<?xml version="1.0" encoding="UTF-8"?>

<modsCollection xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd">
<mods version="3.3">

<genre>conference paper</genre>

<titleInfo><title>Do Android App Developers Accurately Report Collection of Privacy-Related Data?</title></titleInfo>





<name type="personal">
  <namePart type="given">Mugdha</namePart>
  <namePart type="family">Khedkar</namePart>
  <role><roleTerm type="text">author</roleTerm> </role><identifier type="local">88024</identifier></name>
<name type="personal">
  <namePart type="given">Ambuj Kumar</namePart>
  <namePart type="family">Mondal</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>
<name type="personal">
  <namePart type="given">Eric</namePart>
  <namePart type="family">Bodden</namePart>
  <role><roleTerm type="text">author</roleTerm> </role><identifier type="local">59256</identifier><description xsi:type="identifierDefinition" type="orcid">0000-0003-3470-3647</description></name>







<name type="corporate">
  <namePart></namePart>
  <identifier type="local">76</identifier>
  <role>
    <roleTerm type="text">department</roleTerm>
  </role>
</name>



<name type="conference">
  <namePart>39th IEEE/ACM International Conference on Automated Software Engineering (ASE 2024)</namePart>
</name>






<abstract lang="eng">Many Android applications collect data from users. The European Union&apos;s General Data Protection Regulation (GDPR) requires vendors to faithfully disclose which data their apps collect. This task is complicated because many apps use third-party code for which the same information is not readily available. Hence we ask: how accurately do current Android apps fulfill these requirements?
In this work, we first expose a multi-layered definition of privacy-related data to correctly report data collection in Android apps. We further create a dataset of privacy-sensitive data classes that may be used as input by an Android app. This dataset takes into account data collected both through the user interface and system APIs.
We manually examine the data safety sections of 70 Android apps to observe how data collection is reported, identifying instances of over- and under-reporting. Additionally, we develop a prototype to statically extract and label privacy-related data collected via app source code, user interfaces, and permissions. Comparing the prototype&apos;s results with the data safety sections of 20 apps reveals reporting discrepancies. Using the results from two Messaging and Social Media apps (Signal and Instagram), we discuss how app developers under-report and over-report data collection, respectively, and identify inaccurately reported data categories.
Our results show that app developers struggle to accurately report data collection, either due to Google&apos;s abstract definition of collected data or insufficient existing tool support. </abstract>

<relatedItem type="constituent">
  <location>
    <url displayLabel="2409.04167v1.pdf">https://ris.uni-paderborn.de/download/56137/56138/2409.04167v1.pdf</url>
  </location>
  <physicalDescription><internetMediaType>application/pdf</internetMediaType></physicalDescription>
</relatedItem>
<originInfo><dateIssued encoding="w3cdtf">2024</dateIssued><place><placeTerm type="text">Sacramento, California</placeTerm></place>
</originInfo>
<language><languageTerm authority="iso639-2b" type="code">eng</languageTerm>
</language>



<relatedItem type="host"><titleInfo><title>In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering Workshops (ASEW ’24)</title></titleInfo>
  <identifier type="arXiv">2409.04167</identifier><identifier type="doi">10.1145/3691621.3694949</identifier>
<part>
</part>
</relatedItem>


<extension>
<bibliographicCitation>
<mla>Khedkar, Mugdha, et al. “Do Android App Developers Accurately Report Collection of Privacy-Related Data?” &lt;i&gt;In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering Workshops (ASEW ’24)&lt;/i&gt;, 2024, doi:&lt;a href=&quot;https://doi.org/10.1145/3691621.3694949&quot;&gt;10.1145/3691621.3694949&lt;/a&gt;.</mla>
<short>M. Khedkar, A.K. Mondal, E. Bodden, in: In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering Workshops (ASEW ’24), 2024.</short>
<bibtex>@inproceedings{Khedkar_Mondal_Bodden_2024, title={Do Android App Developers Accurately Report Collection of Privacy-Related Data?}, DOI={&lt;a href=&quot;https://doi.org/10.1145/3691621.3694949&quot;&gt;10.1145/3691621.3694949&lt;/a&gt;}, booktitle={In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering Workshops (ASEW ’24)}, author={Khedkar, Mugdha and Mondal, Ambuj Kumar and Bodden, Eric}, year={2024} }</bibtex>
<apa>Khedkar, M., Mondal, A. K., &amp;#38; Bodden, E. (2024). Do Android App Developers Accurately Report Collection of Privacy-Related Data? &lt;i&gt;In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering Workshops (ASEW ’24)&lt;/i&gt;. 39th IEEE/ACM International Conference on Automated Software Engineering (ASE 2024), Sacramento, California. &lt;a href=&quot;https://doi.org/10.1145/3691621.3694949&quot;&gt;https://doi.org/10.1145/3691621.3694949&lt;/a&gt;</apa>
<ieee>M. Khedkar, A. K. Mondal, and E. Bodden, “Do Android App Developers Accurately Report Collection of Privacy-Related Data?,” presented at the 39th IEEE/ACM International Conference on Automated Software Engineering (ASE 2024), Sacramento, California, 2024, doi: &lt;a href=&quot;https://doi.org/10.1145/3691621.3694949&quot;&gt;10.1145/3691621.3694949&lt;/a&gt;.</ieee>
<chicago>Khedkar, Mugdha, Ambuj Kumar Mondal, and Eric Bodden. “Do Android App Developers Accurately Report Collection of Privacy-Related Data?” In &lt;i&gt;In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering Workshops (ASEW ’24)&lt;/i&gt;, 2024. &lt;a href=&quot;https://doi.org/10.1145/3691621.3694949&quot;&gt;https://doi.org/10.1145/3691621.3694949&lt;/a&gt;.</chicago>
<ama>Khedkar M, Mondal AK, Bodden E. Do Android App Developers Accurately Report Collection of Privacy-Related Data? In: &lt;i&gt;In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering Workshops (ASEW ’24)&lt;/i&gt;. ; 2024. doi:&lt;a href=&quot;https://doi.org/10.1145/3691621.3694949&quot;&gt;10.1145/3691621.3694949&lt;/a&gt;</ama>
</bibliographicCitation>
</extension>
<recordInfo><recordIdentifier>56137</recordIdentifier><recordCreationDate encoding="w3cdtf">2024-09-16T08:50:54Z</recordCreationDate><recordChangeDate encoding="w3cdtf">2024-11-18T13:19:51Z</recordChangeDate>
</recordInfo>
</mods>
</modsCollection>
