Options
2026
Conference Paper
Title
Informed Consent by Design: Developer-Oriented Privacy Best Practices for GDPR Compliant mHealth Applications
Abstract
When developing applications that collect and process personal data, caution is needed due to the potential for significant harm to individuals’ rights and freedoms. This risk is particularly pronounced in the domain of health applications, where data sensitivity is intensified by the intimate nature of health information and the potential for misuse, discrimination, or unauthorized access. Central to safeguarding these rights is the principle of informed consent, enabling individuals to make well-informed decisions about whether to share their data and under what circumstances. However, effective implementation of informed consent remains a persistent challenge in practice. While numerous theoretical models and design concepts for improving consent mechanisms have been proposed in the literature, their concrete implementation remains limited. A key barrier lies in the fact that software developers are expected to implement complex regulatory requirements, such as those outlined in the General Data Protection Regulation (GDPR), with limited legal expertise and without clear guidance on what specific technical or procedural measures are necessary for compliance. Interviews with software developers and product managers involved in healthcare applications highlighted a consistent gap in specific, actionable guidance for implementing data protection requirements. To this end, we have developed privacy best practices to support development teams in designing and implementing effective, transparent, and user-centric informed consent.
Author(s)
Conference
Open Access
File(s)
Rights
CC BY-NC-ND 4.0: Creative Commons Attribution-NonCommercial-NoDerivatives
Additional link
Language
English