Google Play restrictions on sensitive data access policy: fixes and checks
By The Draftbit team · Updated
Sources checked
This guide is for Google Play apps handling financial details, private contacts, security data, children's data, or persistent identifiers.
A general privacy disclosure doesn’t override the restrictions on particular data. Google prohibits public disclosure of financial/payment details and government IDs, unauthorized exposure of private contacts, and certain links between persistent identifiers and other information.
Check the specific use
Inspect public profiles, logs, exports, analytics joins, and shared URLs. We’d test access from another account as well as the intended user. Security apps need clear data-use disclosures, and children’s apps need SDKs approved for that use.
Persistent identifiers such as IMEI have narrow linking exceptions for specified SIM-linked telephony and enterprise device-owner management, with prominent disclosure. Ordinary analytics doesn’t establish that exception.
Remove the exposure or prohibited link
Correct access controls, payloads, and identifier use. Use an appropriate alternative identifier where the feature permits it.
Retest with fictional records and inspect the final data destinations. Give Google the exact field or link removed and how permitted access now works. A privacy-policy update alone won’t repair public exposure.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Google Play: Restrictions on sensitive data access Checked 22 September 2026