5G Positioning: Security and Privacy Aspects 309
adapted to the digital realm and tracking technologies through case law (US v. Jones). This
development has also led to geolocation technologies being viewed from the perspective
of reasonable expectations [59]. If personal data are transferred from the EU to the US, the
receiving organization based in the latter has to join the so‐called Privacy Shield program
to guarantee an adequate level of data protection (see art 25 DPD; art 45 GDPR [35]) or
some other legal basis must exist (Ch. IV DPD; Ch. V GDPR [35]).
13.11.8 Challenges and Future Scenarios in Legal Frameworks and Policy
Whereas location‐based services previously tended to be based on individuals’ prior
requests – whether for one‐off use or more long‐lasting use of location data (e.g. for
navigation) – currently, many applications and services would rather rely on locating
and tracking individuals [38]. This development is bound to accelerate with IoT and
new technologies. Furthermore, the integrity of data becomes an important issue. With
5G, there are elevated risks involved with regard to unintentional disclosures of location
data or data misuse and abuse; also where data is intentionally made available to service
providers and app developers. Indeed, the constant evolution of technologies behind
location‐based application and services inherently poses risks with regard to location
data and position privacy [1,40].
The legal framework provided by the general data protection law in the EU has a wide
scope of applications, both in terms of substance and territory. Moreover, more specific
issues are tackled, for instance in the ePrivacy Directive. On a global scale, or from a US
perspective, the view might not be the same. Since 5G has international implications
starting from spectrum and standards all the way to the global reach of potential applications, a lack of a common approach to privacy and data protection could be problematic.
Current policies around 5G development largely focus on investments, business, and
technological issues, while in research papers privacy has also gained attention, mainly
Table 13.3 Summary of EU legal instruments.
Instrument
What?
Who?
Legitimate processing
DPD
personal data
any controller
any processor
● (explicit) consent/legal ground
● information
● principles of processing
● data subject’s rights
● security
GDPR
personal data
any controller
any processor
● (explicit) consent/legal ground
● information
● data protection by design
● data subject’s rights
● security
ePrivacyD
traffic data/location data
telecom operator
● legal ground/(prior) consent
● information
● user/subscriber rights
● security
adapted to the digital realm and tracking technologies through case law (US v. Jones). This
development has also led to geolocation technologies being viewed from the perspective
of reasonable expectations [59]. If personal data are transferred from the EU to the US, the
receiving organization based in the latter has to join the so‐called Privacy Shield program
to guarantee an adequate level of data protection (see art 25 DPD; art 45 GDPR [35]) or
some other legal basis must exist (Ch. IV DPD; Ch. V GDPR [35]).
13.11.8 Challenges and Future Scenarios in Legal Frameworks and Policy
Whereas location‐based services previously tended to be based on individuals’ prior
requests – whether for one‐off use or more long‐lasting use of location data (e.g. for
navigation) – currently, many applications and services would rather rely on locating
and tracking individuals [38]. This development is bound to accelerate with IoT and
new technologies. Furthermore, the integrity of data becomes an important issue. With
5G, there are elevated risks involved with regard to unintentional disclosures of location
data or data misuse and abuse; also where data is intentionally made available to service
providers and app developers. Indeed, the constant evolution of technologies behind
location‐based application and services inherently poses risks with regard to location
data and position privacy [1,40].
The legal framework provided by the general data protection law in the EU has a wide
scope of applications, both in terms of substance and territory. Moreover, more specific
issues are tackled, for instance in the ePrivacy Directive. On a global scale, or from a US
perspective, the view might not be the same. Since 5G has international implications
starting from spectrum and standards all the way to the global reach of potential applications, a lack of a common approach to privacy and data protection could be problematic.
Current policies around 5G development largely focus on investments, business, and
technological issues, while in research papers privacy has also gained attention, mainly
Table 13.3 Summary of EU legal instruments.
Instrument
What?
Who?
Legitimate processing
DPD
personal data
any controller
any processor
● (explicit) consent/legal ground
● information
● principles of processing
● data subject’s rights
● security
GDPR
personal data
any controller
any processor
● (explicit) consent/legal ground
● information
● data protection by design
● data subject’s rights
● security
ePrivacyD
traffic data/location data
telecom operator
● legal ground/(prior) consent
● information
● user/subscriber rights
● security
