Mobile Apps and GDPR
Today, I had an enlightening conversation about the potential use of an app. The person I was talking to argued for the merits of a web app, while I, in alignment with Apple's views, believe that web apps are less powerful and more dangerous compared to true mobile apps. This debate will be the subject of a future blog. However, one statement that stunned me was, "Only web apps are GDPR compliant." This claim was attributed to a prominent company, which I found unbelievable.
Let's understand the requirements and reasons behind GDPR. The General Data Protection Regulation (GDPR) was introduced to harmonise privacy laws across the EU.
What is the GDPR? GDPR stands for the General Data Protection Regulation. It has been enforceable since May 25, 2018. The regulation is designed to protect user data storage and usage, ensuring that users control their data rather than companies.

What does this mean for mobile apps, most of which were already compliant? The GDPR applies to all businesses with customers or website/mobile app visitors from the European Union (EU). This means any organisation working with EU residents' personal data must protect their users' data and be GDPR compliant.
What does "Personal Data" refer to under the GDPR? "Personal Data" under the GDPR includes any information relating to an identifiable person who can be directly or indirectly identified by reference to an identifier. This broad definition includes personal information, cookies, IP addresses, and device IDs.
What does the GDPR mean for your mobile app? With GDPR compliance required for businesses with EU customers or app users, it's essential to understand what data is used and how it will be processed. We always ask our clients to consider if they need certain data and if it can be minimized.
Generally, mobile apps are more secure, and GDPR compliance is a key aspect. When submitting any app to the stores, there are specific GDPR steps and data requirements. This regulation ensures apps are more likely to be GDPR compliant than websites.
Here are some key steps we focus on when designing a mobile app:
· Privacy by Design: Privacy by Design is a legal requirement under the GDPR. From the creation of your mobile app, you must consider users’ privacy, holding and processing only necessary data.
· Ask for Explicit Consent: Businesses must request and receive user consent to collect, use, and move personal data. This includes data for advertising, analytics, and crash logging. Consent must be clear and understandable.
· Providing Visibility and Transparency: It is crucial to be transparent about
data usage. If you are a data controller, you must allow users to manage and protect their data effectively. A clear Privacy Policy is a requirement for app stores.
· Respond to User Requests: Under GDPR, you must respond to user requests about their data usage within one month, or up to three months for complex requests.
· The Right to Be Forgotten: Users have the right to request the removal of their data under the GDPR. You must remove all personal details from your systems upon request.

· Log and Justify Your Data Collection: You must document all data collection activities, maintaining a secure log of data collection processes.
In summary, mobile apps are regulated and verified by app stores, providing assurance that GDPR compliance has been considered and demonstrated. This regulation makes apps more likely to be GDPR compliant than web apps or websites.





Comments