Skip to content
News · Electronic Frontier Foundation EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds

Developers Must Beware of Ad Libraries that Betray Users’ PrivacySAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ location data into systems that location data brokers use to track people, an Electronic Frontier Foundation (EFF) report found. EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location

How it connects

CJEU: Processing of beneficiary data not based on consent; individuals must be informed Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their… Nov 9, 2010 Consent Personal Data Right to Restriction
451423 French Supreme Court reviews CNIL €35M cookie consent fine against Amazon The French DPA had received a complaint on 28 May 2018 regarding the lawfulness of processing by Amazon Europe Core ('Provider' or 'The company'). The French DPA had forwarded… Supreme Administrative Court Jun 27, 2022 Consent Cookies Supervision
CJEU: Website operator embedding social plugin must obtain prior consent as controller Consent: It is the duty of the operator to obtain prior consent from the data subject. The consent given to the operator relates only to the operation or set of operations… Jul 29, 2019 Consent Personal Data Processing
449209 CE asks CJEU if GDPR one-stop-shop applies to ePrivacy cookie consent cases On 7 December 2020, the French DPA (CNIL) imposed two fines totaling € 100 million on Google LLC and Google Ireland Ltd for violating Article 82 of the French Data Protection Act… Jan 28, 2022 Consent Supervision Supervisory Authorities

Full text

Developers Must Beware of Ad Libraries that Betray Users’ PrivacySAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ location data into systems that location data brokers use to track people, an Electronic Frontier Foundation (EFF) report found. EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers. The probe revealed how such SDKs can facilitate and encourage location data sharing – without users’ knowledge or meaningful consent – through privacy-invasive defaults, financial incentives, and unclear documentation. “Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information,” EFF Staff Technologist Lena Co