Beginning of this year, the California Attorney General issued a report entitled “Privacy on the Go” which provided much-needed recommendations as to how the mobile ecosystem should function, move forward, but do so with privacy in mind.
The FTC (Federal Trade Commission) issued its own report the next month in February; with a similar; but expanded title: “Mobile Privacy Disclosures; Building Trust Through Transparency.”
Clearly the floodgates had been opened on an overdue discussion and debate around how the rise of mobile applications should specifically operate; beyond what’s required by more general data protection legislations.
On May 9th, Rep. Hank Johnson introduced “The Application Privacy, Protection, and Security Act of 2013” (APPS) at Congress.
Johnson’s summary: “The APPS Act would require that app developers maintain privacy policies, obtain consent from consumers before collecting data, and securely maintain the data they collect.”
So will it affect all app developers? No. Only those developers whose applications collect users’ personal data need worry; although (without any actual statistics) that’s almost certainly a pretty high percentage.
Since April 2nd, the “Code of Conduct” found in the FTC’s report requires any app which collects; biometrics (such as Apple’s new 5S fingerprint scanner), browser history, text log, contacts, financial information, health/medical/therapy information, location or user files… to all offer a privacy notice.
In order to comply with the act, app developers must create their own notice which clearly states four aspects; what data is to be collected, how it will be used, whom it will be shared, and how the data is retained (for how long and how to delete.)
Google’s “Play Store” on Android already offers a basic form of compliance as part of their security measures; with a notice about the app showing the access and permissions it requires before a user begins the download.
In the same respect as “more general” protection legislations such as the ‘Data Protection Directive’ in the United States, and the ‘Data Protection Act’ in the United Kingdom – developers must put reasonable precautions in place to prevent data being accessed without authorisation.
Don’t forget this Act is alongside these other legislations – not instead of – and others such as; the Children’s Online Privacy Protection Act (COPPA), or state-level law such as the California Online Privacy Protection Act (CalOPPA), must all be complied with.
What do you think about the Apps Act of 2013? Required legislation?