12: Full or Pseudo Anonymisation
The IRIS application requires saving driver images and heart-rate signals to create an unbiased dataset and improve personalized drowsiness detection. From a legal and ethical standpoint, would full anonymization of the data (leading to retention for up to 5 years, even after profile deletion) or pseudo-anonymization (allowing for a user-requested "right to be forgotten" delete functionality) would allow to use them without any legal implications?
37 Answers
-
Yes, additional issues arise. Incidental data capture of passengers without consent creates risks of unlawful processing, lack of transparency, and proportionality violations. Ethically and legally, IRIS must implement data exclusion mechanisms, signage, and privacy-by-design measures to avoid capturing non-drivers.
Passenger privacy risk → consent issues • Minimize data collection → only drivers • Notifications/visibility required
Yes
Full anonymization offers stronger privacy protection but may limit personalization. Personalization can be acceptable if combined with strict security and deletion rights. The priority is reducing identifiability while preserving fairness.
Yes, capturing passengers’ biometric or health data without consent raises GDPR violations, ethical consent issues, and legal liability for the operator.
This falls under GDPR Article 9 as health data. It is ethically "intimate" because it can reveal non-target conditions like heart disease, stress, or pregnancy. Legally, the risk is that IRIS could be reclassified as a Medical Device if its primary function is monitoring physiological health.
Yes because it is more likely that there are people who use public services that don't consent to the processing of data
Deploying IRIS in taxis, buses, or other public service vehicles introduces distinct ethical and legal challenges. Passengers who are incidentally captured by cameras may have no contractual relationship with the system provider and may not have provided informed consent. Ethically, this creates an imbalance of power and undermines autonomy. Legally, it risks unlawful processing of personal data, as passengers may be recorded without a valid lawful basis. To mitigate this, IRIS would need: Strict camera positioning and masking to avoid capturing passengers. Real-time blurring or exclusion mechanisms. Clear signage and transparency notices. Failure to implement such measures could result in GDPR violations and reputational damage, even if the system’s primary purpose is driver safety.
Yes. Deploying IRIs raises ethical and legal issues regarding passenger privacy and lack on consent
Yes it is illegal
Yes there are
Consent challenges Privacy intrusion Ethical duty
Deploying the IRIS application in public service vehicles does raise distinct ethical and legal issues, primarily concerning data privacy and consen
Yes
Yes, a lot of issues will arise.
I think a full annoymisation of the data should be used because a big risk with using pseudo-anonymisation is re-identification. The data would then still be classed as personal data.
Declared full anonymisation. This may also increase rates of consent.
Given the nature of the project, full anonymisation could make the data significantly less useful to the project. Provided that robust safeguards are implemented, I believe pseudo-anonymisation to be appropriate.
Pseudo-anonymisation is helpful, but full anonymisation should be preferred wherever possible because re-identification risk remains. If exact re-linking is needed for safety testing, access should be tightly restricted.
It sounds ideal, but if that prevents meaningful model improvement, strong pseudonymisation with strict controls can be acceptable. The key issue is preventing re-identification and secondary use.
IT can support development, but full anonymisation is better when the project is only about aggregate improvement. Any exception should be justified and documented.
I would favor pseudonymisation only if there is a strong, documented reason not to fully anonymise. Otherwise, the safest approach is to remove identity links entirely.
Full anonymisation is preferable unless it destroys the value of the dataset.
Full anonymisation is safer; pseudonymisation may be acceptable if the research purpose truly requires linkage and the safeguards are strong. The limitation should be explicit.
Pseudonymisation can support controlled testing, but it is not a full substitute for anonymisation where identity is not needed. Re-identification risk should remain a key concern.
Full anon is the better ethical target, but if a pseudonymous dataset is needed for longitudinal testing, access controls must be strict. The trade-off should be documented.
Pseudonymisation can support development, but full anonymisation is better.
Full anonymisation is safest, but pseudonymisation may be acceptable if the research purpose truly requires linkage and the safeguards are strong. The limitation should be explicit.
I think pseudo-anonymization is efficient.
• Full optimization. • If not deployed ethically.
Generally, pseudo-anonymization should be sufficient, but that depends on data security and the degree to which someone could reconstruct the information from the data.
I believe a pseudo-anonymous identity would be sufficient and that there is not a reason for full anonymization.
I need much more information to answer this. As it stands, I wouldn't agree to any saving particularly of images.
This depends on whether there is explicit consent or not. Generally pseudo-anonymisation is a safe approach but may distort the original data.
Your Answer
Login to add your answer!
We’d love to hear your thoughts — share a meaningful answer by logging in.