D 2.1 Privacy, Data Protection and Ethical Issues in New and Emerging
Total Page:16
File Type:pdf, Size:1020Kb
Project acronym: PRESCIENT Project title: Privacy and emerging fields of science and technology: Towards a common framework for privacy and ethical assessment Project number: 244779 Programme: Seventh Framework Programme for research and technological devel- opment Objective: SiS-2009-1.1.2.1: Privacy and emerging fields of science and technol- ogy: ethical, social and legal aspects. Contract type: Collaborative project Start date of project: 1 January 2010 Duration: 36 months Deliverable 2: Privacy, data protection and ethical issues in new and emerging technologies: Five case studies Editors: Rachel Finn and David Wright, Trilateral Research & Consulting Authors: Rachel Finn, Michael Friedewald, Raphael Gellert, Serge Gutwirth, B¨arbel H¨using, Piret Kukk, Emilio Mordini, Philip Sch¨utz, Silvia Venier, David Wright Dissemination level: Public Deliverable type: Report Version: 1.0 Due date: 30 September 2011 Submission date: 25 November 2011 Terms of use This document was developed within the PRESCIENT project (see http://www.prescient-project. eu), co-funded by the European Commission within the Seventh Framework Programme (FP7), by a consortium, consisting of the following partners: Fraunhofer Institute for Systems and Innovation Research (co-ordinator), • Trilateral Research Consulting LLP, • Centre for Science, Society and Citizenship, and • Vrije Universiteit Brussel • This document is intended to be an open specification and as such, its contents may be freely used, copied, and distributed provided that the document itself is not modified or shortened, that full authorship credit is given, and that these terms of use are not removed but in- cluded with every copy. The PRESCIENT partners shall take no liability for the complete- ness, correctness or fitness for use. This document is subject to updates, revisions, and ex- tensions by the PRESCIENT consortium. Address questions and comments to: coordinator@ prescient-project.eu Table of Contents ! Chapter 1, Introduction: Privacy, data protection and ethical issues in new and emerging technologies ............................................................................................. 5! 1.1! Introduction ....................................................................................................................... 6! 1.2! Methodology ..................................................................................................................... 6! 1.3! Outline of the Report......................................................................................................... 6! Chapter 2, RFID-enabled contactless cards for public transport: security, privacy, ethics and legislation......................................................................................................... 10! 2.1! Introduction ..................................................................................................................... 11! 2.2! Current status of RFID-enabled travel cards and expected progress in the near future.. 11! 2.3! Stakeholders (industry, etc.) and drivers driving the development of RFID-enabled travel cards .......................................................................................................... 14! 2.3.1! Beneficiaries of RFID travel cards .............................................................................. 16! 2.4! Privacy impacts and ethical issues raised by RFID-enabled travel cards ....................... 16! 2.5! Extent to which the existing legal framework addresses the privacy impacts ................ 21! 2.6! Need for new legislation, codes of conduct, etc. to deal with privacy impacts not covered by the existing framework and how to deal with ethical issues ............ 25! 2.7! Conclusion....................................................................................................................... 27! 2.8! References ....................................................................................................................... 28! Chapter 3, Privacy, data protection and policy issues in RFID enabled e-Passports...... 31! 3.1! Introduction ..................................................................................................................... 32! 3.2! RFID – State of the Art ................................................................................................... 32! 3.2.1! RFID tags ..................................................................................................................... 32! 3.2.2! RFID readers................................................................................................................ 33! 3.2.3! RFID backend systems and middleware ...................................................................... 34! 3.2.4! RFID functionalities..................................................................................................... 34! 3.2.5! The e-passport.............................................................................................................. 35! 3.3! Stakeholders and drivers behind the development of the technology............................. 38! 3.3.1! Governments................................................................................................................. 38! 3.3.2! International Organisations......................................................................................... 38! 3.3.3! Industry Players ........................................................................................................... 39! 3.3.4! Non-Governmental Organisations ............................................................................... 39! 3.3.5! End users...................................................................................................................... 40! 3.4! Privacy and security issues.............................................................................................. 41! 3.4.1! Shortcomings in the security of the passport ............................................................... 41! 3.4.2! Security threats/data processing operations that threaten the privacy........................ 43! 3.4.3! Privacy violations......................................................................................................... 45! 3.4.4! Privacy and securities issues with the e-passport: some additional thoughts ............. 46! 3.5! Extent to which the existing legal framework addresses the privacy impacts ................ 47! 3.5.1! Applicability of the e-directive ..................................................................................... 48! 3.5.2! The Data Protection Directive ..................................................................................... 49! 3.6! Need for new legislation, codes of conduct, etc.............................................................. 52! 3.7! Privacy legislation and RFID, what conclusions?........................................................... 55! 3.8! References ....................................................................................................................... 57! 1 Chapter 4, Privacy, Data Protection and Ethical Concerns in relation to New Technologies of Surveillance: ............................................................................... 60! 4.1! Introduction ..................................................................................................................... 61! 4.2! Methodology ................................................................................................................... 61! 4.3! Body scanners, security and privacy ............................................................................... 61! 4.3.1! Introduction.................................................................................................................. 61! 4.3.2! Current status of the technology and expected progress in the near future ................ 62! 4.3.3! Stakeholders and drivers driving the development of the technology.......................... 67! 4.3.4! Privacy impacts and ethical issues raised by the technology ...................................... 70! 4.3.5! Extent to which the existing legal framework addresses the privacy impacts ............. 73! 4.3.6! Need for new legislation, codes of conduct etc. to deal with privacy impacts not covered by the existing framework and how to deal with ethical issues ................. 78! 4.3.7! Discussion .................................................................................................................... 83! 4.4! Unmanned aircraft systems, surveillance, safety and privacy ........................................ 83! 4.4.1! Introduction.................................................................................................................. 83! 4.4.2! Current status of the technology and expected progress in the near future ................ 85! 4.4.3! Stakeholders and drivers driving the development of the technology.......................... 92! 4.4.4! Privacy impacts and ethical issues raised by the technology ...................................... 95! 4.4.5! Extent to which the existing legal framework addresses the privacy impacts ............. 98! 4.4.6! Need for new legislation, codes of conduct etc. to deal with privacy impacts not covered by the existing framework ........................................................................ 101! 4.4.7! Discussion .................................................................................................................