Examples of Abuse

Almost everyday a company or government abuses your data. Whether these abuses are intentional or the result of error, we must learn from these abuses so that we can better build tomorrow's policies and technologies. This resource is an opportunity to learn that this has all happened before, as well as a tool to query these abuses.

Please contact us if you think we are missing some key stories.

 

15 May 2020
Many of India’s informal workforce of 450 million people - 90% of the total workforce - were abruptly closed out of their places of employment when prime minister Narendra Modi abruptly ordered a lockdown in April. Left without pay, unable to stay in their living conditions, and with only limited
18 May 2020
France, like the UK, opted to develop its own contact tracing app. "StopCovid", using a centralised design developed by the Pan-European Privacy-Preserving Proxity Tracing (PEPP-PT) group, which created a framework called ROBust and the privacy-presERving proximity Tracing protocol (ROBERT). French
18 May 2020
La Quadrature du Net and La Ligue des Droits de l’Homme have won a ruling from the Conseil d’État, France’s highest administration court, making drones equipped with cameras and flying low enough to detect individuals by their clothing or a distinctive sign illegal. During the lockdown, French
18 May 2020
On 21 April 2020, it was published in the Official Gazette of Mexico City that 4,264 non-salaried workers would be granted basic economic support in a single payment to cope with the health emergency. The Ministry of Labour and Employment Promotion (STyFE) had the possibility to launch this
19 May 2020

Security researchers have found seven problems with the NHSx contact tracing app including: weaknesses in registration that could allow attackers to steal encryption keys; storing unencrypted data on handsets; generating a new random ID code only once a day; and design decisions with respect to Bluetooth connections that could enable tracking. These questions are independent of whether the app is centralised or decentralised.

Writer: BBC; Chris Culnane and Vanessa Teague
Publication: BBC; State of IT
 

19 May 2020
Cameras repurposed as "fever-detecting" aren't designed for and are not very good at detecting infections, but businesses, airlines, major employers, and public officials are nonetheless reacting to the coronavirus pandemic by spending large sums to buy them without understanding their limitations
19 May 2020
Researchers are scraping social media posts for images of mask-covered faces to use to improve facial recognition algorithms. In April, researchers published to Github the COVID19 Mask Image Dataset, which contains more than 1,200 images taken from Instagram; in March, Wuhan researchers compiled the
19 May 2020
As part of its pandemic-related emergency measures, in April the Scottish government extended the deadline for public bodies to respond to freedom of information requests to 40 days. A month later, it was forced to withdraw the changes after opposition parties on the Scottish parliament's COVID-19
19 May 2020
After governments in many parts of the world began mandating wearing masks when out in public, researchers in China and the US published datasets of images of masked faces scraped from social media sites to use as training data for AI facial recognition models. Researchers from the startup
20 May 2020
Both COVID-19 mortality and the economic impact of the virus-related closures are disproportionately affecting the UK’s ethnic minorities after taking age and location into account, exacerbating existing inequalities and reversing what had appeared to be progress. There are also concerns about child
20 May 2020
The outsourcing company Serco, which the UK government has contracted to perform contact tracing, accidentally shared the email addresses of almost 300 of the contact tracers it hired when a staff member sent an introductory email and used CC rather than blind CC. Serco does not intend to refer
21 May 2020
Technical flaws in Moscow's app, intended to track people with COVID-19 and symptoms of other respiratory diseases, led the authorities to wrongly fine hundreds, perhaps even thousands, of people, alleging they had breached self-quarantine. The app was originally launched at the end of March, but
21 May 2020

In an analysis, the smartphone privacy company Jumbo Privacy finds that Care19, North Dakota's official COVID-19 contact tracing app, sends latitude and longitude data and a unique user advertising identifier to Foursquare and other data to Google servers and the bug-tracking Bugfender. The app's privacy policy does not disclose this third-party sharing. The app development company, ProudCrowd, said it would update the privacy policy and that the data-sharing agreement does not allow Foursquare to collect or use the Care19 data beyond returning the names of nearby businesses. North Dakota officials say future versions of the app will incorporate Apple-Google's new Exposure Notification API.



Writer: Steven Melendez
Publication: Fast Company

 

21 May 2020
Immunity passports are likely to increase discrimination and threaten fairness and public health - and won't work for practical reasons. First and foremost, scientists do not yet know whether infection confers immunity or for how long; the serological tests so far developed are insufficiently
21 May 2020
As the waning pandemic leads to signs that the protest movement is resuming, China is moving to draft new national security legislation and incorporate it into Hong Kong's Basic Law, bypassing the territory's Legislative Council. Elections for the Council are due to be held in September, and Chinese
22 May 2020
Following a similar effort in the Netherlands, the UK is planning a national research programme in collaboration with universities, water companies, and public research bodies to detect coronavirus in sewage for use as an early warning system for future outbreaks of COVID-19. About half of those
22 May 2020
Excluded groups such as sex workers and asylum seekers are being left behind in the UK’s COVID-19 response as control measures amplify existing health inequalities and put life-saving advice and care further out of reach. The closure of services and some GP registrations, a lack of access to
25 May 2020
Latvia became one of the first countries to use Apple's and Google's new joint toolkit to launch a smartphone contact tracing app, Apturi Covid. For now, the app will only work for Latvia's 2 million citizens, but the intention is that it should interoperate with the apps other countries to aid
25 May 2020
Numerous companies are repurposing their body monitors, asset trackers, and electronic ankle monitors and marketing them to the newly-created market for strap-on surveillance bracelets to enforce quarantine and social distancing including companies such as AiRISTA Flow. Redpoint Positioning
25 May 2020
As part of a survey of the human rights compliance of contact tracing apps Amnesty International's Security Lab discovered that security vulnerabilities in Qatar's mandatory contact tracing app, EHTERAZ, would have allowed attackers to access the personal information, including name, national ID