首页> 外文会议>IEEE International Symposium on Software Reliability Engineering >An Empirical Evaluation of GDPR Compliance Violations in Android mHealth Apps
【24h】

An Empirical Evaluation of GDPR Compliance Violations in Android mHealth Apps

机译:Android mHealth应用中违反GDPR的实证评估

获取原文

摘要

The purpose of the General Data Protection Regulation (GDPR) is to provide improved privacy protection. If an app controls personal data from users, it needs to be compliant with GDPR. However, GDPR lists general rules rather than exact step-by-step guidelines about how to develop an app that fulfills the requirements. Therefore, there may exist GDPR compliance violations in existing apps, which would pose severe privacy threats to app users. In this paper, we take mobile health applications (mHealth apps) as a peephole to examine the status quo of GDPR compliance in Android apps. We first propose an automated system, named HPDROID, to bridge the semantic gap between the general rules of GDPR and the app implementations by identifying the data practices declared in the app privacy policy and the data relevant behaviors in the app code. Then, based on HPDROID, we detect three kinds of GDPR compliance violations, including the incompleteness of privacy policy, the inconsistency of data collections, and the insecurity of data transmission. We perform an empirical evaluation of 796 mHealth apps. The results reveal that 189 (23.7%) of them do not provide complete privacy policies. Moreover, 59 apps collect sensitive data through different measures, but 46 (77.9%) of them contain at least one inconsistent collection behavior. Even worse, among the 59 apps, only 8 apps try to ensure the transmission security of collected data. However, all of them contain at least one encryption or SSL misuse. Our work exposes severe privacy issues to raise awareness of privacy protection for app users and developers.
机译:通用数据保护条例(GDPR)的目的是提供改进的隐私保护。如果应用控制用户的个人数据,则该应用必须符合GDPR。但是,GDPR列出了有关如何开发满足要求的应用程序的一般规则,而不是确切的分步指南。因此,现有应用程序中可能存在违反GDPR的情况,这将给应用程序用户带来严重的隐私威胁。在本文中,我们将移动健康应用程序(mHealth应用程序)作为一个窥视孔,以检查Android应用程序中GDPR合规性的现状。我们首先提出一个名为HPDROID的自动化系统,以通过识别应用程序隐私策略中声明的数据实践和应用程序代码中与数据相关的行为来弥合GDPR通用规则与应用程序实现之间的语义鸿沟。然后,基于HPDROID,我们检测到三种违反GDPR合规性的行为,包括隐私政策的不完整,数据收集的不一致性以及数据传输的不安全性。我们对796个mHealth应用进行了实证评估。结果显示,其中189个(23.7%)没有提供完整的隐私政策。此外,有59个应用通过不同的方式收集敏感数据,但其中46个(77.9%)包含至少一种不一致的收集行为。更糟糕的是,在59个应用程序中,只有8个应用程序试图确保所收集数据的传输安全性。但是,它们全部包含至少一种加密或SSL滥用。我们的工作暴露了严重的隐私问题,以提高应用程序用户和开发人员的隐私保护意识。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号