{"id":2677,"date":"2024-10-11T14:23:09","date_gmt":"2024-10-11T14:23:09","guid":{"rendered":"https:\/\/cleach.com\/?p=2677"},"modified":"2024-10-11T14:23:11","modified_gmt":"2024-10-11T14:23:11","slug":"new-cnil-guidelines-towards-better-personal-data-protection-in-mobile-applications","status":"publish","type":"post","link":"https:\/\/cleach.com\/en\/new-cnil-guidelines-towards-better-personal-data-protection-in-mobile-applications\/","title":{"rendered":"New CNIL Guidelines: Towards Better Personal Data Protection in Mobile Applications"},"content":{"rendered":"<p style=\"text-align: justify;\">On September 24, 2024, the CNIL published a recommendation aimed at helping professionals develop and implement mobile applications that respect privacy and comply with personal data protection regulations.<\/p>\n<p style=\"text-align: justify;\">Mobile applications have become an everyday tool for millions of French users. However, they pose significant risks in terms of data protection, as they often access sensitive information such as real-time location, photos, or health data without the users&#8217; knowledge.<\/p>\n<p style=\"text-align: justify;\">\u00a0Given the importance of the situation, it became necessary for the CNIL to remind the various market players of their obligations and to (re)emphasize on obligations that are too often overlooked.<\/p>\n<p style=\"text-align: justify;\"><strong>I\/ Aim of the Guidelines: Framework for Stakeholders and Transparency for Users<\/strong><\/p>\n<p style=\"text-align: justify;\">These guidelines aim to clarify and define the roles of the various actors involved in mobile applications development and ensure greater transparency regarding how user data is handled. They also seek to ensure that users \u2018consent is obtained without coercion.<\/p>\n<p style=\"text-align: justify;\">Specific recommendations are directed to each actor in the sector:<\/p>\n<p style=\"text-align: justify;\"><strong style=\"color: initial;\">1. Measures for the application publisher:<\/strong><\/p>\n<p style=\"text-align: justify;\">The publisher (legal entity or individual company) responsible for making the application available via platforms like app stores must ensure their product complies with data protection regulations.<\/p>\n<p style=\"text-align: justify;\">From now on, the publisher is required to:<\/p>\n<p>&#8211; Identify the personal data processing carried out;<\/p>\n<p>&#8211; Ensure the processing complies with GDPR and the French law ;<\/p>\n<p>&#8211; Integrate data protection into the application design (privacy by design);<\/p>\n<p>&#8211; Map out its partners;<\/p>\n<p>&#8211; Manage user consent and rights as such (practical advice is provided by the CNIL on how to inform users, collect consent, and allow them to exercise their rights);<\/p>\n<p>&#8211; Maintain the application\u2019s compliance throughout its lifecycle;<\/p>\n<p>&#8211; Implement control over usage permissions (e.g., access to location, microphone, etc.).<\/p>\n<p><strong style=\"text-align: justify; color: initial;\">2. Recommendations for developers<\/strong><\/p>\n<p style=\"text-align: justify;\">The developer, responsible for creating the application, must:<\/p>\n<p>&#8211; Develop applications that respect users&#8217; rights.<\/p>\n<p>&#8211; Ensure compliance with the principle of data minimization (collecting only what is necessary);<\/p>\n<p>&#8211; Incorporate processes for collecting user consent.<\/p>\n<p>&#8211; Guarantee the security of the application.<\/p>\n<p><strong style=\"text-align: justify; color: initial;\">3. Recommendations for software development kit (SDK) providers:<\/strong><\/p>\n<p style=\"text-align: justify;\">SDK providers, offering software components integrated into the application must:<\/p>\n<p>&#8211; Apply data protection principles by design and by default;<\/p>\n<p>&#8211; Provide clear information on data processing related to the SDK\u2019s use;<\/p>\n<p>&#8211; Facilitate the exercise of user rights, working with publishers to implement effective consent collection mechanisms.<\/p>\n<p>&#8211; Provide secure SDKs.<\/p>\n<p><strong style=\"text-align: justify; color: initial;\">4. Recommendations for operating system providers<\/strong><span style=\"text-align: justify; color: initial;\">:<\/span><\/p>\n<p style=\"text-align: justify;\">The operating system provider (the entity providing the specially configured operating system installed on the user\u2019s mobile device, within which the application will run) must:<\/p>\n<p>&#8211; Apply data protection principles by design, minimizing the data processed by the OS;<\/p>\n<p>&#8211; Inform partners and third parties of the OS&#8217;s specific data processing activities;<\/p>\n<p>&#8211; Provide permission systems that respect the principle of data protection by design;<\/p>\n<p>&#8211; Protect minor users, particularly by incorporating parental control tools;<\/p>\n<p>&#8211; Guarantee platform security (encryption of connections, backups, etc.).<\/p>\n<p><strong style=\"text-align: justify; color: initial;\">5. Recommendations for app store providers:<\/strong><\/p>\n<p style=\"text-align: justify;\">App store providers (those responsible for the online distribution platforms of mobile applications such as App store or Google Play Store) must:<\/p>\n<p>&#8211; Analyze submitted applications to detect security vulnerabilities;<\/p>\n<p>&#8211; Inform users (including providing information about third-party SDKs used by each app);<\/p>\n<p>&#8211; Provide reporting tools and clear procedures for users to exercise their rights.<\/p>\n<p style=\"text-align: justify;\"><strong>II\/ Deadlines for Compliance and Sanctions<\/strong><\/p>\n<p style=\"text-align: justify;\">Industry actors in the mobile app sector have until March 2025 to comply with these new rules.<\/p>\n<p style=\"text-align: justify;\">The CNIL has announced a major inspection campaign starting in early spring 2025 to ensure compliance with applicable rules and the implementation of its recommendations.<\/p>\n<p style=\"text-align: justify;\">\u00a0During these inspections, the CNIL is empowered to take corrective measures, including:<\/p>\n<p>&#8211; A formal warning;<\/p>\n<p>&#8211; An order to bring the processing into compliance with legal requirements or to comply with requests to exercise users&#8217; rights. This order may be accompanied by a fine of up to \u20ac100,000 per day of delay;<\/p>\n<p>&#8211; Temporary or permanent limitation of data processing, its prohibition, or the withdrawal of an authorization;<\/p>\n<p>&#8211; Revocation of a certification;<\/p>\n<p>&#8211; Suspension of data flows to a recipient located in a third country or international organization;<\/p>\n<p>&#8211; Partial or total suspension of the approval of binding corporate rules;<\/p>\n<p>&#8211; An administrative fine of up to \u20ac20 million or 4% of global annual turnover for non-compliance with the fundamental principles of GDPR.<\/p>\n<p style=\"text-align: justify;\"><strong>Conclusion:<\/strong><\/p>\n<p style=\"text-align: justify;\"><strong>With these recommendations, the CNIL is setting a strict framework for mobile application stakeholders to strengthen the protection of users&#8217; privacy. The whole production and distribution chain is impacted.<\/strong><\/p>\n<p style=\"text-align: justify;\"><strong>Industry professionals must act quickly to comply by March 2025 or face sanctions.<\/strong><\/p>\n<p style=\"text-align: justify;\"><strong>The CNIL has also provided advice for mobile app users, informing them of their rights and how to protect their data.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On September 24, 2024, the CNIL published a recommendation aimed at helping professionals develop and implement mobile applications that respect privacy and comply with personal data protection regulations. Mobile applications have become an everyday tool for millions of French users. [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":2674,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[12],"tags":[],"class_list":["post-2677","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-unspecified"],"acf":[],"_links":{"self":[{"href":"https:\/\/cleach.com\/en\/wp-json\/wp\/v2\/posts\/2677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cleach.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cleach.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cleach.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/cleach.com\/en\/wp-json\/wp\/v2\/comments?post=2677"}],"version-history":[{"count":1,"href":"https:\/\/cleach.com\/en\/wp-json\/wp\/v2\/posts\/2677\/revisions"}],"predecessor-version":[{"id":2678,"href":"https:\/\/cleach.com\/en\/wp-json\/wp\/v2\/posts\/2677\/revisions\/2678"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cleach.com\/en\/wp-json\/wp\/v2\/media\/2674"}],"wp:attachment":[{"href":"https:\/\/cleach.com\/en\/wp-json\/wp\/v2\/media?parent=2677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cleach.com\/en\/wp-json\/wp\/v2\/categories?post=2677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cleach.com\/en\/wp-json\/wp\/v2\/tags?post=2677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}