ALFIE ETD-HUB

12: Full or Pseudo Anonymisation

Asked: 6 months, 1 week ago By: Catalink Views: 141 Catalink Case Study: IRIS

The IRIS application requires saving driver images and heart-rate signals to create an unbiased dataset and improve personalized drowsiness detection. From a legal and ethical standpoint, would full anonymization of the data (leading to retention for up to 5 years, even after profile deletion) or pseudo-anonymization (allowing for a user-requested "right to be forgotten" delete functionality) would allow to use them without any legal implications?

37 Answers

Answered: 4 months, 3 weeks ago By: Chiamakaokorie
-
Answered: 4 months, 3 weeks ago By: Tundefasina
Yes, additional issues arise. Incidental data capture of passengers without consent creates risks of unlawful processing, lack of transparency, and proportionality violations. Ethically and legally, IRIS must implement data exclusion mechanisms, signage, and privacy-by-design measures to avoid capturing non-drivers.
Answered: 4 months, 3 weeks ago By: Zainabodogwu2
Passenger privacy risk → consent issues • Minimize data collection → only drivers • Notifications/visibility required
Answered: 4 months, 3 weeks ago By: Oliverharrow
Yes
Deleuze replied: If the data is truly anonymised, then GDPR no longer applies to that anonymised dataset, because the information no longer relates to an identified or identifiable person. GDPR Recital 26 says data protection rules do not apply to anonymous information where the individual is not, or is no longer, identifiable. However, true anonymisation is a high bar, especially for driver images and heart-rate signals. Facial images are inherently identifying unless transformed so that the person cannot reasonably be recognised or re-identified. Heart-rate signals may also be linkable to a person when combined with timestamps, vehicle ID, trip records, device IDs, demographic attributes, or other sensor data. The EDPB states that anonymised data must be rendered anonymous so the individual is not identifiable by any means reasonably likely to be used. There is also a practical conflict: if IRIS needs the data for personalised drowsiness detection, the system usually needs some continuing link to the driver. Once data is fully anonymised, it cannot support driver-specific personalisation, account-level correction, or a meaningful “delete my data” request, because the controller no longer knows which records belong to that driver. So full anonymisation may be suitable for long-term aggregate model improvement, but not for personalised modelling.
Answered: 4 months, 3 weeks ago By: Ngozioshoba
Full anonymization offers stronger privacy protection but may limit personalization. Personalization can be acceptable if combined with strict security and deletion rights. The priority is reducing identifiability while preserving fairness.
Answered: 4 months, 3 weeks ago By: Efeadelaja
Yes, capturing passengers’ biometric or health data without consent raises GDPR violations, ethical consent issues, and legal liability for the operator.
Deleuze replied: Pseudonymisation is probably the better approach for personalised drowsiness detection, because it allows the system to retain a protected link between the model data and the driver while still enabling the driver to request deletion. GDPR Article 17 gives individuals the right to erasure where, for example, the data is no longer necessary for the purpose, consent is withdrawn where consent is the lawful basis, or the data has been unlawfully processed. However, the right to erasure is not absolute, so IRIS would need a documented process for deciding when deletion must be honoured and when a lawful retention exception applies. Under the EU AI Act, if IRIS is a high-risk AI system, Article 10 is especially relevant. It permits processing special-category personal data for bias monitoring, detection, and correction only to the extent strictly necessary and subject to safeguards. That means IRIS cannot simply retain sensitive driver data because it is useful. It must show why sensitive data is needed for fairness and safety, why anonymised or synthetic data would not be sufficient, and what safeguards prevent misuse.
Answered: 4 months, 3 weeks ago By: Kelechinwosu
This falls under GDPR Article 9 as health data. It is ethically "intimate" because it can reveal non-target conditions like heart disease, stress, or pregnancy. Legally, the risk is that IRIS could be reclassified as a Medical Device if its primary function is monitoring physiological health.
Answered: 4 months, 3 weeks ago By: Beatricelorne
Yes because it is more likely that there are people who use public services that don't consent to the processing of data
Answered: 4 months, 3 weeks ago By: Zainabodogwu32
Deploying IRIS in taxis, buses, or other public service vehicles introduces distinct ethical and legal challenges. Passengers who are incidentally captured by cameras may have no contractual relationship with the system provider and may not have provided informed consent. Ethically, this creates an imbalance of power and undermines autonomy. Legally, it risks unlawful processing of personal data, as passengers may be recorded without a valid lawful basis. To mitigate this, IRIS would need: Strict camera positioning and masking to avoid capturing passengers. Real-time blurring or exclusion mechanisms. Clear signage and transparency notices. Failure to implement such measures could result in GDPR violations and reputational damage, even if the system’s primary purpose is driver safety.
Answered: 4 months, 3 weeks ago By: Miles_Hatcher
Yes. Deploying IRIs raises ethical and legal issues regarding passenger privacy and lack on consent
Answered: 4 months, 3 weeks ago By: Aminaolorun
Yes it is illegal
Answered: 4 months, 3 weeks ago By: Clarawhitby
Yes there are
Answered: 4 months, 3 weeks ago By: Ifeanyiakare
Consent challenges Privacy intrusion Ethical duty
Answered: 4 months, 3 weeks ago By: Kunleekwueme
Deploying the IRIS application in public service vehicles does raise distinct ethical and legal issues, primarily concerning data privacy and consen
Answered: 4 months, 3 weeks ago By: Sadeogunlana
Yes
Answered: 4 months, 3 weeks ago By: Tomashbrook
Yes, a lot of issues will arise.
Answered: 1 month ago By: Brightfox_45
I think a full annoymisation of the data should be used because a big risk with using pseudo-anonymisation is re-identification. The data would then still be classed as personal data.
Answered: 1 month ago By: Cleverwolf_27
Declared full anonymisation. This may also increase rates of consent.
Answered: 1 month ago By: Brightrobin_21
Given the nature of the project, full anonymisation could make the data significantly less useful to the project. Provided that robust safeguards are implemented, I believe pseudo-anonymisation to be appropriate.
Answered: 1 month ago By: Warmlynx_14
Pseudo-anonymisation is helpful, but full anonymisation should be preferred wherever possible because re-identification risk remains. If exact re-linking is needed for safety testing, access should be tightly restricted.
Answered: 1 month ago By: Swiftowl_37
It sounds ideal, but if that prevents meaningful model improvement, strong pseudonymisation with strict controls can be acceptable. The key issue is preventing re-identification and secondary use.
Answered: 1 month ago By: Cleverrobin_87
IT can support development, but full anonymisation is better when the project is only about aggregate improvement. Any exception should be justified and documented.
Answered: 1 month ago By: Swiftrobin_35
I would favor pseudonymisation only if there is a strong, documented reason not to fully anonymise. Otherwise, the safest approach is to remove identity links entirely.
Answered: 1 month ago By: Boldlynx_38
Full anonymisation is preferable unless it destroys the value of the dataset.
Answered: 1 month ago By: Quietbadger_45
Full anonymisation is safer; pseudonymisation may be acceptable if the research purpose truly requires linkage and the safeguards are strong. The limitation should be explicit.
Answered: 1 month ago By: Swiftdeer_99
Pseudonymisation can support controlled testing, but it is not a full substitute for anonymisation where identity is not needed. Re-identification risk should remain a key concern.
Answered: 1 month ago By: Bravebear_45
Full anon is the better ethical target, but if a pseudonymous dataset is needed for longitudinal testing, access controls must be strict. The trade-off should be documented.
Answered: 1 month ago By: Calmwolf_53
Pseudonymisation can support development, but full anonymisation is better.
Answered: 1 month ago By: Brightowl_58
Full anonymisation is safest, but pseudonymisation may be acceptable if the research purpose truly requires linkage and the safeguards are strong. The limitation should be explicit.
Answered: 1 month ago By: Brightbear_54
I think pseudo-anonymization is efficient.
Answered: 1 month ago By: Warmhawk_15
• Full optimization. • If not deployed ethically.
Answered: 1 month ago By: Quietrobin_25
Generally, pseudo-anonymization should be sufficient, but that depends on data security and the degree to which someone could reconstruct the information from the data.
Answered: 1 month ago By: Braveowl_80
I believe a pseudo-anonymous identity would be sufficient and that there is not a reason for full anonymization.
Answered: 1 month ago By: Kindbadger_56
I need much more information to answer this. As it stands, I wouldn't agree to any saving particularly of images.
Answered: 1 month ago By: Warmwolf_18
This depends on whether there is explicit consent or not. Generally pseudo-anonymisation is a safe approach but may distort the original data.

Your Answer

Login to add your answer!

We’d love to hear your thoughts — share a meaningful answer by logging in.