I'm unsure what they mean by "storage of data on the [...] device" because you can't use an App without having first installed it (which uses your device's storage already), so doesn't the app have reasonable implicit permission to make use of the user's storage?
...while the part about an app being able to "access" stored data is ambiguous: does that include the app reading its own resource/assets data from its installed app-package/directory? Or if it's referring to apps reading from the user's own (i.e. private) data like Contacts database, photos, GPS sensors, etc - then as far as I'm concerned that's not a legal or policy question, but a clear and gaping security hole in the OS because the app was somehow able to break out of the sandbox to read into other data-stores on the user's device.