Mobile app analysis report
Summary
- Active vendors
- Vendors without consent
- Not declared in the CMP
Active vendor categories
Skanopy runs an app on a real phone and records what it sends, to whom, and when it happens.
Privacy policy, declarations, SDK list: none of it tells you what the app does at runtime. An automated analysis on a real phone shows it.
You give a link, you get a report. Within 48 hours.
Two ways in:
On real phones, a real journey replayed automatically:
Every third-party actor that fires is mapped.
Every fact, named:
We installed 20 of the top-ranked news apps and refused tracking. Within about two minutes of use, 95 third-party actors fired despite that refusal.
Every third-party actor that fires puts the publisher on the hook, even unknowingly. Skanopy makes that activity visible and verifiable.
| Grounds | ||||
|---|---|---|---|---|
| €530M | Transfers of European users’ data to China. | Irish DPC | 2025 | |
The Irish DPC found that European users’ data was accessible from China without protection equivalent to EU law. During the proceedings, TikTok acknowledged that data had in fact been stored on Chinese servers, contrary to its earlier statements. | ||||
| €150M | Refusing cookies made harder than accepting them. | CNIL | 2022 | |
On google.fr and youtube.com, a single button accepted cookies while refusing them took several clicks. The CNIL held that this asymmetry discouraged refusal, and paired the fine with an injunction carrying a daily penalty. | ||||
| €60M | Advertising trackers set without collecting consent. | CNIL | 2022 | |
Issued the same day as the Google decision, on the same ground: refusing cookies took more effort than accepting them. The CNIL acts here under rules derived from the ePrivacy directive, which lets it proceed without the GDPR one-stop-shop. | ||||
| €40M | Targeted advertising with no proof of consent, upheld by France’s highest court. | CNIL | 2023 | |
Criteo tracks users for advertising retargeting but could not demonstrate that consent had actually been collected by its publisher partners. The CNIL also found failures in transparency and in handling data-subject rights. | ||||
| €35M | Advertising cookies dropped before any consent. | CNIL | 2020 | |
Advertising cookies were dropped on arrival at amazon.fr, before any action by the visitor, and the notice shown did not mention their advertising purpose. | ||||
| €8M | Ad identifier read on the device without consent, on the App Store. | CNIL | 2023 | |
On iOS 14.6, the identifiers used to personalise App Store advertising were read without prior consent, at the same time as Apple required that consent from third-party apps. | ||||
| €6.5M | Data shared with advertising partners without valid consent. | Norway | 2021 | |
The Norwegian authority sanctioned data sharing with advertising partners: merely being a Grindr user reveals a sexual orientation, sensitive data requiring explicit consent. The amount initially considered was reduced after the company’s submissions were examined. | ||||
| €3M | Device identifier read for advertising despite tracking refusal. | CNIL | 2022 | |
The mobile games publisher read a technical identifier for advertising purposes although the user had refused tracking in the iOS settings. A refusal expressed at the system level was therefore not enough to stop it. | ||||
The GDPR provides for fines of up to €20M, or 4% of worldwide annual turnover.

At Didomi, the European leader in consent management, I designed the compliance monitoring that watches the web: trackers, cookies, evidence. I guided dozens of large European publishers, across media, news and e‑commerce, to compliance.
On mobile, it is the same problem, more opaque, and nobody is really addressing it.
I built Skanopy to bring to apps what proved itself on the web.
What we measure in the field, what regulators have decided, and what research has already measured.