ALFIE ETD-HUB

13: How are Non-Drivers Affected?

Asked: 6 months, 1 week ago By: Catalink Views: 175 Catalink Case Study: IRIS

If the IRIS application is deployed in public service vehicles (like taxis or buses), are there distinct ethical and legal issues that arise - given that there is a possibility that some passengers (non-drivers of the company) may be detected/captured by the IRIS application for some period of time without providing explicit consent to the legal agreements?

37 Answers

Answered: 4 months, 3 weeks ago By: Chiamakaokorie
-
Answered: 4 months, 3 weeks ago By: Tundefasina
Full anonymization removes GDPR obligations but may limit model improvement. Pseudonymization is usually sufficient if combined with strong access controls and a right-to-erasure mechanism, allowing users to delete their data. Retaining identifiable data after profile deletion would raise legal risks.
Answered: 4 months, 3 weeks ago By: Zainabodogwu2
Full anonymization → safest, fewer legal limits • Pseudonymization → allowed if “right to be forgotten” and strong securi
Deleuze replied: The key legal point is that passengers cannot be treated as having agreed to IRIS merely because the driver, operator, or vehicle owner accepted the legal terms. If passengers’ faces, bodies, voices, or behavioural signals are captured, they may become data subjects in their own right. The operator therefore needs a lawful basis for processing their personal data under GDPR Article 6, separate from any agreement with the driver. Consent is not the only possible lawful basis, but if the company relies on consent it must be genuine, informed, freely given, and specific; passive entry into a bus or taxi is unlikely to be enough on its own. The strongest compliance position would be that IRIS is designed so that it does not capture or process passenger data at all, or does so only in a fleeting and technically unavoidable way. For example, the camera should be physically angled and technically configured to focus only on the driver; passenger faces should be excluded from the field of view, blurred, cropped, or discarded immediately; and all processing should preferably occur locally in the vehicle without recording or transmission. This reflects GDPR’s data protection by design and by default requirement, which requires controllers to implement appropriate technical and organisational measures so that only necessary personal data is processed.
Answered: 4 months, 3 weeks ago By: Oliverharrow
Should be deleted once 5 years has passed
Answered: 4 months, 3 weeks ago By: Ngozioshoba
Only data necessary for fatigue detection should be collected and stored for limited periods. Users must understand why their data is processed. Regular checks ensure the data is not reused beyond its purpose.
Answered: 4 months, 3 weeks ago By: Efeadelaja
Pseudo-anonymization with deletion on request is generally sufficient under GDPR, but full anonymization reduces legal risk; retaining data after deletion could still have legal implications.
Answered: 4 months, 3 weeks ago By: Meilincai
The data must be saved up to 10 years according to the EU AI charter for various reasons including the database
Answered: 4 months, 3 weeks ago By: Kelechinwosu
If you fully anonymize data, it is no longer considered "personal data," and GDPR no longer applies. You could legally retain this data for 5 years (or indefinitely) even after a profile is deleted.
Deleuze replied: If IRIS is deployed across a fleet of buses, taxis, or public transport vehicles, a Data Protection Impact Assessment would very likely be required. The use of cameras, AI analysis, possible biometric or health-related inferences, and systematic monitoring in vehicles accessible to the public creates a high-risk processing scenario. GDPR Article 35 specifically identifies systematic monitoring of publicly accessible areas on a large scale as a case where a DPIA is required. The status of the data must also be assessed carefully. A passenger’s face captured by a camera is personal data if the passenger is identifiable. It is not automatically special-category biometric data merely because it is a facial image; GDPR Recital 51 says photographs should not systematically be treated as special-category data unless processed through specific technical means allowing unique identification or authentication. However, if IRIS performs face recognition, passenger identification, biometric categorisation, or emotional/physiological inference on passengers, the legal risk becomes much higher.
Answered: 4 months, 3 weeks ago By: Zainabodogwu32
From both a legal and ethical standpoint, full anonymization is preferable but not always technically feasible for biometric datasets. Full anonymization removes all identifiable links to individuals and places data outside GDPR’s scope. This allows longer retention (e.g. 5 years) but is extremely difficult to achieve with facial or physiological data without destroying its utility. Pseudonymization retains identifiers separately and allows compliance with GDPR rights, including the right to erasure (“right to be forgotten”). In practice, pseudonymization combined with strict access controls, encryption, and deletion mechanisms is generally considered sufficient and more realistic, provided users can request deletion and data is not retained longer than necessary. Ethically, respecting user control and deletion rights is critical to maintaining trust, even if anonymization would offer fewer legal constraints.
Answered: 4 months, 3 weeks ago By: Miles_Hatcher
Full anonymisation is not strictly required though it provides protection
Answered: 4 months, 3 weeks ago By: Aminaolorun
It is not required but it provides protection
Answered: 4 months, 3 weeks ago By: Clarawhitby
Shii idk
Answered: 4 months, 3 weeks ago By: Ifeanyiakare
Pseudo-anonymization with a functional “right to be forgotten” is generally sufficient if personal identifiers can be deleted on request. Full anonymization is stricter, allows longer retention without legal risk, but may limit personalized model improvements. Key: Must prevent re-identification and comply with GDPR retention limits.
Answered: 4 months, 3 weeks ago By: Kunleekwueme
I believe full anonymisation would allow use without legal implication, provided thr users agreed to the data collection.
Answered: 4 months, 3 weeks ago By: Sadeogunlana
Let full anonymization be required
Answered: 4 months, 3 weeks ago By: Tomashbrook
I suppose psuedo-anonymisation can be used.
Answered: 1 month ago By: Brightfox_45
Yes. Having the system automatically detect who the person is means, the passengers may have to upload their data without wanting to, this will go against some legal agreements. The passengers needs to have a choice of whether they want their system to be used on public transport as well as in their own vehicle.
Answered: 1 month ago By: Cleverwolf_27
Consent is clearly an issue here, also accuracy and reliability of data collection regarding identity if each individual esp on what could be crowded public services. Legitimacy of use on limited public services i.e., buses when there may not be the option of use another service without this technology.
Answered: 1 month ago By: Brightrobin_21
Even with explicit consent practices, it could reduce public trust, making people less comfortable travelling in such vehicles.
Answered: 1 month ago By: Warmlynx_14
Yes, public vehicles raise extra consent and bystander-privacy issues because passengers may be captured incidentally. Clear notices, limited retention, and opt-out pathways would be important.
Answered: 1 month ago By: Swiftowl_37
In buses and taxis, passengers may not have a practical way to meaningfully consent, so this needs extra legal scrutiny. Notices alone may not be enough if capture is unavoidable.
Answered: 1 month ago By: Cleverrobin_87
Public-vehicle use is especially sensitive because bystanders may be recorded incidentally and may not know monitoring is occurring. That means public transport use needs stronger safeguards than private driving.
Answered: 1 month ago By: Swiftrobin_35
Public-service vehicles need extra safeguards because monitoring can affect non-users who never opted in. The use case should be limited and clearly communicated.
Answered: 1 month ago By: Boldlynx_38
It raises a bystander issue that is hard to solve with consent alone. The operator should use strong notices and minimize incidental collection.
Answered: 1 month ago By: Quietbadger_45
If passengers can be captured without knowing it, public-transport deployment becomes more ethically fraught. That means public transport use needs stronger safeguards than private driving.
Answered: 1 month ago By: Swiftdeer_99
If passengers can be captured without knowing it, public-transport deployment becomes more ethically fraught. That means public transport use needs stronger safeguards than private driving.
Answered: 1 month ago By: Bravebear_45
Passenger privacy matters because incidental capture can happen even when passengers never agreed to monitoring. That means public transport use needs stronger safeguards than private driving.
Answered: 1 month ago By: Calmwolf_53
Public-service deployment creates a bystander issue that is hard to solve with consent alone. The operator should use strong notices and minimize incidental collection.
Answered: 1 month ago By: Brightowl_58
In shared vehicles, the rights of non-consenting passengers should be treated carefully because they may be recorded incidentally. Special notice and policy controls are needed.
Answered: 1 month ago By: Brightbear_54
yes
Answered: 1 month ago By: Warmhawk_15
Penalties could escalate and the company would be liable.
Answered: 1 month ago By: Quietrobin_25
There is a worry someone might have abort implied consent based on making users aware of the possibility. Some worry that it gives users no choice around consent, just choice in relation to use (can they really choose not to use the taxi or bus?)
Answered: 1 month ago By: Braveowl_80
I think it is very important the data stored is only for the driver and not the passengers in the public service vehicles. Full transparency is necessary to ensure anyone entering the vehicle is aware of the emerging system and that their images may be detected but will not be stored.
Answered: 1 month ago By: Kindbadger_56
Privacy <- more serious in public vehicles (not only driver) taking away users right to agree/disagree (if applied in all)
Answered: 1 month ago By: Warmwolf_18
Yes (if the user image is processed); otherwise, no.

Your Answer

Login to add your answer!

We’d love to hear your thoughts — share a meaningful answer by logging in.