Contact tracing

30 Jun 2020
After ORG asked questions via its legal representative, AWO’s Ravi Naik, the UK’s Department of Health and Social Care agreed to change the period it would retain Test and Trace data from 20 years to eight. Public Health England manager Yvonne Doyle explained that the novelty of COVID-19 was the
20 Jul 2020
In early July the Open Rights Group issued a pre-action legal letter to UK health secretary Matt Hancock and the Department of Health and Social Care saying they have breached requirements under the Data Protection Act 2018 and GDPR by failing to conduct an impact assessment for the Test and Trace
08 Jul 2020
Israel’s initial success in curbing the spread of the coronavirus in April was followed in June by a surge in cases that government advisers blamed on insufficient resources for ministries to implement an effective trace-and-trace programme and increase testing to the level that would show clearly
05 Jun 2020
UK police reported to be planning separate contact tracing system Police forces in the UK are planning their own contact tracing system because they are concerned that giving details to the national contact tracing system would compromise undercover operations and working methods. Options under
04 Jun 2020
The app-based track-and-trace system that was supposed to be in place in the UK by June 1 will not be working at full speed until September or October, and the chief executive of Serco, one of the main companies contracted to deliver it, doubted the system would evolve smoothly. Scientists have said
11 Jun 2020
A detailed analysis of Pakistan’s app, which was developed by the Ministry of IT and Telecom and the National Information Technology Board and which offers dashboards for each province and state, self-assessment tools, and popup hygiene reminders, finds a number of security issues. Among them: the
15 Jun 2020
After the data protection authority ruled that Norway’s Smittestopp app disproportionately intruded on users’ privacy by collecting location data without demonstrating it was strictly necessary and by failing to allow users to separately grant permission for contact tracing and for using the data
13 Jun 2020
The UK government spent two months touting its contact tracing app as the prospective basis for returning to something close to normality. As the June 1 target date approached, however, the government increasingly downplayed its importance. In the meantime, Apple and Google’s API were adopted by
20 May 2020
After the CEO of NHSx told the the UK parliament that data harvested by the NHSx contact tracing app would be retained for future research, the UK Ministry of Defence said it would turn the data over to its Jhub to sanitise the data and remove all personally identifying information before passing it
26 Jun 2020
Germany’s “Corona-Warn” contact tracing app amassed 6.5 million users (7.8% of the German population) in the first 24 hours after its June 16 launch despite setbacks that included disputes over data privacy and functionality. The app was developed in six weeks by a team of developers and engineers
01 Jun 2020
Concerns that contact tracing could expand to purposes beyond public health gained some weight when the Minnesota Department of Public Safety Commissioner John Harrington told press that law enforcement was using “contact tracing” to investigate protesters arrested after the murder of George Floyd
05 Jun 2020
After problems with its TraceTogether contact tracing app, Singapore is planning a comprehensive contact tracing system in which it will distribute to all its 5.7 million residents a wearable device that will identify people who have interacted with people carrying the coronavirus. The devices can
03 Jun 2020
The lack of data protection laws and the absence of a privacy commission are contributing factors to Pakistan’s failure to investigate or remedy security flaws in the country’s recently-launched COVID-19 tracking technology, which partially depends on a system originally developed to combat
01 Jun 2020
Italy has launched Immuni, one of the first contact tracing apps based on the Apple-Google API. The app is opt-in, and includes an explanation of the privacy and security measures in its setup. The app collects anonymously bluetooth tokens that are automatically randomised, but does not collect GPS
13 May 2020
The Slovak Constitutional Court declared unconstitutional parts of the newly amended telecommunication law that permitted state authorities to access telcommunications data for the purposes of contact tracing. The parliament approved the legislation in March, but the court ruled that the need for
12 May 2020
Any user of India's Aaorgya Setu contact tracing app can now request deletion of the data they've entered according to the Aaorgya Seta Emergency Data Access and Knowledge Sharing Protocol, 2020, which specifies the definition, collection, processing, and storage of the data the app collects. The
13 May 2020
In designing its Healthy Together contact tracing app, the US state of Utah opted for a GPS and Bluetooth-based design created by social media startup Twenty; it does not use the Google-Apple API. The goal is for the app to assist the 1,200 Utah Department of Health workers who are doing phone call
20 May 2020
In its final report, the expert group appointed by the Norwegian Ministry of Health and Care Services to assess the security and privacy of the country's COVID-19 contact tracing app, "Smittestopp", concluded that the app handles neither responsibly. The group recommended removing all data once it's
19 May 2020

Security researchers have found seven problems with the NHSx contact tracing app including: weaknesses in registration that could allow attackers to steal encryption keys; storing unencrypted data on handsets; generating a new random ID code only once a day; and design decisions with respect to Bluetooth connections that could enable tracking. These questions are independent of whether the app is centralised or decentralised.

Writer: BBC; Chris Culnane and Vanessa Teague
Publication: BBC; State of IT

21 May 2020

In an analysis, the smartphone privacy company Jumbo Privacy finds that Care19, North Dakota's official COVID-19 contact tracing app, sends latitude and longitude data and a unique user advertising identifier to Foursquare and other data to Google servers and the bug-tracking Bugfender. The app's privacy policy does not disclose this third-party sharing. The app development company, ProudCrowd, said it would update the privacy policy and that the data-sharing agreement does not allow Foursquare to collect or use the Care19 data beyond returning the names of nearby businesses. North Dakota officials say future versions of the app will incorporate Apple-Google's new Exposure Notification API.

Writer: Steven Melendez
Publication: Fast Company


29 May 2020
The UK's NHSx contact tracing initiative requires anyone who tests positive for COVID-19 to provide the full name, postcode/house number, phone number, and email of anyone they've been in contact with, and Public Health England will keep the data for 20 years. The privacy notice was quickly updated
26 May 2020
China is adding new features to its coronavirus surveillance app, which has helped many workers and employers return to their former lives, and looks likely to become a permanent fixture. Zhou Jiangyong, the Communist Party secretary of the eastern city of Hangzhou, has said the city's app, which it
28 May 2020
The Chinese city of Hangzhou is considering making the app it requires residents to download and install for the COVID-19 crisis and that controls whether and where residents may travel a permanent fixture to create a "firewall to enhance people's health and immunity". Other countries may follow
21 May 2020
Technical flaws in Moscow's app, intended to track people with COVID-19 and symptoms of other respiratory diseases, led the authorities to wrongly fine hundreds, perhaps even thousands, of people, alleging they had breached self-quarantine. The app was originally launched at the end of March, but
27 May 2020
The lower house of the French parliament paved the way for the launch of the government's independently-developed contact tracing app. The minister in charge, technology minister Cedric O, praised the app, developed by companies such as Orange and Dassault Systemes, as a French project "with the
25 May 2020
As part of a survey of the human rights compliance of contact tracing apps Amnesty International's Security Lab discovered that security vulnerabilities in Qatar's mandatory contact tracing app, EHTERAZ, would have allowed attackers to access the personal information, including name, national ID
23 May 2020
Contact tracing apps will only work effectively if people trust them and install them in sufficient numbers. Soon after its launch, however, the North Dakota contact tracing app people were already dropping it after posting complaints in the Google App store. In a survey of 798 Americans
05 May 2020
On the day South Korea relaxed its social distancing measures, a 29-year-old man tested positive for COVID-19. The previous weekend, he had visited five nightclubs in the gay district of Itweon in Seoul, mingling with around 7,200 other people. After nearly 80 new COVID-19 cases have been linked to
26 May 2020
South Korea's second spike in coronavirus cases was curbed via a contact tracing regime that uses credit card records, mobile phone tracking, and GPS location data in order to track the previous movements of infected individuals working alongside efficient diagnostic testing. Successfully tracing an
23 May 2020
The best contact tracers in US history were a group of mid-20th century venereal disease investigators working for a programme at the Centers for Disease Control and Prevention whose strategy eventually led to the eradication of smallpox in the 1970s. Talking to infected people and tracking down
25 May 2020
Local health authorities in Germany have relied on human contact tracers since the country confirmed its first COVID-19 cases early in 2020, and say that doing so has helped the country keep its death rate comparatively low even with a less restrictive lockdown than many other countries. Germany
25 May 2020
Latvia became one of the first countries to use Apple's and Google's new joint toolkit to launch a smartphone contact tracing app, Apturi Covid. For now, the app will only work for Latvia's 2 million citizens, but the intention is that it should interoperate with the apps other countries to aid
27 May 2020
An Ipsos MORI survey conducted on May 20-22 found generally high levels of compliance with lockdown restrictions, though many were suffering. While roughly three-quarters were confident they could download and operate a contact tracing app and would be willing to comply with its recommendations
03 May 2020
Only 16% of Australians had downloaded the country's COVIDSafe app by May 3, a week after its launch on April 26, even though most said they support the federal government's coronavirus contact tracing app. In an Ipsos poll, 80% of those who said they were unlikely to download the app cited privacy
06 May 2020
Shortly after launch, security researcher Baptiste Robert discovered that India's contact tracing app, Aarogya Setu ("Health Bridge"), allows users to spoof their GPS location, find out how many people reported themselves as infected within any 500-metre radius, and mount a triangulation attack to
07 May 2020
In a technical analysis of the UK NHSx contact tracing app for iOS, security engineers find that Apple's Bluetooth design makes it harder to detect iPhones running the app in background mode, and the app is using "keepalive" notifications in order to keep the app able to make the necessary
14 Apr 2020
Our partners from Hiperderecho in Peru proposed 15 measures to improve the COVID-19 app that the Peruvian Government is rolling out in the country (in Spanish). Link:
21 Apr 2020
The French government asked Apple to change the way its phones handle Bluetooth in order to accommodate the design of its contact tracing app. Downloading and installing the app will be voluntary, but the app will use a centralised design in which the data will be fed into a government server for
29 Apr 2020
Numerous efforts to create apps to help monitor and map the spread of COVID-19 rely on satnav-based location data from Galileo. The CovTrack app developed on a pro-bono basis by the Romanian company RISE, for example, uses Bluetooth connections between mobile phones to store identification data the
30 Apr 2020
Researchers at the University of Cape Town are developing the smartphone app COVI-ID to help the South African government track people who may not know they have contracted COVID-19, as well as people who have come into contact with those who have tested positive. The app will use Bluetooth and
26 Apr 2020
A reverse-engineering analysis of Vietnam's official Bluetooth-based contact tracing app, Bluezone, which was developed by a coalition of local technology companies and the Ministry of Information and Communications, shows that the app is broadcasting a fixed six-character ID the app assigned to
30 Apr 2020
The Indian authorities have said that the country's contact-tracing app, Aarogya Setu ("health bridge", in Sanskrit), will be voluntary - but mandatory for federal government employees, food delivery workers, and some other service providers. It may also be needed to access public transport and
30 Apr 2020
Two million people downloaded Australia's COVIDSafe app in the first four days it was available; the government's goal is to reach 10 million, or about 40% of the population. Users are asked for a (not necessarily real) name, age, mobile number, and postal code. The app exchanges a Bluetooth
22 Apr 2020
Police will be barred from accessing metadata collected by Australia's proposed coronavirus contact tracing app, which will be able to identify when users have been 1.5 metres of each other for more than 15 minutes, Australia's government services minister, Stuart Robert, and prime minister, Scott
21 Apr 2020
By May 11, the Swiss Federal Office of Public Health, working with EFPL and ETH Zurich, will launch a secure, decentralised system for contact tracing developed by the Decentralised Privacy-Preserving-Proximity Tracing (DP-3T) international consortium, whose Swiss partners are Ubique and
20 Apr 2020
A data breach that posted 100 to 200 names, email addresses, and encrypted passwords online was found in the Belgian Covid-19 Alert! app, one of seven candidates for adoption by the Dutch government. The app identifies phones that have been close to each other via Bluetooth signals and can send them
26 Apr 2020
Three days after announcing Germany would adopt the centralised Pan-European Privacy-Preserving Proximity Tracing (PEPP-PT) standard for contact tracing, the country's chancellery minister Helge Braun and health minister Jens Spahn announced they would instead use the decentralised approach backed
15 Apr 2020
India's COVID-19 tracker app, Aarogya Setu, was downloaded 50 million times in the first 13 days it was available. Developed by the National Informatics Centre a subsidiary of the Ministry of Electronics and IT, the app is available on both Android and iOS smartphones, and uses GPS and Bluetooth to
15 Apr 2020
The Australian government's planned contact tracing app will reportedly be based on Singapore's TraceTogether, which relies on Bluetooth connections to detect other phones in range and log the results, so that if a phone user tests positive for COVID-19 and consents their close contacts can be
09 Apr 2020
The Norwegian contact tracing app, Infection Stop, relies on a centralised database to store users' GPS locations for 30 days, like its Chinese counterpart. Sumula, the company that developed the app, claims is necessary because of technical limitations in Apple's smartphone operating system iOS
10 Apr 2020
Apple and Google have announced a partnership to enable governments and health agencies to use Bluetooth for proximity-based contact tracing to help reduce the spread of the novel coronavirus while preserving user privacy and security. The effort is due to begin with the May release of APIs that
01 Apr 2020
Led by Germany's Fraunhofer Heinrich Hertz Institute for Telecoms, technologists and scientists from at least eight countries, are working on a proximity-based contact tracing technology that complies with GDPR. The Pan-European Privacy-Preserving Proximity Tracing project (PEPP-PT) is intended to
01 Apr 2020
On April 1, Iceland launched an app that uses GPS to locate people who may have been in close contact with confirmed COVID-19 patients. A message containing a download link for the app will be sent to all Icelanders; downloading it and then agreeing to disclose GPS data are both voluntary, but for
24 Mar 2020
Researchers at Germany's Robert Koch Institute and Fraunhofer Heinrich Hertz Institute are working on an app that uses Bluetooth connections between smartphones and is compliant with GDPR to anonymously save the distance and duration of contact between people on the smartphone to make it possible to
26 Mar 2020
Indonesian Ministry of Communication and Informatics/KOMINFO official website) On Thursday, 26 March 2020, the Indonesian Minister of Communication and Informatics, Johnny G. Plate, issued the Ministerial Decree No. 159/2000 to facilitate the cooperation between the Government and telecommunication
24 Mar 2020
The success of South Korea's efforts to combat the coronavirus without a national lockdown and without suspending civil rights depended in part on preparation put in place after the 2015 MERS epidemic and in part on the country's network of private testing labs, which enabled the country to quickly