Do App Permissions Satisfy Requirements for Valid Consent for the Purpose of GDPR?

Fox Rothschild LLP
Contact

Fox Rothschild LLP

This is important for U.S. companies, because the same logic applies regarding the use of app permissions for “Do Not Sell” or consent for sensitive information (e.g. precise location, biometrics) under the U.S. privacy laws. You may need your own supplemental disclosure/consent if you cannot edit the permissions’ text.

Key points:

  • Permissions are only intended to give or block access to the protected resources and information of the mobile device, regardless of the purposes pursued by the publisher of the application.
  • You can use them when consent is not necessary (e.g. collection of location data to make a navigation app work).
  • When consent IS required, a simple request for permission is sufficient only in limited cases. (For example, if the permission relates to a single processing, a single purpose and a single recipient of the data.)
  • In most cases, it is necessary to use a consent management platform in addition to the permission request.
  • CNIL recommends to OS vendors to give controllers flexibility regarding structuring permissions.
  • Controllers using both a CMP and a request for permission must present them in a way that is not confusing for the user.
  • Consent can be obtained either before or after the request for permission, but the user must understand what’s going on.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Fox Rothschild LLP

Written by:

Fox Rothschild LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Fox Rothschild LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide