Mobile app GDPR audit: what to check, and how to prove it
An app declares itself in a privacy policy, but it acts in the traffic it emits. An audit confronts the two: which third parties fire, what data leaves, when relative to consent. Here is the full method, the deliverable, and what it costs.
Where the data goes
Every server contacted, the country it answers from, and the organisation hosting it.
Why audit a mobile app, and why now
The obligation is not new. In France, Article 82 of the Data Protection Act governs any reading or writing of information on a phone, exactly as on the web, and the GDPR requires you to demonstrate compliance, not just assert it. What changed is enforcement: the CNIL, the French data protection authority, published its recommendation on mobile applications in September 2024, updated it in spring 2025, and made apps one of its priority inspection themes for 2025.
The sanctions already exist: a mobile games publisher was fined 3 million euros for reading a device identifier for advertising purposes despite a refusal of tracking expressed at system level. The charge was not a badly written policy; it was what the app actually did.
And that is precisely what nobody sees. The code is compiled, the traffic is encrypted, third-party SDKs, the ready-made software bricks an app embeds, are black boxes: a publisher rarely knows what each kit sends, and many discover their own partners the day someone asks. For want of a tool, the store listing and the privacy policy stand in for proof.
A serious audit reverses the burden: it establishes dated findings, recorded on the app itself, that can be set against the declaration and replayed on every version. That is the material missing from records of processing, privacy policies and answers to a supervisory authority.
What a mobile app audit must verify
Six readings which, side by side, tell whether the declaration holds.
The third parties actually active
Every SDK and third party that fires during use, with the domain contacted and its category: advertising, audience measurement, attribution, social networks. Including the ones firing in the background.
The personal data that leaves
The identifiers and data transmitted off the device, who they go to, and whether they circulate across several third parties at once.
The timing, against consent
What fires before the banner, while it waits for an answer, and after a refusal. The timing is often the real issue.
The banner against the active parties
The parties the consent screen declares, compared with the ones actually firing, IAB list and custom vendors included.
Permissions requested and used
The ones the app asks for, when it asks, and the ones it actually uses during the journey. Proportionality is judged on use.
Where the data goes
The country of each contacted server, the host sitting behind it, and that country’s data-protection level per the CNIL referential.
The method: observe the app as it runs
Read, inspect, observe: only observation shows what actually leaves. And a finding only holds for the version observed.
Read the declarations
The store listing, the privacy policy, the list of announced partners. Necessary, but declarative: nothing there proves what the app does once installed.
Inspect the package
Static analysis lists the libraries embedded in the installer file. Useful as an inventory, silent on behavior: a kit can sit there and never fire, and what leaves cannot be read from it.
Observe the execution
The app runs on a real phone, a real journey is followed, consent banner included, and every outgoing exchange is recorded, decrypted and dated. This is Skanopy’s method, fully automated.
Replay on every version
An update can add an SDK or switch a partner with nothing moving on screen. The same journey replays on each version, and the reports compare from one release to the next.
How Skanopy works.
Point us to the app
Two ways in:
- A Google Play Store link
- A .apk file, for a pre-release before it ships
Skanopy analyzes it
On real phones, a real journey replayed automatically:
- Tracking refused
- Signed in
- Article opened
- Form submitted
Every third-party actor that fires is mapped.
You receive your report
Every fact, named:
- Active third-party actors
- Identifiers shared
- Permissions requested
- Storage access
- Consent-banner compliance
What an audit surfaces: twenty news apps, tracking refused
We installed 20 of the top-ranked news apps and refused tracking. Within about two minutes of use, 95 third-party actors fired despite that refusal.
Read the full study- Advertising40
- Identity and data11
- Infrastructure / CDN11
- Analytics6
- Video6
- Social5
- Outside the list16
0third-party actors fired
Number of third-party actors per category, tracking refused.
How much does a mobile app audit cost?
The first step is free: the flash audit analyzes your app and sends you, within 48 business hours, the list of third parties it actually contacts. A Google Play link is enough, nothing to install.
The full audit, with the decrypted content of the exchanges, the data transmitted and its timing against consent, is quoted based on how many apps you have and how often you need to analyze. Billing is monthly and legible, based on the analyses you run, not billed consulting days, and every new version of the app can be analyzed without starting over.
Frequently asked questions
In three steps: install the app on a real phone, follow a real usage journey, consent banner included, then record every outgoing exchange, decrypted and dated. The findings are then set against what the app declares. This is what Skanopy automates end to end, with no access to the source code.
The free flash audit is delivered within 48 business hours. Analyses on paid plans are processed faster, depending on the plan.
The flash audit is free. The full audit is quoted and billed monthly, based on the number of apps and the analysis cadence. The plans compare line by line on the pricing page.
A website can be observed from the browser’s own tools. An app is a compiled binary with encrypted traffic, often hardened against analysis: its exchanges can only be read by running it on a controlled device. That is what makes its audit more demanding, and rarer.
A Google Play link, or the installer file if the app is not published yet. No access to the source code, no kit to integrate, nothing to install in your infrastructure.
No, by design. The report establishes facts: parties contacted, data transmitted, timing against consent, permissions used. The legal assessment belongs to the DPO or counsel, with the app’s context in hand.
On every release that changes an SDK or a partner, and at a regular cadence at minimum: an update can change behavior without the banner moving. The reports of two versions read side by side.
The analysis currently covers Android apps, from a Google Play link or an .apk file. Analyses are processed in the European Union.
How do you audit a mobile app?
In three steps: install the app on a real phone, follow a real usage journey, consent banner included, then record every outgoing exchange, decrypted and dated. The findings are then set against what the app declares. This is what Skanopy automates end to end, with no access to the source code.