ALFIE ETD-HUB

12: Full or Pseudo Anonymisation

Asked: 7 months, 4 weeks ago By: Catalink Views: 207 Catalink Case Study: IRIS

The IRIS application requires saving driver images and heart-rate signals to create an unbiased dataset and improve personalized drowsiness detection. From a legal and ethical standpoint, would full anonymization of the data (leading to retention for up to 5 years, even after profile deletion) or pseudo-anonymization (allowing for a user-requested "right to be forgotten" delete functionality) would allow to use them without any legal implications?

37 Answers

Answered: 6 months ago By: Chiamakaokorie

-

Answered: 6 months ago By: Tundefasina

Yes, additional issues arise. Incidental data capture of passengers without consent creates risks of unlawful processing, lack of transparency, and proportionality violations. Ethically and legally, IRIS must implement data exclusion mechanisms, signage, and privacy-by-design measures to avoid capturing non-drivers.

Answered: 6 months ago By: Zainabodogwu2

Passenger privacy risk → consent issues • Minimize data collection → only drivers • Notifications/visibility required

Answered: 6 months ago By: Oliverharrow

Yes

Deleuze replied: If the data is truly anonymised, then GDPR no longer applies to that anonymised dataset, because the information no longer relates to an identified or identifiable person. GDPR Recital 26 says data protection rules do not apply to anonymous information where the individual is not, or is no longer, identifiable. However, true anonymisation is a high bar, especially for driver images and heart-rate signals. Facial images are inherently identifying unless transformed so that the person cannot reasonably be recognised or re-identified. Heart-rate signals may also be linkable to a person when combined with timestamps, vehicle ID, trip records, device IDs, demographic attributes, or other sensor data. The EDPB states that anonymised data must be rendered anonymous so the individual is not identifiable by any means reasonably likely to be used. There is also a practical conflict: if IRIS needs the data for personalised drowsiness detection, the system usually needs some continuing link to the driver. Once data is fully anonymised, it cannot support driver-specific personalisation, account-level correction, or a meaningful “delete my data” request, because the controller no longer knows which records belong to that driver. So full anonymisation may be suitable for long-term aggregate model improvement, but not for personalised modelling.
Answered: 6 months ago By: Ngozioshoba

Full anonymization offers stronger privacy protection but may limit personalization. Personalization can be acceptable if combined with strict security and deletion rights. The priority is reducing identifiability while preserving fairness.

Answered: 6 months ago By: Efeadelaja

Yes, capturing passengers’ biometric or health data without consent raises GDPR violations, ethical consent issues, and legal liability for the operator.

Deleuze replied: Pseudonymisation is probably the better approach for personalised drowsiness detection, because it allows the system to retain a protected link between the model data and the driver while still enabling the driver to request deletion. GDPR Article 17 gives individuals the right to erasure where, for example, the data is no longer necessary for the purpose, consent is withdrawn where consent is the lawful basis, or the data has been unlawfully processed. However, the right to erasure is not absolute, so IRIS would need a documented process for deciding when deletion must be honoured and when a lawful retention exception applies. Under the EU AI Act, if IRIS is a high-risk AI system, Article 10 is especially relevant. It permits processing special-category personal data for bias monitoring, detection, and correction only to the extent strictly necessary and subject to safeguards. That means IRIS cannot simply retain sensitive driver data because it is useful. It must show why sensitive data is needed for fairness and safety, why anonymised or synthetic data would not be sufficient, and what safeguards prevent misuse.
Answered: 6 months ago By: Kelechinwosu

This falls under GDPR Article 9 as health data. It is ethically "intimate" because it can reveal non-target conditions like heart disease, stress, or pregnancy. Legally, the risk is that IRIS could be reclassified as a Medical Device if its primary function is monitoring physiological health.

Answered: 6 months ago By: Beatricelorne

Yes because it is more likely that there are people who use public services that don't consent to the processing of data

Answered: 6 months ago By: Zainabodogwu32

Deploying IRIS in taxis, buses, or other public service vehicles introduces distinct ethical and legal challenges. Passengers who are incidentally captured by cameras may have no contractual relationship with the system provider and may not have provided informed consent. Ethically, this creates an imbalance of power and undermines autonomy. Legally, it risks unlawful processing of personal data, as passengers may be recorded without a valid lawful basis. To mitigate this, IRIS would need: Strict camera positioning and masking to avoid capturing passengers. Real-time blurring or exclusion mechanisms. Clear signage and transparency notices. Failure to implement such measures could result in GDPR violations and reputational damage, even if the system’s primary purpose is driver safety.

Answered: 6 months ago By: Miles_Hatcher

Yes. Deploying IRIs raises ethical and legal issues regarding passenger privacy and lack on consent

Answered: 6 months ago By: Aminaolorun

Yes it is illegal

Answered: 6 months ago By: Clarawhitby

Yes there are

Answered: 6 months ago By: Ifeanyiakare

Consent challenges Privacy intrusion Ethical duty

Answered: 6 months ago By: Kunleekwueme

Deploying the IRIS application in public service vehicles does raise distinct ethical and legal issues, primarily concerning data privacy and consen

Answered: 6 months ago By: Sadeogunlana

Yes

Answered: 6 months ago By: Tomashbrook

Yes, a lot of issues will arise.

Answered: 2 months, 2 weeks ago By: Brightfox_45

I think a full annoymisation of the data should be used because a big risk with using pseudo-anonymisation is re-identification. The data would then still be classed as personal data.

Answered: 2 months, 2 weeks ago By: Cleverwolf_27

Declared full anonymisation. This may also increase rates of consent.

Answered: 2 months, 2 weeks ago By: Brightrobin_21

Given the nature of the project, full anonymisation could make the data significantly less useful to the project. Provided that robust safeguards are implemented, I believe pseudo-anonymisation to be appropriate.

Answered: 2 months, 2 weeks ago By: Warmlynx_14

Pseudo-anonymisation is helpful, but full anonymisation should be preferred wherever possible because re-identification risk remains. If exact re-linking is needed for safety testing, access should be tightly restricted.

Answered: 2 months, 2 weeks ago By: Swiftowl_37

It sounds ideal, but if that prevents meaningful model improvement, strong pseudonymisation with strict controls can be acceptable. The key issue is preventing re-identification and secondary use.

Answered: 2 months, 2 weeks ago By: Cleverrobin_87

IT can support development, but full anonymisation is better when the project is only about aggregate improvement. Any exception should be justified and documented.

Answered: 2 months, 2 weeks ago By: Swiftrobin_35

I would favor pseudonymisation only if there is a strong, documented reason not to fully anonymise. Otherwise, the safest approach is to remove identity links entirely.

Answered: 2 months, 2 weeks ago By: Boldlynx_38

Full anonymisation is preferable unless it destroys the value of the dataset.

Answered: 2 months, 2 weeks ago By: Quietbadger_45

Full anonymisation is safer; pseudonymisation may be acceptable if the research purpose truly requires linkage and the safeguards are strong. The limitation should be explicit.

Answered: 2 months, 2 weeks ago By: Swiftdeer_99

Pseudonymisation can support controlled testing, but it is not a full substitute for anonymisation where identity is not needed. Re-identification risk should remain a key concern.

Answered: 2 months, 2 weeks ago By: Bravebear_45

Full anon is the better ethical target, but if a pseudonymous dataset is needed for longitudinal testing, access controls must be strict. The trade-off should be documented.

Answered: 2 months, 2 weeks ago By: Calmwolf_53

Pseudonymisation can support development, but full anonymisation is better.

Answered: 2 months, 2 weeks ago By: Brightowl_58

Full anonymisation is safest, but pseudonymisation may be acceptable if the research purpose truly requires linkage and the safeguards are strong. The limitation should be explicit.

Answered: 2 months, 2 weeks ago By: Brightbear_54

I think pseudo-anonymization is efficient.

Answered: 2 months, 2 weeks ago By: Warmhawk_15

• Full optimization. • If not deployed ethically.

Answered: 2 months, 2 weeks ago By: Quietrobin_25

Generally, pseudo-anonymization should be sufficient, but that depends on data security and the degree to which someone could reconstruct the information from the data.

Answered: 2 months, 2 weeks ago By: Braveowl_80

I believe a pseudo-anonymous identity would be sufficient and that there is not a reason for full anonymization.

Answered: 2 months, 2 weeks ago By: Kindbadger_56

I need much more information to answer this. As it stands, I wouldn't agree to any saving particularly of images.

Answered: 2 months, 2 weeks ago By: Warmwolf_18

This depends on whether there is explicit consent or not. Generally pseudo-anonymisation is a safe approach but may distort the original data.

Your Answer

Login to add your answer!

We’d love to hear your thoughts — share a meaningful answer by logging in.