Internet privacy in the new age of deregulation

When it comes to internet privacy, there are only two schools of thought: the naive approach, thinking that your data is private and secure, and the approach the rest of us take, thinking that it’s a post-apocalyptic wasteland of fear and insecurity.

So, with that, how does the new ruling this past month regarding internet privacy, or the lack thereof, impact companies and private citizens? Hold on to your hats because this is about to get legal.

Key Takeaways

  • New FCC deregulation removed the requirement for ISPs to obtain customer permission before using or sharing highly sensitive information, including precise location, financial and health data, social security numbers, browsing history, and app usage.
  • ISPs can use less sensitive information, like email addresses, unless customers specifically opt out, while still being required to clearly disclose privacy policies and implement industry best practices for securing collected data.
  • Major ISPs including Comcast, Verizon, and AT&T issued carefully worded, largely noncommittal statements following the ruling, often referencing narrower legal protections (like the Communications Act’s telecommunications-specific privacy provisions) rather than addressing browsing data directly.
  • With regulatory oversight reduced, the responsibility for managing personal data exposure increasingly falls on individuals and businesses themselves, rather than being guaranteed through legal protections.
  • A more pragmatic, security-conscious approach to internet use, education, and personal data management has become essential in this new regulatory environment, since legal protections can no longer be assumed as a default safety net.

To begin, we must first understand the legalities of FCC rules. Simply put, when following FCC rules, internet service providers must obtain customer permission in advance to use or share highly sensitive information. This information continues to include everything from precise location, financial and health information, social security numbers, web browsing history, app usage, and the contents of communications.

Now, before continuing with this article, go back, and read that sentence again, maybe even twice to let it truly sink in for a moment. That’s right, for those of you who have opted-in—or more accurately, for those of you who have never read your ISP agreement and just clicked “Agree” in haste—this is the information that you are sharing with a lot of companies. And, not to be hyperbolic, I firmly stand by my statement that it’s a post-apocalyptic wasteland of fear and insecurity.

But that’s not where this ends, or even restarts with the new laws. In fact, ISPs could use less sensitive information, such as email addresses, unless their customers asked them not to, or they opted out. The rules also require ISPs to clearly articulate their respective privacy policies, and to implement so-called industry best practices to secure all collected data.

The million-dollar question becomes, “What’s the projected outcome?” However, the legalities surrounding this new legislation really depend on trusting ISPs to “do the right thing,” whatever that may be. But, as always, legal-speak can be interpreted in many ways—and don’t say I didn’t warn you.

In communications released in the past few weeks, ISPs have very carefully worded their statements to be vague and noncommittal—so much so, I feel like they took lessons from me in my college dating years (I hope my wife isn’t reading this).

For instance, Comcast stated that it did not “sell its customers’ individual web browsing history” and had no plans to do so. Following suit, Verizon used similar language in its statement. As for AT&T, it stated that it hadn’t changed its privacy practices and noted that it was still subject to the privacy rules included in the Communications Act. What wasn’t said, was that in all cases the Act’s privacy provisions discuss only telecommunications data such as call location and information published in telephone directories.

So, where does this leave us now? To be honest, I don’t think anyone really knows. Truthfully, the moral to this story is simply one of “Trust No-one” (thanks, Fox Mulder for making me so damn paranoid). But all jokes aside, let’s approach this from a simplified viewpoint. In the new world order of internet data and subsequent tracking, nothing is sacred anymore. The age of due diligence now falls squarely upon our individual shoulders to manage our own proverbial backyards.

A little education around internet security, tools to mitigate risk, and taking a more pragmatic approach to surfing the internet isn’t a bad thing. This new legislation should do nothing more than make us more self-aware, more diligent, and just a little bit smarter.

And remember, the truth is out there—it just costs a little more these days.

CONTACT INTELECA TODAY FOR MORE INFORMATION REGARDING INTERNET PRIVACY

FAQs

Does the FCC have any control over the internet?

Yes, but its authority is more limited than many people assume, and it has shifted significantly over the years. As of 2026, there are no federal net neutrality rules in effect. A federal court (the Sixth Circuit) struck down the FCC’s most recent attempt to regulate broadband as a public utility in January 2025, ruling the agency lacked the statutory authority to do so. Broadband internet is currently classified as a lightly regulated “information service” rather than a utility-style common carrier, which significantly narrows what the FCC can enforce. The FCC still retains real authority in specific areas, including transparency requirements, broadband subsidy programs, consumer complaint handling, and national security restrictions on network equipment, but it can no longer dictate how ISPs manage or prioritize internet traffic without new authorization from Congress.

What data can an internet service provider collect from a person?

ISPs are generally positioned to collect substantial data about their customers, including browsing activity, connection metadata, app usage, and general account information, since all of this traffic passes through their infrastructure. What ISPs are permitted to actually use or share, however, depends on the current regulatory environment and their own privacy policies, both of which have changed multiple times over the past decade as internet regulation has shifted back and forth between stricter and lighter oversight. Reviewing an ISP’s specific privacy policy remains the most reliable way to understand exactly what data is being collected and how it may be used, since federal requirements around this have not remained consistent.

Can ISPs see everything you do online?

ISPs have visibility into a significant amount of unencrypted traffic and metadata, including which websites you visit and how much data you use, though encrypted connections (like HTTPS, which most websites now use) limit their ability to see the specific content of what you’re doing on a given site. Using a VPN can further limit what an ISP is able to observe by routing and encrypting traffic through a separate server. Given that federal privacy protections around this kind of data have shifted considerably in recent years, individuals concerned about ISP-level visibility into their online activity may want to look into encryption tools and privacy-focused browsing practices rather than relying on regulatory protection alone.

Talk to an expert

Book an appointment with an expert for a complimentary consultation.

Let’s partner. Together, we’ll build solutions so you can Make the Most of IT.

IT Support & Sales
800-961-3094

 I am very pleased with the quality of service Inteleca provides. I sincerely appreciate your responsiveness and the way you conduct business. I look forward to doing business with Inteleca for years to come.

Contact Us