News | New Code of Practice for App Store Operators and App Developers | Eaton Smith | Law Firm & Solicitors Huddersfield Skip to main content

News

..with you every step of the way!

news


03/04/2023

New Code of Practice for App Store Operators and App Developers

The Department for Digital, Culture, Media and Sport (DCMS) published a new voluntary code of practice for app store operators and app developers on 09 December 2022.

The code is designed to set out minimum security and privacy requirements for both operators and developers.

In this article, we will outline the scope of the code as it applies to app developers, and how the code might impact on your business activities.

The Code’s Principles

The Code sets out eight core principles, each of which are deemed as equally important. Some of the principles apply primarily to app store operators, and some apply primarily to developers (and some to both). The principles are mainly mandated through existing UK laws, and it is expected that there will be a degree of overlap between compliance with the code and existing legal obligations (with compliance with the code demonstrating steps towards adherence with those legal obligations).

As confirmed above, this article focuses mainly on the principles that are expected to apply to app developers, and as such not all eight principles are set out in detail. For further information on all of the applicable principles, please refer to the DCMS’s Code of Practice for App Store Operators and App Developers publication dated 09 December 2022.

Principle 2: Ensure apps adhere to baseline security and privacy requirements.

This principle states that developers must:

  • Use industry standard encryption within their apps specifically in relation to data in transit and where an app needs to encrypt data locally.
  • Ensure that the primary function of an app operates if a user chooses to disable its optional functionality and permissions, and not request permissions/privileges that are not functionally required by the app.
    The term “functionally required” is defined as being a requirement that is necessary for the user-facing operation of the app and does not include any background operation which does not offer the user any further features or an improved experience.
  • Take steps to make the app adhere to security requirements, data protection by design (see ico.org.uk for further details), and broader requirements set out in data protection law.
  • Have a process to readily update and monitor their software dependencies for known vulnerabilities in all the published versions of their app.
  • Have a simple uninstall process for their app (which may be the standard functionality of the operating system, if that contains one).

Principle 3: Implement a vulnerability disclosure process.

This principle states that developers must:

  • Implement and maintain, for every app, a vulnerability disclosure process, with such process being a simple, clear and secure method of reporting found vulnerabilities.

Principle 4: Keep apps updated to protect users.

This principle states that developers must:

  • Provide updates to fix security vulnerabilities within their app;
  • Update their app when a third-party library or software development kit (SDK) that they are using receives a security or privacy update;

App store operators may also contact developers in the event that their apps are left without updates for a period of 2 years. If no response is received after 1 month, the app store operator will be expected to make the app unavailable for further download and will also be expected to send instructions to current users about how to remove that particular app from their device.

Principle 5: Provide important security and privacy information to users in an accessible way.

This principle states that developers must:

  • Provide information about an app’s behaviour, including:

(a) Where a user’s data is stored, shared and processed (preferably within a privacy policy).

(b) When the app was last updated

(c) Any other relevant security information.

(d) The permissions the app may request, such as access to contacts, location, microphone and provide justification as to why each of those permissions are needed.

Principle 8: Ensure appropriate steps are taken when a personal data breach arises.

This principle states that developers must:

  • Ensure that when they become aware of a security incident in an app which involves a personal data breach, that they assess the impact of that incident, and inform relevant stakeholders, including developers, app store operators, and library/SDK developers.
  • Ensure that when a personal data breach occurs via an app, that they inform affected users and signpost instructions on how those users can protect themselves.

Monitoring Compliance with the Code

There will be a 9-month period for operators and developers to adhere to the code, however DCMS has stated that initially it will focus on assessing adherence of the code by app store operators. The DCMS intends to commence meetings with app store operators at some point in early 2023, to determine if those operators have started to enact changes in their process’ as a result of the code. The code is of course voluntary, and accordingly both operators and developers will be able to differentiate themselves by affirming publicly that they comply with the code, and the DCMS has committed to working with operators and developers to confirm this is the case.

The Code will be reviewed and may be subject to updates no later than every two years to take into account technological developments, further clarifications and modifications to regulations & changes to threats posed.

The Code’s Place Among Wider Developments in the UK

The code will of course be of huge significance to app store operators and app developers alike. In addition to the Code, companies operating in the UK market are likely to face a number of changes in the regulatory landscape in 2023, including:

  • The UK GDPR, which currently largely mirrors the EU GDPR, is likely to be revised in the near term. The UK Government is reportedly planning to launch a further limited consultation on the Data Protection and Digital Information Bill before seeking to progress it through the parliamentary process.
  • The long-awaited Online Safety Bill, which will apply to companies hosting user-generated content and providing search engines, is expected to progress through the parliamentary process early in 2023 and introduce new duties to protect users from illegal content.
  • The UK Government has declared its intention to reform the regulation of digital markets and the existing competition and consumer law regimes through introducing a new Digital Markets, Competition and Consumer Bill. The Bill is expected to face its first reading in parliament in Spring 2023 and will be supplemented by enforceable codes of conduct.

This is not legal advice; it is intended to provide information of general interest about current legal issues. You should specific legal advice before acting in reliance on any of the information provided.