Examining the Integrity of Apple’s Privacy Labels: GDPR Compliance and Unnecessary Data Collection in iOS Apps
-
Published:2024-09-09
Issue:9
Volume:15
Page:551
-
ISSN:2078-2489
-
Container-title:Information
-
language:en
-
Short-container-title:Information
Author:
Surma Zaid Ahmad1, Gowdar Saiesha1, Pandit Harshvardhan J.2ORCID
Affiliation:
1. School of Computing, Dublin City University, D09 V209 Dublin, Ireland 2. ADAPT Centre, Dublin City University, D09 V209 Dublin, Ireland
Abstract
This study investigates the effectiveness of Apple’s privacy labels, introduced in iOS 14, in promoting transparency around app data collection practices with respect to the GDPR. Specifically, we address two key research questions: (1) What special categories of personal data, as regulated by the GDPR, are collected and used by apps, and for which purposes? (2) What disparities exist between app-stated permissions and the apparent unnecessary data gathering across various categories in the iOS App Store? By analyzing a comprehensive dataset of 541,662 iOS apps, we identify common practices related to prevalent use of sensitive and special categories of personal data, revealing widespread instances of unnecessary data collection, misuse, and potential GDPR violations. Furthermore, our analysis uncovers significant inconsistencies between the permissions stated by apps and the actual data they gather, highlighting a critical gap in user privacy protection within the iOS ecosystem. These findings underscore the need for stricter regulatory oversight of app stores and the necessity of effective privacy notices to build accountability and trust and ensure transparency. This study offers actionable insights for regulators, app developers, and users towards creating secure and transparent digital ecosystems.
Reference20 articles.
1. Kelley, P.G., Bresee, J., Cranor, L.F., and Reeder, R.W. (2009, January 15–17). A “Nutrition Label” for Privacy. Proceedings of the 5th Symposium on Usable Privacy and Security (SOUPS ’09), Mountain View, CA, USA. 12p. 2. Xiao, Y., Li, Z., Qin, Y., Guan, J., Bai, X., Liao, X., and Xing, L. (2022). Lalaine: Measuring and Characterizing Non-Compliance of Apple Privacy Labels at Scale. arXiv. 3. Balash, D.G., Ali, M.M., Wu, X., Kanich, C., and Aviv, A.J. (2022). Longitudinal Analysis of Privacy Labels in the Apple App Store. arXiv. 4. Scoccia, G.L., Autili, M., Stilo, G., and Inverardi, P. (2022, January 17–24). An empirical study of privacy labels on the Apple iOS mobile app store. Proceedings of the 9th IEEE/ACM International Conference on Mobile Software Engineering and Systems, Pittsburgh, PA, USA. 5. Kollnig, K., Shuba, A., Van Kleek, M., Binns, R., and Shadbolt, N. (2022, January 21–24). Goodbye tracking? Impact of iOS app tracking transparency and privacy labels. Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency, Seoul, Republic of Korea.
|
|