31 Apps and SDKs flagged for privacy violations

Critical compliance update: 31 apps/SDKs flagged for privacy violations. Ensure your SDKs aren't next.
30-Second TL;DR
What Changed
31 apps and SDKs identified for privacy violations including illegal data collection.
Why It Matters
Developers must audit their SDK integration and data collection practices to avoid regulatory penalties and app store removal. This highlights the increasing scrutiny on third-party SDKs in mobile ecosystems.
What To Do Next
Audit your app's third-party SDKs to ensure they comply with local privacy regulations regarding data collection and permission transparency.
Key Points
- •31 apps and SDKs identified for privacy violations including illegal data collection.
- •Common issues include forced/excessive permission requests and deceptive window redirects.
- •Regulatory action based on the Personal Information Protection Law and Cybersecurity Law.
Deep Insight
Background and context from public sources — not the original article. 23 sources cited.
Enhanced Key Takeaways
- •The regulatory actions are part of an intensified, multi-year national campaign by Chinese authorities to enforce data privacy, with a shift towards routine, standardized enforcement rather than campaign-style inspections.
- •Violations frequently involve collecting sensitive personal information such as biometrics, location, contacts, SMS records, and call logs without explicit user consent or before it is functionally necessary for the app's core services.
- •Foreign companies operating in China are held directly accountable for privacy violations, including those committed by third-party SDKs embedded in their applications, necessitating comprehensive SDK audits.
- •Penalties for non-compliance are substantial, including fines up to RMB 50 million (approximately USD 7.7 million) or 5% of the previous year's annual revenue, business suspensions, confiscation of unlawful income, and potential criminal liability for responsible personnel.
- •Recent draft regulations from the Cyberspace Administration of China (CAC) in early 2026 aim to further strengthen existing laws by mandating clearer disclosures, minimal data collection, and easier user control over permissions and account cancellation.
Technical Deep Dive
- Illegal Data Collection: This often manifests as apps collecting data beyond what is strictly necessary for their declared functions, or gathering sensitive information (e.g., facial features, fingerprints, voiceprints, location, contacts, SMS, call logs, app lists) without specific justification, explicit consent, or prior to the user actively engaging a relevant function.
- Excessive Permission Requests: Apps are flagged for requesting system permissions (e.g., camera, microphone, location, storage) when not actively needed, or for denying users core service functionality if they refuse non-essential data sharing. Developers are expected to request permissions only when actively required and use system frameworks to avoid direct access where possible.
- Deceptive UI Patterns (Dark Patterns): These design elements mislead users into unintended actions. Common examples include:
- Complex and confusing language: Using excessively long or convoluted privacy policies and pop-up notices that are difficult for users to understand.
- Interface interference: Designing interfaces where the 'accept all' option is more prominent or easier to select than privacy-protective alternatives, pre-selecting less secure default settings, or using 'confirm-shaming' to influence user choices.
- Forced action: Requiring users to disclose more personal information than necessary to perform an action, such as closing an account.
- Nagging: Persistently prompting users to agree to requests they have previously declined.
- Deceptive window redirects: Implementing disordered jumps when clicking information windows, leading users to unintended advertising pages or data collection points.
- Detection and Enforcement: Regulatory bodies like MIIT and CAC conduct detection campaigns, which involve third-party inspections, retesting of non-compliant applications, and detailed reviews of privacy policies and actual data collection practices. App operators are also required to provide accessible complaint channels and respond to user requests within specified timeframes.
- SDK Responsibilities: SDK providers are mandated to publish their own privacy rules, limit data collection to declared scopes, offer configuration options, and establish direct channels for user rights requests. App operators bear the primary responsibility for auditing the behavior of embedded SDKs and ensuring their compliance.
Future ImplicationsAI analysis grounded in cited sources
Timeline
- 2017-06-01China's Cybersecurity Law (CSL) came into effect, establishing initial rules for network security and data localization.
- 2019-12-19MIIT announced a campaign against illegal data collection practices, identifying 41 problematic apps, including those from Xiaomi and Tencent.
- 2021-05-01A new regulation came into effect, prohibiting apps from forcing users to accept excessive data collection unrelated to core app functions.
- 2021-11-01China's Personal Information Protection Law (PIPL) became effective, providing a comprehensive national-level framework for personal information protection.
- 2025-03-28CAC, MIIT, Ministry of Public Security, and State Administration for Market Regulation jointly announced special measures to strengthen PIPL enforcement in 2025, focusing on apps, SDKs, and smart terminals.
- 2026-01-10The Cyberspace Administration of China (CAC) published a draft regulation, 'Regulations on the Collection and Use of Personal Information by Internet Applications,' for public comment, further strengthening data collection and usage rules.
Sources (23)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
Weekly AI Recap
Read this week's curated digest of top AI events →
AI-curated news aggregator. All content rights belong to original publishers.
Original source: IT之家 ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
The weekly digest
One email a week. Unsubscribe anytime.
