France’s data protection watchdog reviews contact-tracing app StopCovid

France’s data protection watchdog CNIL has released its second review of StopCovid, the contact-tracing app backed by the French government. The CNIL says there’s no major issue with the technical implementation and legal framework around StopCovid, with some caveats.
France isn’t relying on Apple and Google’s contact-tracing API. Instead, a group of research institutes and private companies have worked on a separate solution.
At the heart of StopCovid, there’s a centralized contact-tracing protocol called ROBERT. It relies on a central server to assign a permanent ID and generate ephemeral IDs attached to this permanent ID. Your phone collects the ephemeral IDs of other app users around you. When somebody is diagnosed COVID-19-positive, the server receives all the ephemeral IDs associated with people with whom they’ve interacted. If one or several of your ephemeral IDs get flagged, you receive a notification.
ROBERT has been a controversial topic as it isn’t an anonymous system — it relies on pseydonymization. It means that you have to trust your government that it isn’t collecting too much information and it doesn’t plan to put names on permanent IDs.
But the CNIL says that ROBERT focuses on exposed users instead of users who are diagnosed COVID-19-positive — it is “a choice that protects the privacy of those persons,” the agency says. The CNIL also says that ROBERT tries to minimize data collection as much as possible.
Inria released a small portion of the source code that is going to power StopCovid a couple of weeks ago. The research institute originally said that some parts wouldn’t be open-sourced. The CNIL contested this decision and Inria has now reversed its stance and the government promises that everything will be released, eventually.
The StopCovid development team is also launching a bug bounty program in partnership with YesWeHack following recommendations from France’s national cybersecurity agency (ANSSI).
On the legal front, the draft decree excludes data aggregation in general. For instance, the government won’t be able to generate a heat map based on StopCovid data — StopCovid doesn’t collect your location anyway.
The CNIL says that the government promises that there won’t be any negative consequence if you’re not using StopCovid, nor any privilege if you’re using it. The government also promises that you’ll be able to delete pseudonymized data from the server. All of this is still ‘to be confirmed’ with the final decree.
Finally, the CNIL recommends some changes when it comes to informing users about data collection and data retention — it’s hard to understand what happens with your data right now. There should be some specific wording for underage people and their parents as well.
In other news, the government has sent me some screenshots of the app. Here’s what it looks like on iOS:
France’s digital minister, Cédric O, will be in front of parliament members tomorrow to debate the pros and cons of StopCovid. It’s going to be interesting to see whether the French government has managed to convince parliament members that a contact-tracing app is useful to fight the spread of COVID-19.
France’s data protection watchdog CNIL has released its second review of StopCovid, the contact-tracing app backed by the French government. The CNIL says there’s no major issue with the technical implementation and legal framework around StopCovid, with some caveats. France isn’t relying on Apple and Google’s contact-tracing API. Instead, a…
Recent Posts
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010