App Store Privacy Exposed: Uncovering Data Collection Practices and GDPR Compliance
摘要
Mobile phones have become an essential part of our daily lives, serving not only as tools for communication but also as aids in completing tasks related to work, leisure, or transactions with public and private sector organizations. They are also widely used for entertainment, accessing information, supporting health management, and facilitating exercise routines. This functionality is largely enabled by the installation and use of mobile apps. To operate effectively, these apps often require access to personal data stored on the user’s device or data collected through connected devices. In May 2018, the European Union introduced the General Data Protection Regulation (GDPR), aimed at protecting the privacy and personal data of individuals. This research investigates the types of personal data app developers declare they collect and how this data is managed, particularly in relation to GDPR guidelines. The study focuses on the App Store repository, which serves as the primary platform for the iOS ecosystem. Key areas of analysis include the existence of privacy policies, app metadata, and privacy labels, with findings raising significant concerns about how developers handle user data.