Sold at a loss.
Paid for by watching you.

Most televisions now identify what is on the screen, second by second, and send the record home to be sold. That is not a rumour and it is not a reading of a privacy policy. In 2024 researchers put two new sets behind a packet capture and wrote down what left the house. This page covers what they saw, what their method could not see, and why the only measure that does not depend on a manufacturer's good behaviour is keeping the set off your network entirely.

What the technology actually is

The feature is called Automatic Content Recognition, and the clearest way to describe it is Shazam for your screen. The television captures the image it is displaying, reduces it to a fingerprint, and matches that fingerprint against a catalogue of known media. It does not need to understand the picture. It only needs to recognise it, which is a far cheaper problem, and one that was solved for music twenty years ago.

The capture rates come from the manufacturers' own documentation. LG states that its system captures frames every 10 milliseconds. Samsung states that its system captures every 500 milliseconds. Neither figure is disputed by anyone. They are published, and they are the basis on which the Texas Attorney General described the technology as screenshotting the screen twice a second.

The output is a timeline. Not "this household likes cooking shows," but a minute-by-minute record of what was on that screen, which is a different and much more specific object. It covers whatever the panel displays, so the source does not matter: cable, antenna, a streaming app, a disc, a console, or a laptop plugged into the side.

Somebody measured it

In November 2024, a team from UC Davis, University College London and Universidad Carlos III de Madrid published a black-box audit of ACR network traffic at the ACM Internet Measurement Conference. The method is the reason to trust it. They bought new LG and Samsung sets, put each one behind a controlled network hub, captured every packet the television sent, and then repeated the whole experiment across six ways of watching, four privacy configurations, and two countries.

That design is what makes the findings hold. They are not inferred from a policy document or from a company's description of itself. They are what the wire showed.

  • The fingerprints go out on a clock. LG batches its 10 millisecond captures and transmits a fingerprint every 15 seconds. Samsung batches its 500 millisecond captures and transmits once per minute. Both patterns are visible as regular spikes in the traffic.
  • It runs hardest when the TV is a dumb monitor. The two scenarios with the highest ACR traffic on both brands were broadcast television and HDMI. Plugging in a laptop or a games console does not put the television to sleep. It is the condition under which the television has the least other information about you, and it is the condition under which it fingerprints most.
  • Logging out changes nothing. Traffic was materially identical whether the researchers were signed into a manufacturer account or not. The authors conclude that the tracking is keyed to the set's advertising ID and IP address rather than to any account you control.
  • The data does not always stay in the country. For the UK sets, one Samsung ACR endpoint resolved to a server in New York. British viewing records were leaving the jurisdiction whose data protection law was supposed to be the strong one.

They then ran the same experiments with the advertising and tracking settings switched off. In their words, "once opt-out is exercised, there is a complete absence of communication with any previously identified ACR domains, and no new ACR-related domains are observed." Their stated conclusion is that "the opt-out mechanisms implemented on LG and Samsung smart TVs are working."

That is worth knowing and it is worth acting on. It is also weaker than it sounds, and the limit is stated by the authors rather than inferred by us.

  • Nothing was decrypted. The method section says it directly: the analysis was "focused at extracting traffic patterns from the data captured by Mon(IoT)r without decrypting it." Nobody read a payload. What was demonstrated is that packets to known ACR domains stopped, which is not the same claim as nothing being collected, retained, or sent later by another route. The authors list man-in-the-middle work to read the payloads as future work, meaning it had not been done.
  • It is a snapshot, and the snapshot is old. Two brands, two countries, one firmware version, 2024. Nothing about that result carries forward automatically to a set sold today, and firmware is precisely the layer a manufacturer can change without telling anyone.
  • Absence of traffic to a known domain is the weakest form of proof there is. It is evidence, and it is the best available evidence, and it would be satisfied equally by a system that had genuinely stopped and by one that had moved.

So the honest version is this. Somebody checked, and what they could see stopped. That is a real finding and it is more than anyone had before. It is not a guarantee, it is ageing, and it is the reason the recommendation further down this page does not begin with a settings menu.

One viewer did get it switched off

Buried in the same measurements is the most instructive result on this page. ACR traffic dropped sharply while the researchers were streaming through a third-party app. Peaks fell by as much as twelvefold, consistent with the fingerprinting simply not running.

The reason is not a privacy setting. It is a commercial one. Netflix's stated position, quoted in the paper, is that it wants ACR deactivated during its streaming "in order to preserve the integrity of its subscribers viewing experiences and maintain sole control over measurement of its viewership." The measurement of who watched what is valuable, and Netflix declined to let the television manufacturer have it.

So the fingerprinting can be turned off per source, cleanly, at scale, and it already has been. Not for you. For a company with the leverage to ask. When you watch broadcast television or plug in your own machine, nobody is in the room negotiating on your behalf, and the fingerprinting runs at full rate.

That is worth holding onto, because it disposes of the argument that this is technically unavoidable. It is avoidable. It has been avoided. The question was only ever who had standing to demand it.

The country comparison makes the same point from the other side. In the UK, the manufacturers' own free ad-supported channels showed reduced ACR traffic. In the US, the identical channels showed traffic comparable to broadcast. The paper's suggested explanation is that the content agreements differ between the two markets. Same hardware, same software, different contracts, different amount of watching.

Regulators have been here before

None of this is new, and it has already been found unlawful once. In February 2017 the FTC and the New Jersey Attorney General settled with Vizio for $2.2 million over exactly this practice on 11 million televisions. The order records that Vizio was capturing second-by-second viewing data, appending demographic detail such as income, marital status and education, and selling the combined profiles. The FTC put the collection rate at as many as 100 billion data points a day. Vizio had also pushed the tracking software onto sets that shipped without it.

Eight years later Texas sued five manufacturers over the same technology. Samsung settled in February 2026 and LG in May 2026, both agreeing to stop collecting ACR data without informed consent and to put the disclosure on screen rather than in a policy. The cases against Sony, Hisense and TCL are still open, and those are allegations that have not been tested at trial.

The full record for each company, with the figures and the sources, is in the dossier rather than repeated here.

Read those two dates together. A federal regulator established in 2017 that doing this without clear consent was unlawful, and in 2025 a state attorney general had to establish it again against five more companies. The 2017 order changed one company's conduct. It did not change the industry's, because nothing made it.

Why the television was so cheap

The usual way to make this argument is to say that if you are not paying for the product, you are the product. That is a slogan, and it is weaker than the evidence, because in this case the evidence is a filed financial statement.

Vizio was a public company until Walmart acquired it, so its numbers are on the record. In the shareholder letter it filed with the SEC in February 2024, covering the full year 2023, the split reads like this.

Vizio Holding Corp. full year 2023 results, comparing the hardware business to the advertising and data business.
Full year 2023 Devices, meaning televisions Platform+, meaning ads and viewing data
Net revenue $1,081.8 million $598.2 million
Gross profit Negative $8.6 million $364.9 million

Vizio sold a billion dollars of televisions in 2023 and lost money on them. Every cent of gross profit the company made, and then some, came from the advertising and data business attached to the sets. The hardware was not a product with a thin margin. At the gross profit line it was a negative number, absorbed as the cost of placing a screen in a room.

This is the subsidy stated in the company's own accounts. The television was cheap because the television is not what was being sold. The reason the set in the shop undercut the one next to it is that its manufacturer had a second revenue line and the other did not, and the second line is a record of what you watch.

Ten weeks after that letter, Walmart completed its acquisition of Vizio. It did not buy a screen factory. The dossier entry for Walmart covers the rest, and the general pattern is on the Enshittification page: the point at which a product stops being the thing you bought and becomes the place where something is sold.

What actually works

There is one answer that does not depend on trusting anybody, and there is a second answer that does. They are not equivalent, so they are not presented as a menu of equals.

1. Never put it on your network

A television with no route to the internet has nowhere to send a fingerprint. Whatever the set captures, whatever the firmware decides to do next year, whatever a future agreement screen says: with no network path, none of it leaves the room. This is the only measure on this page that is true by construction rather than by permission, and it is the reason it goes first.

Feed it from a source device you chose, over HDMI. Decline the network during first-time setup rather than joining and forgetting, because on many models the setup flow treats connecting as the default path and some will re-prompt after an update.

The cost is real, so here it is plainly. No built-in apps, so you are buying a separate box. No firmware updates, which occasionally matter for panel or HDMI handshake fixes. Some sets nag at every startup. That is the price of the only version that does not rely on a manufacturer's continued good behaviour.

One thing worth knowing, and it applies to a set that is on the network. The audit found broadcast and HDMI to be the two highest ACR traffic scenarios on both brands. Fingerprinting does not stop because the picture arrives over a cable. So "I only use it as a monitor" is not by itself a defence if the television still has wifi. It is a complete defence once it does not. The external box and the disconnection are two halves of the same measure, and the second half is the one doing the work.

The box you plug in has its own version of this business, so choose it on the same terms. Roku and Amazon are built on advertising and viewing data in much the way Vizio is. An external device is one whose terms you can read and whose hardware you can replace. It is not automatically clean.

2. If the set is going to be online anyway, turn the settings off

Plenty of people are not going to give up the built-in apps, and telling them to is how privacy writing gets ignored. On Samsung the setting to look for is Viewing Information Services, and on LG it is the Viewing Information agreement, under privacy or user agreements. Menu paths move between firmware versions, so any list of them rots. Hunt for the words "viewing information" and switch off everything adjacent to them.

It is not one switch. The researchers' own opt-out configuration lists roughly a dozen separate settings on the LG set and six on the Samsung, spread across advertising, personalisation, voice and recommendation menus. A choice split across twelve menus is technically offered and practically declined, which is exactly the defect the Texas settlements are meant to address by forcing a plain on-screen disclosure.

Be clear about what this buys you. It is a vendor-controlled setting, honoured for as long as the vendor honours it, and resettable by a firmware update or a fresh consent prompt. The 2024 audit is the best evidence anyone has that it does something, and that evidence is a two-year-old traffic pattern on firmware that has since been replaced. Use it. Do not mistake it for the first option.

Why this one is fixable

Set this page beside the one about your car and the contrast is the whole argument. There, a federal statute requires a camera pointed at the driver and places no condition on what it may keep. There is no setting, no menu, and no consumer fix, because the hardware arrives under a mandate.

Here, everything is the other way round. Nothing requires a television to fingerprint the screen. It does it because it is profitable, which means it stops being done the moment it stops being profitable or stops being allowed. Three things have already been shown to work on it:

  • Measurement, when someone funds it. The value of the IMC audit is not that it settled anything. It is that it made a specific, falsifiable claim that anyone with a network hub can re-run, and it was honest about stopping at the encryption. That work needs doing again, on current firmware, by people who can read the payloads. There is far more policy writing that assumes such audits exist than there is money paying for them.
  • An enforcement action, when someone brings one. Texas did not ask the manufacturers to behave better. It sued five of them, and the two settlements require informed consent and an on-screen disclosure, which is the specific defect that made the setting useless in practice.
  • Leverage, when someone has it. Netflix got the fingerprinting switched off during its own content by treating viewership measurement as an asset worth protecting. That is precisely what it is when it is yours, too. The difference was standing, not technology.

The gap is that the first and third of those are not available to an individual, and the second exists in one state at a time. The organisations that work this specific issue are the Electronic Frontier Foundation, the Electronic Privacy Information Center, and Consumer Reports advocacy, which has run its own smart TV testing for years.

In the meantime, the thing you control is the network cable and the wifi password. A television that was never given them is not relying on anyone's promise, is not affected by the next firmware update, and does not need a researcher to verify it. Everything else on this page is a reason to want that, or a second-best for when it is not possible.