The Electronic Frontier Foundation published findings in August 2026 warning that Android app developers may be inadvertently sharing their users’ precise location data with advertisers and data brokers through third-party code embedded in their apps.
The issue centers on software development kits, or SDKs — code snippets that developers integrate into their apps, often to enable advertising and generate revenue. According to the EFF, these SDKs inherit the location permissions users grant to the app itself, and data collection is enabled by default unless the developer manually switches it off. Many developers may not be aware this is happening.
The EFF identified Android apps quietly sharing location data in this way, including two with a combined 60 million downloads. Researchers analyzed the apps’ network traffic to determine which third-party services were receiving location data. Bill Budington, a senior staff technologist at the EFF, noted that the SDKs examined represent a small slice of the broader advertising ecosystem but collectively claim to reach billions of users across tens of thousands of apps.
The EFF’s report states there are “no SDK-specific location permissions,” meaning user consent given to an app effectively extends to any SDKs embedded within it. The organization urged app makers to disable unnecessary data collection and called on advertising SDK providers to stop making personal data sharing the default setting.
The implications extend beyond advertising. The EFF noted that users’ location histories collected in this way can be sold to data brokers, who may then sell that information to militaries, governments, and intelligence agencies, including the FBI. The data also poses a security risk — some data brokers have previously experienced hacks or data theft.
“App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs,” the EFF wrote.
Source: TechCrunch