COVID-19 contact tracing apps: a stress test for privacy, the GDPR, and data protection regimes

COVID-19 contact tracing apps: a stress test for privacy, the GDPR, and data protection regimes
复制标题

DOI:
10.1093/jlb/lsaa034
复制
发表时间:
2020-01-01
影响因子:
3.4
通讯作者:
Liddell, Kathleen
Liddell, Kathleen
中科院分区:
医学3区
文献类型:
--
作者:
Bradford, Laura;Aboy, Mateo;Liddell, Kathleen

文献摘要

被引文献

相似文献

数字监控在遏制中国、新加坡、以色列和韩国的COVID-19疫情方面发挥了关键作用。谷歌和苹果最近宣布打算建立接口,允许使用Android和iPhone设备进行蓝牙联系人跟踪。在本文中,我们将研究拟议的Apple/Google蓝牙暴露通知系统与西方隐私和数据保护制度和原则的兼容性,包括通用数据保护条例(GDPR)。与直觉相反的是,GDPR的广泛范围并不是障碍,而是在大流行等不确定条件下的优势。其基于原则的方法为符合基本权利的制度设计提供了一个功能蓝图。相比之下,美国《健康保险流通与责任法案》(Health Insurance Portability and Accountability Act,简称HIPAA),甚至是新的《加州消费者隐私法》(Consumer Privacy Act,简称CCPA)等针对具体行业的较窄规则,在紧急情况下可能难以弥补。
Digital surveillance has played a key role in containing the COVID-19 outbreak in China, Singapore, Israel, and South Korea. Google and Apple recently announced the intention to build interfaces to allow Bluetooth contact tracking using Android and iPhone devices. In this article, we look at the compatibility of the proposed Apple/Google Bluetooth exposure notification system with Western privacy and data protection regimes and principles, including the General Data Protection Regulation (GDPR). Some what counter-intuitively, the GDPR's expansive scope is not a hindrance, but rather an advantage in conditions of uncertainty such as a pandemic. Its principle-based approach offers a functional blueprint for system design that is compatible with fundamental rights. By contrast, narrower, sector-specific rules such as the US Health Insurance Portability and Accountability Act (HIPAA), and even the new California Consumer Privacy Act (CCPA), leave gaps that may prove difficult to bridge in the middle of an emergency.