Description

Published Recommendations for Mobile Applications

On 24 September 2024, the French Commission Nationale de l'Informatique et des Libertés (CNIL) published its recommendations to enhance privacy protection in mobile applications. The release of the recommendations follows a public consultation in 2023 and the recommendations are aimed at helping professionals design apps that respect users' privacy and reinforce General Data Protection Regulation (GDPR) compliance in mobile applications. In particular, the CNIL's recommendations target all actors in the mobile app ecosystem, including app publishers, developers, software development kit (SDK) providers, operating system providers, and app stores. The goal is to ensure that personal data is protected at every stage of an app’s lifecycle. The recommendations clarify the responsibilities of each actor and offer practical advice to improve legal security. Furthermore, the recommendations focus on improving how users are informed about the use of their data, ensuring that this information is clear, accessible, and provided at the right time within the app. In addition, the CNIL stresses the importance of obtaining informed and freely given consent from users, particularly for data not essential to the app’s core functionality, such as for advertising purposes. Users must be able to refuse or withdraw consent as easily as they can give it, without facing any constraints. CNIL states that it will carry out a mobile application compliance campaign in spring 2025.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
software provider: app stores, software provider: other software
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2023-07-21
in consultation

On 21 July 2023, the French National Commission on Informatics and Liberty (CNIL) opened a consulta…

2023-10-08
processing consultation

On 8 October 2023, the French National Commission on Informatics and Liberty (CNIL) closed a consul…

2024-09-24
adopted

On 24 September 2024, the French Commission Nationale de l'Informatique et des Libertés (CNIL) publ…