Privacy Policy for Apps: What App Providers Need to Know

Last updated:
17.04.2023
It is not just website and online shop operators who need to address data protection; app providers are also subject to the European Union's data privacy regulations. The GDPR imposes numerous obligations on business owners, including app operators, to protect the personal data of their users.
Privacy Policy for Apps: What App Providers Need to Know
Key Takeaways
  • Apps must comply with GDPR, BDSG, and TTDSG.
  • User consent is often required.
  • GDPR violations can result in heavy fines.
  • Data minimization and a legitimate purpose are essential.
  • The privacy policy must be easily accessible and understandable.

In recent years, regulatory authorities have increasingly turned their attention to mobile apps. The access permissions that many apps require have significant implications for personal data—and, consequently, for data protection. In this article, we explain what app operators need to know about privacy policies and data processing, and how you can implement data protection compliance.

Do you need legal support for your app implementation?

Our team consists of over 80 data protection experts who are happy to provide comprehensive advice. Feel free to contact us at any time.

Key facts about data protection for apps at a glance 

  • Apps are also required to implement and comply with the regulations of the GDPR, the BDSG, and the TTDSG. This applies in particular to app tracking and access permissions. 
  • App operators face numerous information obligations. In many cases, you must also obtain explicit user consent for the processing of personal data. 
  • Violations of the GDPR can lead to significant fines: Failure to comply with the requirements can result in turnover-based penalties amounting to millions.

What rules apply to data protection in apps?

In principle, the same regulations apply to the processing of personal data in apps as to data processing in companies, on websites, or in online shops. Therefore, the general rule is: the collection, processing, and storage of personal data are only permitted if they are necessary to fulfill the purpose of the processing—in other words, if they serve a legitimate purpose.

If data processing involves high risks, it must be assessed whether the company's interest in processing the data outweighs the risks to the rights and freedoms of the users. Furthermore, data processing is in some cases subject to the user's explicit consent, such as tracking via cookies or advertising. If an app exclusively provides its intended service and processes personal data in the process, the processing can be based on the performance of a contract under Art. 6(1)(b) GDPR. For example, a fitness app designed to track running speed may process the user's GPS data for this purpose without requiring consent. Some data may also be processed on the basis of the provider's overriding legitimate interest. 

What applies to app access permissions regarding data protection? 

Depending on the app provided and the services it offers, different data collection and access permissions may be necessary, such as location access for navigation or photo library access for social media platforms. 

It is important that data usage serves a legitimate purpose. For instance, it would likely be questionable why a simple information app would need access to a user's location data. As an app operator, always ensure that data is used only for its intended purpose.

Furthermore, the principle of data minimization applies: only the scope of personal data and data categories that are strictly necessary for using the app may be collected.

What data can be processed in apps?

Data protection always applies to the collection, use, processing, and storage of personal data. This includes data that allows conclusions to be drawn about the identity of a specific person. In the case of apps, this can include data such as photos, locations, audio recordings, IP addresses, names, dates of birth, fingerprints, or device identifiers.

Which data may be processed in an individual case depends on the purpose of the app. What specific service is being offered? Is it a game, a news app, or a graphics program? An image editing app, for example, requires access to the photo library, whereas a crossword puzzle app likely does not. When in doubt, it is advisable to seek legal advice. 

Below, we provide a brief overview of general information regarding typical data processing in apps. For individual questions, please feel free to contact us at any time to arrange a non-binding consultation.

App tracking and usage analysis 

Many apps typically use usage analysis or so-called app tracking. The legal risk involved depends on how the analysis is conducted. 

  • If usage analyses are conducted anonymously from the outset, no consent is required. 
  • If cookies are set or device data is read during usage analysis, consent is mandatory. For example, Google Analytics is a service used for usage analysis rather than advertising, yet it still requires consent. 
  • In contrast, app tracking records each user individually in order to tailor advertising measures to the specific user and display personalized ads. This involves collecting and processing a wide range of data, such as locations, usage behavior, personal interests, and individual characteristics. It is therefore a high-risk process that must always be viewed in relation to its purpose.

For both non-anonymous methods, the user's explicit consent must be obtained. A complete and legally compliant privacy policy is also required to inform users about data processing and their rights and obligations.

The user's right to object is particularly relevant, as consent can be withdrawn at any time.

Transfer to third parties 

Special caution is required when personal data is transferred to third parties. Stricter rules apply in these cases to protect personal data. Many app operators use external plugins that allow third-party providers to access and process data.

When transferring data, ensure that this is carefully documented in the privacy policy and that explicit consent is obtained from users. In this case, the consent should explicitly cover the transfer of data to third parties; merely informing users about data processing by the app is not sufficient.

It is important that third-party providers also adhere to applicable data protection requirements. App operators are therefore required to conclude a data processing agreement (DPA) with external service providers. This contract obligates external service providers to comply with the regulations of the GDPR.

Learn more about your obligations regarding Monitoring data processors.

Checklist: Privacy Policy for Apps 

Collecting and processing personal data via apps is a challenge for many operators, as data protection requirements are often opaque, complex, and difficult to navigate. A privacy policy must include various pieces of information required for GDPR-compliant implementation.
Learn what matters when creating a privacy policy in our checklist for app operators. 

Content of the Privacy Policy for Apps 

Who operates the app? Provide information about your company (including legal form) and include contact details so that users can effectively exercise their rights.
What data is processed, to what extent, and for what purpose? What usage rights does the app require? Clarify all potential questions regarding data processing.

  • How long is data stored? When is data deleted? How can users actively influence this?
  • Are there external service providers to whom data is transferred? If so, to what extent? State the purpose and duration of the transfer.
  • What rights do users have? Refer to the rights of withdrawal and the resulting obligations for the app operator. Read more about GDPR access rights.
  • Are app analytics or app tracking used? Is there an opt-out button? List as many tools as possible that are used in data processing and point out options for objection.
  • Is data transferred to third countries when using the app or when sharing data with external service providers? You must provide information about every transfer to a third country.

Special features of privacy policies for apps 

  • The privacy policy must be easy to find (a good rule of thumb is two clicks from any subpage). This also applies to apps.
  • It must be written in clear, understandable language so that non-lawyers can also grasp their rights and obligations. At the same time, the privacy policy must comply with all legal requirements. 
  • The font size must be set or adjustable so that it is easy to read even on devices with small screens. This is particularly important because apps are primarily used on mobile devices, such as smartphones.
  • The privacy policy must also be accessible before downloading and using the app, for example in the App Store or Play Store. It must be possible for interested users to inform themselves about the data protection provisions before entering into a contract, if applicable.

Conclusion on data protection for apps 

The use of apps typically generates a large amount of data, which is usually utilized and potentially shared by app operators on a massive scale. Depending on the purpose of the app and the services offered, vast quantities of data are collected, processed, and stored. This poses a significant legal risk regarding data protection. Violations of the GDPR can result in heavy fines of up to 2% of annual turnover.

App providers should therefore always be aware that data protection requirements apply to them as well. This includes, for example, the principle of data minimization, a legally compliant and complete privacy policy, and the ability for users to effectively exercise their rights. Furthermore, user consent is always required.

Do you need help implementing data protection for your app?

As experts in the field of data protection, we are happy to provide comprehensive advice on your specific needs as an app operator. Feel free to contact us at any time for a non-binding consultation.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in