Personal Information Protection and Privacy Policy Compliance of Health Code Apps in China: Scale Development and Content Analysis

被引:1
|
作者
Jiang, Jiayi [1 ]
Zheng, Zexing [1 ,2 ]
机构
[1] Cent South Univ, Law Sch, Changsha, Peoples R China
[2] Cent South Univ, Law Sch, 932 Lushan South Rd, Changsha 410083, Hunan, Peoples R China
来源
JMIR MHEALTH AND UHEALTH | 2023年 / 11卷
关键词
contact tracing; privacy policy; personal information protection; compliance; content analysis; COVID-19; BALANCE;
D O I
10.2196/48714
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Background: Digital technologies, especially contact tracing apps, have been crucial in monitoring and tracing the transmis-sion of COVID-19 worldwide. China developed health code apps as an emergency response to the pandemic with plans to use them for broader public health services. However, potential problems within privacy policies may compromise personal information (PI) protection. Objective: We aimed to evaluate the compliance of the privacy policies of 30 health code apps in the mainland of China with the Personal Information Protection Law (PIPL) and related specifications. Methods: We reviewed and assessed the privacy policies of 30 health code apps between August 26 and September 6, 2023. We used a 3-level indicator scale based on the information life cycle as provided in the PIPL and related specifications. The scale comprised 7 level-1 indicators, 26 level-2 indicators, and 71 level-3 indicators. Results: The mean compliance score of the 30 health code apps was 59.9% (SD 22.6%). A total of 13 (43.3%) apps scored below this average, and 6 apps scored below 40%. Level-1 indicator scores included the following: general attributes (mean 85.6%, SD 23.3%); PI collection and use (mean 66.2%, SD 22.7%); PI storage and protection (mean 63.3%, SD 30.8%); PI sharing, transfer, disclosure, and transmission (mean 57.2%, SD 27.3%); PI deletion (mean 52.2%, SD 29.4%); individual rights (mean 59.3%, SD 25.7%); and PI processor duties (mean 43.7%, SD 23.8%). Sensitive PI protection compliance (mean 51.4%, SD 26.0%) lagged behind general PI protection (mean 83.3%, SD 24.3%), with only 1 app requiring separate consent for sensitive PI processing. Additionally, 46.7% (n=14) of the apps needed separate consent for subcontracting activities, while fewer disclosed PI recipient information (n=13, 43.3%), safety precautions (n=11, 36.7%), and rules of PI transfer during specific events (n=10, 33.3%). Most privacy policies specified the PI retention period (n=23, 76.7%) and postperiod deletion or anonymization (n=22, 73.3%), but only 6.7% (n=2) were committed to prompt third-party PI deletion. Most apps delineated various individual rights: the right to inquire (n=25, 83.3%), correct (n=24, 80%), and delete PI (n=24, 80%); cancel their account (n=21, 70%); withdraw consent (n=20, 60%); and request privacy policy explanations (n=24, 80%). Only a fraction addressed the rights to obtain copies (n=4, 13.3%) or refuse advertisement of automated decision-making (n=1, 3.3%). The mean compliance rate of PI processor duties was only 43.7% (SD 23.8%), with significant deficiencies in impact assessments (mean 5.0%, SD 19.8%), PI protection officer appointment (mean 6.7%, SD 24.9%), regular compliance audits (mean 6.7%, SD 24.9%), and complaint management (mean 37.8%, SD 39.2%). Conclusions: Our analysis revealed both strengths and significant shortcomings in the compliance of privacy policies of health code apps with the PIPL and related specifications considering the information life cycle. As China contemplates the future extended use of health code apps, it should articulate the legitimacy of the apps' normalization and ensure that users provide informed consent. Meanwhile, China should raise the compliance level of relevant privacy policies and fortify its enforcement mechanisms.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] Privacy Policy Compliance of Chronic Disease Management Apps in China: Scale Development and Content Evaluation
    Ni, Zhenni
    Wang, Yiying
    Qian, Yuxing
    [J]. JMIR MHEALTH AND UHEALTH, 2021, 9 (01):
  • [2] Medical Information Protection in Internet Hospital Apps in China: Scale Development and Content Analysis
    Jiang, Jiayi
    Zheng, Zexing
    [J]. JMIR MHEALTH AND UHEALTH, 2024, 12
  • [3] Privacy at risk? Understanding the perceived privacy protection of health code apps in China
    Huang, Gejun
    Hu, An
    Chen, Wenhong
    [J]. BIG DATA & SOCIETY, 2022, 9 (02):
  • [4] Scrutinizing Privacy Policy Compliance of Virtual Personal Assistant Apps
    Xie, Fuman
    Zhang, Yanjun
    Yan, Chuan
    Li, Suwan
    Bu, Lei
    Chen, Kai
    Huang, Zi
    Bai, Guangdong
    [J]. PROCEEDINGS OF THE 37TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE 2022, 2022,
  • [5] Evaluating the Privacy Policy of Android Apps: A Privacy Policy Compliance Study for Popular Apps in China and Europe
    Liu, Kaijun
    Xu, Guoai
    Zhang, Xiaomei
    Xu, Guosheng
    Zhao, Zhangjie
    [J]. Scientific Programming, 2022, 2022
  • [6] Evaluating the Privacy Policy of Android Apps: A Privacy Policy Compliance Study for Popular Apps in China and Europe
    Liu, Kaijun
    Xu, Guoai
    Zhang, Xiaomei
    Xu, Guosheng
    Zhao, Zhangjie
    [J]. SCIENTIFIC PROGRAMMING, 2022, 2022
  • [7] Privacy in Chinese iOS apps and impact of the personal information protection law
    Kollnig, Konrad
    Zhang, Lu
    Zhao, Jun
    Shadbolt, Nigel
    [J]. COMPUTER LAW & SECURITY REVIEW, 2024, 55
  • [8] Privacy and Health in the Information Age: A Content Analysis of Health Web Site Privacy Policy Statements
    Rains, Stephen A.
    Bosch, Leslie A.
    [J]. HEALTH COMMUNICATION, 2009, 24 (05) : 435 - 446
  • [9] A Revival of the Privacy Protection of Health-Related Personal Information?
    Abbing, Henriette
    [J]. EUROPEAN JOURNAL OF HEALTH LAW, 2011, 18 (03) : 247 - 254
  • [10] The legal construction of personal information protection and privacy under the Chinese Civil Code
    Cui, Shujie
    Qi, Peng
    [J]. COMPUTER LAW & SECURITY REVIEW, 2021, 41