All articles

The CNIL puts SDK providers in scope: what its guidance changes

In September 2024, France’s data protection authority, the CNIL, published guidance dedicated to mobile apps. It does not address publishers alone: it names the whole chain, and explicitly includes SDK providers.

The whole chain, not just the publisher

The CNIL’s guidance allocates responsibility across the publisher, the developer, SDK providers, app stores and operating systems. Each must be qualified, by contract, as controller, joint controller or processor, based on what it actually does with the data.

The CNIL states that it does not consider itself bound by the labels parties give each other. An SDK provider that decides, on its own account, what it collects cannot hide behind a mere-processor label.

A permission is not consent

The guidance recalls that a technical authorization granted by the system, access to storage, to the advertising identifier or to location, is not consent under the GDPR. Consent must remain freely given, specific, informed and unambiguous.

For an SDK, being granted access does not authorize using it while the user’s choice, expressed in the banner, is not honored.

Inspections have started

The CNIL opened a control campaign on mobile apps from spring 2025, extending its 2023 checks on tracking without consent. GDPR breaches carry fines of up to 20 million euros or 4% of annual worldwide turnover.

The Grindr precedent, sanctioned for data shared with advertising partners through embedded SDKs, shows this kind of processing is already judged and fined in Europe.

What an SDK provider can do

Document, on real apps, what its SDK does once integrated: when it fires relative to the banner, what it sends, what it keeps sending after a refusal. That is the material missing when everything happens on the publisher’s side.

That is the purpose of a check for ad networks and adtech: a factual, dated finding, app by app, to make objective what a contract does not guarantee.