Data Safety & the Privacy Policy on Google Play: A Practical Guide

What Google requires from every app — even one that collects no data: the Data safety form, the privacy policy, and why the two must match.

Reviewed August 17, 2026May change — always verify in Play Console3 min read2 official sources

Written & maintained by AppsTestLabAbout AppsTestLabHow we research

A document and phone illustration about data safety and privacy
A document and phone illustration about data safety and privacy
On this page
  1. The two mandatory pieces
  2. What the privacy policy must contain
  3. Filling out the Data safety form
  4. Third-party code counts as yours
  5. Account deletion, if your app creates accounts

Almost every new developer underestimates this page: the Data safety form and the privacy policy are mandatory for every app on Google Play — including an app that collects nothing at all. They're also part of what reviewers see when your app goes through review. This guide makes the whole corner concrete.

The two mandatory pieces

What the privacy policy must contain

  • Developer identification and a privacy point of contact or inquiry mechanism
  • The types of personal and sensitive user data the app accesses, collects, uses, and shares — and who it's shared with
  • Secure data handling procedures
  • The data retention and deletion policy
  • Clear labeling as a privacy policy (the title should say 'privacy policy')

Filling out the Data safety form

  1. Read the overview first

    The form's Overview section tells you exactly what you'll be asked. Read it before starting — most mistakes come from rushing the preamble.

  1. Answer data collection section

    For each required user data type, say whether your app collects or shares it. If nothing applies, the form still gets completed — declaring 'no data collected' is a valid, common answer.

  1. Declare the data types

    Select every type your app or its SDKs collect or share. If in doubt, check your declared permissions and the APIs your app uses.

  1. Describe usage and handling

    For each declared type, answer how it's used and how it's protected — encryption in transit or at rest, for example.

  1. Preview and submit

    Preview what users will see on the listing, submit, and keep the form accurate as the app changes.

Third-party code counts as yours

Data collected or shared by any SDK or third-party library inside your app must be reflected in the form and the privacy policy. Google Play's SDK Index publishes guidance from many SDK providers — start there when auditing what your dependencies actually do.

Account deletion, if your app creates accounts

Apps that offer account creation must give users a clear, accessible way to delete their account — and actually delete the associated data. Freezing the account instead of deleting it doesn't satisfy the requirement.

Sources & references

Official Google documentation

These links open Google's official Play Console Help pages used to verify this guide. AppsTestLab guidance is independent and not affiliated with Google.

Ready to test?

5,000+ apps tested. A 99% historical approval rate. And a 100% money-back guarantee.

Tell us about your app and we'll confirm the right testing approach. One WhatsApp message to start, no complicated setup.

Guarantee applies to eligible app testing orders · Google makes the final approval decision

Chat on WhatsApp