Skip to content

In-App Search History Collection in Privacy Policy

In-App Search History Collection in Privacy Policy

Description

If your privacy policy does not mention the collection of your users' in-app search history, but this data type is declared in your Play Data Safety Section, there is a discrepancy in the information provided to users regarding the data being collected from them. This lack of transparency can lead to a breach of trust and potential privacy concerns for users.

Recommendation

To mitigate the vulnerability of collecting users' in-app search history, ensure that your privacy policy clearly discloses this practice in the Play Data Safety Section and obtain explicit consent from users before collecting and storing this sensitive data. Additionally, implement strong encryption measures to protect the data and regularly audit and review your data collection practices to ensure compliance with privacy regulations.

Standards

  • OWASP_MASVS_L1:
  • OWASP_MASVS_L2:
  • OWASP_MASVS_RESILIENCE:
  • CWE_TOP_25:
  • GDPR:
    • ART_5
    • ART_6
    • ART_7
    • ART_9
    • ART_11
    • ART_13
    • ART_15
    • ART_16
    • ART_17
    • ART_32
  • CCPA:
    • CCPA_1798_100
    • CCPA_1798_105
    • CCPA_1798_110
    • CCPA_1798_115
    • CCPA_1798_120
    • CCPA_1798_125
    • CCPA_1798_130
    • CCPA_1798_135
    • CCPA_1798_140
    • CCPA_1798_150
  • PCI_STANDARDS:
  • OWASP_MASVS_v2_1:
    • MASVS_PRIVACY_1
    • MASVS_PRIVACY_2
    • MASVS_PRIVACY_3
    • MASVS_PRIVACY_4
  • OWASP_ASVS_L1:
  • OWASP_ASVS_L2:
  • OWASP_ASVS_L3:
  • SOC2_CONTROLS:
    • CC_2_3
    • CC_5_3