Wednesday, 5 August 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 5 August 2026 at 04:53

Android app developers may be unknowingly sharing users' location data with advertisers

The Electronic Frontier Foundation warns that many Android apps share users' precise location data with third parties, including advertisers and data brokers, by default, often without developers' knowledge.

Foto: TechCrunch

For many apps, requesting access to a device's precise location is perfectly reasonable—a weather app needs it for forecasts, a fitness app for route tracking. However, new research from the Electronic Frontier Foundation (EFF) reveals that some apps are inadvertently passing this data on to third parties, such as advertisers and data brokers. The issue lies in third-party code components, known as software development kits (SDKs), which can inherit an app's permissions and collect the user's exact location unless the developer explicitly disables this feature.

The EFF emphasizes that many developers may not realize that this data sharing is enabled by default. The organization urges app makers to turn off unnecessary data collection wherever possible. While advertising SDKs are promoted as a way for developers to monetize their apps, the trade-off is that users' location histories end up with data brokers, who then sell that information to militaries, governments, and intelligence agencies like the FBI. There is also a security and privacy risk if the data is hacked or stolen, which has happened to some data brokers.

The EFF identified several Android apps quietly sharing location data, including two that have been downloaded a combined 60 million times. The foundation analyzed the apps' network traffic to see which services received the location data. Bill Budington, a senior staff technologist at the EFF, told TechCrunch that the SDKs examined represent a small percentage of the broader advertising ecosystem, yet they claim to reach billions of users across tens of thousands of apps, giving a sense of the scale of this type of location data collection.

The EFF's report notes that there are no SDK-specific location permissions, meaning once a user allows an app to access their location, that data is also shared with advertisers. The entities offering these SDKs are generally commercially incentivized to encourage more data collection. The EFF argues that app-level permission alone cannot constitute meaningful consent for location sharing by third-party advertising SDKs, and that these SDKs should not make sharing personal data, especially sensitive location data, the default option.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category