New Self-Regulatory Rules For Mobile Apps: What Your Company Needs To Know

by Perkins Coie
Contact

Even as efforts to achieve industry-wide consensus on Do Not Track appear to be stalling, self‑regulatory associations are forging ahead with their own rules governing online and mobile data collection.  On July 24, the Digital Advertising Alliance (DAA) and the Network Advertising Initiative (NAI) each released rules governing the use of data collected through mobile applications.  Together, the two documents offer a roadmap for providing users transparency and a unified choice method for Cross-App Data usage.

Who Is Covered by the New Rules?

The NAI’s Mobile Application Code applies only to NAI member companies, and only to the extent they are engaged in Cross-App advertising, which is defined roughly as delivering advertising based on data collected through applications owned or operated by different parties.  However, the DAA’s mobile guidance applies to, and can be enforced by the DAA’s accountability programs against, any company that collects “Cross-App Data,” “Precise Location Data” or “Personal Directory Data.”

  • Cross-App Data is “data collected from a particular device regarding application use over time and across” non-affiliated applications.  It includes unique values assigned or attributed to a device, or a unique combination of characteristics associated with a device, often referred to as “device fingerprinting.”  It does not include data that is collected about non-affiliate applications but is not associated or combined across applications.
  • Precise Location Data is “data obtained from a device about the physical location of the device that is sufficiently precise to locate a specific individual or device.”  It may include data obtained from a cell tower, or Wi-Fi triangulation or latitude-longitude coordinates obtained from GPS, but does not include ZIP code, city name or general geographic information derived from an IP address.  As with Personal Directory Data, it does not include data that is not associated with a particular individual or device.  It also does not include data that is rendered “not precise” within a reasonable period of time following collection, assuming it is not used other than for certain permitted purposes.
  • Personal Directory Data is “calendar, address book, phone/text log, or photo/video data created by a consumer that is stored on or accessed through a particular device.”  It does not include data that is not associated with a particular individual or device.

Cross-App Data Collection: New Rule Requirements

The obligations imposed by the new rules vary based on whether the entity is acting as a “first party” app provider or a “third party” mobile-ad network or similar technology provider.   

Third-Party Website Notice

Both the NAI Mobile Application Code and the DAA mobile guidance require third parties to provide notice of their mobile-data collection practices on their own websites.  Under both sets of principles, such notice must describe the types of data collected, the uses of such data including transfer to any third parties, an easy-to-use mechanism for exercising choice, and a statement of adherence to the relevant principles.  Under the NAI principles, such notice must also include a data retention statement, a general description of the technologies used for cross-app advertising and related purposes, and a list of any segments that are based on health-related information or interests.

Third-Party “Enhanced” Notice

Because the companies that collect data across apps for the purpose of serving targeted ads generally do not have direct relationships with consumers, they are also required, under both sets of principles, to help ensure that notice of their data collection and use activities is provided where consumers download and use apps.  In the case of the NAI’s code, such notice must be provided in any app store or website from which the app may be obtained and should also be provided in and around ads that are informed by Cross-App Data.  Under the DAA guidance, such notice may be provided in or around ads delivered based on Cross-App Data, or as part of downloading or using the app for the first time, as well as in the app’s settings or privacy policy.

First-Party Notice

Unlike the NAI’s principles, the DAA’s guidance is binding on first parties who provide apps.  Any app provider that affirmatively authorizes third parties to collect data on their apps are required by the DAA guidance to point to a universal choice mechanism or to individually list the third parties that collect data through their apps.  They are also required to indicate their adherence to the DAA’s mobile principles.

Choice Mechanism

Both the DAA and the NAI principles require the provision of an opportunity to opt out of the collection and use of Cross-App Data for interest-based advertising purposes. Under the DAA principles, when third parties provide consumers access to a platform or operating system setting that allows consumers to exercise choice, it does satisfy the principle. Both sets of principles allow data collection for purposes such as ad delivery, frequency capping and analytics without the provision of an opt-out mechanism.

Precise Location Data: New Rule Requirements

Under the NAI’s principles, use of Precise Location Data for Cross-App advertising requires member companies to obtain opt-in consent unless the first party has already obtained consent, the member company uses the data to serve an ad based on the user’s location at that specific moment in time, and the member company does not store or save the Precise Location Data.  Platform-provided consent mechanisms are sufficient to meet this principle, but only if the user is notified that Precise Location Data may be shared with third parties and the purposes for which the data will be used.  If sufficient notice cannot be provided through the platform or operating system, it must be provided through alternate means.

DAA Guidance on Obtaining Consent

Under the DAA mobile guidance, first parties that transfer Precise Location Data to third parties, or permit third parties to collect such data directly, are required to obtain “consent,” which is defined as an “individual’s action in response to a clear, meaningful, and prominent notice regarding the collection and use of data for a specific purpose.”  First parties are also required to provide notice of any transfer of Precise Location Data to third parties or of third parties’ collection of such data through their apps, both on their own websites and at the time the app is downloaded, first opened and such data is first collected.  First parties can satisfy the principle by directing users to their device or platform settings, if such settings permit consumers to provide or withdraw consent with respect to the collection and use of Precise Location Data.

Of note, the DAA mobile guidance does not impose any obligations on first parties that do not share Precise Location Data with third parties or permit third parties to collect such data directly.  Rather, the guidance is intended to provide a means by which first parties may obtain consent on behalf of the third parties with which they partner.  Third parties, on the other hand, are required to obtain consent or to obtain reasonable assurances that the first party obtained consent on their behalf, regardless of any intent to transfer.

Personal Directory Data: New Rule Requirements

Both sets of principles forbid third parties from obtaining and using Personal Directory Data without user authorization.  The DAA guidance forbids first parties from authorizing third parties to access and use Personal Directory Data except for certain permitted purposes.

Implementation Schedule 

The DAA’s mobile guidance explains that it will work to develop and implement, or otherwise specify, a choice mechanism or setting for Cross-App Data.  While this choice mechanism is being developed, the principles will not be in effect or enforced by the Better Business Bureau or Direct Marketing Association, which are accountability programs for the DAA.  Nevertheless, once such a choice mechanism is operational and formally announced, any entity engaged in the collection and use of Cross‑App Data, Precise Location Data or Personal Directory Data will be subject to enforcement.  The BBB has already issued 19 public decisions under its online behavioral advertising principles.

The NAI’s Mobile Application Code makes clear that the new principles will not be enforced during the 2013 compliance cycle. 

Key Takeaways for the Mobile App Industry

While it is not clear when either set of mobile principles will be enforced by either of the DAA accountability programs or by the NAI, it is important to start thinking about bringing your app or service into compliance with the rules.

  • Building the principles into current practices and disclosures now can help prevent the need to reengineer your products in the future.  Taking steps toward compliance with the rules can demonstrate your company’s commitment to privacy practices and discourage scrutiny, such as investigations or enforcement actions by the Federal Trade Commission or state regulators who might view these areas as within the scope of general advertising and privacy laws.
  • If you are an app developer, advertiser or host any type of app, take a close look at your relationships with third parties and advertising networks in particular.  Make sure you are familiar with the type of data they collect, how they use it, whether they combine that data with data from any unrelated apps, and whether they offer an opt-out mechanism.
  • If you are a third-party ad technology provider, you will be subject to both the DAA mobile guidance document and to the NAI Mobile Application Code, if you are an NAI member company.  As a result, your company will face new notice and choice obligations.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Perkins Coie | Attorney Advertising

Written by:

Perkins Coie
Contact
more
less

Perkins Coie on:

Readers' Choice 2017
Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
Sign up using*

Already signed up? Log in here

*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
Privacy Policy (Updated: October 8, 2015):
hide

JD Supra provides users with access to its legal industry publishing services (the "Service") through its website (the "Website") as well as through other sources. Our policies with regard to data collection and use of personal information of users of the Service, regardless of the manner in which users access the Service, and visitors to the Website are set forth in this statement ("Policy"). By using the Service, you signify your acceptance of this Policy.

Information Collection and Use by JD Supra

JD Supra collects users' names, companies, titles, e-mail address and industry. JD Supra also tracks the pages that users visit, logs IP addresses and aggregates non-personally identifiable user data and browser type. This data is gathered using cookies and other technologies.

The information and data collected is used to authenticate users and to send notifications relating to the Service, including email alerts to which users have subscribed; to manage the Service and Website, to improve the Service and to customize the user's experience. This information is also provided to the authors of the content to give them insight into their readership and help them to improve their content, so that it is most useful for our users.

JD Supra does not sell, rent or otherwise provide your details to third parties, other than to the authors of the content on JD Supra.

If you prefer not to enable cookies, you may change your browser settings to disable cookies; however, please note that rejecting cookies while visiting the Website may result in certain parts of the Website not operating correctly or as efficiently as if cookies were allowed.

Email Choice/Opt-out

Users who opt in to receive emails may choose to no longer receive e-mail updates and newsletters by selecting the "opt-out of future email" option in the email they receive from JD Supra or in their JD Supra account management screen.

Security

JD Supra takes reasonable precautions to insure that user information is kept private. We restrict access to user information to those individuals who reasonably need access to perform their job functions, such as our third party email service, customer service personnel and technical staff. However, please note that no method of transmitting or storing data is completely secure and we cannot guarantee the security of user information. Unauthorized entry or use, hardware or software failure, and other factors may compromise the security of user information at any time.

If you have reason to believe that your interaction with us is no longer secure, you must immediately notify us of the problem by contacting us at info@jdsupra.com. In the unlikely event that we believe that the security of your user information in our possession or control may have been compromised, we may seek to notify you of that development and, if so, will endeavor to do so as promptly as practicable under the circumstances.

Sharing and Disclosure of Information JD Supra Collects

Except as otherwise described in this privacy statement, JD Supra will not disclose personal information to any third party unless we believe that disclosure is necessary to: (1) comply with applicable laws; (2) respond to governmental inquiries or requests; (3) comply with valid legal process; (4) protect the rights, privacy, safety or property of JD Supra, users of the Service, Website visitors or the public; (5) permit us to pursue available remedies or limit the damages that we may sustain; and (6) enforce our Terms & Conditions of Use.

In the event there is a change in the corporate structure of JD Supra such as, but not limited to, merger, consolidation, sale, liquidation or transfer of substantial assets, JD Supra may, in its sole discretion, transfer, sell or assign information collected on and through the Service to one or more affiliated or unaffiliated third parties.

Links to Other Websites

This Website and the Service may contain links to other websites. The operator of such other websites may collect information about you, including through cookies or other technologies. If you are using the Service through the Website and link to another site, you will leave the Website and this Policy will not apply to your use of and activity on those other sites. We encourage you to read the legal notices posted on those sites, including their privacy policies. We shall have no responsibility or liability for your visitation to, and the data collection and use practices of, such other sites. This Policy applies solely to the information collected in connection with your use of this Website and does not apply to any practices conducted offline or in connection with any other websites.

Changes in Our Privacy Policy

We reserve the right to change this Policy at any time. Please refer to the date at the top of this page to determine when this Policy was last revised. Any changes to our privacy policy will become effective upon posting of the revised policy on the Website. By continuing to use the Service or Website following such changes, you will be deemed to have agreed to such changes. If you do not agree with the terms of this Policy, as it may be amended from time to time, in whole or part, please do not continue using the Service or the Website.

Contacting JD Supra

If you have any questions about this privacy statement, the practices of this site, your dealings with this Web site, or if you would like to change any of the information you have provided to us, please contact us at: info@jdsupra.com.

- hide
*With LinkedIn, you don't need to create a separate login to manage your free JD Supra account, and we can make suggestions based on your needs and interests. We will not post anything on LinkedIn in your name. Or, sign up using your email address.