Mobile app GDPR audit: what to check, and how to prove it

An app declares itself in a privacy policy, but it acts in the traffic it emits. An audit confronts the two: which third parties fire, what data leaves, when relative to consent. Here is the full method, the deliverable, and what it costs.

Where the data goes

Every server contacted, the country it answers from, and the organisation hosting it.

Netherlands2
EU / EEA member
Equativ via LeaseWeb B.V.prg.smartadserver.com
Magnite via Magnite, Inc.prebid-server.rubiconproject.com
4 countries · 2 outside EU

Why audit a mobile app, and why now

The obligation is not new. In France, Article 82 of the Data Protection Act governs any reading or writing of information on a phone, exactly as on the web, and the GDPR requires you to demonstrate compliance, not just assert it. What changed is enforcement: the CNIL, the French data protection authority, published its recommendation on mobile applications in September 2024, updated it in spring 2025, and made apps one of its priority inspection themes for 2025.

The sanctions already exist: a mobile games publisher was fined 3 million euros for reading a device identifier for advertising purposes despite a refusal of tracking expressed at system level. The charge was not a badly written policy; it was what the app actually did.

And that is precisely what nobody sees. The code is compiled, the traffic is encrypted, third-party SDKs, the ready-made software bricks an app embeds, are black boxes: a publisher rarely knows what each kit sends, and many discover their own partners the day someone asks. For want of a tool, the store listing and the privacy policy stand in for proof.

A serious audit reverses the burden: it establishes dated findings, recorded on the app itself, that can be set against the declaration and replayed on every version. That is the material missing from records of processing, privacy policies and answers to a supervisory authority.

What a mobile app audit must verify

Six readings which, side by side, tell whether the declaration holds.

  • The third parties actually active

    Every SDK and third party that fires during use, with the domain contacted and its category: advertising, audience measurement, attribution, social networks. Including the ones firing in the background.

  • The personal data that leaves

    The identifiers and data transmitted off the device, who they go to, and whether they circulate across several third parties at once.

  • The timing, against consent

    What fires before the banner, while it waits for an answer, and after a refusal. The timing is often the real issue.

  • The banner against the active parties

    The parties the consent screen declares, compared with the ones actually firing, IAB list and custom vendors included.

  • Permissions requested and used

    The ones the app asks for, when it asks, and the ones it actually uses during the journey. Proportionality is judged on use.

  • Where the data goes

    The country of each contacted server, the host sitting behind it, and that country’s data-protection level per the CNIL referential.

The method: observe the app as it runs

Read, inspect, observe: only observation shows what actually leaves. And a finding only holds for the version observed.

Read the declarations

The store listing, the privacy policy, the list of announced partners. Necessary, but declarative: nothing there proves what the app does once installed.

Inspect the package

Static analysis lists the libraries embedded in the installer file. Useful as an inventory, silent on behavior: a kit can sit there and never fire, and what leaves cannot be read from it.

Observe the execution

The app runs on a real phone, a real journey is followed, consent banner included, and every outgoing exchange is recorded, decrypted and dated. This is Skanopy’s method, fully automated.

Replay on every version

An update can add an SDK or switch a partner with nothing moving on screen. The same journey replays on each version, and the reports compare from one release to the next.

How Skanopy works.

  1. Point us to the app

    Two ways in:

    • A Google Play Store link
    • A .apk file, for a pre-release before it ships
  2. Skanopy analyzes it

    On real phones, a real journey replayed automatically:

    • Tracking refused
    • Signed in
    • Article opened
    • Form submitted

    Every third-party actor that fires is mapped.

  3. You receive your report

    Every fact, named:

    • Active third-party actors
    • Identifiers shared
    • Permissions requested
    • Storage access
    • Consent-banner compliance

How much does a mobile app audit cost?

The first step is free: the flash audit analyzes your app and sends you, within 48 business hours, the list of third parties it actually contacts. A Google Play link is enough, nothing to install.

The full audit, with the decrypted content of the exchanges, the data transmitted and its timing against consent, is quoted based on how many apps you have and how often you need to analyze. Billing is monthly and legible, based on the analyses you run, not billed consulting days, and every new version of the app can be analyzed without starting over.

Frequently asked questions

  • In three steps: install the app on a real phone, follow a real usage journey, consent banner included, then record every outgoing exchange, decrypted and dated. The findings are then set against what the app declares. This is what Skanopy automates end to end, with no access to the source code.

  • The free flash audit is delivered within 48 business hours. Analyses on paid plans are processed faster, depending on the plan.

  • The flash audit is free. The full audit is quoted and billed monthly, based on the number of apps and the analysis cadence. The plans compare line by line on the pricing page.

  • A website can be observed from the browser’s own tools. An app is a compiled binary with encrypted traffic, often hardened against analysis: its exchanges can only be read by running it on a controlled device. That is what makes its audit more demanding, and rarer.

  • A Google Play link, or the installer file if the app is not published yet. No access to the source code, no kit to integrate, nothing to install in your infrastructure.

  • No, by design. The report establishes facts: parties contacted, data transmitted, timing against consent, permissions used. The legal assessment belongs to the DPO or counsel, with the app’s context in hand.

  • On every release that changes an SDK or a partner, and at a regular cadence at minimum: an update can change behavior without the banner moving. The reports of two versions read side by side.

  • The analysis currently covers Android apps, from a Google Play link or an .apk file. Analyses are processed in the European Union.

How do you audit a mobile app?

In three steps: install the app on a real phone, follow a real usage journey, consent banner included, then record every outgoing exchange, decrypted and dated. The findings are then set against what the app declares. This is what Skanopy automates end to end, with no access to the source code.

See what your app really transmits.