APPS Act (H.R. 6547)
United States. Score: 57/100. The APPS Act would require mobile apps to get specific permission before collecting and using consumer data, and to delete consumer data upon request. Although the Act…
Country: United States
Score: 57/100
SUMMARY
The APPS Act would require mobile apps to get specific permission before collecting and using consumer data, and to delete consumer data upon request. Although the Act provides for helpful “safe harbors” that can guide companies’ data collection, its definitions are vague and required consent processes are clumsy. Also, the Act does not recognize compelling reasons for a business to retain consumer data after a “deletion” request – such as legal, accounting, billing, and security needs. The best that can be said for the APPS Act is that so long as the FTC cautiously exercises its rule-making authority, the Act probably won’t do major damage beyond adding confusion and paperwork.
EXPECTATIONS
The APPS Act would obligate mobile apps to (1) obtain permission from consumers before collecting and using data, and (2) delete consumers’ data upon their request. These obligations seem straightforward and reasonable, but as directed would actually be impractical and perhaps harmful to commerce and data security. Additionally, key definitions in the Act are unclear and thereby can cause confusion or dispute.
CONCERNS
- The Act requires all mobile applications, prior to collecting consumer data, to obtain users’ specific permission with regard to the use and storage of the data. This replaces the current situation in which consumers receive notice of these practices, but do not need to agree to a contract. By requiring consumer agreement instead of a simple notice, the Act may result in apps incorporating several contractual terms (e.g., jurisdiction and venue) that would otherwise be unnecessary, and provides opportunities to include arbitration and other provisions that some my dislike.
- The Act requires apps to delete certain information when consumers request but does not exempt from deletion data that should be maintained for legal, billing, auditing, or security purposes. The Act also does not recognize that data “deletion” is a term of art, and that often data is masked so that it is generally inaccessible but it may remain accessible, e.g., to law enforcement and hackers.
- The Act helpfully excludes “de-identified information” from the definition of protected “personal information,” but otherwise it delegates this important definition to the Federal Trade Commission.
- The Act authorizes “safe harbors” which can be very helpful, but it provides only a narrow process for recognition of safe harbors which substantially reduces their value.
Scorecard
Scored on DCI’s 10-factor, 100-point scale.
| Factor | Score | Assessment |
|---|---|---|
| Clear Terms | 4/10 | The most important definition – “personal information” – is delegated to FTC regulation so its clarity will be unknown for a year or longer after enactment. Additionally, key definitions, like when data is “deidentified” and thus not covered, are unclear. |
| Specific Harms | 2/10 | The legislation seeks to avoid the generalized harm of “consumer deception” by mandating that consumers know and agree to how their data is used. It does not focus on specific harms, e.g., regarding sensitive data. |
| Helpful Processes | 6/10 | The process of gaining approval for Terms of Service is clear, but it is questionable whether this approval requirement is any more helpful then the existing notice requirement. |
| Not Retroactive | 10/10 | The Act does not apply retroactively. |
| Not Harmful | 7/10 | The Act does not directly inhibit beneficial data models and uses, but the data deletion requirement has no exceptions, so it may inhibit app publishers’ ability to use data that otherwise would be retained for fraud detection or data security. |
| Free Speech | 10/10 | No; it does not inhibit freedom of expression or government transparency. |
| Simple Consents | 4/10 | Because the Act relies on explicit consent, lawyers will prepare lengthy, detailed consent interfaces wrapped inside Terms and Conditions. The likely effect is annoying “consent fatigue” and consumers not reading the Terms and Conditions – so consumer clarity will not improve. |
| International Commerce | 1/10 | The Act conflicts with international law, by imposing a “consent” requirement that is not imposed by other countries. It also inhibits global uniformity by requiring a system of individual contracts – rather than building on the uniform platform controls that, e.g., Google and Apple already provide. |
| Fair Enforcement | 6/10 | The enforcement provisions are not unfair, but it remains uncertain whether they will be applied unfairly because the most important provisions of the Act – defining “personal” information and “safe harbors” – are delegated to the FTC and will be unknown for a year or longer after enactment. |
| Small Enterprises | 7/10 | Because the APPS Act requires explicit (and apparently very specific) consent to collect and process data, it is likely that (a) startups and small companies will have proportionately higher legal costs than larger competitors, and (b) consumers will be less likely to give consent to startups and small companies. Larger companies will benefit and smaller companies will find it more difficult to compete. |