Journal of Information Security Reserach ›› 2021, Vol. 7 ›› Issue (9): 810-814.

Previous Articles     Next Articles

Privacy Considerations of European Contact Tracing Technology (DP3T)

  

  • Online:2021-09-13 Published:2021-09-13

欧洲的接触者追踪技术(DP3T)之隐私考量

孙雨潇1  张清芳2  符婷3  李艳丽4   

  1. 1(中国农业科学院  北京  100081)
    2(伦敦大学学院法学院  伦敦 )
    3(哈萨克斯坦国立大学国际关系学院  阿拉木图)
    4(中国农业科学院  北京  100081)

  • 通讯作者: 孙雨潇
  • 作者简介:孙雨潇 硕士,研究实习员.主要研究方向为信息安全与隐私保护. sunyuxiao@caas.cn 张清芳 硕士研究生.主要研究方向为数据合规和隐私保护. jennifer0law@gmail.com 符婷 博士研究生.主要研究方向为国际环境法、国际经济法等. 331690195@qq.com 李艳丽 硕士,研究员.主要研究方向为信息化管理与数据共享等. liyanli@caas.cn

Abstract: COVID-19 broke out at the end of 2019 has not been eradicated until today, and people around the world are still being affected. One of the measures to prevent the spread of the pandemic is to identify people who have been in contact closely with persons infected by coronavirus, trace contacts map and issue effective, accurate notifications to the public who are in close contact with infected person. In response to this demand, the government or companies continue to develop some contact tracing apps to help track contacts to conduct real-time analysis of coronavirus. However, there is increasing concern about the impact of this technology on privacy since public or private organizations will share a large amount of personal data. To reconcile this issue, Decentralized Privacy-Preserving Proximity Tracing (DP3T) was pushed to the front and received public scrutiny. Based on the technical and legal background in Europe, we first analyzes DP3T briefly then introduces its application to GDPR, and finally concludes that such technology should fall within the scope of GDPR and future focus may be aware of the platform issues.

Key words: contact tracing, distributed technology, decentralized storage, privacy protection, European data protection law

摘要: 2019年底爆发的新冠肺炎疫情危机至今尚未解除,欧洲、美洲等地受到波及的疫情影响还在延续.有效预防新冠疫情大范围蔓延的措施之一是识别出与新冠肺炎疫情感染者密切接触的人,追踪其路径并向公众发布并发出警示有效通知.为响应此需求缓解疫情,全球范围内相关组织积极研发和实施有效追踪技术,将其用于疫情传播分析.但此类追踪技术涉及到相关信息的大量共享,人们愈发担心其有效性及其对隐私的干涉.为调和二者的冲突,基于分布式存储技术的接触者追踪(DP3T)进入公众视野并接受检视.本文立足于欧洲技术及法律背景,首先分析DP3T对个人数据的收集情况,然后介绍其与GDPR的适用问题,最终认定此类技术应当落入GDPR相关数据保护法的治理范围内并在未来需要警惕平台导致的隐私问题.

关键词: 接触者追踪, 分布式技术, 去中心化存储, 隐私保护, 欧洲数据保护法