- Published Articles
- In the Press
- Press Releases
Sign Up for Alerts
Sign up to receive receive industry-specific emails from our legal team.
Sign Up for Alerts
We provide tailored, industry-specific legal updates to our clients and other friends of the firm.
Areas of Interest
January 10th, 2013
California Releases New Mobile App Privacy Recommendations
California's Attorney General recently released a set of official privacy recommendations for consideration by mobile app developers, mobile ad networks and related industry players. The recommendations, published in a report entitled, "Privacy on the Go: Recommendations for the Mobile Ecosystem," include development and disclosure recommendations that encourage participants in the mobile app ecosystem to consider privacy at the outset of the app design process and to focus on minimizing surprises to users from unexpected privacy practices. Although some of the recommendations are already required by existing law, most of them are provided for purposes of educating the industry and promoting privacy best practices.
This report comes on the heels of recent enforcement actions initiated by the California Attorney General against mobile app producers, as well as a recent FTC report critical of mobile app privacy practices.
The report includes the following suggestions:
I. Recommendations for App Developers
- Consider privacy at the outset of the development process. Create checklists to review the personally identifiable information ("PII") your apps could collect, and to help you make privacy decisions about data collection, use, disclosure, and retention.
- Avoid or limit collections of "sensitive information" (e.g., precise geo-location, financial and medical data, stored data such as contacts or photos, children's information, etc.) and any PII not needed for your app's basic functionality. Do not retain PII longer than strictly necessary.
- Provide users with control settings to help them manage how their information is treated, especially for sensitive information. Develop mechanisms to give users access to their PII.
- Use an app-specific or other non-persistent device identifier rather than a persistent, globally unique identifier.
- Make sure the app's default settings are privacy protective.
- Use security safeguards (such as encryption) to protect PII from unauthorized access, use, disclosure, modification or destruction.
- Comply with applicable laws (such as laws pertaining to Apps directed to children) and industry requirements (such as Payment Card Industry Data Security Standards).
- Designate someone in your organization to have responsibility for App privacy and provide appropriate training to employees concerning privacy.
II. Recommendations for Mobile Ad Networks
- Avoid delivering ads outside of the context of the app. For example, avoid modifying users' mobile web browser settings or placing icons on their mobile desktops. However, if ads will be delivered outside of the app, obtain prior consent from users, and provide clear attribution to the applicable host app.
- Use enhanced communication methods (e.g., just-in-time notices), and obtain prior consent from users, before accessing PII.
- Use app-specific or temporary device identifiers, rather than device-specific identifiers.
- Transmit user data securely.
III. Recommendations for App Platform Providers
- Allow users to access and review Privacy Policies for apps from within the app platform prior to their download of the app.
- Educate app developers about their privacy obligations, and encourage consumers to look for relevant privacy policies and controls.
- Provide users with tools to report non-compliant apps.
IV. Recommendations for Others
- Developers of operating systems for mobile devices - such as Apple, Google, and Microsoft - are encouraged to develop global privacy settings that allow users to control the information and device features accessible to apps.
- Mobile Carriers are encouraged to educate mobile customers on mobile privacy, especially with respect to children.
For more information on the report, or legal issues associated with mobile apps, please contact Greg Boyd at (212) 826 5581 or firstname.lastname@example.org; or any other member of the Technology, Digital Media & Privacy or Advertising Groups.
Other Advertising Law Alerts
FTC Updates Endorsement Guide FAQs and Settles First-Ever Action Against Individual “Influencers”
Recent developments demonstrate the FTC's continued interest in social media endorsements.
September 11 2017
FTC Announces Reforms to Its Investigative Process
Recently, the FTC announced a set of internal reforms intended to improve the process by which the Commission investigates unfair, deceptive and fraudulent business practices. The reforms relate to the Civil Investigative Demands ("CID") that the FTC's Bureau of Consumer Protection issues to request information from investigation targets.
September 7 2017
End of an Era at NAD?
Last week Frankfurt Kurnit's Advertising Group proudly hosted "A Twenty-Year NAD Retrospective: The Levine Legacy," an ABA program honoring Andrea Levine, on the occasion of her retirement as Director of NAD. With NAD transitioning to new (as yet unnamed) leadership, we thought it would be a good time to review some of the best practices that guide NAD practitioners every day.
July 10 2017