Each layer of that has a specification, in that specification each side has implementations of that specification. To me, I fundamentally don't care what an individual corporation "can or can't do". I care what the spec says, because that's what the corporation can and can't do unless they have something completely 100% proprietary.
Speculation is worthless, show me the spec of what function calls enable the collection of this data, and what the structure of the message looks like over the wire.
Beyond that, on a rooted device that I have full control over, I should be able to work out the details of how that's happening and whether or not I want to fiddle with it to allow my carry around computer to do so or not.
If the implicit assumption that root access to my pocket computer makes it unable to turn off such a thing, then that's news. The rest are layers and layers of complexity as to what the defaults of the systems involved are allowed to do via permissions systems. We're either cool with those defaults, or we aren't.
So, imo. Start with the specs, if it's possible via them then it's surely happening whether or not it's "legal" to do so. My apologies if this comes across as harsh, but what else did we expect? We're fortunate enough to live in the cusp of the information age, but the first 50/100/200 years of this are bound to be messy before it either goes full dystopian forever, or enough outrage affects those defaults.