Android app developers may be unwittingly sharing their users’ location data with advertisers

Concerns Over Location Data Sharing in Mobile Apps

In the digital landscape, the necessity for apps to access precise location data is often justified. For instance, a weather application requires your location to provide accurate forecasts, while a fitness app tracks your running route based on where you are. However, a growing concern has emerged regarding the inadvertent sharing of this sensitive information with third parties, including advertisers and data brokers.

Recent findings from the Electronic Frontier Foundation (EFF) highlight a critical issue for app developers: the third-party code integrated into their applications may be collecting users’ location data without their explicit consent. This often occurs because developers may not be aware that the default settings for these code snippets, known as software development kits (SDKs), allow for such data collection.

The EFF emphasizes that unless developers actively disable this feature, the SDKs will inherit the app’s permissions, leading to the collection of users’ precise location data. This unintentional sharing raises significant privacy concerns, as many developers may not realize they are transmitting their users’ location information to external entities.

While SDKs designed for advertising purposes can provide a revenue stream for developers, the trade-off is substantial. Users’ location histories can end up in the hands of data brokers, who monetize this information and sell it to various organizations, including military and intelligence agencies like the FBI. Furthermore, the potential for security breaches looms large, as the data collected by these brokers can be vulnerable to hacking or theft.

The EFF’s investigation revealed that certain Android apps, which have collectively been downloaded over 60 million times, were found to be quietly sharing users’ location data. By analyzing network traffic, the EFF was able to identify which services were receiving this sensitive information.

Bill Budington, a senior staff technologist at the EFF, noted that while the SDKs examined represent a small fraction of the advertising ecosystem, they still claim to reach billions of users across tens of thousands of applications. This statistic underscores the extensive reach of location data collection practices.

According to the EFF’s report, there are currently “no SDK-specific location permissions.” This means that once users consent to share their location data with an app, it is also automatically shared with advertisers. The companies providing these SDKs are typically motivated to encourage data collection, further complicating the landscape of user privacy.

The EFF asserts that “app-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.” They advocate for a shift in industry standards, urging that advertising SDKs should not default to sharing personal data, especially when it pertains to sensitive information such as a user’s location.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

AppWizard
Android app developers may be unwittingly sharing their users' location data with advertisers