- Published Articles
- In the Press
- Press Releases
Sign Up for Alerts
Sign up to receive receive industry-specific emails from our legal team.
Sign Up for Alerts
We provide tailored, industry-specific legal updates to our clients and other friends of the firm.
Areas of Interest
January 10th, 2013
California Releases New Mobile App Privacy Recommendations
California's Attorney General recently released a set of official privacy recommendations for consideration by mobile app developers, mobile ad networks and related industry players. The recommendations, published in a report entitled, "Privacy on the Go: Recommendations for the Mobile Ecosystem," include development and disclosure recommendations that encourage participants in the mobile app ecosystem to consider privacy at the outset of the app design process and to focus on minimizing surprises to users from unexpected privacy practices. Although some of the recommendations are already required by existing law, most of them are provided for purposes of educating the industry and promoting privacy best practices.
This report comes on the heels of recent enforcement actions initiated by the California Attorney General against mobile app producers, as well as a recent FTC report critical of mobile app privacy practices.
The report includes the following suggestions:
I. Recommendations for App Developers
- Consider privacy at the outset of the development process. Create checklists to review the personally identifiable information ("PII") your apps could collect, and to help you make privacy decisions about data collection, use, disclosure, and retention.
- Avoid or limit collections of "sensitive information" (e.g., precise geo-location, financial and medical data, stored data such as contacts or photos, children's information, etc.) and any PII not needed for your app's basic functionality. Do not retain PII longer than strictly necessary.
- Provide users with control settings to help them manage how their information is treated, especially for sensitive information. Develop mechanisms to give users access to their PII.
- Use an app-specific or other non-persistent device identifier rather than a persistent, globally unique identifier.
- Make sure the app's default settings are privacy protective.
- Use security safeguards (such as encryption) to protect PII from unauthorized access, use, disclosure, modification or destruction.
- Comply with applicable laws (such as laws pertaining to Apps directed to children) and industry requirements (such as Payment Card Industry Data Security Standards).
- Designate someone in your organization to have responsibility for App privacy and provide appropriate training to employees concerning privacy.
II. Recommendations for Mobile Ad Networks
- Avoid delivering ads outside of the context of the app. For example, avoid modifying users' mobile web browser settings or placing icons on their mobile desktops. However, if ads will be delivered outside of the app, obtain prior consent from users, and provide clear attribution to the applicable host app.
- Use enhanced communication methods (e.g., just-in-time notices), and obtain prior consent from users, before accessing PII.
- Use app-specific or temporary device identifiers, rather than device-specific identifiers.
- Transmit user data securely.
III. Recommendations for App Platform Providers
- Allow users to access and review Privacy Policies for apps from within the app platform prior to their download of the app.
- Educate app developers about their privacy obligations, and encourage consumers to look for relevant privacy policies and controls.
- Provide users with tools to report non-compliant apps.
IV. Recommendations for Others
- Developers of operating systems for mobile devices - such as Apple, Google, and Microsoft - are encouraged to develop global privacy settings that allow users to control the information and device features accessible to apps.
- Mobile Carriers are encouraged to educate mobile customers on mobile privacy, especially with respect to children.
For more information on the report, or legal issues associated with mobile apps, please contact Greg Boyd at (212) 826 5581 or firstname.lastname@example.org; or any other member of the Technology, Digital Media & Privacy or Advertising Groups.
Other Advertising Law Alerts
The Truth Will Set You Free: The FTC Provides New Guidance on Consumer Reviews
Late last year, Congress passed the Consumer Review Protection Act, a law designed to stop businesses from using contracts to prevent customers from posting honest reviews about the business.
March 8 2017
FTC Finds “All Natural” Claim Violated FTC Act
The FTC has issued a Final Order against California Naturel, Inc., a seller and marketer of personal care products, finding that the company's "all natural" claims were false and misleading in violation of the FTC Act.
December 15 2016
FTC Policy Statement Focuses on Homeopathic Health Claims
Last week, the Federal Trade Commission issued its new "Enforcement Policy Statement on Marketing Claims for Over-the-Counter (OTC) Homeopathic Drugs," as well as a staff report on a workshop that the Commission held last year on OTC homeopathic drug advertising.
November 28 2016