Google blocked more than 255,000 Android apps from obtaining excessive access to sensitive user data in 2025, according to the Play Store transparency report the company published in February 2026. That single figure sits inside a much larger 1.75 million apps Google rejected for policy violations that year. Apple and China's regulators track the same problem differently: Apple discloses a combined rejection total with no privacy-specific line item, while China's Ministry of Industry and Information Technology names dozens of apps by number every few weeks and, when operators miss the fix deadline, orders the worst offenders removed outright.

255,000 Android apps blocked from misusing sensitive data in 2025 255K Android apps Google blocked from excessivesensitive-data access, Play Store 2025

How many apps did Google block for privacy violations in 2025?

Google blocked more than 255,000 Android apps from obtaining excessive access to sensitive user data in 2025, including permissions such as location, contacts, and SMS, according to the company's most recent Play Store transparency report. The same report puts the total number of policy-violating app submissions rejected in 2025 at over 1.75 million, and says Google banned more than 80,000 developer accounts tied to malware or repeated policy breaches.

Apps blocked for sensitive-data misuse, Google Play (year over year) 0400k800k1.2M1.6M202320242025255k

Figure 1: Google's disclosed sensitive-data-access block count has swung sharply year to year rather than climbing steadily, a sign the underlying category definition has shifted between reports. Source: Google Play Store transparency reports, 2023 through 2025 editions.

The count is not a smooth trend line. Google's 2023 report cited roughly 200,000 app submissions rejected or remediated for abusing sensitive permissions like location tracking and SMS access, and the 2024 report cited 1.3 million apps blocked from unnecessary sensitive-data access, well above both the year before and the year after. Google has not published a methodology note explaining the swing, so treat each year's figure as a snapshot under that year's counting rules rather than a directly comparable trend. Whatever the exact definition in a given year, the message across all three reports is the same: sensitive-permission abuse is one of the most common reasons an app never reaches the Play Store at all.

How does that compare to Google's total enforcement each year?

Sensitive-data blocks are one slice of a larger enforcement program. Google's total count of rejected app submissions, covering every policy category, has stayed in the same 1.75 million to 2.36 million range across the last three annual reports, even as the privacy-specific figure above swung widely within it.

Total policy-violating app submissions blocked, Google Play 0625k1.25M1.88M2.5M2.28M20232.36M20241.75M2025

Figure 2: Google's total rejection count fell in 2025 after two years above 2.2 million. Source: Google Play Store transparency reports, 2023 through 2025 editions.

Of the 1.75 million submissions Google rejected in 2025, the 255,000 blocked specifically for sensitive-data misuse works out to roughly 14.6% of the total. The rest were rejected for other policy reasons: malware, spam, intellectual-property claims, and content violations among them.

Share of 2025 Google Play rejections tied to sensitive-data misuse 14.685.4Sensitive-data access violations14.6All other policy violations85.4

Figure 3: Privacy-specific blocks account for a minority of Google's total 2025 enforcement volume. Source: PrivacyTerms.io calculation from Google Play Store transparency report totals, 2025 edition.

Sites and apps that collect location, health, or contact data sit squarely inside the category most likely to get flagged before it ever reaches users, which is why matching the permissions an app actually requests to a privacy policy generator that discloses each data type in plain language reduces the odds of a rejected submission in the first place.

How many apps has China ordered removed for privacy violations?

China's Ministry of Industry and Information Technology (MIIT) runs the most transparent public removal process of any major regulator, naming specific batches of apps and SDKs by count on a recurring schedule. Its last four bulletins, spanning April 2025 to July 2026, named between 31 and 52 apps and SDKs each time for violations including unlawful data collection, excessive permission demands, and forced or frequent permission prompts.

Figure 4: MIIT's four most recent public bulletins each named 31 to 52 apps and SDKs for personal-information violations. Source: China's Ministry of Industry and Information Technology, bulletins dated April 21 2025, May 29 2025, May 21 2026, and July 2 2026.

Naming an app is only the first step. When operators do not fix the cited violations inside the rectification window, local regulators order the app removed. The Shanghai Communications Administration did exactly that in June 2026, forcibly taking down 46 apps and SDKs that, per the regulator's notice, "still had not rectified as required." The scale of that enforcement has grown sharply since the program's early years: MIIT's own figures show that from 2019 through early 2021 it technically tested roughly 620,000 apps, ordered 2,234 to rectify violations, and removed 132 from app shelves, a fraction of the count now moving through a single Shanghai batch.

Figure 5: The scale of a single enforcement batch has grown from a multi-year cumulative total to a routine monthly or bimonthly count. Source: MIIT enforcement bulletins and Shanghai Communications Administration takedown notice, 2019 to 2026.

How does an app actually go from flagged to removed?

MIIT's own published numbers describe a funnel, not a single removal event. Most apps that get technically tested are never named publicly, most apps that get named are given a chance to fix the problem, and only a minority that miss the fix deadline are actually pulled from app stores.

Figure 6: Removal is the last stage of a multi-step process, and it applies to a small share of the apps that enter it. Source: China's Ministry of Industry and Information Technology, cumulative figures for 2019 through early 2021.

The same sequence, naming followed by a rectification window followed by a recheck, shows up in every recent MIIT bulletin and in the Shanghai takedown notice. An app that fixes the cited issue before the deadline stays on the shelf. One that does not gets added to the next forced-removal list.

Does Apple disclose how many apps it removes for privacy violations?

Not as a standalone figure. Apple's 2023 App Store Transparency Report says the company reviewed 6,892,500 app submissions and rejected 1,763,812 of them, roughly 25.6%, citing performance, design, and legal reasons together rather than breaking privacy out as its own category.

That combined reporting makes Apple harder to compare directly against Google's disclosed sensitive-data figure or China's named-batch counts. Apple's App Review Guidelines include a dedicated privacy section, Guideline 5.1, covering data collection, minimization, and account deletion, and rejections under that guideline are folded into the "legal" bucket in the transparency report rather than counted separately. A developer whose app gets pulled for a privacy violation and one whose app gets pulled for a trademark dispute show up in the same number.

Do US regulators remove apps for privacy violations, or just fine them?

Mostly fines, not removal. Where MIIT and Shanghai's regulators pull noncompliant apps from shelves, the primary US privacy enforcer, the Federal Trade Commission, has more often reached financial settlements while the app in question stayed listed and operating.

Which app privacy practices typically pass review, and which trigger removal discloses data use requests excess permissions offers account deletion sells data without consent

The FTC fined GoodRx 1.5 million dollars in 2023, its first enforcement action under the Health Breach Notification Rule, over sharing prescription and health data with Facebook and Google without proper disclosure. It reached a 7.8 million dollar settlement with BetterHelp the same year over sharing sensitive counseling data with Facebook and Snapchat. More recently, a case tied to an earlier FTC finding against period-tracking app Flo Health led Google and Flo Health to a combined 56 million dollar settlement in 2025 over sharing reproductive health data without adequate consent. In every one of these three cases, the app remained available for download throughout the investigation and after the settlement.

This mirrors a pattern our mobile app privacy statistics coverage has tracked across the broader app ecosystem: US enforcement tends to change a company's data practices and its balance sheet, not its App Store listing.

How do platforms compare on app privacy enforcement?

Platform or regulatorAction disclosedCountPeriod
Google Play (privacy-specific)Apps blocked from excessive sensitive-data access255,0002025
Google Play (all policy reasons)Total app submissions rejected1,750,0002025
Apple App StoreTotal apps rejected, no privacy breakout1,763,8122023
China MIITApps and SDKs named per bulletin31 to 52Apr 2025 to Jul 2026
Shanghai Communications AdministrationApps forcibly removed after missed deadline46Jun 2026
US FTC-linked settlementsFinancial settlement, app stayed liveUp to $56M2023 to 2025

Source: Google Play Store transparency reports, Apple App Store Transparency Report, MIIT and Shanghai Communications Administration bulletins, FTC and related settlement filings.

That contrast in enforcement style also shows up in how permission requests get treated once an app is live. Readers researching how consent actually plays out can compare it against our data on how users respond when an app asks to track them, since a permission an app never should have asked for in the first place is exactly the category Google's 255,000 figure is measuring.

The Bottom Line

No single number answers "how many apps have been removed for privacy breaches," because the platforms and regulators measuring it count different things. Google's 255,000 blocked in 2025 measures pre-publication rejections tied to one category, sensitive-data access, out of a much larger 1.75 million total. China's MIIT and Shanghai regulators measure the opposite end: apps that were already public, got named, and then were pulled after missing a fix deadline, a process that removed 46 apps in a single June 2026 batch. Apple's 1,763,812 rejected submissions in 2023 fold privacy in with unrelated reasons, and the FTC's biggest recent privacy cases resulted in fines rather than removals at all. Any app or site handling sensitive categories like location, health, or biometric data sits inside the highest-scrutiny group across every one of these systems, and the fastest way to stay out of a rejection or takedown list is a privacy policy generator that discloses exactly what gets collected and why before a reviewer or regulator asks.

Frequently Asked Questions

How many apps did Google block for privacy violations in 2025? Google blocked more than 255,000 Android apps from obtaining excessive access to sensitive user data in 2025, part of 1.75 million total app submissions the company rejected for policy violations that year, according to the Play Store transparency report Google published in February 2026.

How many apps has China forced offline for privacy violations? The Shanghai Communications Administration removed 46 apps and SDKs in June 2026 after their operators missed the deadline to fix personal-information violations, and China's Ministry of Industry and Information Technology has named 31 to 52 apps and SDKs for similar violations in each of its last four bulletins between April 2025 and July 2026.

Does Apple disclose how many apps it removes for privacy violations? Not as a separate figure. Apple's 2023 App Store Transparency Report says it rejected 1,763,812 of 6,892,500 apps submitted that year for performance, design, and legal reasons combined, with no line item isolating privacy-specific removals.

Do US regulators remove apps for privacy violations, or just fine them? Mostly the latter. The settlement covering Flo Health and Google reached 56 million dollars in 2025 over reproductive health data sharing, and separate FTC orders fined GoodRx 1.5 million dollars and BetterHelp 7.8 million dollars in 2023, but none of the three apps were removed from app stores.

Where the Numbers Come From

  1. BleepingComputer. (2026). "Google Blocked Over 1.75 Million Play Store App Submissions in 2025." Citing Google's Play Store transparency data: 255,000 apps blocked from excessive sensitive-data access, 1.75 million submissions rejected, 80,000 developer accounts banned. Published February 19, 2026.
  2. Infosecurity Magazine. (2025). "Google Blocked 2.36 Million Policy-Violating Apps." Citing Google's 2024 transparency data: 2.36 million apps blocked, 158,000 developer accounts banned, 1.3 million apps blocked from unnecessary sensitive-data access. Published January 30, 2025.
  3. Developer Tech. (2024). "Google Blocked 2M Malicious Apps from the Play Store in 2023." Citing Google's 2023 transparency data: 2.28 million apps blocked, roughly 200,000 submissions rejected or remediated for sensitive-permission abuse, 333,000 developer accounts banned.
  4. China Ministry of Industry and Information Technology. (2025). Bulletin naming 49 apps and SDKs for personal-information rights violations, 2025 Batch 2 (47th overall). Published May 29, 2025.
  5. Data Compliance China. (2026). "MIIT 2026 Batch 4: 32 App Public Naming." Bulletin naming 32 apps and SDKs, 2026 Batch 4 (57th overall). Published July 2, 2026.
  6. Data Compliance China. (2026). "MIIT 2026 Batch 3: 31 App Public Naming." Bulletin naming 31 apps and SDKs, 2026 Batch 3 (56th overall). Published May 21, 2026.
  7. Data Compliance China. (2026). "Shanghai 46-App Takedown for Failure to Rectify." Shanghai Communications Administration order removing 46 apps and SDKs after a missed rectification deadline. Published June 24, 2026.
  8. Federal Trade Commission. (2023). GoodRx Holdings enforcement action, 1.5 million dollar settlement over unauthorized health-data sharing with Facebook and Google.
  9. Federal Trade Commission. (2023). BetterHelp enforcement action, 7.8 million dollar settlement over sharing sensitive mental-health data with third parties.

Note: All figures verified as of July 2026. Google's sensitive-data-access block count has varied significantly between its 2023, 2024, and 2025 transparency reports due to undisclosed methodology changes; treat each year's figure independently rather than as a smooth trend. MIIT and Shanghai enforcement figures are refreshed as new bulletins are published, roughly every four to eight weeks.