The earlier version (20080522) had guidance on how and when disclosures should be provided, in "4.3.3 Provide Disclosures that are Timely and Accessible":


4.3.3 Provide Disclosures that are Timely and Accessible What it means

Disclosures about application behavior are useful (i.e. result in user awareness of the implications of using an application) only if they are provided at a useful time and in useful ways. How to do it

Disclosures should be provided during application selection/loading or first use of sensitive functions.

Disclosures should be automatically provided e.g. as a user dialog, or easily accessible to the user e.g. via an "about this application" menu option.


This guidance is important since developers need to know that they have options as to how/when to provide the disclosures. The nature of the application and the types of information/behaviors it uses will affect how/when disclosures are provided. For example, applications that do not use any API's that will result in real-time prompts should inform the user when the application starts or on first use of the sensitive function. Prompt on application startup is also useful if prompts during execution would interfere with operation of the application, or be not possible (e.g. the application doesn't provide a UI during operation).

We can add text on the API-provided prompts to this section as well, as one type of "timely" disclosure, to increase the value of the section (if that was the concern prompting its removal).

Best regards,

Bryan Sullivan | AT&T