news

attention! these 13 apps have privacy violations

2024-09-26

한어Русский языкEnglishFrançaisIndonesianSanskrit日本語DeutschPortuguêsΕλληνικάespañolItalianoSuomalainenLatina

based on the cybersecurity law, the personal information protection law, the method for identifying illegal and irregular collection and use of personal information by apps, and other laws and regulations as well as relevant national standards, the national computer virus emergency response center recently discovered through internet monitoring that 13 mobile apps had privacy non-compliance behaviors.
1. the privacy policy is difficult to access, the basic information of the app operator is not disclosed, and the validity of the privacy policy is not disclosed. the 9 apps involved are as follows:
"friends of cars and goods" (version 1.2.2, app store),
"tanks ol" (version 1.6.13, wandoujia),
"global translator" (version 1.5.7, xiaomi app store),
"tianjin travel" (version 1.24.0, app store),
"lingxiu gaotai" (version 3.2.8, app store),
gansu rural credit cooperatives (version 4.3.0, app store),
"lan ting xu" (version 2.2, huawei app store),
"new lingtai" (version 4.0.0, huawei app store),
"driving school appointment" (version 2.1.84, tengniu.com).
2. the privacy policy does not list the purpose, method, scope, etc. of the collection and use of personal information by the app (including entrusted third parties or embedded third-party codes and plug-ins). the five apps involved are as follows:
"friends of cars and goods" (version 1.2.2, app store),
"tanks ol" (version 1.6.13, wandoujia),
"huajin futures" (version 7.0.11.2, baidu mobile assistant),
"lan ting xu" (version 2.2, huawei app store),
"korean translation" (version 1.5.6, wandoujia).
3. app clients provide personal information to third parties without user consent and without anonymization; personal information processors provide personal information they process to other personal information processors without informing the individual of the recipient’s name or name, contact information, processing purpose, processing method, and type of personal information, and without obtaining the individual’s separate consent. the following 7 apps are involved:
"friends of cars and goods" (version 1.2.2, app store),
"tanks ol" (version 1.6.13, wandoujia),
"huajin futures" (version 7.0.11.2, baidu mobile assistant),
"tianjin travel" (version 1.24.0, app store),
"nojia cloud management 3" (version v1.0.9, pc6.com),
"lingxiu gaotai" (version 3.2.8, app store),
"new lingtai" (version 4.0.0, huawei app store).
4. the app begins to collect personal information or opens the permission to collect personal information before obtaining the user's consent. the following 1 app is involved:
"sakura girls school simulator" (version 1.0.4, 2265 android network).
5. the app does not provide effective functions for correcting, deleting personal information, or canceling user accounts, or sets unnecessary or unreasonable conditions for correcting, deleting personal information, or canceling user accounts; fails to respond to requests for personal information query, correction, or deletion in a timely manner through online operations, and the promised time limit for completing verification and processing exceeds 15 working days. the following 1 app is involved:
"tanks ol" (version 1.6.13, wandoujia).
6. the app failed to establish and publish channels for complaints and reports on personal information security, or failed to accept and handle complaints within the promised time limit; the personal information processor failed to establish a convenient mechanism for accepting and handling applications for individuals to exercise their rights. the following 5 apps are involved:
"friends of cars and goods" (version 1.2.2, app store),
"tanks ol" (version 1.6.13, wandoujia),
"lan ting xu" (version 2.2, huawei app store),
"new lingtai" (version 4.0.0, huawei app store),
"driving school appointment" (version 2.1.84, tengniu.com).
7. where personal information is processed based on personal consent, the individual has the right to withdraw his or her consent. the personal information processor does not provide a convenient way to withdraw consent; the user is provided with ways and methods to withdraw consent for the collection of personal information, but this is not clearly stated in the privacy policy and other collection and use rules. the 8 apps involved are as follows:
"friends of cars and goods" (version 1.2.2, app store),
"tanks ol" (version 1.6.13, wandoujia),
"global translator" (version 1.5.7, xiaomi app store),
"nojia cloud management 3" (version v1.0.9, pc6.com),
"lan ting xu" (version 2.2, huawei app store),
"new lingtai" (version 4.0.0, huawei app store),
"driving school" (version 2.1.84, tengniu.com),
"sakura girls school simulator" (version 1.0.4, 2265 android network).
8. pushing information and conducting commercial marketing to individuals through automated decision-making, without providing options that are not targeted at their personal characteristics, or without providing individuals with a convenient way to refuse; the privacy policy does not state that the collected user personal information is used for targeted push and precision marketing; the privacy policy explicitly states that there is a targeted push function, but the page does not clearly distinguish between personalized push services. the three apps involved are as follows:
"tanks ol" (version 1.6.13, wandoujia),
"huajin futures" (version 7.0.11.2, baidu mobile assistant),
"global translator" (version 1.5.7, xiaomi app store).
9. processing sensitive personal information without obtaining the individual’s separate consent. the two apps involved are as follows:
"friends of cars and goods" (version 1.2.2, app store),
"gansu rural credit cooperative" (version 4.3.0, app bao).
10. personal information processors handle personal information of minors under the age of 14 without formulating special personal information processing rules. the following 4 apps are involved:
"tanks ol" (version 1.6.13, wandoujia),
"global translator" (version 1.5.7, xiaomi app store),
"nojia cloud management 3" (version v1.0.9, pc6.com),
"sakura girls school simulator" (version 1.0.4, 2265 android network).
in response to the above situation, the national computer virus emergency response center reminds the majority of mobile phone users to first be cautious when downloading and using the above-mentioned illegal mobile apps, and at the same time, pay attention to carefully read their user agreements and privacy policies, do not arbitrarily open and agree to unnecessary privacy permissions, do not arbitrarily enter personal privacy information, and regularly maintain and clean up related data to avoid the leakage of personal privacy information.
note: the app detection period listed in this article is from august 1 to september 13, 2024
report/feedback