USENIX Security2024Top-tier venue
Unpacking Privacy Labels: A Measurement and Developer Perspective on Google's Data Safety Section
Rishabh Khandelwal, Asmit Nayak, Paul Chung, Kassem Fawaz
Abstract
Google has mandated developers to use Data Safety Sections (DSS) to increase transparency in data collection and sharing practices. In this paper, we present a comprehensive analysis of Google's Data Safety Section (DSS) using both quantitative and qualitative methods. We conduct the first large-scale measurement study of DSS using apps from Android Play store (n=1.1M). We find that there are internal inconsistencies within the reported practices. We also find trends of both over and under-reporting practices in the DSSs. Next, we conduct a longitudinal study of DSS to explore how the reported practices evolve over time, and find that the developers are still adjusting their practices. To contextualize these findings, we conduct a developer study, uncovering the process that app developers undergo when working with DSS. We highlight the challenges faced and strategies employed by developers for DSS submission, and the factors contributing to changes in the DSS. Our research contributes valuable insights into the complexities of implementing and maintaining privacy labels, underlining the need for better resources, tools, and guidelines to aid developers. This understanding is crucial as the accuracy and reliability of privacy labels directly impact their effectiveness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6a8ed03f-1b83-40ff-864f-dfbf8a39b94dCited by top-tier papers4
- Abandon All Hope Ye Who Enter Here: A Dynamic, Longitudinal Investigation of Android's Data Safety SectionIoannis Arkalakis, Michalis Diamantaris, Serafeim Moustakas, Sotiris Ioannidis et al.USENIX Security 2024 · 13 citations
- Tinker, Tailor, Trust: How Developers Create Privacy Policies With and Without AIShiva Mayahi, Noura Alomar, Nathan MalkinCHI 2026 · 1 citation
- I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-appsYifeng Cai, Ziqi Zhang, Mengyu Yao, Junlin Liu et al.USENIX Security 2025
- Health Hazard, Handle with Care: Investigating the Privacy Risks of Android's Health ConnectKonstantinos Spyridakis, Ioannis Arkalakis, Michalis Diamantaris, Sotiris Ioannidis et al.USENIX Security 2026
Builds on3
- Ask the Experts: What Should Be on an IoT Privacy and Security Label?Pardis Emami Naeini, Yuvraj Agarwal, Lorrie Faith Cranor, Hanan HibshiS&P 2020 · 195 citations
- Which Privacy and Security Attributes Most Impact Consumers' Risk Perception and Willingness to Purchase IoT Devices?Pardis Emami Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, Lorrie Faith CranorS&P 2021 · 80 citations
- Understanding Challenges for Developers to Create Accurate Privacy Nutrition LabelsTianshi Li, Kayla Reiman, Yuvraj Agarwal, Lorrie Faith Cranor et al.CHI 2022 · 56 citations
Related papers
- Matcha: An IDE Plugin for Creating Accurate Privacy Nutrition LabelsTianshi Li, Lorrie Faith Cranor, Yuvraj Agarwal, Jason I. HongUbiComp 2024 · 17 citations
- Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile AppsShidong Pan, Dawen Zhang, Mark Staples, Zhenchang Xing et al.USENIX Security 2024 · 18 citations
- PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy PoliciesAnhao Xiang, Weiping Pei, Chuan YueCCS 2023 · 24 citations
- Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & PrivacyDuc Cuong Nguyen, Erik Derr, Michael Backes, Sven BugielS&P 2019 · 66 citations
- Understanding Worldwide Private Information Collection on AndroidYun Shen, Pierre-Antoine Vervier, Gianluca StringhiniNDSS 2021
