Digital Contact Tracing And Privacy: 4 Rights-Based Safeguards
Navigating the complex balance between pandemic technology and digital privacy.
The Collision of Public Health, Technology, and Civil Liberties
During global health emergencies, society instinctively turns to technological innovation for salvation. The rapid development and deployment of digital tools—ranging from mobile contact tracing applications to automated biometric screening systems—offer a tantalizing promise: the ability to monitor, contain, and ultimately defeat infectious diseases. However, the integration of these powerful surveillance technologies into daily life presents profound challenges to civil liberties and digital privacy. When the dust of a crisis settles, the infrastructure of monitoring often remains, fundamentally altering the relationship between citizens, corporations, and the state.
Protecting public health and safeguarding civil liberties are not mutually exclusive goals. In fact, public trust is the cornerstone of any effective health initiative. If populations believe that their sensitive medical or location data will be mishandled, sold, or used against them, they will reject the very tools designed to keep them safe. Understanding the nuances of these technologies and establishing rigorous legal frameworks is essential to ensure that emergency measures do not permanently erode fundamental rights.
The Promise and Peril of Digital Contact Tracing
One of the most prominent technological interventions during recent health crises has been the development of digital contact tracing and exposure notification systems. Traditional contact tracing—a labor-intensive process conducted by public health professionals—relies on interviews and human memory to identify potential disease transmission chains. To automate and scale this process, governments and tech giants collaborated to utilize smartphone capabilities.
Location Tracking vs. Proximity Sensing
Initial attempts at digital tracing often relied on GPS and Cell-Site Location Information (CSLI). However, these methods are fraught with both technical and ethical pitfalls. GPS struggles with indoor precision and verticality—it cannot reliably distinguish between someone in an apartment on the third floor and someone directly below them on the second floor. More importantly, tracking exact geographical coordinates creates a highly intrusive, centralized map of citizens’ daily movements, raising severe mass surveillance concerns.
To mitigate these privacy risks, the focus shifted to Bluetooth Low Energy (BLE) proximity tracking. Instead of recording where an individual is, BLE systems record who they have been near. Smartphones exchange randomly generated, rotating cryptographic keys with nearby devices. If a user tests positive, they can voluntarily upload their keys to a server, which then alerts others who came into close contact.
While proximity tracking represents a significant victory for privacy-by-design, it is not a panacea. Bluetooth signals can travel through thin walls and glass, potentially generating false positives by registering a “contact” between two people who were safely separated by a physical barrier. Furthermore, the World Health Organization (WHO) has emphasized that such digital proximity tracking technologies must be guided by strict ethical considerations, ensuring that they are voluntary, temporary, and transparently operated to protect user privacy.
Biometric Surveillance: The Fever Check Mirage
As businesses, airports, and public spaces scrambled to reopen during health crises, automated thermal imaging cameras became a ubiquitous sight. Marketed as non-invasive “fever-screening” tools, these systems promised to instantly identify potentially infected individuals in crowded areas. However, the widespread deployment of biometric surveillance poses significant threats to both public health efficacy and civil liberties.
Scientific Limitations and False Security
The core scientific premise of using thermal imaging to detect infectious diseases is deeply flawed. These cameras measure skin surface temperature, not internal core body temperature. Skin temperature is heavily influenced by environmental factors such as ambient weather, physical exertion, and even the consumption of alcohol. Consequently, thermal scanners generate high rates of both false positives and false negatives.
The U.S. Food and Drug Administration (FDA) has actively warned consumers and facility operators that improper use of thermal imaging systems can provide inaccurate temperature readings, creating a dangerous illusion of safety. Relying on flawed biometric data can lead to infected individuals passing through checkpoints undetected, while healthy individuals face unwarranted public embarrassment, denial of entry, or workplace discrimination.
The Normalization of Facial Surveillance
Beyond their dubious medical utility, thermal cameras serve as a trojan horse for the normalization of biometric tracking. Many of these systems are bundled with facial recognition capabilities designed to identify and log the individuals being scanned. Once installed, this hardware creates a permanent, networked infrastructure for mass surveillance. When the health emergency recedes, the hardware remains, ready to be repurposed for security tracking, employee monitoring, or law enforcement identification without the public’s explicit consent.
Data Governance and the Threat of “Mission Creep”
The collection of vast amounts of sensitive health and location data demands uncompromising data governance. The greatest threat to civil liberties in the digital age is “mission creep”—the phenomenon where data collected for a specific, benevolent purpose is subsequently accessed and utilized for entirely different, often punitive, reasons.
Protecting Information from Law Enforcement and Immigration
If citizens suspect that data collected by a public health app could be subpoenaed by law enforcement, accessed by immigration agencies, or sold to data brokers, participation will plummet. Vulnerable communities, including undocumented immigrants and marginalized minorities who often face disproportionate policing, are particularly at risk. To prevent this, protective firewalls must be established. Legislation must explicitly prohibit the sharing of emergency public health data with non-health agencies.
Data Minimization and Sunset Clauses
Robust digital privacy requires adherence to the principle of data minimization: systems should only collect the absolute minimum amount of information necessary to achieve their public health objective, and they should retain that data for the shortest possible duration. Data should be kept on decentralized, local devices rather than centralized government servers whenever feasible.
Furthermore, emergency technologies must be tethered to strict sunset clauses. A sunset clause is a legal provision ensuring that an application is deactivated, and all associated data is permanently destroyed, once the specific public health emergency is declared over. Surveillance powers granted during a crisis must not be allowed to calcify into the new normal.
The Digital Divide and Health Equity
Technological interventions are only effective if they are accessible. A critical blind spot in the deployment of digital health solutions is the exacerbation of existing socioeconomic inequalities, commonly referred to as the digital divide.
Telehealth and the Broadband Gap
The rapid pivot to telehealth services protected millions from exposure to pathogens in crowded waiting rooms. However, telehealth requires reliable broadband internet and access to modern smartphones or computers. Low-income households, rural communities, and elderly populations often lack this infrastructure. When public health strategies become heavily reliant on digital platforms, those without access are marginalized, receiving delayed or inferior care.
The Office of the National Coordinator for Health Information Technology (ONC) has highlighted that advancing health equity requires intentional design in health IT systems. Interoperability and digital access must be expanded to ensure that marginalized populations are not left behind. Furthermore, when these populations do access digital tools, they are often subjected to predatory data harvesting by apps that lack robust privacy protections, penalizing them simply for seeking care.
Algorithmic Bias in Healthcare
Beyond simple access, the algorithms that power digital health triage and resource allocation must be scrutinized for bias. Machine learning models trained on historical healthcare data often inherit the systemic biases present in that data. If an algorithm determines who receives priority testing or automated care based on flawed, demographically skewed data, it can result in discriminatory outcomes for minority communities, violating their civil rights under the guise of objective mathematics.
Framework for the Future: Protecting Rights in a Digital Age
As we navigate the intersection of public health and digital innovation, we must build a framework that intrinsically respects human rights. The false dichotomy between privacy and safety must be rejected; we can and must demand both.
- Voluntary Adoption: The use of digital public health tools must remain strictly voluntary. Coercive measures, such as denying employment or access to public services for refusing to download an app, violate fundamental autonomy.
- Open-Source Transparency: The code powering exposure notification and health monitoring apps should be open-source. This allows independent security researchers and privacy advocates to audit the software, ensuring it performs exactly as claimed without hidden tracking mechanisms.
- Independent Oversight: The deployment of crisis technology must be overseen by independent auditing boards composed of public health experts, technologists, and civil liberties advocates, rather than operating solely under executive authority.
- Comprehensive Federal Privacy Legislation: The reliance on patchwork state laws and outdated regulations is insufficient. A comprehensive, federal data privacy law is desperately needed to regulate corporate data collection and restrict how third-party apps handle sensitive consumer health information.
Ultimately, technology is a tool, not an outcome. Its impact on society is dictated by the laws and ethical standards that govern its use. By insisting on rigorous privacy protections, data minimization, and equitable access, we can harness the power of digital innovation to protect public health without sacrificing the civil liberties that define a free society.
Frequently Asked Questions (FAQ)
Why is Bluetooth preferred over GPS for digital exposure notification?
GPS tracks a user’s absolute physical location, which creates severe privacy and mass surveillance risks. It is also often inaccurate indoors. Bluetooth Low Energy (BLE), conversely, operates via proximity sensing. It does not record where you are, only which other devices you have been near, preserving location privacy while effectively monitoring potential exposure.
Are thermal imaging cameras an effective way to detect viruses?
No. Thermal imaging cameras only measure skin surface temperature, which can be affected by ambient environment, physical activity, and stress. The FDA has warned that they are not diagnostic tools and can yield inaccurate readings. Furthermore, they raise significant privacy concerns regarding biometric data collection and facial surveillance.
What is a “sunset clause” in the context of health technology?
A sunset clause is a mandatory legal mechanism built into emergency measures ensuring that temporary surveillance tools and applications are permanently dismantled, and their collected data securely deleted, once a public health crisis has officially ended. This prevents temporary emergency powers from becoming permanent.
How does the digital divide impact public health tracking?
Digital health solutions like telehealth and tracing apps require smartphones, cellular data, and broadband internet. Vulnerable populations, including low-income and rural communities, often lack this access. Relying solely on digital interventions can marginalize these groups, leading to unequal health outcomes and gaps in disease monitoring.
Is data collected by public health apps protected by HIPAA?
Not always. The Health Insurance Portability and Accountability Act (HIPAA) primarily applies to covered entities like doctors, hospitals, and health insurance plans. Data collected directly from consumers by commercial smartphone apps or third-party tech developers often falls outside of HIPAA’s jurisdiction, highlighting the need for stronger, comprehensive data privacy laws.
References
- Ethical considerations to guide the use of digital proximity tracking technologies for COVID-19 contact tracing — World Health Organization (WHO). 2020-05-28. https://www.who.int/publications/i/item/WHO-2019-nCoV-Ethics_Contact_tracing_apps-2020.1
- FDA Alerts Public about Improper Use of Thermal Imaging Devices — U.S. Food and Drug Administration (FDA). 2021-03-04. https://www.fda.gov/news-events/press-announcements/fda-alerts-public-about-improper-use-thermal-imaging-devices-warns-firms-illegally-offering-thermal
- Supplemental Background Research Document for the Health Information Technology Advisory Committee (HITAC) Annual Report — Office of the National Coordinator for Health Information Technology (ONC). 2023-02-08. https://www.healthit.gov/topic/health-it-health-care-settings/health-equity
Read full bio of medha deb





