As part of the app review, Dataswift has to set up a legal contract between your app and your users. This contract enables your users to give your app the permission and the right to use a namespace within your users' own database (each user has his/her own database). If your app is requesting for any other data from another namespace of their databases, a data debit must also be specified within the contract. This contract is set up by Dataswift before your app goes live and will be autogenerated when your users sign in to your app.
Dataswift requires information for the review and for the contract to be set up. We also require the application to declare the rating of application based on the Rating Assurance system. Below is a checklist that can help you prepare for review
Check your app rating and try to get the best possible rating for your app's data conduct.
Are you putting third party data into the PDA Database? Make sure it belongs to the PDA owner and that you have all the necessary permissions from the third-party data provider to be written into the PDA Database (usually subject access request can be used but you would need to ensure your legal agreement with your users say so).
If you also hold the data outside the PDA database, either ensure it's not identifiable or if it is, ensure it is secure. If the data is identifiable, note that your app rating for the first letter will go down to a B or lower.
Be ready to accurately declare what data will be in the PDA database, what data will sit on both your backend servers and the PDA database, and what data is not.
Be ready to declare any conditions imposed on a PDA owner for reuse and re-sharing of the data you place in his/her database.
If you collect sensitive data, be ready to declare your data conduct in terms of collection, storage, usage, processing and sharing.
If you are requesting for other namespace data (e.g. calendar or FB), be ready to answer questions on duration, purpose and what specific data is required.
Ensure your app meets the consumer law requirements of all applicable laws in any jurisdiction that you intend to offer your services.
If you are sharing PDA data with third parties, ensure you will get the owner's consent. The platform will not cover any legal agreement outside of what your app is doing with the PDA owner's HAT data
Ensure the provision of essential goods or services is not dependent on your app as this would impact your user's acceptance of the data contract? (housing, food & medicine)
Ensure no other service contingent on the acceptance of this data contract of the PDA owner's data usage by your app
Ensure your app will not result in any prejudice or harm to the PDA owner. Get a Privacy Impact Assessment and Data Protection Impact Assessment done if in doubt.
Ensure your app and the data contract do not propose any specific or general risk
Ensure you have all your app information (submitted within the developers portal). You won't be able to pass review if they are not included in the submission.
Ensure you have a set of login credentials so that the review team can go through the entire user journey of the app. The list of information needed is available within the developer's portal
Ensure that your application’s user journey follows these journeys.
Ensure a "PDA Accepted here" icon is on your marketing website
Ensure the PDA registration screen where your user enters an email to register for your app is included in the link to the PDA Terms of service and has the standard way of explaining a PDA and is clearly shown. This is usually as follow:
We use Personal Data Accounts (PDAs) powered by the HAT Microserver technology to give you control and legal rights over your data. By proceeding to you agree to:
Learn how we protect your data:
Your PDA enables you to own data rights for reuse and sharing with applications. For more information on the technology that power PDAs, please visit https://hubofallthings.com
Be sure to check the pricing for your application here.
If you intend to operate outside the US, Europe, or Brazil, please inform Dataswift.
If you need other features for the PDAs (children PDAs, elderly PDAs, or special PDAs for the health sector), please check with Dataswift support team. Our policy is that no new features will be enabled or worked on unless the first version of the application has gone live and have live users.
All the best for your app!