US telecom agency issues draft mobile app code of conduct with guidelines for user data collection


The US government’s National Telecommunications and Information Administration today issued its first draft of what will be a mobile apps code of conduct intended to better protect consumers and their privacy. If made final, policy states that publishers must provide consumers with “short-form” notices in multiple languages informing them of how their data is being used.

After soliciting feedback from privacy, civil liberties, and consumer advocates, along with app developers and publishers, and mobile ecosystem representatives, the NTIA sought to help make mobile apps more transparent to their end users. The idea was spurred on by President Obama’s need to enact an online privacy “bill of rights” (which is somewhat ironic given the NSA’s recently revealed surveillance program).

As listed in the draft code of conducts, the NTIA states that “where practicable, app developers are encouraged to provide consumers with access to the short notice prior to download or purchase of the app.” It stresses that this process is entirely voluntary, but those app developers that comply must list in their short notice four things:

(a) the collection of types of data listed in SectionII.A whether or not consumers know that it is being collected;
(b) a means of accessing a long-form privacy policy, if any exists;
(c) the sharing of user-specific data, if any, with third-parties listed in Section II.B as defined below; and
(d) the identity of the entity providing the app.

Just so that there’s no doubt about what “data” means, the government entity specifically says it includes biometrics, browser history, phone or text log, contacts, financial info, health, medical, or therapy info, location, and user files.

However, there is an exception to the short-form notice. If the data is actively submitted by the user through an open field voluntarily, then it appears to be fair game. Also, if an app “as one of its functions” has in-app purchasing and does not otherwise passively collect financial information without advance consumer notice, then the app creator is in the clear — but only if the consumer’s purchase doesn’t constitute a material change from the app’s original short-form notice.

The NTIA goes a bit deeper into exceptions to the rule, saying that short-form notices aren’t needed when collecting or sharing unidentifiable data as long as “reasonable steps” are taken to disassociate it from the owners. What is a “reasonable step”?

  • Have reasonable measures been taken to de-identify the data?
  • Publishers must not attempt to reassociate the data.
  • Publishers are contractually prohibited from having third-party contractors or vendors make the association.

US Assistant Secretary of Commerce for Communications and Information and NTIA Administrator Lawrence Strickling issued a statement after the draft was released, heaping praise on the agency’s success:

NTIA is pleased that today a diverse group of stakeholders reached a seminal milestone in the efforts to enhance consumer privacy on mobile devices.  We encourage all the companies that participated in the discussion to move forward to test the code with their consumers.

The American Civil Liberties Union (ACLU) has come out in support of the policy calling it a “modest but important step forward” for consumer privacy. However, it wasn’t all praise, as the organization’s legislative counsel Christopher Calabrese said, “The fact that it took a year to come to agreement on just this single measure, however, makes it clear that we need comprehensive privacy legislation in order to gain meaningful privacy protections for consumers. After all, we should be able to enjoy cool new technologies without giving up our privacy.”

The NTIA has not specified what its next steps are, but it probably wouldn’t be far-fetched to believe it will track developer feedback and consumer reaction for an undetermined period of time. Hopefully it won’t take another year for this to move to the next phase.

As published on http://thenextweb.com/insider/2013/07/26/us-telecom-agency-issues-draft-mobile-app-code-of-conduct-with-guidelines-for-user-data-collection/

Unknown's avatar

About Shailendra Nair

AI Generalist & Executive Tech Leader in Insurance & Benefits Tech. Driving growth, trust, and resilience from AIG to Marsh McLennan. I am an AI Generalist and Executive Technology Leader with a career dedicated to reimagining how insurance and benefits ecosystems work in a digital first world. My expertise spans Insurance & Benefits Tech, digital transformation, and cybersecurity, with a proven ability to turn technology into both a growth engine and a resilience enabler. I have worked with global leaders such as PepsiCo, Allianz, AIG, and Marsh McLennan, experiences that gave me a rare mix of perspectives across insurance carriers, broking, and benefits advisory. This combination allows me to design solutions that balance global standards, local compliance, and client expectations while driving measurable business value. My strength lies in full stack insurance technology leadership, covering Property & Casualty, Life, and Benefits. I bring hands-on expertise in infrastructure, cloud, security, and enterprise architecture, combined with data platforms, AI automation, and digital ecosystems. Having led across this spectrum, I can translate complex technology into practical outcomes that deliver trust, scale, and innovation. As an AI Generalist, I focus on impact: • Building automation first operations that scale efficiently. • Designing chatbots and intelligent assistants to empower employees and clients. • Deploying AI-driven QA frameworks to improve speed and accuracy. • Exploring agentic AI roles to support compliance and transformation. My philosophy is simple: technology should reduce friction, inspire confidence, and accelerate growth. I design platforms that enhance sales, revenue, and client stickiness, proving that tech can directly enable business outcomes. At the same time, I remain deeply client centric a solution enabler who thinks out of the box to solve real challenges and deliver measurable ROI. 🌍 What excites me most is reimagining benefits ecosystems for the future of work. Employees demand seamless digital first experiences, organizations need efficiency, and regulators require trust and security. My mission is to build ecosystems that are secure, resilient, innovative, and human focused.
This entry was posted in Technology and tagged , . Bookmark the permalink.

Kindly leave your feedback or suggestions