Skip to main content
Shaping Europe’s digital future

Privaatsuse käitumisjuhend mobiilsetes terviserakendustes

The privacy code of conduct on mobile health apps aims to promote trust among users and provide a competitive advantage for those who sign up to it.

    Isik, kellel on telefon ikoonidega, mis esindavad selle kohal hõljuvaid mobiilseid terviserakendusi

© iStock by Getty Images - 1141201617 marchmeena29

The first versions of the code of conduct for mobile health apps were prepared against the background of the European Commission's 2014 mobile health green paper consultation. The consultation revealed that people often do not trust mobile health apps because of privacy concerns.

Following this consultation, the European Commission encouraged industry stakeholders to create a privacy code of conduct on mobile health apps in order to increase trust.

The objective was that the code of conduct would obtain the formal approval of European data protection authorities. Under the current General Data Protection Regulation (GDPR), the role of assessing codes falls under the mandate of the European Data Protection Board. Codes approved by the European Data Protection Board can be granted general validity across the EU through an implementing act.

History and current status

The work on a mobile health code of conduct started in April 2015, when a drafting team of industry members started developing the text of the code. The European Commission acted as a facilitator, providing legal and policy expertise and resources and overseeing the development of this work.

This drafting team included the App Association (ACT), App developers Alliance, Apple, COCIR, Digital Europe, ECHA, DHACA, EFPIA, Google, Intel, Microsoft, Qualcomm and Samsung. They worked through regular meetings, and presented the work at various events in order to obtain further feedback. The vision was that the code should be easily understandable for SMEs and individual developers who may not have access to legal expertise.

An early version of the work was submitted by the drafting team to the Article 29 Working Party in June 2016 for a first round of feedback. Following various suggestions for improvement from the Working Party, the Code was reworked (.pdf), and formally submitted on 7 December 2017, requesting approval under the Data Protection Directive.

The Working Party published its assessment in April 2018. It found that the criteria of the GDPR should be applied, and that the existing code did not yet adequately address these requirements. As a result, the Code was not approved.

Next steps

The Commission is engaged with a range of industry stakeholders in order to encourage the further development of the current draft Code, so that it may be submitted to the European Data Protection Board in the future to seek a formal approval.

Main provisions for app developers

The current draft of the Code consists of practical guidance for app developers on data protection principles while developing mobile health apps. The Code addresses notably the following topics:

User consent 

The user consent for the processing of personal data must be free, specific and informed. Explicit consent needs to be obtained for the processing of health data. Any withdrawal of consent has to result in the deletion of the user's personal data.

Purpose limitation and data minimisation

The data may be processed only for specific and legitimate purposes. Only data that are strictly necessary for the functionality of the app may be processed.

Privacy by design and by default

The privacy implications of the app have to be considered at each step of the development and wherever the user is given a choice. The app developer has to pre-select the least privacy invasive choice by default.

Data subject rights and information requirements

The user has the right to access their personal data, to request corrections and to object to further processing. The app developer needs to provide the user with certain information on the processing.

Data retention 

Personal data may not be stored longer than necessary.

Security measures

Technical and organisational measures need to be implemented to ensure the confidentiality, integrity and availability of the personal data processed and to protect against accidental or unlawful destruction, loss, alteration, disclosure, access or other unlawful forms of processing.

Advertising in mobile health apps

There is a distinction between advertising based on the processing of personal data (requiring opt-in consent) and advertising not relying on personal data (opt-out consent).

Use of personal data for secondary purposes

Any processing for secondary purposes needs to be compatible with the original purpose. Further processing for scientific and historical research or statistical purposes is considered as compatible with the original purpose. Secondary processing for non-compatible purposes requires a new consent.

Disclosing data to third parties for processing operations

The user needs to be informed prior to disclosure and the app developer needs to enter into a binding legal agreement with the third party.

Data transfers

For data transfers to a location outside the EU/EEA, there needs to be legal guarantees permitting such transfer, e.g. an adequacy decision of the European Commission, European Commission Model Contracts or Binding Corporate Rules.

Personal data breach

The code provides a checklist to follow in case of a personal data breach, in particular the obligation to notify a data protection authority.

Data gathered from children

Depending on the age limit defined in national legislation, the most restrictive data processing approach needs to be taken and a process to obtain parental consent needs to be put in place.

Latest News

NEWS ARTICLE |
Pakkumiskutse: mitmehaigestumusega inimeste integreeritud hooldus

Käesoleva konkursikutse eesmärk on käivitada uute lahenduste katsetamine ja väljatöötamine, et ennetada ja rahuldada multimorbitiitiliste inimeste vajadusi, tagades õigeaegse juurdepääsu teenustele, kaasjuhitud hooldusreisid ning üleminekud erialade ja sektorite vahel. Pakkumiste esitamise tähtaeg: 10. jaanuar 2023

NEWS ARTICLE |
Euroopa aktiivsena ja tervena vananemise nädal 2022

Täisväärtusliku eluperioodi pikendamist käsitlev Euroopa nädal (EWAHA) toob kokku partnerid kogu Euroopast, kes on huvitatud tervena vananemise edendamisest ja toetamisest ning kasutavad ära Euroopa vananeva elanikkonna võimalusi meie digimaailmas.

NEWS ARTICLE |
Pakkumiskutse: Andmepõhine enesehooldus krooniliste haigustega patsientide jaoks maapiirkondades

Rootsi, Hispaania, Taani ja Norra tervishoiuteenuste ostjad kutsuvad huvitavaid pakkujaid üles esitama oma kommertskasutusele eelneva hanke pakkumisi. Eesmärk on käivitada innovatsiooni kogu Euroopas, et võimaldada tulemuslikke, tõhusaid ja kasutajasõbralikke andmepõhiseid teenuseid, mis võimaldaksid Euroopa maaelanikkonnal end ise hooldada kroonilisi haigusi.

Seotud sisu

Üldpilt

e-tervishoid

Euroopa Komisjon teeb tööd selle nimel, et tagada kodanikele juurdepääs ohututele ja kvaliteetsetele tervishoiu- ja hooldusteenustele.

Vaata lisaks

Terviseandmete haldamine

Euroopa Komisjon võttis vastu teatise ja komisjoni talituste töödokumendi tervishoiu ja hoolduse digiülemineku kohta, et hoogustada Euroopa Liidu tegevust.