EU offers privacy guidelines for RFID

February 22, 2005, 10:57 AM —  IDG News Service — 

The European Union (E.U.) has expressed concern that the use of RFID (radio frequency identification) technology by businesses and governments could violate human dignity as well as data protection rights and has published guidelines for businesses and agencies intending to use the technology.

The E.U.'s executive body, the European Commission, tapped its advisory body on data protection and privacy, known as the Article 29 Working Party, to conduct its first assessment of data protection issues related to RFID. The technology is a method for storing, receiving and transmitting data via antennas on tags that respond to radio frequency queries.

"The ability to surreptitiously collect a variety of data all related to the same person; track individuals as they walk in public places (airports, train stations, stores); enhance profiles through the monitoring of consumer behavior in stores; read the details of clothes and accessories worn and medicines carried by customers are all examples of uses of RFID technology that give rise to privacy concerns," the group wrote in its report, published Jan. 19.

The resulting guidelines include gaining unambiguous consent from individuals where RFID is used and providing clear information to the so-called data subjects including the presence and location of RFID tags and trackers, what sort of data is being collected and how it is being processed. The E.U. also wants individuals to be made fully aware that they have the right to gain complete access to any personal data being collected and stored on them as well as the right to check on the accuracy of the data.

The global RFID market is forecast to be worth US$7.26 billion by 2008, according to a study by IDTechEx Ltd. released Monday. The Cambridge, England-based RFID specialist estimates that by 2008, 46.8 billion tags will be sold for the tracking of medicines, baggage, animals, books and tickets while another 15.3 billion tags will be sold for pallets and cases.

Additionally, by 2010, 48 percent of RFID tags by volume will be sold in East Asia, followed by 32 percent to North America, IDTechEx said.

The E.U. data protection working group said that such widespread use creates a variety of data protection concerns. "The problem is aggravated by the fact that, due to its relative low cost, this technology will not only be available to major actors but also to smaller players and individual citizens," the report said.

The group said it was seeking to provide guidelines not only to those using RFID technology but to manufacturers of RFID tags, readers and applications as well as RFID standardization bodies. For example, the International Organizations of Standardization has developed some sector specific standards for the use of RFID tags on freight containers, transport units and animals, while the International Civil Aviation Organization, which is affiliated with the United Nation, has developed global standards for passports that include RFID chips.

The working group's report urged such standardization bodies to include data protection features in technical specifications. It also called for the use of encryption on tags and applications to prevent unauthorized disclosure of the data collected and stored.

Less likely to be welcomed by businesses is the group's desire to make it easy for individuals to disable RFID tags. "When the individual has a right to withdraw his/her consent or object to the process and the subsequent right to disable the tag, both manufacturers and deployers of RFID technology should ensure that such operation of disabling the tag is easy to carry out," the report said.

The Article 29 Working Party group said it is seeking public consultation until March 31.

IDG News Service

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff

VMware ESX Server in the Enterprise
By Edward L. Haletky
Published Dec 29, 2007 by Prentice Hall.
Enter now! | Official rules | Sample chapter

Green IT
By Toby Velte, Anthony Velte, Robert C. Elsenpeter
To be published Oct. 10, 2008 by McGraw Hill Professional
Enter now! | Official rules | About the book

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

More Resources