App Procurement & Development Policy and Guidance
This guidance will help you understand your needs along with the University of Glasgow’s goals, values, and legal obligations when developing or procuring a new application for download on smartphones. This documentation has been created by the Digital Experience team in consultation with the University of Glasgow Legal Department.
Apps included in a service procurement or developed by a third party, rather than procured individually, are still subject to the University of Glasgow’s Mobile App Endorsement Policy. It is essential that App Owners understand these requirements to ensure compliance and protect university interests. While this document focuses on apps hosted on the University’s App and Google Play Stores, much of the guidance is applicable. Advice should be sought from the Procurement Team before engaging a third party to develop, license, or otherwise utilise an app—wherever it may ultimately be hosted.
Apps built by students and incorporated by staff members into curriculum or for other uses must also adhere to the Mobile App Endorsement Policy.
Business cases that include a Mobile App offering should approach the Enterprise Design Authority (EDA) for advice and approval. That approval will include a comprehensive review of Mobile App Endorsement Policy requirements below.
Definitions
- Mobile App: A software application designed to run on mobile devices such as smartphones or tablets that requires a download by the end user.
- Mobile App Owner: The individual, department, or entity responsible for the overall management, governance, and strategic direction of a Mobile App throughout its lifecycle.
- Mobile App Developer: A professional or organisation engaged in the creation, design, coding, and implementation of Mobile Apps for specific platforms or operating systems.
- Mobile App Service Provider: The party accountable for overseeing the day-to-day operation, maintenance, and support of the services and infrastructure that facilitate the functioning of a Mobile Application.
- End User: The final consumer or user of a Mobile App, who interacts with and utilises its features, functionalities, and content for various purposes or tasks.
Mobile App Endorsement Policy
The following are the minimum set of criteria that a new Mobile App must meet to be endorsed by the University of Glasgow:
- All Mobile Apps must meet WCAG 2.2 AA accessibility standard with a published accessibility statement online. Mobile Apps serving EU-based users must additionally meet European Accessibility Act (2025) standards.
- All Mobile App Owners must use the Data Protection Impact Assessment Tool, completing a Data Protection Impact Assessment (DPIA) to protect the rights of end users and their personal data if required by the DP & FOI Office.
- All Mobile Apps must publish an End User License Agreement (EULA) or link to a broader Terms & Conditions provided by the University of Glasgow.
- All Mobile Apps must publish a Privacy Notice or link to a broader Privacy Notice provided by the University of Glasgow.
- The Freedom of Information (Scotland) Act 2002 provides a general right of access to information held by the University. All Mobile Apps must have the ability and a procedure to respond accurately and in a timely manner to requests filtered through the Data Protection & Freedom of Information Office.
- All Mobile Apps that process payments must have completed the necessary Payment Card Industry Data Security Standard (PCI-DSS) compliance.
- All Mobile Apps—particularly those that do not duplicate a service offering with alternative availability—must complete an Equality Impact Assessment (EIA).
- All Mobile Apps must adhere to the university Information Security Guidelines.
- All images, fonts and any other third-party intellectual property must be appropriately licenced and is the responsibility of the Mobile App Owner.
- A University of Glasgow branded Mobile App must meet brand standards and/or adhere to the Design System.
- Mobile Apps must meet a minimum release schedule of one software update per academic year.
All Mobile Apps will be required to maintain these policy standards. If a Mobile App falls below these standards due to, for example, accessibility, security, or data protection concerns, then the Mobile App will be removed by the university.
All apps intended for release in the name of, or associated with, the University must be assessed by Legal before release to appropriately manage our limited or unlimited liability risk. Contact the Legal Team (Legal@glasgow.ac.uk) for further information. Some Mobile Apps may require further escalation to the Senior Management Group where the legal review identifies unusual or significant risk. The Legal Team will advise whether further escalation and approval is required.
Mobile App Development Guidance
It is critical to carefully consider whether a Mobile App is the correct means of achieving your goal. Mobile apps do not benefit from search engine optimisation or the authority of the University of Glasgow website. They require a download, which can cause technical limitations for students based on device type, operating system, and data usage. Apps often require more technical knowledge for maintenance and are more difficult to ensure content is accessible and translatable.
When first considering a Mobile App as a solution or promotional tool, ask yourself:
- Who are the primary end users of this Mobile App? Will they be motivated to download it? What problem does this solve for them?
- What is the maximum addressable audience of this app? Is the investment worth the reach that this Mobile App might provide?
- Will end users return repeatedly to the Mobile App? Successful Mobile Apps have a hook that keep users returning. If it is a one-time use for end users, then an interactive website may be more appropriate.
- How will you promote this app? Awareness campaigns to end users can be expensive and time-consuming to run.
- Is an app the best medium for this information? If the primary function of the app is to display content (e.g. text, images, video, etc.) without interactivity, then a website is a more appropriate platform.
Once you have established that a Mobile App is the right course of action, you will need to confirm how you will build, maintain, and operate the Mobile App though its entire life cycle. Questions to consider:
- Who is the University-employed Mobile App Owner? If that person were to leave the University or be unable to fulfil their role, who would take Ownership?
- Is the Mobile App Owner the same person as the Mobile App Service Provider? Making strategic decisions about the use, costs and future of the app can be a different role to the administration and running of day-to-day services through the Mobile App. Ensuring service provision is resourced is key to delivering a successful Mobile App.
- What is the relationship with the Mobile App Developer? Are they likely to be around to support the Mobile App after launch? Will they commit to maintain and launch the minimum required one software update per academic year?
- If the app integrates with other University systems, what happens to your service when those systems are down for maintenance or deprecated? Apps are accessible and usable 24/7 by the End User. Ensuring contingency plans, including user communication, are in place for integrated services helps ensure a reliable service for end users.
- What metrics will you track to ensure the app is successful? Number of downloads is not a good indicator of success—a Mobile App should be measured by continued use of the services that it provides. Returning users, features used, and time engaged should all be considered alongside the Mobile App Service Provider’s benefits and key metrics for their service. Goals should be specific, measurable, achievable, relevant, and time bound (e.g., increase the number of students accessing a mobile app feature by 20% within the next 6 months).
- How long will the app be maintained? If there is a specific endpoint to support or the services the app provides, how will it be deprecated? How will existing end users be informed and accommodated when the service is discontinued? Apps cannot be maintained forever, and projects often have defined budgets and end dates.
Building a Mobile App is a complex and potentially resource-intensive activity—both in the initial development and launch phase, but also in the day-to-day running and operating phase of its lifecycle. Ensuring that you have considered all the above and adhere to all policy requirements is essential to the success of a Mobile App.
If you need help working through this policy or have questions, please reach out to the Digital Experience team at digital-experience@glasgow.ac.uk, who can work with you to direct you further.
Last updated 12/08/2026