The agreement states that Google may collect network connection information, potentially malicious URLs, operating system data, and information about all applications installed on the user's device for malware protection purposes. Even if users disable certain protection features, the terms state that information about installed applications may continue to be analyzed for security issues without being sent to Google.
This analysis describes what Google Play Store's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses collection of device-level data including the full list of installed applications and network connection information, not limited to apps installed through Google Play, for security analysis purposes. Under this clause, some level of application inventory analysis continues even when users disable certain protection features in device settings.
Interpretive note: The precise scope of data collected and the distinction between local analysis and data transmission to Google is disclosed at a high level but not with full technical specificity, creating some uncertainty about the exact data processing practices authorized.
The updated terms establish two new financial obligations for subscription users. First, Google may charge your payment method up to 48 hours before the start of a billing period, rather than 24 hours as previously stated. Second, the revised terms now explicitly state that if a subscription charge fails and you have not cancelled, you remain responsible for the uncollected amount, and Google may attempt to charge a backup payment method. This may alter your billing dates and the timing of when you are billed each period. Additionally, users are now explicitly liable for any background data fees incurred by Google system services and content updates, including when the device screen is locked. You can review your subscription settings in Google Play to monitor billing schedules and update payment methods.
View change record →Added explicit language about Google's ability to warn users and uninstall/block unsafe apps, replacing vague continuation language.
View full change record →Under this provision, Google may collect information about all applications installed on a user's device (including those from non-Google Play sources) and network connection data for malware protection purposes. Disabling certain protection features in device settings does not entirely stop analysis of installed applications; the terms state that local analysis may continue without data being transmitted to Google.
How other platforms handle this
to lodge a complaint with the data protection authority in your jurisdiction.
You can always contact your local data protection authority if you have concerns regarding your rights under local law.
To stop us collecting your location information, you can update your device settings, stop using the Service, or uninstall our mobile apps.
"Để bảo vệ bạn khỏi phần mềm độc hại từ bên thứ ba, URL độc hại và các sự cố bảo mật khác, Google có thể nhận thông tin về kết nối mạng trên Thiết bị của bạn, các URL có thể độc hại, hệ điều hành và các ứng dụng được cài đặt trên Thiết bị của bạn thông qua Google Play hay từ các nguồn khác. Google có thể cảnh báo bạn nếu Google cho rằng một ứng dụng hay URL không an toàn hoặc Google có thể gỡ bỏ hay chặn việc cài đặt ứng dụng đó trên Thiết bị của bạn nếu Google biết ứng dụng đó gây hại cho thiết bị, dữ liệu hoặc người dùng. Bạn có thể chọn vô hiệu hóa một số tính năng bảo vệ này trong cài đặt trên Thiết bị của mình. Tuy nhiên, Google có thể tiếp tục nhận thông tin về các ứng dụng được cài đặt qua Google Play và các ứng dụng được cài đặt trên Thiết bị của bạn từ các nguồn khác có thể tiếp tục được phân tích về các vấn đề bảo mật mà không cần gửi thông tin đến Google.Excerpt from Google Play Store's Google Play Terms
(1) REGULATORY LANDSCAPE: This provision engages GDPR (for EU users) regarding the lawful basis for collecting device-level data including installed application inventories, which may constitute personal data under GDPR.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision discloses collection of device-level data including the full list of installed applications and network connection information, not limited to apps installed through Google Play, for security analysis purposes. Under this clause, some level of application inventory analysis continues even when users disable certain protection features in device settings.
Under this provision, Google may collect information about all applications installed on a user's device (including those from non-Google Play sources) and network connection data for malware protection purposes. Disabling certain protection features in device settings does not entirely stop analysis of installed applications; the terms state that local analysis may continue without data being transmitted to Google.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Google Play Store.