Following its Dec. report, Privacy International finds seven major Android apps, including Yelp and Duolingo, still send personal data to Facebook upon launch
Even when you're not logged in or don't have a Facebook account — Major Android mobile apps from companies including Yelp …
Context & Ripple Effects
Privacy International's December report flagged popular Android apps — TripAdvisor, Kayak, Indeed, MyFitnessPal — for sharing user data with Facebook without consent, a practice it argued may breach GDPR. The new finding is a follow-up audit: months later, seven major apps including Yelp and Duolingo are still transmitting personal data to Facebook at app launch, even when the user is not logged in or has no Facebook account.
The story sits inside a longer arc the coverage documents well: a 2015 survey already found popular apps sending emails and location to third parties, and February's report on 17K Android apps building permanent device activity records showed how systematic ad-targeting collection had become. That the named offenders persist after public disclosure is what makes this update matter.
First-order effects
- Yelp and Duolingo now have documented, repeated evidence that their apps transmit personal data to Facebook on launch without user consent — direct GDPR exposure for EU users they cannot attribute to a third party's bug twice.
- Facebook keeps receiving identifiable data from people who never opted in, deepening its regulatory risk at a moment when Privacy International has already framed the practice as a potential GDPR violation.
Second-order effects
- Every major Android developer using embedded analytics or social SDKs faces pressure to audit what those kits transmit at launch, since Privacy International's method makes any app reproducible as a named offender.
- Regulators weighing the December complaint gain a stronger case: continued transmission after disclosure shifts the narrative from oversight to disregard, raising the likelihood of formal GDPR proceedings against both the apps and Facebook.
Third-order effects
- If researcher-led audits remain the only enforcement mechanism, app-store privacy becomes a compliance-by-publication regime where SDK vendors and platform owners — Google and Facebook — absorb structural accountability for data flows developers embed but do not govern.
- The pattern across 2015, 2018, 2019, and the later iOS push-notification findings points toward platform-level technical restrictions replacing app-level policy promises as the only reliable control on third-party data collection.
The trend: Third-party data collection embedded in mobile SDKs is proving resistant to disclosure and consent rules, leaving independent audits and platform-level technical controls as the emerging enforcement path.