Lalaine: Measuring and Characterizing Non-Compliance of Apple Privacy Labels at Scale
Yue Xiao, Zhengyi Li, Yue Qin, Xiaolong Bai, Jiale Guan, Xiaojing, Liao, Luyi Xing

TL;DR
This study introduces Lalaine, a new methodology to systematically evaluate the accuracy and compliance of Apple privacy labels against actual app data practices, revealing significant non-compliance issues.
Contribution
Lalaine is the first systematic approach to measure privacy-label accuracy at scale, analyzing over 5,000 iOS apps to uncover privacy-label non-compliance and root causes.
Findings
High prevalence of privacy-label non-compliance
Identified root causes for inaccurate privacy labels
Insights for improving privacy-label design and enforcement
Abstract
As a key supplement to privacy policies that are known to be lengthy and difficult to read, Apple has launched the app privacy labels, which purportedly help users more easily understand an app's privacy practices. However, false and misleading privacy labels can dupe privacy-conscious consumers into downloading data-intensive apps, ultimately eroding the credibility and integrity of the labels. Although Apple releases requirements and guidelines for app developers to create privacy labels, little is known about whether and to what extent the privacy labels in the wild are correct and compliant, reflecting the actual data practices of iOS apps. This paper presents the first systematic study, based on our new methodology named Lalaine, to evaluate data-flow to privacy-label (flow-to-label) consistency. Lalaine analyzed the privacy labels and binaries of 5,102 iOS apps, shedding light on…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy, Security, and Data Protection · Green IT and Sustainability · Sexuality, Behavior, and Technology
