13: How are Non-Drivers Affected?
If the IRIS application is deployed in public service vehicles (like taxis or buses), are there distinct ethical and legal issues that arise - given that there is a possibility that some passengers (non-drivers of the company) may be detected/captured by the IRIS application for some period of time without providing explicit consent to the legal agreements?
37 Answers
-
Full anonymization removes GDPR obligations but may limit model improvement. Pseudonymization is usually sufficient if combined with strong access controls and a right-to-erasure mechanism, allowing users to delete their data. Retaining identifiable data after profile deletion would raise legal risks.
Full anonymization → safest, fewer legal limits • Pseudonymization → allowed if “right to be forgotten” and strong securi
Should be deleted once 5 years has passed
Only data necessary for fatigue detection should be collected and stored for limited periods. Users must understand why their data is processed. Regular checks ensure the data is not reused beyond its purpose.
Pseudo-anonymization with deletion on request is generally sufficient under GDPR, but full anonymization reduces legal risk; retaining data after deletion could still have legal implications.
The data must be saved up to 10 years according to the EU AI charter for various reasons including the database
If you fully anonymize data, it is no longer considered "personal data," and GDPR no longer applies. You could legally retain this data for 5 years (or indefinitely) even after a profile is deleted.
From both a legal and ethical standpoint, full anonymization is preferable but not always technically feasible for biometric datasets. Full anonymization removes all identifiable links to individuals and places data outside GDPR’s scope. This allows longer retention (e.g. 5 years) but is extremely difficult to achieve with facial or physiological data without destroying its utility. Pseudonymization retains identifiers separately and allows compliance with GDPR rights, including the right to erasure (“right to be forgotten”). In practice, pseudonymization combined with strict access controls, encryption, and deletion mechanisms is generally considered sufficient and more realistic, provided users can request deletion and data is not retained longer than necessary. Ethically, respecting user control and deletion rights is critical to maintaining trust, even if anonymization would offer fewer legal constraints.
Full anonymisation is not strictly required though it provides protection
It is not required but it provides protection
Shii idk
Pseudo-anonymization with a functional “right to be forgotten” is generally sufficient if personal identifiers can be deleted on request. Full anonymization is stricter, allows longer retention without legal risk, but may limit personalized model improvements. Key: Must prevent re-identification and comply with GDPR retention limits.
I believe full anonymisation would allow use without legal implication, provided thr users agreed to the data collection.
Let full anonymization be required
I suppose psuedo-anonymisation can be used.
Yes. Having the system automatically detect who the person is means, the passengers may have to upload their data without wanting to, this will go against some legal agreements. The passengers needs to have a choice of whether they want their system to be used on public transport as well as in their own vehicle.
Consent is clearly an issue here, also accuracy and reliability of data collection regarding identity if each individual esp on what could be crowded public services. Legitimacy of use on limited public services i.e., buses when there may not be the option of use another service without this technology.
Even with explicit consent practices, it could reduce public trust, making people less comfortable travelling in such vehicles.
Yes, public vehicles raise extra consent and bystander-privacy issues because passengers may be captured incidentally. Clear notices, limited retention, and opt-out pathways would be important.
In buses and taxis, passengers may not have a practical way to meaningfully consent, so this needs extra legal scrutiny. Notices alone may not be enough if capture is unavoidable.
Public-vehicle use is especially sensitive because bystanders may be recorded incidentally and may not know monitoring is occurring. That means public transport use needs stronger safeguards than private driving.
Public-service vehicles need extra safeguards because monitoring can affect non-users who never opted in. The use case should be limited and clearly communicated.
It raises a bystander issue that is hard to solve with consent alone. The operator should use strong notices and minimize incidental collection.
If passengers can be captured without knowing it, public-transport deployment becomes more ethically fraught. That means public transport use needs stronger safeguards than private driving.
If passengers can be captured without knowing it, public-transport deployment becomes more ethically fraught. That means public transport use needs stronger safeguards than private driving.
Passenger privacy matters because incidental capture can happen even when passengers never agreed to monitoring. That means public transport use needs stronger safeguards than private driving.
Public-service deployment creates a bystander issue that is hard to solve with consent alone. The operator should use strong notices and minimize incidental collection.
In shared vehicles, the rights of non-consenting passengers should be treated carefully because they may be recorded incidentally. Special notice and policy controls are needed.
yes
Penalties could escalate and the company would be liable.
There is a worry someone might have abort implied consent based on making users aware of the possibility. Some worry that it gives users no choice around consent, just choice in relation to use (can they really choose not to use the taxi or bus?)
I think it is very important the data stored is only for the driver and not the passengers in the public service vehicles. Full transparency is necessary to ensure anyone entering the vehicle is aware of the emerging system and that their images may be detected but will not be stored.
Privacy <- more serious in public vehicles (not only driver) taking away users right to agree/disagree (if applied in all)
Yes (if the user image is processed); otherwise, no.
Your Answer
Login to add your answer!
We’d love to hear your thoughts — share a meaningful answer by logging in.