All articles

CNIL mobile app guidance for SDK providers: what changes

In September 2024, France’s data protection authority, the CNIL, published guidance dedicated to mobile apps. It does not address publishers alone: it names the whole chain, and explicitly includes SDK providers.

The whole chain, not just the publisher

The CNIL’s guidance allocates responsibility across the publisher, the developer, SDK providers, app stores and operating systems. Each must be qualified, by contract, as controller, joint controller or processor, based on what it actually does with the data.

The CNIL states that it does not consider itself bound by the labels parties give each other. An SDK provider that decides, on its own account, what it collects cannot hide behind a mere-processor label.

A permission is not consent

The guidance recalls that a technical authorization granted by the system, access to storage, to the advertising identifier or to location, is not consent under the GDPR. Consent must remain freely given, specific, informed and unambiguous.

For an SDK, being granted access does not authorize using it while the user’s choice, expressed in the banner, is not honored.

Inspections have started

The CNIL opened a control campaign on mobile apps from spring 2025, extending its 2023 checks on tracking without consent. GDPR breaches carry fines of up to 20 million euros or 4% of annual worldwide turnover.

The Grindr precedent, sanctioned for data shared with advertising partners through embedded SDKs, shows this kind of processing is already judged and fined in Europe.

The report the CNIL published in February 2026 confirms the follow-through: 143 formal notices issued in 2025, several of them aimed at mobile apps, and 83 sanctions totalling 486.8 million euros across all sectors. For an SDK provider, the question is no longer whether this ground gets inspected, but what an inspection would see of its kit, starting with the advertising identifier it consumes.

What an SDK provider can do

Document, on real apps, what its SDK does once integrated: when it fires relative to the banner, what it sends, what it keeps sending after a refusal. That is the material missing when everything happens on the publisher’s side.

That is the purpose of a check for ad networks and adtech: a factual, dated finding, app by app, to make objective what a contract does not guarantee.

Sources

Every finding in this article traces back to one of these documents.

  1. CNIL ’24Recommendation on mobile applicationsCNIL, 24 September 2024
  2. CNIL ’25Recommendation on mobile applications, amended versionCNIL, deliberation no. 2025-024 of 27 March 2025
  3. CNIL ’25The CNIL’s inspections in 2025: mobile apps, prison administration, local-authority cybersecurityCNIL, annual inspection programme
  4. CNIL ’26Sanctions and corrective measures: the CNIL presents the 2025 reportCNIL, 9 February 2026

Common questions

Is an SDK provider a processor or a controller?
It depends on what it actually does with the data, not on the label written into the contract. The CNIL states that it is not bound by the qualifications parties give each other: a provider that decides its own purposes becomes a controller, or a joint controller with the publisher.
What does an SDK provider risk in case of a breach?
The GDPR provides for fines of up to 20 million euros or 4% of annual worldwide turnover. The joint responsibility the CJEU retained across the ad chain, and the formal notices recorded in the CNIL’s 2025 report, show the exposure is no longer theoretical.

And the app you audit, what does it actually embed?