{"id":2112,"date":"2012-03-22T15:27:00","date_gmt":"2012-03-22T21:27:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2112"},"modified":"2025-02-06T08:04:33","modified_gmt":"2025-02-06T14:04:33","slug":"mobile-data-privacy","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/mobile-data-privacy\/","title":{"rendered":"Mobile Data Privacy: A Critical Component of Your Cybersecurity Strategy"},"content":{"rendered":"\t\t<section id=\"block_42d0c3b9f279f4a33668c92d3e02eeab\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>Mobile Data Privacy: A Critical Component of Your Cybersecurity Strategy<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_9fe6087d92d38203b1eabf430ef06c10\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<h2>What is data privacy?<\/h2>\n<p>Data is one of a company\u2019s most valuable assets in today\u2019s business environment. Customer data fuels insights, product\/service development, personalized experiences, and relevant go-to-market strategies. Properly analyzed, the right data gives companies a competitive edge in efficiency and therefore, profitability.<\/p>\n<p>Websites, apps, social media platforms\u2026 these are all data wells, collecting and storing personal information about consumers to provide and customize services. This sensitive data covers many fields. It can be a consumer\u2019s name, location, contact information, medical records\u2026 and so much more. And it can relate to online or real-world interactions.<\/p>\n<p>Data privacy addresses the proper handling, storage, access, retention, changeability, and security of sensitive data.<\/p>\n<h2>What laws govern data privacy?<\/h2>\n<p>Privacy laws such as Europe\u2019s General Data Protection Regulation (<a href=\"https:\/\/gdpr-text.com\/\" target=\"_blank\" rel=\"noopener\">GDPR<\/a>) regulate consumer data storage, sharing, and disclosure practices in today\u2019s digital economy. Implemented in May 2019, the GDPR claims to be the \u201ctoughest privacy and security law in the world.\u201d<\/p>\n<p>And a company doesn\u2019t have to be based in Europe to be impacted by it. <strong>As long as your organization targets or collects data related to individuals in the EU, you must abide by <a href=\"https:\/\/trustarc.com\/regulations\/gdpr\/\">GDPR regulations.<\/a><\/strong> Otherwise, you can expect penalties reaching into the tens of millions of euros \u2013 up to 4% of the offending company\u2019s annual turnover.<\/p>\n<p>The GDPR is large and far-reaching and has implications that may impact many areas of your company, including your marketing strategies. It\u2019s disrupting traditional business models and the way data value transfer works.<\/p>\n<p>Since the GDPR, other privacy laws have bloomed around the world. There are the <a href=\"https:\/\/trustarc.com\/regulations\/lgpd-brazil\/\">Brazilian General Data Protection Law (LGPD)<\/a> and the <a href=\"\/regulations\/china-pipl\/\">Chinese Personal Information Protection Law (PIPL)<\/a>. And there are also a number of individualized laws around US states, like the <a href=\"https:\/\/trustarc.com\/regulations\/ccpa-cpra\/\">California Consumer Privacy Act (CCPA)<\/a>. Colorado, Connecticut, Virginia, and Utah have all created legislation similar to CCPA, and 11 other states have privacy bills in consideration.<\/p>\n<p>All of them aim to unify the multiple local privacy laws that regulate the processing of personal data. But their proliferation makes unification a challenge for any multi-jurisdiction organization, not least those companies that use mobile apps to communicate with customers.<\/p>\n<h2>How does the rise of mobile apps impact data privacy?<\/h2>\n<p>The iPhone, the first connected mobile application platform, was introduced in 2007. In the ensuing decades, the devices have become ubiquitous. The average user has installed an average of 80 applications. Most apps communicate with both the phone user and the application developing company, providing personal information from the former to the latter.mobile app consent<\/p>\n<p>Some apps also interact with other apps, which creates a series of complex challenges for protecting user data and has led to a series of high-profile mobile data privacy breaches, where personal information provided by the user has been shared with unintended parties. A Google search of \u201cTikTok privacy issues\u201d responds with over 300 million hits.<\/p>\n<h2>What is unique about mobile data privacy?<\/h2>\n<p>In its report on mobile device data privacy, the European Union Agency for Cybersecurity (<a href=\"https:\/\/www.enisa.europa.eu\/\" target=\"_blank\" rel=\"noopener\">ENISA<\/a>) identified what makes mobile devices a unique challenge for data privacy:<\/p>\n<ul>\n<li>The variety of data and sensors held in mobile devices<\/li>\n<li>Use of different types of identifiers and extended possibility of users\u2019 tracking<\/li>\n<li>The complex mobile app ecosystem<\/li>\n<li>Limitations of app developers<\/li>\n<li>The extended use of third-party software and services.<\/li>\n<\/ul>\n<p>If for no other reason than the litany of privacy policy acceptance prompts that mobile phone users are required to accept, phone-based consumers are very aware of the risks \u2013 and inclined to gravitate to brands associated with strong protection of their valuable data.<\/p>\n<h2>What should app developers do to protect consumer data?<\/h2>\n<p>The complex challenges of data privacy protection on mobile devices does not exempt companies from complying with all applicable laws and regulations, from GDPR to US state laws.<\/p>\n<p>In their mobile data privacy report, ENISA identified three areas of GDPR compliance that are particularly challenging in a mobile app environment:<\/p>\n<ul>\n<li><strong>Transparency and consent<\/strong> [with multiple apps interacting with a common phone infrastructure, how can an app developer be sure all accesses of a consumer\u2019s data have been revealed to them for consent?]<\/li>\n<li><strong>Data protection by design and by default<\/strong> [how to convince consumers that data protection is the default design in an environment where ease of information access \u2013 including access across apps \u2013 is the ultimate goal].<\/li>\n<li><strong>Security of processing<\/strong> [how to protect consumer personal information on a device populated by apps of unknown origin].<br \/>\nmobile app developersLuckily for app developers, mobile device operating systems are increasingly attuned to their platforms\u2019 inherent risks to data privacy. Apple and Google established a policy of default application isolation, wrapping any application access to shared resources with security and user consent.<\/li>\n<\/ul>\n<p>Savvy application developers can use these platform tools and others to secure the data, but it begins with a mindset of accountability and data stewardship. Any byte of personal data provided by the customer is the developer\u2019s responsibility to protect in fully-disclosed ways and follow solid data management procedures end-to-end.<\/p>\n<p>So good coding practices, backend data management practices, and platform support go a long way toward taming the wild environment in which consumers\u2019 data live. But even with these safe practices, consumers are rightly concerned about exactly what is happening with their data.<\/p>\n<h2>Why should I be concerned about mobile data privacy?<\/h2>\n<p>Because your customers are. A <a href=\"https:\/\/calyxinstitute.org\/documents\/Digital_Privacy_And_Security_Survey_2021.pdf\" target=\"_blank\" rel=\"noopener\">Digital Privacy and Security Survey<\/a> conducted by the Calyx Institute in 2021 found that 80% of respondents were concerned about digital privacy. But, only 59% declared they felt more aware of how their data is treated than a year ago.<\/p>\n<p>According to the US Federal Trade Commission (FTC), <em>\u201cright now, it is almost impossible to figure out which apps collect data and what they do with it.\u201d<\/em> A clear privacy policy assertion is key to giving your mobile app users confidence.<\/p>\n<p>TrustArc believes that every mobile application should have, as the FTC puts it, \u201csimple and short disclosures or icons that are easy to find and understand on the small screen of a mobile device.\u201d TrustArc has Mobile App Consent solutions available today for app developers to create a privacy policy that meets these criteria.<\/p>\n<p>By sharing an easy, understandable privacy disclosure, your application \u2013 and your company \u2013 can ease your mobile users\u2019 minds.<\/p>\n<h2>Mobile data privacy: Compliance check box or brand?<\/h2>\n<p>With the proliferation of laws and regulations on data privacy and the complex challenges that meeting these entails in a mobile environment, it is easy to focus on compliance aspects of data privacy protection and the legal risks of failing to do so.<\/p>\n<p>But a compliance-only focus misses the opportunity that your company has to distinguish your brand in the area of data privacy protections. Consumers are surrounded by news of data breaches \u2013 and these come to mind every time your customers are about to enter private information into your app. Their willingness to trust will not be based on a technical understanding of the complexities of your application but on their association of your brand with digital safety.<\/p>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/data-privacy\/\" class=\"badge\">Data Privacy<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/mobile-app-privacy\/\" class=\"badge\">Mobile App Privacy<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t","protected":false},"excerpt":{"rendered":"<p>Since the iPhone&#8217;s debut in 2007, mobile apps and devices have presented complex data protection challenges. What&#8217;s unique about mobile data privacy, and what should mobile app developers know?<\/p>\n","protected":false},"featured_media":1687,"template":"","topic-resource":[55,66],"type-resource":[6],"class_list":["post-2112","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-data-privacy","topic-resource-mobile-app-privacy","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Mobile Data Privacy: A Critical Component of Your Cybersecurity Strategy | TrustArc<\/title>\n<meta name=\"description\" content=\"Since the iPhone&#039;s debut in 2007, mobile apps and devices have presented complex data protection challenges. What&#039;s unique about mobile data privacy, and what should mobile app developers know?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/mobile-data-privacy\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/mobile-data-privacy\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/mobile-data-privacy\\\/\",\"name\":\"Mobile Data Privacy: A Critical Component of Your Cybersecurity Strategy | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/mobile-data-privacy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/mobile-data-privacy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-purple.png\",\"datePublished\":\"2012-03-22T21:27:00+00:00\",\"dateModified\":\"2025-02-06T14:04:33+00:00\",\"description\":\"Since the iPhone's debut in 2007, mobile apps and devices have presented complex data protection challenges. What's unique about mobile data privacy, and what should mobile app developers know?\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/mobile-data-privacy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/mobile-data-privacy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-purple.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-purple.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Mobile Data Privacy: A Critical Component of Your Cybersecurity Strategy | TrustArc","description":"Since the iPhone's debut in 2007, mobile apps and devices have presented complex data protection challenges. What's unique about mobile data privacy, and what should mobile app developers know?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/mobile-data-privacy\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/mobile-data-privacy\/","url":"https:\/\/trustarc.com\/resource\/mobile-data-privacy\/","name":"Mobile Data Privacy: A Critical Component of Your Cybersecurity Strategy | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/mobile-data-privacy\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/mobile-data-privacy\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-purple.png","datePublished":"2012-03-22T21:27:00+00:00","dateModified":"2025-02-06T14:04:33+00:00","description":"Since the iPhone's debut in 2007, mobile apps and devices have presented complex data protection challenges. What's unique about mobile data privacy, and what should mobile app developers know?","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/mobile-data-privacy\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/mobile-data-privacy\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-purple.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-purple.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2112","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1687"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2112"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2112"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2112"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}