- Insights This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
How intrusive are contact-tracing apps in ASEAN?
With most experts saying that a vaccine for Covid-19 may not hit the market until mid-2021, ASEAN governments are seeking ways to ease lockdowns and create a close-to-normal society. Part of this effort is the release of contact-tracing apps.
These apps can access usersโ locations and people they have been in contact with through GPS or Bluetooth technology. Once downloaded, such apps can access and exchange a userโs unique ID-related information via short-distance Bluetooth signals with any mobile phone with the same app. The personโs contact history will also be shared with relevant government agencies, which means that if any user has been exposed to an infected person, it will be documented.
Running in the background of your phone, itโs easy to forget how much of your information these apps can access. Thatโs why we surveyed these apps to discover just how intrusive they might be.
Straits Interactive assembled a local team from the International Association of Privacy Professionals to do a detailed privacy sweep of contact-tracing smart apps from the governments of six ASEAN countries.
These contact-tracing apps were benchmarked against the survey parameters used by the Global Privacy Enforcement Network, which conducted a privacy sweep of mobile apps in 2014. That sweep involved the participation of 25 privacy enforcement authorities around the world. (View the full report here.)
It assessed the following:
- The types of permissions sought by a surveyed app
- Whether those permissions exceeded what would be expected based on the appโs functionality
- How the app explained to consumers why it wanted the personal data and what it planned to do with it
โPermissionsโ in an app protect the privacy of a user. Every app must include an โapp manifestโ that lists the permissions it uses, among other things.
A mobile phoneโs operating system also dictates permissions to an extent. The vast majority of mobile phones run on the Android OS, and it uses two permission categories:
- Normal permissions: These do not directly risk the userโs privacy. For example, granting permission to set the time zone is a normal one. If an app lists a normal permission in its manifest, the system grants it automatically.
- Dangerous permissions: These give the app access to the userโs personal data in their mobile phones, such as contacts and SMS texts as well as certain system features like the camera. If a dangerous permission is requested, privacy laws do not allow the relevant personal data to be collected, used, or disclosed unless the user gives explicit consent by accepting the request for permission. In addition, privacy laws generally restrict dangerous permissions to personal data that the app may collect, use, or disclose while the user is actually using it. These laws also restrict the gathering of information simply because a user downloaded the app.
Often, people blindly agree to or allow these permissions without first understanding their functions and donโt read the privacy policies of the applications they use.
The following table shows the various dangerous permissions being used in the six contact-tracing smart apps we reviewed:

Photo credit: Straits Interactive
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.
๐ Premium Content
- Meet the 25 top-funded startups and tech companies in the Philippines

- Alibabaโs AI capex spike isnโt the story investors think

- Surviving the funding game: how timing can make or break your startup

- Meet the 10 top-funded startups and tech companies in Thailand

- Meet Southeast Asiaโs top angel investors





