Sources: Apple sends cease and desist emails to Chinese apps testing CAID, which is designed to track users in spite of Apple's upcoming IDFA privacy changes
Chinese apps test multiple workarounds to keep tracking iPhones without prompting for consent — A cat-and-mouse game …
Context & Ripple Effects
CAID emerged as a China Advertising Association-developed response to Apple’s IDFA changes, with Tencent and ByteDance reported to be testing it before Apple intervened. Apple had already publicly framed the delayed IDFA rollout as a privacy measure, including in its dispute with Facebook over data collection.
The cease-and-desist campaign turns that policy stance into app-distribution enforcement against a specific workaround. It matters because CAID sought to preserve cross-app iPhone tracking without the consent prompt Apple’s changes were designed to require.
First-order effects
- Chinese apps testing CAID face an immediate choice between removing the identifier and risking conflict with Apple over their iPhone app distribution.
- Tencent, ByteDance, and other CAID testers lose a prospective route to maintain targeted-ad tracking as IDFA consent requirements take effect.
Second-order effects
- Apple’s enforcement raises the cost of coordinating an industry-wide identifier: the later CAID effort’s failure to gain traction after blocked updates shows app-update control can constrain adoption.
- Developers and advertisers seeking addressable iOS audiences shift toward data practices Apple permits, including the anonymized and aggregated collection later reported among Meta, Snap, and other iOS developers.
Third-order effects
- The dispute establishes app updates as a privacy-policy enforcement lever, leaving tracking systems embedded in apps and SDKs under continuing scrutiny rather than resolved by the IDFA change alone.
- Subsequent reports that opt-out apps still sent identifying information to third parties point to a durable SDK governance gap: consent rules can limit a named identifier without eliminating data flows that enable identification.
The trend: Mobile privacy is moving from limiting platform identifiers to a continuing contest over app-level and SDK-based methods of identifying users.