Android app developers may be inadvertently sharing users' precise location data with third parties, such as advertisers and data brokers, according to new findings from the Electronic Frontier Foundation (EFF). This occurs because certain third-party code, known as software development kits (SDKs), can collect location data by default when integrated into an app.
The EFF states that unless developers actively disable this collection, these SDKs inherit the app's permissions and gather precise location data. Many developers might not realise this data-sharing setting is enabled by default.
The EFF's analysis of app network traffic identified Android apps that were sharing user location data, including two with a combined 60 million downloads. Bill Budington, a senior staff technologist at the EFF, noted that while the examined SDKs represent a small part of the advertising ecosystem, they claim to reach billions of users across tens of thousands of apps.
The report highlights that there are "no SDK-specific location permissions," meaning that if a user grants location access to an app, that data is also shared with advertisers. The EFF has urged app makers to disable unnecessary data collection.