Article

Privacy Recommendations for Mobile Applications

Practical privacy and data protection measures for the design and operation of mobile applications.

Adem Akkır6 min read

Mobile applications can process extensive device, behavioural and identity data. This publication reviews transparency, permissions, data minimisation and security through a privacy-by-design perspective.

On 22 December 2023, the Turkish Data Protection Board published a guide entitled Recommendations on the Protection of Privacy in Mobile Applications to support the effective protection of personal data when mobile applications are used. A summary of the guide and our recommendations appears below.

The guide first explains the personal data processed in mobile applications and emphasises the importance of processing personal data only within the scope of the relevant activity, which is a fundamental rule of data processing.

It notes that mobile applications process both personal data and other data for purposes such as enriching the user experience, providing and improving functionality, improving the service and developing marketing strategies.

Examples of data processed by mobile applications include:

  • Identity information,
  • Membership information, including passwords and usernames,
  • Contact information,
  • Financial information,
  • Online identifiers, including MAC and IP addresses, IMEI and IMSI numbers, and fingerprints derived from the list of applications installed on a device,
  • User interactions,
  • Location information,
  • Phone books and in-application friend lists,
  • Biometric data, including facial recognition, fingerprints and voiceprints,
  • Health data in health applications,
  • Images in a user's gallery where access to the device camera and gallery has been granted,
  • Audio collected through voice commands or messaging and navigation applications, such as WhatsApp,
  • Text data collected from messaging platforms.

The guide addresses special categories of personal data separately and recommends stricter measures because processing such data requires greater attention to privacy.

For example, voice-recognition applications that have also received media attention may use voiceprint biometrics to collect biometric data about a person. The guide states that this processing must be carried out in compliance with the applicable regulatory framework.

After explaining processing activities, the recommendations consider the roles of controllers and processors in the mobile application ecosystem. Responsibility may fall on many actors, including the application provider, application developer, advertising network, application store operator, operating system provider, library provider and device manufacturer.

Drawing on complaint scenarios, the Authority states that the application provider will generally be the data controller, but that more than one controller may emerge in relation to a mobile application.

The Board illustrates this through fraud prevention. The integration of a third-party service provider to provide two-factor authentication, as commonly required in Board decisions, or the use of advertising networks in mobile applications may result in more than one data controller.

The recommendations also define concepts such as mobile application developer, mobile application provider and application store. As technological infrastructure enables an increasing number of transactions to be carried out on mobile devices, the risks to personal data have grown accordingly.

The guide aims to raise public awareness and contains recommendations for both data subjects and parties processing personal data. Recommendations for individuals include:

  • Before installing an application, users should ensure that it comes from a reliable source and, where possible, install it from the device's official application store, such as the App Store or Google Play.
  • Users should check the application developer and confirm the correct application name. This can reduce the risk of harm from copied or counterfeit applications.
  • Users should assess whether the personal data requested is relevant to the application and, where possible, review its privacy terms. In line with the principle of proportionality, they should be cautious about requests for data beyond what is necessary to use the application.
  • Users should pay attention to permissions and use strong passwords.

The Board seeks to raise awareness of processing activities that test or exceed the limits of proportionality. Accessing biometric data merely to enable use of an application may breach the principles in Article 4 of the KVKK requiring processing to be relevant, limited and proportionate to its purpose.

Individual awareness is also important for detecting and monitoring infringements and for holding controllers accountable when they breach data processing principles. The Board therefore states that users with privacy concerns about permissions requested by an application should consider refusing access and looking for an alternative application.

For example, an application that uses location data will commonly offer three choices: allow all the time, allow only while using the application, or deny. Users should select the option that best reflects their purpose. If the application will not be used continuously, allowing location access at all times will not be the appropriate choice.

For parties processing personal data, the guide explains the general principles through detailed examples, including fairness, accuracy, relevance and proportionality, and compliance with statutory retention periods.

In line with these principles, developers and providers are advised to comply with transparency obligations, consider users' interests and use user-friendly interfaces for privacy settings and updates.

Another significant issue highlighted by the guide is the failure to give users separate choices for permissions relating to the application itself and to third parties integrated into it.

Applications should be transparent about third-party operations when requesting permissions. If there is no lawful basis for processing personal data through an integrated third-party service, that service should not be used in the application.

Users should be given a way to correct personal data so that information remains accurate and identity theft risks arising from outdated data can be reduced.

Processing must also remain limited, relevant and proportionate to its purpose. The guide, consistently with the law, recommends processing the minimum data necessary to achieve the purpose and refraining from collecting data whose connection with the relevant function or activity cannot be explained.

Controllers should establish retention and deletion periods justified by clearly defined business needs or legal obligations and must not retain personal data for longer than necessary.

The guide also recalls that applications based outside Türkiye may have to register with VERBIS if they are accessible in Türkiye, and it discusses explicit consent and other processing conditions. The importance of explicit consent is not always fully understood by controllers, and practices contrary to legislation and Board decisions continue to occur.

Explicit consent must be freely given, must not be conditional and must be capable of being withdrawn at any time. As the Board illustrates, if a feature requested by a user does not require access to location, the application must not collect location data for targeted advertising unless the user has given explicit consent.

Other important recommendations include encouraging multi-factor authentication, applying periodic software updates and using methods such as CAPTCHA or simple arithmetic questions to prevent automated attacks.

Contact

Let us consider this issue together.

Contact us