Location Data Sharing: A Hidden Threat to Android App Users
When you grant an app permission to access your device’s precise location, it’s often for a good reason. Your favorite weather app needs to know your location to provide an accurate forecast, or your fitness app needs it to track your running route. However, some apps are inadvertently sharing their users’ location data with third parties, including advertisers and data brokers, due to a lack of awareness about the data-sharing settings.
The Electronic Frontier Foundation (EFF) has conducted an investigation to warn app developers about the potential risks associated with third-party code snippets, known as software development kits (SDKs), that are used in their apps. These SDKs often inherit the app’s permissions, including location data, and collect users’ precise location data without their explicit consent.
The EFF’s findings suggest that many app developers may not realize that their users’ location data is being shared with third parties by default. This raises concerns about the trade-off between app monetization and user privacy. While advertising SDKs are promoted as a way for developers to generate revenue, the data collected from users’ location histories is often sold to data brokers, who then monetize this information.
The data collected can be a security and privacy risk if it falls into the wrong hands. Data brokers have experienced hacks and data breaches in the past, which could compromise users’ sensitive information. The EFF urges app developers to disable unnecessary data collection whenever possible and to be more transparent about the data-sharing practices in their apps.
The EFF’s report highlights that there are no SDK-specific location permissions, meaning that once a user allows their location data to be shared with an app, it is also shared with advertisers. This raises questions about the meaning of user consent in the context of location data collection. The EFF argues that app-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.
The entities offering these SDKs are often commercially incentivized to collect more data from users. This can lead to a situation where users’ location data is shared with third parties without their explicit consent. The EFF’s report emphasizes that advertising SDKs should not make sharing personal data the default, especially for sensitive information like location data.
The EFF’s investigation identified two Android apps that had been downloaded a combined 60 million times, which were quietly sharing users’ location data with third parties. The EFF ran its tests by analyzing the apps’ network traffic and seeing which services were receiving the users’ location data.
Bill Budington, a senior staff technologist at the EFF, explained that the SDKs they examined account for a small percentage of the broader advertising ecosystem but claim to reach billions of users across tens of thousands of apps. This gives a sense of the scale of location data collection associated with these SDKs.
The EFF’s report emphasizes the importance of transparency and user consent in the context of location data collection. App developers must be aware of the potential risks associated with third-party code snippets and take steps to protect their users’ sensitive information.
By disabling unnecessary data collection and being more transparent about data-sharing practices, app developers can help ensure that their users’ location data is not inadvertently shared with third parties.