{"id":2118,"date":"2013-08-01T16:13:00","date_gmt":"2013-08-01T22:13:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2118"},"modified":"2025-01-03T12:40:15","modified_gmt":"2025-01-03T18:40:15","slug":"whats-next-for-the-ntia-mobile-app-transparency-code","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/whats-next-for-the-ntia-mobile-app-transparency-code\/","title":{"rendered":"What\u2019s Next for the NTIA Mobile App Transparency Code?"},"content":{"rendered":"\t\t<section id=\"block_03576e392c9241c12dfb543c6dce163c\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>What\u2019s Next for the NTIA Mobile App Transparency Code?<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_70498076581c997e7615b9fc1ff8a8f1\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<h2>The evolution of mobile app transparency: NTIA\u2019s multi-stakeholder journey<\/h2>\n<p>On July 12, 2012, the Department of Commerce\u2019s <a href=\"https:\/\/www.ntia.doc.gov\/\" target=\"_blank\" rel=\"noopener\">NTIA division<\/a> kicked off a <a href=\"https:\/\/www.ntia.gov\/federal-register-notice\/notice-multistakeholder-process-open-meeting-july-12-2012\" target=\"_blank\" rel=\"noopener\">multi-stakeholder proceeding<\/a> focused on deciding a standard for mobile app transparency \u2013 the format and elements of a mobile app privacy notice (or as we\u2019ll refer to it, the NTIA code).<\/p>\n<p>Sitting with the many other attendees in the vast cavernous hall of the Herbert Hoover Auditorium that day and observing the wide range of interests represented in the room, I was admittedly skeptical about whether this group could reach consensus on anything that could provide meaningful guidance to app developers.<\/p>\n<p>Even for the most Pollyannaish of privacy heads, the possibility that representatives from government, industry and the advocacy community could actually sit down together (let alone decide on a mobile privacy standard together) seemed remote.<\/p>\n<h3>Navigating the NTIA Code: A crucial step towards privacy and transparency<\/h3>\n<p>Fast forward a little over a year to July 25, 2013. At its 16th (and for now final) meeting, a majority of stakeholders voted to \u201cfreeze\u201d a draft NTIA code and start testing it in the marketplace before finalizing later this year. Issues remain about some of the draft code\u2019s provisions, around user comprehension of terms used in the code, and how these terms should be laid out in a mobile notice.<\/p>\n<p>For the majority of stakeholders however, the draft NTIA code is a win.<\/p>\n<p>It\u2019s worth stepping back and thinking about what <em>has<\/em> been decided and agreed upon by the NTIA Multistakeholder group. For the first time, a broad coalition representing consumers and industry has agreed on some basic data elements that should be noticed by mobile apps (for the full story, the current version of the draft code is posted on the NTIA\u2019s site).<\/p>\n<p>Mobile app developers who want to comply with the NTIA\u2019s self-regulatory standard must notify users about whether they collect and share personal information \u2013 defined broadly to include data generated from a user\u2019s activity on that device (browser and phone history), user uploaded files (contacts, photos) and sensitive data (health, financial, location).<\/p>\n<p>Providing this type of information to consumers is important; TRUSTe\u2019s research shows that 72% of smartphone users are more concerned about privacy than they were a year ago.<\/p>\n<p>Having participated in and attended the NTIA meetings, it is clear that there are critical issues around implementation that remain open \u2013 but I also believe that these issues can be resolved by test driving different versions of an NTIA compliant format in the marketplace.<\/p>\n<p>For instance, an outstanding issue that is key for many stakeholders, including TRUSTe, is whether an app developer should list all data elements (nutrition label) or just the ones collected\/shared by the app (ingredient approach)?<\/p>\n<p>Clearly this particular issue can be resolved through usability testing \u2013 are users confused by a mobile app\u2019s privacy notice that informs them about the entire universe of data collection that could be happening on their device?<\/p>\n<p>In this regard, TRUSTe is working with ACT, the Innovators Network and companies like AT&amp;T, Apple, Facebook, Microsoft and Verizon, to conduct a program of consumer and developer testing that determines the answers to the remaining open issues and ensures that an NTIA compliant notice effectively communicates with consumers.<\/p>\n<p>In fact, ACT is already testing this <a href=\"https:\/\/privacydashboard.s3.amazonaws.com\/index.html\" target=\"_blank\" rel=\"noopener\">version of an NTIA compliant notice<\/a> with a few of its developers. The Future of Privacy forum also worked on some UI <a href=\"https:\/\/www.ntia.doc.gov\/files\/ntia\/publications\/ntia_ui_comps_update_7.23.pdf\" target=\"_blank\" rel=\"noopener\">mockups of an NTIA compliant notice<\/a>.<\/p>\n<p>In the next few months, we hope to share the results of these consumer tests with you and roll TRUSTe\u2019s own version of an NTIA compliant mobile short notice.<\/p>\n<p>In the end, is the NTIA code a win for consumers and the app developer community? Absolutely.<\/p>\n<p>The current draft of the NTIA code builds on the \u201cTransparency\u201d principle in the Obama Administration\u2019s <a href=\"https:\/\/obamawhitehouse.archives.gov\/the-press-office\/2012\/02\/23\/we-can-t-wait-obama-administration-unveils-blueprint-privacy-bill-rights\" target=\"_blank\" rel=\"noopener\">Consumer Privacy Bill of Rights<\/a>, which gives consumers the right to access \u201ceasily understandable information about privacy and security practices.\u201d The mobile notices being contemplated by the NTIA code will not only inform, but also educate consumers about they types of data being collected by a mobile application, and with whom that data is being shared. That\u2019s why testing will be such an integral part of this process.<\/p>\n<p>The NTIA code will also provide much needed guidance to the app developer community, by establishing a self-regulatory standard that this community can build and improve upon. The fact that the NTIA code was developed through the Multistakeholder process gives it credibility with a wide range of audiences \u2013 academic, advocacy and industry \u2013 all of who actively contributed to and participated in the process that resulted in the current version of the NTIA code.<\/p>\n<h2>App Developer Requirements<\/h2>\n<p>In closing, I thought I would provide a quick rundown on what\u2019s currently required of app developers who want to provide consumers with an NTIA-compliant mobile short form notice.<\/p>\n<p>The mobile app\u2019s short form privacy policy should inform the consumer whether or not the app collects the following types of data:<\/p>\n<ul>\n<li><strong>Biometrics<\/strong> (information about your body, including fingerprints, facial recognition, signatures and\/or voice print)<\/li>\n<li><strong>Browser History<\/strong> (a list of websites visited)<\/li>\n<li><strong>Phone or Text Log<\/strong> (a list of the calls or texts made or received)<\/li>\n<li><strong>Contacts<\/strong> (a list of contacts, social networking connections or their phone numbers, postal, email and text addresses)<\/li>\n<li><strong>Financial Info<\/strong> (credit, bank and consumer-specific financial information such as transaction data)<\/li>\n<li><strong>Health, Medical or Therapy Info<\/strong> (health claims and other information used to measure health or wellness)<\/li>\n<li><strong>Location<\/strong> (precise past or current location of where a user has gone)<\/li>\n<li><strong>User Uploaded Files<\/strong> (files stored on the device that contain your content, such as calendar, photos, text, or video)<\/li>\n<\/ul>\n<p>The app\u2019s privacy policy must also inform consumers if they share the above-referenced data categories or personal data with third parties such as:<\/p>\n<ul>\n<li><strong>Ad Networks<\/strong> (companies that display ads to you through apps)<\/li>\n<li><strong>Carriers<\/strong> (companies that provide mobile connections)<\/li>\n<li><strong>Consumer Data Resellers<\/strong> (companies that sell consumer information to other companies for multiple purposes including offering products and services that may interest you)<\/li>\n<li><strong>Data Analytics Providers<\/strong> (companies that collect and analyze your data)<\/li>\n<li><strong>Government Entities<\/strong> (any sharing with the government except where required by law or expressly permitted in an emergency)<\/li>\n<li><strong>Operating Systems and Platforms<\/strong> (software companies that power your device, app stores, and companies that provide common tools and information for apps about app consumers)<\/li>\n<li><strong>Other Apps<\/strong> (other apps of companies that the consumer may not have a relationship with)<\/li>\n<li><strong>Social Networks<\/strong> (companies that connect individuals around common interests and facilitate sharing)<\/li>\n<\/ul>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/mobile-app-privacy\/\" class=\"badge\">Mobile App Privacy<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t","protected":false},"excerpt":{"rendered":"<p>Explore the NTIA&#8217;s Multistakeholder Journey in shaping mobile app transparency. Dive into the complexities, successes, and challenges of developing the NTIA code. <\/p>\n","protected":false},"featured_media":1259,"template":"","topic-resource":[66],"type-resource":[6],"class_list":["post-2118","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-mobile-app-privacy","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>What\u2019s Next for the NTIA Mobile App Transparency Code? | TrustArc<\/title>\n<meta name=\"description\" content=\"Explore the NTIA&#039;s Multistakeholder Journey in shaping mobile app transparency. Dive into the complexities, successes, and challenges of developing the NTIA code.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/whats-next-for-the-ntia-mobile-app-transparency-code\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/whats-next-for-the-ntia-mobile-app-transparency-code\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/whats-next-for-the-ntia-mobile-app-transparency-code\\\/\",\"name\":\"What\u2019s Next for the NTIA Mobile App Transparency Code? | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/whats-next-for-the-ntia-mobile-app-transparency-code\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/whats-next-for-the-ntia-mobile-app-transparency-code\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-rect-purple-test.png\",\"datePublished\":\"2013-08-01T22:13:00+00:00\",\"dateModified\":\"2025-01-03T18:40:15+00:00\",\"description\":\"Explore the NTIA's Multistakeholder Journey in shaping mobile app transparency. Dive into the complexities, successes, and challenges of developing the NTIA code.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/whats-next-for-the-ntia-mobile-app-transparency-code\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/whats-next-for-the-ntia-mobile-app-transparency-code\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-rect-purple-test.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-rect-purple-test.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"What\u2019s Next for the NTIA Mobile App Transparency Code? | TrustArc","description":"Explore the NTIA's Multistakeholder Journey in shaping mobile app transparency. Dive into the complexities, successes, and challenges of developing the NTIA code.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/whats-next-for-the-ntia-mobile-app-transparency-code\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/whats-next-for-the-ntia-mobile-app-transparency-code\/","url":"https:\/\/trustarc.com\/resource\/whats-next-for-the-ntia-mobile-app-transparency-code\/","name":"What\u2019s Next for the NTIA Mobile App Transparency Code? | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/whats-next-for-the-ntia-mobile-app-transparency-code\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/whats-next-for-the-ntia-mobile-app-transparency-code\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-rect-purple-test.png","datePublished":"2013-08-01T22:13:00+00:00","dateModified":"2025-01-03T18:40:15+00:00","description":"Explore the NTIA's Multistakeholder Journey in shaping mobile app transparency. Dive into the complexities, successes, and challenges of developing the NTIA code.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/whats-next-for-the-ntia-mobile-app-transparency-code\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/whats-next-for-the-ntia-mobile-app-transparency-code\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-rect-purple-test.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-rect-purple-test.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1259"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2118"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2118"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}