Resource Center / Resource Articles / Implementing kids’ privacy protections around the world

Implementing kids’ privacy protections around the world

The PerfectPetPal case study

This resource provides a case study on a fictional pet simulator mobile app.


Published: August 2024


Contributors:


Disclaimer: Before you start searching the app stores to download PerfectPetPal, you should know PPP is entirely fictional. The authors prepared this document for a training workshop on children's privacy that took place 14 Nov. 2023 at the IAPP EU Data Protection Congress 2023. After presenting an overview of privacy laws and enforcement matters from jurisdictions around the world, the authors used a case-study approach with workshop participants to apply the different legal frameworks to the fictional pet simulator mobile app. The training concluded with a mini workshop on data protection impact assessments that tied back to the hypothetical pet simulator.

The case study published here does not contain or constitute legal advice and should not be relied on for such purposes. The legal points in this document are high-level, nonexhaustive examples intended only to stimulate discussion. Any similarity between the hypothetical facts in this document and real-life apps, companies or features is coincidental. Neither the IAPP nor the authors of this document accept any liability for any errors or omissions in this document.

Navigate by Topic

Everybody loves pets, right? PerfectPetPal is a recently launched pet simulator mobile app that allows users, known as owners, to create and interact with virtual pets and other owners in new and exciting ways. PPP is wildly popular with people of all ages. The app has more than 100 million monthly active users worldwide, with thousands of new downloads daily. The app is getting lots of buzz — and attention — from journalists, privacy advocates and possibly data privacy regulators. PPP has hired you to assess their privacy practices and provide them with a plan of action.

Here are some additional facts to help you to get started on your examination. You may need to conduct a DPIA or a privacy impact assessment.

01

PerfectPetPal is a pet simulator app that allows users to create and interact with virtual pets and other users.

02

The app has over 100 million monthly active users from all over the world.

03

PPP has hired you to assess their privacy practices and provide them with a plan of action.


Registration

PPP is incredibly easy to join. All users need to do to become the owner of a PerfectPet is download the app from the Apple or Google storefront, and then sign up with their full names, home addresses and cell phone numbers. Then they can design a PerfectPet right away! PPP displays users' profiles publicly to help owners make friends. They can also use PPP's "Look Alike" feature and take the PetPoll up front to help them create a uniquely tailored PerfectPet in minutes. PPP is free, although owners can add payment information to their accounts to purchase petcoins, which can be used to acquire items, accessories, services and experiences for PerfectPets.


Privacy notice and disclosures

  • PPP does not knowingly collect data from users under the age of 13 or the age of digital consent in particular jurisdictions.
  • PPP does not sell owners' data, although it may use or share information for legitimate business purposes.
  • PPP presents a pop-up upon first use of its special features and asks for consent to collect, use and share data related to the special feature.
  • PPP has a privacy notice in its mobile app, which users can access via a link in the settings menu.
  • PPP's privacy notice explains it collects and uses users' personal information to provide its services.
  • PPP displays a seal on the front page of its mobile app announcing it is "data law compliant."

PPP's mobile app has a privacy notice that owners can access via a link in the settings menu in a section called "About this App." This section contains another link to a menu labeled "Statement," where users can find PPP's 39-page privacy notice. It informs users that privacy is important and encourages them to read it carefully.

The notice explains the app collects and uses users' personal information to provide its services. It also states the product is intended only for adults, and it does not knowingly collect data from users under the age of 13 or the age of digital consent in particular jurisdictions. It explains PPP does not sell owners' data, although it may sometimes use or share information for legitimate business purposes.

The second to last page of the policy states, "By using the PPP app and its features, you accept the terms of this privacy policy and agree to the data collection, use and sharing described herein." In addition to the overall privacy policy, PPP presents a pop-up upon first use special features like the "Look Alike" tool, "PetPoll" or "PetTales" and asks users to consent to the app's collection, use and sharing of data related to the special feature. It offers three choices: "Yes," "Ask me later" or "I'm not sure."

PPP says it takes its users' privacy seriously. On the front page of its mobile app, it displays a seal announcing it is "data law compliant." The seal has ribbons that say "privacy," "trust" and "security."


Key features

PPP allows owners to create and care for a wide array of virtual pets, including feeding them, grooming them and customizing their appearances. There are some cool tools available.

  • expand_more

  • expand_more

  • expand_more

  • expand_more

  • expand_more


Discussion and resources


Know your audience

"PPP is wildly popular with people of all ages. It generates over 100 million monthly active users from all over the world and thousands of new downloads every day."

  • expand_more


DPIAs

"Numerous facts above provide details on PPP's privacy practices, or lack thereof. Review the facts closely to prepare any required or optional PIAs and help provide PPP with a plan of action to address the concerns it is facing from journalists, privacy advocates and data privacy regulators."

  • expand_more


Parental consent and data minimization

"All users need to do to become the owner of a PerfectPet is download the app from the Apple or Google storefront, and then sign up with their full names, home addresses and cell phone numbers."

  • expand_more


Privacy defaults and direct communications

"PPP displays users' profiles publicly to help owners make friends."

"Owners and their virtual pets can connect with each other through special interest groups known as pleagues."

  • expand_more


Transparency of privacy notices and disclosures

"PPP's mobile app has a privacy notice that owners can access via a link in the settings menu in a section called 'About this App.' This section contains another link to a menu labeled 'Statement,' where users can find PPP's 39-page privacy notice. … The notice explains the app collects and uses users' personal information to provide its services. It also states the product is intended only for adults, and it does not knowingly collect data from users under the age of 13 or the age of digital consent in particular jurisdictions."

  • expand_more


Data disclosures to third parties

"PPP does not sell owners' data, although it may use or share information for legitimate business purposes."

  • expand_more


Privacy consents and dark patterns

"PPP presents a pop-up upon first use special features like the 'Look Alike' tool, 'PetPoll' or 'PetTales' and asks users to consent to the app's collection, use and sharing of data related to the special feature. It offers three choices: 'Yes,' 'Ask me later' or 'I'm not sure.'"

  • expand_more


Certification, compliance and safe harbor programs

"On the front page of its mobile app, (PPP) displays a seal announcing it is 'data law compliant.' The seal has ribbons that say 'privacy,' 'trust' and 'security.'"

  • expand_more


Biometric data

"One of the hottest new features PPP offers is a 'Look Alike' tool that allows owners to customize the eyes, hair, nose, mouth and ears of their PefectPet by uploading their own photos to PetSim — selfies preferred!"

  • expand_more


Location data

"When users pramble with their PerfectPets in real life, (PPP) helpfully alerts them to pet-related locations and shopping experiences it thinks users will enjoy."

  • expand_more


Unauthorized purchases

PPP "allows owners to buy items for their PerfectPets with a special virtual currency known as PetCoin."

  • expand_more


Generative AI

"To enjoy PetTales, owners share information about their friends, families, jobs, hometowns, dreams, wishes and even their real-life pets with a special PetBot that creates personally tailored stories for owners. The PetTales feature automatically uploads the stories to the owner's pleagues so users can share these fantastic tales with each other."

  • expand_more


Conclusion

It is clear the concerns raised by journalists and privacy advocates about PerfectPetPal are real, and the company's privacy notices and practices need some — well, a lot — of work. Now you need to convince PerfectPetPal they need to develop and implement a plan of action or face disgruntled users and displeased regulators. In doing so, you will need to touch on everything from privacy notices to consent to location data, biometrics and beyond. You will need to navigate a thicket of laws from multiple jurisdictions that are constantly evolving. IAPP resources can help you stay up to date.


Additional resources



Approved
CDPO, CDPO/BR, CDPO/FR, CIPM, CIPP/A, CIPP/C, CIPP/E, CIPP/G, CIPP/US, CIPT, LGPD
Credits: 3

Submit for CPEs