---
title: "Pixalate’s H1 2024 GDPR Violation Risks Report: Apple App Store"
description: Pixalate’s H1 2024 GDPR Violation Risks Report for the Apple App Store provides a detailed legal analysis on data privacy violation risks arising under the EU and UK’s General Data Protection Regulation (‘GDPR’)
image: https://www.pixalate.com/hubfs/Blog_Media/Blog%20photos/GDPR%20Violation%20Risks%20Report_%20Apple%20App%20Store%20landing%20page%20cover.png
---

[![pixalate-full-logo](https://www.pixalate.com/hs-fs/hubfs/Pixalate_Logos/pixalate-full-logo.jpg?width=150&height=60&name=pixalate-full-logo.jpg "pixalate-full-logo")](https://www.pixalate.com)

Search

**Menu**

** **

![](https://www.pixalate.com/hubfs/Blog_Media/Blog%20photos/pixalate-blog-bg.png)

[Mobile Apps](https://www.pixalate.com/blog/topic/mobile-apps) | [GDPR](https://www.pixalate.com/blog/topic/gdpr) | [Privacy](https://www.pixalate.com/blog/topic/privacy) |

 4 min read

# Pixalate’s H1 2024 Legal Investigation Report on Apple App Store Identifies How the App Store & App Developers Are Likely Violating GDPR Articles 5, 12, 13 & 24

 Written by [Pixalate](https://www.pixalate.com/blog/author/pixalate)

 Aug 22, 2024 10:45:00 AM

*Pixalate’s research reveals that over 380,000 users within the United Kingdom, France and other European countries face ongoing privacy risks when using Apple devices, as their personal data is transmitted in the open programmatic advertising bid stream by 1,300+ Apple App Store-hosted and targeted advertising-enabled mobile apps – these apps are likely failing to inform users of their privacy rights and what essentially happens to their personal data once processed, triggering potential violations of GDPR *[*Articles 5,12*](https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679#d1e1374-1-1)* and *[*13*](https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679#d1e1374-1-1)*. Pixalate’s research further investigates and shares insights on Apple App Store appearing to enable these likely non-compliant apps to conduct targeted advertising by sharing EU & UK-based users’ IDFAs/IDFVs with them.*

**LONDON, August 22, 2024** –[Pixalate,](https://www.pixalate.com/) the global market-leading ad fraud protection, privacy, and compliance analytics platform, today released the [H1 2024 GDPR Violation Risks Report: Apple App Store.](https://www.pixalate.com/gdpr-violation-risks-report-apple-app-store) The report provides a detailed legal analysis on data privacy violation risks arising under the European Union (‘EU’) and United Kingdom’s (‘UK’) [General Data Protection Regulation](https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679#d1e1374-1-1) (‘GDPR’), specifically under [Articles 5, 12, 13, 24](https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679#d1e1374-1-1) and [Rec. 75](https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679#d1e1374-1-1) in connection with the Apple App Store and app developers that have published mobile apps on Apple’s App Store. 

The report also evaluates potential GDPR violation risks for Apple as a “Data Controller,” as defined under GDPR [Article 4(7)](https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679#d1e1374-1-1) – Apple appears to share users’ device identifiers (Identifier for Advertisers, Identifier for Vendors, a.k.a IDFAs/IDFVs) with 1,384 Apple App Store-hosted mobile apps that do not have detected privacy policies yet appear to process users’ personal data by sharing their IDFAs/IDFVs in the ad bid stream.

To compile this research, Pixalate’s data science team analysed over 32,000 Apple App Store-hosted mobile apps that were downloadable from their App Store in the EU and UK during H1 2024, met the territorial scope of GDPR, and had open programmatic ad impressions targeted towards EU and/or UK-based users, as measured by Pixalate.

## **Pixalate’s ****H1 2024 Apple App Store GDPR Violation Risk ****Report**** – Key Findings: **

- **380,000+ **EU and UK-based users’ personal data** **was shared in the ad bid stream** **by** **targeted advertising-enabled** **apps that did not have detected privacy policies during H1 2024.
- **1,384** Apple App Store-hosted apps:  
    - **did not have a detected privacy policy** during H1 2024, and 
    - **shared EU and UK-based users’ personal data** in the open programmatic advertising bid stream.
- Personal data shared in the open programmatic ad bid stream included **location data, IP address, and device identifiers (IDFVs/IDFAs)**, as measured by Pixalate: 
    - **842 (61%) **targeted advertising-enabled apps shared EU and UK-based users’ IDFAs/IDFVs** **in the open programmatic ad bid stream in H1 2024.
    - **330 (24%)** targeted advertising-enabled apps shared all three forms of personal data in the open programmatic ad bid stream during H1 2024.

By sharing users’ IDFAs/IDFVs with apps without detected privacy policies, Apple is likely failing to meet its Data Controller obligations to ensure that users’ device identifiers are handled with *integrity and confidentiality,* as per GDPR [Article 5(f)](https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679#d1e1807-1-1).

“Pixalate has undertaken this investigation to produce data insights and legal analyses concerning actual practices of app developers, websites and reputable app-hosting platforms to help users ascertain whether their personal data is actually processed with user privacy at the forefront,” said Yusra Kayani, Pixalate’s EMEA Director of Data Protection and Privacy. “It is a concerning realisation that the identified apps without detected privacy policies exist and operate within the Apple App Store ecosystem, yet Apple appears to lay dormant in taking action to identify and remove such apps that are likely violating GDPR provisions alongside Apple’s own developer licence agreements and App Store guidelines.”

## **Top 10 EU+UK Registered App Store-Hosted Apps Without Detected Privacy Policies Sharing Personal Data in the Ad Bid Stream**

| **Rank** | **Title** | **Developer** | **Developer Country** | **Est. No of EU+UK Users Impacted (H1 2024)** |
| --- | --- | --- | --- | --- |
| 1 | [LALIGA Fantasy 23-24](https://apps.apple.com/app/968915185) | Liga Nacional de Futbol Profesional | SPAIN | 79K (20%) |
| 2 | [Paint the Flag](https://apps.apple.com/app/6448735170) | Mobsmile Yazilim Hizmetleri Limited Sirketi | UNITED KINGDOM | 14K (4%) |
| 3 | [My Monster Pet: Train & Fight](https://apps.apple.com/app/6444027030) | traxnet ou | ESTONIA | 4K (1%) |
| 4 | [Führerschein ClickClickDrive](https://apps.apple.com/app/1435154541) | ClickClickDrive GmbH | GERMANY | 4K (0.96%) |
| 5 | [Dingbats - Between the lines](https://apps.apple.com/app/1252269368) | Romain Lebouc | FRANCE | 2K (0.53%) |
| 6 | [Handy Craft](https://apps.apple.com/app/1568269420) | Voodoo | FRANCE | 2K (0.51%) |
| 7 | [Freecell - move all cards to the top](https://apps.apple.com/app/567851353) | Brilliant Labs Limited | UNITED KINGDOM | 1K (0.34%) |
| 8 | [Crush the Monsters：Cannon Game](https://apps.apple.com/app/6444258258) | HEROCRAFT LTD | UNITED KINGDOM | 1K (0.3%) |
| 9 | [Closer – Actu et exclus People](https://apps.apple.com/app/317547865) | Reworld Media Magazines | FRANCE | 1K (0.29%) |
| 10 | [Tipping Point Blast! Coin Game](https://apps.apple.com/app/1471370760) | Two Way Media Ltd | UNITED KINGDOM | 1K (0.29%) |

 

Access the full H1 2024 GDPR Violation Risks Report – Apple App Store here. You will also receive the list of 1,384 App Store-hosted apps without detected privacy policies that are sharing EU and UK-based users’ personal data in the ad bid stream during H1 2024, as measured by Pixalate.

[![GDPR Violation Risks Report: Apple App Store](https://no-cache.hubspot.com/cta/default/2364596/6cddabb5-0644-4146-ba65-0e761b6817f8.png)](https://cta-redirect.hubspot.com/cta/redirect/2364596/6cddabb5-0644-4146-ba65-0e761b6817f8)

**About Pixalate**

Pixalate is the market-leading fraud protection, privacy, and compliance analytics platform for Connected TV (CTV) and Mobile Advertising. We work 24/7 to guard your reputation and grow your media value. Pixalate offers the only system of coordinated solutions across display, app, video, and CTV for better detection and elimination of ad fraud. Pixalate is an MRC-accredited service for the detection and filtration of sophisticated invalid traffic (SIVT) across desktop and mobile web, mobile in-app, and CTV advertising. [www.pixalate.com](https://c212.net/c/link/?t=0&l=en&o=3568931-1&h=899623499&u=https%3A%2F%2Fwww.pixalate.com%2F&a=www.pixalate.com)

***Disclaimer***

*The content of this press release, and the associated report – including all content set forth herein – reflects Pixalate’s opinions with respect to subject matter that Pixalate believes may be useful to the digital media industry, inclusive of advertisers, advertising technology companies, developers of mobile applications, professional advisors, non-governmental entities, and regulators. Pixalate is sharing this report’s data–and opinions relating thereto–not to impugn the standing or reputation of any entity, person, or app, but, instead, to report opinions and suggest trends pertaining certain apps available for download via the Apple App Store during the H1 2024 time period studied. Any data shared herein is grounded in Pixalate’s proprietary technology and compliance analytics, which Pixalate is continuously evaluating and updating. Any references to outside sources should not be construed as endorsements. Pixalate’s opinions are just that: opinions (i.e., they are neither facts nor guarantees). Pixalate's opinions regarding possible applicability of, legal obligations under, and compliance with the GDPR are for informational purposes only, and are not offered as legal advice. Nothing in this report: (i) is intended to constitute professional and/or legal advice; (ii) actually constitutes professional and/or legal advice; or (ii) sets forth a comprehensive or complete statement of the matters discussed or the law relating thereto.*

### Search Blog

Search

### Follow Pixalate

<https://twitter.com/pixalateinc> <https://www.linkedin.com/company/pixalate> <https://www.facebook.com/pixalate>

### Subscribe to our blog

*By entering your email address and clicking Subscribe, you are agreeing to our [Terms of Use ](https://www.pixalate.com/terms)and [Privacy Policy.](https://www.pixalate.com/privacypolicy)

Previous Story

[← Pixalate Releases Q2 2024 Global Mobile Device Market Share Report: Apple iPhone Leads Globally (51%), Followed by Samsung, Huawei, & Xiaomi](https://www.pixalate.com/blog/q2-2024-global-mobile-device-market-share-report)

[** ](https://www.pixalate.com/blog)

Next Story

[Pixalate's COPPA Manual Reviews: ‘Fish Out of Water!' →](https://www.pixalate.com/blog/app-review-series-fish-out-of-water)

## You May Also Like

These Stories on Mobile Apps

[![](https://www.pixalate.com/hubfs/Abandoned%20Mobile%20Apps%20Report%20-%20blog%20cover.png) ](https://www.pixalate.com/blog/pixalate-releases-may-2026-global-abandoned-mobile-apps-report)

[Mobile Apps](https://www.pixalate.com/blog/topic/mobile-apps)

### [Pixalate Releases May 2026 Global Abandoned Mobile Apps Report: “Draw In™” at the top on Apple App Store, “GUNSHIP BATTLE: Helicopter 3D” tops Google Play Store](https://www.pixalate.com/blog/pixalate-releases-may-2026-global-abandoned-mobile-apps-report)

 Jun 24, 2026 9:00:02 AM |

 3 min read

[![](https://www.pixalate.com/hubfs/Blog%20Media/2026%20Covers%20and%20Images/MONTHLY%20MOST%20COMMON%20MOBILE%20AD%20FRAUD%20TYPES%20GOOGLE%20-%20APPLE%20BLOG%20COVER.png) ](https://www.pixalate.com/blog/pixalates-may-2026-most-common-mobile-app-ad-fraud-types)

[Ad Fraud](https://www.pixalate.com/blog/topic/ad-fraud)

### [Pixalate Releases May 2026 Most Common Mobile App Ad Fraud Types: ‘High Risk Device ID’ Most Common Type Across Google Play Store (32%); ‘High Risk IP’ Most Common on Apple App Store (48%)](https://www.pixalate.com/blog/pixalates-may-2026-most-common-mobile-app-ad-fraud-types)

 Jun 9, 2026 9:00:00 AM |

 2 min read

[![](https://www.pixalate.com/hubfs/Blog%20Media/2026%20Covers%20and%20Images/MONTHLY%20TOP%20MOBILE%20AD%20FRAUD%20TYPES%20GOOGLE%20-%20APPLE%20BLOG%20COVER.jpg) ](https://www.pixalate.com/blog/pixalates-april-2026-most-common-mobile-app-ad-fraud-types)

[Ad Fraud](https://www.pixalate.com/blog/topic/ad-fraud)

### [Pixalate Releases April 2026 Most Common Mobile App Ad Fraud Types: ‘High Risk Device ID’ Most Common Type Across Google Play Store (28%); ‘High Risk IP’ Most Common on Apple App Store (23%)](https://www.pixalate.com/blog/pixalates-april-2026-most-common-mobile-app-ad-fraud-types)

 May 18, 2026 9:00:00 AM |

 2 min read

**

### Subscribe to our blog

*By entering your email address and clicking Subscribe, you are agreeing to our [Terms of Use ](https://www.pixalate.com/terms)and [Privacy Policy.](https://www.pixalate.com/privacypolicy)

![pixalate-logo-red-small](https://www.pixalate.com/hs-fs/hubfs/2018NewTemplate/pixalate-logo-red-small.png?width=208&name=pixalate-logo-red-small.png "pixalate-logo-red-small")

**

 By entering your email address and clicking Subscribe, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and [Privacy Policy](https://www.pixalate.com/privacypolicy)

Products

[Analytics](https://www.pixalate.com/products/analytics) [Blocking](https://www.pixalate.com/products/blocking) [Media Rating Terminal](https://www.pixalate.com/products/mrt) [Publisher Trust Indexes](https://www.pixalate.com/rankings/?group=app&reportId=publisherTrustIndex) [Seller Trust Indexes](https://www.pixalate.com/rankings/?group=app&reportId=publisherTrustIndex) [IoT Device Rankings](https://www.pixalate.com/rankings/?group=app&reportId=iotDeviceReach)

Resources

[Blog](https://blog.pixalate.com/) [Press](https://www.pixalate.com/press) [Careers](https://www.pixalate.com/jobs) [Team](https://info.pixalate.com/pixalate-leadership-team)

Contact

Email

[** sales@pixalate.com ](mailto:sales@pixalate.com)

[** privacy@pixalate.com ](mailto:privacy@pixalate.com)

US:

[** +1 888 749 2528 ](tel:+1%20888%20749%202528)

EU:

[** +44 (0)800 011 2050 ](tel:+44%20(0)800%20011%202050)

Slack:

[Join ATSAPI Slack Channel ](https://atsapi-pixalate.slack.com/join/shared_invite/zt-10dtow5cj-OEtlNr5yzJkrZMQUqcEEow#/shared-invite/email)

Offices

Global Offices

US

1775 Greensboro Station Place, Suite 425, McLean, VA 22102

UK

20 North Audley Street   
London, W1K 6WE, United Kingdom

EU

10 Earlsfort Terrace   
Dublin 2, D02 T380, Ireland

Singapore

10 Anson Road, #22-02 International Plaza, Singapore 079903

[![facebook](https://www.pixalate.com/hubfs/footer/icons/facebook.png) ](https://www.facebook.com/pixalate) [![x](https://www.pixalate.com/hubfs/footer/icons/twitter-x.png) ](https://twitter.com/pixalateinc) [![linkedin](https://www.pixalate.com/hubfs/footer/icons/linkedin.png) ](https://www.linkedin.com/company/pixalate) ![wechat](https://www.pixalate.com/hubfs/footer/icons/wechat.png) [![slack](https://www.pixalate.com/hubfs/footer/icons/slack.png) ](https://atsapi-pixalate.slack.com/join/shared_invite/zt-10dtow5cj-OEtlNr5yzJkrZMQUqcEEow#/shared-invite/email)

[Terms of Use](https://www.pixalate.com/terms) [Privacy Policy](https://www.pixalate.com/privacypolicy) [GDPR Compliance](https://www.pixalate.com/gdpr) Disclaimer

Copyright © 2025 Pixalate

[Back to top **](https://www.pixalate.com/blog/h1-2024-gdpr-violation-risks-report-apple-app-store#)

# Disclaimer

 Disclaimer: The content of this page reflects Pixalate’s opinions with respect to the factors that Pixalate believes can be useful to the digital media industry. Any proprietary data shared is grounded in Pixalate’s proprietary technology and analytics, which Pixalate is continuously evaluating and updating. Any references to outside sources should not be construed as endorsements. Pixalate’s opinions are just that - opinion, not facts or guarantees.

 Per the MRC, “'Fraud' is not intended to represent fraud as defined in various laws, statutes and ordinances or as conventionally used in U.S. Court or other legal proceedings, but rather a custom definition strictly for advertising measurement purposes. Also per the MRC, “‘Invalid Traffic’ is defined generally as traffic that does not meet certain ad serving quality or completeness criteria, or otherwise does not represent legitimate ad traffic that should be included in measurement counts. Among the reasons why ad traffic may be deemed invalid is it is a result of non-human traffic (spiders, bots, etc.), or activity designed to produce fraudulent traffic.”

**

**

*By clicking Download and entering your email address, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and have read and acknowledge our [Privacy Policy](https://www.pixalate.com/hubfs/2024-08-20_Pixalate_Privacy_Policy.pdf).

*Copyright © 2025 Pixalate** *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

*

×

## Subscribe to the Pixalate Blog

The first step in ad fraud prevention.

Loading...

 By entering your email address and clicking Submit, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and [Privacy Policy](https://www.pixalate.com/privacypolicy).

![pixalate-logo-white](https://www.pixalate.com/hubfs/Blog_V2_08_26_2016/logo/Pixalate_Logo_WHITE.png)

##### Contact Us12

Loading...

![pixalate-logo-white](https://www.pixalate.com/hubfs/Blog_V2_08_26_2016/logo/Pixalate_Logo_WHITE.png)

##### Download GSTI

Loading...

Schedule your demo today

Please complete all fields

Loading...

By entering your email address and clicking Submit, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and [Privacy Policy](https://www.pixalate.com/privacypolicy).

*

* *

*

*