Privacy International revealed the extent to which app developers handle data on Facebook, even if the user is not a Facebook user. The disclosure was made last Sunday during the 35thChaos Communication Conference.

Privacy International conducted a report based on 34 Android apps used by between 10 million and 500 million users. The charity said researchers were particularly concerned about how users’ data was being exploited in the back-end systems of Facebook and Google. Specifically, the findings showed that 23 of the apps tested sent data to Facebook, which tells them which social network a user has opened or which app they have closed, along with information about the device, language and time zone settings. Also, the fact that the apps send Facebook the user’s Google advertising ID allows tracking companies to easily conduct profile matching. For example, travel booking app “Kayak” passed data to Facebook with every search made within the app, such as departure, arrival, airport, date, number and type of tickets. Privacy International pointed out that this data transfer between the application and Facebook occurred regardless of whether the user had logged out of Facebook or did not have an account on the social media platform.
Facebook generally offers advertising and analytics services to app developers, which help them obtain information about how people use social media. This practice is also followed by other social media as well as websites and apps, such as Adobe, Flurry, and Mixpanel. Through the research conducted, Privacy International questioned whether and to what extent personal data protection laws are being complied with on Facebook and its applications.
