2021/11/15 by Konrad Kollnig, Kollnig, Konrad
Computer Science · Social Sciences · #Advanced Malware Detection Techniques #Computers and Society (cs.CY) #Cryptography and Security (cs.CR) #Digital and Cyber Forensics #FOS: Computer and information sciences #Privacy, Security, and Data Protection
paper · pdf · doi:10.48550/arxiv.2111.07860
openalex publication_date 2021/11/15 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Data protection law, including the General Data Protection Regulation (GDPR), usually requires a privacy policy before data can be collected from individuals. We analysed 15,145 privacy policies from 26,910 mobile apps in May 2019 (about one year after the GDPR came into force), finding that only opening the policy webpages shares data with third-parties for 48.5% of policies, potentially violating the GDPR. We compare this data sharing across countries, payment models (free, in-app-purchases, paid) and platforms (Google Play Store, Apple App Store). We further contacted 52 developers of apps, which did not provide a privacy policy, and asked them about their data practices. Despite being legally required to answer such queries, 12 developers (23%) failed to respond.