Apple Mandates Privacy Manifests for Apps and SDKs to Enhance Data Collection Transparency
October 11, 2026
Apple requires a privacy manifest (PrivacyInfo.xcprivacy) to document data collection and required-reason API use for both apps and included SDKs, and these manifests must be discoverable in the app bundle.
Privacy manifests must include data types collected, required-reason API reasons, and a tracking declaration (NSPrivacyTracking) with domains (NSPrivacyTrackingDomains) when tracking is used.
There are four top-level keys to include: NSPrivacyTracking, NSPrivacyTrackingDomains, NSPrivacyCollectedDataTypes, NSPrivacyAccessedAPITypes; for each required-reason API category, include reasons that reflect actual shipped usage.
If SDK behavior is unclear, consult vendor materials and confirm with exact dependency versions; this guide does not replace broader privacy/compliance checks.
Inventory the app targets and SDKs, identify distribution forms, and determine which manifests each SDK contributes; follow Apple’s guidance for SDKs, including static libraries via Xcode 15 for bundling resources.
Follow a repeatable release review: inventory targets/SDKs, verify SDKs require manifest, document data/API/tracking behavior per component, confirm manifests are bundled, generate privacy report, and re-run on changes.
Do not rely on an SDK’s manifest being covered by an app’s manifest; the component using the API must report its own usage in its manifest.
The guidance references Apple documentation and a related privacy-label article for AI-built apps; ensure alignment with current inventories and materials.
In Xcode, create PrivacyInfo.xcprivacy via File → New File and ensure the manifest is included in the target’s resources for proper reporting.
For each component, compare manifest declarations with actual data collection, API use, tracking behavior, and tracking domains; ensure accuracy and alignment with shipped functionality.
Data-collection information applies on all platforms, while required-reason API information is required on iOS, iPadOS, tvOS, visionOS, and watchOS; treat these as separate checks.
Summary based on 1 source
Get a daily email with more Tech stories
Source

OTF • Oct 11, 2026
Apple privacy manifests: declare data and required-reason API use