The children's app industry is thriving, but at the cost of children's privacy. These apps routinely disclose children's data to multiple data trackers and ad networks, which accumulates to long-term privacy risks as children spend increasing time online. To investigate why this is happening and how developers might change their practices, a mixed-methods approach was used against 5 leading data protection frameworks that set out requirements and recommendations for data collection in children's apps. The study involved 134 surveys and 20 semi-structured interviews with popular Android children's app developers. The analysis revealed that while developers largely respect children's best interests, they have to make compromises due to limited monetisation options, perceived harmlessness of certain third-party libraries, and lack of availability of design guidelines. The study identified four major themes: (i) developers' perceived responsibilities and motivations in designing for children's best interests; (ii) perceptions of data collection practices; (iii) reliance on third-party libraries; and (iv) the need to earn money. Developers often relied on Google's app publication requirements, which are not always directly aligned with principles set out by the AADC. The study calls for supporting documents to aid developers in navigating the opaque and complex development ecosystem, research into alternative and privacy-friendly monetisation methods, tools to support developers in auditing their apps, and tools to empower end-users in case developers do not keep up with age-appropriate practices. While the presence of trackers and third-party libraries in Android applications is well researched, the privacy landscape of iOS apps is less documented. Future work aims to extend this study to include iOS apps and developers as well. Additionally, the study focused on US and European regulations due to regulatory interventions taking place in Europe primarily ICO’s enforcement of the statutory AADC that will come into effect in 2021. The participants who responded may have represented those with better awareness of potential issues or took children’s best interests more seriously than the average developer. However, the study provided valuable insights into a research direction about which little is known. While the principles developers aimed to realize aligned with best practices, it is likely that some developers have malicious intents or are indifferent about children's privacy. In conclusion, the study provided a much-needed developer perspective regarding challenges and barriers to better privacy in children's apps. It highlighted the need for concrete yet neutral design guidelines, alternative yet privacy-friendly monetisation methods, tools for supporting developers when auditing their apps as well as tools empowering end users if developers fail to adhere with age appropriate practices.
- - The children's app industry is thriving but at the cost of children's privacy
- - Apps routinely disclose children's data to multiple data trackers and ad networks, which accumulates to long-term privacy risks as children spend increasing time online
- - A mixed-methods approach was used against 5 leading data protection frameworks that set out requirements and recommendations for data collection in children's apps
- - Developers largely respect children's best interests but have to make compromises due to limited monetisation options, perceived harmlessness of certain third-party libraries, and lack of availability of design guidelines
- - Four major themes were identified: (i) developers' perceived responsibilities and motivations in designing for children's best interests; (ii) perceptions of data collection practices; (iii) reliance on third-party libraries; and (iv) the need to earn money
- - The study calls for supporting documents to aid developers in navigating the opaque and complex development ecosystem, research into alternative and privacy-friendly monetisation methods, tools to support developers in auditing their apps, and tools to empower end-users in case developers do not keep up with age-appropriate practices
- - Future work aims to extend this study to include iOS apps and developers as well
- - The study provided valuable insights into a research direction about which little is known
- - It highlighted the need for concrete yet neutral design guidelines, alternative yet privacy-friendly monetisation methods, tools for supporting developers when auditing their apps as well as tools empowering end users if developers fail to adhere with age appropriate practices.
The app industry for kids is doing well, but it's not good for their privacy. Apps share information about kids with many companies that track data and show ads. This can be dangerous in the long run as kids spend more time online. A study looked at how developers make apps for kids and found they try to do what's best, but have to compromise because they need to make money and don't always have clear guidelines. The study suggests creating tools to help developers make better apps and protect children's privacy, and also researching new ways to make money without sharing data. The study will continue looking at apps for iPhones too.
Definitions:
- Industry: a group of businesses that work together
- Privacy: keeping things private or secret
- Data: information that is collected
- Monetisation: making money from something
- Guidelines: rules or suggestions on how to do something
The Children's App Industry: Thriving at the Cost of Children's Privacy
The children’s app industry is booming, but this growth comes with a price – the privacy of our children. Research has revealed that many apps routinely disclose children’s data to multiple data trackers and ad networks, which can lead to long-term privacy risks as kids spend more time online. To investigate why this is happening and how developers might change their practices, a mixed-methods approach was used against 5 leading data protection frameworks that set out requirements and recommendations for data collection in children’s apps. The study involved 134 surveys and 20 semi-structured interviews with popular Android children’s app developers.
Developers' Perceived Responsibilities & Motivations
The analysis revealed that while developers largely respect children’s best interests, they have to make compromises due to limited monetisation options, perceived harmlessness of certain third-party libraries, and lack of availability of design guidelines. Developers often relied on Google's app publication requirements which are not always directly aligned with principles set out by the AADC (Age Appropriate Design Code).
Perceptions of Data Collection Practices
The study identified four major themes related to perceptions around data collection practices: (i) developers' perceived responsibilities and motivations in designing for children's best interests; (ii) perceptions of data collection practices; (iii) reliance on third-party libraries; and (iv) the need to earn money.
Reliance on Third Party Libraries
Developers often rely on third party libraries when creating their apps as it helps them save time during development process. However these libraries may contain code that collects user information without informing users or obtaining consent from parents/guardians first - something which goes against regulations such as GDPR or COPPA in US.
Monetization Challenges
Another challenge faced by developers is monetization - making money off their apps so they can continue developing new ones or improving existing ones. Unfortunately most methods available involve collecting user information through ads or other tracking services which raises concerns about privacy violations especially when it comes to child users who cannot give informed consent yet are still exposed to such services through these apps.
While the presence of trackers and third-party libraries in Android applications is well researched, the privacy landscape of iOS apps is less documented so future work aims to extend this study include iOS apps too . Additionally ,the study focused primarily on US & European regulations due its primary focus being ICO ‘ s enforcement of statutory AADC coming into effect 2021 . The participants who responded may have represented those with better awareness potential issues or took child ‘ s best interest more seriously than average developer . However ,study provided valuable insights into research direction about which little known . While principles developers aimed realize aligned best practice ,likely some developer malicious intent indifferent child ‘ s privacy . In conclusion ,study provided much needed developer perspective regarding challenges barriers better privacy child ‘ s app highlighted need concrete neutral design guideline alternative yet privacy friendly monetisation method tools supporting developer auditing app tool empowering end user case fail adhere age appropriate practice