Developers say the App Store has started rejecting updates for apps using third-party SDKs that collect data that can be used for device fingerprinting
here's why Ben Lovejoy / 9to5Mac : Snap has tested workaround to App Tracking Transparency; 95% effective Mike Peterson / AppleInsider : Snap explored ways to bypass Apple's App Tracking Transparency feature Jonny Evans / Computerworld : Apple switches off the ‘open web’ by making it better Allison Schiff / AdExchanger : Apple Is Rejecting Apps That Use Third-Party Code For Alleged Privacy Infractions Christopher Baugh / iPhone in Canada Blog : Apple Begins to Implement Anti-Tracking Protection Measures Built Into iOS 14 Josiah Motley / KnowTechie : Apple will reject your app if it contains third-party trackers that collect data without consent Filipe Espósito / 9to5Mac : App Store now rejecting apps using third-party SDKs that collect user data without consent Chris Smith / BGR : Apple is already rejecting apps that track users without asking permission Andrew Orr / The Mac Observer : Apple Starts Blocking Apps That Use ‘Adjust SDK’ for Tracking Andrew Blustein / Adweek : Apple Clamps Down on IDFA Workarounds Juli Clover / MacRumors : Apple Now Rejecting App Updates That Defy iOS 14.5 App Tracking Transparency Rules Financial Times : Snap confirms it was testing probabilistic matching to track iOS users for a few months, but will discontinue the program after Apple rolls out tracking changes Tyler Lee / Ubergizmo : Apple Is Now Rejecting Apps That Use Third-Party SDKs To Collect User Data Without Consent Joe Wituschek / iMore : Apple is now rejecting apps that use third-party SDKs to collect user data Tweets: Eric Seufert / @eric_seufert : Per a number of developers, Apple has begun rejecting app updates that include the Adjust SDK related to its collection of data used for device fingerprinting. @thomasbcn : Here's a first warning to *some* probabilistic attribution techniques under iOS14.5 (that particular SDK was updated, problem is solved for now) https://www.forbes.com/... by @johnkoetsier Eric Seufert / @eric_seufert : Is this text new? Apple is now explicitly stating that SDKs or native code that actively collects these specific device identifiers will cause an app to be rejected from the App Store https://twitter.com/... Eric Seufert / @eric_seufert : CAID update: Cyberspace Administration of China (CAC) mandates that apps not restrict access to content when users do not share non-essential personal data. I'm still hearing about app updates rejected when CAID is integrated (1/X) https://www.straitstimes.com/ ...
Context & Ripple Effects
Apple had already tightened App Store rules around third-party handling of location and address-book data. The reported rejections extend that enforcement to embedded SDK behavior, exposing the earlier privacy crackdown as a broader review standard rather than a one-off rule change.
The conflict arrives alongside App Tracking Transparency: Snap tested probabilistic matching as a workaround but planned to discontinue it as Apple’s changes rolled out. Apple later moved toward requiring developers to justify use of APIs susceptible to fingerprinting, formalizing the scrutiny seen in these rejections.
First-order effects
- Developers whose updates include CAID or the Adjust SDK face blocked releases until they remove or change code that collects device-identifying data.
- Third-party SDK vendors become an immediate App Store compliance risk for their app customers, even where the app developer did not build the tracking mechanism.
Second-order effects
- App developers must audit embedded SDKs more closely, shifting integration decisions toward vendors that can document data collection and App Store compliance.
- Tracking providers lose a route around App Tracking Transparency as App Review can enforce against fingerprinting-related code before an update reaches users.
Third-order effects
- Apple’s App Store is becoming a governance layer for software supply chains: developer accountability increasingly extends to the data practices of bundled third-party code.
- The later API-reason requirement aimed at fingerprinting suggests a shift from detecting prohibited behavior in review toward constraining the technical inputs that enable it.
The trend: Mobile platform privacy enforcement is moving from user-facing consent rules toward tighter control of SDKs and APIs that can enable tracking.