Tired of ads? Enjoy an ad-free experience by signing up.
  • Insights
    This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
Kevin Shepherdson ยท ยท 4 min read

How intrusive are contact-tracing apps in ASEAN?

With most experts saying that a vaccine for Covid-19 may not hit the market until mid-2021, ASEAN governments are seeking ways to ease lockdowns and create a close-to-normal society. Part of this effort is the release of contact-tracing apps.

These apps can access usersโ€™ locations and people they have been in contact with through GPS or Bluetooth technology. Once downloaded, such apps can access and exchange a userโ€™s unique ID-related information via short-distance Bluetooth signals with any mobile phone with the same app. The personโ€™s contact history will also be shared with relevant government agencies, which means that if any user has been exposed to an infected person, it will be documented.

Running in the background of your phone, itโ€™s easy to forget how much of your information these apps can access. Thatโ€™s why we surveyed these apps to discover just how intrusive they might be.

Straits Interactive assembled a local team from the International Association of Privacy Professionals to do a detailed privacy sweep of contact-tracing smart apps from the governments of six ASEAN countries.

These contact-tracing apps were benchmarked against the survey parameters used by the Global Privacy Enforcement Network, which conducted a privacy sweep of mobile apps in 2014. That sweep involved the participation of 25 privacy enforcement authorities around the world. (View the full report here.)

It assessed the following:

  • The types of permissions sought by a surveyed app
  • Whether those permissions exceeded what would be expected based on the appโ€™s functionality
  • How the app explained to consumers why it wanted the personal data and what it planned to do with it

โ€œPermissionsโ€ in an app protect the privacy of a user. Every app must include an โ€œapp manifestโ€ that lists the permissions it uses, among other things.

A mobile phoneโ€™s operating system also dictates permissions to an extent. The vast majority of mobile phones run on the Android OS, and it uses two permission categories:

  • Normal permissions: These do not directly risk the userโ€™s privacy. For example, granting permission to set the time zone is a normal one. If an app lists a normal permission in its manifest, the system grants it automatically.
  • Dangerous permissions: These give the app access to the userโ€™s personal data in their mobile phones, such as contacts and SMS texts as well as certain system features like the camera. If a dangerous permission is requested, privacy laws do not allow the relevant personal data to be collected, used, or disclosed unless the user gives explicit consent by accepting the request for permission. In addition, privacy laws generally restrict dangerous permissions to personal data that the app may collect, use, or disclose while the user is actually using it. These laws also restrict the gathering of information simply because a user downloaded the app.

Often, people blindly agree to or allow these permissions without first understanding their functions and donโ€™t read the privacy policies of the applications they use.

The following table shows the various dangerous permissions being used in the six contact-tracing smart apps we reviewed:

Photo credit: Straits Interactive

Stay ahead in Asiaโ€™s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

๐Ÿ„ For casual readers / ๐Ÿ‘ถ Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

โŒ›Sign up in 20s. No payment details needed.

๐Ÿ“– For learners / ๐Ÿ‘ Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Kevin Shepherdson

Kevin is the CEO and Founder of Straits Interactive Pte Ltd, a specialist in data privacy platform solutions and professional services in the ASEAN region. An advocate for data protection, Kevin is also the international author of โ€œ99 Privacy Breaches to Beware ofโ€ and a Fellow in Information Privacy (FIP).