When the FTC bars a data broker from selling location data without affirmative express consent, it's not just a headline. It's a 10-year enforcement roadmap. The May 2026 stipulated final order against Kochava and CDS offers a rare regulatory template for what "affirmative express consent" looks like when the Commission sets the requirements.
This is practical, not theoretical. If your team acquires location data from upstream sources, resells data products, or operates a marketplace where third parties access consumer information, you need a consent verification program that can withstand FTC scrutiny. Here's the framework the order mandates, translated into a working template you can adapt.
Purpose of the Template
This template helps you create a supplier consent verification program. It's a documented process to confirm that every upstream data source obtained valid consumer consent before you acquire, process, or resell that data. The FTC's order requires Kochava to verify consent from suppliers; this template provides the structure to do the same, whether you're a data broker, analytics platform, or enterprise acquiring third-party datasets.
Use this template to:
- Audit suppliers before onboarding them
- Document the consent chain for every data product
- Identify gaps where consent can't be verified
- Respond to regulatory inquiries with evidence
Prerequisites
Before deploying this template, ensure you have:
Legal clarity on sensitive data. The Kochava order defines "sensitive location data" as locations revealing medical, religious, or other protected activities. Your definition must align with the data types you handle, such as health data, financial records, precise geolocation, or biometrics.
A data inventory showing upstream sources. You can't verify consent if you don't know where the data came from. Map every supplier, data feed, and third-party integration.
Authority to reject suppliers. This program only works if you're empowered to walk away from a vendor whose consent documentation doesn't meet standards. Secure executive buy-in now.
The Template
Copy this into your compliance documentation system and customize the bracketed sections.
SUPPLIER CONSENT VERIFICATION PROGRAM
Version 1.0 | Effective [DATE]
1. Scope and Definitions
This program applies to all data acquired from third-party sources where [YOUR COMPANY] does not have a direct relationship with the consumer.
Sensitive Data includes [list your categories: precise location data tied to sensitive locations, health-related information, financial account details, biometric identifiers, etc.].
Affirmative Express Consent means the consumer took a clear affirmative action (e.g., clicked a button, checked a box, provided a signature) after receiving a disclosure that specifically identified [YOUR COMPANY] or the data use case.
Upstream Source means any supplier, partner, or vendor providing consumer data to [YOUR COMPANY] where the data was originally collected from consumers by that supplier or an earlier party in the supply chain.
2. Pre-Onboarding Supplier Assessment
Before acquiring data from a new upstream source, the [PRIVACY TEAM / DATA GOVERNANCE TEAM] must obtain and review:
- Consent collection mechanism documentation: Screenshots or technical specifications showing how the supplier obtained consent, including the exact language presented to consumers.
- Legal basis attestation: Written confirmation that consent meets the requirements of [GDPR Article 7 / CCPA opt-in standards / FTC Act Section 5 / applicable regulation].
- Consent scope verification: Confirmation that the consent explicitly covered [YOUR COMPANY'S] use case (e.g., "data will be shared with third-party analytics providers" or "data may be sold to data brokers").
- Consent timestamp and retention: Evidence that consent records are timestamped and retained for the duration of processing plus [X years].
Approval criteria: The supplier passes if consent is affirmative, explicit, granular (not bundled with unrelated permissions), and documented. If consent was obtained via pre-ticked boxes, inactivity, or broad "privacy policy" acceptance, reject the supplier.
3. Ongoing Supplier Audits
For active suppliers, conduct quarterly audits:
- Consent revalidation check: Confirm the supplier has not changed its consent mechanism or expanded data collection without updating consent.
- Breach and misuse reporting: Require suppliers to report any incident where consumer data was misused, shared beyond the consented scope, or subject to a regulatory complaint.
- Withdrawal mechanism verification: Confirm consumers can withdraw consent and that withdrawal requests are processed within [X days]. Test the withdrawal process annually by submitting a sample request.
4. Sensitive Data Filtering
For data products containing sensitive information:
- Maintain a sensitive location list identifying categories of locations that reveal protected activities (medical facilities, places of worship, addiction treatment centers, reproductive health clinics, legal services offices).
- Update this list quarterly based on regulatory guidance and incident reports.
- Filter all acquired datasets to remove or flag sensitive data before it enters production systems.
- Delete any sensitive data for which upstream consent cannot be confirmed within [30 days] of identification.
5. Consumer Rights Response
When a consumer requests information about data recipients or withdrawal of consent:
- Identify all upstream sources that provided data about that consumer.
- Notify those sources of the withdrawal request within [5 business days].
- Confirm deletion or cessation of processing within [30 days].
- Maintain records of all consumer requests and supplier responses for [3 years].
6. Incident Reporting
If a supplier violates consent terms or misuses data:
- Document the incident within [24 hours].
- Notify [FTC / relevant regulator] if the violation involves sensitive data or affects more than [threshold number] consumers.
- Suspend data acquisition from that supplier pending investigation.
- Terminate the supplier relationship if the violation was willful or cannot be remediated.
How to Customize It
Adjust "sensitive data" definitions to match your regulatory environment. If you operate in the EU, reference GDPR Article 9 special categories. If you're subject to CCPA, include the 11 enumerated categories. The Kochava order focused on location data tied to sensitive locations; your definition should cover whatever data types carry heightened risk in your business.
Set realistic audit frequencies. The template calls for quarterly audits. If you have hundreds of suppliers, prioritize high-risk sources (those providing health data, precise location, or data from vulnerable populations) for quarterly review and lower-risk sources for annual review.
Define your consent standard. The FTC's order requires "affirmative express consent." In practice, that means the consumer clicked "I agree" or checked a box after seeing a disclosure that named your use case. It doesn't mean they scrolled past a privacy policy or failed to opt out. Write your approval criteria to reflect this bright line.
Integrate with procurement. This program should block data acquisition contracts that don't pass the pre-onboarding assessment. Work with your legal and procurement teams to make consent verification a mandatory step in vendor onboarding, not an afterthought.
Validation Steps
Deploy this template, then test it:
Run a pilot audit on three existing suppliers. Can you produce the consent documentation the template requires? If not, you've found your gaps.
Submit a test consumer request. Pretend you're a consumer asking which third parties received your data. Time how long it takes to answer. If it's more than a few days, your data lineage tracking isn't sufficient.
Review a rejected supplier. Identify one upstream source whose consent mechanism doesn't meet your standard. Document why you rejected them. This record proves your program has teeth.
Schedule your first quarterly sensitive location list update. The Kochava order requires quarterly reassessment. Put the recurring task on your calendar now, with a named owner.
The FTC's order against Kochava will be in effect for 10 years. That's a decade of mandatory supplier audits, consent verification, and incident reporting. If you're in the data supply chain, you're building the same program, either proactively or in response to your own enforcement action. This template gives you the structure to start now.



