Ad SDKs Funnel User Location Data to Brokers by Default, EFF Report Reveals
A new investigation by the **Electronic Frontier Foundation (EFF)** has exposed how widely used advertising Software Development Kits (SDKs) are configured to automatically transmit user location data to data brokers. This occurs without explicit user consent or developer awareness, leveraging privacy-invasive defaults and financial incentives built into the SDKs.
SAN FRANCISCO β A recent report by the **Electronic Frontier Foundation (EFF)** sheds light on a pervasive privacy concern: advertising SDKs are routinely feeding users' location data into systems utilized by location data brokers. This practice often occurs without users' knowledge or meaningful consent, driven by privacy-invasive default settings and financial incentives within the mobile app ecosystem.
The **EFF** initiated its investigation to understand the pipeline from mobile applications to location data brokers. The probe uncovered how certain SDKs facilitate and even encourage the sharing of sensitive location data through poorly documented settings and financial structures.
"Defaults matter, not just for users, but for app developers as well," stated **Lena Cohen**, **EFF** Staff Technologist. "If app developers donβt pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose usersβ location information."
**Cohen** and **EFF** Senior Staff Technologist **Bill Budington** meticulously reviewed the public developer documentation of numerous popular advertising SDKs. Their goal was to identify how these SDKs manage and communicate with developers regarding location data handling.
Their analysis specifically highlighted four advertising SDKs β **InMobi**, **BidMachine**, **Verveβs HyBid**, and **Huaweiβs Petal Ads** β that are configured to collect and share a user's location by default for ad targeting, provided the app has been granted location permissions. The **EFF** emphasized that while these four were singled out, many other SDKs may also exhibit similar problematic behaviors, and developers can still choose to share location data even when it's not the default setting. Previous instances of advertising SDKs collecting location data without valid user consent have already led to criticism and legal action.
**Budington** underscored the severe implications of this data collection: "When developers let advertising SDKs collect location data, theyβre putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for **ICE** investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel."
Developers, according to **Budington**, bear a significant responsibility to safeguard their users from these potential harms, irrespective of the default configurations of advertising SDKs. The **EFF** calls for action from developers, regulators, and legislators to prevent apps from inadvertently leaking user location data to advertising companies and data brokers.