California v. Delta Air Lines: Why a Website Privacy Policy May Not Cover a Mobile App
California’s lawsuit against Delta Airlines shows why mobile apps need privacy policies that clearly address their data practices—and how federal preemption can limit state enforcement even when an app allegedly fails to comply with CalOPPA.
Key point: If an organization does not have a privacy policy that specifically addresses its mobile app’s information practices, it may be prohibited from collecting or using personal data through the app under California law.
In 2012, the California Attorney General (CA AG) sued Delta Air Lines for allegedly violating the California Online Privacy Protection Act (CalOPPA) because its mobile app did not have an adequately disclosed privacy policy.
The CA AG alleged that Delta could not lawfully collect and use personal data through its mobile app without providing consumers with a clear and accessible policy explaining its data practices.
According to the CA AG, Delta’s general online privacy policy did not satisfy CalOPPA because it did “not mention the Fly Delta application, [was] not reasonably accessible to the consumers of the Fly Delta application,” and failed to “disclose anywhere several types of [personally identifiable information] that the Fly Delta application collects but the Delta website does not collect.”
The CA AG’s complaint sought to prohibit Delta from continuing to distribute its mobile app until it complied with CalOPPA. It also sought civil penalties of up to $2,500 for each violation, which the CA AG argued could include each download of the Fly Delta app.
The action was ultimately dismissed on federal preemption grounds. The court concluded that the federal Airline Deregulation Act preempted the state-law claims against Delta because they related to the services provided by a commercial airline.
Although the action was dismissed, it helped draw attention to the application of privacy-notice requirements to mobile apps. It also encouraged organizations to adopt app-specific privacy policies or revise their general online privacy policies to expressly address their mobile applications and the data collected through them.
Resources
People of the State of California v. Delta Air Lines, Inc.—Complaint, No. CGC-12-526741 (Cal. Super. Ct., San Francisco Cnty., filed Dec. 6, 2012).
