Pixalate’s Analysis of GDPR Risks in the Apple App Store
Pixalate, a global leader in ad fraud protection, privacy, and compliance analytics, has recently published a report that examines potential GDPR violation risks within the Apple App Store. This report provides a thorough assessment of how both the App Store and app developers may be violating GDPR Articles 5, 12, 13, and 24.
Exploring GDPR Violation Risks
The report explains Apple's role as a “Data Controller” within the GDPR framework. According to Article 4(7), Apple seems to be sharing users’ device identifiers with numerous apps that do not have adequate privacy policies in place. Notably, 1,384 apps available on the Apple App Store have been identified as engaging in practices that could lead to unauthorized processing of personal data.
Device Identifiers and Data IP Addresses
In this investigation, Pixalate's data science team analyzed over 32,000 apps available on the Apple App Store in the EU and UK. This analysis uncovered significant issues, revealing that personal data from over 380,000 users was shared during the ad bid stream by targeted apps that failed to disclose their privacy policies.
Key Insights from Pixalate’s Report
The report highlights specific applications on the Apple App Store that lack detected privacy policies while sharing personal data in the ad bid stream. Here are some of the key findings:
- 380,000+ EU and UK users’ personal data was shared in the ad bid stream by apps without privacy policies.
- 1,384 apps hosted on the Apple App Store did not have detected privacy policies during the analysis period.
- 842 (61%) of the targeted apps shared device identifiers in the ad bid stream.
- 330 (24%) of the targeted advertising-enabled apps shared location data, IP addresses, and device identifiers.
Concerns Over Device Identifiers
By transmitting users’ identifiers (IDFAs/IDFVs) to apps that lack clear privacy policies, Apple may not be fulfilling its obligations under Article 5(f) of the GDPR. This article requires data controllers to ensure that personal data is processed with integrity and confidentiality.
Expert Insights from Pixalate
Yusra Kayani, Pixalate’s EMEA Director of Data Protection and Privacy, expressed concern regarding the ongoing presence of apps without detected privacy policies on the Apple App Store. Despite the potential GDPR violations and breaches of developer license agreements, there appears to be a lack of action in identifying and removing these problematic apps.
Notable Apps Sharing Personal Data
The report also identifies the top 10 apps on the Apple App Store that lack privacy policies and are sharing user data:
- LALIGA Fantasy 23-24 - Liga Nacional de Futbol Profesional (Spain) - 79K users affected.
- Paint the Flag - Mobsmile Yazilim Hizmetleri Limited Sirketi (United Kingdom) - 14K users affected.
- My Monster Pet: Train & Fight - traxnet ou (Estonia) - 4K users affected.
- Führerschein ClickClickDrive - ClickClickDrive GmbH (Germany) - 4K users affected.
- Dingbats - Between the lines - Romain Lebouc (France) - 2K users affected.
- Handy Craft - Voodoo (France) - 2K users affected.
- Freecell - move all cards to the top - Brilliant Labs Limited (United Kingdom) - 1K users affected.
- Crush the Monsters: Cannon Game - HEROCRAFT LTD (United Kingdom) - 1K users affected.
- Closer – Actu et exclus People - Reworld Media Magazines (France) - 1K users affected.
- Tipping Point Blast! Coin Game - Two Way Media Ltd (United Kingdom) - 1K users affected.
Conclusion
In summary, the findings from Pixalate’s report underscore serious concerns regarding how user data is managed on the Apple App Store. As data privacy regulations tighten, it is essential for companies like Apple to take decisive action against violations to protect user privacy and ensure compliance with GDPR requirements.
Frequently Asked Questions
What is the focus of Pixalate’s report?
Pixalate’s report aims to identify GDPR violation risks linked to the Apple App Store and the apps it hosts.
How many apps are identified as violating GDPR?
There are 1,384 apps on the Apple App Store that do not have detected privacy policies and may be violating GDPR.
What type of personal data is shared by these apps?
The apps are sharing sensitive personal data, including location data, IP addresses, and device identifiers.
What has been the response from Pixalate’s representatives?
Yusra Kayani has raised concerns about Apple's insufficient action to remove apps that violate privacy policies and regulations.
Why is this report important?
This report provides vital insights into app developers' practices and the implications for user data protection under GDPR.