Apple · Apple App Store Review Guidelines · View original document ↗

App Privacy Label Disclosure Requirement

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Apple Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Developers must publish an accurate summary of all data their app collects, including data gathered by any third-party tools embedded in the app, and this information appears on the App Store listing page as a privacy nutrition label.

This analysis describes what Apple's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a disclosure mechanism that consumers can use to assess an app's data practices before downloading, covering identifiers, location data, usage data, contact information, and other categories as disclosed by the developer.

Consumer impact (what this means for users)

The App Privacy label on each App Store listing discloses what categories of data the app collects and how they are used, including data from third-party SDKs embedded in the app; the accuracy of these disclosures depends on the developer's compliance with the guideline's requirement to keep labels current and complete.

How other platforms handle this

Groq Medium

We use your information for the following purposes: ... In accordance with applicable legal requirements, for advertising and marketing purposes, including to send you information about products or services that may be of interest to you...

Activision Medium

YOU MUST BE AND HEREBY AFFIRM THAT YOU ARE AN ADULT OF THE LEGAL AGE OF MAJORITY IN YOUR COUNTRY OR STATE OF RESIDENCE. If you are under the legal age of majority, your parent or legal guardian must consent to this agreement.

ADP Medium

If you are a California resident, you may have certain rights under the California Consumer Privacy Act (CCPA). These rights may include: the right to know about personal information collected, disclosed, or sold; the right to delete personal information collected from you; the right to opt-out of t...

See all platforms with this clause type →

Monitoring

Apple has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
All new apps and app updates must include accurate privacy information in App Store Connect that will be displayed on your App Store product page. Apps must clearly describe new privacy-related features. You must keep this information up to date. Privacy labels should reflect your app's data collection and use practices including data collected by third-party partners, SDKs, and analytics tools used in your app.

— Excerpt from Apple's Apple App Store Review Guidelines

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: The App Privacy label requirement engages with GDPR transparency obligations (enforced by EU data protection authorities) and CCPA disclosure requirements (enforced by the California Attorney General and California Privacy Protection Agency). The FTC Act's prohibition on unfair or deceptive practices is relevant if labels are inaccurate or incomplete. Developers must ensure that third-party SDK data collection is accurately reflected, as the guidelines place responsibility on the developer for the entire app's disclosures. GOVERNANCE EXPOSURE: High. Inaccurate or incomplete privacy labels expose developers to both Apple enforcement action (rejection, removal) and regulatory enforcement by privacy authorities who may treat label inaccuracies as deceptive disclosures. The requirement to include third-party SDK practices significantly expands the scope of what must be disclosed and audited. JURISDICTION FLAGS: EU developers must ensure labels satisfy GDPR transparency requirements, which may require more granular disclosure than Apple's label categories alone provide. California developers face CCPA-specific disclosure obligations that may require supplemental privacy notices beyond what the App Privacy label covers. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams integrating third-party SDKs should require data processing agreements and data practice disclosures from SDK vendors sufficient to complete accurate privacy labels. Failure to obtain this information from vendors may result in inaccurate labels and associated compliance exposure. COMPLIANCE CONSIDERATIONS: Legal and compliance teams should implement a recurring audit process for App Privacy labels covering all embedded third-party SDKs, triggered at each app update submission. Data mapping documentation should be maintained to substantiate label accuracy in the event of regulatory inquiry or Apple review.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over deceptive practices and has examined the accuracy of app privacy disclosures under consumer protection frameworks
    File a complaint →

Applicable regulations

EU AI Act
European Union
BIPA
Illinois, USA
CCPA/CPRA
California, USA
COPPA
United States Federal
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
HIPAA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
TCPA
United States Federal
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Apple App Store Review Guidelines
Entity
Apple
Document last updated
May 5, 2026
Tracking information
First tracked
April 28, 2026
Last verified
May 12, 2026
Record ID
CA-P-011497
Document ID
CA-D-00025
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
307db15d06f03003277f88a1476a1308e92cc7cba75906b4fac341d1054f5040
Analysis generated
April 28, 2026 08:36 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Apple
Document: Apple App Store Review Guidelines
Record ID: CA-P-011497
Captured: 2026-04-28 08:36:55 UTC
SHA-256: 307db15d06f03003…
URL: https://conductatlas.com/platform/apple/apple-app-store-review-guidelines/app-privacy-label-disclosure-requirement/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Apple's App Privacy Label Disclosure Requirement clause do?

This provision establishes a disclosure mechanism that consumers can use to assess an app's data practices before downloading, covering identifiers, location data, usage data, contact information, and other categories as disclosed by the developer.

How does this clause affect you?

The App Privacy label on each App Store listing discloses what categories of data the app collects and how they are used, including data from third-party SDKs embedded in the app; the accuracy of these disclosures depends on the developer's compliance with the guideline's requirement to keep labels current and complete.

Is ConductAtlas affiliated with Apple?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Apple.