The Rule They’re Fighting
The New York City Taxi and Limousine Commission requires every for-hire vehicle operator to submit monthly records of every trip: pickup and drop-off times and locations, driver identification, and license plate number. That sounds like a routine regulatory data call until you calculate what it actually produces: a 30-day movement profile of every passenger who hires a car in the five boroughs — where they live, where they work, where they worship, who they visit, how long they stay.
The TLC’s stated justification is driver fatigue: granular per-trip data lets it ensure drivers do not work unreasonably long shifts. Spokesman Jason Kersten calls the rules “vital to driver and passenger safety, corporate accountability, and our ability to make informed decisions as we regulate the largest industry of its kind in the United States.” Fine as far as it goes — except that the commission has never demonstrated that per-trip granular location data is causally necessary for fatigue monitoring. The link is correlational. There is no mechanism evidence in the public record connecting individual pickup/drop-off coordinates to accident prevention beyond what aggregated data would provide.
The TLC’s rule predates modern re-identification capability and reflects a pre-digital paradigm in which trip data was treated as inert business records. It was designed at a time when no one could plausibly cross-reference government taxi data with celebrity photos to identify specific riders and publish the results online. That time ended in 2014.
The Re-Identification Precedent That Should Have Changed Everything
In 2014, Anthony Tockar of Neustar Research obtained the TLC’s own open-records taxi dataset — the same type of data the current rule requires — and cross-referenced it with celebrity photographs published on gossip blogs. He was able to map identifiable individual movements to specific rides. The result was a public disclosure of which celebrities did not tip their drivers.
That is not a hypothetical risk. It is a demonstrated, published exploit of the TLC’s own data architecture. And nothing was adjusted afterward. The rule today collects data with the same granularity that made the 2014 re-identification possible. Georgetown Law professor Paul Ohm has documented the principle at work: “Really precise, longitudinal geolocation information is absolutely impossible to anonymize,” he told the New York Times. “D.N.A. is probably the only thing that’s harder to anonymize than precise geolocation information.” Wheely’s website translates that to “Only DNA is harder to anonymize than human movements.”
Temporal aggregation creates identifiability. The TLC rule collects exactly the granularity needed to enable it.
The Company That Sells Privacy as a Product
Wheely USA entered the New York market in March 2026. Founder Anton Chirkunov launched the company in 2012, and it already operates in London, Paris, and Dubai. Its fleet is mostly Mercedes, Cadillacs, and Range Rovers. The vehicles come stocked with chargers, water, and hot towels. Drivers sign nondisclosure agreements and attend a company “Chauffeur Academy” that trains them on etiquette, dress, and — the core of the product — discretion. The company says top drivers can earn up to $12,000 a month.
Wheely’s business model is privacy delivered as a service. Every element — the fleet, the training, the NDAs, the premium pricing — constitutes an operational promise that the passenger’s movements are not recorded, shared, or exposed. The TLC rule makes that promise undeliverable by requiring disclosure of every trip’s pickup and drop-off to a centralized city database. You cannot sell discretion and then produce a monthly ledger of every passenger’s location to the government.
Chirkunov put it plainly: “We believe that riders have the right to travel in their city without their movements being tracked by the government.”
The Company’s Own History Became the Judge’s Argument Against It
This is not Wheely’s first confrontation with a government demanding location data. The company refused Moscow’s real-time geolocation data demands beginning in 2020, was subjected to a court-ordered three-month operational suspension, and ultimately exited the Russian capital rather than comply. That’s a multi-year standoff documented by the Guardian, Reuters, and Forbes — and it became the district court’s central argument against Wheely’s constitutional claim.
U.S. District Judge Colleen McMahon ruled this spring that the privacy intrusion was “relatively modest” and was outweighed by the city’s legitimate safety concerns. She noted that Wheely “was aware of the reporting requirements when it entered the city’s highly regulated taxi industry.” The language from her ruling: “What it cannot do is persuade this Court that any of its arguments for why the TLC Rules are unconstitutional, or otherwise unlawful, has the slightest merit.” And then the line that converted Wheely’s own privacy record into a legal concession: the company is “free to leave the New York market — as it did in Moscow over similar demands — or play by the city’s existing rules.”
The district court applied a balancing test designed for a pre-digital regulatory context. It did not calibrate for comprehensive movement profiling. It treated the data as trip records rather than as the movement-profile material that the 2014 re-identification incident and Ohm’s scholarship have shown it to be.
The Unusual Coalition That Proves This Is Not About Luxury Rides
Three organizations have filed legal briefs supporting Wheely’s appeal: the Cato Institute, the Legal Aid Society, and the U.S. Chamber of Commerce. These organizations have opposite priors on nearly every regulatory question. The libertarian Cato Institute argued that the district court’s decision “could subject many New Yorkers to the possibility of long-term and continuous surveillance.” The Legal Aid Society filed not because it represents luxury riders — it doesn’t — but because the surveillance architecture the TLC has built does not stop at the luxury tier. Low-income New Yorkers, immigrants, and individuals interacting with the criminal justice system face the same data-collection exposure with more severe consequences. The U.S. Chamber of Commerce frames the issue as regulatory burden on operators.
Their convergence on a single claim — that the TLC data-collection mandate goes too far — is itself the structural signal. This is not a dispute about one company’s compliance costs or one ridership tier’s privacy preferences. The case is about government data-collection architecture generally. If it were about rule content alone, you would not see Legal Aid and the Chamber on the same side.
The Carpenter Doctrine and Its Unresolved Extension
Wheely is pinning its appeal on the Supreme Court’s 2018 decision in Carpenter v. United States, which held that police generally need a warrant to obtain cell-site location information spanning seven days or more. The Court recognized that aggregated location data produces a “comprehensive picture” of an individual’s life — movements, associations, habits — meriting Fourth Amendment protection.
The TLC rule collects 30 days of trip-level movement data from every licensed vehicle: time, place, driver, vehicle, for every trip, every month. The structural parallel to Carpenter’s CSLI is clear. The problem is an institutional distinction: Carpenter addressed data held by a third-party carrier under the Stored Communications Act. The TLC rule addresses data operators are required to submit directly to a government agency. Whether that distinction immunizes the rule from Carpenter’s reasoning is the question before the Second Circuit. It is genuinely unresolved, and the court has not yet applied Carpenter to TLC-type administrative data collection.
The Root Condition: No Institutional Mechanism for Proportionality Review
Beneath the litigation lies a structural failure. The TLC data-collection rule carries no mandatory periodic proportionality review mechanism. There is no institutional process requiring the commission to demonstrate that collection scope is calibrated to specific identified risks or that anonymization procedures remain current to re-identification technology. The rule was written in a pre-digital paradigm, and nothing in its design compels the commission to adjust it as data-combination and de-anonymization capabilities advance.
That is the root cause, three levels below the litigation symptom. Removing the current rule would address the surfaced failure — over-collection — but would not prevent recurrence. Without a review mechanism, any administration can re-impose over-collection. The problem is institutional, not rule-specific.
What a Win or Loss Means Beyond Wheely
If the Second Circuit upholds the TLC rule, it becomes a template. Other cities can apply comparable reporting requirements to licensed vehicle operators of every kind — food delivery, medical transport, paratransit. The data-collection mandate, once validated by judicial approval, travels with the precedent of that approval. The coalition’s breadth — Cato, Legal Aid, Chamber — is itself evidence of that reach: the organizations contesting Wheely’s compliance are contesting a model of municipal data collection that, if upheld, scales to every licensed vehicle in every city that adopts it.
The corrective fix is narrow: eliminate granular pickup/drop-off location data for non-safety-specific uses and retain de-identified or aggregated data for legitimate fatigue monitoring. The preventive fix is structural: establish a mandatory periodic proportionality review mechanism for all TLC data-collection rules, requiring the commission to recalibrate collection scope and anonymization procedures to current technology.
Confidence and the Open Questions
The dominant causal chain — an institutional procedure gap produces over-collection, which produces convergent opposition from surveillance-concern, social-equity, and regulatory-burden interests — is logically sound and empirically grounded in the coalition breadth. If the problem were simply the content of the current rule, the coalition would be narrower. Confidence is moderate because the appeal outcome turns on a legal question the Supreme Court has not squarely resolved and because the rule’s original adoption date is not established in the source material — the pre-digital-paradigm inference is plausible but ungrounded in specific historical evidence.
The alternative chains are equally plausible: the Second Circuit could hold that Carpenter’s reasoning does not extend to voluntarily submitted regulatory business records, leaving the TLC rule intact without addressing the institutional gap. Or the case could function primarily as a strategic Carpenter vehicle — a deliberate test designed to push the privacy-reasoning frontier from CSLI to administrative data collection, regardless of which company brought it. All three alternatives produce the same surfaced symptom: a Fourth Amendment challenge to the TLC rule. Even if the institutional fix is enacted, the case will have served as the vehicle for litigating the line between regulatory business records and constitutionally protected movement data — a line that, given the demonstrated re-identification risk, was overdue for testing.
Analytical techniques used in this piece
This analysis applies the methods below. Each links to a short, plain-English explainer you can read and reuse.
- Relationship Mapping
- Extracts the network of ties among people, institutions, and entities.
- Root-Cause Analysis
- Traces a symptom back along its causal chain to the conditions that actually generated it.
- Stakeholder Mapping
- Charts the parties to a situation — their interests, power, and alignments.