Skip to main content
They Are Listening

The Legal Landscape

How comprehensive audio surveillance remains legal under current frameworks.

The Federal Wiretap Act (18 U.S.C. § 2511)

Enacted in 1968, the Wiretap Act strictly prohibits the intentional interception of oral communications. At first glance, a smart speaker recording a conversation without a wake word appears to be a direct violation.

The Loophole: One-Party Consent. Federal law and the majority of US states operate under "one-party consent." This means only one party in a conversation needs to consent to the recording. But what if it's ambient noise? Tech companies bypass this entirely via Terms of Service. By setting up the device, you provided explicit, ongoing, transferable consent to audio processing. You are the consenting party.

GDPR (Europe) & CCPA (California)

These frameworks approach the problem differently: focusing on the *data* rather than the *interception*.

  • GDPR (General Data Protection Regulation): Requires explicit, informed consent for data collection, and the right to erasure. This forced tech companies to build portals where users can view and delete their audio histories. However, the *inferences* drawn from that audio and synced to ad profiles are often obfuscated.
  • CCPA (California Consumer Privacy Act): Gives residents the right to know what data is collected and the right to say "Do Not Sell My Personal Information." Tech giants often argue they don't "sell" data in the traditional sense; they sell *access* to audiences based on that data, creating a gray area.

The FTC & Unfair Practices

The Federal Trade Commission has occasionally stepped in under its authority to regulate "unfair and deceptive acts" (Section 5 of the FTC Act). The Vizio settlement (concerning ACR) was based on the fact that the collection was *deceptive*—it was hidden in settings unrelated to privacy, like "Smart Interactivity."

The lesson for tech companies wasn't "stop tracking." The lesson was "put the tracking in the Terms of Service."