Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Other deployment scenarios and stigmatization concerns #12

Closed
pdehaye opened this issue Apr 4, 2020 · 2 comments
Closed

Other deployment scenarios and stigmatization concerns #12

pdehaye opened this issue Apr 4, 2020 · 2 comments
Labels
privacy risk Questions or comments regarding privacy issues and concerns

Comments

@pdehaye
Copy link

pdehaye commented Apr 4, 2020

In the threat model, the Tech-Savvy user is described as "Blackhat/Whitehat hackers, NGOs, Academic researchers, etc". It might be worth adding explicitly three roles there: journalist, public health authority and epidemiologist.

Indeed it might also be useful for epidemiological research or public understanding to deploy sensors in one location in order to count the number of infections signaled to public authorities transiting through that location, without the need to obtain consent from the individuals (see Art 9.2.i). This might be particularly useful when done along a highway or on a train, for instance.

Note that this deployment scenario introduces new concerns around stigmatization ("this neighborhood is full of infected cases"), but I am not sure how the GDPR appreciation of this would work, as it would amount to an individual encouragement to install an app that would potentially lead to collective effects.

@lbarman lbarman added the privacy risk Questions or comments regarding privacy issues and concerns label Apr 6, 2020
@kennypaterson
Copy link
Collaborator

The tech-savvy user classification is meant to capture actors who set out to gain more information from the system than would otherwise be available to users via the app. We don't consider the 3 roles you mention as falling under that classification, except possibly "journalist" under some circumstances. So we don't plan to expand our text here.

The deployment of sensors for "mass harvesting" of ephemeral IDs is part of our threat model, not our operational model. Epidemiology research needs to be supported by other means, e.g. via information about infected individuals that becomes available to the health authority as a natural part of its use of the system.

@pdehaye
Copy link
Author

pdehaye commented Apr 9, 2020

This paper is making assertions about data protection issues as well as privacy.

Please re-open and re-classify as a legal issue. The stigmatization concerns brings in new obligations to explain under GDPR (among others).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
privacy risk Questions or comments regarding privacy issues and concerns
Projects
None yet
Development

No branches or pull requests

3 participants