Back to blog
dns Published: AEU DNS Newsroom

Internet Society, Mozilla and EFF Urge AT&T, T-Mobile and Verizon to Adopt Basic Privacy Promises

Internet Society, Mozilla and EFF Urge AT&T, T-Mobile and Verizon to Adopt Basic Privacy Promises

Three leading internet advocacy organizations are asking major U.S. mobile carriers to commit to limiting data collection and retention, and to be transparent about data sharing.

The Internet Society, Mozilla, and the Electronic Frontier Foundation have joined together to call on three of the largest mobile carriers in the United States, AT&T, T-Mobile, and Verizon, to commit to basic user privacy protections. In a joint statement, the groups are asking these companies to limit the data they collect and how long they keep it, and to be clear about how that data is stored and used, including any sharing with business partners or affiliates for purposes that are not strictly necessary to run the network.

Internet service providers, or ISPs, sit in a uniquely powerful position. When you connect to the internet at home or on your phone, your ISP carries the traffic between your device and the websites and services you use. Every time you visit a website, your device first asks a Domain Name System, or DNS, resolver to translate a human-friendly name like example.com into the numeric Internet Protocol address a computer needs. Most people use the DNS resolver provided by their ISP by default. This means the ISP can see which website names you look up, even if the content of the page itself is protected by HTTPS encryption. Over time, a record of those lookups can build a detailed picture of your interests, health concerns, financial situation, political views, and daily habits.

The call from the three organizations focuses on two central demands. First, the carriers should commit to limiting data collection and retention. In practice, this means collecting only what is needed to provide the service and not storing it longer than necessary. Second, the carriers should ensure transparency around how that data is stored and used. This includes being open about any sharing of customer data with business partners and affiliates for non-operational purposes, such as advertising, analytics, or other commercial activities that are not essential to keeping the network running. Without such commitments, users have little visibility into who sees their browsing history, location patterns, or application usage.

Why does this matter to everyday internet users? ISPs have access to a stream of metadata, information about your communications rather than the content of those communications. While metadata may seem less sensitive than the content of a message or a web page, it can be extremely revealing. The websites you visit, the times of day you connect, the amount of data you use, and the pattern of your connections can expose private details about your personal life. If that information is shared with third parties for non-operational purposes, it can be used to build detailed profiles for targeted advertising, sold to data brokers, or in some cases accessed by government agencies. The groups argue that basic privacy protections should be the baseline, not an optional extra.

There are practical steps anyone can take to reduce what their ISP can see, even before carriers adopt stronger promises. One effective measure is to stop using the ISP's default DNS resolver. Instead, you can choose a privacy-first DNS service that supports encrypted DNS protocols such as DNS over HTTPS, DNS over TLS, or DNS over QUIC. These protocols scramble the connection between your device and the DNS resolver, so your ISP cannot easily read which website names you are looking up. This does not hide the fact that you are online, but it removes a major source of browsing history that ISPs otherwise collect silently. For readers who want to reduce what their ISP can observe, a privacy-first resolver such as AEU DNS, which offers encrypted DNS over HTTPS, TLS and QUIC and keeps no logs, is one practical tool to consider.

In addition to encrypted DNS, using a reputable virtual private network, or VPN, can further protect your traffic by creating an encrypted tunnel for all data, not just DNS lookups. Making sure websites you visit use HTTPS, the secure version of the web that scrambles page content, is also important. Checking the privacy settings on your mobile phone or home router can reveal options to limit ad personalization or data sharing. While these measures do not replace strong corporate privacy commitments or legal protections, they give individuals a meaningful way to reduce the amount of data their ISP can collect, retain, and potentially share with others.

The joint call by the Internet Society, Mozilla, and the Electronic Frontier Foundation highlights a growing expectation: ISPs should treat user privacy as a fundamental responsibility, not a revenue opportunity. As more daily activities move online, the line between metadata and sensitive personal information continues to blur. Clear limits on collection and retention, along with honest transparency about sharing practices, are essential first steps. For users, understanding how their ISP handles data and taking control of their own DNS and connection security are practical ways to protect their privacy today.

Terms explained

ISP (Internet Service Provider)
The company that provides your home or mobile internet connection and can see some of your online activity.
DNS (Domain Name System)
The internet's address book that translates easy-to-remember website names into the numeric addresses computers use.
encrypted DNS
A way of making DNS requests private so that only you and the DNS service can see which website names you look up.
HTTPS
The secure version of the web that scrambles the content of pages you visit so others cannot read them in transit.
VPN (Virtual Private Network)
A service that creates a private, encrypted tunnel for all your internet traffic, hiding it from your internet provider.
data retention
The practice of keeping records of your online activity for a certain period of time.

How to protect yourself

  1. Change the DNS server (the internet's address book) on your device or home router to a privacy-focused encrypted DNS service so your internet provider cannot easily see which websites you look up.
  2. Use a reputable VPN, a service that creates a private encrypted tunnel for all your internet traffic, whenever you are on a mobile network or public Wi-Fi.
  3. Check your mobile carrier's privacy settings and turn off ad personalization or data sharing options where they are available.
  4. Make sure your web browser has the setting to always use HTTPS turned on, so the content of pages you visit is scrambled in transit.
  5. Read your internet provider's privacy policy to understand what data they collect, how long they keep it, and who they share it with.

Source: internetsociety.org

Get private, encrypted DNS