A new investigation by the Electronic Frontier Foundation (EFF) has found that many Android app developers may be unknowingly sharing users’ precise location data with advertisers and data brokers through third-party software development kits (SDKs). According to the report, some advertising and analytics SDKs automatically enable location data collection once an app receives location permission from a user, meaning developers may inadvertently expose sensitive user information without realizing the feature is active by default.
The findings raise fresh concerns about the mobile advertising ecosystem, where third-party code embedded inside apps can collect and monetize user data independently of an app developer’s intentions. While users explicitly grant location permission to an app, they may not be aware that the data can also flow to advertising partners or data brokers through integrated SDKs. The EFF is urging developers to audit the third-party components used in their apps and disable unnecessary location-sharing features.
EFF Warns of Hidden Location Data Sharing
The privacy advocacy group found that:
- Some Android SDKs collect precise location data by default.
- Developers may not realize location-sharing is enabled.
- Location data can be transmitted to advertisers and data brokers.
- The behavior occurs after users grant an app permission to access their location.
Rather than developers intentionally selling location information, the issue often stems from default SDK configurations that are insufficiently documented or easy to overlook during app development.
Key Findings
| Item | Details |
|---|---|
| Research Organization | Electronic Frontier Foundation (EFF) |
| Platform | Android |
| Issue | Third-party SDKs may share user location data by default |
| Potential Recipients | Advertisers and data brokers |
| Main Concern | Developers may be unaware the feature is enabled |
How the Data Sharing Happens
Many Android applications rely on third-party SDKs to add features such as:
- Advertising.
- Analytics.
- User engagement.
- Crash reporting.
- App monetization.
According to the EFF, certain SDKs automatically begin collecting and transmitting location information after the app receives permission from the user. Developers integrating these SDKs may assume location access is used only for app functionality, when it can also be used for advertising or profiling purposes unless explicitly disabled.
Why It Matters for Users
Location data is among the most sensitive categories of personal information because it can reveal:
- Home and work locations.
- Daily travel patterns.
- Frequently visited businesses.
- Religious or medical visits.
- Personal routines and habits.
When aggregated over time, even anonymized location data can often be linked back to individuals through movement patterns, increasing privacy risks if shared widely across advertising networks or data brokers.
Potential Privacy Risks
| Risk | Impact |
|---|---|
| Targeted advertising | More detailed user profiling |
| Data brokerage | Location information sold to third parties |
| Privacy exposure | Sensitive movement patterns revealed |
| Developer liability | Unintended sharing through SDK defaults |
Recommendations for App Developers
The EFF recommends that Android developers:
- Audit all third-party SDKs included in their apps.
- Review default privacy settings before deployment.
- Disable unnecessary location collection features.
- Verify how user data is transmitted to external partners.
- Clearly disclose data-sharing practices in privacy policies.
Developers are also encouraged to collect only the minimum location data necessary for an app’s functionality, following the principle of data minimization.
What Android Users Can Do
Although much of the responsibility lies with developers, users can reduce exposure by:
- Reviewing location permissions regularly.
- Granting location access only when necessary.
- Choosing “Only while using the app” instead of continuous access where possible.
- Checking Google Play’s Data Safety section before installing apps.
- Removing location permission from apps that no longer require it.
Growing Scrutiny of Mobile Privacy
The EFF’s findings add to broader concerns over the mobile advertising ecosystem, where regulators and privacy advocates have increasingly questioned how sensitive user data is collected and shared through third-party SDKs. Recent enforcement actions and investigations have focused on companies accused of transmitting personal information—including health and location data—to advertisers without adequate transparency or user consent.
Looking Ahead
The EFF’s research highlights how complex third-party software components can create unintended privacy risks for both developers and users. While many Android developers rely on SDKs to accelerate app development and monetization, default configurations that enable location sharing can expose sensitive user information without the developer’s explicit intent. The findings reinforce the need for stronger privacy-by-default practices, better SDK documentation, and more transparent data-sharing controls across the Android ecosystem.
Looking ahead, the report is likely to increase pressure on SDK providers, app developers, and platform operators to improve transparency around location data collection. As regulators worldwide continue to tighten privacy requirements, developers may face greater scrutiny over the third-party code embedded in their apps, making regular privacy audits and careful SDK management an essential part of mobile application development.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.


