The Case for App Scanning and SDK Governance: Lessons from Texas Lawsuit The State of Texas has filed a lawsuit against a large insurance company and its analytics subsidiary for alleged violations of the Texas Data Privacy and Security Act (TDPSA), the Data Broker Law, and the Texas Insurance Code. What happened: - A large insurance company and its analytics subsidiary created a Software Development Kit (SDK), that was embedded into third-party apps offering location-based services. - This SDK secretly collected sensitive user data, including precise locations, speed, direction, and other phone sensor data, without users' awareness. - The collected data was used to create a massive driving behaviour database covering millions of users. - This data was monetized, influencing insurance premiums and policies, often without users' knowledge or consent. - Users were not informed about how their data was being collected or shared, and privacy policies were not clear or accessible. Key issues: 1) No user consent: People did not know their data was being collected or sold. 2) Inaccurate profiling: The SDK often mistook passengers or other scenarios as "bad driving," leading to misleading profiles. 3 ) Non-compliance: The analytics subsidiary failed to register as a data broker, as required by Texas law. Why this matters: This case highlights the risks of hidden data collection in apps. It shows how companies can misuse sensitive data and the importance of protecting user privacy through stronger controls. The way forward: To effectively address these risks, organizations must take assertive action by implementing the following measures - a) Conduct regular mobile app scanning: Analyze apps weekly or bi-weekly to identify permissions, embedded SDKs, and dataflows. b) Govern SDKs effectively: Establish strict policies for integrating and monitoring SDKs. Require transparency from SDK providers about what data is collected, how it is used, and who it is shared with. Avoid SDKs that fail to meet these standards. c) Monitor hidden dataflows: SDKs often operate in the background and can rely on permissions obtained by the app to collect sensitive data. Regularly audit these dataflows to uncover any implicit collection or sharing practices and address potential violations proactively. d) Communicate transparently with users: Update #privacy policies to clearly explain what data is collected, how it will be used, and who it will be shared with. Obtain explicit consent before collecting or sharing sensitive data. The risks of hidden #dataflows and implicit data collection are significant, especially as #SDKs become more complex. How frequently does your team #audit apps for SDK behaviors and permissions? What tools or strategies have you found most effective in uncovering hidden #datasharing?
Data Collection Deception
Explore top LinkedIn content from expert professionals.
-
-
Warning to all LinkedIn users: You receive a message from a person supposedly connected to a reputable survey company such as IDR. The incoming email address or user looks legit. The message is addressed to you personally e.g.”Dear Clive…..” The message invites you to participate in a compensated survey, (e.g. for $30 or $50) related to something related to your industry (e.g. “a study focused on ETF usage and selection practices among financial professionals across Europe”.) The message says “If you qualify based on a short screening form, you’ll be invited to complete a brief survey.” and contains a link to an external form, (e.g. in a Microsoft Forms link). This simple “screening” appears innocuous but you are still asked to share potentially sensitive information such as your name, email address, LinkedIn profile and place of work. No matter what rubbish you write in the screening, you’ll automatically qualify for the survey. The subsequent “survey” starts with some innocuous questions before seeking answers to more sensitive questions such as: Personal Identifiers: The form often asks for full legal name, business email, and phone number. Professional Information: Common questions include employer/company name, job title and role. (E.g. “Please briefly describe the focus of your role and main responsibilities.”). You may be asked to provide other sensitive information such as type of clients, or assets under management. This level of data collection is unnecessary for market research and is a typical hallmark of scams. You might receive a follow-up call in which you are asked for your bank account details or PayPal information “for payment” and asked for a copy of your photo ID, business card, or proof of employment to confirm your identity or eligibility for the honorarium. Providing any information opens risks of identity theft, phishing, social engineering, account compromise, and financial fraud. Do not submit any sensitive information through these forms. Even initial “screening” steps are often used to harvest professional and contact data for further targeting.
-
Uber’s cancel-ride screen is the perfect example of how data can mislead PMs. Every time I cancel a ride, Uber asks: “Why are you cancelling?” But here’s the honest reality: When I’m cancelling a ride, I’m almost always in a hurry. I’m not reading anything. I tap “Other” or whichever option gets me out fastest. And I’m pretty sure most people do the same. Now imagine a PM looking at this dashboard: “Most users cancelled for ‘Other’.” “Lets understand the root cause for the same.” “Let’s fix this.” But the insight is completely misleading. The data isn’t showing the real reason. It’s showing the user’s state of mind: “I’m in a rush, don’t make me think.” This is why blindly trusting data can be dangerous. If we don’t understand the context in which data is collected, even a clean dataset can push us toward the wrong decisions. Before relying on any metric, it’s worth asking: When is the user giving this input? What behaviour is influencing the response? Is the data actually meaningful? Because if the input is unreliable, every analysis and decision built on top of it will be unreliable too. What’s one dataset you’ve seen which might lead to the wrong conclusions? #ProductManagement #Observation #DesignThinking #UXDesign #UserExperience
-
Your data can lie to you, let me tell you some truth. Dear Data Lovers 💙 We’ve all been there—trusting a dataset only to realize later that it painted an incomplete or even misleading picture. Correlation is not causation. Averages can hide extremes. Percentages can be deceptive without absolute numbers. Ever seen a report showing a 200% growth rate, only to realize later that the baseline was almost nothing? Or a dashboard that made a problem look small because it used the wrong scale? The truth is, data doesn’t lie—but how we collect, analyze, and present it can create illusions. Here are three classic ways data can “lie” to you: 🔹 Simpson’s Paradox – When Trends Reverse A university claims its acceptance rate is higher for women than men. But when broken down by department, women applied more to highly competitive departments, skewing the data. The overall trend masks the real story. 🔹 Survivorship Bias – Ignoring Missing Data During WWII, engineers reinforced returning aircraft based on bullet hole patterns. But they ignored planes that never made it back. The real weak spots? The areas with no bullet holes on surviving planes—because hits there were fatal. 🔹 Misleading Averages – The Salary Trap A company reports an “average salary” of $100,000, but most employees actually earn $50,000—because a few executives make millions. Using median instead of mean would tell the real story. That’s why critical thinking and business context are just as important as analytics tools. Have you ever been fooled by data? Let’s discuss in the comments! #dataanalytics #datascience #consulting #insights #corporateculture LinkedIn LinkedIn News India LinkedIn Guide to Creating
-
Nonprofit friends, planning to collect data soon? Remember: Your questions shape your data—but they don’t always get you what you need. Imagine this: You are filling out a border form, and it asks: "Do you exceed duty-free allowances per person?" The only answers are Yes or No. For someone who didn't bring any goods, selecting No implies they did get something but stayed within the limit. The question doesn't account for people for whom the question is irrelevant, forcing them to provide inaccurate information. Now think about your data collection tools (say, your last survey): ● Are your questions boxing people into answers that don't reflect their reality? ● Are you assuming experiences that don't apply to everyone? ● Are you unintentionally excluding voices by limiting response options? Poorly worded questions = bad data = flawed decisions = a loss of trust. Here are three examples of common pitfalls: ● Assumptions baked into questions Example: “What barriers prevent you from attending our events?” assumes the respondent knows about your events and faces barriers. A better question: “Have you heard of our events?” followed by, “What barriers, if any, prevent you from attending?” ● Excluding relevant options Example: “Which of these programs have you used?” but leaving out “I haven’t used any.” Guess what happens? People pick a random answer or leave it blank, and now your data is a mess. ● Vague questions Example: “On a scale of 1-5, how satisfied are you with our communication?” Without specifying—emails? Social media? In-person?—responses will be all over the place. Your questions are your bridge to listening and understanding. Two things to remember here (and by no means this is the complete list): ● Plan your survey – the why, what, how, when, what-next… before jumping to design ● Use inclusive language, providing options like "Does not apply.", wherever relevant. Ensuring people responding to it can see themselves in the questions and responses is the only way to give them the true choice of what and how much they want to share with us. Please reach out if you want to plan a Survey Kaleidoscope workshop with your team on your upcoming survey (for context, it's a workshop where we solely plan the survey collectively - every single element of how to ensure a successful survey happens) #nonprofits #nonprofitleadership #community
-
TRUST BREAKS BEFORE IT BENDS: "The mechanism is technically precise and deliberately invisible." Precision means intent. Invisibility means risk. Together, they mean fingerprinting, not analytics. What LinkedIn is doing is environmental intelligence: understanding what tools you use, what signals you emit, what your digital posture reveals about your role, your employer, your vulnerabilities, and your "competitive value." When a platform with nearly a billion users can silently inventory your browser environment, the situation goes far beyond privacy and notions of consent. And it will lead to stinging discontent, among users. Think about it. This was a 6,167‑item fingerprinting operation running silently inside Chromium‑based browsers (Chrome, Edge, Brave, Opera, Arc.) The script executed in milliseconds, checked for thousands of extensions, encrypted the results, and shipped them off to LinkedIn and third‑party endpoints. All without disclosure. All mapped to real identities. Systems built to see without being seen rarely announce themselves. (They wait for us to realize the architecture was the point all along.) Since this story broke there has been no public statement from either LinkedIn or its parent co. I will continue to monitor and update. This is both important and outrageous. Under GDPR, much of this detailed data collection qualifies as Special Category Data - the kind you can’t process without explicit consent. And consent was never part of the design. https://lnkd.in/gbFvzSZh #AuguryIT #microsoft #privacyprotection
-
From a cybersecurity perspective, what happened is bigger than the giveaway itself. Thousands of Nigerians reportedly rushed into a livestream and publicly dropped account numbers linked to OPay, Moniepoint, and other fintech platforms in exchange for the possibility of receiving money. Many people saw poverty. A cybersecurity analyst sees data exposure. Most Nigerians do not realize that many fintech account numbers are directly tied to phone numbers. That means every account number dropped publicly potentially becomes an intelligence point. To an ordinary person, it is an account number. To a criminal, it is a lead. To a fraudster, it is data. To a kidnapper, it is a starting point. To a terrorist network, it is a database. Now imagine thousands of such details being harvested in one place, voluntarily provided by the owners themselves. No hacking required. No malware required. No phishing required. People simply handed over the information. Cybersecurity professionals have a saying: "The easiest system to breach is the human being." The real danger is not the ₦50 million allegedly shared. The real danger is the digital footprint left behind. Phone numbers can be linked to social media accounts. Social media accounts reveal friends, family members, locations, workplaces, schools, routines, and habits. One piece of information often leads to another. This is how intelligence gathering works. Not through dramatic Hollywood hacking scenes. But through the collection of small pieces of publicly available information until a complete profile emerges. The most dangerous data breach is the one people participate in willingly. And if thousands of Nigerians truly submitted their account details in a public livestream, what occurred was not merely a giveaway. It was a massive open-source intelligence exercise waiting to be exploited by anyone watching. #TheUpdate #OSINTinsight
-
I came across this on Ivy Wanjiru's Money Monday and it got me thinking. "Record meetings so that when someone tries to deny something, you play the recording." As a Data Protection and Privacy practitioner, the biggest blind spot for organizations on data protection compliance is employee privacy. Most times this operates from the assumption that provided an employee has executed a contract with your organization then anything goes including how their personal data is processed. I know the argument would be that meeting participants/interviewees are notified of recording by the platform. In my opinion this is insufficient because the platform does not disclose to what use the data will be put to. Additionally, determinations from the Office of the Data Protection Commissioner have continued to burst this assumption. The ODPC's determination in Andrew Alston vs Liquid Telecom Kenya (ODPC Complaint No. 1125 of 2025) speaks directly to this. In this case, the Complainant held a consultation call with the Respondent's HR following his retrenchment. The call was recorded. He explicitly did not consent to the recording and was told it would be deleted. It wasn't. It was retained and later shared with a sister company, Liquid Mauritius, who used it as evidence in international arbitration proceedings against him. The organization was ordered to compensate him Ksh 700,000 and an enforcement notice was issued. In arriving at this determination Data Commissioner found that: 📌 The automated platform notification is not enough. It does not fulfil the duty to notify under Section 29 of the DPA. The Complainant was not informed of the purpose for which the data was being collected, the third parties it would be transferred to, or the security measures in place. Transparency requires meaningful information not a Zoom pop-up. 📌 Purpose limitation means what it says. The call was recorded in the context of an HR consultation on exit details. It was later used as evidence in arbitration by a party that wasn't even part of the original data collection. So what should your organization do if it intends to use recordings? 📌 Start by defining the purpose you intend to use the recording for. 📌 Assess whether the method is unnecessarily intrusive or whether the same purpose can be met through another means, such as written confirmations or meeting minutes. 📌 If recording is genuinely necessary, the next step is to update your Employee Privacy Policies and HR Manuals to reflect that recordings may be used for purposes such as disciplinary proceedings or internal investigations.And critically make sure those updates don't just sit on your intranet. Actually communicate them to staff. A policy that employees have never seen offers you very little protection when a data subject complaint lands on your desk. #dataprotection #dataprivacy #compliance
-
👉 Researchers have recently discovered a method employed by Meta (Facebook, Instagram) and Yandex to monitor Android users' browsing behaviour by exploiting a system-level loophole that bypasses users' privacy safeguards. I am not an IT specialist, but the explanation is clear enough to follow and to translate into practical terms. When a user has one of these apps installed, it opens a local communication port on the device, commonly referred to as localhost. If the app is running in the background and the user visits a website that includes tracking scripts such as Meta Pixel or Yandex Metrica (Meta Pixel alone is present on over 5.8 million websites), those scripts can detect the app and establish a direct connection to it via the localhost port. This allows the app to collect information about the website visit, potentially including session data, cookies or user identifiers. Because this communication happens locally, it is unaffected by the typical privacy measures users might rely on, such as private browsing modes, cookie deletion or the use of a VPN. This behaviour is fully documented and clearly explained at https://lnkd.in/daSMtPr3. What stands out is that this is not an exploit in the traditional sense. It simply relies on the way Android handles local network communication. It is a technically clever implementation with significant implications. It establishes a direct, hidden exchange between the browser and the app using the device's architecture without the user's awareness or control. In privacy discussions, we often refer to dark patterns, fingerprinting and similar techniques. This example introduces a different type of concern. It is not only about the method of data collection but about the extent to which the user's attempts to maintain privacy can be quietly circumvented. There is value in paying close attention to these less visible, system-level mechanisms. If this form of tracking becomes commonplace, many of the tools users rely on to safeguard their privacy, including browsers, cookie settings and VPNs, risk becoming ineffective. And consent, in such a scenario, risks becoming little more than a formality.
-
So let’s talk about the quiet middlemen nobody invited but everyone’s data somehow met anyway. Data brokers. These are the companies that scrape, buy, sell, and repackage your personal information. Then they slap it on a website and call it “people search” or “public records.” Sounds harmless. It’s not. As a Cybercrimes Detective, I can tell you exactly how scammers use these sites. ✅ They look you up by name or phone number ✅They get your current and past addresses ✅Your relatives and associates ✅Your age range, emails, sometimes employment history That’s not trivia. That’s a scam blueprint. This is how scams go from random to personal. “Hi, this is your bank.” “Hi, this is law enforcement.” “Hi, this is your grandson.” When a scammer already knows where you live, who you’re related to, and what city you’re in, the lie lands harder. Trust comes faster. Victims comply sooner. Data brokers don’t usually scam people. But they absolutely fuel scams. So what can you do. 1️⃣ Manual opt-outs Most data broker sites have opt-out pages. They’re buried. They’re annoying. And there are dozens of them. But it’s free if you have the time and patience. 2️⃣ Use removal services Companies like Incogni, DeleteMe, Optery, Aura, and others will do the legwork for you. You’re essentially paying someone to play whack-a-mole with your data year-round. For many people, that’s worth it. 3️⃣ California’s new Delete Act California now allows residents to submit a single request that requires registered data brokers to delete their personal information. This is a big step. Other states are watching closely. Bottom line. You can’t stop data collection entirely. But you can reduce your digital footprint. And every record removed is one less puzzle piece a scammer can use against you. #DataPrivacyWeek isn’t just about strong passwords. It’s about starving scammers of the information they rely on. Pause. Think. Verify. And maybe… delete yourself from the internet just a little. #FraudHero #fraud #scams #databroker #fraudprevention #PauseThinkVerify #StoptheScam