Mozilla will require Firefox extension developers to clearly disclose any collection or sharing of user data with third parties starting in November 2025. The move is part of the company’s effort to build user trust and provide greater transparency about the data protection practices of its popular browser add-ons.

The new requirements will be incorporated into the extensions' manifest.json file, via the browser_specific_settings.gecko.data_collection_permissions field . Developers will be required to declare the practices data collection of their new extensions starting November 3, 2025 , and all extensions updated in the first half of 2026 will be required to adopt this framework.
See also: YouTube introduces AI tool to protect against deepfakes
What data is affected?
Mozilla says that personally identifiable information (PII) that can be collected includes things like names, email addresses, search terms, and browsing activities, such as visited domains and URLs. Even extensions that don't collect data must explicitly stateso that users know exactly what each add-on's functionality includes.
All of this information will be displayed during the extension installation process, next to the permissions requested by the add-on, and will also be recorded on the extension's registration page at addons.mozilla.org and in the "Permissions and Data" section of about:addons in Firefox.

According to the company, “the user will be able to accept or reject data collection, just like with extension permissions. The developer can also specify that the extension does not collect data.” This transparency allows users to have greater control and make informed decisions about protecting their privacy.
See also: WhatsApp warns of screen sharing scams
Only for new extensions
The requirement applies only to new extension submissions. Existing add-ons do not need to adapt to the new framework until an update is submitted, giving developers time to comply.
However, extensions that do not properly declare their data collection practices will be banned from the add-on repository Mozilla. Developers will receive detailed error messages explaining the points of non-compliance so they can fix the issues before resubmitting.
Additional security initiatives
Last month, Mozilla announced a feature that allows developers to revert to previously approved versions of their extensions to quickly fix critical bugs and issues. The move strengthens the reliability of add-ons and reduces risks for users.

Additionally, in June, a new security feature was introduced for the add-on portal, aimed at blocking malicious extensions that exploit cryptocurrency wallets. This initiative demonstrates Mozilla’s strategy of combining transparency with technical protections, while protecting the user experience from third-party threats.
See also: OpenAI: Extra protections for Sora after concerns about Deepfake content
The importance for users and developers
Mozilla's new policy sets new standards for transparency and privacy in the browser. Developers are required to accurately disclose their data practices, strengthening the credibility of their add-ons, while giving users more information and control.
In an era where privacy and data security are at the forefront, Mozilla's move is an important step in building trust and reducing the risks of malicious add-ons. The combined transparency and technical security initiatives make Firefox one of the most user-friendly and secure browsers today.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
