Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement states that Google may collect network connection information, potentially malicious URLs, operating system data, and information about all applications installed on the user's device for malware protection purposes. Even if users disable certain protection features, the terms state that information about installed applications may continue to be analyzed for security issues without being sent to Google.
This analysis describes what Google Play Store's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses collection of device-level data including the full list of installed applications and network connection information, not limited to apps installed through Google Play, for security analysis purposes. Under this clause, some level of application inventory analysis continues even when users disable certain protection features in device settings.
Interpretive note: The precise scope of data collected and the distinction between local analysis and data transmission to Google is disclosed at a high level but not with full technical specificity, creating some uncertainty about the exact data processing practices authorized.
Added explicit language about Google's ability to warn users and uninstall/block unsafe apps, replacing vague continuation language.
View full change record →Under this provision, Google may collect information about all applications installed on a user's device (including those from non-Google Play sources) and network connection data for malware protection purposes. Disabling certain protection features in device settings does not entirely stop analysis of installed applications; the terms state that local analysis may continue without data being transmitted to Google.
How other platforms handle this
The right to notice. You have the right to be notified which categories of Personal Data are being collected and the purposes for which the Personal Data is being used.
In certain circumstances, the right to data portability, which means that you can request that we provide certain Personal Data we hold about you in a machine-readable format
If you want to see what information we have collected about you, you can request a copy of your data in the Data & Privacy section of your User Settings. You should receive your data packet within 30 days.
Monitoring
Google Play Store has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Để bảo vệ bạn khỏi phần mềm độc hại từ bên thứ ba, URL độc hại và các sự cố bảo mật khác, Google có thể nhận thông tin về kết nối mạng trên Thiết bị của bạn, các URL có thể độc hại, hệ điều hành và các ứng dụng được cài đặt trên Thiết bị của bạn thông qua Google Play hay từ các nguồn khác. Google có thể cảnh báo bạn nếu Google cho rằng một ứng dụng hay URL không an toàn hoặc Google có thể gỡ bỏ hay chặn việc cài đặt ứng dụng đó trên Thiết bị của bạn nếu Google biết ứng dụng đó gây hại cho thiết bị, dữ liệu hoặc người dùng. Bạn có thể chọn vô hiệu hóa một số tính năng bảo vệ này trong cài đặt trên Thiết bị của mình. Tuy nhiên, Google có thể tiếp tục nhận thông tin về các ứng dụng được cài đặt qua Google Play và các ứng dụng được cài đặt trên Thiết bị của bạn từ các nguồn khác có thể tiếp tục được phân tích về các vấn đề bảo mật mà không cần gửi thông tin đến Google.Excerpt from Google Play Store's Google Play Terms
(1) REGULATORY LANDSCAPE: This provision engages GDPR (for EU users) regarding the lawful basis for collecting device-level data including installed application inventories, which may constitute personal data under GDPR. The ePrivacy Directive (and national implementations) may apply to the collection of information from terminal equipment. In the US, the FTC Act is relevant to the adequacy of disclosure and consent for device monitoring practices. (2) GOVERNANCE EXPOSURE: Medium. The collection of a full device application inventory (not limited to Google Play apps) is a broad data collection practice. The disclosure that analysis may continue locally even after disabling certain features is operationally relevant but may not fully satisfy user expectations regarding the scope of data collection. (3) JURISDICTION FLAGS: EU and EEA users have heightened exposure under GDPR and ePrivacy frameworks. The collection of OS and application data from devices may require a specific legal basis beyond contractual necessity, particularly for non-Google Play sourced applications. California users have CCPA rights regarding the collection and use of device information. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise MDM deployments should evaluate whether the device-level data collection authorized by this provision is consistent with organizational data protection policies, particularly where employee devices are enrolled in Google Play. (5) COMPLIANCE CONSIDERATIONS: Data protection officers should review whether the disclosure of full application inventory collection in the ToS satisfies GDPR transparency and lawful basis requirements. The distinction between data transmitted to Google and locally analyzed data should be assessed for completeness of the privacy disclosure.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision discloses collection of device-level data including the full list of installed applications and network connection information, not limited to apps installed through Google Play, for security analysis purposes. Under this clause, some level of application inventory analysis continues even when users disable certain protection features in device settings.
Under this provision, Google may collect information about all applications installed on a user's device (including those from non-Google Play sources) and network connection data for malware protection purposes. Disabling certain protection features in device settings does not entirely stop analysis of installed applications; the terms state that local analysis may continue without data being transmitted to Google.
ConductAtlas has identified this type of provision across 294 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Google Play Store.