Mobile Privacy and Business-to-Platform Dependencies: An Analysis of SEC Disclosures

29 Pages Posted: 19 Mar 2018 Last revised: 1 May 2019

See all articles by Ronan Ó Fathaigh

Ronan Ó Fathaigh

University of Amsterdam - Institute for Information Law (IViR)

Joris van Hoboken

University of Amsterdam

N.A.N.M. van Eijk

affiliation not provided to SSRN

Date Written: March 16, 2018


Activision Blizzard, Inc., which acquired Candy Crush Saga for $5.8 billion in 2016, sounded a warning in its latest filings with the Securities and Exchange Commission (SEC), about its dependency on mobile platforms. If these platforms would be required to change "how the personal information of consumers is made available to developers, our business could be negatively impacted." This paper seeks to systematically examine the dependence of mobile apps on mobile platforms for the collection and use of personal information. The paper discusses how app business models are shaped by governance of user data by mobile platforms, in order to reflect on the role of platforms in privacy regulation more generally. The paper is based upon a study examining privacy and data-related disclosures filed by public companies with the SEC, which we anticipate producing new and unique insights into the data practices and data-related aspects of the business models of popular mobile apps. Many of the companies behind popular apps have been private companies with closed books, and a full understanding of their data collection practices and business models has been difficult. However there have recently been a number of initial public offerings (IPOs) by major mobile app companies, and a flurry of acquisitions by public companies. This development means that many mobile app companies are required to make certain disclosures to the SEC. These disclosure requirements include the most significant "risk factors" associated with a company's business, including relating to data collection, data privacy, personal information, and role of mobile platforms. This study shows how an examination of SEC disclosures can be uniquely illuminating for communications policy and can provide a new insight into mobile privacy. A preliminary analysis we conducted when designing this study revealed that SEC disclosures by the largest mobile app companies shed light on the gatekeeping role mobile platforms perform in terms the collection and use of personal information. SEC filings can also reveal information on a mobile app company's data practices, and the role user data analytics play in its business model. The study we will first select public companies that predominantly operate their business, or important parts of their business, as an app in the mobile app environment. Second, a set of specific issues will be analyzed, including collection and use of personal information, use of data analytics software on mobile devices, and the role of mobile platforms in the collection and use of personal information, and The SEC filings over a period will be examined, to discover whether data practices and risks have changed over time. Finally, the findings will be discussed having regard to privacy policies of the respective companies, to determine any differences, and discuss the relevance of both SEC disclosures and privacy policies for transparency purposes. The paper will add to the scholarship on privacy disclosures and builds upon recent research on cybersecurity disclosures and SEC filings. However, scholars have not yet examined SEC disclosures concerning data privacy in mobile app ecosystems or used SEC filings to look at business-to-platform dependencies.

Keywords: Mobile platforms, mobile apps, data privacy, transparency, securities regulation

Suggested Citation

Ó Fathaigh, Ronan and van Hoboken, Joris V. J. and van Eijk, N.A.N.M., Mobile Privacy and Business-to-Platform Dependencies: An Analysis of SEC Disclosures (March 16, 2018). TPRC 46: The 46th Research Conference on Communication, Information and Internet Policy 2018, Available at SSRN:

Ronan Ó Fathaigh (Contact Author)

University of Amsterdam - Institute for Information Law (IViR) ( email )

Nieuwe Achtergracht 166
Amsterdam, 1000 BA

Joris V. J. Van Hoboken

University of Amsterdam ( email )

Spui 21
Amsterdam, 1018 WB

N.A.N.M. Van Eijk

affiliation not provided to SSRN

Do you have negative results from your research you’d like to share?

Paper statistics

Abstract Views
PlumX Metrics