Privacy Policies of Free Medical, Health, Fitness Mobile Applications and the GDPR

Muhammad Yaqub,Feng Jinchao,Imran Shabir Chuhan,Kaleem Arshid,Wenqian Zhang
DOI: https://doi.org/10.1109/IMIP57114.2023.00021
2023-01-01
Abstract:mHealth apps are one of the most beneficial conveniences provided by smartphones for human beings. Free mHealth apps are extremely popular in facilitating healthcare for low-income populations. A vast variety of personal and identifiable data is handled by contemporary mHealth apps; hence their adherence to modern privacy standards and demands is vital. General Data Protection Regulation (GDPR) is a comprehensive, current privacy standard. This research analyzes 50 popular free Medical and Health and Fitness Android apps for privacy adherence to GDPR. Although the apps in the data set had 1 million or more downloads and a user rating of more than 4.00, their adherence to vital aspects of GDPR was discouraging. Declaration of types of personally identifiable information collected by the data collectors, identification details of the data controller, purposes of data processing and sharing, details of data protection officer, the legal basis for data processing, data storage period, data subjects’ rights, details of a supervisory authority and implementation of informed consent are the points on which privacy policies of apps in this research were analyzed. Fulfillment of informed consent, declaration of purposes of data processing, declaring details of data recipients, and provision of data subjects’ rights were among some of the weakest privacy aspects of the apps analyzed in this research. It is recommended that mHealth app developers focus on the implementation of privacy recommendations to enhance the effectiveness of their apps.
What problem does this paper attempt to address?