News

Why Governments Ban Apps: 5 Risk Questions, Explained

Why Governments Ban Apps on Official Devices

When governments ban apps on official devices, the headline and the decision rarely match. The measures taken in 2023 by the European Commission, the United States, Canada and the United Kingdom were internal device policies for staff, issued by the bodies that manage those devices, and in several cases the announcements said in terms that they did not apply to personal phones or to the public. This article sets out what those documents actually say, the questions a security review asks, and the objections raised against this kind of measure.

Updated October 2026. This is a description of published decisions and of the arguments made on each side. It is not legal advice, it takes no position on any country or company, and policies change.

governments ban apps: Fediverse smartphone apps (photo by Elena Rossini)
Fediverse smartphone apps (photo by Elena Rossini) by Elexfedi, CC BY-SA 4.0, via Wikimedia Commons

Why governments ban apps on their own devices: four documented cases

The European Commission’s Corporate Management Board suspended use of the TikTok application on Commission corporate devices, and on personal devices enrolled in the Commission mobile device service, in February 2023. The published statement describes the aim as protecting the Commission against cybersecurity threats and actions that may be exploited for cyber-attacks against its corporate environment, and describes the measure as an internal corporate decision strictly limited to devices enrolled in its mobile service.

In the United States, the No TikTok on Government Devices Act was enacted in the Consolidated Appropriations Act, 2023, and OMB memorandum M-23-13 of 27 February 2023 set the deadlines. Within 30 days agencies had to identify the application’s use or presence on information technology, set up a process for limited exceptions, remove and disallow installations on agency owned or operated systems, and block internet traffic from those systems to the application. Contract requirements followed at 90 days and solicitation requirements at 120. Exceptions are permitted only for law enforcement activities, national security interests and activities, and security research, must be granted by an agency head or designee, cannot cover a whole agency, and last up to one year before review.

Canada’s Treasury Board announced its measure on 27 February 2023, effective the following day, removing the application from government-issued mobile devices and blocking future downloads after the Chief Information Officer of Canada found an unacceptable level of risk to privacy and security. The same statement noted that there was no evidence at that point that government information had been compromised. On 30 October 2023 the same approach was applied to WeChat and to Kaspersky applications, again on government-issued devices only, and the announcement said that for the public the decision to use a social media application or mobile platform is a personal choice.

The United Kingdom announced its ban on 16 March 2023, covering government corporate devices across all departments, with exemptions possible case by case with ministerial approval for work such as enforcement or online harms research. The Cabinet Office review behind it looked at the vulnerability of government data on social media apps and at how sensitive information could be accessed and used. The announcement stated that the ban did not extend to personal devices for government employees, ministers or the general public.

5 risk questions a device review asks

  1. What can the app reach? Contacts, location, clipboard, microphone, files and device identifiers, measured against what the app needs to do its job.
  2. Where does the data go and rest? Which companies and which jurisdictions hold it, and which processors sit in between.
  3. Who could lawfully compel disclosure? Not whether anyone has, but which legal powers could reach the data and what obligations the holder would be under.
  4. How are updates delivered and verified? An app is a channel that can change after installation, so the integrity of the update path matters as much as the current version.
  5. What does aggregation reveal? One official’s location history is a privacy question. Thousands of officials, correlated, is a pattern-of-life question about an institution.

Notice what that list does not contain: a finding that the software is malicious. When governments ban apps on managed devices, the published reasoning is almost always about what the structure permits. The Canadian statement is explicit that no evidence of compromise had been found, and the Commission’s reasoning is framed around threats that may be exploited rather than incidents that occurred. Reviews of this kind assess what the legal and technical structure makes possible, which is why a company can truthfully say it has handed over nothing while a regulator still concludes the risk is unacceptable for its own staff.

The arguments against

Objections come in three recognisable forms, and it is worth stating them as their proponents do. The first is scope creep: measures that begin as device policies become proposals to restrict the public, and those raise free expression questions that a staff handbook does not. The American Civil Liberties Union has argued against nationwide restrictions on exactly that basis, saying such a step would need to be necessary to prevent extremely serious and immediate harm to national security, and warning that broad powers to block foreign owned applications set a precedent.

The second is proportionality. Critics point out that the data practices being described are common across the mobile advertising industry, so singling out individual applications addresses the symptom and leaves the market intact. The third is evidential: because these reviews turn on capability rather than proven incidents, there is often no public finding to examine, which makes the decisions hard to scrutinise from outside. Supporters answer that waiting for proof of compromise is not a defensible standard for devices holding government business.

What it means if you are not a civil servant

  • Read the scope line. Most of these announcements say who is covered. If it says corporate or government-issued devices, your own phone is not in scope.
  • Separate the two debates. A device policy for staff and a nationwide restriction on an app are different decisions, with different legal tests and different consequences.
  • Apply the questions to yourself. Permissions you have granted, and what a work and personal phone share, are the parts you control.
  • Expect more than one app. Canada’s October 2023 decision covered a messaging app and a security vendor, which is a reminder that these reviews are about data flows and legal exposure, not one category of software.

The practical takeaway is mundane. The same hygiene that protects a managed device protects yours: fewer permissions, separation between work and personal accounts, passkeys instead of reused passwords, and a clear idea of what a VPN actually protects. If you want the other half of the picture, how feeds decide what you see, read how recommendation algorithms work.

Common questions

When governments ban apps, who is actually covered? The staff and devices the issuing body manages. The 2023 measures named corporate or government-issued devices, and in Canada and the United Kingdom the announcements said expressly that they did not reach personal devices or the general public.

Do these decisions mean malware was found? No. Canada stated there was no evidence at that point that government information had been compromised, and the reasoning published by these bodies is about risk and capability rather than a proven incident.

Who takes the decision? The body that manages the devices. In the EU it was the Commission’s Corporate Management Board, in the United States the Office of Management and Budget through memorandum M-23-13, in Canada the Treasury Board acting on the Chief Information Officer’s assessment, and in the United Kingdom the Cabinet Office.

Are exceptions allowed? Yes, narrowly. M-23-13 permits exceptions only for law enforcement, national security interests and activities, and security research, granted by an agency head, documented, not applied across a whole agency, and reviewed within a year. The UK allows case by case exemptions with ministerial approval.

Why do critics object if only staff phones are affected? Mainly because of what follows. Civil liberties groups argue that restrictions on the public engage free expression and require a far higher standard of justification, and that broad powers to block applications set a precedent.

Sources and further reading

Where the figures and rules above come from, so you can check them:

Photo credit: Fediverse smartphone apps (photo by Elena Rossini) by Elexfedi, CC BY-SA 4.0, via Wikimedia Commons.

Join the discussion

Held for review before it appears. Links are not allowed and your email is never published.