# SP-003 Privacy Mobile Device Pattern

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for protecting personally identifiable information (PII) on mobile devices, addressing data minimisation, encryption at rest, secure transmission, consent management, and regulatory compliance for mobile processing of personal data.
Use when: Apply this pattern when the organisation processes personally identifiable information on mobile devices and is subject to data protection regulations such as GDPR, CCPA/CPRA, HIPAA, LGPD, POPIA, or sector-specific privacy requirements. This includes organisations in regulated industries (financial services, healthcare, legal, insurance) that handle client or patient PII on mobile devices, any organisation subject...
Not when: This pattern is not necessary if the organisation does not process any PII or confidential personal information on mobile devices and has technical controls in place to prevent PII from reaching mobile endpoints.

## Threats and the controls that mitigate them (10)
- T-PM-001 Unauthorised Disclosure of PII Through Device Loss or Theft: 
- T-PM-002 Excessive Personal Data Collection by Mobile Applications: 
- T-PM-003 Personal Data Interception in Transit on Untrusted Networks: 
- T-PM-004 Regulatory Non-Compliance for Mobile Processing of Personal Data: 
- T-PM-005 Failure to Honour Data Subject Rights for Mobile-Held Data: 
- T-PM-006 Employee Privacy Violation Through Excessive MDM Monitoring: 
- T-PM-007 Personal Data Residue After Incomplete Device Wiping: 
- T-PM-008 Cross-Border Data Transfer Violation via Mobile Device Travel: 
- T-PM-009 Third-Party SDK Data Collection Without Adequate Consent: 
- T-PM-010 Personal Data Exfiltration via Unmanaged Mobile Applications: 

## More
- Every control and what it mitigates, as JSON: /api/v1/patterns/SP-003/crosswalk
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-003/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 17 KB: /api/v1/patterns/SP-003
- Page for people: /patterns/sp-003/
- Related: SP-001 Client Module; SP-006 Wireless Private Network Pattern; SP-007 Wireless Public Hotspot Pattern; SP-013 Data Security Pattern; SP-015 Secure Remote Working; SP-024 iPhone Pattern

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
