Normative challenges of identification in the Internet of Things: Privacy, profiling, discrimination, and the GDPR

In the Internet of Things (IoT), identification and access control technologies provide essential infrastructure to link data between a user's devices with unique identities, and provide seamless and linked up services. At the same time, profiling methods based on linked records can reveal unex...

Full description

Bibliographic Details
Main Author: Wachter, S
Format: Journal article
Published: Elsevier 2018
_version_ 1797100478254809088
author Wachter, S
author_facet Wachter, S
author_sort Wachter, S
collection OXFORD
description In the Internet of Things (IoT), identification and access control technologies provide essential infrastructure to link data between a user's devices with unique identities, and provide seamless and linked up services. At the same time, profiling methods based on linked records can reveal unexpected details about users' identity and private life, which can conflict with privacy rights and lead to economic, social, and other forms of discriminatory treatment. A balance must be struck between identification and access control required for the IoT to function and user rights to privacy and identity. Striking this balance is not an easy task because of weaknesses in cybersecurity and anonymisation techniques. The EU General Data Protection Regulation (GDPR), set to come into force in May 2018, may provide essential guidance to achieve a fair balance between the interests of IoT providers and users. Through a review of academic and policy literature, this paper maps the inherent tension between privacy and identifiability in the IoT. It focuses on four challenges: (1) profiling, inference, and discrimination; (2) control and context-sensitive sharing of identity; (3) consent and uncertainty; and (4) honesty, trust, and transparency. The paper will then examine the extent to which several standards defined in the GDPR will provide meaningful protection for privacy and control over identity for users of IoT. The paper concludes that in order to minimise the privacy impact of the conflicts between data protection principles and identification in the IoT, GDPR standards urgently require further specification and implementation into the design and deployment of IoT technologies.
first_indexed 2024-03-07T05:38:06Z
format Journal article
id oxford-uuid:e49c4ea8-fe71-48ac-9f85-13c3e0ede718
institution University of Oxford
last_indexed 2024-03-07T05:38:06Z
publishDate 2018
publisher Elsevier
record_format dspace
spelling oxford-uuid:e49c4ea8-fe71-48ac-9f85-13c3e0ede7182022-03-27T10:18:01ZNormative challenges of identification in the Internet of Things: Privacy, profiling, discrimination, and the GDPRJournal articlehttp://purl.org/coar/resource_type/c_dcae04bcuuid:e49c4ea8-fe71-48ac-9f85-13c3e0ede718Symplectic Elements at OxfordElsevier2018Wachter, SIn the Internet of Things (IoT), identification and access control technologies provide essential infrastructure to link data between a user's devices with unique identities, and provide seamless and linked up services. At the same time, profiling methods based on linked records can reveal unexpected details about users' identity and private life, which can conflict with privacy rights and lead to economic, social, and other forms of discriminatory treatment. A balance must be struck between identification and access control required for the IoT to function and user rights to privacy and identity. Striking this balance is not an easy task because of weaknesses in cybersecurity and anonymisation techniques. The EU General Data Protection Regulation (GDPR), set to come into force in May 2018, may provide essential guidance to achieve a fair balance between the interests of IoT providers and users. Through a review of academic and policy literature, this paper maps the inherent tension between privacy and identifiability in the IoT. It focuses on four challenges: (1) profiling, inference, and discrimination; (2) control and context-sensitive sharing of identity; (3) consent and uncertainty; and (4) honesty, trust, and transparency. The paper will then examine the extent to which several standards defined in the GDPR will provide meaningful protection for privacy and control over identity for users of IoT. The paper concludes that in order to minimise the privacy impact of the conflicts between data protection principles and identification in the IoT, GDPR standards urgently require further specification and implementation into the design and deployment of IoT technologies.
spellingShingle Wachter, S
Normative challenges of identification in the Internet of Things: Privacy, profiling, discrimination, and the GDPR
title Normative challenges of identification in the Internet of Things: Privacy, profiling, discrimination, and the GDPR
title_full Normative challenges of identification in the Internet of Things: Privacy, profiling, discrimination, and the GDPR
title_fullStr Normative challenges of identification in the Internet of Things: Privacy, profiling, discrimination, and the GDPR
title_full_unstemmed Normative challenges of identification in the Internet of Things: Privacy, profiling, discrimination, and the GDPR
title_short Normative challenges of identification in the Internet of Things: Privacy, profiling, discrimination, and the GDPR
title_sort normative challenges of identification in the internet of things privacy profiling discrimination and the gdpr
work_keys_str_mv AT wachters normativechallengesofidentificationintheinternetofthingsprivacyprofilingdiscriminationandthegdpr