Data Use

Criteria: Data usage is consistent with the context of the relationship with the user and is transparent.

See the test in action:

Notes:

  • Some devices may capture a category of information but not transmit that data to the service provider, instead using the data only locally on the device, or presenting it for the information of the owner.
  • In such cases, that data capture may not be reported in the legal documents as being collected by the service provider.
  • While we encourage companies to develop products that only store collected data locally on the device instead of transmitting data to the cloud, it is still a best practice for companies to inform users of all data collected, even if a piece of information does not leave the device.

Indicators

  1. The company puts limits on the use of my data that are consistent with the purpose for which the data is collected.
  2. The company explicitly discloses every way in which it uses my data.

Methodology for Assessing Each Indicator

1) The company puts limits on the use of my data that are consistent with the purpose for which the data is collected.

  • Obtain and review a copy of the service provider’s legal documents.
  • Find the portion of the legal documents that addresses data use and compare the reasons the company provides for using data with the reasons it provides for collecting data. In particular, consider whether the company provides reasons why it needs each type of data collected in order to operate the product or provide offered services.
  • Look in particular for data uses that fall outside of the stated purposes for data collection.
  • If the legal documents are not clear about whether they apply to the “smart device” being evaluated, or only to the websites and other services of the service provider, limit grade to PARTIAL PASS.
  • If the use limitations stated in the legal documents are related to and proportional with the stated purposes for collecting the data, mark PASS.
  • If the legal documents refer to uses of personal information that are outside the scope of the stated reasons listed for data collection, or if the documents do not explain whether or how certain collected data is used, mark FAIL.

2) The company explicitly discloses every way in which it uses my data.

  • Make use of the product, both as an everyday user would and making sure to explore all the features of the product.
  • Make note of all instances where personal data is likely to be used.
    • Look for personalization, advertisements, and “automatic” features.
    • If the product has a phone app, look at the permissions requested by the app as well as any information on data collection that the phone operating system offers (e.g. the app using the phone’s location services).
  • Review the language in legal documents discussing how data is used.
    • Consider whether the language states that it is a comprehensive list of all the ways in which collected data is used.
    • Compare the list of uses to the observations from the prior step.
  • If the legal documents are not clear about whether they apply to the “smart device” being evaluated, or only to the websites and other services of the service provider, limit grade to PARTIAL PASS.
  • If all of the uses of personal data observed during the testing of the product are included in the legal documents, mark PASS.
  • If use of the product produces evidence of uses of data not disclosed in the legal documents, mark FAIL.

Table of Contents

Close