California’s Department of Justice has issued a 23-page report on privacy in the mobile ecosystem – but we can still use these rules if we’re outside San Francisco, right?
The state of California has issued a 23-page document giving advice to app developers about keeping privacy practices in check, in part to help enforce its COPPA (California Online Privacy Protection Act) legislation.
This isn’t the first time a governing body has doled out tips for devs, of course; the US Federal Trade Commission (FTC) did similar back in September, handing out seven “general guidelines that all app developers should consider” including transparency concerning data practices and building privacy concerns in from the start of a development project.
The latter is also something which resonates with the Californian report, entitled ‘Privacy on the Go: Recommendations for the Mobile Ecosystem’.
“Our recommendations, which in many places offer greater protection than afforded by existing law, are intended to encourage all players in the mobile marketplace to consider privacy implications at the outset of the design process,” the report notes.
The highlights of the report for app developers were:
- Have a data checklist to review personally identifiable data your app collects, and bear it in mind when putting together a privacy policy
- Avoid or limit collecting unnecessary personally identifiable data (anything which does not contribute to the app’s basic functionality)
- Develop a privacy policy which is “clear, accurate and conspicuously accessible to users and potential users”
- Use enhanced measures, like special notices, to draw users’ attention to unexpected data practices
Of the 23 pages, a full seven are devoted to recommendations for app developers, as opposed to the three pages in total for app platform providers, advertising networks and ‘others’.
Going further into the report, and in particular privacy practices, the report advised to be transparent; limit data collection and retention; give users access to personally identifiable data; use security safeguards such as encryption; and be accountable to any privacy policy you draw up.
This all seems like common sense, and relate closely to the FTC guidelines of September.
But the Department of Justice is handing down lawsuits to those who aren’t complying with COPPA. Delta Airlines was the first company to face legal action back in December, with Attorney General Kamala Harris saying in a press release: “Losing your personal privacy should not be the cost of using mobile apps, but all too often it is.”
The full report can be read here. Are there any guidelines that you’re not following?