Yesterday, I had a business lunch. The restaurant asked me to input my data on SocialPass, an app now mandatory in Canton Vaud for restaurants gastrovaud.ch/coordonnees-de…
I get the need for tracking, not the creation of abusive surveillance infrastrutures ignoring data protection👇 Image
The app is extremely invasive. The designers have not heard of Data Minimization. It is unclear why my address, my name, or *my date of birth!* is at all necessary for a tracer to call me (yes, all fields mandatory and phone number checked via SMSa) Image
The privacy policy does not specify the purpose of the collection of these data (also not heard about purpose limitation)
socialpass.ch/protectiondesd…
I have to give it to them that they say they won't use or sell the data... Why even collect it then??????
The data is encrypted. This is good. But where is the key? Who has access under which conditions?
Also.. what data? What is the visitor/visit relation if the visitor data resides on the phone? Image
They declare only Cantonal doctors can access data (not clear which data) but not under which conditions. Double authorization, cool. Who authorizes what? Is there any oversight or participation from the establishments? Can lists be decrypted without their involvement? Who can? Image
At the end of the day, encrypted or not, this is a very juicy centralized database of, let's not forget, data that is not necessary for tracing Image
And you may be thinking... why did you not ask for pen&paper...? We did ask. The waitress said no, it is not allowed! #StarveOrSurveillance is the new normal Image
And isn't this discrimination? Well, if you have no phone then you can use paper... so actually the new-normal hashtag is #IfWeCanSurveillYouWeWill
(so ironically, discriminates against those with phones by requiring from them different more invasive information) Image
Incidentally, we just proposed a system that shows that none of this abusive collection and excessive power for the data holder is necessary to enable this tracing github.com/CrowdNotifier/…
If tracing must happen, let's make it such that it doesn't erode our fundamental rights

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Carmela Troncoso

Carmela Troncoso Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @carmelatroncoso

3 Apr
As countries deploy data-hungry contact tracing, we worry about what will happen with this data. Together with colleagues from 7 institutions, we designed a system that hides all personal information from the server. Please read and give comments!
More info in our repo: github.com/DP-3T/
3-page brief: github.com/DP-3T/document…
White paper: github.com/DP-3T/document…
Data Protection: github.com/DP-3T/document…
Read 9 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!