Urgent.News

What's breaking now, across thousands of outlets.

Tech

Android App Advertising SDK Location Data Sharing Explained

Android app teams can inherit location-sharing behavior from advertising SDKs even when consent screens and Play disclosures do not reflect it. The post Android App Advertising SDK Location Data Sharing Explained appeared first on TechRepublic .

Google's Android system allows advertising software development kits (SDKs) to collect or share a device's location without explicit user consent. Four popular SDKs—BidMachine, InMobi, HyBid, and Huawei’s Petal Ads—can transmit a device's precise location by default, even when the host app has granted location permission, according to a recent Electronic Frontier Foundation (EFF) investigation.

This practice leaves app developers responsible for data flows they may not have knowingly enabled, as Android treats an app and its embedded code as a single permission holder.

During the investigation, the EFF tested two apps: QR Scanner, which boasts over 50 million downloads, and GPS Speedometer, with more than 10 million users. Both apps sent precise coordinates to BidMachine, a location-sharing SDK, without displaying any notice or disclosing third-party location sharing in their Data safety sections. For the other three SDKs, the findings were based on documentation reviews, with HyBid's case involving an open-source code analysis.

When location data is included in real-time bidding requests, the precise coordinates can be broadcast to thousands of potential advertisers and collected by data brokers participating in the auctions. This inherited-permission issue extends beyond advertising, as a recent Android SDK vulnerability exposed host-app privileges, and research into SDKs used in apps marketed to US military personnel found discrepancies between privacy disclosures and actual data practices.

Google's Android SDK safety guidance places responsibility on developers for any data collection performed by the SDKs they use, including those they may not be utilizing. Third-party location sharing must be clearly disclosed in the Data safety form and comply with prominent disclosure and consent requirements. In a 2024 case against InMarket, the Federal Trade Commission accused the company of not ensuring that apps using its location SDK had obtained informed consent before using location data for targeted advertising.

Developers should conduct thorough checks before each release, as Google Play's expanded app screening does not substitute for these checks. Ongoing traffic capture and disclosure reviews should be part of release controls rather than one-time integration tasks.

Written by urgent.news from TechRepublic's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techrepublic.com →

More in Tech

More from Thursday 6 August →