• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechPrivacy

Apple’s Routing of User Data to Google Could Be Breaking EU Privacy Law

By
David Meyer
David Meyer
Down Arrow Button Icon
By
David Meyer
David Meyer
Down Arrow Button Icon
October 15, 2019, 12:05 PM ET

Apple is an unusually privacy-focused company in the Big Tech world, so its potential violations of user privacy tend to gather a lot of attention.

This proved to be the case with a report last week from the privacy site Reclaim the Net, which noted that Apple’s Safari browser sometimes sends information about the sites users are visiting off to Google and China’s Tencent, to check whether or not those webpages are fraudulent. The report particularly focused on Tencent’s alleged ties to the Chinese Communist Party.

Apple responded yesterday by explaining how the mechanism in question—the Safari Fraudulent Website Warning—is designed to protect privacy.

However, experts say this may break a key privacy law in the European Union because users do not give their explicit consent to their data being shared in this way.

Here’s how Apple’s Fraudulent Website Warning system works: The Safari browser alerts users when they visit websites that are known to be fraudulent—for example, websites trying to fool people into thinking they are other sites, so as to con them into divulging passwords. This information is regularly updated, with the underlying data coming from Google and—for users located on the Chinese mainland—Tencent.

As Johns Hopkins cryptography professor Matthew Green explained in a Sunday blogpost about the situation, Google’s current approach to flagging up fraudulent sites does not involve sending the company every web address (or URL) that a user visits‐the privacy implications of that would obviously be horrendous.

What happens instead is that Google creates a “hash” of each unsafe URL in its database. In other words, its algorithm translates the address into a mathematical representation, in a way that allows a visited URL to be checked against that entry (since the algorithm would always turn it into the same string of characters) but that does not allow reverse-translation back to a recognizable web address. Google then abbreviates these hashes and sends the short versions off to browsers such as Safari.

The browser creates a hash of each web address its user is trying to visit, and checks it against its list of Google- or Tencent-provided abbreviated hashes. If there’s a match, Safari then asks the provider for the full-length hash, to make sure if the site is fraudulent or not.

In theory, that means Google (or Tencent) does not get to monitor Safari users’ surfing habits. However, as Green noted: “The weakness in this approach is that it only provides some privacy. The typical user won’t just visit a single URL, they’ll browse thousands of URLs over time. This means a malicious provider will have many ‘bites at the apple’ (no pun intended) in order to de-anonymize that user.”

Apple stressed in its statement that Tencent only received data from users with their region set to China, adding: “The actual URL of a website you visit is never shared with a safe browsing provider and the feature can be turned off.”

The system may be designed to protect users from phishing attacks that fool them into handing over bank passwords and the like, but—because people have to opt out of this system, rather than opting in—it could also fall foul of EU online privacy rules.

The rule in question is not the much-feared General Data Protection Regulation (GDPR) that came into effect last year, threatening fines of up to 4% of global revenues for severe violations. While many know the GDPR as a law that requires users’ consent for handling their personal data, it is in fact more flexible than that—another legal basis for data processing is acting in the “legitimate interests” of the data subject, and fraud protection probably falls into this category.

Instead, the law Apple might be breaking is the ePrivacy Directive of 2002, which specifically deals with electronic communications—this law is best known as the one that forces sites to display “cookie” notices, though it is more wide-ranging than that.

According to Michael Veale, a lecturer in digital rights and regulation at University College London in the U.K., there are “certainly questions” about whether Apple should be asking for explicit consent before sending Google user data, even if it’s just abbreviated hashes.

That’s because the ePrivacy Directive becomes an issue when a company accesses data from a user’s “terminal device” (such as a phone) for a purpose that is not essential to the service being provided (in this case, the browser.) In such circumstances, Veale said, “GDPR-quality consent” is required.

“Arguments would exist both ways, but there’s definitely a possibility that consent would be required,” Veale said. “It’s strange Apple did not ask for one-off opt-in consent, but they may well be wary of asking individuals if the company they perceive as privacy-friendly can send even redacted browsing data to Google.”

Even if Apple has broken the EU ePrivacy Directive here, it is unlikely that it would suffer a serious punishment.

The directive is now ancient in tech-world terms, and it gives individual EU countries discretion over the fines they can levy for transgressions. So, while GDPR violations can theoretically lead to fines in the billions of dollars, the U.K. for example has a $630,000 cap on ePrivacy fines.

The ePrivacy Directive was supposed to have been replaced by a tougher ePrivacy Regulation at the same time as the GDPR came into effect in May 2018, with maximum fines at the same high level as those under the GDPR. But, likely thanks to extremely heavy lobbying, the ePrivacy Regulation has been stuck in legislative limbo for the last two years. While the European Commission and Parliament have passed a draft version, the EU’s member states still haven’t been able to agree on a final version.

Apple did not respond to a question about the legality of its safe browsing mechanism under EU privacy law, instead providing a more general statement about how the system works. Google did not respond to a request for comment.

About the Author
By David Meyer
LinkedIn icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Jensen Huang
SuccessProductivity
The shaky job market won’t last: Nvidia CEO Jensen Huang is ‘fairly confident’ that AI will increase productivity and hiring—but there’s a catch
By Preston ForeJanuary 14, 2026
3 hours ago
Illustration of Google logo and Gemini open on a smartphone.
AIGoogle
Google connects Gemini to users’ emails and photos in push to build a personal assistant
By Beatrice NolanJanuary 14, 2026
3 hours ago
Future of WorkColleges and Universities
Why a college degree is still worthwhile—and the 3 things it can teach you that AI can’t do
By Jake AngeloJanuary 14, 2026
4 hours ago
man with glasses stares into camera
CryptoCryptocurrency
Meld raises $7 million to integrate stablecoin networks, build the ‘Visa for crypto’
By Carlos GarciaJanuary 14, 2026
4 hours ago
newsom
PoliticsTaxes
‘You are really playing with fire with this one’: California billionaires tax ignites, pitting labor unions and voters against tech execs
By MIchael R. Blood, Michael Liedtke and The Associated PressJanuary 14, 2026
5 hours ago
engineer
Commentaryengineering
China graduates 1.3 million engineers per year, versus just 130,000 in the U.S. We need AI to bridge the gap
By Paul Eremenko and Ashish SrivastavaJanuary 14, 2026
5 hours ago

Most Popular

placeholder alt text
Success
Despite his $2.6 billion net worth, MrBeast says he’s having to borrow cash and doesn’t even have enough money in his bank account to buy McDonald’s
By Emma BurleighJanuary 13, 2026
1 day ago
placeholder alt text
Tech
Elon Musk asked people to upload their medical data to X so his AI company could learn to interpret MRIs and CT scans
By Sasha RogelbergJanuary 11, 2026
3 days ago
placeholder alt text
AI
'Godfather of AI' says the technology will create massive unemployment and send profits soaring — 'that is the capitalist system'
By Jason MaJanuary 12, 2026
2 days ago
placeholder alt text
Economy
The longer the Supreme Court delays its tariff decision, the better it is for President Trump
By Jim EdwardsJanuary 13, 2026
1 day ago
placeholder alt text
Future of Work
'Microshifting,' an extreme form of hybrid working that breaks work into short, non-continuous blocks, is on the rise
By Nick LichtenbergJanuary 13, 2026
1 day ago
placeholder alt text
Success
Google's Sergey Brin admits he's hiring 'tons' of workers without degrees: 'They just figure things out on their own in some weird corner'
By Preston ForeJanuary 12, 2026
2 days ago

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.