🏠Stalecollected in 10m

31 Apps and SDKs flagged for privacy violations

31 Apps and SDKs flagged for privacy violations
PostLinkedIn
🏠Read original on IT之家

💡Critical compliance update: 31 apps/SDKs flagged for privacy violations. Ensure your SDKs aren't next.

⚡ 30-Second TL;DR

What Changed

31 apps and SDKs identified for privacy violations including illegal data collection.

Why It Matters

Developers must audit their SDK integration and data collection practices to avoid regulatory penalties and app store removal. This highlights the increasing scrutiny on third-party SDKs in mobile ecosystems.

What To Do Next

Audit your app's third-party SDKs to ensure they comply with local privacy regulations regarding data collection and permission transparency.

Who should care:Developers & AI Engineers

Key Points

  • 31 apps and SDKs identified for privacy violations including illegal data collection.
  • Common issues include forced/excessive permission requests and deceptive window redirects.
  • Regulatory action based on the Personal Information Protection Law and Cybersecurity Law.

🧠 Deep Insight

Web-grounded analysis with 23 cited sources.

🔑 Enhanced Key Takeaways

  • The regulatory actions are part of an intensified, multi-year national campaign by Chinese authorities to enforce data privacy, with a shift towards routine, standardized enforcement rather than campaign-style inspections.
  • Violations frequently involve collecting sensitive personal information such as biometrics, location, contacts, SMS records, and call logs without explicit user consent or before it is functionally necessary for the app's core services.
  • Foreign companies operating in China are held directly accountable for privacy violations, including those committed by third-party SDKs embedded in their applications, necessitating comprehensive SDK audits.
  • Penalties for non-compliance are substantial, including fines up to RMB 50 million (approximately USD 7.7 million) or 5% of the previous year's annual revenue, business suspensions, confiscation of unlawful income, and potential criminal liability for responsible personnel.
  • Recent draft regulations from the Cyberspace Administration of China (CAC) in early 2026 aim to further strengthen existing laws by mandating clearer disclosures, minimal data collection, and easier user control over permissions and account cancellation.

🛠️ Technical Deep Dive

  • Illegal Data Collection: This often manifests as apps collecting data beyond what is strictly necessary for their declared functions, or gathering sensitive information (e.g., facial features, fingerprints, voiceprints, location, contacts, SMS, call logs, app lists) without specific justification, explicit consent, or prior to the user actively engaging a relevant function.
  • Excessive Permission Requests: Apps are flagged for requesting system permissions (e.g., camera, microphone, location, storage) when not actively needed, or for denying users core service functionality if they refuse non-essential data sharing. Developers are expected to request permissions only when actively required and use system frameworks to avoid direct access where possible.
  • Deceptive UI Patterns (Dark Patterns): These design elements mislead users into unintended actions. Common examples include:
    • Complex and confusing language: Using excessively long or convoluted privacy policies and pop-up notices that are difficult for users to understand.
    • Interface interference: Designing interfaces where the 'accept all' option is more prominent or easier to select than privacy-protective alternatives, pre-selecting less secure default settings, or using 'confirm-shaming' to influence user choices.
    • Forced action: Requiring users to disclose more personal information than necessary to perform an action, such as closing an account.
    • Nagging: Persistently prompting users to agree to requests they have previously declined.
    • Deceptive window redirects: Implementing disordered jumps when clicking information windows, leading users to unintended advertising pages or data collection points.
  • Detection and Enforcement: Regulatory bodies like MIIT and CAC conduct detection campaigns, which involve third-party inspections, retesting of non-compliant applications, and detailed reviews of privacy policies and actual data collection practices. App operators are also required to provide accessible complaint channels and respond to user requests within specified timeframes.
  • SDK Responsibilities: SDK providers are mandated to publish their own privacy rules, limit data collection to declared scopes, offer configuration options, and establish direct channels for user rights requests. App operators bear the primary responsibility for auditing the behavior of embedded SDKs and ensuring their compliance.

🔮 Future ImplicationsAI analysis grounded in cited sources

App developers and SDK providers will face a significantly higher compliance burden in China.
The ongoing crackdowns and new draft regulations indicate a sustained and intensified focus on data privacy, requiring continuous audits, transparent disclosures, and robust consent mechanisms from all entities operating in the Chinese market.
User control over personal data in Chinese applications will substantially increase.
New regulations emphasize data minimization, explicit consent for sensitive data, easy opt-out options for personalized services, and streamlined processes for account cancellation and data deletion, empowering users with greater autonomy.
The regulatory framework in China will become more harmonized and rigorously enforced.
The collaboration between multiple regulatory bodies (CAC, MIIT, MPS) and the shift towards routine, sector-specific enforcement signals a more coordinated and systematic approach to data governance, translating abstract legal standards into clear, enforceable compliance expectations.

Timeline

2017-06-01
China's Cybersecurity Law (CSL) came into effect, establishing initial rules for network security and data localization.
2019-12-19
MIIT announced a campaign against illegal data collection practices, identifying 41 problematic apps, including those from Xiaomi and Tencent.
2021-05-01
A new regulation came into effect, prohibiting apps from forcing users to accept excessive data collection unrelated to core app functions.
2021-11-01
China's Personal Information Protection Law (PIPL) became effective, providing a comprehensive national-level framework for personal information protection.
2025-03-28
CAC, MIIT, Ministry of Public Security, and State Administration for Market Regulation jointly announced special measures to strengthen PIPL enforcement in 2025, focusing on apps, SDKs, and smart terminals.
2026-01-10
The Cyberspace Administration of China (CAC) published a draft regulation, 'Regulations on the Collection and Use of Personal Information by Internet Applications,' for public comment, further strengthening data collection and usage rules.
📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: IT之家