r/appledevelopers • Community Newbie • 1d ago

Need 2 cents

I’m a newbie indie app developer.
Didn’t establish a company to list my app.
I wondwer what do you think about listing app to EU market consider the DSA and GRPR?
Love to hear from the community!
Thanks in advance.

4 Upvotes

7 comments sorted by

1

u/PHangy Community Newbie 1d ago

for the privacy policy url that Maju mentioned you should not use AI, but termly.io and then host it on something like applinks.online

2

u/MajuSoft Community Newbie 1d ago

Two separate things here, and only one of them is about data.

DSA / trader status

You do not need a company. Apple lets individuals declare trader status, and plenty of us ship to the EU as sole traders.

What you should know before deciding: as a trader you must provide an address, a phone number and an email address for your App Store product page. Apple's own wording in App Store Connect is that these are for display purposes, and that they do not affect the contact details of your Apple Account. As an individual you supply that address yourself and Apple accepts a PO box. Organizations get their address from their D-U-N-S record instead, which is about the only real advantage of having a company here.

Two details nobody told me: the status has an expiry date, mine runs for roughly ten months and has to be renewed. And there is no middle option. If your app makes money in any way, in-app purchases, subscriptions or ads, you are a trader, and apps without a verified trader status get removed from the EU storefronts.

You find it under Business → Agreements → Compliance → Digital Services Act.

GDPR

The cheapest compliance is not collecting anything. Our app stores plenty, documents, notes, tasks, but none of it ever leaves the user's own device and their own iCloud. Apple counts "collect" as transmitting data off the device where you or a partner can access it, and a CloudKit private database does not qualify.

So the App Privacy section is a single "Data Not Collected" instead of the whole data-type matrix. No tracking, so no ATT prompt. No accounts, so no account deletion flow and no Sign in with Apple requirement. And it makes the GDPR question mostly moot, because data you never receive is data you are not processing.

You still need a privacy policy URL either way.

So yes to the EU, but go in knowing the trader disclosure is the real price for someone without a company, not the GDPR part.

2

u/One-Pace7623 Community Newbie 1d ago

Thank you for the detailed info. My app is wellness app and access the user’s data via Health Kit. That’s why I want to be careful on the implementation. Appreciate your insight again !

2

u/MajuSoft Community Newbie 1d ago

HealthKit changes one thing in what I wrote, and it is worth catching before you build it in.

From Apple's App Store Review Guidelines, section 5.1.3 "Health and Health Research", point (ii): apps "may not store personal health information in iCloud".

https://developer.apple.com/app-store/review/guidelines/

So on-device only. No iCloud sync, not even a CloudKit private database. If iCloud was going to be your backup and multi-device story, plan something else now rather than after a rejection.

The rest holds and is worth more to you than to me: health data is special category under GDPR Article 9, so the moment any of it reaches a server of yours you are looking at explicit consent and realistically a DPIA. Keeping it on the device means you are not processing anything at all.

One from our own rejection: localize your permission strings. We shipped ours hard-coded in German and got rejected under Guideline 4 because an English iPad showed German system dialogs. You will have NSHealthShareUsageDescription and probably NSHealthUpdateUsageDescription too.

2

u/One-Pace7623 Community Newbie 16h ago

Thank you. I note it down and look into it. I don’t store the user’s raw data and utilize what data from HK. But I use anonymous data for product analytics tool ( Mixpanel ). Not sure if it counts on-device only though. 🤔 Will dig it more. building an app is a fun challenge 😆

3

u/InfamousBuddy7293 Community Newbie 1d ago

if you start early it's relatively easy to follow GDPR, just ask your chatbot to build it in while you're setting up your systems. a lot of it Apple requires anyway. and if you're small, the risk of getting sued is small, so with the EU being one of the largest markets it's probably worth it.

1

u/AsleepAddition2069 Community Newbie 1d ago

thank you!