We would like to con­grat­u­late Mug­dha Khedkar on passing her doc­tor­al ex­am­in­a­tion

 |  Heinz Nixdorf InstituteSecure Software Engineering / Heinz Nixdorf Institut

Mugdha Khedkar successfully completed her PhD on the topic ‘Assisting GDPR Compliance through Static Analysis of Android Apps’ under the supervision of Prof. Dr Eric Bodden. We offer our warmest congratulations!

Summary of the thesis:

Android applications collecting data from users must comply with legal frameworks to ensure data protection. This requirement has become even more important since the implementation of the General Data Protection Regulation (GDPR) by the European Union in 2018. In practice, GDPR compliance involves conducting effective privacy assessments, requiring close collaboration between stakeholders with diverse expertise-including developers, privacy experts, legal experts, and auditors.


This thesis introduces a multi-layered definition of privacy-related data, grounded in GDPR’s notion of personal data, and presents Privacy-Relevant Input Classification Engine (PRICE), a command-line tool for statically labeling privacy-related data collected by Android apps. Using PRICE, we examine data collection patterns across Android apps and assess how accurately these apps report their data collection practices. Our analysis reveals that apps most frequently collect data capable of partially identifying users, highlighting the need for greater consistency in privacyaware development and reporting. Complementing this analysis, we investigate developers’
experiences with Google Play Store’s Data Safety Section (DSS) through a survey and analysis of online developer discussions. This study identifies key challenges developers face in completing the DSS, including difficulties in identifying privacy-related data and limited understanding of the form.


Building on these findings, the thesis explores how static program analysis can be used to automate and support privacy assessments. We introduce Assessor View, a static analysis-based web tool designed to assist multiple stakeholders involved in privacy evaluations. Assessor View provides a unified view of privacy-related data flows and supports collaboration across technical and non technical roles. Qualitative evaluations with technical and legal participants indicate that the tool’s warnings and guidance are valuable to Data Protection Officers and privacy experts, representing a significant step toward improving communication between legal and technical experts and streamlining privacy assessments.


Finally, we extend both PRICE and Assessor View to more directly support stakeholder needs by enabling accurate, source code-driven report generation. These extensions aim to reduce manual effort, improve consistency between implemented behavior and reported disclosures, and support reliable and transparent privacy assessments.


Collectively, these contributions advance the state of the art in privacy-aware software engineering and provide a foundation for more systematic, automated, and legally compliant privacy assessments of Android applications.

From left to right: Prof. Dr Ben Hermann, Dr. Arnab Sharma, Prof. Dr Eric Bodden, Mughda Khedkar, Assistant Professor Dr Mohamed Soliman Not pictured is the committee member: Prof. Awais Rashid