Privacy International claims most Android apps share data with Facebook without user consent

The social media giant’s third-party tracking via the Facebook SDK may constitute a GDPR breach

Graphic of individuals being glared at by cameras and having their privacy invaded

Privacy International has found that more than half of Android apps, including big names like Skyscanner and Tripadvisor, automatically transfer data to Facebook when opened without user consent.

In a 51-page report titled 'How Apps on Android Share Data with Facebook', Privacy International revealed 61% of the 34 apps tested transfer data such as "app installed" or "SDK initialised" when the app is opened. The app also sends data about the nature of the device the user owns, and the user's location based on language and time zone settings.

According to researchers, this data is gathered by Facebook regardless of consent, or whether users even have a Facebook account.

The data reveals how often people use these apps, according to Privacy International's analysis, and is often sent with a unique identifier such as Google Advertising ID (AAID), or Apple's IDFA. Together, the data could be used by advertisers to link data about user behaviour and paint a comprehensive profile.

Advertisement
Advertisement - Article continues below

"If combined, data from different apps can paint a fine-grained and intimate picture of people's activities, interests, behaviours and routines, some of which can reveal special category data, including information about people's health or religion," the report warned.

"For example, an individual who has installed the following apps that we have tested, "Qibla Connect" (a Muslim prayer app), "Period Tracker Clue" (a period tracker), "Indeed" (a job search app), "My Talking Tom" (a children's' app), could be potentially profiled as likely female, likely Muslim, likely job seeker, likely parent."

The report also found that some apps routinely send Facebook data that is highly detailed and occasionally sensitive, including data on users who do not have Facebook accounts.

Privacy International highlighted how travel app KAYAK, for example, would send information about flight searches including departure dates, departure city, destination, number of tickets, number of children and class of ticket.

"Facebook places the sole responsibility on app developers to ensure that they have the lawful right to collect, use and share people's data before providing Facebook with any data," the report continued.

"However, the default implementation of the Facebook SDK is designed to automatically transmit event data to Facebook."

The digital rights group suggested this constitutes a breach of the EU's General Data Protection Regulation (GDPR) given the Facebook SDK automatically shares data before apps are able to ask users to agree or consent.

In light of developers filing 'bug reports' last year, Facebook released a voluntary feature that should allow developers to delay collecting automatically logged events, such as "SDK initialised", until after they acquire user consent. This feature was only launched 35 days after GDPR took effect on 25 May, however, and only works with SDK version 4.34 and later.

"Prior to our introduction of the "delay" option, developers had the ability to disable transmission of automatic event logging data, except for a signal that the SDK had been initialised," Facebook said in response to the report.

"Following the June change to our SDK, we also removed the signal that the SDK was initialised for developers that disabled automatic event logging.

Advertisement
Advertisement - Article continues below

"In June we also introduced another option for businesses that want to use our auto-event logging feature in compliance with our Business Tools Terms.

"Today, an app developer can either choose to use a pre-installed mechanism for obtaining an end user's prior informed consent (as they could in the past), or use the SDK delay feature."

Privacy International's report insisted that despite these options for developers, automatic data transmission was still detected for the majority of apps tested.

A number of possible factors could explain this, including the fact that data sharing is the default option, and that many apps run older versions of the Facebook SDK. Skyscanner, for instance, was running version 4.33.0 of the SDK when tested in early December, while Spotify was running version 4.310.

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Recommended

Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/mobile/mobile-phones/354273/pablo-escobars-brother-launches-budget-foldable-phone
Mobile Phones

Pablo Escobar's brother launches budget foldable phone

4 Dec 2019
Visit/network-internet/wifi-hotspots/354283/industrial-wi-fi-6-trial-reveals-blistering-speeds
wifi & hotspots

Industrial Wi-Fi 6 trial reveals blistering speeds

5 Dec 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019