Analysis of "Cookies, Identifiers and Other Data That Google Silently Stores on Android Handsets" Study This study, conducted by D.J. Leith from Trinity College Dublin, investigates the data stored on Android devices by pre-installed Google apps, including Google Play Services and the Google Play Store. The findings raise significant privacy concerns related to user consent, data tracking, and compliance with EU privacy regulations (GDPR & e-Privacy Directive). Potential Legal and Privacy Implications Violation of EU e-Privacy Directive - Article 5(3) of the e-Privacy Directive requires explicit user consent before storing or accessing any data on user devices. - No consent is sought for any of the cookies or identifiers stored by Google. - No opt-out mechanism is provided, meaning users have no control over this tracking. Potential GDPR Violations - Google Android ID, DSID, NID, and other identifiers likely count as personal data under GDPR. - Google’s lack of transparency about the use of these identifiers violates GDPR’s principles of lawfulness, fairness, and transparency. - Processing of sensitive data (e.g., sexual orientation via Play Store ad tracking on "gay dating apps") requires explicit consent under GDPR Article 9. - Google automatically logging users into multiple apps without consent could violate GDPR’s purpose limitation principle. What This Means for Users - Even if you factory reset your Android device and don’t use Google apps, tracking still happens. - Google is automatically logging users into multiple services, collecting telemetry data, and storing tracking identifiers without consent. - The study suggests Google may be violating both GDPR and the EU e-Privacy Directive. This study provides strong technical evidence that Google is storing personal data without user consent and in a manner that may violate EU privacy laws. The lack of transparency and opt-out options is particularly concerning. If regulators take action, this could lead to major legal consequences for Google, similar to past GDPR fines. However, for now, Android users remain heavily tracked unless they take active measures to limit Google’s data collection. Notice: Since the study was published, Google has announced fingerprinting is now applied across all devices and services, meaning the potential impact of Googles abuse in data collection is now unparalleled, and it makes Google one of the most data collecting organizations on the planet. Direct link to the study: https://lnkd.in/gXj2fr2c #Privacy #GDPR #DataProtection #ePrivacy #GoogleTracking #AndroidPrivacy #UserConsent #BigTech #CyberSecurity #TechRegulation #SurveillanceEconomy #DigitalRights #TechEthics
Data Privacy in Digital Self-Tracking Tools
Explore top LinkedIn content from expert professionals.
Summary
Data privacy in digital self-tracking tools refers to how personal information collected by apps and devices—such as location, health data, or online behavior—is gathered, stored, and shared, often without users fully understanding or consenting to such practices. This issue is becoming more urgent as many platforms silently track user activities, sometimes exposing sensitive details or even creating safety risks.
- Review permissions: Regularly check the settings on your apps and devices to control what personal data they can access and limit sharing whenever possible.
- Demand transparency: Look for platforms that clearly explain how your data is used and give you simple ways to manage your privacy preferences.
- Think before you share: Avoid providing identifiable information in apps, especially when planning or searching for sensitive topics, and consider safer offline alternatives for critical information.
-
-
Imagine saving a random contact years ago—and now they can track your location just because you ordered dinner on Zomato Zomato’s “Friend Recommendations” feature just gave me a mini existential crisis. I never gave the app access to my contacts, never synced anything, never chose to “follow” anyone—and yet, a bunch of random people from my phonebook were listed as “friends.” I could see their food choices, recommendations, and even my brother’s activity—someone who swears he’s never officially recommended a single dish on the app. I could even see recommendations from my 3rd floor neighbour or someone whose contact I saved 15 years ago but don’t even remember who they are. So perhaps our actions—like ratings or just ordering frequently—are being interpreted as recommendations and shown to others. So basically I can see where all they order from and perhaps where they live? Perhaps. How? Welcome to the eerie world of data triangulation and invisible profiling. Even passive behavior—like ordering food without leaving a review—is being interpreted, tagged, and shared under the veil of “social recommendations.” This isn’t just about food anymore. It’s a reminder of how platforms construct detailed behavioral profiles from seemingly innocuous actions. It’s also a reminder of how transparency, consent, and user agency remain alarmingly vague in our digital ecosystems. Scary? Yes. Surprising? Sadly, not anymore. #DigitalPrivacy #AlgorithmicProfiling #TechEthics #Zomato #SurveillanceEconomy #DataTransparency
-
You used ChatGPT to research shelters. To plan your escape. To figure out custody laws. You thought those conversations were private. They're not. In August 2025, a court forced OpenAI to hand over someone's chat logs in a domestic violence case. Your AI safety planning could become evidence. The National Network to End Domestic Violence raised the alarm: those chat logs are safety plans, abuse disclosures, shelter searches, visa information, financial escape routes. And now they can be subpoenaed. NNEDV warned this could expose victims to retaliation and surveillance—especially when abusers have lawyers and survivors don't. Here's how to protect your digital safety: 1. Avoid sharing identifiable details with AI tools Don't use real names, addresses, or specific locations. Instead of: ❌ "Shelters near 123 Oak Street, Brooklyn" ✅ "Shelters in New York City" Instead of: ❌ "My husband John tracks my phone" ✅ "Partner monitors my device" The less specific you are, the less useful the data is if subpoenaed. 2. Use privacy-preserving tools Privacy browsers (Tor, Brave in private mode) VPN if possible Opt out of "model improvement" in settings Use AI tools that don't store chat history 3. Use analog methods for the most sensitive planning Critical information—shelter addresses, advocate names, emergency contacts—write on paper and keep hidden. AI is useful for general information, but dangerous details should stay offline. 4. Tell your lawyer or advocate about your digital footprint Tell them: What AI tools you've used What you've searched online What devices you've used Whether your partner has account access They need to know to protect you if data gets subpoenaed. 5. Know your rights in your jurisdiction Privacy laws vary. Ask your advocate: "Can my AI chat history be used against me? What protections exist?" What this means for your safety: Digital safety planning is now part of survival strategy. Escaping abuse means protecting your data as carefully as your physical safety. AI can help you research—but use it carefully, knowing privacy isn't guaranteed. If you're planning to leave or already have, reach out to organizations that specialize in tech safety for survivors. They can help you assess your digital risk and build a safer plan. In AI For Real Life, we teach women how to use AI strategically—but we also talk about when NOT to use it, or how to use it more safely when the stakes are high. If you or someone you love is navigating abuse, understanding the digital landscape is part of staying safe. ___ Hi, I'm Amanda — I run AI For Real Life, a community where Multi-Hyphenate Women use AI to make their mental load lighter and their income less random. Follow me for content on AI, money and culture — for women who are tired of chronic exhaustion and jobs that pay peanuts.
-
Regulators are coming after your tracking pixels. In the US, we are currently handling numerous pixel lawsuits and working with clients on compliance with both wiretapping, State laws and HIPAA in connection with pixel deployment. Now, Tobias Judin 🏳️🌈 and Datatilsynet in Norway, are going after these with investigation uncovering that websites often share sensitive information through the pixels unknowingly. 6 points that apply in the US as well: 🔹 Identify which tracking pixels, cookies, and other tracking tools your service uses; especially ones that use the info for their own purpose (this could be a "sale" or completely prohibited in the US if sensitive) 🔹 Browsing data can be sensitive. Consider the types of people who use your service and what inferences can be drawn about them, directly or indirectly, based on their browsing history. 🔹 Trackers on websites that target children as especially difficult because they require parental consent for deployment. In the US this has been enforced under COPPA 🔹 You need to give people a choice about the trackers. In the EU - this is pure consent; in the US this can be an opt out unless the data is sensitive. 🔹 You must provide accurate and understandable information about what the tracking tools do, and how they affect the individual and their privacy, as publicly as possible. This should be just-in-time but also in your privacy disclosures. 🔹 You are responsible for the trackers on your website, even if your particular use of them is innocent. You will generally be the one facing enforcement. https://lnkd.in/ef83G5XR pic by ChatGPT
-
Location-broker data leak & the ballad of privacy So, a company called Gravy Analytics – a location-data broker – was hacked and suffered a major leak. But what does a “location data broker” do? These companies basically trade our data (yeah, yours and mine) received from mobile apps, ad networks, smart devices – even cars. So Gravy collected it, someone stole it, and now it’s out there. There were no names or IDs in the leak; however, it appears that with a little digital wizardry, hackers can de-anonymize real people – uncovering home addresses, workplaces, favorite shopping spots, and more. Only a slice of the stolen data has become public so far (the whole database appears to be massive), but yes – it covers the whole world. What can you do to decrease your geolocation footprint? 1️⃣ Be picky with app permissions. Don’t grant location access unless it’s absolutely necessary. 2️⃣ Tighten up your privacy settings. Limit data-sharing in the apps you use. 3️⃣ Block background location tracking. 4️⃣ Ditch unused apps. Fewer apps – fewer problems. 5️⃣ Kill your ad ID. Disable it on iOS, or delete it on Android. 6️⃣ Use anti-tracking tools. Let’s be real: online privacy isn’t something to be optimistic about. But that doesn’t mean ditching basic digital hygiene is a good idea. More about the story, as well as practical steps to protect your data – here: https://kas.pr/c99m
-
Significant privacy ruling in California could have global implications including for GDPR enforcement in Europe. A jury has found Meta in breach of state privacy laws in a class-action suit brought by users of the Flo period tracking app. The case centred on allegations that Meta collected sensitive menstrual health data, including period dates and fertility goals, without user consent, and used it for ad-targeting. Originally filed in 2021, the lawsuit also named Google, AppsFlyer and Flurry. Google settled in July, Flo earlier this month. Meta continues to dispute the verdict, stating it never accessed or used such data and that its terms prohibit developers from sharing sensitive information. Lawyers for the plaintiffs described the outcome as “a clear message” about Big Tech’s responsibilities on digital health data and that it serves as a reminder that privacy is not a mere a legal formality: but about trust, ethics, and safeguarding users. From a UK and EU perspective, this case resonates strongly with the principles underpinning GDPR, particularly around explicit consent, data minimisation, and the handling of special category data. If similar practices were found to occur within the EU, they could trigger significant regulatory scrutiny and fines under GDPR. As healthtech, adtech and AI continue to converge, this ruling is a reminder for companies to consider how they manage intimate (special category personal) data, and whether current frameworks and frameworks are suitable. #GDPR #PrivacyMatters #DigitalHealth #TechEthics #AdTech #UserTrust #LegalUpdate #HealthTech #DataProtection #BigTech #Regulation https://lnkd.in/g2DNEErg
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development