Android app developers may be unwittingly sharing their users’ location data with advertisers
The Electronic Frontier Foundation has warned Android app developers that third-party software components embedded in their apps may be quietly sharing users' precise location data with advertisers and data brokers, often without the developer's knowledge. This happens because software development kits (SDKs) used for advertising and monetisation automatically inherit whatever permissions the host app has been granted, meaning that once a user allows an app to access their location, that data can also flow to third parties unless the developer specifically disables it. The findings matter because location histories collected this way can end up being sold on to militaries, governments and intelligence agencies, and are also vulnerable to breaches affecting data brokers.
The EFF identified Android apps engaging in this practice, including two with a combined 60 million downloads, by analysing network traffic to see which services received users' location data. A senior EFF technologist said the SDKs examined represent only a small slice of the wider advertising ecosystem but still claim to reach billions of users across tens of thousands of apps. The report concludes there is no separate consent mechanism for SDKs, so app-level location permissions alone cannot represent meaningful user consent, and it is urging advertising SDK providers to stop making data-sharing the default setting.
- EFF finds many Android apps leak location data via ad SDKs by default
- Two apps alone had 60 million combined downloads
- Developers often unaware; EFF urges disabling sharing by default
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Researchers and privacy advocates argue this reporting performs a valuable public service by exposing how software development kits (SDKs) embedded in apps can quietly harvest and forward precise location data to advertising networks, often without developers themselves grasping the full implications of the code they've integrated. From this perspective, transparency is essential: developers deserve clear disclosure about what third-party libraries actually do, and users deserve to know when their movements are being tracked and monetised, since informed consent is meaningless if even the app-maker doesn't understand the data flows they've enabled.
The case against
Others, including some in the advertising and app-development industry, would contend that the framing risks overstating culpability and alarm, since SDK providers typically do disclose data practices in technical documentation and terms of service, and the complexity of modern software supply chains means some diffusion of responsibility is an inevitable feature of an ecosystem that offers developers free or low-cost tools in exchange for data access. They might add that location-based advertising funds free apps millions rely on, and that the solution lies in clearer platform-level permissions and industry standards rather than implying widespread negligence or bad faith on the part of developers who are themselves navigating an opaque and fast-changing landscape.