Lessons in VCR Repair: Compliance of Android App Developers with the California Consumer Privacy Act (CCPA)

04/03/2023
by   Nikita Samarin, et al.
0

The California Consumer Privacy Act (CCPA) provides California residents with a range of enhanced privacy protections and rights. Our research investigated the extent to which Android app developers comply with the provisions of the CCPA that require them to provide consumers with accurate privacy notices and respond to "verifiable consumer requests" (VCRs) by disclosing personal information that they have collected, used, or shared about consumers for a business or commercial purpose. We compared the actual network traffic of 109 apps that we believe must comply with the CCPA to the data that apps state they collect in their privacy policies and the data contained in responses to "right to know" requests that we submitted to the app's developers. Of the 69 app developers who substantively replied to our requests, all but one provided specific pieces of personal data (as opposed to only categorical information). However, a significant percentage of apps collected information that was not disclosed, including identifiers (55 apps, 80 30 improvements to the CCPA that could help app developers comply with "right to know" requests and other related regulations.

READ FULL TEXT
research
06/06/2022

Longitudinal Analysis of Privacy Labels in the Apple App Store

In December of 2020, Apple started to require app developers to annotate...
research
01/29/2023

Demystifying Privacy Policy of Third-Party Libraries in Mobile Apps

The privacy of personal information has received significant attention i...
research
04/17/2020

Privacy-Preserving Script Sharing in GUI-based Programming-by-Demonstration Systems

An important concern in end user development (EUD) is accidentally embed...
research
06/10/2023

HIPAAChecker: The Comprehensive Solution for HIPAA Compliance in Android mHealth Apps

The proliferation of mobile health technology, or mHealth apps, has nece...
research
10/20/2018

Empirically Assessing Opportunities for Prefetching and Caching in Mobile Apps

Network latency in mobile software has a large impact on user experience...
research
02/14/2022

Intent-Aware Permission Architecture: A Model for Rethinking Informed Consent for Android Apps

As data privacy continues to be a crucial human-right concern as recogni...
research
02/21/2022

Recommendations to Develop, Distribute and Market Sonification Apps

After decades of research, sonification is still rarely adopted in consu...

Please sign up or login with your details

Forgot password? Click here to reset