoyed stranger gets a phone call. In an immigration enforcement context, a false match means armed agents arrive at the wrong address.
There is no published error rate for this program. There is no public accounting of how often contractors identify the wrong person, and no obvious mechanism by which anyone would find out.
The structural point
This is the part that should concern you regardless of your views on immigration policy.
A government agency that wants to locate a million people has, historically, been constrained by the cost of doing so. Investigations take investigators. Investigators are expensive, and their number is set by appropriations. That friction is not a bug in a constitutional system — it is one of the practical limits that has always made mass domestic surveillance harder than it sounds.
The commercial data broker economy removes that friction. Data that was collected for advertising, credit scoring, and marketing — collected under consent flows nobody read, from apps whose privacy policies mention “trusted partners” — is now the operational substrate for locating people at industrial scale. And because the government is buying rather than compelling, most of the doctrine that would otherwise apply simply doesn’t attach.
The Supreme Court’s decision in Chatrie established that police need a warrant to demand location data on everyone near a crime scene. It said nothing about buying the same data on the open market, which is precisely the gap this program operates in.
The states that noticed
Some legislatures have moved. In 2026:
- Washington prohibited the use of automatic license plate reader data for immigration enforcement.
- Maryland prohibited data controllers from selling personal data to entities involved in civil immigration enforcement.
These are the right shape of response — they attack the supply rather than trying to regulate the buyer. A federal agency’s purchasing authority is hard for a state to touch. A data broker’s ability to sell into a specific market is much easier.
They are also, so far, a minority position among the fifty states, and they are being tested.
What you can actually do
The honest answer is that individual action has limited reach against a system this large. But it is not zero, and the actions that help here are the same ones that help against every other buyer of the same data.
-
Use California’s DROP if you are a California resident. The Delete Request and Opt-Out Platform sends one deletion request to every registered data broker in the state. Brokers must begin processing through it starting August 1. This is the single highest-leverage thirty minutes available to a Californian.
-
Revoke location permission from apps that do not need it. Ad SDKs embedded in ordinary apps inherit whatever location permission the host app holds. On Android, set location to “Ask every time” or deny it outright for anything that is not a map.
-
Turn off your advertising ID. Android: Settings → Privacy → Ads → Delete advertising ID. iOS: Settings → Privacy & Security → Tracking → off, and disable Personalized Ads separately.
-
Opt out of the large brokers directly, even outside California. LexisNexis, Thomson Reuters CLEAR, Acxiom, Whitepages, Spokeo, and the credit bureaus’ marketing arms all have opt-out processes. They are deliberately tedious. Do them anyway.
-
Support state-level supply-side restrictions. The Washington and Maryland models are the ones that work. They are also the ones your state legislature can actually pass.
The pattern
Every piece of this program was built for something else. The credit header data was for lending. The location data was for advertising. The facial recognition was for photo tagging. The skip tracing industry was for repossessing cars.
Nobody consented to any of it being assembled into a domestic location-finding apparatus with a million-person target list, because nobody was asked. The consent was collected one app permission at a time, for purposes that sounded harmless, from people who had no way to know the aggregate.
That is not an accident of this particular program. It is the load-bearing feature of the entire commercial data economy: collect for one purpose, resell for any purpose, and let the buyer’s identity be someone else’s problem.



