Google Play restrictions on sensitive data access policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Google Play apps handling financial details, private contacts, security data, children's data, or persistent identifiers.

A general privacy disclosure doesn’t override the restrictions on particular data. Google prohibits public disclosure of financial/payment details and government IDs, unauthorized exposure of private contacts, and certain links between persistent identifiers and other information.

Check the specific use

Inspect public profiles, logs, exports, analytics joins, and shared URLs. We’d test access from another account as well as the intended user. Security apps need clear data-use disclosures, and children’s apps need SDKs approved for that use.

Persistent identifiers such as IMEI have narrow linking exceptions for specified SIM-linked telephony and enterprise device-owner management, with prominent disclosure. Ordinary analytics doesn’t establish that exception.

Correct access controls, payloads, and identifier use. Use an appropriate alternative identifier where the feature permits it.

Retest with fictional records and inspect the final data destinations. Give Google the exact field or link removed and how permitted access now works. A privacy-policy update alone won’t repair public exposure.

Messages this guide can help with

Restrictions on sensitive data access; Restrictions on sensitive data access policy violation; Restrictions on sensitive data access rejection; Restrictions on sensitive data access denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access