Privacy & Compliance · Study deck

Mobile Data Collection and Permissions

Before accepting a permission prompt, inspect @fig-mobile-data-permission-record to connect the feature need to every party that can use the resulting grant.

Privacy Priya is your guide for this deck.

mobileprivdata
iotclass.org

After studying this chapter

Learning objectives

You will be able to:

  • Explain: Sensitive capabilities are gated by runtime permissions the user grants while the app is running, paired with a declared purpose the platform shows in the prompt.
  • Explain: A feature may justify one selected photo without justifying the entire library; an SDK destination may create a second use that the prompt never explained.
  • Explain: The deeper layer explains the machinery that decides what an app can collect and how that collection becomes visible, or stays hidden.
  • Explain: The app asks for a permission, the user wants the feature to work, and the easy answer is to tap Allow.
iotclass.org

Major section

The App Is a Front Door to the Phone

A feature may justify one selected photo without justifying the entire library; an SDK destination may create a second use that the prompt never explained.

  • This record turns the front-door analogy into the chapter's running review method: need, boundary, recipient, and proof.
  • The app asks for a permission, the user wants the feature to work, and the easy answer is to tap Allow.
  • An IoT companion app is the front door to a phone's data.
iotclass.org

Major section

Scope Permissions and Map the Flows

The output is a recorded decision per feature, not a manifest full of permissions requested just in case.

  • Anything that cannot be tied to a live feature becomes a removal candidate, not a backlog note.
  • For each bundled library, record what data it can read, what it sends, and where it goes.
A cumulative curve of the percentage of an app
A cumulative curve of the percentage of an app
iotclass.org

Major section

Permissions, Identifiers, and Disclosures

The deeper layer explains the machinery that decides what an app can collect and how that collection becomes visible, or stays hidden.

  • Three mechanisms matter most: how permissions are granted, how identifiers enable tracking, and how disclosures are supposed to keep both honest.
  • Sensitive capabilities are gated by runtime permissions the user grants while the app is running, paired with a declared purpose the platform shows in the prompt.
  • App-plus-library controls need both static and dynamic evidence.
iotclass.org

Major section

Decide What a Step Counter May Collect

For a basic daily count, accelerometer samples can be reduced on the device to a step total.

  • The mobile collection record should change when that tracking state changes.
  • Raw motion need not leave the phone, and contacts do not help count steps.
A cumulative curve of the percentage of an app
A cumulative curve of the percentage of an app
iotclass.org

Deck summary

Key takeaways

A feature may justify one selected photo without justifying the entire library; an SDK destination may create a second use that the prompt never explained.

  • The output is a recorded decision per feature, not a manifest full of permissions requested just in case.
  • The deeper layer explains the machinery that decides what an app can collect and how that collection becomes visible, or stays hidden.
  • For a basic daily count, accelerometer samples can be reduced on the device to a step total.
iotclass.org

Retrieval practice

Recall check 1 of 3

Privacy Priya says: answer from memory, then check your reasoning.

Q1An IoT app says it collects very little, but it bundles a third-party analytics library that sends device identifiers to another company. How should the app's privacy posture be judged?

AIgnore it because only first-party collection counts in the privacy review
BCount the SDK's identifier sharing as part of the app's own data collection
CTreat it as zero collection because the developer did not write the SDK code
DAssume device identifiers are harmless because users can reset them
Show answer

Answer: B Third-party code running inside the app collects under the app's permissions, so its behavior counts as the app's collection.

iotclass.org

Retrieval practice

Recall check 2 of 3

Privacy Priya says: answer from memory, then check your reasoning.

Q2A fitness IoT app lets users attach a photo to a workout. Which data-access choice best follows data minimization?

ARequest full photo-library read access during onboarding for convenience
BBundle photos, contacts, and precise location into one first-launch prompt
CUse the system photo picker so only the chosen workout photo is shared
DUpload the full library so past and future workout photos are always available
Show answer

Answer: C A scoped picker shares only the chosen photos, which is the least access that delivers the feature.

iotclass.org

Retrieval practice

Recall check 3 of 3

Privacy Priya says: answer from memory, then check your reasoning.

Q3An app's store listing says it does not track users, but a bundled advertising SDK reads the advertising identifier and sends it to an ad network for cross-app profiling. What is wrong, and what is the fix?

ANothing is wrong because the advertising identifier is anonymous and resettable
BKeep the label unchanged so users are not prompted again
CCollect more identifiers so the ad network can classify traffic more accurately
DThe listing omits SDK tracking; gate or remove the SDK and update disclosure
Show answer

Answer: D The disclosure must match reality, and cross-app tracking needs consent, so the SDK should be gated or removed and the privacy label fixed.

iotclass.org

Print reference

Answers

Answer key.

  1. B · Third-party code running inside the app collects under the app's permissions, so its behavior counts as the app's collection.
  2. C · A scoped picker shares only the chosen photos, which is the least access that delivers the feature.
  3. D · The disclosure must match reality, and cross-app tracking needs consent, so the SDK should be gated or removed and the privacy label fixed.
iotclass.org