
In a new section titled “3.3.3 (J), Accessory Notifications Framework and Accessory Live Activities Framework,” Apple says that third parties “may not use Forwarding Information for advertising, profiling, training models, or monitoring location.” It also states that they “may not disseminate the Forwarding Information to any other Application, or any other device besides Your Authorized Target Accessory.”
The new section goes on to state that developers can’t store forwarded notification data on servers, in the cloud, or on any remote device, and the data can only be decrypted on the accessory itself, not on a server or anywhere else along the way.
Besides formatting adjustments, the forwarded information can’t be altered in any way that changes its meaning, while the accessory that receives the notification can’t share that data or its encryption keys with any other device, including the user’s own iPhone. In other words, the data must be locked to the device it was sent to.
Even if a developer’s app doesn’t use these frameworks at all, Apple says it reserves the right to forward that app’s notifications to a third-party accessory if the user enables it.
Last September, Apple complained that its obligations under the EU’s Digital Markets Act (DMA) would cause feature rollout delays in the bloc, but it also warned of new privacy and security threats. Apple based these threats on companies’ submitted requests, which included the complete content of a user’s notifications, as well as the full history of Wi-Fi networks a user has joined.
Apple said it had explained the risks of such requests to the European Commission, but the concerns had not been accepted as valid reasons to turn them down. The new developer rules appear to be Apple’s best effort to mitigate the risks regardless.
Taken together, they make it clear that Apple wants no tracking, no profiling, no cloud copies, and no sharing between devices, with developers bearing full responsibility for their app’s compliance with the new rules.
This article, “Apple Sets Privacy Rules for Third-Party Access to Live Activities and Notifications” first appeared on MacRumors.com
Discuss this article in our forums