Auditing a mobile app, from GDPR to a regulator’s inspection

On mobile, what an app declares and what it does diverge. Skanopy measures the gap: the data that leaves, to whom, and when relative to consent. Dated facts, ready for an audit.

Where the data goes

Every server contacted, the country it answers from, and the organisation hosting it.

Netherlands2
EU / EEA member
Equativ via LeaseWeb B.V.prg.smartadserver.com
Magnite via Magnite, Inc.prebid-server.rubiconproject.com
4 countries · 2 outside EU

The CNIL now audits mobile applications

In 2025, mobile apps were one of the CNIL’s priority inspection themes, and the campaign began that spring. Its recommendation on mobile applications, published in September 2024 and updated in spring 2025, sets out the responsibilities along the chain: the publisher is the data controller, and an SDK provider can become jointly responsible as soon as it reuses the data for its own purposes.

What governs reading and writing information on a phone, in France, is Article 82 of the Data Protection Act. It draws no line between the browser and the app: dropping an identifier or reading data falls under the same rules. The obligation is the same as on the web; enforcement, now, is real on mobile.

The problem is visibility. The code is compiled, the traffic is encrypted, and the embedded third-party SDKs are black boxes. A publisher rarely knows exactly what each kit sends, and a DPO has no tool to observe it. For want of anything better, what is declared stands in for proof.

Accountability asks for the opposite: being compliant is not enough, you have to be able to demonstrate it. That takes verifiable facts about the app itself, recorded on a real phone, on a date, and replayable as they were.

What the CNIL looks at in a mobile app

In practice, the CNIL’s recommendation and controls turn on these key points.

  • Consent before anything is stored

    Consent must be collected before an SDK or a tracker reads or writes information on the device, and refusing must stay as easy as accepting. Article 82: the choice comes before the trigger, not after.

  • The permissions requested

    The justification and proportionality of the permissions (location, contacts, storage) against the features the app actually offers.

  • Third-party SDKs

    How the embedded third-party kits are configured, the data they collect, and how responsibility is split between the publisher and its providers.

  • User information

    Clear, accessible information, inside the app, about the data collected, its purposes and its recipients.

  • Exercising rights

    A simple way, from within the app, to exercise your rights: access, erasure, objection, withdrawal of consent.

  • Data security

    Appropriate technical and organizational measures. The CNIL cites the OWASP testing guide (MASTG) as a support for assessing an app’s security.

What Skanopy measures

Skanopy runs the app on a real phone, follows a real journey, and records what it transmits as well as what it touches on the device. Factual, dated, reproducible signals. The legal call stays with the DPO.

The third parties contacted

Every vendor and tracker the app fires, the domain it targets, and its category: advertising, audience measurement, attribution, social networks. Including the ones that fire in the background, with nothing on screen to show for it.

The personal data transmitted

The identifiers and data that leave the device, who they go to, and whether they are persistent or shared across several recipients.

What is read from and written to the device

What the SDKs write on the phone and read back later: stored identifiers, cookies dropped by web views. That is the very act Article 82 covers.

The permissions actually used

The permissions the app asks for, when it asks, and the ones it puts to use during the journey. Proportionality is judged on use, not on the declared list.

Where the data goes

The country of each contacted server, the host sitting behind it, and that country’s data-protection level per the CNIL referential. Transfers outside the European Union read straight off the report.

The timing, relative to consent

What fires before the banner, while it waits for an answer, and after a refusal. The timing is often the real issue.

The gaps with the banner

The active third parties the consent screen does not declare, checked against the IAB list, custom vendors, and Google Additional Consent.

How Skanopy works.

  1. Point us to the app

    Two ways in:

    • A Google Play Store link
    • A .apk file, for a pre-release before it ships
  2. Skanopy analyzes it

    On real phones, a real journey replayed automatically:

    • Tracking refused
    • Signed in
    • Article opened
    • Form submitted

    Every third-party actor that fires is mapped.

  3. You receive your report

    Every fact, named:

    • Active third-party actors
    • Identifiers shared
    • Permissions requested
    • Storage access
    • Consent-banner compliance

Frequently asked questions

  • By comparing what the app declares with what it does once installed. Four things can be checked on the device: which third parties it contacts, what data leaves the phone, when relative to the user’s choice, and which permissions are actually used. These findings are not a verdict: they give the data protection officer the factual material they are missing in order to decide.

  • By running it on a real phone and watching what comes out. The code is compiled, the traffic is encrypted, and the embedded SDKs are black boxes: neither the store listing nor the privacy policy tells you what actually leaves. The exchanges have to be decrypted while the app runs, which a browser tool cannot do.

  • Yes. In 2025 mobile apps were one of the CNIL’s priority inspection themes, following its September 2024 recommendation, and the campaign began that spring. Inspections look in particular at third-party SDK configuration, consent, and the permissions requested.

  • Every server contacted is placed by country, with the host sitting behind it and that country’s data-protection level per the CNIL referential. You see which parties receive data outside the European Union, instead of inferring it from a privacy policy.

  • No. Skanopy establishes dated, reproducible facts: these are signals, not verdicts. The legal assessment is the DPO’s, with the app’s full context in hand. The deliverable is a technical analysis report, not a legal opinion.

  • It gives you the material your compliance documents call for: the third parties actually active, the data that leaves the device and who receives it, the timing relative to consent, the permissions used. Enough to update a privacy policy, complete a record of processing, or document a file with dated findings.

  • No. A Google Play link is enough, or the installer file if the app is not published yet. The analysis observes the app the way a user experiences it, with no access to the code.

  • That is the safer course. An update can add an SDK, switch a partner or change a behavior without the banner moving an inch. Each version is declared and analyzed on its own, and the reports sit side by side: you see what changed from one release to the next, and before publication if you analyze the installer file.

  • Today, the analysis covers Android apps. A Google Play link or an .apk file is enough. Your analyses stay in Europe.

How do I know if my mobile app is GDPR compliant?

By comparing what the app declares with what it does once installed. Four things can be checked on the device: which third parties it contacts, what data leaves the phone, when relative to the user’s choice, and which permissions are actually used. These findings are not a verdict: they give the data protection officer the factual material they are missing in order to decide.