Privacy Perspectives | Illusions of Permission and COVID-19-tracking apps Related reading: Protecting privacy on COVID-19 surveillance apps.
COVID-19-tracking apps help identify parties with whom a COVID-19-infected person had contact. The apps do this by drawing on information concerning the positioning of somebody ‘s cell phone and its proximity to other apparatus.
Countries are currently split into those where the government requires the usage of those apps and those that do not. Mandatory contact-tracking apps are in use in China, India and Turkey. The remainder of the world is following the voluntary route. Nations in this camp include Australia, Austria, Finland, Germany, Ireland, Israel, the Netherlands and the United Kingdom.
In the United States, however, the question is not whether the government will require the people to download an app to track their contacts and movement. Nobody is proposing that approach. Rather, the critical issue is how the government and private business will limit access to spaces and opportunities based on whether or none "consents" to using an app or other monitoring device.
By way of example, an employer can block entry to a workplace unless a person has an app on his phone that uses Bluetooth to monitor copies or location a QVC code in a building’s entrance into an app. The future might be one of "no app, no entry" or perhaps "no app, no occupation. "
The future might be one of "no app, no entry" or perhaps "no app, no occupation. "
In these situations, reliance on approval is illusory. Even though the usage of the app remains voluntary, in the feeling of never being government-imposed, its usage is part of a take-it-or-leave-it circumstance.
In most regions of data privacy legislation, we’ve already been down the route of justifying monitoring through the fiction of approval. By way of example, "notice-and-choice" is often utilized to justify email monitoring at work; employers inform employees in advance of their coverage and using a workplace email process is then deemed to represent consent to the coverage. A similar approach is taken by offices that require keycards to enter spaces. In the employee handbook, a business tells folks about the way the keycard collects data. It then spreads the keycards and mandates their use and, presto, consent is granted each time a worker pops the apparatus at an entryway.
Instead of falling back on illusions of approval, the solitude challenges of COVID-19-tracking apps require a federal law. Fortunately, there are now two proposals for such a law before the Senate. Before analyzing the two bills, however, it is sensible to think through original principles.
How should this type of law proceed?
It ought to reflect that public health during a pandemic is a priority. In the end, regulation ought to be careful to using those devices in offices because this context will be particularly prone to illusions of consent for COVID-19 data collection.
In terms of the two competing federal bills, both have pluses and share many regions of agreement.
The good news first about the two bills. Both agree about the need for data minimization, which means set of the smallest amount of information. Further, the proposed statutes mandate data security, which can be important as any data collected with these apps will be a target of interest for hackers, domestic and international.
The bills also exude transparency. They do this by mandating data to the affected party in the stage of collection and from requiring general information. By way of example, the Wicker bill requires "transparency reports to the public under which companies will describe their data collection activities relating to COVID-19. " Along with requiring regulated entities to issue public reports, the Blumenthal-Warner bill requires the secretary of Health and Human Services to consult with the Federal Trade Commission and Commission on Civil Rights in reporting to the "civil rights impact of the collection, use, and disclosure of health information in response to the COVID-19 public health emergency. " These approaches have merit and should be incorporated at a combined invoice.
Finally, both bills contain an exit plan and enforcement mechanisms. Mandated deletion periods guard against the phenomena, according to Northeastern University’s Woodrow Hartzog, of "surveillance inertia. " Regarding enforcement, the Wicker bill would grant the FTC and state attorneys general enforcement power. The Blumenthal-Warner invoice goes farther and provides private rights of actions.
Even with no crystal ball, one can forecast significant controversy about this issue. The need will be to find a sensible compromise that allows the enactment of a COVID-19 privacy legislation.
Now for one big difference: The Wicker invoice contains an exception for the workplace. This exception covers "worker screening data," that covers data relating "to the COVID-19 public health emergency" and for use in determining "if the individual is allowed to go into a physical site of operation of the covered entity. " The general idea behind such exclusion is, in my opinion, sensible. It enables employees to maintain their workplace safe, such as by alerting infected employees from the place of employment.
If there was a workplace exception, however, the law must set strong legal limitations on the range of data collection and the purposeful applications to be made from personal information. And here the Blumenthal-Warner bill excels. It averts "illusions of permission " by calling for the collection, use or disclosure of only such data that’s "necessary, proportionate, and restricted for a good faith public health purpose. " Additionally, it details a long list of prohibited uses of emergency health data, such as for commercial advertising, soliciting or selling solutions in a discriminatory manner, or participating in discrimination at any place of public accommodation.
Additionally, a revised invoice should have additional strong protections to maintain a workplace https://aaaareview.com/reverse-phone-lookup app from being used for tracking beyond the factory or office. COVID-19-tracking apps ought to be restricted to the place of employment and to contacts with other people in the workplace. In addition, the law should require that an employer delete all of gathered data after a set time period, such as three weeks.
As a last note, the usage of COVID-19-tracking apps can only lead to ending the present emergency as part of a larger political response to the pandemic. The overriding needs to begin with a robust system for testing and tracing. There’s also an urgent requirement for the development of quarantine spaces for infected individuals who lack these safe environments. There must also be strong legal protections for people with the virus, including the development of greater unemployment protections without that there will only be disincentives for individuals to seek outside testing.
We are running a marathon and not a rush, and the present crisis requires a pragmatic and proportionate reaction that sets legal limits on data collection and the subsequent use of collected data. COVID-19-tracking apps will be here shortly, they won’t be truly voluntary, and the law ought to carefully regulate their use as part of a larger public health response.