According to researchers from Oxford University's Big Data Institute, at least 60% of the population in a country would need to download such apps in order to achieve the so-called "digital herd immunity" and put an end to the spread of COVID-19. However, concerns over privacy and security implications of such contact tracing apps are widespread globally, with significant attitudes of mistrust over the intrusion and misuse of 'Big Data' prevalent in western democracies. These concerns have perhaps been stoked by the well-publicised state surveillance measures that have been taken in Asia when rolling out such apps, many of which have been condemned as intrusive, with particular disquiet around China's 'Health Code'.
Clearly, this crisis has unveiled new thoughts on how far public interest grounds can be stretched by governments and their sponsored apps to process health data at scale when the processing of such data is key to saving lives.
China's Health Code App
The health code service made available to citizens of the PRC requires registration on one of the ubiquitous platforms developed by Alipay or WeChat for the Chinese government. For registration purposes, basic information is required at first then further queries on health status and travel history are more invasive of privacy, as users are then asked to identify any close contacts diagnosed with the virus. The app provides users with colour-coded designations precisely based on their health status and travel history, and a QR code that can be scanned by authorities.
Although, the apps work differently by city and province, a person identified under a green code would generally be allowed to travel freely around China. A yellow code would require self-isolation while a red code would alert the user of being a confirmed Covid-19 patient subject to quarantine.
The coronavirus crisis has brought to light the extent of China's surveillance state powers and its ability to redirect its mass surveillance network to efficiently track people in the fight against the virus. The lack of information provided to citizens on how the apps work and what data is stored reflect the general approach. The data sharing arrangement between the two tech giants and government agencies is no less a concern and no explanation was provided on why the information collected through the apps may be shared with some state services unrelated to the fight against the virus.
Overall, China's successful apps are down the pervasive use of smartphones amongst the population and the unfettered access and data sharing of user's data between the tech giants and the government.
However, there is growing trepidation that these apps may not only trigger serious breaches of privacy and data security but that they may also be setting a troubling blueprint for new forms of automated social control that could persist long after the pandemic eases off.
United States' Contact Tracing Projects
Many State governments, private enterprises, and academics across the US have disclosed plans to develop contact tracing technology to help contain the COVID-19 pandemic. Washington has largely left it to private initiatives and, in particular, academics to lead the charge.
In this respect, academia has kept privacy considerations at the core of their considerations in the development of their contact tracing projects. MIT pioneered with the Safe Paths app. It is a multi-faculty, cross-MIT effort, in collaboration with institutes including Harvard University, Stanford University, and the State University of New York at Buffalo; clinical input from Mayo Clinic and Massachusetts General Hospital; and mentors from the World Health Organization, the U.S. Department of Health and Human Services, and the Graduate Institute of International and Development Studies.
The Safe Paths app (PrivateKit) uses overlapped GPS and Bluetooth trails that allow users to know if they have been in contact with someone diagnosed positive for the virus, by matching location data on users' devices with anonymised location data of infected patients. In this way, the app maintains the privacy of both the user and the diagnosed infected patients. Users remain in control of their data stored in their devices. Data sharing between Covid-19 patients and health authorities is on an opt-in basis.
Another initiative led by the Stanford University and the University of Waterloo has devised a contact tracing app called Covid Watch based exclusively on Bluetooth signals.
Unlike the European Union which has adopted the GDPR, the United States are still discussing a potential new federal privacy law which would have impacted the development of contact tracing technology. However, the apps still need to comply with a number of strict privacy and security requirements both at the federal and state level.
In particular, at the federal level, privacy and security rules applying to the health sector set out under the Health Insurance Portability and Accountability Act (HIPAA) should apply to contact tracing projects if the teams involved in the app developments or management qualify as regulated “covered entities", such as the healthcare providers and other related players. This is not to disregard the importance of significant privacy and security laws implemented by a great number of US states which may equally impact such apps, such as the California Consumer Privacy Act (CCPA) which came into force on the 1st January, 2020. The CCPA grants expansive consumer privacy protections through new data privacy rights.
It is worth noting that a group of four Republican Senators plans to introduce a privacy bill that would regulate the data collected by coronavirus contact tracing apps. The so called COVID-19 Consumer Data Protection Act would “provide all Americans with more transparency, choice, and control over the collection and use of their personal health, geolocation, and proximity data,” according to a joint statement. It is contemplated that state attorneys general will enforce the Act.
“As Congress seeks to enact a uniform comprehensive data privacy and security framework, thoughtful and targeted legislative efforts, like this bill, will address specific consumer privacy violations resulting from COVID-19,” Senator Moran said in a statement.
The bill will require organisations to obtain express consent from individuals if personal data about their health, location or proximity to another person is collected. They will also be required to disclose the uses, retention and deletion period of the data and to implement specific measures to ensure that no re-identification of individuals may be possible on the basis of anonymised data.
THE EU AND THE UK CONTACT TRACING APPS: CENTRALISED VERSUS DECENTRALISED?
In contrast to China's contact tracing model based on the use of location data, the EU and the UK have had to build into its contact tracing technology solutions the concept of privacy by design, and have had to comply with all applicable privacy and data protection laws.
In the EU, most of the Member States favour short-range Bluetooth connections or “handshakes” between mobile devices to register a potential contact, without tracking physical location using GPS and therefore using location data. However, there is widespread disagreement between choosing to log such contact events on the individual devices or on a central server.
Therefore, two distinct and competing models of contact tracing technology are dividing the EU. These are the 'centralised' versus the 'decentralised' approaches.
On one side, a group of countries initially led by Germany champions the Pan-European Privacy-Preserving Proximity Tracing (PEPP-PT https://www.pepp-pt.org) which recommends the 'centralised' approach. Composed of a consortium of over 130 members, including telecommunications operators, health service providers, scientists and other relevant actors and stakeholders, this initiative launched on 31 March 2020in order to develop and offer an EU data privacy and data protection compliant tracing technology that could also be effective in the fight against the spread of COVID-19.The opponents to this approach, backed by Switzerland, Austria and Estonia favour a 'decentralised' contact tracing protocol called DP-3T that would be supported by the technology alliance formed between Apple and Google.
Indeed, in a unique collaboration move, Apple and Google have teamed up to join in the global effort against the pandemic by allowing their mobile operating systems to be used to operate the apps. By using Low Energy Bluetooth (i.e. Bluetooth that is always on), they are able to establish a decentralised contact-tracing framework (CTF), allowing connection to be made between phones which are in close proximity with each other. This is a major contribution as current apps using Bluetooth and smartphones do not allow the wireless protocol to operate constantly. The system will collate data from both Android and iPhone users who sign up to the app and is expected to be made available by mid-May 2020. It is also worth noting that both tech giants have been heavily investing in in the trillion-dollar health care industry in the past year but nothing may give them a bigger headway into the industry than this joint contribution to tracking the spread of coronavirus.
The main differentiator between the above discussed models resides in the storage location of troves of health and location data which comes with significant intrinsic privacy consequences:
- Under the decentralised model, such data would be kept on the users' devices. Users can opt-in to share their phone number or details of their symptoms, which would be used by health authorities to contact them and give advice on the best course of action in the event they are found to be at risk. This consent would be given in the app, instead of being part of the system’s central architecture
- Under the centralised model, all data would be stored in a central server which may potentially open the door to government's mass surveillance in the absence of strong fundamental rights and security safeguards.
Showing the direction most EU countries are likely to take, Germany, where the shadow of historical institutionalised surveillance renders mass tracking very unpopular has now rallied to the decentralised model with an app deemed much less intrusive, relying on the Bluetooth “handshake” between two devices rather than tracking the location of individuals.