Your customers trust you. Your app might be betraying that trust.
Picture this: you run a small Malaysian business. Maybe you sell food, run a boutique, or manage a delivery service. Someone downloads your app, grants location permission so they can find your store or track their order. Simple, right?
Not quite. According to findings by the Electronic Frontier Foundation, Android apps can quietly share that same location data with advertisers and data brokers — and the developer often has no idea it’s happening. The third-party code embedded in your app inherits your app’s location permission by default. Unless someone actively switches it off, every location ping from your user’s phone also goes to companies you’ve never heard of.
TL;DR
- Advertising SDKs inside Android apps collect precise location data by default once the app has location permission — even if the developer never intended it.
- The EFF identified apps sharing this data, including two with a combined 60 million downloads.
- For Malaysian SMEs, this is a PDPA liability and a customer trust risk — even if you outsourced your app development.
- You need to ask your developer what SDKs are in your app and turn off unnecessary data collection.
What This Actually Means
When your app developer adds third-party tools — like advertising banners, crash reporting, or analytics — they’re inserting chunks of code called SDKs (software development kits). Think of it like hiring a contractor who quietly brings his own subcontractor onto your job site. That subcontractor may be selling your customer’s data without your knowledge, and without your contractor even realising it’s happening.
The EFF found there are no SDK-specific location permissions in Android. When a user allows the app to access their location, every SDK embedded in the app inherits that access automatically. Some SDKs then stream location data to their own servers, which feed into data brokers — companies that build and sell detailed location histories.
“App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs. Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s location.” — Electronic Frontier Foundation
That data doesn’t just power ads. The EFF report says these location histories get sold to militaries, governments, and intelligence agencies like the FBI. The same data is a security risk if it gets hacked or stolen, which has happened to data brokers before.
How This Applies to Malaysian SMEs
You might be thinking: “I don’t have an app, so this doesn’t affect me.” Stop right there. If you’re planning an app — for deliveries, loyalty programmes, bookings, or e-commerce — this is your early warning. And if you already have an app, this may be happening inside your product right now.
Here’s the uncomfortable part: even if you hired a developer or an agency to build your app, you are responsible for what that app does with customer data. Malaysia’s Personal Data Protection Act (PDPA) applies to you as the data user, not to your vendor. Your developer’s job is to write code; your job is to own the consequences. If your app leaks location data and a customer files a complaint, “I didn’t know” won’t hold up.
Let’s make this real. You own a restaurant in Penang and your app takes reservations with location access so customers can “find your branch.” A reservation widget your developer installed includes a location-tracking SDK from a foreign ad network. Every customer who uses that feature unknowingly shares their location with that network — which sells it to a data broker. You never see a single sen from that arrangement. But your business name is on the app, and your reputation absorbs the damage.
Then there’s the trust angle. Malaysian consumers are more aware of data privacy than you might think, especially after years of data breach headlines. Imagine a local news story: “Penang restaurant app caught sharing customer location data with foreign advertisers.” You’d lose customers — not because you did something malicious, but because you didn’t check what your developer installed. For a small business, one such story can undo years of goodwill.
Practical Takeaways
- Ask your developer for a full list of SDKs in your app — what each one does, and whether it accesses location data. Get this in writing.
- Turn off location data collection for SDKs that don’t need it. If an ad SDK doesn’t need location, configure it to not collect it.
- Review your app’s permission prompts. Only ask for location when it’s genuinely needed for a feature the user is actively using.
- Audit every third-party service in your app at least twice a year. Code gets updated regularly, and SDKs can change their behaviour without your developer noticing.
- If you haven’t built an app yet, make privacy a requirement in your developer brief. Ask how they handle SDK permissions and data minimisation before you sign.
What Happens to Your Customer’s Location Data
| Step | What Happens | Who’s Involved |
|---|---|---|
| 1 | User grants location permission to your app | Your app |
| 2 | Embedded SDK inherits that permission automatically | Advertising SDK vendor |
| 3 | SDK streams location data to its own servers | SDK vendor’s infrastructure |
| 4 | Data is aggregated and sold as location histories | Data brokers |
| 5 | Buyers include governments, militaries, and intelligence agencies | E.g., the FBI |
The scale is worth understanding. The EFF says the SDKs they examined claim to reach billions of users over tens of thousands of apps. That’s not a niche problem. And the two Android apps identified in the report had a combined 60 million downloads. Your app might be a thousand times smaller — but the data leak works exactly the same way.
The Bigger Picture
This is moving in one direction: accountability. Regulators around the world — and increasingly in Malaysia — are holding app publishers responsible for what happens to user data, even data handled by someone else’s SDK. The “the developer did it” excuse is running out of road.
For small businesses, this is actually an opportunity. Big companies move slowly. You can move fast. By making privacy a deliberate part of how you build and run your app, you can earn trust that your competitors haven’t earned yet. A simple statement — “We don’t sell your data, and we actively block SDKs that try to collect it” — is something most big-name apps can’t honestly say.
Don’t wait for a breach, a complaint, or a news headline to force you into action. Call your developer this week. Ask the questions in this article. You don’t need to become a privacy expert — you just need to know what’s inside your own app. Your customers’ trust depends on it.
Ready to Streamline Your Operations?
Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →
