Site navigation

ICO Urges App Developers to Prioritise User Privacy

Elizabeth Greenberg

,

user privacy
The call for privacy comes after a review of fertility and period apps, though the investigation found no data protection wrong-doings. 

The Information Commissioner’s Office (ICO) is reminding all app developers to ensure they protect user privacy, following the regulator’s review of period and fertility apps.

Last year, the ICO looked closely at period and fertility apps to understand how they process personal data and identify whether there is any negative impact on users as a result.

The review saw the ICO contact several app providers to find out more about their privacy practices, as well as engaging with app users to understand their experiences.

While no serious compliance issues or evidence of harms were identified, the ICO has still issued a reminder to all developers about the importance of protecting users’ personal information, especially where sensitive information is involved.

“Signing up to an app often involves handing over large amounts of personal information, especially with apps that support our health and wellbeing,” Emily Keaney, deputy commissioner regulatory policy, said.

“Users deserve peace of mind that their data is secure, and they are only expected to share information that is necessary.

“When we announced we were looking into period and fertility apps, we received a helpful response from users who were able to share their experiences with us. We want to reassure users that we haven’t found any evidence these apps are using their data in a way that could cause them harm.

“However, our review has highlighted there are improvements app developers could make to ensure they are meeting all their obligations to be transparent with their users and keep their data safe.”

The regulator has shared four practical tips to help app developers comply with data protection obligations and maintain the privacy of their users.

Be transparent

Developers need to ensure their apps are being transparent with how they use people’s personal information. This means providing users with information including: the purpose for processing personal data, the retention periods of that data, and who it will be shared with.

The ICO calls this ‘privacy information’, and it must be concise, clear, and easily accessible.

Obtain valid consent

Genuine consent means offer people a real choice, the ICO says. App developers must therefore ensure they have the right to consent to use people’s personal information.


Recommended reading


Data protection law sets a high standard for consent, which must be explicit, unambiguous, and involve a clear action to opt-in.

Platforms must not use pre-ticked boxes or any default method for consent, and must make it easy for people to withdraw their consent at any time.

Establish the correct lawful basis

Data protection law requires platforms to have a valid lawful basis to process personal data, such as consent, contract, or legitimate interests.

When deciding on a lawful basis, platforms must consider the purposes and context of their processing to determine which lawful basis is most appropriate – companies cannot adopt a one-size-fits-all approach.

Be accountable

Developers must be held accountable for the personal information they and their platforms hold. If a developer is determining the purpose and means of processing data, then they are the data controller, and are responsible for complying with data protection law.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data