Privacy law is not a fence. It is the ongoing argument about where the fence goes, who gets to move it, and whether the thing on the other side is worth protecting in the first place. That argument is the whole story of 2026, and the U.S. Supreme Court’s decision in Chatrie v. United States is the clearest illustration of it yet.
Public defenders who handle Fourth Amendment cases have watched geofence warrants move through the federal courts for years, waiting to see whether the Supreme Court would treat them as searches at all. The Chatrie ruling answered that question. It held that obtaining location history through a geofence warrant is a search under the Fourth Amendment. That is the headline. Read the opinion for what it actually settled, though, and the fence turns out to have been sketched, not built.
The Court did not hold that all geofence warrants are unconstitutional. It left open whether the specific warrant in Chatrie was reasonable. It left open how narrowly future geofences must be drawn. It left open how probable cause should be assessed when the suspect is unknown at the moment of the request — the entire premise of a geofence, since police use one precisely because they do not yet know whose phone was there. And it left open how much discretion officers may exercise in deciding which users, out of the initial pool returned by Google, to unmask by name.
Four questions. Each of them determines whether a given warrant clears the constitutional floor the Court just raised. None of them has an answer yet.
For defendants like Chatrie, that ruling is both a win and a homework assignment. The next several years of geofence litigation will be spent arguing over what “reasonable” means when the government asks a private company to hand over an anonymized haystack and then pick names out of it. Every one of those arguments is a fight about definitions — what counts as a search, what counts as particularity, what counts as probable cause when the target is a geographic box rather than a person.
That is the pattern worth naming. Legal privacy in the United States is being built through litigation as much as legislation — through product-level opt-outs, through Fourth Amendment cases, through state attorneys general acting where Congress has not. Meanwhile, Congress has been circling FISA Section 702 reauthorization without landing, punting again on the key spying law while surveillance pricing probes expanded on a separate track. The Electronic Frontier Foundation has been sharp on the SCREEN Act, arguing in its analysis that the age-verification bill threatens privacy far beyond the adult websites it ostensibly targets. Even the sanctions regime is being pressed into service, as the recent designation of an Italian webhost extended sanctions law into anonymous speech infrastructure.
At the state level, the ground keeps shifting. A fresh set of state privacy law provisions took effect on July 1, 2026. Any company operating across state lines is now managing a patchwork that looks less like a coherent national framework and more like a mosaic assembled by twenty different legislatures with twenty different theories of harm. What counts as “sensitive data” in one state is unremarkable in another. What counts as consent in Colorado is not what counts as consent in Texas. Chatrie did not create that fragmentation, but it fits the same shape: the underlying question is definitional, and every definition is contested.
The compliance officers watching this from other jurisdictions see the pattern too. In Brussels, the European Commission’s Digital Omnibus package was framed as a simplification exercise. The most contested provision would have amended Article 4(1) of the GDPR — the foundational definition of what counts as personal data — so that information would not automatically be considered personal data for every entity just because some other entity could re-identify it. Consumer group BEUC warned this could remove GDPR protection from cookies, device IDs, and hashed email addresses for processors lacking re-identification capacity. The European Data Protection Board and European Data Protection Supervisor urged co-legislators not to adopt the change. A leaked compromise text in February 2026 dropped the Article 4(1) revision entirely. The retreat matters only if it holds — and parliamentary negotiations had not formally started as of late March 2026. The single most important word in European privacy law was, for several months, on the table for revision by the same body that wrote it.
That is the same category of instability Chatrie exposes on the American side. Not whether privacy law is getting stronger or weaker, but whether the underlying definitions — of personal data in Brussels, of a search in Richmond — are settled at all.
The comforting story about legal privacy is that somewhere there is a clean rule that protects a clear right. The less comforting reality is that the rule is a set of definitions, and the definitions are the fight.
On remand, the case returns to the Fourth Circuit to decide whether this particular warrant was reasonable — the question the Supreme Court didn’t answer. The Court has told defense attorneys that a geofence is a search. It has not told them what makes one reasonable, what makes one particular, or what makes one supported by probable cause. Those answers will come from district court and appellate judges over the next several years, in rulings that will individually feel technical and collectively decide how much of a person’s location history the government can sweep up before it needs a name to attach it to.
That is where the fence gets built. Not in the majority opinion, but in the hundreds of downstream rulings interpreting what the majority opinion meant. Australia’s privacy regulator ran the numbers this year, and the IAPP’s write-up of the results captured the public mood on the other side of that wall: many companies still treat privacy as an administrative checklist, but the public increasingly views aggressive data collection as structurally unfair — a trust gap wide enough that only one in ten Australians think companies’ data practices are usually fair. Some analysts argue firms that treat privacy regulation as an operational input rather than a threat see the opposite of the value-destruction narrative playing out in their favor. But the analysts and the customers are both downstream of the same upstream question, and Chatrie is a reminder of how unsettled that question remains.
Legal privacy is a status, not a settlement. It holds only as long as the actors who wrote it keep choosing to hold it. When they stop — or when they simply leave the hard questions for later, as the Chatrie Court did — the definition itself becomes negotiable, and everything downstream of the definition moves with it.
The rights people assume they have under privacy law are only as durable as the definitions underneath them. Those definitions are being redrafted right now, in rooms most people will never see, by people whose names most people will never learn. In the Chatrie decision, the Supreme Court walked into one of those rooms, drew a line, and walked out again before deciding what the line was made of.