Many popular Android apps are collecting highly precise location data and transmitting it to advertisers, data brokers, and even government agencies, all because of a default setting left enabled in some third-party software development kits (SDKs). The Electronic Frontier Foundation (EFF) has analyzed several apps downloaded millions of times and discovered that location data collected without meaningful user consent ends up in an opaque market where anyone can purchase it, including intelligence services and law enforcement.
When a developer integrates an SDK for monetization, they often enable all data collection options without realizing it. These SDKs, designed to maximize advertising profits, collect by default the device's precise location, which can be accurate to within 10 feet (about 3 meters) in some circumstances. This level of detail is far more invasive than approximate location based on IP address, which covers about 1.2 square miles. Authorities have used this data for targeted surveillance and tracking of US citizens, raising serious privacy concerns.
Sponsored Protocol
User consent does not cover sharing with SDKs
Many apps request location permission for legitimate functions, such as weather or fitness, but this consent is automatically extended to third-party SDKs. The EFF emphasizes that "app-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs." In two cases analyzed, the apps were downloaded over 50 million and 10 million times, but they showed no notice or requested consent for sharing location data, also violating Google Play Store's Data Safety section guidelines.
A data market fueling surveillance and military operations
Precise location is extremely valuable to advertisers as it increases bid prices for ad space, but it also creates a perverse incentive for massive data collection. Data sold by advertisers and data brokers has been purchased by intelligence agencies and law enforcement for highly targeted operations. Some SDKs even include documentation for developers on how to enable data protection for users subject to GDPR and COPPA, but these settings are not enabled by default. This means even developers who want to comply with the law may not know their SDKs are violating privacy.
Sponsored Protocol
EFF recommendations for developers, regulators, and legislators
The EFF has made clear recommendations for various stakeholders. Developers have a responsibility to protect user privacy by checking third-party SDKs to ensure they do not share data by default. Regulators should pursue both developers who fail to ensure proper data handling and companies that deliberately develop SDKs designed to collect invasive amounts of data by default. Additionally, US legislators should adopt a federal law similar to GDPR that bans behavioral advertising, thereby removing the incentive to collect data excessively.
Sponsored Protocol
For more on privacy and data transparency, you can read about how Xbox Helix is working to make games more accessible, or catch up on the latest news about Meta and AI images. Additionally, the story of Jeff Dean leaving Google shows how the tech industry is evolving.