Time Running Out for Mobile App Operators Targeted by California Attorney General
Time 2 Minute Read

In late October 2012, California Attorney General Kamala D. Harris began sending letters to approximately 100 mobile app operators, informing them that they are not in compliance with the California Online Privacy Protection Act (“CalOPPA”). Pursuant to CalOPPA, “an operator of a commercial Web site or online service that collects personally identifiable information through the Internet about individual consumers residing in California who use or visit its commercial Web site or online service” must post a privacy policy that contains specified elements. A mobile app arguably could be an “online service” under CalOPPA, which provides that an online service operator that collects “personally identifiable information” and “fails to post its policy within 30 days after being notified of noncompliance” is in violation of CalOPPA. The law affects a wide range of mobile app operators because of its very broad definition of “personally identifiable information,” which includes any “individually identifiable information about an individual consumer collected online by the operator from that individual and maintained by the operator in an accessible form,” such as a name, an email address or any other identifier “that permits the physical or online contacting of a specific individual.”

The notifications of noncompliance state:

“An app’s commercial operator must therefore conspicuously post its privacy policy in a means that is reasonably accessible to the consumer. Having a Web site with the applicable privacy policy conspicuously posted may be adequate, but only if a link to that Web site is ‘reasonably accessible’ to the user within the app.”

If a mobile app already contains a reasonably accessible link to a privacy policy, compliance with the law may involve only ensuring that the privacy policy contains the elements required by CalOPPA. Operators whose apps contain no such link and no built-in mechanism for remotely adding one may need to publish an updated version of the app for users to download; it remains to be seen how the Attorney General will deal with these apps as the 30-day deadlines for compliance begin to pass.

You May Also Be Interested In

Time 2 Minute Read

California has introduced Assembly Bill 2244, proposing a pioneering “California Certified” labeling standard for foods not classified as ultra-processed. The bill relies on forthcoming regulatory definitions and imposes retail placement requirements for qualifying products. As California continues to advance UPF regulation, this initiative is expected to shape food law trends nationwide.

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 1 Minute Read

As reported on the Hunton Employment & Labor Perspectives blog, SB 574 is a California bill that would set specific duties for attorneys who use generative artificial intelligence and would restrict how arbitrators may use such tools in decision-making.

Time 1 Minute Read

The California Consumer Privacy Act continues to drive significant enforcement activity—particularly when minors’ data is involved. In a recent action, the California Privacy Protection Agency imposed a $1.1 million fine on youth sports platform PlayOn Sports for alleged violations involving student data and inadequate opt-out mechanisms. The case highlights growing regulatory scrutiny around how companies collect, share, and provide transparency about personal information—especially when schools and students are involved. 

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page