Android apps may be sharing location data with advertisers by default
Original: Android app developers may be unwittingly sharing their users’ location data with advertisers
Why This Matters
Default SDK data sharing at scale raises serious user privacy risks across millions of Android devices.
The Electronic Frontier Foundation warns that Android app developers may unknowingly share users' precise location data with advertisers via third-party SDKs enabled by default. Two affected apps had been downloaded a combined 60 million times.
The Electronic Frontier Foundation (EFF) has published findings warning Android app developers that third-party advertising SDKs embedded in their apps may collect and share users' precise location data with advertisers and data brokers by default — without the developer's awareness.
When users grant location permissions to an app, those permissions are automatically inherited by any SDKs integrated into the app. Unless the developer actively disables data collection, the SDKs silently transmit location data to third parties. The EFF noted there are 'no SDK-specific location permissions,' meaning user consent given to an app does not equate to informed consent for third-party data sharing.
The EFF identified Android apps — including two with a combined 60 million downloads — quietly sharing location data. Tests were conducted by analyzing app network traffic to determine which external services were receiving location data.
Bill Budington, senior staff technologist at the EFF, told TechCrunch the SDKs examined represent a small fraction of the ad ecosystem but claim to reach billions of users across tens of thousands of apps. Location histories collected via these SDKs are sold to data brokers, who then sell them to militaries, governments, and agencies including the FBI. The data also poses security risks if breached. The EFF urged developers to disable unnecessary data collection and called on SDK providers to stop making personal data sharing the default.