The duty to inform: the 2026 European action, and what a mobile app struggles to declare
Informing people is the GDPR obligation most readily assumed to be settled: the privacy policy exists, it is online, case closed. The European coordinated action launched on 19 March 2026 reopens it for a year. Here is what the authorities are checking, what the CNIL expects from an app precisely, and why the accuracy of that information cannot be drafted into existence.
What the 2026 coordinated action puts on the table
Every year the European Data Protection Board picks a theme and has the national authorities examine it at the same time. For 2026 it is transparency and information obligations, Articles 12, 13 and 14 of the GDPR. The action was launched on 19 March, and twenty-five European data protection authorities are taking part, the CNIL among them.
The method is stated plainly: participating authorities will contact controllers from different sectors across Europe, either through a questionnaire or through investigations. In the second half of the year the national findings are pooled, then consolidated into a report adopted at European level.
The previous edition covered the right to erasure, and its French results give the measure of the exercise. Published on 18 February 2026, they record on-site inspections at six organisations of various sizes and sectors, and two formal notices already issued off the back of them. A coordinated action is not an awareness campaign.
The three items that jam inside an app
Article 13 lists what has to be told to the person at the moment their data is collected. Three items are particularly resistant to the mobile format.
First, the third parties that receive the data: “the recipients or categories of recipients of the personal data, if any”. In an app these are, first, the third-party software components the publisher embeds, the SDKs, and behind them the actors that use what those components send back. Then transfers, which the article requires to be announced “where applicable”, which presumes knowing where the data lands once it leaves: that is the whole subject of transfers outside the European Union. Finally retention, “the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period”: the period the publisher applies says nothing about the one applied by the partner that received the data.
What the three have in common is that they do not describe a design intent, they describe what actually leaves the phone. The CNIL says as much in the opening of its recommendation, noting that the processing carried out inside apps can be, or appear, opaque, and that information about the existence of data collection and its purposes is often unclear.
What the CNIL expects, in detail
Its mobile app recommendation covers the subject in the part addressed to the publisher, in a passage on informing users correctly under Articles 12 to 14 of the GDPR. The information has to include the mandatory items under Article 13 or 14, and whether each processing operation is required or optional, along with how a refusal affects the use of the app. The authority further recommends adding the list of data access permissions requested, whether each is required or optional, and the purposes pursued through them, which meets permission minimization halfway.
On monetization it leaves no way out: transmitting users’ personal data to commercial partners, for instance to monetize the app, must be explicitly brought to people’s attention.
On where, two distinct requirements. The publisher must make sure the privacy policy is easily accessible before any processing takes place, directly from within the app, and the CNIL recommends making it available before the app is even downloaded, on the publisher’s site or on the app’s store listing. That is the same ground as the Play Store Data safety section, with a different substantive requirement.
On form, finally, it distances itself from the single document: using one privacy policy is not the only way to meet the information obligation, and in the mobile context it often fails to meet the goals of simplicity and concision. The recommendation is to contextualize the information at the moment of each collection. The rest of the grid sits in the CNIL mobile app recommendation.
The gap between text and behaviour has been measured
This is not a theoretical worry. A study presented at the 29th USENIX Security Symposium in 2020 compared the text of privacy policies against the observed behaviour of 13,796 Android apps: up to 42.4% of them either incorrectly disclose or omit disclosing their privacy-sensitive data flows. The authors show the gap widens precisely on the identity of whoever receives the data: without separating the publisher from the third party, up to 38.4% of apps would be wrongly classified as consistent with their own policy.
The cause is structural more than culpable. A publisher embeds a third-party component and inherits its behaviour, which the contract describes in general terms. The CNIL does put part of the burden on the provider, which must make sure the publisher is properly informed when the provider processes data on its own account, including through the contractual terms. But a contractual commitment is a promise, not a measurement. That is the subject of the SDK blind spot and of what the CNIL expects from SDK providers.
Answering the questionnaire presumes having observed
An authority’s questionnaire asks for facts: which third parties receive what, at what moment, towards which countries, for how long. A DPO cannot attest to a list they have not seen, and contracts state what was agreed with each provider, not what the app sends once installed.
The only way to establish those facts is to run the app on a real phone and record what comes out of it: the third-party actors actually contacted, the data sent, and the moment of each transmission relative to the user’s choice. That is the point of a mobile app GDPR audit, and the raw material of a map of what the app emits.
A privacy policy written from that record holds up in front of an inspector. Looking for the facts after writing the text risks discovering the gap at the same time as the authority does. Preparing therefore means taking the facts first, and the CNIL audit of a mobile app page sets out what inspections look at.
Sources
Every finding in this article traces back to one of these documents.
- EDPB ’26CEF 2026: EDPB launches coordinated enforcement action on transparency and information obligations under the GDPREuropean Data Protection Board, 19 March 2026
- CNIL ’26CEF 2026: the EDPB launches a coordinated action on transparency and information obligationsCNIL, 19 March 2026
- CNIL ’26Right to erasure: results of the CNIL inspections under the European coordinated actionCNIL, 18 February 2026
- GDPRRegulation (EU) 2016/679, Articles 12 to 14: information to the data subjectOfficial Journal of the European Union
- CNIL ’25Mobile app recommendation, amended versionCNIL, deliberation no. 2025-024 of 27 March 2025
- USENIX ’20Actions Speak Louder than Words: Entity-Sensitive Privacy Policy and Data Flow Analysis with PoliCheckAndow et al., 29th USENIX Security Symposium, 2020
Common questions
- What is the 2026 European coordinated action?
- An examination carried out at the same time by several European authorities on a single theme. The European Data Protection Board launched it on 19 March 2026 on the transparency and information obligations of Articles 12, 13 and 14 of the GDPR. Twenty-five authorities are taking part, through questionnaires or investigations, and pool their findings in the second half of 2026.
- What information must a mobile app give its users?
- The mandatory items of Article 13 or 14 of the GDPR, including the publisher’s identity, the purposes, the legal basis, the third parties that receive the data, transfers outside the European Union and retention periods. The CNIL additionally asks that each processing operation be marked as required or optional, and recommends including the list of permissions requested with their purposes.
- Where must a mobile app’s privacy policy be?
- It must be easily accessible directly from within the app, before any processing takes place. The CNIL further recommends making it available before the app is downloaded, on the publisher’s site or on the app’s store listing, with at minimum the publisher’s identity, the purposes of the processing and how to exercise data subject rights.
- How do you check that the privacy policy matches the app’s behaviour?
- By running the app on a phone and recording what comes out of it: the third-party actors contacted, the data sent and the moment of each transmission. That is the only way to establish the real list of third parties receiving data, and then compare it with the one that is declared.