Where does your data go? Comparing network traffic and privacy policies of public sector mobile applications

dc.contributor.authorCarlsson Robin
dc.contributor.authorHeino Timi
dc.contributor.authorKoivunen Lauri
dc.contributor.authorRauti Sampsa
dc.contributor.authorLeppänen Ville
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organization-code1.2.246.10.2458963.20.71310837563
dc.contributor.organization-code2610302
dc.converis.publication-id68670874
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/68670874
dc.date.accessioned2025-08-28T02:20:38Z
dc.date.available2025-08-28T02:20:38Z
dc.description.abstract<p>As services increasingly move online and mobile devices become ubiquitous, mobile applications are widely used by ordinary people with little technical knowledge. Consequently, user privacy has become an essential matter to consider when developing mobile applications. In this paper, we study the privacy of 32 mobile applications provided by Finnish public sector bodies. First, we investigate with network traffic analysis what kind of personal data these application send out to third party analytics services. We then analyze the privacy policy documents of these applications and assess their clarity and transparency. Our findings show that there are several inconsistencies between the actual traffic of the studied applications and what is said about processing personal data in privacy policies. This underlines the need for software developers and organizations to be better aware of privacy regulations and data their applications send out. There is also lots of work to be done in making the privacy policies less vague and more informative, for example when it comes to explaining what technical data items are sent to third parties and how this can potentially affect the user privacy.<br></p>
dc.format.pagerange214
dc.format.pagerange225
dc.identifier.eisbn978-3-031-04826-5
dc.identifier.isbn978-3-031-04825-8
dc.identifier.issn2367-3370
dc.identifier.jour-issn2367-3370
dc.identifier.olddbid208954
dc.identifier.oldhandle10024/191981
dc.identifier.urihttps://www.utupub.fi/handle/11111/36434
dc.identifier.urlhttps://link.springer.com/chapter/10.1007/978-3-031-04826-5_21
dc.identifier.urnURN:NBN:fi-fe2022021619507
dc.language.isoen
dc.okm.affiliatedauthorCarlsson, Robin
dc.okm.affiliatedauthorHeino, Timi
dc.okm.affiliatedauthorKoivunen, Lauri
dc.okm.affiliatedauthorRauti, Sampsa
dc.okm.affiliatedauthorLeppänen, Ville
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA4 Conference Article
dc.publisher.countrySwitzerlanden_GB
dc.publisher.countrySveitsifi_FI
dc.publisher.country-codeCH
dc.publisher.placeCham
dc.relation.conferenceWorld Conference on Information Systems and Technologies
dc.relation.doi10.1007/978-3-031-04826-5_21
dc.relation.ispartofjournalLecture Notes in Networks and Systems
dc.relation.ispartofseriesLecture Notes in Networks and Systems
dc.relation.volume468
dc.source.identifierhttps://www.utupub.fi/handle/10024/191981
dc.titleWhere does your data go? Comparing network traffic and privacy policies of public sector mobile applications
dc.title.bookInformation Systems and Technologies: WorldCIST 2022, Volume 1
dc.year.issued2022

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
CarlssonR_etal_2022_LNNS_Where_does_your.pdf
Size:
425.89 KB
Format:
Adobe Portable Document Format