The regulatory actions filed at 26-0502 and 26-0207 both turn on "sensitive location data". The phrase deserves examination, because it describes something that does not exist as stored data.
No broker holds a field marked "attended a fertility clinic". It holds a device identifier, a coordinate and a timestamp. The sensitive fact is produced by joining that against a public map.
Minimisation Frameworks Were Built For Fields
Privacy regimes classify data by category — health data, religious belief, biometric data — and impose stronger obligations on the sensitive ones. That works when sensitivity is a property of a stored value.
Inference breaks the model. Ordinary data, lawfully collected, becomes sensitive when combined with public information anyone can obtain. There is no point in the pipeline at which a compliance control was triggered.
The Same Problem In The Files This Desk Has Published
The pattern recurs. Loyalty purchase history in 26-0202 implies dietary and religious observance. Utility consumption in 26-0326 implies occupancy. Cardiac monitoring in 26-0617 implies sleep and stress. Travel history in 26-0702 implies association.
In each case the organisation collected something mundane for a legitimate purpose, and the sensitive interpretation was available to anyone who obtained it.
What Follows For Anyone Holding Data
The useful question in a data protection assessment is not "is this field sensitive". It is "what could be inferred from this if it were published tomorrow".
That question is rarely asked, it has no compliance checkbox, and on the evidence of this database it predicts real-world harm considerably better than the field classification does.
This is an analysis file built on published regulatory material, listed below, read against files previously published by this desk. The framing is ours and labelled as such. Corrections: corrections@forensicpost.com.