On February 27, the Article 29 Data Protection Working Party adopted an opinion on smart devices. The opinion strives to clarify the European regime on the collection and use of personal information by means of smart devices.

According to the Working Party, EU data privacy law kicks in as soon as mobile apps are targeted at users within the EU. App providers and other companies collecting and processing personal information via such apps are subject to the EU regulatory regime, even if they are not located in the EU. In addition, all actors in the app business such as app developers, OS and device manufacturers, app stores and advertisers are called upon by the Working Party to collaborate with each other to achieve the highest level of data protection and privacy.

The Working Party considers all these actors as potential data controllers; i.e., the entities which carry the principal obligations under EU data privacy laws.

Synopsis of Core Legal Requirements

Apps serve a wide range of purposes, including web browsing, electronic communication, entertainment, social networking and banking and are often available at no upfront cost to end users. To protect users’ privacy, the opinion considers that data controllers processing information from apps on smart devices must comply with the following key data protection obligations:

  • Transparency

Potential app users should be informed in a meaningful way about the type of personal information collected and processed through apps and the exact purposes for which the information is being used. It is recommended to provide a “just in time” notice, which means that the notice be delivered at the point in time when it matters to individuals; i.e., before the collection of information by apps. In addition, the app notice must also be accessible after the installation. App notices should contain information concerning: the identity and contact details of the data controller; the precise categories of personal data processed; the specific purpose of the processing; any disclosure of data to third parties for advertising and/or analytics purposes and whether users will be asked to consent to such data sharing, and how users may exercise their individual rights.

  • Free and Meaningful Consent

The opinion notes that two different kinds of consent are required prior to the installation of an app and the processing of personal information: consent as one of the legal bases to process personal data and consent as the sole legal basis to store information on or access information from the mobile device. Both can be obtained simultaneously and must be provided in a free, specific and informed manner. The Working Party specifies that consent must be granular, in the sense that it “is sought for each type of data the apps intend to access,” such as location data, payment data, etc. This approach is believed to adequately inform the user about the service and to ask for specific consent for each type of data processed. In addition, users should be offered means to withdraw their consent in a simple and effective manner.

  • Security Measures To Protect Personal Data

The opinion recalls that app businesses acting as data controllers must take the necessary organizational and technical security measures, such as data storage locations, server architecture and user identification methods to ensure the protection of the personal information processed. To that end, the Working Party encourages data controllers to take into account the principles of Privacy by Design and privacy by default at all stages of the design and implementation of the app. In addition, the ENISA security guidelines on mobile devices for app developers may be instructive.

  • Purpose Limitation and Data Minimization

The principle of purpose limitation requires that personal information may only be collected and processed for the specific and legitimate purpose for which it was originally collected. Moreover, data controllers must carefully consider which data are strictly necessary to perform the desired functionality.


The Working Party points out important data protection risks for app users in the mobile app “ecosystem”. These risks are mainly caused by the wide range of technical possibilities to access data stored on mobile devices combined with a lack of legal awareness amongst data controllers. The Working Party expects cooperation between the different players on the app and smart device market.

The most important recommendations are as follows:

App Developers

  • Ask for free, specific, and informed consent before the app starts to retrieve or place information on the device;
  • Ask for granular consent for each type of data the app will access; e.g., location, contacts, credit cards and payment data, and allow users to revoke their consent;
  • Provide a readable and easily accessible app notice;
  • Collect only data that are strictly necessary to perform the desired functionality;
  • Define a reasonable data retention period depending on the purpose of the app and the relevance of the data;
  • Take organizational and technical security measures at all stages of the design and implementation of the app;
  • Exercise higher duty of care with users who are minors, and
  • Consider proactively notifying app users of any data breach.

 App Stores

  • Enforce the information obligations of app developers, such as disclosure to third parties or the principle of data minimization;
  • Consider subjecting all apps to a reputation mechanism, and
  •  Implement a privacy-friendly remote uninstall mechanism.

OS and Device Manufacturers

  • Ensure security of processing and consider alerting users to different data usage by apps.

Third Parties

  • Avoid delivering ads outside the context of the app.

Overall, the recommendation signals that all the players in the app industry should use their creative talent to deliver more innovative solutions to effectively comply with the EU legal requirements on mobile devices.

The full text of the opinion is available here.

Coauthored by Jonathan Guzy, who specializes in data protection and privacy and can be reached at j.guzy@lorenz-law.com. 

Written By

Jan Dhont


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Advertise in IAPP Publications

Find out how to get your message in front the people you want to reach. Download a media kit now.

Get more News »

Find a KnowledgeNet Chapter Near You

Network and talk privacy at IAPP KnowledgeNet meetings, taking place worldwide.

Women Leading Privacy

Events, volunteer opportunities and more designed to help you give and get career support and expand your network.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

The Training Post—Can’t-Miss Training Updates

Subscribe now to get the latest alerts on training opportunities around the world.

New Web Conferences Added!

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Staff

Get your team up to speed on privacy by bringing IAPP training to your organization.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

Learn more about IAPP certification »

Get Close-up

Looking for tools and info on a hot topic? Our close-up pages organize it for you in one easy-to-find place.

Where's Your DPA?

Our interactive DPA locator helps you find data protection authorities and summary of law by country.

IAPP Westin Research Center

See the latest original research from the IAPP Westin fellows.

Looking for Certification Study Resources?

Find out what you need to prepare for your exams

More Resources »

GDPR Comprehensive: Registration Open

New! Intensive two-day GDPR training led by the sharpest minds in the field. It's a can't-miss event.

The Congress Is Cancelled

The IAPP Europe Data Protection Congress 2015 is cancelled. Click through to learn more.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

Exhibit at an Event

Put your brand in front of the largest gatherings of privacy pros in the world. Learn more.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»