PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy Policies
Anhao Xiang, Weiping Pei, Chuan Yue
Abstract
The European General Data Protection Regulation (GDPR) mandates a data controller (e.g., an app developer) to provide all information specified in Articles (Arts.) 13 and 14 to data subjects (e.g., app users) regarding how their data are being processed and what are their rights. While some studies have started to detect the fulfillment of GDPR requirements in a privacy policy, their exploration only focused on a subset of mandatory GDPR requirements. In this paper, our goal is to explore the state of GDPR-completeness violations in mobile apps' privacy policies. To achieve our goal, we design the PolicyChecker framework by taking a rule and semantic role based approach. PolicyChecker automatically detects completeness violations in privacy policies based not only on all mandatory GDPR requirements but also on all if-applicable GDPR requirements that will become mandatory under specific conditions. Using PolicyChecker, we conduct the first large-scale GDPR-completeness violation study on 205,973 privacy policies of Android apps in the UK Google Play store. PolicyChecker identified 163,068 (79.2%) privacy policies containing data collection statements; therefore, such policies are regulated by GDPR requirements. However, the majority (99.3%) of them failed to achieve the GDPR-completeness with at least one unsatisfied requirement; 98.1% of them had at least one unsatisfied mandatory requirement, while 73.0% of them had at least one unsatisfied if-applicable requirement logic chain. We conjecture that controllers' lack of understanding of some GDPR requirements and their poor practices in composing a privacy policy can be the potential major causes behind the GDPR-completeness violations. We further discuss recommendations for app developers to improve the completeness of their apps' privacy policies to provide a more transparent personal data processing environment to users.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 26d0dcd2-8d54-404c-bbb0-9da805238255Cited by top-tier papers7
- Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKsYifan Zhang, Zhaojie Hu, Xueqiang Wang, Yuhui Hong et al.USENIX Security 2024 · 3 citations
- Harmful Terms and Where to Find Them: Measuring and Modeling Unfavorable Financial Terms and Conditions in Shopping Websites at ScaleElisa Tsai, Neal Mangaokar, Boyuan Zheng, Haizhong Zheng et al.WWW 2025 · 3 citations
- Helping Johnny Make Sense of Privacy Policies with LLMsVincent Freiberger, Arthur Fleig, Erik BuchmannCHI 2026 · 3 citations
- CASPR: Context-Aware Security Policy RecommendationLifang Xiao, Hanyu Wang, Aimin Yu, Lixin Zhao et al.NDSS 2025
- A Big Step Forward? A User-Centric Examination of iOS App Privacy Report and EnhancementsLiu Wang, Dong Wang, Shidong Pan, Zheng Jiang et al.S&P 2025
Related papers
- Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile AppsShidong Pan, Dawen Zhang, Mark Staples, Zhenchang Xing et al.USENIX Security 2024 · 18 citations
- Freely Given Consent?: Studying Consent Notice of Third-Party Tracking and Its Violations of GDPR in Android AppsTrung Tin Nguyen, Michael Backes, Ben StockCCS 2022 · 32 citations
- Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android AppsTrung Tin Nguyen, Michael Backes, Ninja Marnau, Ben StockUSENIX Security 2021 · 70 citations
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 20 citations
- Are We Getting Well-informed? An In-depth Study of Runtime Privacy Notice Practice in Mobile AppsShuai Li, Zhemin Yang, Yuhong Nan, Shutian Yu et al.CCS 2024 · 1 citation
