The death of privacy policies: How app stores shape GDPR compliance of apps

Research output: Contribution to journalArticleAcademicpeer-review

28 Downloads (Pure)


The General Data Protection Regulation (GDPR) obliges data controllers to inform users about data processing practices. Long criticised for inefficiency, privacy policies face a substantive shift with the recent introduction of privacy labels by the Apple App Store and the Google Play Store. This paper illustrates how privacy disclosures of apps are governed by both the GDPR and the contractual obligations of app stores and is complemented by empirical insights into the privacy disclosures of 845,375 apps from the Apple App Store and 1,657,353 apps from the Google Play Store. While the GDPR allows for the use of privacy labels as a complementary tool next to privacy policies, the design of the privacy labels does not satisfy the standards set in Art. 5(1)(a) GDPR and Art. 12-14 GDPR. The app stores may consequently distort the compliance of apps with data protection laws. The empirical data highlight further problems with the privacy labels. The design of the labels favours disclosures of developers that offer a variety of apps that can process data across different services and contradictory disclosures do not get flagged nor verified by app stores. The paper contributes to the overall discussion of how app stores in their role as intermediaries govern privacy standards and the impact of private sector-led initiatives.
Original languageEnglish
Number of pages38
JournalInternet Policy Review
Issue number2
Publication statusPublished - 2 Apr 2024

Bibliographical note

Publisher Copyright:
© 2024, Alexander von Humboldt Institute for Internet and Society. All rights reserved.

Erasmus Sectorplan

  • Sectorplan Recht-Public and Private Interests
  • Sectorplan Recht-Empirical Legal Studies
  • Sectorplan SSH-Breed


Dive into the research topics of 'The death of privacy policies: How app stores shape GDPR compliance of apps'. Together they form a unique fingerprint.

Cite this