• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechPrivacy

Apple’s Routing of User Data to Google Could Be Breaking EU Privacy Law

By
David Meyer
David Meyer
Down Arrow Button Icon
By
David Meyer
David Meyer
Down Arrow Button Icon
October 15, 2019, 12:05 PM ET

Apple is an unusually privacy-focused company in the Big Tech world, so its potential violations of user privacy tend to gather a lot of attention.

This proved to be the case with a report last week from the privacy site Reclaim the Net, which noted that Apple’s Safari browser sometimes sends information about the sites users are visiting off to Google and China’s Tencent, to check whether or not those webpages are fraudulent. The report particularly focused on Tencent’s alleged ties to the Chinese Communist Party.

Apple responded yesterday by explaining how the mechanism in question—the Safari Fraudulent Website Warning—is designed to protect privacy.

However, experts say this may break a key privacy law in the European Union because users do not give their explicit consent to their data being shared in this way.

Here’s how Apple’s Fraudulent Website Warning system works: The Safari browser alerts users when they visit websites that are known to be fraudulent—for example, websites trying to fool people into thinking they are other sites, so as to con them into divulging passwords. This information is regularly updated, with the underlying data coming from Google and—for users located on the Chinese mainland—Tencent.

As Johns Hopkins cryptography professor Matthew Green explained in a Sunday blogpost about the situation, Google’s current approach to flagging up fraudulent sites does not involve sending the company every web address (or URL) that a user visits‐the privacy implications of that would obviously be horrendous.

What happens instead is that Google creates a “hash” of each unsafe URL in its database. In other words, its algorithm translates the address into a mathematical representation, in a way that allows a visited URL to be checked against that entry (since the algorithm would always turn it into the same string of characters) but that does not allow reverse-translation back to a recognizable web address. Google then abbreviates these hashes and sends the short versions off to browsers such as Safari.

The browser creates a hash of each web address its user is trying to visit, and checks it against its list of Google- or Tencent-provided abbreviated hashes. If there’s a match, Safari then asks the provider for the full-length hash, to make sure if the site is fraudulent or not.

In theory, that means Google (or Tencent) does not get to monitor Safari users’ surfing habits. However, as Green noted: “The weakness in this approach is that it only provides some privacy. The typical user won’t just visit a single URL, they’ll browse thousands of URLs over time. This means a malicious provider will have many ‘bites at the apple’ (no pun intended) in order to de-anonymize that user.”

Apple stressed in its statement that Tencent only received data from users with their region set to China, adding: “The actual URL of a website you visit is never shared with a safe browsing provider and the feature can be turned off.”

The system may be designed to protect users from phishing attacks that fool them into handing over bank passwords and the like, but—because people have to opt out of this system, rather than opting in—it could also fall foul of EU online privacy rules.

The rule in question is not the much-feared General Data Protection Regulation (GDPR) that came into effect last year, threatening fines of up to 4% of global revenues for severe violations. While many know the GDPR as a law that requires users’ consent for handling their personal data, it is in fact more flexible than that—another legal basis for data processing is acting in the “legitimate interests” of the data subject, and fraud protection probably falls into this category.

Instead, the law Apple might be breaking is the ePrivacy Directive of 2002, which specifically deals with electronic communications—this law is best known as the one that forces sites to display “cookie” notices, though it is more wide-ranging than that.

According to Michael Veale, a lecturer in digital rights and regulation at University College London in the U.K., there are “certainly questions” about whether Apple should be asking for explicit consent before sending Google user data, even if it’s just abbreviated hashes.

That’s because the ePrivacy Directive becomes an issue when a company accesses data from a user’s “terminal device” (such as a phone) for a purpose that is not essential to the service being provided (in this case, the browser.) In such circumstances, Veale said, “GDPR-quality consent” is required.

“Arguments would exist both ways, but there’s definitely a possibility that consent would be required,” Veale said. “It’s strange Apple did not ask for one-off opt-in consent, but they may well be wary of asking individuals if the company they perceive as privacy-friendly can send even redacted browsing data to Google.”

Even if Apple has broken the EU ePrivacy Directive here, it is unlikely that it would suffer a serious punishment.

The directive is now ancient in tech-world terms, and it gives individual EU countries discretion over the fines they can levy for transgressions. So, while GDPR violations can theoretically lead to fines in the billions of dollars, the U.K. for example has a $630,000 cap on ePrivacy fines.

The ePrivacy Directive was supposed to have been replaced by a tougher ePrivacy Regulation at the same time as the GDPR came into effect in May 2018, with maximum fines at the same high level as those under the GDPR. But, likely thanks to extremely heavy lobbying, the ePrivacy Regulation has been stuck in legislative limbo for the last two years. While the European Commission and Parliament have passed a draft version, the EU’s member states still haven’t been able to agree on a final version.

Apple did not respond to a question about the legality of its safe browsing mechanism under EU privacy law, instead providing a more general statement about how the system works. Google did not respond to a request for comment.

About the Author
By David Meyer
LinkedIn icon
See full bioRight Arrow Button Icon

Latest in Tech

Future of WorkBrainstorm Design
The workplace needs to be designed like an ‘experience,’ says Gensler’s Ray Yuen, as employees resist the return to office
By Angelica AngDecember 5, 2025
9 minutes ago
Four years ago, BKV started buying up the two Temple power plants in Texas—located between Austin and Dallas—which now total 1.5 gigawatts of electricity generation capacity—enough to power more than 1.1 million homes, or a major data center campus. There is room to expand.
Energypower
How a Texas gas producer plans to exploit the ‘mega trend’ of power plants for AI hyperscalers
By Jordan BlumDecember 5, 2025
9 minutes ago
Big TechSpotify
Spotify users lamented Wrapped in 2024. This year, the company brought back an old favorite and made it less about AI
By Dave Lozo and Morning BrewDecember 4, 2025
11 hours ago
InnovationVenture Capital
This Khosla Ventures–backed startup is using AI to personalize cancer care
By Allie GarfinkleDecember 4, 2025
15 hours ago
AIEye on AI
Companies are increasingly falling victim to AI impersonation scams. This startup just raised $28M to stop deepfakes in real time
By Sharon GoldmanDecember 4, 2025
15 hours ago
Jensen Huang
SuccessBillionaires
Nvidia CEO Jensen Huang admits he works 7 days a week, including holidays, in a constant ‘state of anxiety’ out of fear of going bankrupt
By Jessica CoacciDecember 4, 2025
15 hours ago

Most Popular

placeholder alt text
Economy
Two months into the new fiscal year and the U.S. government is already spending more than $10 billion a week servicing national debt
By Eleanor PringleDecember 4, 2025
21 hours ago
placeholder alt text
Success
‘Godfather of AI’ says Bill Gates and Elon Musk are right about the future of work—but he predicts mass unemployment is on its way
By Preston ForeDecember 4, 2025
16 hours ago
placeholder alt text
Success
Nearly 4 million new manufacturing jobs are coming to America as boomers retire—but it's the one trade job Gen Z doesn't want
By Emma BurleighDecember 4, 2025
17 hours ago
placeholder alt text
Success
Nvidia CEO Jensen Huang admits he works 7 days a week, including holidays, in a constant 'state of anxiety' out of fear of going bankrupt
By Jessica CoacciDecember 4, 2025
15 hours ago
placeholder alt text
North America
Jeff Bezos and Lauren Sánchez Bezos commit $102.5 million to organizations combating homelessness across the U.S.: ‘This is just the beginning’
By Sydney LakeDecember 2, 2025
3 days ago
placeholder alt text
Health
Bill Gates decries ‘significant reversal in child deaths’ as nearly 5 million kids will die before they turn 5 this year
By Nick LichtenbergDecember 4, 2025
1 day ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.