SDKs, APIs and analytics quietly collect telemetry and end-user data inside your customers apps.
In short
Developer tools, SDKs, APIs and analytics collect telemetry and end-user data inside other apps, which usually makes you a Processor with real exposure. Penalties reach ₹250 crore.
What changes for this sub-sector.
Device IDs, IPs and usage events can identify people and count as personal data.
Inside a customer app you are a processor; act only on instructions under contract.
Make it clear what your SDK collects so the host app can obtain and document consent.
Default to collecting the minimum; give developers switches to reduce it further.
Protect the telemetry and events you gather in transit and at rest.
Disclose where SDK data goes and who else processes it.
Document SDK collection and consent pass-through first.
The readiness check flags telemetry, consent-passthrough and transfer gaps.
Take the readiness check →