The death of privacy policies: How app stores shape GDPR compliance of apps

被引:0
|
作者
Kraemer, Julia [1 ]
机构
[1] Erasmus Univ, Rotterdam, Netherlands
来源
INTERNET POLICY REVIEW | 2024年 / 13卷 / 02期
关键词
GDPR; App Store; Privacy labels; Transparency; Mobile apps;
D O I
10.14763/2024.2.1757
中图分类号
G2 [信息与知识传播];
学科分类号
05 ; 0503 ;
摘要
The General Data Protection Regulation (GDPR) obliges data controllers to inform users about data processing practices. Long criticised for inefficiency, privacy policies face a substantive shift with the recent introduction of privacy labels by the Apple App Store and the Google Play Store. This paper illustrates how privacy disclosures of apps are governed by both the GDPR and the contractual obligations of app stores and is complemented by empirical insights into the privacy disclosures of 845,375 apps from the Apple App Store and 1,657,353 apps from the Google Play Store. While the GDPR allows for the use of privacy labels as a complementary tool next to privacy policies, the design of the privacy labels does not satisfy the standards set in Art. 5(1)(a) GDPR and Art. 12-14 GDPR. The app stores may consequently distort the compliance of apps with data protection laws. The empirical data highlight further problems with the privacy labels. The design of the labels favours disclosures of developers that offer a variety of apps that can process data across different services and contradictory disclosures do not get flagged nor verified by app stores. The paper contributes to the overall discussion of how app stores in their role as intermediaries govern privacy standards and the impact of private sector -led initiatives.
引用
收藏
页数:38
相关论文
共 16 条
  • [1] On GDPR Compliance of Companies' Privacy Policies
    Mueller, Nicolas M.
    Kowatsch, Daniel
    Debus, Pascal
    Mirdita, Donika
    Boettinger, Konstantin
    TEXT, SPEECH, AND DIALOGUE (TSD 2019), 2019, 11697 : 151 - 159
  • [2] PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy Policies
    Xiang, Anhao
    Pei, Weiping
    Yue, Chuan
    PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 3373 - 3387
  • [3] A BERT-based Empirical Study of Privacy Policies' Compliance with GDPR
    Zhang, Lu
    Moukafih, Nabil
    Alamri, Hamad
    Epiphaniou, Gregory
    Maple, Carsten
    2023 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS, 2023,
  • [4] Why this app? How parents choose good educational apps from app stores
    Montazami, Armaghan
    Pearson, Heather Ann
    Dube, Adam Kenneth
    Kacmaz, Gulsah
    Wen, Run
    Alam, Sabrina Shajeen
    BRITISH JOURNAL OF EDUCATIONAL TECHNOLOGY, 2022, 53 (06) : 1766 - 1792
  • [5] How to Make Privacy Policies both GDPR-Compliant and Usable
    Renaud, Karen
    Shepherd, Lynsay A.
    2018 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2018,
  • [6] How Dangerous Permissions are Described in Android Apps' Privacy Policies?
    Baalous, Rawan
    Poet, Ronald
    11TH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS (SIN 2018), 2018,
  • [7] Examining the Integrity of Apple’s Privacy Labels: GDPR Compliance and Unnecessary Data Collection in iOS Apps
    Surma, Zaid Ahmad
    Gowdar, Saiesha
    Pandit, Harshvardhan J.
    Information (Switzerland), 2024, 15 (09)
  • [8] Comparing Privacy Label Disclosures of Apps Published in both the App Store and Google Play Stores
    Rodriguez, David
    Jain, Akshath
    del Alamo, Jose M.
    Sadeh, Norman
    2023 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS, EUROS&PW, 2023, : 150 - 157
  • [9] Is Your Policy Compliant? A Deep Learning-based Empirical Study of Privacy Policies' Compliance with GDPR
    Al Rahat, Tamjid
    Long, Minjun
    Tian, Yuan
    PROCEEDINGS OF THE 21ST WORKSHOP ON PRIVACY IN THE ELECTRONIC SOCIETY, WPES 2022, 2022, : 89 - 102
  • [10] Analyzing GDPR compliance in Cloud Services' privacy policies using Textual Fuzzy Interpretive Structural Modeling (TFISM)
    Razavisousan, Ronak
    Joshi, Karuna P.
    2021 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (SCC 2021), 2021, : 89 - 98