Site navigation

UK Gov Introduces New Security and Privacy Rules for Apps

Graham Turner

,

Privacy Rules for Apps
In a bid to protect consumers from malicious apps which can steal data and money, the UK Government has introduced new rules for app store operators and developers.

Millions of people across the UK use apps on their smartphones, game consoles and smart TVs for a wide range of everyday activities such as work, communication, entertainment and banking.

However, there’s a lack of rules governing the security of apps and the app stores where they are accessed, which opens the door for malware.

Consumers are also often unable to make informed choices when deciding to download an app because they don’t have important information such as who has access to their data, or where it is stored and processed.

In response to a call for views earlier this year, the government will request that the app industry signs up to a new code of practice in the hopes of boosting security and privacy requirements on all apps and app stores available in the UK.

The voluntary code of practice for app developers and operators is a world-first and will protect the UK’s app market, with the mobile app market alone generating more than £74 billion in revenue last year.

The new measures include requiring apps to have a process so that security experts can report software vulnerabilities to developers, making sure security updates are highlighted properly to users and that security and privacy information is provided to users in a clear and easy-to-understand way.

Cyber minister Julia Lopez said: “More people are using apps to pay bills, play games and stay in touch with loved ones, with so much of our day-to-day activities now online.

“Consumers should be able to trust that their money and data is in safe hands when using apps and these measures will not only boost our digital economy but also protect people from fraud.

“We’ve already strengthened our laws to boost security in consumers’ digital devices and the telecoms networks we rely on. Today we are taking steps to get app stores and developers to keep customers even safer in the online world.”

The government will work with operators and developers to support them with implementing the voluntary code over a nine-month period. This includes companies such as Apple, Google, Amazon, Huawei, Microsoft, LG, Epic Games, Nintendo, Valve, Sony and Samsung.

Alongside this, the Department for Digital, Culture, Media and Sport (DCMS) will work to explore what current laws could be extended to cover apps and app stores and whether regulation is needed to mandate the code in the future.

Under the code, app store operators and developers will need to:

  • Share security and privacy information in a user-friendly way with consumers. Examples include when an app is made unavailable on an app store, when an app was last updated and the locations where users’ data are stored and processed for each app.
  • Allow their apps to work even if a user chooses to disable optional functionality and permissions, such as preventing the app accessing a microphone or knowing a user’s location.
  • Have a robust and transparent app vetting process in place which ensures only apps which meet the code’s minimum security and privacy rules are published on their stores.
  • Provide clear feedback to developers when an app is not published on their store for security or privacy reasons.
  • Have a vulnerability disclosure process in place, such as a contact form, so software flaws can be reported and resolved without being made publicly known for malicious actors to exploit.
  • Ensure developers keep their apps up to date to reduce the number of security vulnerabilities in apps.

Many developers and operators already follow some of these requirements and those which adopt the code will be able to demonstrate they’re following its principles by declaring this on their company website, app website or app store.

The government is collaborating with international partners to develop international support for the code and will explore the possibility of creating an international standard for apps and app stores.


Recommended


The new voluntary rules are part of the government’s £2.6 billion National Cyber Strategy which aims to protect and promote the digital economy, strengthen the UK’s cyber resilience and ensure businesses have the best security standards in place to protect their users.

Paul Maddinson, NCSC Director of National Resilience and Strategy, said: “Our devices and the apps we rely on are increasingly essential to everyday life, and it’s important that developers and app store operators take steps to protect users.

“By signing up to this code of practice, developers and operators can demonstrate how they are delivering security as standard, as well as protect users from malicious actors and vulnerable apps.”


Get all the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data