Skip to content
This repository was archived by the owner on Sep 4, 2023. It is now read-only.
This repository was archived by the owner on Sep 4, 2023. It is now read-only.

Suggested new risk for DPIA: tracking by bluetooth #60

@floort

Description

@floort

Unauthorized tracking due to enabled bluetooth

  • Fase: app usage
  • Category: Enviroment
  • Incident: Because Bluetooth has to be enabled to use the notification app, it is possible to track users of the app through traditional bluetooth tracking techniques. The most common advise to prevent this unlawful tracking is to disable bluetooth (and WiFi) is not possible to follow in public spaces while also using the notification app.
  • Impact: High. There is evidense tracking data in this context have been used by police to look for suspects of crimes. It's also hard or impossble for data subjects to exersise ther rights when being tracked in public.
  • Probability: Medium. While this tracking is unlawful, there is significant evidence companies and gouvernment have been using bluetooth tracking in public.
  • Risk: High-Medium
  • Measures:
    • Some or most modern smartphones have MAC adres randomisation features to make tracking via this method more difficult. This measure isn't available on all phones and all contexts.
  • Impact after measures: Medium. Most users of the app are probably safe from tracking, however not all of them will be.
  • Risk after measures: Medium-Medium

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions