Research: Google's Messages and Dialer apps on Android collect data without explicit consent or an opt-out, potentially violating GDPR; Google is making changes
Thomas Claburn / The Register :
Context & Ripple Effects
This finding extends a long-running line of GDPR pressure on Google's Android stack: a nonprofit founded by Max Schrems filed a complaint over the Android Ad ID back in 2020, and Privacy International earlier documented popular Android apps sharing data with Facebook without consent. What is new here is the target — not an ad identifier or third-party apps, but Google's own preinstalled Messages and Dialer.
The pattern also echoes court documents detailing how Google buried location-data off toggles deep in Android settings and pressed partners like LG to follow suit. That history makes the absence of an opt-out in two of the most-used apps on the platform look less like an oversight and more like the next enforcement frontier.
First-order effects
- Google is now changing Messages and Dialer in response to the research, meaning EU users of two default apps should get consent flows or opt-outs they never had.
- The researchers have handed EU regulators a concrete, named violation candidate on Google's own first-party software, raising the stakes beyond the Ad ID complaint.
Second-order effects
- Other Android OEMs shipping their own dialer and messaging variants face the same consent question, since the research targets a category of preinstalled app rather than one binary.
- Google's compliance work here lands amid its broader EU friction — its security VP has already warned that DMA proposals to open Android could spike fraud — giving the company another front where EU rules force engineering changes.
Third-order effects
- If enforcement follows the complaint trail from ad IDs to first-party system apps, consent-by-default becomes a design requirement for anything preinstalled on Android sold in Europe, not just for third-party SDKs.
- The recurring gap between what Android collects and what users knowingly agreed to points toward structural scrutiny of platform-level telemetry, with regulators treating hidden toggles as evidence rather than edge cases.
The trend: European privacy enforcement is climbing the Android stack from third-party apps and ad identifiers to Google's own preinstalled software, forcing consent mechanisms into platform defaults.