Description

Data Protection Agency published recommendations for professionals designing mobile applications

On 14 January 2025, the Data Protection Agency (CNIL) published its recommendations to guide professionals in designing mobile applications that respect user privacy, with a focus on the role of permissions. Permissions in mobile applications allow users to control which features and data are accessible to each app, such as sensors or memory on their devices. These permissions are technical and do not regulate the purposes for which data is processed. The CNIL's recommendations emphasise that permissions are not the same as obtaining user consent under the General Data Protection Regulation (GDPR). Permissions help users block access to certain data, ensuring confidentiality, but they do not necessarily meet the requirements for free, specific, informed, and unambiguous consent. The CNIL advises operating system providers to design permission systems that allow app publishers to choose the scope of permissions as finely as possible, including the degree of data accuracy, the material scope, and the duration of authorisation. When both a consent management platform (CMP) and a permission request are presented to users, their articulation should be clear and not confusing.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
software provider: app stores, software provider: other software
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2023-07-21
in consultation

On 21 July 2023, the French Data Protection Agency (CNIL) opened a consultation on the draft Recomm…

2023-10-08
processing consultation

On 8 October 2023, the French National Commission on Informatics and Liberty (CNIL) closed a consul…

2024-09-24
adopted

On 24 September 2024, the French Data Protection Agency (CNIL) published its recommendations to enh…

2025-01-14
adopted

On 14 January 2025, the Data Protection Agency (CNIL) published its recommendations to guide profes…

2025-03-27
adopted

On 27 March 2025, the French Data Protection Authority adopted the revised recommendation for profe…