The US Federal Trade Commission (FTC) has issued several privacy guidelines in an attempt to help developers avoid getting bogged down in privacy difficulties.
A total of nine specific provisions were listed in the guidelines, titled ‘Marketing Your Mobile App’, with two coming under ‘truthful advertising’: tell the truth about what your app can do; and disclose key information clearly and conspicuously.
This is evidently to stop companies misleading customers, arguably in a manner similar to the Russian company Connect Ltd, who was earlier this week fined £50,000 by UK regulator PhonepayPlus for an extortionate SMS scheme.
If the FTC guidelines were enforced on this case of course Connect Ltd, trading as SMSBill, would have been guilty of not disclosing information “clearly and conspicuously” – given that the payment information for their app was not only buried on page six of the regs, but also was wrong.
Looking at privacy, the seven specific guidelines the FTC issued were:
- Build privacy considerations in from the start: Essentially ensuring each app development project is on a sure footing from the very first day – or, as the FTC put it, “privacy by design”.
- Be transparent about your data practices: The FTC has no problem with devs needing to collect or share data out so an app can work; however it recommended that the policy is to “be clear”.
- Offer choices that are easy to find and easy to use: Deploying tools that offer choices in how an app can be used. “Make it easy for people to find the tools you offer, design them so they’re simple to use, and follow through by honouring the choices users have made.”
- Honour your privacy promises: “Chances are you make assurances to users about the security standards you apply,” notes the FTC. “At minimum, app developers have to live up to those promises”. This appears to be a particular bugbear for the FTC, who has shot down “dozens” of companies that claimed good levels of security, but failed to do it day-to-day.
- Protect kids’ privacy: advising that, if an app is designed for children, there will almost certainly be extra compliance hoops to traverse, most notably the Children’s Online Privacy Protection Act (COPPA).
- Collect sensitive information only with consent: “It’s a mistake to assume they won’t mind”, says the FTC, especially with regard to medical and financial information – or even precise geo-location details.
- Keep user data secure: The FTC notes that the most effective way to keep user data secure is to collect only the data needed; take reasonable precautions against well-known security risks; limit access to a need-to-know basis; and ensure data is disposed of once no longer needed.
The FTC noted: “Of course, there’s no one-size-fits-all approach. Every app is different. Still, there are some general guidelines that all app developers should consider”.
There are plenty of difficulties associated with privacy and marketing your app. Do you agree that these guidelines are a good starting point?