Home / Business and Politics / Cannot do without privacy protection! European bodies very clear on contact tracing applications

Cannot do without privacy protection! European bodies very clear on contact tracing applications

aplikacija za praćenje
aplikacija za praćenje / Image by: foto

The European Data Protection Supervisor (EDPS) and the European Union Agency for Fundamental Rights (FRA) have issued a joint statement regarding the increasingly widespread use of contact tracing applications for coronavirus infections. The development of such applications significantly increases the risks associated with privacy violations, and data protection must be a central consideration during their development.

The European bodies EDPS and FRA have renewed their cooperation agreement to further strengthen data protection across the EU to ensure the highest possible level of respect for privacy in the development of tracking applications or any other technology.

FRA Director, Michael O'Flaherty, stated that there is no doubt that technology can play a vital role in people’s lives, whether it is about transitioning to a „new normal“ or in cases concerning public health protection, but on the condition that it is used in accordance with human rights and data protection principles.

The impact on lives due to the outbreak of the pandemic was also emphasized by Wojciech Wiewiórowski, the European Data Protection Supervisor, who asserted that this situation tests the resilience of societies to circumstances caused by a global crisis as they attempt to contain its consequences, and that data protection is not a problem but part of the solution.

At the same time, they emphasized that the FRA bulletin with specific guidelines for the development of tracking applications, which I reported on in mid-April, contained requirements related to privacy protection that must be met during the development itself, such as a clear legal basis, exclusively voluntary use, and the use of data only and exclusively for the purposes for which they were collected. The original signed agreement of these two European bodies can be seen here.

Research conducted by FRA reveals that many Europeans do not want to share their data, neither with public nor private entities. About 41% of them do not want to share any personal data with private companies, while as many as 55% fear crimes related to identity theft and misuse of personal data.

Many European countries have embarked on the development of their own tracking applications, by state and private companies, which have often ended very poorly. Significant public discontent was experienced by the Dutch tracking application from which personal data „leaked a little“ during development, and the last known major „breaches and failures“ did not escape public attention either, including the British application that simply did not work well due to a technological flaw that the authors had been warned about multiple times. Namely – it did not function at all.

In this regard, Croatia has chosen a potentially safer variant that respects all guidelines issued by FRA and comments from EDPS, opting to include Google/Apple technological support, which is the basis of the German application.

Assistant Professor Dr. Tihomir Katulić from the Department of Information Technology Law at the Faculty of Law, University of Zagreb, commented on the joint statement of EDPS and FRA regarding the research results as expected and in line with the growing awareness of citizens about the importance of secure and reliable processing of personal data.

Regarding the chosen model, Katulić welcomes the goodwill that leading big data platforms are now showing in terms of applying the guidelines of European institutions such as the Agency for Fundamental Rights and recommendations from the European Data Protection Supervisor, but at the same time reminds of past experiences with the behavior of American Big Data companies, warning of a recent decision by the French High Administrative Court rejecting Google’s appeal and confirming the fine imposed by the French supervisory authority against Google for violating the provisions of the General Data Protection Regulation regarding informing about the processing of personal data of users of Google’s Android system, as well as other ongoing proceedings against Microsoft, Facebook, and Apple across the European Union, concluding that constant vigilance and dedicated work by supervisory bodies are necessary to prevent similar violations in the future.

Author: Natalija Parlov Una PhD candidate in International Relations and expert in information security and behavioral digital marketing. She is the author of numerous scientific and professional papers in the field of information security, behavioral marketing, market entry, and international relations. She consults foreign and domestic companies and institutions in the fields of process forensics, information security, behavioral marketing analytics, and compliance with European legal regulations. She is an auditor for the largest German certification body TÜV NORD for international standards of Information Security Management System ISO/IEC 27001, Social Security and Business Continuity Management System ISO 22301, Quality Management System ISO 9001, and Anti-Bribery Management System ISO 37001. She is the director of two companies: PARLOV Digital Intelligence for behavioral digital marketing and APICURA Business Intelligence for information security and compliance with European legal regulations. LinkedIn

{embed_digitalno_izdanje}{/embed_digitalno_izdanje}