Mobile app analysis report
Summary
- 28Active vendors
- 23Vendors without consent
- 16Not declared in the CMP
Skanopy runs an app on a real phone and records what it sends, to whom, and when it happens.

Skanopy runs an Android app on a real phone and records what leaves it: which data, to which third-party actors, before or after the user’s choice.
| Without Skanopy | With Skanopy |
|---|---|
| The questionnaireWhat the teams believe they integrated. | The SDKs actually present, including the ones nobody declared. |
| The SDK listWhat ships in the app, not what runs. | Which ones actually run, when, and what they send. |
| The consent bannerThe vendor list it declares, with no way to check it. | The ones it leaves out, firing anyway. |
| The code scanWhat the publisher wrote, not what the third-party kits do. | What a kit does once running, and what its server asks it for next. |
Privacy policy, declarations, SDK list: none of it tells you what the app does at runtime. An automated analysis on a real phone shows it.
Every server contacted, the country it answers from, and the organisation hosting it.
Each actor classified and described against a precise reference: advertising, analytics, social networks and many more.
The user refuses tracking at launch. Here is what stops, and what carries on.
Email address, phone number, device fingerprint: spotted in the exchanges, with the third party receiving them.
The measurement covers that journey, not just the app opening.
Refuse cookies, sign in, open an article, submit the contact form.
Every criterion recorded as the user actually meets it.
The actors the app really fires, against the list the banner announces.
You give a link, you get a report. Within 48 hours.
Two ways in:
On real phones, a real journey replayed automatically:
Every third-party actor that fires is mapped.
Every fact, named:
We installed 20 of the top-ranked news apps and refused tracking. Within about two minutes of use, 95 third-party actors fired despite that refusal.
Read the full study0third-party actors fired
Number of third-party actors per category, tracking refused.
Every third-party actor that fires puts the publisher on the hook, even unknowingly. Skanopy makes that activity visible and verifiable.
| Grounds | ||||
|---|---|---|---|---|
| €530M | Transfers of European users’ data to China. | Irish DPC | 2025 | |
The Irish DPC found that European users’ data was accessible from China without protection equivalent to EU law. During the proceedings, TikTok acknowledged that data had in fact been stored on Chinese servers, contrary to its earlier statements. | ||||
| €150M | Refusing cookies made harder than accepting them. | CNIL | 2022 | |
On google.fr and youtube.com, a single button accepted cookies while refusing them took several clicks. The CNIL held that this asymmetry discouraged refusal, and paired the fine with an injunction carrying a daily penalty. | ||||
| €60M | Advertising trackers set without collecting consent. | CNIL | 2022 | |
Issued the same day as the Google decision, on the same ground: refusing cookies took more effort than accepting them. The CNIL acts here under rules derived from the ePrivacy directive, which lets it proceed without the GDPR one-stop-shop. | ||||
| €40M | Targeted advertising with no proof of consent, upheld by France’s highest court. | CNIL | 2023 | |
Criteo tracks users for advertising retargeting but could not demonstrate that consent had actually been collected by its publisher partners. The CNIL also found failures in transparency and in handling data-subject rights. | ||||
| €35M | Advertising cookies dropped before any consent. | CNIL | 2020 | |
Advertising cookies were dropped on arrival at amazon.fr, before any action by the visitor, and the notice shown did not mention their advertising purpose. | ||||
| €8M | Ad identifier read on the device without consent, on the App Store. | CNIL | 2023 | |
On iOS 14.6, the identifiers used to personalise App Store advertising were read without prior consent, at the same time as Apple required that consent from third-party apps. | ||||
| €6.5M | Data shared with advertising partners without valid consent. | Norway | 2021 | |
The Norwegian authority sanctioned data sharing with advertising partners: merely being a Grindr user reveals a sexual orientation, sensitive data requiring explicit consent. The amount initially considered was reduced after the company’s submissions were examined. | ||||
| €3M | Device identifier read for advertising despite tracking refusal. | CNIL | 2022 | |
The mobile games publisher read a technical identifier for advertising purposes although the user had refused tracking in the iOS settings. A refusal expressed at the system level was therefore not enough to stop it. | ||||
The GDPR provides for fines of up to €20M, or 4% of worldwide annual turnover.

At Didomi, the European leader in consent management, I designed the compliance monitoring that watches the web: trackers, cookies, evidence. I guided dozens of large European publishers, across media, news and e‑commerce, to compliance.
On mobile, it is the same problem, more opaque, and nobody is really addressing it.
I built Skanopy to bring to apps what proved itself on the web.
What we measure in the field, what regulators have decided, and what research has already measured.
The Data safety section of a Play Store listing is filled in by the publisher, and Google does not check it against what the app actually does.