This unit needs a preamble, because it is the area where the most mistaken beliefs circulate: in the great majority of cases, an app with too many permissions does not produce an incident. It produces data collection — which is a different thing, ordinary and largely regulated.
Serious consequences do exist, but they concern a minority of cases and specific permissions. Telling them apart is more useful than being alarmed about everything.
It expands on the recommendation checking what your apps can do.
The three levels of consequence
| Level | What happens | Frequency |
|---|---|---|
| 1. Ordinary collection | Data used for advertising and profiling | Very common |
| 2. Extended sharing | Data passed to third parties beyond expectation | Common |
| 3. Improper use | Permissions exploited to cause harm | Rare |
Almost everything that happens is at level 1. The consequences described as dramatic belong to level 3, which is rare and nearly always concerns apps installed outside the official stores.
1. The financial consequences
At levels 1 and 2 they are indirect: the advertising you see, the offers you receive, the prices you are shown. Diffuse costs, hard to quantify.
At level 3 they become direct, and they nearly always go through two specific permissions:
| Permission | Possible consequence |
|---|---|
| Access to notifications | Reading verification codes |
| Accessibility | Reading typed credentials, actions taken on your behalf |
| Drawing over other apps | Fake forms shown on top of real apps |
| Sending messages | Subscriptions to paid services |
The first row is the most relevant, because it links this unit to the one on multi-factor authentication: an app reading notifications sees the codes as they arrive, and so the second factor stops being an obstacle.
2. The consequences for other people
It is the most underestimated aspect of this unit, and it is worth putting at the centre.
The address book handed over. When you grant access to contacts, you share the data of dozens or hundreds of people: names, numbers, emails, sometimes addresses. None of them consented, and none will ever know.
The shared calendar. A work calendar contains the names of attendees, the places, the times. It describes an organisation and the relationships between the people working in it.
Photos with other people. Access to the gallery includes images featuring family, friends, colleagues.
The messages you receive. If an app reads notifications, it also reads what other people write to you.
That changes the nature of the decision: you are not only deciding for yourself. It is the strongest argument for granting access to contacts sparingly, and the reason many systems now offer to share only selected contacts.
3. The professional consequences
A personal device used for work. If the phone holds company mail, documents and contacts, an app with broad permissions reaches those too. In many organisations this is governed by rules, and responsibility for what is installed on the device falls on whoever uses it.
Clients’ contacts. Handing over the address book means handing over the professional details of people who gave them for a working relationship.
The company calendar. Meetings, attendees, places: information describing activity under way.
Apps installed by colleagues. On shared or informally managed devices, permissions granted by one apply to everybody.
None of these is an emergency. Together, though, they justify a practice many organisations adopt: separating the work device from the personal one, or using the separate profiles modern systems offer.
4. The psychological consequences
Here they take a particular shape, tied to the misunderstanding about listening.
The feeling of being listened to. It is by far the most widespread belief, and it produces real discomfort — even though continuous listening finds no technical confirmation. The discomfort comes from a genuine experience: the advertising seems to know. And it does know, but by other routes.
Knowing it comes from profiling and not from the microphone changes the emotional effect little, but it changes a great deal about what can be done: against imaginary listening there is no remedy; against profiling there is.
Resignation. “Everything is collected by now anyway.” It is understandable and it produces inaction. In this unit more than others it is unfounded, though: revoking a permission has an immediate effect, and the effect is verifiable.
The proportionate remedy. Look at the list. It does not solve profiling — which comes through many other routes — but it gives back a decision where there was an automatism.
Three situations, three outcomes
To make the distinction between the levels concrete.
Level 1 — The photo-editing app with access to contacts. Mark granted the permission years ago. The app transmitted the address book to its own service, which uses it to suggest friends and for profiling. Outcome: no incident. The consequences are diffuse — more targeted advertising — and they also concern the contacts, who will never know. Revoking stops future collection; what was transmitted remains.
Level 2 — The game sharing more than expected. Helen installed a free game with broad permissions. The game passes the data to several advertising analytics services. Outcome: more intense profiling, and data circulating among parties she does not know and did not choose. It is the declared business model of many free apps, and it is largely legal.
Level 3 — The accessibility app installed on request. John receives a message with a link to an app presented as an assistance tool. To work it asks for accessibility, and guides him step by step through turning it on. Outcome: potentially serious. That app can read what appears on the screen, credentials included, and act on his behalf.
The first two cases are resolved by revoking a permission. The third requires uninstalling the app, changing the credentials of the main services and checking recent sign-ins.
The difference between the three is not the amount of data: it is the specific permission that was granted.
What to do, in order
If you granted excessive permissions:
- Revoke whatever has no functional reason, starting from accessibility, notifications, contacts.
- Check the apps with powerful permissions that you do not recognise, and uninstall them.
- Check the devices linked to your accounts, if an app had broad access.
- Change the credentials of the main services if an app had accessibility or access to notifications.
If you handed the address book to an app that should not have had it:
- Revoke the permission, which stops future collection.
- Know that the data already transmitted remains where it ended up: uninstalling does not delete it.
- If the volume is significant, there is the possibility of requesting deletion under the data protection rules.
Point 4 is the one not to skip: they are the only two permissions that can have compromised credentials.
The consequences on children’s devices
A case deserving space, because it combines several unfavourable factors.
More apps. A teenager’s phone typically has many more than an adult’s, and with a higher turnover.
Less assessment. Permission requests get accepted quickly, often because the app is needed right away for a social reason.
More free apps. The business model based on data collection is more present in the categories young people use most.
Particularly sensitive data. Location, contacts, photos, and the network of relationships.
Consequences that last. A profile built at fifteen stays with a person for a long time.
What genuinely helps, in order of effectiveness:
Reviewing the permissions together, not secretly. A review done together teaches a criterion; one done without their knowledge only produces a reset at the first opportunity.
Explaining the criterion, not the rule. “A game does not need your contacts” is reasoning that transfers to other cases; “never give permissions” does not.
Turning on automatic revocation for unused apps, which does the maintenance without asking anything.
Using family controls in measure. They exist and can be useful, especially for younger children. They should be calibrated to the age, though: a tool suited to eight, kept at sixteen, nearly always produces the opposite of the intended effect.
This is, at bottom, an educational subject more than a technical one — and it is where this recommendation meets the wider sense of the Framework: skills stay, settings change.
How long these consequences last
| Consequence | Reversible? |
|---|---|
| Future collection by the app | Yes, immediately: revoke the permission |
| Excessive permissions still active | Yes: revoke or uninstall |
| An account created inside the app | Yes, but it has to be closed separately |
| Data already transmitted | Partly, through the request the rules provide for |
| Data passed to third parties | With difficulty |
| A shared address book | No: it concerns other people’s data, already out |
| Credentials seen through accessibility | No, but they can be changed |
The first three rows close in a few minutes, and they are most of the situation.
The last is the only one requiring action beyond revoking: if an app had accessibility or access to notifications, the credentials of the main services should be changed, because they may have been seen.
The sixth row is the one that cannot be recovered, and it is why access to contacts deserves more caution than it usually gets: it is not data you can take back, because it was not yours.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Telling ordinary collection from improper use |
| Skills | Knowing which two permissions can compromise credentials |
| Secure Behaviour | Considering that the decision also concerns other people |
Reference level: FL2 — Beginner.
Summary
- Almost everything that happens is ordinary collection, not an incident.
- The serious consequences go through two permissions: accessibility and access to notifications.
- Granting access to contacts means deciding for other people too.
- The feeling of being listened to is real, the cause is profiling — and that can be reduced.
One thing to do today. Check which apps can read your notifications. It is the permission that, in this unit, can do the most damage — and the one almost nobody looks at.
Related content
- Checking what your apps can do — the recommendation this expands on
- Impact of excessive permissions — what each permission allows
- How to review granted permissions — the complete procedure
- Permission abuse — how level 3 comes about
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



