The GDPR and SDK Usage In Android Mobile Apps
Using data on Software Development Kits (SDKs), we study how SDK usage by Android apps changed after the European Union rolled out the General Data Protection Regulation (GDPR) in May 2018. Relative to US-only apps, the number of non-Google SDKs used per app in five major European countries (EU5) exhibits a 3.6% decline in EU5-only apps after the GDPR, and an 8.7% decline in apps multihoming US and EU5. These effects are mostly driven by lower-ranked apps. Using monthly active users as weights to compute average user exposure to SDKs across app categories and country groups, we find no significant reduction in the average SDK exposure in EU5-only or multihoming apps relative to US-only apps. Overall, these findings suggest that the GDPR had only limited effects on the SDK layer of Android apps and did not materially reduce user exposure to the most prevalent SDK ecosystems.
-
-
Copy CitationGinger Zhe Jin, Ziqiao Liu, and Liad Wagman, "The GDPR and SDK Usage In Android Mobile Apps," NBER Working Paper 33099 (2024), https://doi.org/10.3386/w33099.Download Citation
-