Static Analysis for Android GDPR Compliance Assurance

03/16/2023
by   Mugdha Khedkar, et al.
0

Many Android applications collect data from users. When they do, they must protect this collected data according to the current legal frameworks. Such data protection has become even more important since the European Union rolled out the General Data Protection Regulation (GDPR). App developers have limited tool support to reason about data protection throughout their app development process. Although many Android applications state a privacy policy, privacy policy compliance checks are currently manual, expensive, and prone to error. One of the major challenges in privacy audits is the significant gap between legal privacy statements (in English text) and technical measures that Android apps use to protect their user's privacy. In this thesis, we will explore to what extent we can use static analysis to answer important questions regarding data protection. Our main goal is to design a tool based approach that aids app developers and auditors in ensuring data protection in Android applications, based on automated static program analysis.

READ FULL TEXT

page 1

page 2

page 3

research
08/13/2020

An Empirical Evaluation of GDPR Compliance Violations in Android mHealth Apps

The purpose of the General Data Protection Regulation (GDPR) is to provi...
research
02/23/2022

AirGuard – Protecting Android Users From Stalking Attacks By Apple Find My Devices

Finder networks in general, and Apple's Find My network in particular, c...
research
08/29/2022

NL2GDPR: Automatically Develop GDPR Compliant Android Application Features from Natural Language

The recent privacy leakage incidences and the more strict policy regulat...
research
09/07/2022

Assessing Software Privacy using the Privacy Flow-Graph

We increasingly rely on digital services and the conveniences they provi...
research
12/04/2022

A Fine-grained Chinese Software Privacy Policy Dataset for Sequence Labeling and Regulation Compliant Identification

Privacy protection raises great attention on both legal levels and user ...
research
05/11/2023

PriGen: Towards Automated Translation of Android Applications' Code to Privacy Captions

Mobile applications are required to give privacy notices to the users wh...
research
05/24/2023

Towards Fine-Grained Localization of Privacy Behaviors

Mobile applications are required to give privacy notices to users when t...

Please sign up or login with your details

Forgot password? Click here to reset