App rejected: sharing data with third parties
Sharing data without disclosing it, or without a legal ground for it, falls under 5.1.2 and is one of the harder rejections to argue with.
What the rejection means
Sharing data without disclosing it, or without a legal ground for it, falls under 5.1.2 and is one of the harder rejections to argue with.
The usual causes
- An SDK sends identifiers you never mentioned.
- Analytics runs before any consent where consent is required.
- The policy lists no processors at all.
What to change
List every SDK and where it sends data, get consent before anything non-essential runs, and name each processor in the policy.
Before you resubmit
- Open every URL you entered in a private window.
- Read the reviewer's message again and answer the specific point, not the general topic.
- Reply in Resolution Center saying what you changed and where to see it.
Keeping it true after launch
A legal page stops being true the moment the product moves past it, usually by adding a payment provider, an analytics SDK or a sign-in. No store re-checks your pages against your build, so the drift is yours to notice.
- Re-read it whenever you add a dependency that sees user data.
- Re-check what loads on the page after any change: the cookie notice and the policy have to agree.
- Keep the URL stable. Changing where a policy lives breaks every listing that points at it.
Common questions
How long does a resubmission take?
Usually the same as a first review. Answering the exact point raised, with a link, is what shortens it.
Can I argue a rejection?
You can, and sometimes you should. It works when the reviewer has misread something and you can show it in one sentence with a link. It rarely works as a general objection.
