HomeInsightsInformation Commissioner’s Office publishes discussion document on data protection expectations on contact tracing app development

Contact

Information Commissioner Elizabeth Denham and Executive Director of Technology and Innovation Simon McDougall appeared before the Human Rights Joint Committee on 4 May 2020.

Before the session, the ICO sent the Committee a discussion document setting out the ICO’s expectations on how contact tracing solutions may be developed in line with the principles of data protection by design and default. The document also includes a series of best practice recommendations.

The document sets out the principles that should be followed when developing the app:

  • be transparent about the purpose;
  • be transparent about your design choices;
  • be transparent about the benefits;
  • collect the minimum amount of personal data necessary;
  • protect your users;
  • give users control;
  • keep data for the minimum amount of time, and, where appropriate, ensure the user has control over this;
  • securely process the data;
  • ensure the user can opt in or opt out without any negative consequences; and
  • strengthen privacy, do not weaken it.

The document also suggests considering how to test functional and non-functional requirements or use cases and user journeys that are being developed against these principles on a continuous development basis.

To access the document, click here.