| Literature DB >> 32720913 |
Jaime Benjumea1, Jorge Ropero1, Octavio Rivera-Romero1, Enrique Dorronzoro-Zubiete1, Alejandro Carrasco1.
Abstract
BACKGROUND: Cancer patients are increasingly using mobile health (mHealth) apps to take control of their health. Many studies have explored their efficiency, content, usability, and adherence; however, these apps have created a new set of privacy challenges, as they store personal and sensitive data.Entities:
Keywords: GDPR; cancer apps; fairness assessment scale; mhealth apps; privacy
Mesh:
Year: 2020 PMID: 32720913 PMCID: PMC7420637 DOI: 10.2196/17134
Source DB: PubMed Journal: JMIR Mhealth Uhealth ISSN: 2291-5222 Impact factor: 4.773
Definition of General Data Protection Regulation concepts.
| Concept | Definition |
| Data subject | A natural person whose personal data are being processed; the GDPRa defines personal data not only as the data related to an identified person, but also as the data that can be used to identify, directly or indirectly, a natural person. |
| Data controller | “The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data” [ |
| Data processor | “The natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller” [ |
| Recipient | “The natural or legal person, public authority, agency, or another body, to which the personal data are disclosed” [ |
| Representative | A natural or legal person established in the EUb; a representative must be designated by data controllers or processors not in the EU (Article 27). |
| DPOc | A person who must be designated by the controller or processor in certain circumstances (see Article 37 for more details); the duties of the DPOc are defined in Article 39; they include, among others, advising the controller or processor about their duties related to the GDPR and monitoring compliance with GDPR |
aGDPR: General Data Protection Regulation.
bEU: European Union.
cDPO: data protection officer.
Items in the privacy policy (Article 13).
| Item | Item number |
| Identity of data controller | 1 |
| Identity of the representative | 2 |
| Data protection officer details | 3 |
| Purposes for the processing | 4 |
| Legal basis for the processing | 5 |
| Legitimate interests from controller | 6 |
| Recipients (or categories) of the personal data | 7 |
| Transfers to non–European Union countries | 8 |
| Period for which data will be stored | 9 |
| Existence of data subject’s rights | 10 |
| Existence of right to withdraw consent | 11 |
| Right to lodge a complaint with a supervisory authority | 12 |
| Obligation to provide personal data | 13 |
| Existence of automated decision making or profiling | 14 |
Kappa-Cohen indexes for privacy policy items for the 9 apps evaluated in the first iteration.
| Item | Item number | Score | Kappa-Cohen index (n=9) |
| Identity of data controller | 1 | 0: no info; 0.5: partial; 1: full | 0.77 |
| Identity of the representative | 2 | 0: no info; 1: info provided; N/A: not applicable | 1 |
| Data protection officer details | 3 | 0: no info; 1: info provided | 0.61 |
| Purposes for the processing | 4 | 0: no info; 0.5: generic; 1: specific | 0.77 |
| Legal basis for the processing | 5 | 0: no info; 1: info provided | 0.77 |
| Legitimate interests from controller | 6 | 0: no info; 1: info provided; N/A: not applicable | 0.8 |
| Recipients (or categories) of the personal data | 7 | 0: no info; 1: info provided | –0.13 |
| International transfers of data | 8 | 0: no info; 0.5: generic; 1: full details or no international transfers | 0.53 |
| Period for which data will be stored | 9 | 0: no info; 0.5: generic; 1: specific | 0.66 |
| Existence of data subject’s rights | 10 | 0: no info; 0.5: generic; 1: full | 0.49 |
| Existence of right to withdraw consent | 11 | 0: no info; 1: info provided; N/A: not applicable | 0.08 |
| Right to lodge a complaint with a supervisory authority | 12 | 0: no info; 0.5: generic; 1: specific | 0.77 |
| Obligation to provide personal data | 13 | 0: no info; 1: info provided | –0.17 |
| Existence of automated decision making or profiling | 14 | 0: no info; 0.5: generic; 1: specific or no profiling or automated decision making done | 0.17 |
Figure 1Flow diagram.
Selected apps.
| App name | Developer | Rating (stars) | # Ratings | # Downloads | App type | Cancer type | Label |
| BECCA: Breast Cancer Support | Breast Cancer Care | 4.5 | 63 | 10,000+ | Sa | Breast | App1 |
| EmotionSpace cáncer de mama | Pfizer Inc | 2.5 | 2 | 100+ | S | Breast | App2 |
| ChemoWave: For Cancer Patients | Treatment Technologies & Insights | 4.4 | 20 | 1000+ | DMb | General | App3 |
| OWise Breast Cancer | Px HealthCare BV | 4.4 | 10 | 1000+ | DM | Breast | App4 |
| My Cancer Coach | Genomic Health Inc | 4.5 | 86 | 10,000+ | DM | General | App5 |
| Breast Advocate | Toliman Health | 5 | 1 | 100+ | DTIc | Breast | App6 |
| Breast Cancer Support | MyHealthTeams | 4.1 | 47 | 1000+ | S | Breast | App7 |
| KMBCN | Kepharge | 5 | 1 | 10+ | DTI | Breast | App8 |
| Triple Negative Breast Cancer | Kognito | 5 | 2 | 100+ | DTI | Breast | App9 |
| Breast Cancer: Others Like Me | Eli Malki | 0 | 0 | 5+ | S | Breast | App10 |
| Outcomes4Me | Outcomes4Me Inc | 5 | 5 | 100+ | DTI | Breast | App11 |
| Boobytrapp: The Breast Cancer App | Boobytrapp | 3.7 | 3 | 100+ | S | Breast | App12 |
| The BAPS App Wales | The Orchard Media & Events Group Ltd | 0 | 0 | 100+ | DM | Breast | App13 |
| BELONG Beating Cancer Together | BelongTail | 4.7 | 1,151 | 100,000+ | DM | General | App14 |
| Diana | F Hoffmann–La Roche | 5 | 7 | 1000+ | DM | Breast | App15 |
| Got Boobs? | Got Boobs | 0 | 0 | 100+ | S | Breast | App16 |
| inKind Space | PixelEdge | 0 | 0 | 10+ | S | Breast | App17 |
| Cancer Surveillance | GoMLV | 3.7 | 21 | 1000+ | DM | General | App18 |
| Focalyx | Lyx Health | 4.8 | 6 | 50+ | DM | Prostate | App19 |
| Adrenal Cancer: Others Like Me | Eli Malki | 5 | 6 | 1000+ | S | Other | App20 |
| How Are You Today? PC | Intelesant | 0 | 0 | 100+ | DM | Prostate | App21 |
| Cancer.Net Mobile | American Society of Clinical Oncology | 4.2 | 227 | 10,000+ | DM | General | App22 |
| TNM Cancer Staging | International Atomic Energy Agency | 4.6 | 323 | 10,000+ | DTI | General | App23 |
| Untire: Beating cancer fatigue | Tired of Cancer BV | 4.5 | 60 | 5000+ | DM | General | App24 |
| Self-Care During Cancer | NearSpace Inc | 4.7 | 6 | 1000+ | S | General | App25 |
| CanDi: Cancer Diet App | Faculty of Health Sciences UniSZA | 4.7 | 60 | 500+ | DM | General | App26 |
| CancerAid | CancerAid PTY LTD | 3.7 | 25 | 1000+ | DM | General | App27 |
| GRYT Health Cancer Community | GRYT Health | 3.9 | 7 | 100+ | S | General | App28 |
| Target Ovarian Cancer Symptoms Diary | Brandwave Marketing | 3.6 | 8 | 1000+ | DM | Other | App29 |
| Pancreatic Cancer Action: Symptom Tracker | Healthbit Ltd | 5 | 3 | 100+ | DM | Other | App30 |
| My Care Plan (cancer survivor) | NearSpace Inc | 4 | 4 | 1000+ | DM | General | App31 |
aS: support.
bDM: disease management.
cDTI: disease and treatment information.
Privacy scores.
| App name | Label | Data controller’s location | Last update | GDPRa aware | Score |
| BECCA: Breast Cancer Support | App1 | UKb | 03/2019 | No | 76.9 |
| EmotionSpace cáncer de mama | App2 | Germany | 05/2018 | No | 75 |
| ChemoWave: For Cancer Patients | App3 | USc | 10/2018 | No | 53.6 |
| OWise Breast Cancer | App4 | UK | N/Ad | Yes | 31.8 |
| My Cancer Coach | App5 | US | 02/2015 | No | 23.1 |
| Breast Advocate | App6 | Unknown | No privacy policy | N/A | 0 |
| Breast Cancer Support | App7 | US | 09/2019 | Yes | 78.6 |
| KMBCN | App8 | Unknown | No privacy policy | N/A | 0 |
| Triple Negative Breast Cancer | App9 | US | 02/2019 | No | 34.6 |
| Breast Cancer: Others Like Me | App10 | Unknown | No privacy policy | N/A | 0 |
| Outcomes4Me | App11 | Unknown | 11/2018 | No | 34.6 |
| Boobytrapp: The Breast Cancer App | App12 | Singapore | 06/2018 | No | 29.2 |
| The BAPS App Wales | App13 | UK | N/A | Yes | 69.2 |
| BELONG Beating Cancer Together | App14 | Israel | 09/2018 | Yes | 75 |
| Diana | App15 | Spain | 10/2018 | No | 40.9 |
| Got Boobs? | App16 | US | 10/2018 | No | 26.9 |
| inKind Space | App17 | US | N/A | No | 25 |
| Cancer Surveillance | App18 | Unknown | N/A | No | 15 |
| Focalyx | App19 | Unknown | No privacy policy | N/A | 0 |
| Adrenal Cancer: Others Like Me | App20 | Unknown | No privacy policy | N/A | 0 |
| How Are You Today? PC | App21 | Unknown | No privacy policy | N/A | 0 |
| Cancer.Net Mobile | App22 | US | 07/2019 | Yes | 50 |
| TNM Cancer Staging | App23 | Unknown | No privacy policy | N/A | 0 |
| Untire: Beating Cancer Fatigue | App24 | Netherlands | N/A | Yes | 66.7 |
| Self-Care During Cancer | App25 | US | 03/2014 | No | 29.2 |
| CanDi: Cancer Diet App | App26 | Unknown | No privacy policy | N/A | 0 |
| CancerAid | App27 | Australia | N/A | No | 42.9 |
| GRYT Health Cancer Community | App28 | US | 12/2018 | No | 46.2 |
| Target Ovarian Cancer Symptoms Diary | App29 | UK | 04/2018 | Yes | 80.8 |
| Pancreatic Cancer Action: Symptom Tracker | App30 | UK | 06/2018 | Yes | 75 |
| My Care Plan (cancer survivor) | App31 | Unknown | No privacy policy | N/A | 0 |
aGDPR: General Data Protection Regulation.
bUK: United Kingdom.
cUS: United States.
dN/A: not applicable.
Figure 2Analysis of privacy policy presence.
Figure 3Privacy score summary (part1).
Figure 4Privacy score summary (part2).
Assessment of privacy policies by app popularity.
| App label | Stars | Ratings | Downloads | Privacy score |
| App14 | 4.7 | 1151 | 100,000+ | 75 |
| App26 | 4.7 | 60 | 500+ | 0 |
| App23 | 4.6 | 323 | 10,000+ | 0 |
| App5 | 4.5 | 86 | 10,000+ | 23.1 |
| App1 | 4.5 | 63 | 10,000+ | 76.9 |
| App24 | 4.5 | 60 | 5000+ | 66.7 |
| App3 | 4.4 | 20 | 1000+ | 53.6 |
| App4 | 4.4 | 10 | 1000+ | 31.8 |
| App22 | 4.2 | 227 | 10,000+ | 50 |
| App7 | 4.1 | 47 | 1000+ | 78.6 |
| App27 | 3.7 | 25 | 1000+ | 42.9 |
| App18 | 3.7 | 21 | 1000+ | 15 |
Summary of compliance with General Data Protection Regulation items.
| Item number | Full information | Partial information | No information | Not applicable |
| 1 | 17 | 3 | 2 | 0 |
| 2 | 0 | 0 | 13 | 9 |
| 3 | 6 | 0 | 16 | 0 |
| 4 | 20 | 2 | 0 | 0 |
| 5 | 15 | 0 | 7 | 0 |
| 6 | 3 | 0 | 6 | 13 |
| 7 | 21 | 0 | 1 | 0 |
| 8 | 8 | 7 | 6 | 13 |
| 9 | 8 | 5 | 9 | 0 |
| 10 | 10 | 2 | 10 | 0 |
| 11 | 6 | 0 | 8 | 8 |
| 12 | 5 | 3 | 14 | 0 |
| 13 | 6 | 0 | 16 | 0 |
| 14 | 2 | 2 | 18 | 0 |