WebWatcher Now All Articles
Threat Intelligence

Your Internet Provider Is Watching: The Data ISPs Collect, the Money They Make, and the Laws That Keep Failing Americans

WebWatcher Now
Your Internet Provider Is Watching: The Data ISPs Collect, the Money They Make, and the Laws That Keep Failing Americans

Photo by Photo by Scott Rodgerson on Unsplash on Unsplash

The Most Overlooked Surveillance Relationship in America

When Americans think about online privacy threats, they tend to focus on social media platforms, data brokers, or advertising networks. Rarely does the conversation center on the company that provides the internet connection itself — the entity through which every search query, streaming request, financial transaction, and private message must travel.

That omission is significant. Internet service providers occupy a position in the digital information chain that no social media platform can match. While Facebook or Google observe what users do within their respective ecosystems, an ISP observes the full scope of a subscriber's internet activity — across every platform, every application, and every device connected to the household or business network.

In the United States, that surveillance capacity operates within a legal framework that has proven remarkably resistant to reform, leaving consumers with limited recourse and ISPs with considerable commercial opportunity.

What Your ISP Can Actually See

The technical scope of ISP visibility is broader than most subscribers realize. At the network layer, an ISP can observe the IP addresses a subscriber communicates with, the volume and timing of data transfers, DNS queries — which reveal the domain names of every site visited — and in some cases, the content of unencrypted communications.

The widespread adoption of HTTPS has reduced content-level visibility for encrypted connections, but it has not eliminated metadata exposure. An ISP may not be able to read the specific messages exchanged with a healthcare provider's portal, but it can observe that a subscriber communicated with that provider, how frequently, and for how long. In aggregate, that metadata constructs a detailed behavioral profile: health concerns, financial activity, political interests, relationship patterns, and daily routines.

Beyond passive observation, many ISPs have historically deployed deep packet inspection — a technology that analyzes the content of data packets traversing their networks — for purposes ranging from network management to targeted advertising. While regulatory pressure has curtailed some of these practices, the underlying technical capability remains.

The Monetization Architecture

ISP data collection is not merely a passive byproduct of network operations. For the largest providers — AT&T, Comcast, Verizon, and Charter among them — subscriber data represents a meaningful commercial asset.

The monetization mechanisms take several forms. Targeted advertising programs, some offered as opt-out rather than opt-in arrangements, allow ISPs to serve or facilitate advertising informed by browsing behavior. AT&T's now-discontinued Internet Preferences program, for instance, charged subscribers a premium fee to avoid having their browsing data used for advertising purposes — effectively placing the cost of privacy on the consumer.

Data sharing with third-party analytics and marketing firms represents another revenue stream, as does the sale of aggregated, ostensibly anonymized behavioral data to market research entities. The qualifier "anonymized" deserves scrutiny: research has repeatedly demonstrated that behavioral datasets can be re-identified with high accuracy when cross-referenced with other available information.

A 2021 Federal Trade Commission staff report examining six major ISPs found that several collected and shared data in ways that were not clearly disclosed to consumers, and that opt-out mechanisms were often difficult to locate and use. The report characterized the data practices of major broadband providers as raising "serious concerns" about consumer privacy.

The Legislative Record: A Study in Persistent Failure

The story of ISP privacy regulation in the United States is largely a story of opportunities identified and then abandoned.

In 2016, the Federal Communications Commission under Chairman Tom Wheeler finalized broadband privacy rules that would have required ISPs to obtain explicit opt-in consent before using or sharing sensitive subscriber data, including browsing history and application usage. The rules represented the most substantive federal privacy protection for broadband subscribers to that point.

They lasted less than a year. In March 2017, Congress used the Congressional Review Act to repeal the FCC's broadband privacy rules before they took effect — a vote that also prohibited the FCC from issuing substantially similar rules in the future. The repeal passed along party lines, and President Trump signed it into law that April.

Subsequent efforts to establish federal broadband privacy protections have stalled repeatedly in committee. The broader push for a comprehensive federal consumer privacy law — a goal pursued by legislators across multiple sessions of Congress — has similarly failed to produce enacted legislation, leaving the regulatory landscape fragmented and inconsistent.

The FCC under the Biden administration attempted to revive broadband privacy rulemaking, but those efforts faced legal challenges and the inherent limitations imposed by the 2017 repeal. The current regulatory environment leaves ISP data practices governed primarily by the FCC's general authority under Section 5 of the FTC Act — a framework that critics argue is insufficient for the scale and sophistication of modern data collection.

State-level action has produced some results. California's Consumer Privacy Act and its successor, the California Privacy Rights Act, provide residents of that state with disclosure and opt-out rights that apply to ISPs operating within California. Several other states have enacted or are considering comparable legislation. However, a patchwork of state laws does not substitute for a coherent national standard, and enforcement capacity at the state level remains constrained.

Why Enforcement Remains Largely Symbolic

Even where privacy rules nominally exist, enforcement has been inconsistent and the penalties imposed have rarely reflected the scale of the violations. The FCC's 2024 fines against major carriers for sharing customer location data without consent — AT&T, T-Mobile, Verizon, and Sprint collectively faced hundreds of millions of dollars in proposed penalties — were significant in dollar terms but took years to finalize after the underlying conduct was identified. The carriers contested the fines aggressively, and the protracted enforcement process illustrated the practical limits of regulatory deterrence.

For ISPs operating in markets with limited competitive alternatives — which describes the broadband landscape for a substantial portion of the US population — the commercial calculus favors continued data collection even in the face of regulatory scrutiny. When a subscriber cannot meaningfully switch providers, the market discipline that might otherwise constrain privacy-invasive practices does not apply.

Practical Steps for Limiting Your Exposure

Given the current regulatory environment, individuals seeking to limit ISP visibility over their internet activity must rely primarily on technical countermeasures rather than legal protections.

Use a reputable VPN service. A virtual private network encrypts traffic between a user's device and the VPN provider's servers, preventing the ISP from observing the content or destinations of that traffic. The critical caveat: the VPN provider then becomes the entity with visibility into that traffic, making provider selection consequential. Look for services with independently audited no-log policies.

Configure DNS over HTTPS. Changing your DNS resolver to a privacy-focused provider — such as Cloudflare's 1.1.1.1 or NextDNS — and enabling DNS over HTTPS prevents your ISP from observing your DNS queries, which constitute one of the most revealing categories of metadata.

Use the Tor Browser for sensitive activity. For communications or research where privacy is paramount, the Tor network routes traffic through multiple encrypted relays, making ISP-level traffic analysis significantly more difficult.

Review your ISP's privacy settings. Most major ISPs maintain online portals where subscribers can opt out of data-sharing programs. These options are frequently buried and may require periodic renewal, but they represent a baseline step worth taking.

Advocate for legislative change. Technical countermeasures address symptoms rather than causes. The structural absence of robust federal broadband privacy law is a policy problem that requires a policy solution — one that sustained public and constituent pressure on legislators remains the most reliable mechanism to advance.

The Asymmetry That Defines the Problem

The ISP privacy issue is, at its core, a problem of asymmetric power. Providers possess detailed knowledge of subscriber behavior; subscribers possess limited knowledge of how that information is used. The legal framework has, to date, done more to protect the former than the latter.

Until that asymmetry is addressed through enforceable federal standards, American internet users will continue navigating a surveillance relationship they largely did not choose and cannot easily exit — one that begins the moment they connect.

All Articles

Related Articles

Threat Intelligence
Your Personal Data Has a Price Tag — Here Is Who Is Selling It and How to Fight Back
Jul 27, 2026
Threat Intelligence
One Password, Two Worlds: How Credential Reuse Turns Employees Into Enterprise Liabilities
Jul 27, 2026
Threat Intelligence
Hidden in Plain Sight: The Browser Extensions Quietly Draining Your Digital Life
Jul 27, 2026