Replies: 2 comments 3 replies
-
As far as I know, it is a legal requirement that the bar/restaurant/... owner hand out the visitors list to public health agencies on demand. Adding a step to ask the visitor for their consent thus would make it impossible for the bar/restaurant owner to act in compliance to the previously mentioned legal requirement. It would first require a change of this law. |
Beta Was this translation helpful? Give feedback.
-
Hi, we are very aware of this issue and we strive to protect our users from illegitimate access to their data. Regarding your specific questions, we have to distinguish two kinds of data access:
In this case the owner of the Venue is contacted and asked to grant access to the Contact Data of potentially affected Guests. The data that becomes accessible to the health authorities in this case contains (besides the Contact Data itself) only the information that this person visited the given Venue at the given time. The history of other "Check-Ins" done by the same person (their Check-In History) is not revealed to anyone in this process. Regarding this type of data access, we will soon release an update to Luca where users will be informed when their Contact Data is accessed. See also this discussion.
In this case the Health Department contacts the user directly and asks them to share their Check-In History. This process is described here. Without the explicit consent of the user, it is not possible for health authorities to reconstruct this history. Note that the private keys required to decrypt the contact data always remain with Venue Owners and Health Departments. We as the Luca operator do not have access to it. Please also have a look at the security objectives in our document. Specifically, O4 and O6 are relevant here. |
Beta Was this translation helpful? Give feedback.
-
Hi,
incidents in the past COVID-19 influenced year have shown that agencies, police authorities and other state actors are heavily trying to misuse the collected data, original meant to protect of and track infections.
Cases of officers raiding bars and restaurants to get hands on the "who was eating here tonight" lists were present all over the world, especially in Germany. Politicians close to ministry of home affairs have not let out any chance, to call the contact tracing being "hindered" by to much privacy.
To install an application like the luca app on my phone without being scared of someone accessing my data without my consent, it would be necessary to provide an architectural scheme, which will prohibit anyone to access my "data trace" without my consent or knowledge. This would include hashed data, which is not anonym and still lets me being tracable.
Furthermore access of my personal tracing data must be impossible to access without my knowledge, even for the luca app operator itself. And yes, I also mean pseudonymized and anonymized data by that. Only such countermeasures would ensure, that no "non disclosure subpoena" is forced on the luca app operator to hand out my data without my knowledge - to anyone.
How exactly do the creators and the operators of the application counteract such concerns - which you must agree are some realistic scenario, as proven in the past year.
Thank you
Beta Was this translation helpful? Give feedback.
All reactions