Meta's Apps Collect Three Times More User Data Than Apple or Microsoft, New Study Finds
Surfshark's August 18, 2026 analysis of 171 App Store listings found Meta's apps declare an average of 25 out of 35 possible data types, more than triple Apple's seven and Microsoft's eight. Here is what the study actually measured, why Google still dominates the raw count of data-hungry apps, and what it means for a small business that runs its storefront, ads, and customer chat through these same platforms.

Meta's apps ask for permission to collect an average of 25 out of 35 possible data types on the Apple App Store. Apple's own apps average seven. Microsoft's average eight. That gap, more than three times, comes from a new study published by the VPN company Surfshark on August 18, 2026, and it landed the same week that Euronews, The Register, and half a dozen smaller outlets picked it up and ran their own versions of the same headline.
For a small business, this is not really a story about Meta's reputation. It is a story about the tools sitting on the same phone a shop owner uses to answer customer messages, post a product photo, and check whether an ad spent its budget. Facebook, Messenger, WhatsApp Business, Instagram, and Meta Ads Manager are Meta apps. Google Maps, Gmail, and Google Ads live on the same device. Understanding what each one actually declares it collects is a five-minute check most owners never make, and the study gives that check a concrete number to compare against.
๐ What Surfshark Actually Measured
Surfshark reviewed 171 apps published on the Apple App Store by five companies: Google (44 apps), Apple (41), Microsoft (40), Amazon (34), and Meta (12). For each app, researchers read the privacy label the developer submitted to Apple, which lists which of 35 defined data categories the app may collect: things like precise location, browsing history, purchase history, contacts, and health data. Apple has required this label, called "App Privacy Details," on every App Store listing since December 2020, so the raw material behind the study already existed in public view. What Surfshark added was the work of reading all 171 labels, tallying the categories, and grouping the results by company and by app category.

Meta's 12 apps collected an average of 25 data types each. Google's 44 apps averaged 17. Amazon's 34 averaged 12. Microsoft's 40 averaged 8, and Apple's own 41 averaged 7. The seven single apps that declared the most categories in the entire study were all Meta products: Meta AI led at 33, with Meta Horizon, Meta Business Suite, Meta Ads Manager, Messenger, Forum, and Facebook each declaring 32.
A methodology detail matters here and it did not make every headline. These numbers describe what an app's developer disclosed it may collect, using Apple's own questionnaire, not independent network traffic captured by Surfshark itself. A declared category does not mean every user's data in that category moves on every use, and it says nothing about how long any of it is retained or who else it is shared with beyond the app's own company. It is a real, useful comparison because every company answered the identical form under the same Apple review process, but it measures disclosed scope, not observed volume or actual data flow.
๐ Google Still Owns the Most Data-Hungry Apps, Just Not the Highest Average
Meta's average is the headline number, but Google shows up differently in the same dataset, and the difference is worth sitting with because it changes what the finding means for someone running a business. Of the 40 individual apps that declared the broadest data collection across the whole study, 29 belonged to Google, compared with nine from Meta and only two from Amazon. Those 29 Google apps each declared between 18 and 26 data types, a narrower range than Meta's most extreme entries but spread across a much larger fleet of products.
The reason the two companies produce different-looking results is portfolio size and shape. Meta has only 12 apps in the sample, concentrated in social networking, business, and productivity, so its high average comes from consistently broad collection across a small, tightly related set of tools. Google has 44 apps spread across a dozen App Store categories, from Photo & Video to Health & Fitness to Developer Tools, and it ranked as the most data-hungry developer in six of those categories even though its company-wide average sits well below Meta's. Google Maps alone, the only app representing Google in the Navigation category, declared 26 data types on its own.
Put another way: Meta's problem, by this measure, is depth. Google's is breadth. A business that relies on Gmail, Google Maps, Google Ads, Google Chrome, and Google Search is spreading its exposure across more individual apps, even if none of them individually looks as extreme as Meta AI's 33 declared categories. Neither pattern is obviously worse in every situation; it depends on how many of a company's apps a given business actually installs and how those apps are configured once installed.

๐งพ Where the Data Actually Goes By Company
Every company in the study collects some baseline data almost universally: device IDs, crash and performance diagnostics, and basic product interaction logs. That baseline exists mostly to keep apps stable and to catch bugs before they reach every user, and none of the coverage around this study singled it out as a problem. Beyond that baseline, though, the pattern diverges sharply by company, and the detail is where a business owner's actual decisions live.
Meta. All 12 Meta apps declare device IDs, product interactions, and performance and crash data. Nine of the 12 also declare precise location, which researchers noted goes beyond what most of those apps need for basic function, and seven declare browsing history, meaning information about sites visited outside the app itself, not just inside it. Within the Business category specifically, Meta's apps averaged 25 data types, compared with 16 for Google, 12 for Amazon, and 9 for Microsoft, so the gap that shows up company-wide repeats itself inside the exact category a shop owner is most likely to touch.
Google. All 44 Google apps declare device IDs, diagnostics, and performance data. Most also list search history, purchase history, photos or videos, physical address, email, name, coarse location, and crash data. Eight Google apps, including Chrome and Gemini, additionally declare browsing history, meaning activity outside the app itself feeds back into Google's systems for those specific products.
Amazon. Precise location shows up in 11 of Amazon's 34 apps, and Amazon Alexa alone declares 28 data types, more than any non-Meta app in the entire study. Only one Amazon app, Amazon Shopper, lists browsing history. Within Business apps specifically, which include Amazon Shipping, Amazon ranked third among the five companies with an average of 12 data types.
Microsoft. Consistently near the bottom of every category Surfshark checked, ranking either least or second-least data-hungry developer in nearly every App Store category examined. The common thread across its 40 apps is crash data, device IDs, email, name, diagnostics, product interaction, and user IDs. Six Microsoft apps declare precise location and two declare browsing history. Its one exception was Graphics & Design, where Microsoft Designer collected 12 data types and ranked first in that narrow category.
Apple. The least data-hungry across nearly every category examined, with the widest spread of categories in the study at 15 in total. Safari was the only Apple app in the sample to declare browsing history, and six Apple apps declare precise location. Apple's 13 Utilities apps collected an average of just six data types, compared with 17 for Google's Utilities apps in the same category.
๐ฌ Why This Matters More For a Business Account Than a Personal One
A business running its storefront through Meta Business Suite, WhatsApp, and Ads Manager is not just handing over the same data types a personal user would hand over by scrolling a feed. Business tools connect a company's transaction history, ad spend, audience lists, and customer message threads to the same identity graph the study describes. That combination is exactly what advertising systems use to build lookalike audiences and predict who is likely to buy, which is the point of running ads there in the first place. The tradeoff is not new information to anyone who has used Meta Ads Manager, but the scale documented this week gives it a specific, citable number instead of a vague sense that "they probably track everything."

None of this means a small business should delete these apps. Facebook, Instagram, WhatsApp Business, and Google's tools remain where most Indonesian shoppers already are, and abandoning them costs more in lost reach than it saves in avoided data collection. Surfshark's own conclusion, echoed by the outlets that covered the study, is not "stop using these apps." It is closer to what any careful driver does with a rental car: know what it does before handing over the keys, not after something goes wrong with the booking.
๐๏ธ Four Checks Worth Five Minutes Each
Check what your business apps are actually authorized to see, right now, on the device you actually use. On iPhone, Settings shows exactly which permissions Facebook, Messenger, WhatsApp Business, and Google apps currently hold: location, contacts, microphone, photos. Android's Privacy Dashboard does the same, listing every permission grant with a timestamp for the last time it was used. Most owners installed these apps once, tapped "allow" on every prompt during setup, and never revisited the list since.
Separate personal accounts from business accounts wherever the platform allows it. A Meta Business Suite account tied to a dedicated business Facebook page keeps customer message data and ad performance away from an owner's personal browsing history and personal contact list. This is standard advice published in Meta's own business help center, not an outside workaround, and it is one of the few controls that meaningfully changes what gets linked to what inside Meta's systems.
Turn off precise location unless the app genuinely needs it for the task at hand. A messaging app answering customer chats does not need GPS-level location; coarse location, if any location at all, is usually enough for the features a shop actually uses. Nine of Meta's 12 apps and eight of Google's 44 declare precise location as an available category, which does not mean every business account needs to leave that permission switched on for every one of them.
Read the one-paragraph data policy the platform already publishes for business tools, rather than the general marketing page aimed at consumers. Meta, Google, and Amazon each publish a business-tools privacy summary that is shorter than this article's callout box below. It answers the only question that matters commercially for most small sellers: does customer chat content ever feed ad targeting, and can a business opt out of that specific use.
๐๏ธ Where Regulation Stands, In Indonesia and Elsewhere
Indonesia's Personal Data Protection Law, known as UU PDP, has been in force since 2022, with businesses required to appoint a Data Protection Officer for higher-risk data processing and to secure clear, specific consent before collecting personal data for commercial use. Legal commentary through 2026, including recent coverage from Hukumonline, has repeatedly noted that the dedicated enforcement body the law calls for is still being finalized even as the compliance obligations already apply in full. That gap leaves many small businesses genuinely uncertain about what "compliant" looks like in practice for a shop that just wants to run ads and answer WhatsApp messages without a legal department.
The honest answer, based on how the law is written, is that a business collecting customer names, phone numbers, and order details through any of these platforms is already a data controller under UU PDP, whether or not it thinks of itself that way. Separate ASEAN-region compliance guides aimed at developers make the same point in different words: the law distinguishes general personal data, like a name or address, from specific personal data, like health or financial records, and specific data carries a higher bar for consent and security regardless of company size.
Outside Indonesia, the regulatory pressure on this exact question has been building for longer. The EU's data protection framework already requires companies to justify each category of data they collect against a specific purpose, and enforcement actions against major platforms for over-broad collection have produced fines running into hundreds of millions of euros in recent years. None of that regulatory history is new because of this Surfshark study. What the study does is make visible, in one comparable table, what a business is already exposed to by using these tools at all, independent of whatever a regulator decides to do next.
๐ This Fits a Pattern Surfshark Has Documented Before
This is not Surfshark's first study on this exact question, and that matters for how much weight to put on this particular result. The company has previously published research on data collection by mobile browsers, finding that Yandex, Microsoft Edge, and Google Chrome carried the highest privacy risk among 15 popular browsers based on their own Play Store disclosures. It has also studied AI chatbot apps specifically, finding that the average chatbot app declares 13 of the same 35 data types, with roughly 45 percent collecting location data and close to 30 percent engaging in tracking used for targeted advertising or data-broker sharing. Meta AI topped that earlier chatbot-specific study too.
Seeing the same company, using the same 35-category framework, arrive at a similar ranking across three separate studies over more than a year gives the pattern more weight than any single one of them would carry alone. It also means a business owner who reads only this week's headline is seeing one frame of a longer-running finding, not a one-off result produced for a news cycle.

๐งฎ A Rough Comparison Table Worth Keeping
Numbers are easier to act on than prose, so here is the company-level picture in one place, drawn directly from Surfshark's published averages and app counts.
- Meta: 12 apps studied, average of 25 of 35 data types, highest single app Meta AI at 33.
- Google: 44 apps studied, average of 17 of 35 data types, 29 of the study's 40 most data-hungry apps.
- Amazon: 34 apps studied, average of 12 of 35 data types, Amazon Alexa the highest at 28.
- Microsoft: 40 apps studied, average of 8 of 35 data types, least or second-least in nearly every category.
- Apple: 41 apps studied, average of 7 of 35 data types, the lowest overall average in the study.
Read this list next to whatever apps actually sit on a business phone, not next to the abstract idea of "Big Tech." A business running Facebook, Messenger, WhatsApp Business, and Meta Ads Manager is touching four apps from the highest-averaging company. A business running mostly Gmail, Google Maps, and Google Ads is touching three apps from a company with a lower average but a much larger total footprint. Neither combination is automatically safer; they are just different shapes of exposure.
๐ ๏ธ What a Realistic 20-Minute Audit Looks Like
For an owner who wants to act on this today rather than file it away, a realistic audit does not require legal help or new software. It looks like this, in order:
First, open the phone's own settings menu, not the app itself, and list every permission each business-critical app currently holds. This takes about five minutes on either iOS or Android and produces a plain list: which apps have location, which have contacts, which have microphone access, which have photo library access.
Second, compare that list against what the app is actually used for in the business. A point-of-sale app plausibly needs camera access to scan a barcode. It does not plausibly need constant precise location if orders are only ever placed in one physical shop. A chat app needs microphone access only if voice notes are actually used with customers.
Third, revoke anything that does not match a real use case, and note the date it was changed somewhere simple, even a phone note. Regulatory frameworks like UU PDP increasingly reward businesses that can show they reviewed and limited their own data exposure, even informally, over businesses that never looked at the question at all.
Fourth, repeat the same check in three months. App updates routinely reset or expand default permissions, and a business that checks once and assumes the settings stay fixed is often surprised at the next audit.
โ What This Means For a Small Business Right Now
The practical takeaway is not to leave any of these platforms. It is to stop assuming that "everyone uses it" is the same thing as "it's harmless by default." A business that reviews its own app permissions once, separates its business accounts from personal ones, and reads the platform's own privacy summary for business tools has done more due diligence than most competitors will bother to do this year. The data types Surfshark counted were already disclosed, sitting in a settings menu most owners have never opened and a privacy label most shoppers scroll past on the App Store page.
That gap between disclosure and awareness, more than any single company's average, is the actual story this week. A study like this does not tell a business to stop advertising on Meta or stop navigating with Google Maps. It tells a business exactly what it agreed to the day it tapped install, and gives it a concrete, five-minute list of settings worth checking before the next customer conversation happens on any of these apps.
Sources: Surfshark research study (August 18, 2026); The Register; Euronews and its German translation via AOL; The IT Nerd; UU PDP compliance commentary via Hukumonline and Opensoft Asia.

