Google Data Safety Form

Last updated on 28 September 2022 by William Blesch (Legal and data protection research writer at TermsFeed)

Google Data Safety Form

Since May of 2021, Google requires all apps listed in the Google Play Store to detail how they handle user data in the "Data Safety Section." App developers will have to detail their data use in a series of bullet points that users see when they click on an app to update or install it.

This article will look at Google's requirements, who it applies to, what types of data must be disclosed, and how to fill in Google's Data Safety Form.

Our Privacy Policy Generator makes it easy to create a Privacy Policy for your business. Just follow these steps:

  1. At Step 1, select the Website option or App option or both.
  2. TermsFeed Privacy Policy Generator: Create Privacy Policy - Step 1

  3. Answer some questions about your website or app.
  4. TermsFeed Privacy Policy Generator: Answer questions about website - Step 2

  5. Answer some questions about your business.
  6. TermsFeed Privacy Policy Generator: Answer questions about business practices  - Step 3

  7. Enter the email address where you'd like the Privacy Policy delivered and click "Generate."

    TermsFeed Privacy Policy Generator: Enter your email address - Step 4

    You'll be able to instantly access and download your new Privacy Policy.



Who Needs to Complete the Data Safety Form in the Play Console?

If you're an app developer and want your app on the Google Play Store, you must complete the data safety form.

This includes apps that are on:

  • Internal
  • Closed
  • Open, or
  • Production tracks

Even app developers who do not collect user data must complete this form. You can use your app's Privacy Policy and completed form to indicate that no user data has been shared or collected.

Requirements for Completing the Data Safety Form

Requirements for Completing the Data Safety Form

You will need to provide information disclosing how your app collects data, whether you share data, how you handle data in your possession, and more. You'll also need to commit to following Google's Families policy (if applicable) and announce whether your app has undergone an independent, third-party security review.

Let's look closer at each of these requirements.

Collection of Data

According to Google, if your app transmits data from off a user's device, that's the definition of "collect."

If your app transmits data or behaves in the following ways, you must disclose it:

  • If user data is sent off the device by SDKs and/or libraries used by your app, regardless of whether it is transmitted to you directly or to a third-party server
  • If your app controls the code or behavior delivered through a webview (an exception is a webview in which users navigate the open web)
  • If your app transmits data off a user device and is processed ephemerally, it must be disclosed in your form response. However, if that data is stored in the memory alone, and is kept only as long as needed to process a specific request in real-time, and isn't used for anything else, then it doesn't have to be disclosed
  • If your app pseudonymously collects data and it can reasonably be re-associated with a user, then you must disclose that fact

Data that isn't within the scope of collection can be seen in this screenshot from Google's Support pages as seen below.

Google Play Console Help: Provide information for Google Play's Data safety section - Not in scope for data collection clause

Data Sharing

When it comes to data sharing, Google distinguishes between "First Parties," which are typically the app developers and organizations that list apps on the Google Play Store, and "Third-Parties," which are any organizations that "aren't the First Party or its service providers."

Now, if your app collects data and then transmits it to a third party, you are sharing that data. In fact, any data transferred in the following ways is considered "sharing data," according to Google.

For example:

  • If your server takes data collected from your app and transfers it to a third-party server
  • Even if all transfers take place on the user's device, it's still considered sharing data if your app transfers data to a third-party app, and you must disclose that fact in your data safety section
  • If your app transfers data to a third party through a library or SDK included in your app
  • If your app transfers data through a webview to a third party. However, as in collecting data, if users are navigating the open web from a webview, you don't need to disclose any data sharing that may occur

In the screenshot below, Google clarifies what types of sharing are exempt from the need for disclosure:

Google Play Console Help: Provide information for Google Play's Data safety section - Data Sharing - Types of transfers not needed to be disclosed as sharing clause

Handling Data

If you allow all users, regardless of region or device, to provide your app with data (in other words, you give them a way to opt-out of data collection), you can state that fact in the data safety form.

Additionally, this can apply to all data types you collect or only some. For instance, if you allow users to opt-out of certain kinds of data collection but not others, you'll need to specify each type and whether it is optional or required.

For instance, Google specifically states that "If your app's primary functionality requires the data type, you should declare that data as required."

Examples of optional data include:

Google Play Console Help: Provide information for Google Play's Data safety section - Examples of optional data clause

Other Disclosures

Some app developers go above and beyond the call of duty. Google recognizes that fact and allows you to highlight your security and privacy practices in the data safety section.

For instance, you could emphasize that you encrypt all data in transit. End-to-end encryption is actually a selling point for some. If your app gives users a way to request data deletion, you could also highlight that fact.

Families Policy

If your app targets kids or you've chosen to opt into Google Play's "Designed for Families" program, then you have to follow the Families Policy requirements.

After ensuring that your app meets all Families Policy requirements, you have the option of displaying a badge in your data safety section, which states that you've "Committed to follow the Play Families Policy."

Independent Security Review

An independent security review of your app is optional right now, but it's clear that Google favors apps that obtain one.

After undergoing a third-party review, you can then declare in your app's Play Store listing that you've undergone a review for compliance with "an independent global security standard."

Remember that a review like this is optional and is not affiliated with Google in any way. Further, it's a security review that you'll have to pay for, and you'll be held responsible by Google for ensuring that all your declarations in this regard are truthful, complete, and accurate.

Data Types that Must be Disclosed in the Data Safety Form

Data Types that Must be Disclosed in the Data Safety Form

App developers will have to disclose what data they collect, use or share such as location data, personal information, financial information, health information, messages, photos, videos, audio files, calendar events, contacts, files, documents, app activity and more.

Almost all of these data types fall under the same categories listed in major data and privacy protection laws, such as Europe's General Data Protection Regulation (GDPR) and California's Consumer Privacy Act (CCPA).

With that said, here are the categories and data types about which you need to be aware.

Location

There are two data types under the location category. They are:

  • Approximate location, and
  • Precise location

Personal Information

Many apps collect personal information, such as:

  • Name
  • Email address
  • Personal identifiers (account name, account ID, account number)
  • Address (mailing address or home address)
  • Phone number
  • Race and ethnicity
  • Sexual orientation
  • Gender identity
  • Political affiliation
  • Religious affiliation
  • Other personal information (date of birth, veteran status, disability status)

If your app collects data in this category, it must be disclosed.

Financial Information

If your app collects financial information in any of the categories below, you'll need to disclose it:

  • Credit card number
  • Debit card number
  • Bank account number
  • Purchase history
  • Credit history
  • Credit score
  • Any other financial information

Health Information

If your app collects the data within the following health categories, you need to disclose it:

  • Medical records or symptoms
  • Data on exercise activity
  • Other physical activity

Messages

If your app collects data from or on emails, SMS or MMS messages, or other in-app messages, you must disclose that fact.

Photos or Videos

If your app collects data from or on a user's photos or videos, you must disclose that fact.

Audio Files

If your app collects data from or the following types of audio files, you must disclose it:

  • Voice recordings
  • Sound recordings
  • Music files
  • Any other user-provided or user-created audio files

Calendar and Contacts

If your app collects data from a user's calendar or contacts, you must disclose that fact. For example, you'll have to be transparent about any data collection on:

  • Calendar events
  • Event notes
  • Event attendees
  • Contact names
  • Message history
  • Social graph information
  • Call history

Files and Documents

If your app collects data from a user's files or documents such as text or file names, you must disclose that fact.

App Activity

You must disclose the collection of information about user behavior while using your app. For example, you'll need to report it if you collect data on:

  • Page views
  • Taps in-app
  • In-app search history
  • Installed apps
  • Other user-generated content (e.g., bios or notes)
  • Other user activities (e.g., gameplay or likes)

Web Browsing

If your app collects data on a user's browsing habits or websites visited, you need to disclose that fact.

App Information and Performance

If your app keeps records of things such as crash logs, diagnostics, or other app performance data, you need to disclose that fact.

Device and Other Identifiers

If your app collects data on the type of user device on which it is installed or other identifiers, you need to report that fact. For example, you'll need to disclose it if your app collects data on:

  • IMEI numbers
  • MAC addresses
  • Widevine Device IDs
  • Firebase installation ID
  • Advertising identifiers

Data Purposes

Google requires app developers to be transparent about why they are collecting data. If you collect data for the following reasons, you must disclose that fact:

  • App functionality
  • Analytics
  • Developer communications
  • Advertising or marketing
  • Fraud prevention, security, and compliance
  • Personalization
  • Account management

How to Fill In the Google Data Safety Form For Your App

Before you complete the Data Safety form, make sure that you:

  1. Have a Privacy Policy URL for your app
  2. Have completed the App Content > Ads form
  3. Have completed the App content > App access form
  4. Have completed the App content > Targeted audience form

Here are the full instructions:

  1. Log in to your Google Play Console account.
  2. In the left menu, click on All apps and then choose the app you wish to work with:
  3. TermsFeed Google Play Console: All apps: TermsFeed app selected

  4. In the left menu, scroll to the Policy section and click on App content:
  5. TermsFeed Google Play Console: Dashboard - App content highlighted

  6. Follow the "To do" list under the App content section to make sure your app complies with Google policies.

    As mentioned above: Add a Privacy Policy URL, then complete the Ads form, the App Access form and the Targeted Audience form. Then, continue with the Data Safety form.

  7. Click on the Start button under the Privacy Policy section:
  8. TermsFeed Google Play Console: App content - Privacy Policy with Start button  highlighted

  9. On this page, you'll see the field for adding the Privacy Policy URL for your app:

    TermsFeed Google Play Console: App content - Privacy Policy URL field button  highlighted

    If you do not have a Privacy Policy, you can use our Privacy Policy Generator and create it within minutes. TermsFeed will host your Privacy Policy URL for free.

  10. Once you have the Privacy Policy created by TermsFeed, click Copy from the Link to your Privacy Policy section to copy the URL:

  11. TermsFeed Generators App: Privacy Policy Download Page - Link to hosted Privacy Policy URL copy option highlighted

  12. Paste the Privacy Policy URL in the field box:
  13. TermsFeed Google Play Console: App content - Privacy Policy URL with paste option button highlighted

  14. Click Save:
  15. TermsFeed Google Play Console: App content - Privacy Policy URL added with Save button highlighted

  16. Go back to the App content section and click on the Start button under the Ads section:
  17. TermsFeed Google Play Console: App content - Ads with Start button highlighted

  18. Answer if your app displays ads or not. Click on the Save button to continue:
  19. TermsFeed Google Play Console: App content - Ads question with Save button highlighted

  20. Go back to the App content section and click on the Start button under the App access section:
  21. TermsFeed Google Play Console: App content - App access with Start button highlighted

  22. Answer if all your app functionality is available to users or it is restricted in some way. Click Save to continue:
  23. TermsFeed Google Play Console: App content - App access question with Save button highlighted

  24. Go back to the App content section and click on the Start button under Targeted audience and content section:
  25. TermsFeed Google Play Console: App content - Targeted audience and content with Start button highlighted

  26. Select the targeted age groups of your app and click on Next to continue:
  27. TermsFeed Google Play Console: App content - Targeted audience and content with Age of targeted group of app question with Next button highlighted

  28. At the Store presence step, click on Next to continue:
  29. TermsFeed Google Play Console: App content - Targeted audience and content - Step 4 Store presence with Next button highlighted

  30. Click on the Save button to continue. You can review your answers under the Summary step.
  31. TermsFeed Google Play Console: App content - Targeted audience and content - Summary step and Save button highlighted

  32. Now it's time to fill in the Data safety form.

    Go back to the App content section, scroll to the Data Safety section and click on the Start button:

  33. TermsFeed Google Play Console: App content - Data Safety with Start button  highlighted

  34. When the Data Safety page opens, click Next at the bottom of the page to start the form:
  35. TermsFeed Google Play Console: App content - Data Safety step 1 Overview with Next button  highlighted

  36. Start answering the questions based on your app and business model.

    For example, under the Data collection and security section, answer the question with Yes or No. Click the Next button at the bottom of the page to continue:

  37. TermsFeed Google Play Console: App content - Data Safety - Step 2 - Data collection and security with Next button highlighted

  38. Under the Data types section, answer the question about the data that is collected or shared with third parties by your app. When done, click Next at the bottom of the page:
  39. TermsFeed Google Play Console: App content - Data Safety - Step 3 - Data types with Next button highlighted

  40. Under the Data usage and handling section, answer the question about how data is used and handled. When done, click Next at the bottom of the page:
  41. TermsFeed Google Play Console: App content - Data Safety - Step 4 - Data usage and handling with Next button highlighted

  42. You're almost done. Preview the answers and click on the Submit button:
  43. TermsFeed Google Play Console: App content - Data Safety - step 5 - Preview highlighted

  44. You're done.

What Happens After You Submit the Data Safety Form?

What Happens After You Submit the Data Safety Form?

After you submit the Data Safety Form, Google will review the information provided in order to ensure that you've appropriately disclosed all necessary details. If Google finds no issues, then your Play Store application or update can continue through its normal process and you don't have to do anything extra.

Your Data Safety Form will need to be complete and accurate, disclosing all relevant data collection and sharing practices. This will include apps that don't collect user data.

Summary

Google's Data Safety requirement helps users will better understand how an app handles their information before downloading it from the Play Store.

Developers will have to ensure that they disclose all relevant information required by Google and that all declarations are truthful, complete, and accurate. App developers must be transparent about what kind of data their app collects (e.g., personal information such as name and email address, contacts, location, financial information, and more):

  • Whether the data is required or optional to use the app
  • Whether the data is encrypted during transit
  • Whether the app was independently reviewed for conformance to a global security standard

Create Privacy Policy, Terms & Conditions and other legal agreements in a few minutes. Free to use, free to download.

Get started today ⇢

Screenshot of TermsFeed Generator

William Blesch

William Blesch

Legal and data protection research writer at TermsFeed

This article is not a substitute for professional legal advice. This article does not create an attorney-client relationship, nor is it a solicitation to offer legal advice.