The phone does not know "everything". It knows different layers — and each has a different manager.

A smartphone does not build one omniscient profile. It consists of separate layers: operating system, application, account, network, backup, sensors and advertising identifier. Each layer knows something different and we ask a different administrator about it.

The phone does not know "everything". It knows different layers — and each has a different manager.
Editorial illustration created with AI assistance.A smartphone does not build one omniscient profile. It consists of separate layers: operating system, application, account, network, backup, sensors and advertising identifier. Each layer knows something different and we ask a different administrator about it.
Evidence record

Evidence passport

Sources and checks
22 sourcesSources checked:
Publication and updates
Published: Updated: Not stated
Correction history
0 corrections
Role of AI
Not stated
Reading time
27 min read
Listen
00:0000:00
Advanced controls
1.00 ×
Ready
Evidence record

Conclusion at a glance

What is established

A smartphone does not build one omniscient profile. It consists of separate layers: operating system, application, account, network, backup, sensors and advertising identifier. Each layer knows something different and we ask a different administrator about it.

What remains uncertain

A demonstrated technical capability alone does not establish real-world adoption, error rates in another setting or effects on particular people.

What would change the conclusion

An independent audit of the deployed system, reproducible measurement in a matching setting or new real-world impact data would change the conclusion.

Article contents
  1. Takeout, seven days of report and statement from the operator are not one file
  2. The phone has at least six layers
  3. A device is not an account
  4. Advertising ID is not a social security number
  5. Comprehensive retention of metadata is not the same as an obligation from the Union
  6. An inventory of your own layers will say more than the sentence the phone knows everything

Section: Technology & AI Author: IN Reading Length: ~27 min Sources and further reading: 22 items Topics: smartphone, privacy, application, operator, GDPR, Apple, Google, NÚKIB SEO / Working Title: What does your mobile phone know about you?

What does your mobile phone know about you? The question sounds simple until we notice that we are not comparing one thing. A device can have an IMEI and the account still survive a device exchange. A position in the timeline can be turned off and still have a position from another activity. According to Czech law, the operator can store operational and location data for a period of 6 months and still not read the content of the end-to-end chat.[13] The seven-day App Privacy Report can show microphone accesses without being a snapshot of the entire purchase history.[7] Therefore, the following text does not ask what "the phone knows". It asks which layer knows what — and which administrator to ask.

1. Takeout, seven days of report and statement from the operator are not one file

Let's imagine one person and three exports. First, it downloads data from your Google account via Takeout. He then turns on App Privacy Report on the iPhone and tracks app access to location, camera, microphone and contacts for a week. Finally, it will ask the operator according to Article 15 of the GDPR for data related to its contract and operation.[3][7][15]

At first glance, there is one dispute: what does the phone know about him. In fact, each output answers a different question. Takeout describes the account and services that the user chooses to export. App Privacy Report describes app accesses and network activity for the last 7 days after turning on the report; Apple states that the data is encrypted on the device and the report is deleted when the device is turned off.[7] The operator describes the subscriber relationship, operational data and location data in the regime of the Electronic Communications Act.[13]

Therefore, they can all be partly right and the common sentence still wrong. A user who sees search history in Takeout is correct that the account may contain a sensitive trace. The user who sees frequent location accesses in the report is correct that applications can reach the sensors. The operator is right that he does not store the content of the messages in the mode of § 97, paragraph 3. The error arises only when these layers become one all-knowing file.

So the first distinction is not whether the phone is smart. It reads who is the administrator of a particular layer. It's not wordplay. If we ask the wrong administrator, we get the right answer to a stranger's question.

The phone doesn't know everything. It knows different layers — and each has a different manager.

— Jiný Kontext

2. The phone has at least six layers

When we hear the word "cell phone", we usually think of an object in our pocket. But in terms of data, it is not a single subject. It's the hub between your operating system, apps, account, network, ad measurement, backups, and other devices. Each layer has a different technical mechanism and a different right.

The first layer is the operating system and sensors. GPS, Wi-Fi, Bluetooth, accelerometer, camera, microphone and contact book are not one socket. The system holds authority over them. Usually, the application does not ask for "everything", but for specific access: position during use, camera, microphone, contacts. Apple describes in the App Privacy Report that the report shows accesses to sensitive data and sensors, as well as contacted domains for the last 7 days.[7]

The second layer is applications and their libraries. An application doesn't have to be the programmer's only code. May contain SDKs for advertising, analytics, maps or logins. NÚKIB therefore recommends downloading applications from authorized stores and monitoring what they reach, especially for suddenly popular applications.[10]

The third layer is a Google or Apple account. The account can survive a phone change. It can be opened in a browser, a tablet or a new device. Takeout is therefore not a statement "from the phone", but an export of account data from selected services.[3]

The fourth layer is the operator's network. This is where the SIM, subscriber agreement, network identification, operational and location data and billing appear. Czech § 97 paragraph 3 ZoEK works with a period of 6 months for the storage of defined data, but at the same time explicitly separates the content of messages.[13]

The fifth layer is advertising and measurement. The Android Advertising ID is a resettable and erasable identifier; after deletion, according to the Google documentation, zeros are returned.[6] After iOS 14,5, Apple IDFA is accessible for tracking across third-party apps only with consent in App Tracking Transparency mode.[8]

The sixth layer is backup and other devices. Photos can be in the cloud, messages in a backup, login in a browser, devices in a family or company profile. The phone in hand may not show the full track until we look at the account and backups.

3. The best overview is the one whose gap you recognise before someone else's request

Users often look for one switch and one listing. This is understandable, but incomplete. One location switch will not cancel all possible sources of location information. One report in 7 days will not show history before power on. A single GDPR request does not cover all controllers, as the data subject is sending it to a specific person or institution, not a "phone".[15][16]

A kind of failure What does he look like? How to test What will limit the damage
Swap layers Takeout, report and operator read as one profile Compare three outputs of the same person The request should always be directed to a specific administrator
One position switch Timeline is off, location remains in another activity Check App Permissions, Timeline, and Web and App Activity Read Google's notices about other location settings
Report as a complete history The seven-day window is taken as the date of purchase Turn on the report and read it as a measurement after switching on Do not infer the past that the report did not collect
Advertising ID as a permanent identity AAID or IDFA is confused with IMEI or IMSI Reset or delete advertising ID, check ATT Separate advertising from network and device
Operator chat content The operator is expected to have WhatsApp text Separate metadata according to ZoEK from application content Don't assign keys to a network that it doesn't have
Hygiene as network reset Uninstalling the app is considered a deletion by the operator Compare the NÚKIB recommendation with § 97 ZoEK Reduce application risk and specifically address the network

Interpretation scheme: This is not a risk ranking. It is a map of places where one administrator is often confused with another.

This changes the practical question. We don't ask if we have enough data about ourselves. We ask if we know which data is missing from the report. An overview is only useful if it does not create a false sense of completeness.

Therefore, a good overview does not end with export. It should end with a question after absence. I can't see operator traffic data in Takeout; that's not Takeout's failure. In the App Privacy Report, I can't see what the app sent before turning on the report; that's not proof it didn't happen. I don't see the body of the end-to-end chat in the operator statement; this is not a loophole in the network, but a feature of a separate application. Each output should read not only what it contains, but also what, in principle, it cannot contain.

4. A device is not an account

The IMEI identifies the mobile device. GSMA in the TS.06 standard describes IMEI as a unique identifier of mobile equipment; it is the identity of the device in the technical layer of the network, not the name of the person in civil life.[19] A Google or Apple account is another kind of identity. Logs users in for services, backups, photos, history, and purchases. He can switch to a new phone and the old device can be wiped.

This does not mean that IMEI is meaningless. It follows that it does not answer the same question as the account. When an operator sees a device on the network, it does not mean that they see the entire content of the Google account. When Google enables account export through Takeout, it does not mean that it provides a listing of everything that happened in the operator's radio network.

The practical fallacy is simple. A person sells a phone, buys a new one and believes that he is starting from scratch. The device may be new. There is no account. Account history, synced contacts, photos and settings can continue. Conversely, a person can erase the phone and still have the data in the account. The same word "mobile" covers two different things here.

A cleaner sentence reads: the device is the carrier and participant of technical relations, the account is the longer-term identity of the service. Sometimes they overlap. They are never the same.

5. An OS is not an application

The operating system sets the framework. Manages permissions, shows warnings, allows accesses to be allowed, restricted or removed. The application in this framework asks for a specific ability. He may need it for a legitimate function. Maps without location work differently than maps with location. A video call without a camera ceases to be a video call.

But this does not mean that every authorization is reasonable. The flashlight app does not need contacts. The game does not necessarily know the exact location. NÚKIB, in its recommendations for suddenly popular applications, draws attention to caution with authorizations that are not related to the purpose of the application and the choice of authorized stores.[10]

With App Store privacy labels, Apple distinguishes between data used for tracking, data associated with the user, and data that is not associated with the user.[9] This is not a guarantee that every application will be error-free. It's an attempt to describe the data flow beyond the "enable" button itself. And that's where the next layer starts: developer, analytics SDK, ad network and server.

So an OS is not an application. The system can force a question and show a report. However, he does not need to know the business reason why the application collects the data, nor how its operator will use it after sending it to the server. Therefore, when checking your own phone, it is necessary to read both columns: what the system allowed and who the application belongs to.

The same permission icon can mean different situations. A navigation app may need your location for a route. A weather app can do with the city. A loyalty program app may want location for marketing purposes. The system dialog usually does not tell the whole business model. It tells which technical gate is opening. If the opening is reasonable, the user must judge from the purpose of the service, the credibility of the developer and whether the permissions can be narrowed.

6. A position has more switches than a single switch indicates

Location is one of the pieces of data we are most quick to create a false sense of security. We have turned off location history, so Google no longer stores your location. But Google's documentation warns that turning off Timeline or Location History alone may not stop location data from being stored from other settings and sources, such as Web and App Activity, Maps, photos, or IP address.[4][5]

It's not one secret trick. It is a property of layers. App exact location, account timeline, location derived from search and location from IP address are not the same switch. Each is created differently and each is managed differently.

In the VŠIT 2025 survey, the CZSO states that 52 % of people aged 16+ in the Czech Republic have at least once changed their access to the geographic location of a device.[1] That number measures the claimed change in access for people 16+ in private households in 2025. It doesn't measure whether they currently have location turned on, how many apps are using it, or whether it's exact or approximate location.

How to test location

For your own phone, it makes sense to go through three places. First, the Location permission for individual applications. Second, the timeline or location history in your Google account. Third, Web and App Activity. If any report says "location is disabled", you have to ask: which location, in which account and for which service?

One position switch is not enough. Google says so explicitly.

— Jiný Kontext

7. Advertising ID is not a social security number

The advertising identifier is useful precisely because it is not the same as a permanent device number. Android Advertising ID can be reset or deleted; Google Play policy states that zeroes are returned to apps after deletion.[6] As of iOS 14,5, iPadOS 14,5, and tvOS 14,5, Apple IDFA is tied to consent to tracking across third-party apps and websites in App Tracking Transparency mode.[8]

This does not mean that advertising will disappear. It follows that a particular way of tracking is limited or must have consent. The application can display contextual advertising, can measure its own service, can work with a logged-in account. ATT is not a ban on advertising. It is a rule for certain tracking across applications and data brokers.

Likewise, an advertising ID is not an IMEI, IMSI or phone number. The IMEI belongs to the device.[19] IMSI belongs to SIM and network. The telephone number belongs to the subscriber relationship. The advertising identifier is the measurement and advertising layer. When these layers are mixed together, the alarmist phrase that one app knows the "phone identity" emerges. Sometimes he knows the bill. Sometimes an advertising ID. Sometimes permission. Each case must be analyzed separately.

In addition, Google Play prohibits the use of other persistent identifiers as a substitute for an Advertising ID for advertising purposes if the User has reset or deleted the Advertising ID.[6][21] This is a rule of the ecosystem, not a law of nature. Its importance rests on the enforcement, auditing and behaviour of specific applications.

8. The App Privacy Report is not a forensic image

App Privacy Report on iPhone is a powerful tool for self-inventory. It will show apps' accesses to location, photos, camera, microphone, contacts, and domains that apps communicate with. Apple describes it for iOS and iPadOS 15,2 and later; the report covers the last 7 days, the data is encrypted on the device and the collection starts only after switching on.[7]

This precision is its limit. It's not seven days since you bought the phone. The report is not a record of everything the application has ever sent to the server. Turning off the report deletes the data.[7] So when a user turns on the report on Monday and doesn't see any suspicious activity on Wednesday, all they can say is: in this window and during this usage, that activity didn't show up.

It is not a weakness of the tool. It is an accurate description of its scope. A forensic image would deal with different questions, different authorizations and different procedures. This text is not an instruction to bypass the lock, PIN or encryption. The App Privacy Report belongs to the inventory of your own device. It helps to see which applications reach sensitive places, but it does not replace a request to the operator of the application or exporting the account.

What needs to be tested

On the iPhone, it makes sense to turn on the report and use the phone normally throughout the week. For Android, you need to go through app permissions and ad ID in settings. In both cases, the test measures its own footprint. Not a foreign device, not bypassing a foreign account, not the work of the police.

9. A deposit is not a phone

The phone can be empty and the account full. It can be broken and backup live. It can be in your pocket and the photos are synced to the cloud in the meantime. Therefore, it is misleading to ask only what is physically in the device.

Google Takeout allows you to export data from selected account services.[3] Apple offers insights and tools within account privacy and security.[9] The user thus sees a different layer than when opening the phone's settings. It can find data that is no longer on the device, or find that something remains only locally.

In addition, the deposit changes the issue of security. When the content is protected end-to-end, the service manager may not have readable content available. When not protected or when the user uses older settings, the range may be different. This article does not add new backup share or gigabyte numbers because the file does not contain such data. This is more accurate than an estimate.

The practical sentence is: if I am interested in the phone, I must also ask about the account and deposit. If I'm interested in an account, I'm not allowed to automatically infer the status of each device from it.

The deposit is also a frequent place of family misunderstanding. One person deletes a photo from their phone and means "I deleted it". The other will find it on the tablet or in the web interface of the same account. Both may be right depending on the layer they are currently seeing. Therefore, it is more accurate to talk about deletion in the device, in the account, in the trash of the service and in the backup separately. The GDPR recognises the right to erasure under conditions, but even there the request is aimed at the administrator and specific processing, not at the physical feeling that inhands hold one device.[15][20]

10. The operator does not read WhatsApp

The operator sees the network layer. Maintains the participation agreement, billing, operational data and defined location data. Czech § 97 paragraph 3 of the Electronic Communications Act requires providers to store operational and location data for a period of 6 months; at the same time, this mode does not explicitly involve the retention of message content.[13]

That's a substantial cut. Metadata of a call, SMS or data connection is not the body of a message in a chat application. End-to-end encryption separates the content from the network that carries the packets. The operator can provide the connection and still not have the key to the content of the WhatsApp conversation.

This does not mean that metadata is innocent. Who, when, from where and how often communicates can be sensitive even without the text of the message. But it follows that the sentence "the operator reads WhatsApp" confuses the network and the application. If someone is handling chat content, they need to ask about the app, account, device, and encryption settings. If it resolves a traffic trace, it looks at the network.

This distinction is also important for a GDPR application. The request to the operator according to Article 15 is aimed at data processed by the operator as administrator.[15][16] It is not a request to dump a foreign application.

11. Comprehensive retention of metadata is not the same as an obligation from the Union

The Czech data retention regime has its own legal dispute. The Supreme Court stated in a press release on the judgment 30 Cdo 2556/2025 of 8. 1. 2026 that the Czech general regulation of the storage of electronic communication data is contrary to EU law.[14] The commentary Iuridicum Remedium reminds us that such a decision does not automatically rewrite the text of the law or every practice of the operators.[22]

This means two things at once. It is not accurate to say that "the European Union requires blanket retention of metadata". The dispute is just heading against flatness. But it's also not accurate to say that there is no network layer of retention since the Supreme Court's press release. As of September 2026, the file is working with the fact that the text of Section 97, paragraph 3 of the ZoEK formally continues.[13][14][22]

For this article, the separation of layers is mainly important. Even if the legal regime of the operator changes, it will not make the App Privacy Report a statement from the operator and Takeout network access. One layer will change. Not the whole phone.

12. Takeout is access to the account. There is no access to the entire phone

The GDPR right of access is a powerful tool, but not a magic key to all data in digital life. Art. 15 gives the data subject the right to obtain confirmation and information about the processing from the controller; Article 12 paragraph 3 stipulates a response without undue delay and usually within 1 month, with the possibility of an extension of up to 2 months for more complex or numerous requests.[15]

The manager is specific. Google is responsible for selected account services. Apple for its services and account. Operator for subscriber relationship and operational data. Application developer for own processing in the application and on the server. In the instructions on the right of access, the EDPB analyzes the relationship between the data subject and the administrator; it does not assume that there is one universal "phone" manager.[16]

Takeout is a practical example. Google describes it as a way to download data from your account and selected services.[3] It is not an image of the phone's flash memory. It is not access to carrier data. It's not a guarantee that every third-party app will output everything the same.

Therefore, a good request does not start with the sentence "send me what the mobile knows about me". It starts with the administrators map. To whom is the request directed? What account, contract or application is involved? What period and what category of data is sought? The precision of the question increases the chance that the answer will not be correct only formally.

13. Application downloads do not measure what the SDK sends

CZSO in VŠIT 2025 states that 57.3% of smartphone users downloaded at least one application in the last 3 months; in absolute terms, there are 4,269.7 thousand people, which corresponds to 49.1% of all people aged 16+ in the survey.[1] The number is useful. He says that installing applications is a common activity for a significant part of smartphone users in the Czech Republic in 2025.

But it doesn't say how many SDKs are in an average app. It doesn't say how many permissions users have granted. It doesn't say whether the app sent data to a developer, ad network, or analytics service. And it doesn't say if it was an app from the official store or a sideload.

That is why it makes sense to read NÚKIB's recommendations alongside the statistics. Statistics describe the extent of usage. NÚKIB recommends caution with applications, authorized stores, updates and restraint with permissions that are not related to the purpose of the application.[10][11][12]

In instructions 2/2023 on the technical scope of Article 5, paragraph 3 of the ePrivacy Directive, the EDPB reminds that the rule does not only apply to cookies in the browser, but generally to access to information in the terminal device and its storage.[17][18] Therefore, mobile applications are not a legal vacuum just because they are not a web cookie bar.

14. NÚKIB hygiene reduces the layer of applications. It does not reset the network

Safety hygiene makes sense. Downloading applications from official stores, updating the system, reading permissions, deleting unused applications and paying attention to suddenly popular services is reasonable. NÚKIB repeats these recommendations in materials for safe movement in cyberspace and for travel.[10][11][12]

The error arises when we read the hygiene of one layer as the erasure of all layers. Uninstalling the app can reduce the risk of it being accessed again. It doesn't have to delete data already submitted by developers. It does not change the subscriber contract with the operator. It does not change the legal regime for keeping operational and location data according to Section 97, paragraph 3 ZoEK.[13]

Similarly, resetting the advertising ID will reduce the continuity of advertising measurement in the given mode. It will not change the IMEI of the device, network SIM or account login. Turning off one location history does not mean that all location data in all services is gone.[4][5]

This is no reason to resign. It's a reason to name what we're doing right now. Application hygiene is work at the application layer. Account export is an account layer job. The request to the operator is work at the network layer. Each has its own meaning and its own niche.

This is where you can tell good advice from false certainty. A good tip will tell which layer to shrink and which to leave. False security promises that one step will erase your entire digital life. Neither uninstall, nor ad id reset, nor a single location switch can do that.

15. Phone usage figures do not measure data content

The CZSO in VŠIT 2025 states that 99.1% of people aged 16+ in private households in the Czech Republic used a mobile phone, i.e. 8,610.0 thousand people.[1] Smartphones were used by 85.8% of people aged 16+, i.e. 7,456.3 thousand people.[1] 82.7% of people 16+ used the Internet on a mobile phone, i.e. 7,185.0 thousand people.[1]

These numbers have both a clear power and a clear limit. It measures the spread of devices and internet usage in 2025 for a defined population. It does not measure the data content of the phones. It does not measure the number of applications on an average device. It does not measure the share of iOS and Android in the Czech Republic in the tables that the dossier read. It does not measure how much data is in the backup.

The age cut shows further caution. At the age of 65-74, 67.5% of the cohort used a smartphone and 33.1% of the same cohort used a push-button phone.[1] For people 75+, the file states that 34.8% will have a smartphone in 2025, compared to 14.5% in 2019.[1] That is growth and minority at the same time. Without this caveat, the elderly could easily be described as either digitally excluded or fully smartphone-savvy. Neither number alone is enough.

The CZSO press release from 11/11/2025 states that 81 % of people 16+ used the internet daily in the 2nd quarter of 2025, and in the context of the report it is mentioned that the most common device is the telephone.[2] But even that is not a measure of what the phone knows. It is a measurement of internet usage.

16. An inventory of your own layers will say more than the sentence the phone knows everything

The practical test is not intended to teach how to bypass foreign locks, foreign accounts or legal procedures. It is supposed to help a person find his way in his own way. A secure inventory starts where the user has the right and access: with their own account, their own device and their own operator.

Three tests of own tracks

The first test is to export the account. For Google, it is about Takeout and the selection of services that the user has in his account.[3] For Apple, it's accounts and privacy settings in the account and device.[9] The result must be read as a layer of the account, not as a whole phone.

The second test is the device. You can turn on the App Privacy Report on the iPhone and use the phone normally for a week; the output will show the last 7 days after turning on the report.[7] On Android, it makes sense to go through app permissions and advertising IDs, including the option to reset or delete.[6]

The third test is the network. The request according to Article 15 of the GDPR is directed to the operator itself and concerns the data it processes as a controller; the response period according to Article 12, paragraph 3 is usually 1 month, with the possibility of an extension of up to 2 months.[15][16] It is not a request for a foreign participant.

If one administrator really merged the operating system, store, account, advertisement, network and backup into one file available from one request, the main thesis would weaken. Google, Apple and ZoEK documentation do not describe such a single file.[3][7][13]

17. A hidden load is one device that we read as one document

A smartphone is practical precisely because the layers disappear from view. With one tap, we open the bank, maps, messages, photos, work chat, shop, backup and navigation. The user experience connects what is legally and technically not connected.

This creates a hidden cost. When something goes wrong, we don't know where to ask. We resolve suspicions about the application with the operator. We look for the position in the account in the device switcher. We read the statement from the operator as the content of the communication. We read the report for the last 7 days as a history since the purchase. And we read the statistics on the spread of smartphones as statistics on data content.

No need to claim that the phone is innocent. There is no need to claim that he knows everything either. The right question is more precise and less convenient: which layer knows what, according to which rule, with which administrator, and how do we know what is missing from the answer?

Such a question is slower than an alarmist headline. But it has one advantage. It leads to an action that can actually be taken: download your own account, go through permissions, turn on reporting, reset your ad ID, request an admin, and note what each step doesn't fix.

The moment we hold the phone in our hand, we are holding the device. The moment we ask for data, we enter a network of accounts, applications, advertising identifiers, operators and backups. And then the question is no longer: "What does the mobile phone know about you?"

It's: which administrator holds which trail — and which layer did you just forget to check?

Evidence record

How this article was made

Method, the role of AI, corrections and source details in one place.

Sources and further reading22 sources
  1. Official statisticschap. 3 and 16, tab. 3,1–3,3. https://csu.gov.cz/produkty/vyuzivani-informacnich-a-komunikacnich-technologii-v-domacnostech-a-mezi-osobami-gnzqheaxdo
    Statistics: CZSO. Use of ICT in households and between persons - · 2025
  2. Official statisticshttps://csu.gov.cz/produkty/umelou-inteligenci-pouziva-tretina-populace
    Statistics: CZSO. Press release A third of the population uses artificial intelligence , 11. 11. · 2025
  3. Other sourceFirm: Google. How to download your Google data (Takeout). https://support.google.com/accounts/answer/3024190
  4. Other sourceFirm: Google. Manage location/timeline history. https://support.google.com/accounts/answer/3118687?hl=en
  5. Other sourceFirm: Google. Timeline data management (position may remain in other settings). https://support.google.com/accounts/answer/14200149?hl=en
  6. Other sourceFirm: Google Play. Advertising ID (resettable, deleteable; zero after deletion). https://support.google.com/googleplay/android-developer/answer/6048248
  7. Other sourceFirm: Apple. About App Privacy Report (iOS 15,2+, 7 days, on-device). https://support.apple.com/en-us/102188
  8. Other sourceFirm: Apple. If an app asks to track your activity (ATT, IDFA, data brokers). https://support.apple.com/en-us/102420
  9. Other sourceFirm: Apple. App privacy features / Personal Safety (turning on the report). https://support.apple.com/guide/personal-safety/app-privacy-features-in-apple-products-ipsd4dac4a2c/web
  10. Institutional sourcehttps://nukib.gov.cz/cs/infoservis/doporuceni/2214-nukib-doporucuje-obezretnost-v-pouzivani-nahle-popularnich-aplikaci/
    Office: NÚKIB. Recommendations for suddenly popular apps, 30/01/ · 2025
  11. Institutional sourceOffice: NÚKIB. Safe movement in the cyber world (brochure). https://nukib.gov.cz/download/publikace/doporuceni/Doporuceni_bezpecny_pohyb_v_kyber_svete_brozura_cb.pdf
  12. Institutional sourceOffice: NÚKIB. Cybersecurity while traveling (OS updates, official stores). https://nukib.gov.cz/download/aktuality/20220124_Kyberbezpe%C4%8Dnost_p%C5%99i_cestov%C3%A1n%C3%AD.pdf
  13. Other sourceColl., on electronic communications, § 90 and § 97. https://www.zakonyprolidi.cz/cs/2005-127#p97
    Law of the Czech Republic: Act No. 127/ · 2005
  14. Book8. 1. 2026. https://www.nsoud.cz/pro-verejnost-a-media/tiskove-zpravy/detail/nejvyssi-soud-potvrdil-protipravnost-plosneho-uchovavani-dat-o-elektronicke-komunikaci-1
    Court of the Czech Republic: High Court. Press release on 30 Cdo 2556/ · 2025
  15. Other sourceEU law: GDPR, Art. 12, 15, 17, 20. https://www.zakonyprolidi.cz/pravoeu/dokument?celex=32016R0679
  16. Institutional source— right of access. https://www.edpb.europa.eu/system/files/2024-04/edpb_guidelines_202201_data_subject_rights_access_v2_en.pdf
    Supervision: EDPB. Guidelines 01/ · 2022
  17. Institutional source— technical scope of Article 5(3) of Directive 2002/58/EC. https://www.edpb.europa.eu/system/files/documents/2025-02/edpb_guidelines_202302_technical_scope_art_53_eprivacydirective_v2_en.pdf
    Supervision: EDPB. Guidelines 2/ · 2023
  18. Other source/58/EC (ePrivacy), Article 5(3). https://eur-lex.europa.eu/legal-content/CS/TXT/?uri=CELEX:32002L0058
    EU law: Directive · 2002
  19. Other sourceIndustry standard: GSMA. TS.06 IMEI Allocation and Approval Process (IMEI uniquely identifies ME). https://imeidb.gsma.com/imei/resources/documents/TS.06%20v28,1%20IMEI%20Allocation%20and%20Approval%20Process.pdf
  20. Other sourceSupervision of the Czech Republic: ÚOOÚ A basic guide to data protection. https://uoou.gov.cz/verejnost/zakladni-prirucka-k-ochrane-udaju
  21. Other sourceFirm: Google Play Developer Program Policy (App Set ID ≠ Advertising ID). https://support.google.com/googleplay/android-developer/answer/17517561?hl=en
  22. Other sourceComment on practice: Iuridicum Remedium / ochranudaju.cz. Quo Vadis, Data Retention? https://www.ochranaudaju.cz/aktuality/quo-vadis-data-retention