The amount of data being tracked and shared between tech companies, health organizations, and government bodies in response to COVID-19 presents a litany of privacy concerns over how that data can be exploited.
Testifying in the new “Paper Hearing” format of the US Senate Committee on Commerce, Science, and Transportation on Thursday, representatives from tech and data privacy think tanks told lawmakers they must consider mitigating the many privacy risks of how COVID-19 data is used when drafting data privacy legislation.
As keen observers of recent history, the witnesses presented evidence of how companies have exploited sensitive health data in the past and how lawmakers can better protect individual rights from being exploited by the coronavirus data that is being collected.
The risks include using data to identify, track, and police individuals; the sharing of sensitive health data between companies; and how governments, businesses, and organizations can exploit the data once the pandemic is over.
In her written testimony, Stacey Gray, Senior Counsel, Future of Privacy Forum (FPF), said that the privacy risks to individuals and their communities come in two forms: immediate and secondary.
Immediate risks include “discrimination, endangered physical security, disproportionate loss of privacy, and unjustified limitations on freedom of movement, to long term risks to freedom, civil liberties and even to democracy,” Gray testified.
Big tech companies like Google and governments like the Chinese Communist Party are tracking where citizens are going during the pandemic by analyzing location data from people’s mobile phones.
“The collection and use of data, including personal data, to respond to a public health crisis like a pandemic can be compatible with privacy and data protection principles”
While Google’s Community Mobility Reports say the tracking data is anonymous, the Chinese government is using location data as surveillance tool through a color coded app, “which dictates whether they can leave the house and where they can go,” according to Business Insider.
Since the Chinese Communist Party has time and time again shown to be an authoritarian regime has been that constantly weaponizes data against its citizens, the app can very easily turn into a policing app for law enforcement to arrest those who venture out of their homes.
This leads us to secondary risks, which have to do with what the data will be used for after the health crisis is over.
“For example,” Gray testified, “some apps may require an individual to take multiple pictures of themselves during the day and upload the selfies to a centralized database.
“With the current state of facial recognition technology it is not far-fetched to foresee the use of the database as a training set for machine learning algorithms.”
Feeding algorithms is just one way the data could be exploited after the COVID-19 crisis is over, but there are many other ways.
Gray covered both data privacy risks and recommendations for lawmakers in more detail in her 12-page written testimony and 13-page Q&A followup.
Michelle Richardson, Director of the Data and Privacy Project at the Center for Democracy and Technology, told lawmakers in the Paper Hearing how health data is collected and shared among stakeholders “in ways that would surprise individuals.”
“There is mounting evidence that non-HIPAA-covered entities are regularly collecting, using, and sharing consumer health information in ways that would surprise individuals and arguably exploit their sensitive data,” Richardson testified.
“Successfully fighting the coronavirus will mean ensuring that a government response does not evolve into law enforcement and broad surveillance functions”
She added, “Here are just a few examples where unregulated health data about consumers was collected and shared:”
“The United States does not have a comprehensive privacy law to protect Americans’ personal information,” added Richardson.
“This has led to the explosion of risky and exploitative data-driven behaviors in the vast unregulated space in between.”
Richardson, too, covered both data privacy risks and recommendations for lawmakers more extensively in her 16-page written testimony and 13-page Q&A.
If used ethically, health data collected during COVID-19 can be used for the betterment of society. If used unethically, the data can be abused by governments for law enforcement purposes and be exploited by businesses looking to sell the information to the highest bidder.
“The collection and use of data, including personal data, to respond to a public health crisis like a pandemic can be compatible with privacy and data protection principles,” Gray testified.
“In many cases, commercial data can be shared in a way that does not reveal any information about identified or identifiable individuals,” she added.
Both Gray and Richardson agree that a federal data privacy law is required in order to protect individual rights, especially during a health crisis.
Richardson suggested that lawmakers consider the following when formulating policy on data collection, use, and sharing:
On behalf of the FPF, Gray relayed her organization’s recommendations to lawmakers for consideration when drafting data privacy laws.
“FPF has long supported comprehensive federal privacy legislation and observed that it should be flexible enough to support data-driven public health initiatives under the right safeguards and within limits consistent with privacy and civil liberties.”
Gray recommended:
The COVID-19 pandemic has made big data an invaluable tool in the fight against the virus, with many public and private entities enlisting the technology.
Once the pandemic is over; however, what will become of all that data? Will it be used to prevent further outbreaks, or will it be used as a tool of oppression?
If Gray and Richardson have anything to say about it, legislation must be made to ensure privacy is protected at all costs.
In the late 19th Century, physicians began inserting hollow tubes equipped with small lights into…
This year wasn’t exactly what the video gaming industry expected — it declined by 7%…
By Oren Askarov, Growth & Operations Marketing Director at SQream Becoming “data-driven” has become a…
Horasis Asia Meeting, led by German entrepreneur Frank Jurgen-Richter, will take place this year on the…
Techstars is one of the world's most recognized startup organizations, helping to support countless founders…
Article by Vikram (V) Venugopal, General Manager, VP BioPharma at Prezent, Partner at Prezentium Biotech…
View Comments