Mobile app stores to require, disclose privacy policies
California's attorney general announced guidelines developed with major companies to make privacy policies readily available to mobile users
IDG News Service - Apple, Google and other mobile platform providers will present privacy policies for all the apps offered in their stores as part of an agreement with the state of California.
California Attorney General Kamala Harris announced an agreement developed with mobile platform companies including Apple, Google, Research In Motion, Amazon, Hewlett-Packard and Microsoft, to ensure that all mobile apps will offer privacy policies that users can read before downloading the app.
Although the plan technically only applies to apps in use in California, it will affect the global marketplace by making privacy policies visible to all users who download apps through the Android Marketplace, the App Store or any of the other platforms hosted by the participating companies.
Just 5 percent of all mobile applications offer a privacy policy, according to a study conducted by TrustE and Harris Interactive. (A developer survey conducted by the Future of Privacy Foundation found that one-third of apps offer such policies.) Even those that do have such policies often make the information available to users only after they have downloaded the app, which is when most programs grab data from the user's phone.
At a press conference in San Francisco announcing the agreement, Harris explained that it had previously been somewhat unclear to developers and platform providers whether the California Online Privacy Protection Act, which requires any "web site or online service that collects personally identifiable information through the Internet" to "conspicuously post its privacy policy," applied to mobile apps.
"There's been a question," Harris said, and "we have resolved that." Harris added that developers should be "on notice" that the state was prepared to enforce the newly clarified law, effective immediately, against both developers and platform providers that fail to comply.
"We take a great deal of pride in the technology that was born in our backyard," Harris said. "There's no desire on any of our parts to slow down what's potentially life-changing and world-changing technology. But we also shouldn't have to accept false choices" between privacy and access to innovation.
In a statement, Jules Polonetsky, director of the Future of Privacy Forum, agreed. "Apps can only provide innovative services to consumers if they use personal information responsibly," Polonetsky wrote. If they surprise consumers, he said, "they risk losing access to user data. The California agreement will ensure that consumers are protected and that the app environment continues to flourish."
The policy is, in some ways, symbolic. It will not limit what apps can grab from smartphones, which can include device ID numbers, email addresses, location, personal contacts and calendar entries. It simply requires apps to inform consumers, who, in fact, may not read such notices. Several privacy advocates and experts contacted by IDG News Service agreed that full resolution of the mobile privacy issue will have to include buy-in from platform operators and app developers, consumer education and potentially regulation.
The attorney general's announcement comes amid privacy controversies involving the social networking app Path, which is based in San Francisco, and Google, which was discovered by a Stanford graduate student to be tracking users' browser habits on the iPhone despite Safari's no-tracking default settings. Talks with the platform companies began in August of last year.
Asked how her office came to focus on mobile privacy, Harris said, "We all use apps." California also has "very tough rules against invasion of privacy," she said, "and those protections apply not only to intrusions by government but also by corporations."
Harris twice declined to comment on her office's position on Google's iPhone tracking.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All DRM and Legal Issues White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All DRM and Legal Issues Webcasts