Mobile app GDPR audit: what to check, and how to prove it
An app declares itself in a privacy policy, but it acts in the traffic it emits. An audit confronts the two: which third parties fire, what data leaves, when relative to consent. Here is the full method, the deliverable, and what it costs.
Where the data goes
Every server contacted, the country it answers from, and the organisation hosting it.
Why audit a mobile app, and why now
The obligation is not new. In France, Article 82 of the Data Protection Act governs any reading or writing of information on a phone, exactly as on the web, and the GDPR requires you to demonstrate compliance, not just assert it. What changed is enforcement: the CNIL, the French data protection authority, published its recommendation on mobile applications in September 2024, updated it in spring 2025, and made apps one of its priority inspection themes for 2025.
The sanctions already exist: a mobile games publisher was fined 3 million euros for reading a device identifier for advertising purposes despite a refusal of tracking expressed at system level. The charge was not a badly written policy; it was what the app actually did.
And that is precisely what nobody sees. The code is compiled, the traffic is encrypted, third-party SDKs, the ready-made software bricks an app embeds, are black boxes: a publisher rarely knows what each kit sends, and many discover their own partners the day someone asks. For want of a tool, the store listing and the privacy policy stand in for proof.
A serious audit reverses the burden: it establishes dated findings, recorded on the app itself, that can be set against the declaration and replayed on every version. That is the material missing from records of processing, privacy policies and answers to a supervisory authority.
What a mobile app audit must verify
Six readings which, side by side, tell whether the declaration holds.
The third parties actually active
Every SDK and third party that fires during use, with the domain contacted and its category: advertising, audience measurement, attribution, social networks. Including the ones firing in the background.
The personal data that leaves
The identifiers and data transmitted off the device, who they go to, and whether they circulate across several third parties at once.
The timing, against consent
What fires before the banner, while it waits for an answer, and after a refusal. The timing is often the real issue.
The banner against the active parties
The parties the consent screen declares, compared with the ones actually firing, IAB list and custom vendors included.
Permissions requested and used
The ones the app asks for, when it asks, and the ones it actually uses during the journey. Proportionality is judged on use.
Where the data goes
The country of each contacted server, the host sitting behind it, and that country’s data-protection level per the CNIL referential.
The method: observe the app as it runs
Read, inspect, observe: only observation shows what actually leaves. And a finding only holds for the version observed.
Read the declarations
The store listing, the privacy policy, the list of announced partners. Necessary, but declarative: nothing there proves what the app does once installed.
Inspect the package
Static analysis lists the libraries embedded in the installer file. Useful as an inventory, silent on behavior: a kit can sit there and never fire, and what leaves cannot be read from it.
Observe the execution
The app runs on a real phone, a real journey is followed, consent banner included, and every outgoing exchange is recorded, decrypted and dated. This is Skanopy’s method, fully automated.
Replay on every version
An update can add an SDK or switch a partner with nothing moving on screen. The same journey replays on each version, and the reports compare from one release to the next.
The CNIL’s expectations, point by point
The CNIL’s recommendation on mobile applications sets the grid an inspection reads from. Against each expectation, what the analysis observes and documents; the qualification stays with the DPO.
Consent before any read or write
The recommendation requires valid consent before SDKs read from or write to the device. The analysis timestamps every outgoing exchange and places it against the choice expressed in the banner: before, during, after a refusal.
Third-party SDKs under control
The publisher bears at minimum joint responsibility for its SDKs’ trackers and must audit its partners. The analysis records the actors actually active during use, with the company and category behind each contacted domain.
Permissions kept to a minimum
Every permission must map to a real feature. The analysis records the permissions declared, the ones requested during the journey, the moment they are requested, and the ones the app actually uses.
Accurate information
The privacy policy and the store listing must tell the truth before download. The analysis sets the public declaration, Data safety section included, against what actually leaves the device.
A refusal as easy as acceptance
Refusal must be offered at the first level and take effect. The analysis puts the banner through its paces and measures what keeps transmitting once the refusal is expressed, actor by actor.
How Skanopy works.
Point us to the app
Two ways in:
- A Google Play Store link
- A .apk file, for a pre-release before it ships
Skanopy analyzes it
On real phones, a real journey replayed automatically:
- Tracking refused
- Signed in
- Article opened
- Form submitted
Every third-party actor that fires is mapped.
You receive your report
Every fact, named:
- Active third-party actors
- Identifiers shared
- Permissions requested
- Storage access
- Consent-banner compliance
What an audit surfaces: twenty news apps, tracking refused
We installed 20 of the top-ranked news apps and refused tracking. Within about two minutes of use, 95 third-party actors fired despite that refusal.
- Advertising40
- Identity and data11
- Infrastructure / CDN11
- Analytics6
- Video6
- Social5
- Outside the list16
How much does a mobile app audit cost?
The first step is free: the flash audit analyzes your app and sends you, within 48 business hours, the list of third parties it actually contacts. A Google Play link is enough, nothing to install.
The full audit, with the decrypted content of the exchanges, the data transmitted and its timing against consent, is quoted based on how many apps you have and how often you need to analyze. Billing is monthly and legible, based on the analyses you run, not billed consulting days, and every new version of the app can be analyzed without starting over.
Frequently asked questions
In three steps: install the app on a real phone, follow a real usage journey, consent banner included, then record every outgoing exchange, decrypted and dated. The findings are then set against what the app declares. This is what Skanopy automates end to end, with no access to the source code.
The free flash audit is delivered within 48 business hours. Analyses on paid plans are processed faster, depending on the plan.
The flash audit is free. The full audit is quoted and billed monthly, based on the number of apps and the analysis cadence. The plans compare line by line on the pricing page.
A website can be observed from the browser’s own tools. An app is a compiled binary with encrypted traffic, often hardened against analysis: its exchanges can only be read by running it on a controlled device. That is what makes its audit more demanding, and rarer.
A Google Play link, or the installer file if the app is not published yet. No access to the source code, no kit to integrate, nothing to install in your infrastructure.
It documents the facts the recommendation asks to verify: the timing of every exchange against consent, the SDKs actually active, the permissions requested and used, the gap between the public declaration and the observed behavior, the effect of a refusal. The report establishes those findings; compliance itself is assessed with your DPO or counsel.
No, by design. The report establishes facts: parties contacted, data transmitted, timing against consent, permissions used. The legal assessment belongs to the DPO or counsel, with the app’s context in hand.
On every release that changes an SDK or a partner, and at a regular cadence at minimum: an update can change behavior without the banner moving. The reports of two versions read side by side.
The analysis currently covers Android apps, from a Google Play link or an .apk file. Analyses are processed in the European Union.
How do you audit a mobile app?
In three steps: install the app on a real phone, follow a real usage journey, consent banner included, then record every outgoing exchange, decrypted and dated. The findings are then set against what the app declares. This is what Skanopy automates end to end, with no access to the source code.