Back to Blog
Privacy

Apple and Google: The 2025 Tracking Protection Landscape

December 15, 2025
7 min read

By Siva J.P., Privacy Research Lead at WysLeap

When Apple intensified its privacy warnings in October 2025, singling out Chrome's fingerprinting practices, it marked the latest salvo in an ongoing privacy war between the tech giants. The timing was strategic: according to browser market share data, Chrome consistently holds over 65% of the global browser market share, making Apple's critique a direct challenge to how the majority of internet users are tracked. But beneath the competitive posturing lies a more complex reality: both companies are reshaping how the internet tracks users—sometimes as rivals, sometimes as collaborators—and businesses need to understand what's changing and why it matters for their analytics strategy.

Recent 2025 Tracking Warnings

In October 2025, Apple intensified its stance against Google's tracking methods, specifically targeting the Chrome browser and raising concerns about user privacy. This marked a significant escalation in the ongoing privacy debate between the two tech giants, coming just months after Italy's antitrust authority fined Apple €98.6 million ($116 million) in December 2025 over its App Tracking Transparency (ATT) feature. Apple's privacy documentation has consistently emphasized the importance of user control over tracking, positioning Safari as a more private alternative to Chrome.

Fingerprinting Concerns

Apple has warned that Google Chrome allows "secretive fingerprinting," a method that uses extensive device characteristics (like installed fonts, plugins, hardware details, and other system-level information) to create a unique profile that users cannot disable or opt out of. This technique bypasses traditional cookie-based tracking and creates persistent cross-site identifiers without user consent or transparency. Apple's privacy documentation emphasizes that such methods undermine user control over their data, noting that invasive fingerprinting can track users even when they clear cookies or use private browsing modes.

Important distinction: Not all fingerprinting is created equal. Consent-based analytics platforms use limited, transparent fingerprinting methods (typically only basic browser and screen characteristics) for first-party analytics only, with clear user disclosure and GDPR compliance. This differs from the invasive, cross-site fingerprinting that Apple criticizes, which collects extensive device data without user knowledge or consent.

Safari Protections

Apple promotes Safari as a more private alternative through its Intelligent Tracking Prevention (ITP) and Advanced Tracking and Fingerprinting Protection features. Safari simplifies system configurations so millions of iPhones appear identical to trackers, effectively masking individual identities. This approach makes fingerprinting significantly more difficult by reducing the uniqueness of device characteristics. Safari's fingerprinting protection works by standardizing certain browser characteristics and limiting access to device-specific information that could be used to create unique identifiers.

Collaborative Efforts

Despite their rivalry, the two companies have partnered on industry-wide standards to prevent "unwanted tracking," demonstrating that privacy concerns can sometimes bridge competitive divides.

Bluetooth Tracker Alerts

In May 2024, Apple and Google announced their collaboration on the "Detecting Unwanted Location Trackers" (DULT) standard, which was finalized in 2025. This collaboration ensures that both iOS (version 17.5+) and Android (version 6.0+) now send automatic alerts if a compatible Bluetooth tracker (like an AirTag or Pebblebee) is detected moving with the user, regardless of which operating system the tracker was originally paired with. According to Apple's official announcement, users receive an "[Item] Found Moving With You" alert, allowing them to view the tracker's identifier, play a sound to locate it, and access instructions to disable it. The DULT working group at the Internet Engineering Task Force (IETF) is standardizing the protocol, with milestones set for July 2025 to publish the standards document defining the protocol to detect and interact with unwanted tracker accessories.

This cross-platform notification system represents a significant step forward in user privacy, protecting users from unwanted location tracking regardless of their device choice. The implementation addresses growing concerns about the misuse of tracking devices like AirTags for stalking or unauthorized surveillance, demonstrating how competitive rivals can collaborate when user safety is at stake.

Fundamental Differences in Tracking Models

The companies remain ideologically split on how they handle user data for their business models, which directly impacts their approach to tracking protections.

Apple's Approach

Apple relies primarily on hardware sales, which allows it to take a more aggressive stance on privacy. The company uses App Tracking Transparency (ATT) to require third-party apps to ask for explicit user permission before tracking them across other companies' apps and websites.

  • Hardware-first business model enables stronger privacy stance
  • App Tracking Transparency (ATT) requires explicit user consent
  • Safari's Intelligent Tracking Prevention (ITP) blocks cross-site tracking
  • Privacy labels on App Store provide transparency

Google's Approach

Google relies heavily on advertising revenue, which creates a different set of priorities. While it has introduced the Privacy Sandbox to replace individual tracking with "cohort-based" tracking, it still collects extensive data within its own ecosystem of apps (Gmail, Maps, Search) to power its ad network. Google's Privacy Sandbox documentation and the Privacy Sandbox website outline its approach to balancing privacy with advertising effectiveness, including proposals like Topics API, FLEDGE, and Attribution Reporting API.

  • Advertising-first business model requires data collection
  • Privacy Sandbox aims to balance privacy with ad effectiveness through cohort-based targeting
  • Extensive data collection within Google's own ecosystem (Gmail, Maps, Search, YouTube)
  • Gradual transition from third-party cookies to alternative methods, with full cookie deprecation planned for 2024-2025

The Reality: Both Companies Collect Data

While Apple positions itself as the privacy champion, it's important to note that both companies collect substantial user data. Apple gathers information through iCloud (photos, documents, backups), Apple Maps (location data, search queries), Siri (voice interactions, search history), and the App Store (purchase history, app usage patterns). Similarly, Google collects data through its ecosystem of services including Gmail, Google Maps, Search, and YouTube.

The key difference isn't whether they collect data, but how they use it: Apple monetizes primarily through hardware sales and services (iCloud subscriptions, App Store commissions, Apple Music, etc.), while Google monetizes through advertising revenue. This fundamental business model difference explains why Apple can take a more aggressive stance on third-party tracking—it doesn't depend on ad revenue in the same way.

Both companies face increasing regulatory pressure from the EU's Digital Markets Act (DMA) and similar legislation worldwide. The DMA, which came into full effect in 2024, designates both Apple and Google as "gatekeepers" and requires them to open their platforms to more competition, allow users to uninstall pre-installed apps, and provide more transparency about data collection. This regulatory pressure is a major driver behind many of the privacy changes we're seeing—companies are adapting not just out of goodwill, but to comply with new legal requirements.

Understanding this context is crucial for businesses: the privacy landscape isn't just about user preferences or competitive positioning—it's also shaped by regulatory mandates that are forcing both companies to change how they handle user data, regardless of their business models.

How to Limit Tracking

Users have more control than ever over their tracking preferences. Here's how to limit tracking on both platforms:

📱On iPhone

  • 1.Navigate to Settings > Privacy & Security > Tracking
  • 2.Disable "Allow Apps to Request to Track"
  • 3.Manage location services under Privacy > Location Services

🤖On Android

  • 1.Go to Settings > Privacy > Ads
  • 2.Reset your advertising ID or opt-out of personalized ads
  • 3.Manage location permissions under Privacy > Location

What This Means for Analytics

The intensifying privacy protections from both Apple and Google have significant implications for web analytics. Traditional tracking methods are becoming less reliable, making privacy-conscious alternatives increasingly important. Businesses relying on cookie-based analytics or third-party tracking pixels are already seeing declining accuracy and will face even greater challenges as these protections intensify.

Analytics platforms designed to work within these new constraints provide accurate visitor insights without relying on cookies or invasive fingerprinting techniques that violate user privacy expectations. These solutions use alternative identification methods that respect user privacy while still delivering valuable analytics data. The key is finding platforms that balance accuracy with privacy compliance.

Key Takeaways for Businesses

  • Privacy is non-negotiable: Users expect and demand better privacy protections
  • Traditional tracking is declining: Cookies and invasive fingerprinting are being blocked
  • Privacy-respecting analytics work: You can still get valuable insights while respecting user privacy
  • Future-proof your analytics: Adopt cookieless solutions now to avoid disruption later

The Future of Privacy-Conscious Analytics

As Apple and Google continue to strengthen privacy protections, businesses need analytics solutions that respect user privacy while still providing valuable insights. Modern analytics platforms designed with privacy in mind are built to meet this challenge, offering:

  • Accurate visitor identification without cookies or invasive fingerprinting
  • GDPR and privacy regulation compliance built-in
  • Advanced features like intent scoring and accuracy metrics
  • Transparent data practices that build user trust

The privacy landscape is evolving rapidly, and businesses that adapt early will be better positioned for long-term success. By choosing analytics solutions that align with these new privacy standards, you can future-proof your analytics while building stronger relationships with your visitors.

When evaluating analytics platforms, prioritize solutions that are designed to work within the new privacy constraints from the ground up, rather than retrofitted to comply. Look for platforms that offer transparent data practices, provide clear documentation about their tracking methods, and demonstrate compliance with GDPR, CCPA, and other privacy regulations. This ensures you're getting a solution that's built for the future, not just adapted to the present.

Actionable Steps for Businesses

  1. Audit your current analytics: Review what data you're collecting and how it's being tracked. Identify dependencies on cookies or third-party tracking.
  2. Update your privacy policy: Ensure it accurately reflects your data collection practices and complies with current regulations.
  3. Test cookieless alternatives: Evaluate analytics platforms that don't rely on cookies to understand their accuracy and capabilities.
  4. Plan for transition: Develop a migration strategy that minimizes disruption while improving privacy compliance.
  5. Monitor regulatory changes: Stay informed about new privacy regulations and how they might affect your analytics strategy.