To main content

Losing Control to Data-Hungry Apps – A Mixed-Methods Approach to Mobile App Privacy

Abstract

Personal data from mobile apps are increasingly impacting users’ lives and privacy perceptions. However, there is a scarcity of research addressing the combination of (1) individual perceptions of mobile app privacy, (2) actual personal dataflows in apps, and (3) how such perceptions and dataflows relate to actual privacy policies and terms of use in mobile apps. To address this limitation, we conducted an innovative mixed methods study including a representative user survey in Norway, an analysis of personal dataflows in apps, and content analysis of privacy policies of 21 popular, free Android mobile apps. Our findings show that more than half the respondents in the user survey repeatedly had refrained from downloading or using apps to avoid sharing personal data. Our analysis of dataflows applied a novel methodology measuring activity in the apps over time (48 hours). The investigation showed that 19 of 21 apps investigated transmitted personal data to a total of approximately 600 different primary and third-party domains. From a European perspective, it is particularly noteworthy that most of these domains were associated with tech companies in the United States, where privacy laws are less strict than companies operating from Europe. The investigation further revealed that some apps by default track and share user data continuously, even when the app is not in use. For some of these, the terms of use provided with the apps did not inform the users about the actual tracking practice. A comparison of terms of use as provided in the studied apps with actual person dataflows as identified in the analysis disclosed that three of the apps shared data in violation with their provided terms of use. A possible solution for the mobile app industry, to strengthen user trust, is privacy by design through opt-in data sharing with the service and third parties, and more granular information on personal data sharing practices. Also, based on the findings from this study, we suggest specific visualizations to enhance transparency of personal dataflows in mobile apps. A methodological contribution is that a mixed methods approach strengthens our understanding of the complexity of privacy issues in mobile apps.
Read publication

Category

Academic article

Client

  • Research Council of Norway (RCN) / 262848

Language

English

Author(s)

Affiliation

  • SINTEF Digital / Sustainable Communication Technologies
  • Diverse norske bedrifter og organisasjoner

Year

2018

Published in

Social science computer review

ISSN

0894-4393

Volume

37

Issue

4

Page(s)

466 - 488

View this publication at Cristin