MOBILE APPLICATIONS (APPS)
Those entities involved in the development, distribution, and exploitation of mobile applications, particularly those that perform the role of data controllers or joint controllers within their respective areas of responsibility, as well as other stakeholders involved in the mobile app ecosystem, such as, among others, application developers and library developers, have the following obligations:
Obligation to inform:
- The information provided to users regarding the processing of their personal data must comply with the requirements set out in Articles 13 and 14 of the GDPR and Article 11 of the LOPDGDD, particularly with regard to layered information, as outlined in the “Guide for Compliance with the Obligation to Inform” and the “Ten-Point Guide for Adapting Privacy Policies to the GDPR on the Internet”.
- This information, in the form of a privacy policy, must be available both within the application and on the app store. In this way, the user will be able to review it before installing the application or at any time during its use.
- Access to the privacy policy must be easily achievable from within the application, requiring the user to perform a minimal number of interactions, ideally no more than two clicks, as recommended by the Article 29 Working Party in its guidelines.
- The data controller must be clearly identified in the privacy policy.
- The information about the processing must be complete and consistent both in the app store, if applicable, and within the application itself. There should be no discrepancies between the two.
- The language used to describe the privacy policies must be appropriate for the target user of the application, considering their age and level of understanding.
- The privacy policies must be clear and specific regarding the processing of personal data carried out.
Data controllers who outsource the development, deployment, and/or operation of applications to third parties with access to personal data must ensure compliance with the requirements set out in the GDPR for each party involved.
While the device displays a notification requesting the user's authorization to access such resources, in many cases, the information provided is insufficient in the context of the GDPR, and the granularity of the permission is not correctly specified, as it must include, among other information, the purpose of the data processing. The need to access these resources must be properly disclosed in the application's privacy policy, so that the user can decide whether or not to grant authorization for the application to access these resources.