Beyond GDPR: Examining Disclosure Gaps in Mobile AR Privacy Policies under U.S. State Privacy Laws

2026-07-27Cryptography and Security

Cryptography and Security
AI summary

The authors studied privacy policies of mobile augmented reality (MAR) apps, focusing on how well these policies follow different U.S. state privacy laws. They created a large dataset of MAR apps and their privacy policies, then developed a system to check if the policies meet specific legal requirements. Their analysis found that many policies are missing important disclosures, meaning they don't fully explain how sensitive data is handled. The authors provided tools and data to help improve future privacy compliance checks.

Mobile Augmented Reality (MAR)Privacy policyU.S. state privacy lawsGeneral Data Protection Regulation (GDPR)Data disclosureAutomated auditingSpatial mapsBiometricsPrivacy complianceGoogle Play Store
Authors
Hong Chen, Xueling Zhang, Hong-Ning Dai, Huashan Chen, Qin Yu, Tiange Xie, Duohe Ma, Feng Liu
Abstract
Mobile Augmented Reality (MAR) apps can collect and process highly sensitive data such as spatial maps and biometrics, yet their privacy policies remain largely understudied. Prior audits of app privacy policies have typically focused on a single legal framework, such as the GDPR. Meanwhile, 20 U.S. states have comprehensive privacy laws in effect, creating a fragmented and rapidly evolving set of privacy policy obligations. To date, no study has systematically audited privacy policies against this emerging body of state-level legislation. In this paper, we present the first large-scale audit of MAR privacy policies under U.S. state privacy laws. We construct a dataset covering the MAR ecosystem, including 8,013 Google Play MAR app metadata records worldwide, and a U.S.-based subset with 6,620 APKs and 6,426 privacy policy files. We further derive an auditable disclosure taxonomy with 5 baseline requirements, 10 triggered requirements, and 4 logic chains, and build a validated four-stage automated pipeline that produces traceable, evidence-grounded disclosure judgments. Our audit reveals widespread disclosure gaps: 44.62\% of audited policies exhibit severe disclosure omissions, with each missing more than eight requirements, and four privacy-policy requirements have violation rates above 90\%. These findings suggest that MAR privacy disclosures are not keeping pace with the growing complexity of U.S. state privacy regulation. We release our dataset, taxonomy, and auditing pipeline to support future research on scalable privacy compliance auditing.