Privacy & Compliance · Study deck

Two Sides of Mobile Privacy

A commuter opens a journey app while the phone scans nearby radios and asks a cloud service for arrivals.

Privacy Priya is your guide for this deck.

mobile
iotclass.org

After studying this chapter

Learning objectives

You will be able to:

  • review mobile data collection, leakage, location, and sensing together across two exposure surfaces
  • check an app's stated declarations against what its traffic actually does
  • Explain: Some clues leave because an app is allowed to collect them.
  • Explain: Strong permission hygiene means little if an embedded component leaks data anyway, and careful app controls do nothing about passive sensing in the environment.
iotclass.org

Major section

What Leaves the Phone and What the Air Reveals

Some clues leave because an app is allowed to collect them.

  • It helps to see two distinct surfaces.
  • Mobile privacy is the habit of checking both paths before trusting the design.
Two parallel mobile-privacy surfaces. On the active app side, platform access gates lead to an app and embedded SDKs, direct and derived data, location choices, destinations and retention. On the ambient wireless side, a sensing system observes radio emissions or channel changes and may derive device-following or presence-and-movement inferences about people who may have no app relationship. A central comparator checks declared behaviour against observed runtime and field evidence, while a shared governance band covers minimisation, appropriate safeguards, ownership, evidence and retesting.
Two parallel mobile-privacy surfaces. On the active app side, platform access gates lead to an app and embedded SDKs, direct and derived data, location choices, destinations and retention. On the ambient wireless side, a sensing system observes radio emissions or channel changes and may derive device-following or presence-and-movement inferences about people who may have no app relationship. A central comparator checks declared behaviour against observed runtime and field evidence, while a shared governance band covers minimisation, appropriate safeguards, ownership, evidence and retesting.
iotclass.org

Major section

Review Collection, Leakage, Location, and Sensing Together

Strong permission hygiene means little if an embedded component leaks data anyway, and careful app controls do nothing about passive sensing in the environment.

  • Reconcile each match, gap, or unstated behavior, then minimize or redesign and run the surface-specific tests.
  • The decision gate permits approval only with recorded limits and evidence; otherwise it holds or rejects release.
Procedure for running and closing a two-surface mobile privacy review. One scoped feature or sensing deployment and an accountable owner lead to a declared record plus separate active-app and ambient evidence lanes. Declarations and observations are compared as match, gap, or unstated; unexplained flows or inferences are removed, constrained, justified and disclosed, or redesigned, and changed controls require fresh evidence. Separate tests cover foreground, background, denied or narrowed permission, signed-out and SDK or no-prompt app paths, and target-present or absent, no-app, bystander, zone-boundary and uncertainty conditions for ambient sensing. A decision gate branches to approve as tested, approve with limits, hold for remediation and retesting, or do not release and redesign. Every outcome records scope, evidence, residual limits, an owner, and change-triggered retesting. The diagram states that an app off-state cannot prove ambient sensing stopped.
Procedure for running and closing a two-surface mobile privacy review. One scoped feature or sensing deployment and an accountable owner lead to a declared record plus separate active-app and ambient evidence lanes. Declarations and observations are compared as match, gap, or unstated; unexplained flows or inferences are removed, constrained, justified and disclosed, or redesigned, and changed controls require fresh evidence. Separate tests cover foreground, background, denied or narrowed permission, signed-out and SDK or no-prompt app paths, and target-present or absent, no-app, bystander, zone-boundary and uncertainty conditions for ambient sensing. A decision gate branches to approve as tested, approve with limits, hold for remediation and retesting, or do not release and redesign. Every outcome records scope, evidence, residual limits, an owner, and change-triggered retesting. The diagram states that an app off-state cannot prove ambient sensing stopped.
iotclass.org

Major section

Check Declarations Against What Actually Happens

The deeper layer explains why mobile privacy resists trust-by-description.

  • The gap between what is declared and what actually happens is where most surprises live, and passive sensing introduces a person who never agreed to anything.
  • Granting a permission permits access, but it says nothing about how responsibly the data is used or where it ends up.
  • Because declared behavior is a claim, the network traffic is the closest thing to ground truth about what leaves a device.
iotclass.org

Major section

Read Both Privacy Surfaces on a Train

Air-side observations need their own mobile privacy retention limit.

  • Nearby beacons and repeated radio observations may still support coarse presence or movement inference.
  • A persistent token plus a distinctive route can reconnect the privacy record to one commuter.
Two parallel mobile-privacy surfaces. On the active app side, platform access gates lead to an app and embedded SDKs, direct and derived data, location choices, destinations and retention. On the ambient wireless side, a sensing system observes radio emissions or channel changes and may derive device-following or presence-and-movement inferences about people who may have no app relationship. A central comparator checks declared behaviour against observed runtime and field evidence, while a shared governance band covers minimisation, appropriate safeguards, ownership, evidence and retesting.
Two parallel mobile-privacy surfaces. On the active app side, platform access gates lead to an app and embedded SDKs, direct and derived data, location choices, destinations and retention. On the ambient wireless side, a sensing system observes radio emissions or channel changes and may derive device-following or presence-and-movement inferences about people who may have no app relationship. A central comparator checks declared behaviour against observed runtime and field evidence, while a shared governance band covers minimisation, appropriate safeguards, ownership, evidence and retesting.
iotclass.org

Deck summary

Key takeaways

Some clues leave because an app is allowed to collect them.

  • Strong permission hygiene means little if an embedded component leaks data anyway, and careful app controls do nothing about passive sensing in the environment.
  • The deeper layer explains why mobile privacy resists trust-by-description.
  • Air-side observations need their own mobile privacy retention limit.
iotclass.org

Retrieval practice

Recall check 1 of 3

Privacy Priya says: answer from memory, then check your reasoning.

Q1What does granting a mobile app a permission most directly mean for privacy?

AIt opens a path for that data category to be collected or sent off device
BIt authorizes local use of the data, while cloud use needs a separate collection permission
CIt limits collection to times when the user has the app visible on the screen
DIt records a user preference, while the app's published policy determines its actual access
Show answer

Answer: A A permission is a data tap; it opens a path for that category of data to be collected and potentially sent off the device.

iotclass.org

Retrieval practice

Recall check 2 of 3

Privacy Priya says: answer from memory, then check your reasoning.

Q2A simple flashlight app requests precise location, contacts, and always-on access. What is the best first response in a mobile privacy review?

AGrant all requested permissions, since the app would not ask without needing them
BDeny unrelated permissions and inspect traffic for bundled-component leaks
CAssume it is safe because it is a small, simple utility
DOnly read the app's privacy description and skip checking the traffic
Show answer

Answer: B A flashlight needs none of those, so deny the unrelated permissions and verify with traffic inspection that nothing leaks regardless.

iotclass.org

Retrieval practice

Recall check 3 of 3

Privacy Priya says: answer from memory, then check your reasoning.

Q3An app's description says it does not collect location, but traffic inspection shows an embedded analytics component sending precise location to a third party. What does this illustrate, and what is the fix?

ADeclared behavior can differ from actual behavior
BNothing is wrong, because the app's own code does not collect location
CThe fix is to update the description to match, while leaving the leak in place
DTraffic inspection is unreliable, so the description should always be trusted instead
Show answer

Answer: A The traffic reveals what the description hid.

iotclass.org

Print reference

Answers

Answer key.

  1. A · A permission is a data tap; it opens a path for that category of data to be collected and potentially sent off the device.
  2. B · A flashlight needs none of those, so deny the unrelated permissions and verify with traffic inspection that nothing leaks regardless.
  3. A · The traffic reveals what the description hid.
iotclass.org