PRACTICAL DATA PROTECTION: HOW WE BUILD APPS WITH BUILT-IN PROTECTION
August 18, 2025
Data protection often seems complicated. In practice, a simple approach helps: as little data as possible, as transparent as possible, as secure as necessary. This is how we implement this - comprehensibly and without legalese.
Why data protection is so important in mobile apps
Data protection is not only a legal obligation, but also a sound business decision: Data breaches cost several million dollars on average—according to IBM’s latest industry report, an average of $4.88 million per incident in 2024.
At the same time, courts are setting clear boundaries: The European Court of Justice requires active consent for tracking technologies (known as the “Planet49” ruling)—a signal of just how carefully consent processes in apps must be designed.
The bar is also set high for data transfers outside the EU: With “Schrems II,” the ECJ overturned the previous agreement with the U.S. and tightened the requirements—companies have needed additional safeguards ever since.
The record fine of 1.2 billion euros imposed on Meta for unlawful data transfers demonstrates that violations can be costly. Regulatory authorities are cracking down—making “data protection by design” all the more important right from the app’s conception.
The question of how to achieve robust data protection in mobile and web apps is therefore highly relevant for companies. We provide clear guidelines on what to look out for:
Who does what?
The product and business units determine what the data is used for and what is truly necessary. The development team implements security measures—from secure login to encryption. Data protection officers assess risks and maintain an overview.
Only what is really necessary
We only store the data necessary for the intended purpose—and for as short a time as possible. We clearly label which information is required and which is optional. We avoid collecting particularly sensitive information or keep it strictly separate from other data.
Understandable consent
When we ask for consent (e.g., for communications or analytics), we do so in a clear and understandable way, and you can revoke your consent at any time. The privacy policy is easy to find and written in plain language. Upon request, users can view or have their data deleted. (Note: Active consent is required for tracking and similar techniques—no “opt-out” via pre-checked boxes.)
Security without secrecy
We separate operational data (e.g., error reports) from personal data. Access is restricted, connections are encrypted, and backups are standard practice. In the event of an emergency, clear procedures are in place to ensure a rapid response. When data is transferred to countries outside the EU, we review the legal basis and supplementary safeguards—a requirement since Schrems II.
Cooperation with service providers
We enter into clear agreements with third-party providers regarding data processing. We document where data is stored and who has access to it, and we review these arrangements regularly. Experience with large platforms shows that regulatory authorities take action when rules are violated.
The last check before the start
Before going live, we’ll take the time to clearly answer these questions: What data do we have? What is it for? How long will it be kept? Where is everything stored? Who has access to what? Only then will we get started. After that, we’ll observe how things play out in day-to-day operations and make improvements step by step.
Conclusion
Good data protection means good product quality: less risk, more trust, and less support work. With clear rules and a healthy dose of simplicity, it becomes a partner rather than a hindrance. And: Thinking ahead saves you from costly setbacks.
Agency for app development
Interested? As part of our digitalization-audit we assess compliance with data protection guidelines in your digital products.
We look forward to learning more about your company and would be happy to consult you.
Sources:
IBM: Cost of a data breach 2024
EuGH C-673/17 - Planet49
EuGH C-311/18 - Facebook Ireland und Schrems
EDPB binding decision
Data protection
GDPR
Privacy by design
Consent
Data minimization
Transparency
Roles and rights
Encryption
Order processing
TOMs
Backups
Compliance
René Krause
[email protected]

