IEEE Access (Jan 2024)

Sharing is Not Always Caring: Delving Into Personal Data Transfer Compliance in Android Apps

  • David Rodriguez,
  • Jose M. Del Alamo,
  • Celia Fernandez-Aller,
  • Norman Sadeh

DOI
https://doi.org/10.1109/ACCESS.2024.3349425
Journal volume & issue
Vol. 12
pp. 5256 – 5269

Abstract

Read online

In an era marked by ubiquitous reliance on mobile applications for nearly every need, the opacity of apps’ behavior poses significant threats to their users’ privacy. Although major data protection regulations require apps to disclose their data practices transparently, previous studies have pointed out difficulties in doing so. To further delve into this issue, this article describes an automated method to capture data-sharing practices in Android apps and assess their proper disclosure according to the EU General Data Protection Regulation. We applied the method to 9,000 random Android apps, unveiling an uncomfortable reality: over 80% of Android applications that transfer personal data off device potentially fail to meet GDPR transparency requirements. We further investigate the role of third-party libraries, shedding light on the source of this problem and pointing towards measures to address it.

Keywords