Mobile App Design Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under COPPA, what is the minimum age threshold that triggers parental consent requirements for US mobile apps?
- 13 (Correct answer)
- 16
- 18
- 12
Correct answer: 13
COPPA (Children's Online Privacy Protection Act) requires verifiable parental consent before collecting personal data from children under 13.
Question 2: A fitness app collects heart rate data from users. Under HIPAA, this data is classified as Protected Health Information (PHI) only when:
- It is linked to an identified individual and held by a HIPAA-covered entity or business associate (Correct answer)
- Any heart rate data is collected regardless of context
- The app is sold on a regulated medical device platform
- The user opts into health data sharing
Correct answer: It is linked to an identified individual and held by a HIPAA-covered entity or business associate
HIPAA PHI requires both identifiability and that the entity holding it is a covered entity or their business associate.
Question 3: Which App Store Review Guideline section primarily governs apps that include user-generated content?
- Guideline 1.2 — User Generated Content (Correct answer)
- Guideline 3.1 — Payments
- Guideline 5.1 — Privacy
- Guideline 2.3 — Accurate Metadata
Correct answer: Guideline 1.2 — User Generated Content
Apple's Guideline 1.2 requires UGC apps to have moderation mechanisms, reporting tools, and the ability to block abusive users.
Question 4: An app targeting the EU market uses a pre-ticked checkbox to obtain consent for marketing emails. Under GDPR, this consent is:
- Invalid, because consent must be freely given and unambiguous (Correct answer)
- Valid if the user does not uncheck it within 30 days
- Valid as long as the privacy policy is accessible
- Invalid only if the user is under 16
Correct answer: Invalid, because consent must be freely given and unambiguous
GDPR Article 7 requires consent to be a clear affirmative act; pre-ticked boxes do not constitute valid consent.
Question 5: Which US federal law requires mobile apps that accept credit card payments to comply with PCI DSS standards?
- There is no single federal law; PCI DSS is an industry standard enforced by card networks (Correct answer)
- The Electronic Fund Transfer Act (EFTA)
- The Gramm-Leach-Bliley Act (GLBA)
- The Federal Trade Commission Act (FTC Act)
Correct answer: There is no single federal law; PCI DSS is an industry standard enforced by card networks
PCI DSS is a contractual requirement set by payment card brands (Visa, Mastercard, etc.), not a US federal statute.
Question 6: A developer wants to use push notifications to re-engage dormant users in California. Under CCPA, what must the app provide?
- A clear opt-out mechanism and disclosure of how notification data is used (Correct answer)
- Explicit opt-in consent renewed every 12 months
- A toll-free number for users to request data deletion
- No additional requirement beyond the standard privacy policy
Correct answer: A clear opt-out mechanism and disclosure of how notification data is used
CCPA requires businesses to inform California consumers about data use and provide an easy opt-out for data sharing that qualifies as a 'sale.'
Question 7: Google Play's target API level policy requires apps to target a recent Android API level primarily to:
- Ensure users receive modern privacy and security protections introduced in newer Android versions (Correct answer)
- Reduce the APK file size on the Play Store
- Enable Google Play Protect scanning
- Allow background location access without additional permissions
Correct answer: Ensure users receive modern privacy and security protections introduced in newer Android versions
Targeting recent API levels ensures apps adopt new Android privacy features like scoped storage and permission changes.
Under COPPA, what is the minimum age threshold that triggers parental consent requirements for US mobile apps?