Auditing a mobile app, from GDPR to a regulator’s inspection
On mobile, what an app declares and what it does diverge. Skanopy measures the gap: the data that leaves, to whom, and when relative to consent. Dated facts, ready for an audit.
Where the data goes
Every server contacted, the country it answers from, and the organisation hosting it.
The CNIL now audits mobile applications
In 2025, mobile apps were one of the CNIL’s priority inspection themes, and the campaign began that spring. Its recommendation on mobile applications, published in September 2024 and updated in spring 2025, sets out the responsibilities along the chain: the publisher is the data controller, and an SDK provider can become jointly responsible as soon as it reuses the data for its own purposes.
What governs reading and writing information on a phone, in France, is Article 82 of the Data Protection Act. It draws no line between the browser and the app: dropping an identifier or reading data falls under the same rules. The obligation is the same as on the web; enforcement, now, is real on mobile.
The problem is visibility. The code is compiled, the traffic is encrypted, and the embedded third-party SDKs are black boxes. A publisher rarely knows exactly what each kit sends, and a DPO has no tool to observe it. For want of anything better, what is declared stands in for proof.
Accountability asks for the opposite: being compliant is not enough, you have to be able to demonstrate it. That takes verifiable facts about the app itself, recorded on a real phone, on a date, and replayable as they were.
What the CNIL looks at in a mobile app
In practice, the CNIL’s recommendation and controls turn on these key points.
Consent before anything is stored
Consent must be collected before an SDK or a tracker reads or writes information on the device, and refusing must stay as easy as accepting. Article 82: the choice comes before the trigger, not after.
The permissions requested
The justification and proportionality of the permissions (location, contacts, storage) against the features the app actually offers.
Third-party SDKs
How the embedded third-party kits are configured, the data they collect, and how responsibility is split between the publisher and its providers.
User information
Clear, accessible information, inside the app, about the data collected, its purposes and its recipients.
Exercising rights
A simple way, from within the app, to exercise your rights: access, erasure, objection, withdrawal of consent.
Data security
Appropriate technical and organizational measures. The CNIL cites the OWASP testing guide (MASTG) as a support for assessing an app’s security.
What Skanopy measures
Skanopy runs the app on a real phone, follows a real journey, and records what it transmits as well as what it touches on the device. Factual, dated, reproducible signals. The legal call stays with the DPO.
The third parties contacted
Every vendor and tracker the app fires, the domain it targets, and its category: advertising, audience measurement, attribution, social networks. Including the ones that fire in the background, with nothing on screen to show for it.
The personal data transmitted
The identifiers and data that leave the device, who they go to, and whether they are persistent or shared across several recipients.
What is read from and written to the device
What the SDKs write on the phone and read back later: stored identifiers, cookies dropped by web views. That is the very act Article 82 covers.
The permissions actually used
The permissions the app asks for, when it asks, and the ones it puts to use during the journey. Proportionality is judged on use, not on the declared list.
Where the data goes
The country of each contacted server, the host sitting behind it, and that country’s data-protection level per the CNIL referential. Transfers outside the European Union read straight off the report.
The timing, relative to consent
What fires before the banner, while it waits for an answer, and after a refusal. The timing is often the real issue.
The gaps with the banner
The active third parties the consent screen does not declare, checked against the IAB list, custom vendors, and Google Additional Consent.
One example: twenty news apps, tracking refused
We installed 20 of the top-ranked news apps and refused tracking. Within about two minutes of use, 95 third-party actors fired despite that refusal.
Read the full study- Advertising40
- Identity and data11
- Infrastructure / CDN11
- Analytics6
- Video6
- Social5
- Outside the list16
0third-party actors fired
Number of third-party actors per category, tracking refused.
How Skanopy works.
Point us to the app
Two ways in:
- A Google Play Store link
- A .apk file, for a pre-release before it ships
Skanopy analyzes it
On real phones, a real journey replayed automatically:
- Tracking refused
- Signed in
- Article opened
- Form submitted
Every third-party actor that fires is mapped.
You receive your report
Every fact, named:
- Active third-party actors
- Identifiers shared
- Permissions requested
- Storage access
- Consent-banner compliance
Frequently asked questions
By comparing what the app declares with what it does once installed. Four things can be checked on the device: which third parties it contacts, what data leaves the phone, when relative to the user’s choice, and which permissions are actually used. These findings are not a verdict: they give the data protection officer the factual material they are missing in order to decide.
By running it on a real phone and watching what comes out. The code is compiled, the traffic is encrypted, and the embedded SDKs are black boxes: neither the store listing nor the privacy policy tells you what actually leaves. The exchanges have to be decrypted while the app runs, which a browser tool cannot do.
Yes. In 2025 mobile apps were one of the CNIL’s priority inspection themes, following its September 2024 recommendation, and the campaign began that spring. Inspections look in particular at third-party SDK configuration, consent, and the permissions requested.
Every server contacted is placed by country, with the host sitting behind it and that country’s data-protection level per the CNIL referential. You see which parties receive data outside the European Union, instead of inferring it from a privacy policy.
No. Skanopy establishes dated, reproducible facts: these are signals, not verdicts. The legal assessment is the DPO’s, with the app’s full context in hand. The deliverable is a technical analysis report, not a legal opinion.
It gives you the material your compliance documents call for: the third parties actually active, the data that leaves the device and who receives it, the timing relative to consent, the permissions used. Enough to update a privacy policy, complete a record of processing, or document a file with dated findings.
No. A Google Play link is enough, or the installer file if the app is not published yet. The analysis observes the app the way a user experiences it, with no access to the code.
That is the safer course. An update can add an SDK, switch a partner or change a behavior without the banner moving an inch. Each version is declared and analyzed on its own, and the reports sit side by side: you see what changed from one release to the next, and before publication if you analyze the installer file.
Today, the analysis covers Android apps. A Google Play link or an .apk file is enough. Your analyses stay in Europe.
How do I know if my mobile app is GDPR compliant?
By comparing what the app declares with what it does once installed. Four things can be checked on the device: which third parties it contacts, what data leaves the phone, when relative to the user’s choice, and which permissions are actually used. These findings are not a verdict: they give the data protection officer the factual material they are missing in order to decide.