Repository logo
 

COVID-19 Contact Tracing Apps: A Stress Test for Privacy, the GDPR and Data Protection Regimes

Published version
Peer-reviewed

Change log

Authors

Bradford, Laura 
Aboy, Mateo 
Liddell, Kathleen 

Abstract

Digital surveillance has played a key role in containing the COVID-19 outbreak in China, Singapore, Israel and South Korea. Google and Apple recently announced the intention to build interfaces to allow Bluetooth contact tracking using Android and iPhone devices. In this article we look at the compatibility of the proposed Apple/Google Bluetooth exposure notification system with Western privacy and data protection regimes and principles, including the General Data Protection Regulation (GDPR). Somewhat counter-intuitively, the GDPR’s expansive scope is not a hindrance, but rather an advantage in conditions of uncertainty such as a pandemic. Its principle-based approach offers a functional blueprint for system design that is compatible with fundamental rights. By contrast, narrower, sector-specific rules such as the US Health Insurance Portability and Accountability Act (HIPAA), and even the new California Consumer Privacy Act (CCPA), leave gaps that may prove difficult to bridge in the middle of an emergency.

Description

Keywords

CCPA, COVID-19, GDPR, HIPAA, OECD privacy principles, privacy and data protection, tracking app

Journal Title

Journal of Law and the Biosciences

Conference Name

Journal ISSN

2053-9711
2053-9711

Volume Title

Publisher

Oxford University Press (OUP)
Sponsorship
Wellcome Trust (105602/Z/14/Z)
Novo Nordisk Foundation (via University of Copenhagen) (NNF17SA0027784)