BBB National Programs Insights
What Parents Need to Know About Mobile App and Device Permissions
If there is one thing most parents know, it’s that Kids. Love. Apps. Kids love apps so much that hundreds of articles highlighting the “best” new apps for kids come out every year; one article even listed 329 of the best new apps for kids. If that sounds overwhelming, there are other articles out there that list the apps that parents should avoid downloading for their kids. But what happens when your child wants to download an app that’s not on any of those lists?
If you want to evaluate an app to determine how safe your child’s data will be if they use it, start by understanding the permissions the app asks for. Both iOS and Android devices allow apps to ask users for permission to access different information on the device that helps provide the app’s services. For example, a fitness app might ask you to enable your “Motion and Fitness” permission so it can help track calories burned, or a navigation app might ask you to enable your location permission so it can accurately direct your trip. Apps may request permission for something innocuous, like setting the time zone, however sometimes those permissions are asking to access things that the Children’s Online Privacy Protection Act (COPPA) classifies as personal information.
Under COPPA, personal information includes information that can directly identify a child under 13 including their first and last name, home address or precise location, online contact information, or telephone number. If the operator of an online service collects, uses, or shares a child’s personal information, they must provide a notice that explains what they are doing with the personal information. If an operator is sharing personal information with third parties or using it for other purposes such as marketing, they must also get Verifiable Parental Consent (VPC) from the child’s parent or guardian to do so.
To learn more about COPPA, see our blog post “COPPA and Children's Privacy: What Parents Should Know and Do.”
When an app asks permission to access information from your phone, this is different than asking for VPC. App platforms such as Apple and Google require apps to ask for permissions, whereas obtaining VPC is required by law. For VPC to be required when an app asks for personal information, two things need to take place:
- The child under 13 is the person providing the personal information. If a parent or other person over 13 is the one providing the personal information (such as a parent uploading a photo of their child to Facebook), no VPC is needed as COPPA only applies to information collected directly from children under 13.
- The app is collecting, storing, or sharing the personal information. If the app saves personal information to its own servers, or discloses it to another company for another purpose, then VPC is required.
- Decide what kinds of permissions you are okay with your child granting. If you are not comfortable with an app requesting your child’s exact location (even if that information is not stored or shared by the app), then be sure to use your discretion when looking at apps that need location to operate.
- Talk to your child! Once they are using the app, encourage them to ask you before granting any app permissions. Explain why you may be okay granting some permissions but not others.
To make this distinction clearer, let’s look at a hypothetical app that’s intended for kids under age 13:
Here are three best practices to support safe app usage:
If you want to learn more about child-directed advertising and data privacy, but are a beginner, make sure you tune into Kidvertising 101 in November, a seminar that will teach the "need-to-know" basics and best practices for successfully navigating this complex landscape.