ALFIE ETD-HUB

13: How are Non-Drivers Affected?

Asked: 7 months, 4 weeks ago By: Catalink Views: 235 Catalink Case Study: IRIS

If the IRIS application is deployed in public service vehicles (like taxis or buses), are there distinct ethical and legal issues that arise - given that there is a possibility that some passengers (non-drivers of the company) may be detected/captured by the IRIS application for some period of time without providing explicit consent to the legal agreements?

37 Answers

Answered: 6 months ago By: Chiamakaokorie

-

Answered: 6 months ago By: Tundefasina

Full anonymization removes GDPR obligations but may limit model improvement. Pseudonymization is usually sufficient if combined with strong access controls and a right-to-erasure mechanism, allowing users to delete their data. Retaining identifiable data after profile deletion would raise legal risks.

Answered: 6 months ago By: Zainabodogwu2

Full anonymization → safest, fewer legal limits • Pseudonymization → allowed if “right to be forgotten” and strong securi

Deleuze replied: The key legal point is that passengers cannot be treated as having agreed to IRIS merely because the driver, operator, or vehicle owner accepted the legal terms. If passengers’ faces, bodies, voices, or behavioural signals are captured, they may become data subjects in their own right. The operator therefore needs a lawful basis for processing their personal data under GDPR Article 6, separate from any agreement with the driver. Consent is not the only possible lawful basis, but if the company relies on consent it must be genuine, informed, freely given, and specific; passive entry into a bus or taxi is unlikely to be enough on its own. The strongest compliance position would be that IRIS is designed so that it does not capture or process passenger data at all, or does so only in a fleeting and technically unavoidable way. For example, the camera should be physically angled and technically configured to focus only on the driver; passenger faces should be excluded from the field of view, blurred, cropped, or discarded immediately; and all processing should preferably occur locally in the vehicle without recording or transmission. This reflects GDPR’s data protection by design and by default requirement, which requires controllers to implement appropriate technical and organisational measures so that only necessary personal data is processed.
Answered: 6 months ago By: Oliverharrow

Should be deleted once 5 years has passed

Answered: 6 months ago By: Ngozioshoba

Only data necessary for fatigue detection should be collected and stored for limited periods. Users must understand why their data is processed. Regular checks ensure the data is not reused beyond its purpose.

Answered: 6 months ago By: Efeadelaja

Pseudo-anonymization with deletion on request is generally sufficient under GDPR, but full anonymization reduces legal risk; retaining data after deletion could still have legal implications.

Answered: 6 months ago By: Meilincai

The data must be saved up to 10 years according to the EU AI charter for various reasons including the database

Answered: 6 months ago By: Kelechinwosu

If you fully anonymize data, it is no longer considered "personal data," and GDPR no longer applies. You could legally retain this data for 5 years (or indefinitely) even after a profile is deleted.

Deleuze replied: If IRIS is deployed across a fleet of buses, taxis, or public transport vehicles, a Data Protection Impact Assessment would very likely be required. The use of cameras, AI analysis, possible biometric or health-related inferences, and systematic monitoring in vehicles accessible to the public creates a high-risk processing scenario. GDPR Article 35 specifically identifies systematic monitoring of publicly accessible areas on a large scale as a case where a DPIA is required. The status of the data must also be assessed carefully. A passenger’s face captured by a camera is personal data if the passenger is identifiable. It is not automatically special-category biometric data merely because it is a facial image; GDPR Recital 51 says photographs should not systematically be treated as special-category data unless processed through specific technical means allowing unique identification or authentication. However, if IRIS performs face recognition, passenger identification, biometric categorisation, or emotional/physiological inference on passengers, the legal risk becomes much higher.
Answered: 6 months ago By: Zainabodogwu32

From both a legal and ethical standpoint, full anonymization is preferable but not always technically feasible for biometric datasets. Full anonymization removes all identifiable links to individuals and places data outside GDPR’s scope. This allows longer retention (e.g. 5 years) but is extremely difficult to achieve with facial or physiological data without destroying its utility. Pseudonymization retains identifiers separately and allows compliance with GDPR rights, including the right to erasure (“right to be forgotten”). In practice, pseudonymization combined with strict access controls, encryption, and deletion mechanisms is generally considered sufficient and more realistic, provided users can request deletion and data is not retained longer than necessary. Ethically, respecting user control and deletion rights is critical to maintaining trust, even if anonymization would offer fewer legal constraints.

Answered: 6 months ago By: Miles_Hatcher

Full anonymisation is not strictly required though it provides protection

Answered: 6 months ago By: Aminaolorun

It is not required but it provides protection

Answered: 6 months ago By: Clarawhitby

Shii idk

Answered: 6 months ago By: Ifeanyiakare

Pseudo-anonymization with a functional “right to be forgotten” is generally sufficient if personal identifiers can be deleted on request. Full anonymization is stricter, allows longer retention without legal risk, but may limit personalized model improvements. Key: Must prevent re-identification and comply with GDPR retention limits.

Answered: 6 months ago By: Kunleekwueme

I believe full anonymisation would allow use without legal implication, provided thr users agreed to the data collection.

Answered: 6 months ago By: Sadeogunlana

Let full anonymization be required

Answered: 6 months ago By: Tomashbrook

I suppose psuedo-anonymisation can be used.

Answered: 2 months, 2 weeks ago By: Brightfox_45

Yes. Having the system automatically detect who the person is means, the passengers may have to upload their data without wanting to, this will go against some legal agreements. The passengers needs to have a choice of whether they want their system to be used on public transport as well as in their own vehicle.

Answered: 2 months, 2 weeks ago By: Cleverwolf_27

Consent is clearly an issue here, also accuracy and reliability of data collection regarding identity if each individual esp on what could be crowded public services. Legitimacy of use on limited public services i.e., buses when there may not be the option of use another service without this technology.

Answered: 2 months, 2 weeks ago By: Brightrobin_21

Even with explicit consent practices, it could reduce public trust, making people less comfortable travelling in such vehicles.

Answered: 2 months, 2 weeks ago By: Warmlynx_14

Yes, public vehicles raise extra consent and bystander-privacy issues because passengers may be captured incidentally. Clear notices, limited retention, and opt-out pathways would be important.

Answered: 2 months, 2 weeks ago By: Swiftowl_37

In buses and taxis, passengers may not have a practical way to meaningfully consent, so this needs extra legal scrutiny. Notices alone may not be enough if capture is unavoidable.

Answered: 2 months, 2 weeks ago By: Cleverrobin_87

Public-vehicle use is especially sensitive because bystanders may be recorded incidentally and may not know monitoring is occurring. That means public transport use needs stronger safeguards than private driving.

Answered: 2 months, 2 weeks ago By: Swiftrobin_35

Public-service vehicles need extra safeguards because monitoring can affect non-users who never opted in. The use case should be limited and clearly communicated.

Answered: 2 months, 2 weeks ago By: Boldlynx_38

It raises a bystander issue that is hard to solve with consent alone. The operator should use strong notices and minimize incidental collection.

Answered: 2 months, 2 weeks ago By: Quietbadger_45

If passengers can be captured without knowing it, public-transport deployment becomes more ethically fraught. That means public transport use needs stronger safeguards than private driving.

Answered: 2 months, 2 weeks ago By: Swiftdeer_99

If passengers can be captured without knowing it, public-transport deployment becomes more ethically fraught. That means public transport use needs stronger safeguards than private driving.

Answered: 2 months, 2 weeks ago By: Bravebear_45

Passenger privacy matters because incidental capture can happen even when passengers never agreed to monitoring. That means public transport use needs stronger safeguards than private driving.

Answered: 2 months, 2 weeks ago By: Calmwolf_53

Public-service deployment creates a bystander issue that is hard to solve with consent alone. The operator should use strong notices and minimize incidental collection.

Answered: 2 months, 2 weeks ago By: Brightowl_58

In shared vehicles, the rights of non-consenting passengers should be treated carefully because they may be recorded incidentally. Special notice and policy controls are needed.

Answered: 2 months, 2 weeks ago By: Brightbear_54

yes

Answered: 2 months, 2 weeks ago By: Warmhawk_15

Penalties could escalate and the company would be liable.

Answered: 2 months, 2 weeks ago By: Quietrobin_25

There is a worry someone might have abort implied consent based on making users aware of the possibility. Some worry that it gives users no choice around consent, just choice in relation to use (can they really choose not to use the taxi or bus?)

Answered: 2 months, 2 weeks ago By: Braveowl_80

I think it is very important the data stored is only for the driver and not the passengers in the public service vehicles. Full transparency is necessary to ensure anyone entering the vehicle is aware of the emerging system and that their images may be detected but will not be stored.

Answered: 2 months, 2 weeks ago By: Kindbadger_56

Privacy <- more serious in public vehicles (not only driver) taking away users right to agree/disagree (if applied in all)

Answered: 2 months, 2 weeks ago By: Warmwolf_18

Yes (if the user image is processed); otherwise, no.

Your Answer

Login to add your answer!

We’d love to hear your thoughts — share a meaningful answer by logging in.