You probably share more information with apps than you think. Some of it feels fairly harmless. Apps on your phone may know which shops you visit, what you bought last week, where you spend your weekends, your favourite coffee brand, your daily step count, how often you vacuum your house and which apps you open most often.
And on its own, that may not sound particularly worrying. But when all of that information is collected, combined and analysed, it can start to tell a much bigger story about your life. It can suggest where you live, where you work, what you spend money on, what your habits are and begin to build patterns to predict what you might do next.
Then there is the more personal information. Apps you use may know what medication you take, details about your health, whether you are trying for a baby, when your period is due, who you are interested in dating, and even your mental state. All of this information is often collected, combined and shared with unknown and unknowable third parties with diverse motives.
Most of us do not think about this when we download an app. We tick a few boxes, press “accept” and get on with our day. But it is worth asking a simple question: what happens to that information afterwards?
What happens after you click “accept”?
When you use an app or website, you expect it to collect the information it needs to provide the service that you signed up for. If you use a period tracker, you expect it to know about your cycle. If you use a dating app, you expect it to know something about your preferences. If you use a loyalty card, you expect it to keep a record of what you have bought.
But what you may not be aware of is just how many other companies could be involved behind the scenes. Many digital services use advertising and analytics technologies to make money, measure performance and improve their products. That can mean information about how you use an app is shared with advertisers, technology providers and data partners you have never heard of, often in diverse foreign countries, and those companies share the data with yet further companies.
That does not automatically mean anything unlawful has happened. Many organisations use personal information responsibly and within the law. But it does mean your information may travel much further than you realise.
Your data could be the real price of a free app
Many apps are never really free. A free period tracker, social network, game, loyalty scheme or email account still costs money to build and run. Apps need developers, servers, support teams and marketing budgets, and if you are not paying for the service at point of download or through a subscription, the company behind it still needs a way to fund it.
In many cases, that funding comes from advertising. The more an advertiser (and their agents) knows about you, the more useful that information can be when deciding which adverts you see, when you see them and what content is shown to you. Your interests, habits, location, purchases and behaviour can all help build a detailed picture of who you are and what you may do next.
Often, you are not deliberately handing over that information as payment. You are simply using a service that appears to be free. But the trade-off may still be there. You may not be paying with money, but you may be paying with your data.
The problem is that this data sharing arrangement is not always clear and rarely fair. You know what a subscription costs because the price is visible before you buy it. It is much harder to know what your health data is worth, what your loyalty card reveals about you or how many companies may have access to information generated by the apps on your phone.
That is why understanding what happens to your data after you click “accept” has become a major consumer rights issue.
What is data misuse?
When you hear the words “data misuse”, you may think of hackers stealing information in a cyber attack. But concerns about personal data do not always start with a breach. Data misuse can also mean your information being collected, shared or used in ways you would not reasonably expect. It can also mean you were not given enough clear information to make a proper choice about how your data would be used. Some information is more sensitive than other information. Details about your health, sex life, sexuality and other personal matters have extra protection under data protection law because the impact can be serious if they are mishandled.
What rights do you have?
You have rights over your personal information.You have the right to know what information organisations hold about you, to understand how it is being used and who it is being shared with. You can ask for inaccurate information to be corrected and, in some circumstances, you can ask for information to be deleted. But, the difficulty is that it can be hard to use those rights when you do not know what is happening to your data in the first place.
Why this has become a consumer rights issue
In recent years, regulators around the world have taken action against companies over the way personal information has been handled.
You don’t need to use Flo or Grindr to see why this matters. The bigger issue affects anyone with a smartphone: once you’ve clicked “accept”, do you know where your information goes and who can access it?
Why this affects almost everyone
This issue goes beyond health apps and dating services. Think about your loyalty cards. Every purchase helps build a picture of your habits and lifestyle and over time, those purchases can reveal far more than you might expect. If you have children, you may have even more reason to care. Campaigners have raised concerns for years about the amount of information collected about young people online. Some have questioned whether behavioural tracking can be used to influence what children see, what they buy and how they interact with online games and services.
What can you do?
You probably do not have time to investigate every app on your phone, read every privacy policy or analyse every cookie banner. You simply want to use services safely and understand what you are signing up for.
That is why the Data Protection Foundation (DPF) has been established. The DPF is a not-for-profit organisation that aims to help you better understand how your information is used, what rights you have and what practical steps you can take to protect yourself. Its services include website tracking analysis, app privacy reviews, data breach alerts and practical guidance to help you better understand and manage your digital privacy.
The DPF also provides information about your rights when organisations misuse personal data and, where appropriate, information about collective legal actions that may be available to people affected by the same issue. The idea is to make it easier for you to understand what is happening to your data, what rights you have and what options may be available if those rights have been breached.
Join the Data Protection Foundation
Want to better understand how your personal data is being used and what you can do if your rights are breached? Join the Data Protection Foundation for free to stay informed about privacy issues, investigations, practical tools and potential collective legal actions that could affect you.
Join the Data Protection Foundation
