Lohan, Alén-Savikko, Chen, Järvinen, Leppäkoski, Kuusniemi, and Korpisaari
310
as a dimension of technological solutions. Importantly, the creation and exploitation of
location‐based applications and services must comply with the legal requirements safeguarding data protection and privacy of individuals. Relevant regulation must be incorporated into every layer, starting from networks, operating systems, and access.
However, there are limits to what legal instruments, including the requirement of
privacy by default, may achieve. Privacy may be enhanced via various control mechanisms, ranging from technical and legal measures to social control (e.g. social and business practices) [100]. Perhaps people should also appreciate their data more and be less
willing to disclose their personal data in exchange for relatively small benefits. Then
again, the usefulness of consenting and purpose limitation, and even data protection by
design (especially data minimization), might be questionable in the context of IoT, cloud
computing, and big data – that is, in the light of collecting massive amounts of data and
having possible future uses that may even be of public benefit [1,7,34]. Nonetheless, one
solution would be to strengthen users’ control mechanisms. This could mean personal
privacy assistants controlling the use of personal big data, encryption for identity verification and purpose specification, or biometrics for access control. With regard to
unique identifiers, randomization could enhance privacy [6,7,34]. The working party
has referred to identity management systems and measures to authenticate access
requests, as well as centralized procedures for operators mediating between third‐party
service providers and users. These arrangements could enhance privacy by leaving individuals unidentifiable by third parties [38].
The steps towards the privacy and security of the location data from a legal perspective are summarized in Figure 13.9.
Which requirements?
justification in the law
consent/explicit consent OR
justification in the law
Which purposes?
communication/billing
value added services, geolocation services, etc.
Which location data?
traffic data
other location data (incl. sensitive data)
anonymization/
erasure
telecom
operator
Figure 13.9 Chart of steps toward location privacy protection.
310
as a dimension of technological solutions. Importantly, the creation and exploitation of
location‐based applications and services must comply with the legal requirements safeguarding data protection and privacy of individuals. Relevant regulation must be incorporated into every layer, starting from networks, operating systems, and access.
However, there are limits to what legal instruments, including the requirement of
privacy by default, may achieve. Privacy may be enhanced via various control mechanisms, ranging from technical and legal measures to social control (e.g. social and business practices) [100]. Perhaps people should also appreciate their data more and be less
willing to disclose their personal data in exchange for relatively small benefits. Then
again, the usefulness of consenting and purpose limitation, and even data protection by
design (especially data minimization), might be questionable in the context of IoT, cloud
computing, and big data – that is, in the light of collecting massive amounts of data and
having possible future uses that may even be of public benefit [1,7,34]. Nonetheless, one
solution would be to strengthen users’ control mechanisms. This could mean personal
privacy assistants controlling the use of personal big data, encryption for identity verification and purpose specification, or biometrics for access control. With regard to
unique identifiers, randomization could enhance privacy [6,7,34]. The working party
has referred to identity management systems and measures to authenticate access
requests, as well as centralized procedures for operators mediating between third‐party
service providers and users. These arrangements could enhance privacy by leaving individuals unidentifiable by third parties [38].
The steps towards the privacy and security of the location data from a legal perspective are summarized in Figure 13.9.
Which requirements?
justification in the law
consent/explicit consent OR
justification in the law
Which purposes?
communication/billing
value added services, geolocation services, etc.
Which location data?
traffic data
other location data (incl. sensitive data)
anonymization/
erasure
telecom
operator
Figure 13.9 Chart of steps toward location privacy protection.
