Honesty is the Best Policy: On the Accuracy of Apple Privacy Labels Compared to Apps' Privacy Policies

06/29/2023
by   Mir Masood Ali, et al.
0

Apple introduced privacy labels in Dec. 2020 as a way for developers to report the privacy behaviors of their apps. While Apple does not validate labels, they do also require developers to provide a privacy policy, which offers an important comparison point. In this paper, we applied the NLP framework of Polisis to extract features of the privacy policy for 515,920 apps on the iOS App Store comparing the output to the privacy labels. We identify discrepancies between the policies and the labels, particularly as it relates to data collected that is linked to users. We find that 287±196K apps' privacy policies may indicate data collection that is linked to users than what is reported in the privacy labels. More alarming, a large number of (97±30%) of the apps that have Data Not Collected privacy label have a privacy policy that indicates otherwise. We provide insights into potential sources for discrepancies, including the use of templates and confusion around Apple's definitions and requirements. These results suggest that there is still significant work to be done to help developers more accurately labeling their apps. Incorporating a Polisis-like system as a first-order check can help improve the current state and better inform developers when there are possible misapplication of privacy labels.

READ FULL TEXT

page 11

page 30

research
06/06/2022

Longitudinal Analysis of Privacy Labels in the Apple App Store

In December of 2020, Apple started to require app developers to annotate...
research
01/24/2023

Knowns and Unknowns: An Experience Report on Discovering Tacit Knowledge of Maritime Surveyors

Context: Requirements elicitation is an essential activity to ensure tha...
research
11/15/2021

Tracking in apps' privacy policies

Data protection law, including the General Data Protection Regulation (G...
research
06/12/2020

Building trust in digital policing: A scoping review of community policing apps

Perceptions of police trustworthiness are linked to citizens' willingnes...
research
04/09/2022

Peekaboo: A Hub-Based Approach to Enable Transparency in Data Processing within Smart Homes (Extended Technical Report)

We present Peekaboo, a new privacy-sensitive architecture for smart home...
research
06/13/2022

Lalaine: Measuring and Characterizing Non-Compliance of Apple Privacy Labels at Scale

As a key supplement to privacy policies that are known to be lengthy and...
research
02/13/2020

Quality Assessment of Online Automated Privacy Policy Generators: An Empirical Study

Online Automated Privacy Policy Generators (APPGs) are tools used by app...

Please sign up or login with your details

Forgot password? Click here to reset