Mobile Apps Fail to Provide Basic Privacy Information According to GPEN's Mobile Apps Sweep Results
Time 1 Minute Read

On September 10, 2014, the Global Privacy Enforcement Network (“GPEN”) published the results of an enforcement sweep carried out in May of this year to assess mobile app compliance with data protection laws. Twenty-six data protection authorities worldwide evaluated 1,211 mobile apps and found that a large majority of the apps are accessing personal data without providing adequate information to users.

The results indicate that:

  • 85% of the mobile apps surveyed failed to provide clear information on how the apps collect, process and disclose user data;
  • In 59% of the cases, it was difficult to find information about privacy prior to installing the app;
  • 31% of the mobile apps appeared to request excessive access to personal data (e.g., geolocation data); and
  • 43% of the privacy notices were not tailored to the size of mobile device screens (e.g., the text is too small to read).

In light of these results, the data protection authorities that participated in the sweep are likely to launch enforcement actions in their jurisdictions. For instance, the Belgian data protection authority announced that it would contact certain stakeholders and, where severe breaches are identified, send cease and desist letters or notify other relevant enforcement authorities.

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 3 Minute Read

On February 17, 2026, the Federal Aviation Administration (FAA) issued a final rule adopting a new airworthiness directive (AD) for certain Bombardier Inc. airplanes. This new AD requires locking features to be installed on applicable network interfaces to prevent unauthorized network access. FAA seeks 45-day public comment on any written data, views, or arguments associated with this final rule, ending on April 3, 2026.

Time 2 Minute Read

On November 17, 2025, the Council of the European Union adopted new rules designed to strengthen cooperation among national data protection authorities, enhancing the enforcement of the EU General Data Protection Regulation.

Time 1 Minute Read

On October 14, 2025, the European Data Protection Board announced that its fifth coordinated enforcement action will focus on compliance with the transparency and information requirements under the GDPR.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page