Draft
Date: February 24, 2026
To: Sundar Pichai, Chief Executive Officer, Google
To: Sergey Brin, Founder and Board Member, Google
To: Larry Page, Founder and Board Member, Google
To: Vijaya Kaza, General Manager for App & Ecosystem Trust, Google
CC: Regulatory authorities, policymakers, and the Android developer community
Re: Mandatory Developer Registration for Android App Distribution

We, the undersigned organizations representing civil society, nonprofit institutions, and technology companies, write to express our strong opposition to Google’s announced policy requiring all Android app developers to register centrally with Google themselves in order to distribute applications outside of the Google Play Store, set to take effect worldwide in the coming months.

While we do recognize the importance of platform security and user safety, the Android platform already includes multiple security mechanisms that do not require central registration. Forcibly injecting an alien security model that runs counter to Android’s historic open nature threatens innovation, competition, privacy, and user freedom. We urge Google to withdraw this policy and work with the open-source and security communities on less restrictive alternatives.

Our Concerns

1. Gatekeeping Beyond Google’s Own Store

Android has historically been characterized as an open platform where users and developers can operate independently of Google’s services. The proposed developer registration policy fundamentally alters that relationship by requiring developers who wish to distribute apps through alternative channels — their own websites, third-party app stores, enterprise distribution systems, or direct transfers — to first seek permission from Google through a mandatory verification process, which involves the agreement to Google’s terms and conditions, the payment of a fee, and the surrendering of government-issued identification.

This extends Google’s gatekeeping authority beyond its own marketplace into distribution channels where it has no legitimate operational role. Developers who choose not to use Google’s services should not be forced to register with, and submit to the judgement of, Google. Centralizing the registration of all applications worldwide also gives Google newfound powers to completely disable any app it wants to, for any reason, for the entire Android ecosystem.

2. Barriers to Entry and Innovation

Mandatory registration creates friction and barriers to entry, particularly for:

Every additional bureaucratic hurdle reduces diversity in the software ecosystem and concentrates power in the hands of large, established players who can more easily absorb such compliance costs.

3. Privacy and Surveillance Concerns

Requiring registration with Google creates a comprehensive database of all Android developers, regardless of whether or not they use Google’s services. This raises serious questions about:

Developers should have the right to create and distribute software without submitting to unnecessary surveillance or scrutiny.

4. Arbitrary Enforcement and Account Termination Risks

Google’s existing app review processes have been criticized for opaque decision-making, inconsistent enforcement, and limited appeal mechanisms. Extending this system to all Android certified devices creates risks of:

A single point of failure controlled by one corporation is antithetical to a healthy, competitive software ecosystem.

5. Anticompetitive Implications

This requirement allows Google to collect intelligence on all Android development activity, including:

This information asymmetry provides Google with significant competitive advantages and may allow it to preempt, copy, or undermine competing products and services, and opens many questions about antitrust.

6. Regulatory concerns

Regulatory authorities worldwide, including the European Commission, the U.S. Department of Justice, and competition authorities in multiple jurisdictions, have increasingly scrutinized dominant platforms’ ability to preference their own services and restrict competition, demanding more openness and interoperability. We also acknowledge the growing concern on regulatory intervention increasing mass surveillance, impeding software freedom, open internet and device neutrality.

We urge Google to find alternative ways to comply with regulatory obligations by promoting models that respect Android’s open nature without increasing gatekeeper control over the platform.

Existing Measures Are Sufficient

The Android platform already includes multiple security mechanisms that do not require central registration:

No evidence has been presented that these safeguards are insufficient to continue to protect Android users as they have for the past seventeen years of Android’s existence. If Google’s concern is genuinely about security rather than control, it should invest in improving these existing mechanisms rather than creating new bottlenecks and centralizing control.

Our Petition

We call upon Google to:

  1. Immediately rescind the mandatory developer registration requirement for third-party distribution
  2. Engage in transparent dialogue with civil society, developers, and regulators about Android security improvements that respect openness and competition
  3. Commit to platform neutrality by ensuring that Android remains a genuinely open platform where Google’s role as platform provider does not conflict with its commercial interests

Over the years, Android has evolved into a critical piece of technological infrastructure that is depended on by hundreds of governments, millions of businesses, and billions of citizens around the world. Unilaterally consolidating and centralizing the power to approve software into the hands of a single unaccountable corporation is antithetical to the principles of free speech, an affront to free software, an insurmountable barrier to competition, and a threat to digital sovereignty everywhere.

We implore Google to reverse course, end the developer verification program, and to begin working collaboratively with the broader community to advance security objectives without sacrificing the open principles upon which Android was built. The strength of the Android ecosystem has historically been its openness, and Google must work towards restoring its role as a faithful steward of that trust.


Signatories

  1. AdGuard 🇨🇾 adguard.com
  2. The App Fair Project 🇫🇷 appfair.org
  3. ARTICLE 19 🇬🇧 article19.org
  4. Aurora Store 🇮🇳 auroraoss.com
  5. The Center for Digital Progress (D64) 🇩🇪 d-64.org
  6. The Chaos Computer Club (CCC) 🇩🇪 ccc.de
  7. Codeberg e.V. 🇩🇪 codeberg.org
  8. Cryptee 🇪🇪 crypt.ee
  9. Digitale Gesellschaft 🇨🇭 digitale-gesellschaft.ch
  10. The Digital Rights Foundation 🇵🇰 digitalrightsfoundation.pk
  11. Digital Rights Watch 🇦🇺 digitalrightswatch.org.au
  12. epicenter.works – for digital rights 🇦🇹 epicenter.works
  13. /e/ Foundation 🇫🇷 e.foundation
  14. European Digital Rights (EDRi) 🇧🇪 edri.org
  15. The Electronic Frontier Foundation (EFF) 🇺🇸 eff.org
  16. F-Droid 🇳🇱 f-droid.org
  17. IzzyOnDroid 🌐 izzyondroid.org
  18. The Free Software Foundation Europe (FSFE) 🇩🇪 fsfe.org
  19. The Free Software Foundation (FSF) 🇺🇸 fsf.org
  20. Ghostery 🇺🇸 ghostery.com
  21. The Guardian Project 🇺🇸 guardianproject.info
  22. JMP.chat 🇨🇦 jmp.chat
  23. Obtainium 🌐 obtainium.imranr.dev
  24. The OpenStreetMap Foundation (OSMF) 🇬🇧 osmfoundation.org
  25. Osservatorio Nessuno OdV 🇮🇹 osservatorionessuno.org
  26. Molly 🌐 molly.im
  27. Nextcloud 🇩🇪 nextcloud.com
  28. Open Rights Group (ORG) 🇬🇧 openrightsgroup.org
  29. Proton AG 🇨🇭 proton.me
  30. Rossman Group 🇺🇸 rossmanngroup.com
  31. Software Freedom Conservancy 🇺🇸 sfconservancy.org
  32. Techlore 🇺🇸 techlore.tech
  33. The Tor Project 🇺🇸 torproject.org
  34. Tuta Mail 🇩🇪 tutao.de
  35. Vivaldi Technologies AS 🇳🇴 vivaldi.com