Showing posts with label mobile privacy. Show all posts
Showing posts with label mobile privacy. Show all posts

Wednesday, February 6, 2013

Mobile Application Privacy: NTIA Publishes Latest Multistakeholder Transparency Draft for Comment


The National Telecommunications and Information Administration ("NTIA"), part of the U.S. Department of Commerce, has been convening multistakeholder meetings to work on improvements to data collection/use transparency--an effort called for in the Obama Administration's Consumer Privacy Bill of Rights. On February 4th, 2013, the NTIA released the latest discussion draft of its Code of Conduct for Mobile Application Transparency. The goals of this initiative, as stated in the latest draft, are to "balance the objectives of transparency, brevity and functionality," or more specifically:


  • Transparency: Consumers expect clear, succinct explanations of an app’s data collection and third party data sharing policies.
  • Brevity: Short form notices must enhance app transparency and understanding in context.
  • Functionality: App developers need transparency standards that they can easily implement in the context of an app without diminishing the user experience.
  • Consumers hold a spectrum of attitudes towards sharing their data with apps. Consumers’ willingness to share data will vary with context and time, and apps should facilitate those choices.
  • Regulators, legislators, and privacy and consumer advocates all seek a fair balance among all of the interests involved, recognizing some consumers’ choice to share data with apps in exchange for a wide variety of tools, content, entertainment.
  • Apps will evolve over time to offer fixes, enhancements, and changes to the original functionality. Apps may need to offer new functionality and/or they may need to adapt their business models. When apps’ data policies evolve in material ways, the apps must promptly and prominently update their disclosures to consumers.
  • Continued work will need to be done to help integrate the full range of fair information practices with effective methods of transparency for innovative data uses. App developers understand that the implementation of these principles is just one aspect of satisfying consumer expectations and they commit to leading their industry to develop common practices and tools that adhere to fair information practices (these principles include access to personal information, control over storing information and sharing it with third parties).
  • App Developers who adhere to this code of conduct and provide short form notice as described in Section II, are engaging in a best practice that significantly enhances transparency of data practices. This code reflects the state of industry best practices for transparency. Although compliance with the code and provision of a short form notice does not guarantee that any individual developer is providing an accurate notice for their specific practices, the authors of this code believe that compliance with the standardization provided by this notice should be a compelling factor serving to limit claims that a notice is deficient.
According to John Verdi, Director of Privacy Initiatives for the NTIA,comments and proposed changes on the latest discussion draft should be sent either to Tim Sparapani or Verdi himself by February 18, 2013. Verdi further states that "[c]omments from prospective adopters are particularly encouraged!"

The informational page for the multistakeholder process on moible application transparency, including meeting schedules and other relevant links, may be found here.

Wednesday, November 28, 2012

Mobile App Privacy: A Slowly Expanding Area

The area of consumer privacy is a broad area that has been discussed, analyzed and given guidance by both the Federal Trade Commission and the White House. Mobile application privacy, an important subset of consumer privacy, is an area of privacy that has been receiving significant attention over the past year as the importance of the mobile platform increases.

The push for protection in mobile app privacy most clearly began with a Joint Statement of Principles laid out by the California Attorney General, created in February 2012. The California Joint Principles represent an agreement by several top companies in the mobile industry. The agreement, which includes Apple, Google, Research In Motion, HP, and Microsoft (in addition to Facebook, which signed on in June), states what these companies promise to do in their mobile app store. The agreement reached by the major mobile companies provides that the California Online Privacy Protection Act is applicable to any application that collects personal data from a consumer. Such an app requires a “conspicuously posted” privacy policy. The agreement provides that when an app is submitted to a mobile app store by the developer there should be a hyperlink to the privacy policy or the actual privacy policy for that particular app. The privacy policy, whether a hyperlink or the full text, should be available in the mobile app store prior to download of the app. The major mobile companies must also provide a method for users to report apps that do not have such a policy or whose policy does not comply with applicable law.

In addition to the Joint Principles, the FTC has released a new Report on marketing mobile applications, in September of 2012, that contains suggestions on how to limit privacy concerns in a mobile app.  The FTC suggests that mobile app creators:

Build privacy considerations in from the start.  The FTC calls this “privacy by design.”… Incorporating privacy protections into your practices, limiting the information you collect, securely storing what you hold on to, and safely disposing of what you no longer need.  Apply these principles in selecting the default settings for your app and make the default settings consistent with what people would expect based on the kind of app you’re selling.  For any collection or sharing of information that’s not apparent, get users’ express agreement.  That way your customers aren’t unwittingly disclosing information they didn’t mean to share.
Be transparent about your data practices….Offer choices that are easy to find and easy to use…Honor your privacy promises…The FTC has taken action against dozens of companies that claimed to safeguard the privacy or security of users’ information, but didn’t live up to their promises in the day-to-day operation of their business.  The FTC also has taken action against businesses that made broad statements about their privacy practices, but then failed to disclose the extent to which they collected or shared information with others – like advertisers or other app developers…Protect kids’ privacy…
Collect sensitive information only with consent.  Even when you’re not dealing with kids’ information, it’s important to get users’ affirmative OK before you collect any sensitive data from them, like medical, financial, or precise geolocation information.  It’s a mistake to assume they won’t mind.
Keep user data secure...The wisest policy is to:
  •  collect only the data you need;
  • secure the data you keep by taking reasonable precautions against well-known security risks;
  • limit access to a need-to-know basis; and
  • safely dispose of data you no longer need.
As mobile app privacy is a new and growing area, the actual implications on businesses are not yet clear. The California Joint Statements only require that those mobile app store providers will provide a location for the individual app’s privacy policy. This only implicitly requires that mobile app creators should have a privacy policy. The FTC guidelines are less stringent. As stated in its report on consumer privacy, the FTC does not believe that they have the powers, at this time, to broadly regulate the area of privacy. However, the FTC suggestions show what the the Commission might enforce if given the power to do so by Congress.

(Written by Brett Alazraki, Fall 2012 IBLT Entrepreneurship Assistance Fellow)