Google has mandated developers to use Data Safety Sections (DSS) to increase transparency in data collection and sharing practices. In this paper, we present a comprehensive analysis of Google's Data Safety Section (DSS) using both quantitative and qualitative methods. We conduct the first large-scale measurement study of DSS using apps from Android Play store (n=1.1M). We find that there are internal inconsistencies within the reported practices. We also find trends of both over and under-reporting practices in the DSSs. Next, we conduct a longitudinal study of DSS to explore how the reported practices evolve over time, and find that the developers are still adjusting their practices. To contextualize these findings, we conduct a developer study, uncovering the process that app developers undergo when working with DSS. We highlight the challenges faced and strategies employed by developers for DSS submission, and the factors contributing to changes in the DSS. Our research contributes valuable insights into the complexities of implementing and maintaining privacy labels, underlining the need for better resources, tools, and guidelines to aid developers. This understanding is crucial as the accuracy and reliability of privacy labels directly impact their effectiveness.
翻译:谷歌强制要求开发者使用数据安全部分(DSS)以提升数据收集与共享实践的透明度。本文采用定量与定性方法,对谷歌数据安全部分(DSS)进行了全面分析。我们首次对安卓Play商店中的应用(n=110万)开展了大规模DSS测量研究,发现报告实践中存在内部不一致性,并观察到过度报告与报告不足两种趋势。随后,我们通过纵向研究探讨了报告实践随时间的演变情况,发现开发者仍在调整其行为。为佐证上述发现,我们开展了开发者研究,揭示了应用开发者处理DSS的具体流程。本文重点阐述了开发者提交DSS过程中面临的挑战与采用的策略,以及导致DSS发生变化的因素。本研究为理解隐私标签实施与维护的复杂性提供了宝贵见解,强调了需要更好的资源、工具与指南来支持开发者。这一认知至关重要,因为隐私标签的准确性与可靠性直接影响其有效性。