The Last Physical Privacy Control Is Disappearing
For years, removing the SIM card from your phone was one of the few ways to be certain your device wasn’t actively connected to a cellular network. No SIM, no cell signal, no triangulation, no carrier data collection. It was crude, but it was reliable.
The shift to eSIM — an embedded SIM chip soldered directly into the phone’s motherboard — has eliminated this option for an increasing number of users. iPhones sold in the US since 2022 are eSIM-only. Android flagship devices from Google, Samsung, and others have followed. In markets across Europe and Asia, network regulators are actively encouraging the transition.
This isn’t a story about eSIM being malicious technology. It’s a story about how convenience, as it usually does, erodes a privacy control — and why users deserve to understand what that means for the data their phone now generates.
What eSIM Actually Is
A physical SIM card is a small removable chip containing your subscriber credentials — the information your carrier uses to authenticate your device on its network. When you switch carriers, you get a new physical SIM. When you want to go offline, you remove it.
An eSIM (embedded SIM) performs the same function but is built into the phone permanently. Subscriber credentials are stored digitally and can be managed remotely — downloaded, switched, or deleted without a physical card swap.
For consumers, this is genuinely useful: you can switch carriers without visiting a store, travel internationally and add a local data plan from your phone, and use multiple carrier profiles on a single device. Newer standards support multiple simultaneous active profiles.
The convenience is real. So is what it changes about your relationship with your carrier.
What Your Carrier Can Track
Whether you have a physical SIM or eSIM, your carrier collects certain categories of data as a function of how cellular networks work. When your phone connects to a cell tower, that connection generates a record. The question is what specifically is recorded and what the carrier does with it.
Network connection records: Every time your device connects to a cell tower, the carrier knows which tower, at what time, and from what device (identified by your IMEI number and your SIM credentials). This creates a location history that is a byproduct of how cellular networks function — the carrier needs this information to route calls and data.
Call and SMS records: Who you called, when, how long the call lasted, who sent you messages. This is carrier metadata — the content of calls and messages isn’t captured by default, but the patterns of communication are. Carriers are legally required to retain this data in most jurisdictions for specific periods.
Data usage records: How much data you use, when, and in some cases the IP addresses you connect to. Some carriers log this at the level of which apps generated the traffic.
Location data derived from network connections: Multiple court decisions in recent years have addressed how carriers can use and share location data derived from cell tower connections. This data is highly precise in dense urban areas where cell towers are closely spaced, and it can reconstruct your movements throughout the day.
eSIM management events: This is specific to eSIM: when a new profile is downloaded, when a profile is activated or deactivated, when credentials are updated. These events are logged by the carrier’s eSIM platform and create a record of how your subscriber credentials have been managed over time.
What Changes Specifically With eSIM
The baseline carrier tracking described above applies to both physical SIM and eSIM users. What eSIM changes is the control layer — and some of what was previously visible to the user becomes opaque.
Remote profile management: With a physical SIM, changes to your carrier relationship required you to physically interact with a new card. With eSIM, carriers can remotely push credential updates, modify your profile, or in some implementations, remotely deactivate your profile. The user may not be notified that this has happened.
No physical offline option: Removing a physical SIM disconnects your device from cellular networks immediately and permanently until you reinsert it. With eSIM, going offline requires using software settings (Airplane Mode, or disabling cellular data in settings). Software controls can be interfered with by operating system bugs, by malware with system-level access, or by device management profiles installed by employers or institutional IT.
eSIM device binding: eSIM profiles are typically bound to the specific device they were activated on, making unauthorized profile transfers harder but also making it easier for carriers to associate a specific device with a specific subscriber account. The data trail between the physical device and the subscriber is stronger with eSIM than with SIM cards that could theoretically be moved between devices.
Carrier activation record: When you activate an eSIM profile, the activation event — including your device’s IMEI, the time of activation, and approximate location — is recorded by the carrier. This creates a more complete enrollment record than a SIM card swap might.
What Carriers Actually Do With This Data
Carriers collect substantial data as a byproduct of operating cellular networks. What do they do with it?
Internal use: Carriers use network data for capacity planning, fraud detection, and customer service. This is the legitimate operational core of carrier data collection.
Law enforcement requests: Carriers are obligated to respond to lawful legal requests for subscriber data. In the US, this includes National Security Letters (which can be issued without judicial review), FISA court orders, and conventional warrants. Carriers process large volumes of these requests. Your location history at a carrier is potentially accessible to law enforcement without you ever knowing.
Third-party data sales: A significant controversy emerged when US carriers were found selling location data derived from cell tower records to data brokers, who in turn sold it to bounty hunters, insurance companies, and others. Multiple carriers paid FCC fines as a result. The practice drew formal regulatory scrutiny, though the degree to which it has fully stopped is disputed.
Aggregated analytics: Carriers sell aggregated, supposedly anonymized mobility data to urban planners, retailers, advertising platforms, and others. Aggregated data is supposed to be impossible to trace to individuals, but research has repeatedly demonstrated that location data is remarkably difficult to truly anonymize — even aggregated patterns can often be traced to specific individuals.
The eSIM Privacy Risk That Gets Overlooked: Data Brokers
The location data collected through cellular network connections has a well-documented path into data broker databases. This isn’t theoretical — the FCC enforcement actions against carriers for selling location data to brokers established that this happened at scale.
Data brokers combine carrier-derived location data with data from other sources: app location tracking, credit card transaction records, social media activity, public records. The combined profile is sold to:
- Insurance underwriters (auto insurance uses driving behavior, health insurance can use location patterns to infer lifestyle behaviors)
- Employers conducting background research
- Political campaigns for voter targeting
- Financial institutions for credit risk assessment
- Law enforcement (both through legal process and through commercial purchases of broker data)
Your carrier’s location data is not the only input to these profiles, but it is one of the most accurate and comprehensive. The shift to eSIM doesn’t change this dynamic — but the loss of the physical SIM removal option eliminates one of the few hardware-level tools for temporarily breaking this data collection.
International Travel and eSIM
eSIM’s most compelling use case for many consumers is international travel. Rather than paying roaming fees or hunting for a local SIM at an airport kiosk, you can add a local data eSIM profile from your phone before you leave.
The privacy implication is worth understanding: every eSIM provider you add records an activation event with your device’s IMEI. If you use three different international eSIM providers across a trip, three different companies now have a record connecting your device identifier to activation events in those countries on those dates.
International eSIM providers range from large established telecoms to small startups with minimal public privacy documentation. Before using an international eSIM, it’s worth checking whether the provider has a privacy policy, where they’re incorporated, and what data they retain.
What You Can Actually Do
The eSIM transition reduces hardware control, but several meaningful software controls remain available.
Use Airplane Mode as your offline control. It’s not as certain as removing a SIM card, but enabling Airplane Mode genuinely disables cellular radio functions on modern devices. Follow up by verifying in Settings that cellular is shown as inactive.
Audit which apps have background location access. Many apps collect location independently of your carrier. On iOS: Settings → Privacy & Security → Location Services. On Android: Settings → Privacy → Permission Manager → Location. Revoke always-on background access from apps that don’t have a clear need for it.
Disable Wi-Fi calling if you don’t use it. Wi-Fi calling can route your calls through your home or work network, creating additional connection records at your ISP level.
Use a VPN for data traffic. A VPN doesn’t hide the fact that your device is connected to a cell tower (that’s network-level metadata the carrier captures regardless), but it does prevent the carrier from logging the IP addresses you connect to and the content of your unencrypted data traffic.
Be selective about international eSIM providers. For travel data, look for providers with clear privacy policies, no-KYC (Know Your Customer) options where available and legally permitted, and data centers in jurisdictions with strong privacy law.
Limit what you store on your phone vs. in the cloud. The data your carrier can access through lawful process is your network activity — not what you have stored. Files encrypted and stored in a private storage service that the carrier has no relationship with are not accessible through carrier legal process.
The Bigger Picture: Hardware Control Is Eroding
The eSIM transition is part of a broader pattern in personal electronics. Batteries are increasingly non-removable. Storage is embedded. Modems are integrated into application processors. The hardware-level privacy controls that technically sophisticated users once relied on — remove the battery, remove the SIM, wipe the drive — are disappearing one by one.
This doesn’t mean privacy is impossible to maintain. It means that software controls, service selection, and data minimization practices become more important as hardware controls disappear.
Understanding what your carrier collects and how — regardless of whether you have a physical SIM or eSIM — is foundational to making informed decisions about the rest of your privacy posture. The eSIM transition is a good moment to examine those assumptions, because many people built them around a hardware affordance that no longer exists.
The phone in your pocket is always connected to cellular infrastructure, generating location records and network metadata continuously. That was mostly true before eSIM, and it’s entirely true after. What changed is that the option to temporarily step outside that infrastructure — simply, physically, without relying on software — is gone.
Knowing that changes how you should think about everything else.