Pixalate Flags 60+ Ad SDKs for Undisclosed Geolocation Data Harvesting
Event summary
- Pixalate launched the Ad SDK Trust Index 1.0, auditing 698 ad SDKs and data brokers for iOS and Android.
- 60+ SDKs were flagged for transmitting precise geolocation data without disclosure, impacting up to 89,224 apps.
- 22 SDKs pose FTC Section 5 violation risk, while 57 SDKs risk App Store ToS violations.
- Pixalate's analysis found discrepancies between SDK code behavior and public privacy disclosures.
- The Index is updated quarterly, with analyzed code snippets and privacy manifests published for inspection.
The big picture
Pixalate's Ad SDK Trust Index 1.0 highlights a systemic governance gap in the mobile ad ecosystem, where SDKs often operate with undisclosed data collection practices. This shift from self-attestation to objective, code-level verification is critical as regulators like the FTC increasingly hold app developers accountable for the data practices of the SDKs they integrate. The Index's findings underscore the growing need for transparency in ad tech, particularly as privacy regulations tighten globally.
What we're watching
- Regulatory Enforcement
- Whether the FTC will escalate enforcement actions against app developers using non-compliant SDKs.
- App Store Policies
- The pace at which Apple and Google will enforce stricter compliance checks on SDK integrations.
- Industry Adoption
- How widely app developers will adopt Pixalate's Ad SDK Trust Index for due diligence.
