Exercising the CCPA Opt-out Right on Android: Legally Mandated but Practically Challenging
Sebastian Zimmeck, Nishant Aggarwal, Zachary Liu, Sage Altman, Konrad Kollnig

TL;DR
This study reveals that most Android apps do not effectively support the CCPA opt-out right, with current methods like UI options and GPC signals being largely ineffective, highlighting a significant compliance gap.
Contribution
The paper provides empirical evidence of low compliance with CCPA opt-out rights on Android and proposes re-purposing the AdID setting to improve user privacy.
Findings
Only 48% of tested apps have a CCPA opt-out setting.
GPC signals are largely ineffective in exercising the opt-out right.
Disabling AdID access does not significantly improve compliance.
Abstract
Many mobile apps' business model is based on sharing user data with ad networks to deliver personalized ads. The California Consumer Privacy Act (CCPA) gives California residents a right to opt out. In two experiments we evaluate to which extent popular Android apps enable California residents to exercise their right. In our first experiment -- manually exercising the right via app-level UIs -- we find that only 48 out of 100 apps implement a respective setting, which suggests that CCPA opt-out right compliance on the Android platform is generally low. In our second experiment -- automatically exercising the opt-out right by sending Global Privacy Control (GPC) signals -- we find for an app dataset of 1,811 apps that GPC is largely ineffective. While we estimate with 95% confidence that 62%--81% of apps in our app dataset must respect the CCPA opt-out right, many apps do not do so. Our…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy, Security, and Data Protection · Advanced Malware Detection Techniques · Cybercrime and Law Enforcement Studies
