TechCrunch News 2024年12月20日
World(coin) must let Europeans comprehensively delete their data, under privacy order
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Worldcoin因其虹膜扫描数据处理方式受到巴伐利亚数据保护机构的调查,并被要求在用户请求时删除数据。该机构认为Worldcoin的数据处理方式不符合GDPR规定,特别是关于用户数据删除权和明确同意的要求。尽管Worldcoin声称其技术架构具有隐私保护性,并对删除用户数据持保留态度,但监管机构强调用户对其个人信息应有自主权。Worldcoin已对此决定提出上诉,认为其数据是匿名化的,不受GDPR管辖。然而,其他欧洲国家也对其进行了监管行动,凸显了该项目在欧洲面临的隐私挑战。

👁️‍🗨️ 巴伐利亚数据保护机构要求Worldcoin在用户请求时全面删除虹膜数据,并要求其在未来处理步骤中获得明确的用户同意。此举源于对Worldcoin数据处理方式的GDPR合规性调查,特别是关于用户数据删除权的问题。

🔒 Worldcoin辩称其技术架构具有隐私保护性,用户数据被匿名化处理,因此不应受GDPR数据删除权限制。他们认为,匿名化数据不在GDPR的管辖范围内,且删除数据会影响其建立全球身份验证系统的目标。

⚖️ 监管机构强调,GDPR不仅保护用户隐私,还确保用户对其个人信息拥有自主权。Worldcoin目前的数据处理方式未能充分支持这一自主权,因此需要做出调整以符合欧盟的法规要求。

🌍 Worldcoin在欧洲其他地区也面临监管挑战,包括葡萄牙和西班牙的紧急行动,这些行动导致其暂停了虹膜扫描业务。这些监管机构特别关注儿童数据被永久捕获的风险,这也进一步加剧了Worldcoin在欧洲的监管压力。

It took a lot more than the initially slated few weeks to arrive, but a pivotal privacy decision that’s been hanging over Sam Altman’s World (aka Worldcoin) for months has finally landed, via a late December decision from the Bavarian data protection authority enforcing the bloc’s General Data Protection Regulation (GDPR), a comprehensive privacy framework that allows for sanctions that can reach up to 4% of global annual turnover.

Despite a decision on an investigation that opened back in April 2023 only — finally — slipping out just before the 2024 holiday break, the outcome doesn’t look like what the eyeball-scanning crypto identity venture was hoping for: it has been issued with a corrective order that requires it to comprehensively delete user data on request.

“All users who have provided ‘Worldcoin’ with their iris data will in future have the unrestricted opportunity to enforce their right to erasure,” said the Bavarian State Office for Data Protection Supervision, Michael Will, in a press statement.

The biometric venture has been given one month from the Bavarian authority’s decision date to implement a deletion procedure “that complies with the provisions of the GDPR” — so mark your calendars for early 2025.

A further component of the Bavarian order requires Worldcoin to obtain explicit consent for what the press statement (vaguely) describes as “certain processing steps in the future”.

We’ve asked for more details but this suggests World’s onboarding process will have to provide EU users with more information prior to eyeball scans being taken. It has also been ordered to delete “certain data records previously collected without a sufficient legal basis”, per the statement.

In addition to our questions about the substance of what’s been ordered, we’ve asked the Bavarian authority why no penalty has been issued for what appear to be a number of GDPR breaches and will update this report with any response.

World has responded to the corrective order by saying it will lodge an appeal.

Why does a requirement to let users ask for their data to be deleted, a right that’s baked into the European regulation as part of the GDPR’s suite of individuals data access rights, look so tricky for World[coin]? The proof-of-humanness blockchain project’s jam is that it’s building a system of immutable and unique IDs for verifying identity remotely. So if a person can edit all trace of themselves out of its ledger simply by asking it’s a challenge to its ambition of becoming a world-spanning authority on human verification.

Tools for Humanity (TfH) spokeswoman, Rebecca Hahn — who does comms for the entity that develops Worldcoin — said its grounds for appeal will focus on claims that World’s technical architecture is “privacy-preserving” and that results in user data being anonymized.

The implication of that being that GDPR data access rights (such as being able to ask for deletion) should not apply, since truly anonymous data falls outside the scope of the law.

Responding on why World is so reluctant to let users delete data, Damien Kieran, TfH’s chief privacy officer, also told TechCrunch: “Our goal is to increase trust in digital interactions. To do that, we created the World’s first anonymous digital passport to prove humanness. That means a person can anonymously verify they are a real human on a platform like X [which happens to be Kieran’s former employer] solving problems such as bots once and for all.

“Key to that is ensuring that if an anonymous person abuses a platform’s policies and the platform suspends them, that person cannot delete their World ID, create a new one and go back to X presenting themselves as a new human. Thus to meet our goals of increasing trust online in the intelligence age, we had to ensure we did this in a way that anonymized the underlying data, meaning it can’t be deleted, and ensures that bad actors can’t abuse the World network and other platforms.” 

Kieran added that World ID holders “can always delete their personal data which resides solely on their phone”.

However basic account data isn’t where this GDPR battle is focused. It’s about information that can be used to uniquely identify an individual.

Earlier this year World introduced an open source Secure Multi-Party Computation system which it claimed “allows iris codes to be encrypted as secret shares and distributed over multiple participants” — without the need for the codes to be decrypted in order for identity checks to take place.

The suggestion is that this technical architecture transforms iris codes through subsequent processing, including encryption and sharding, in a way that limits individual privacy risks.

As part of these changes Worldcoin also introduced a feature letting users request deletion of their iris codes. However the level of control it’s giving users has — evidently — been assessed as not meeting the GDPR’s standard requiring individuals to have control over their information.

And it’s important to stress that the GDPR not only sets rules to protect people’s privacy; the framework also aims to ensure individuals can have autonomy over information held about them. It’s that latter element that poses the biggest challenges to World’s proof-of-humanness mission as it does not factor in supporting that level of individual autonomy.

The Bavarian DPA said Worldcoin’s biometric-based individual verification procedure entails “a number of fundamental data protection risks for at least a large number of data subjects”. And while the authority’s statement makes a reference to “improvements” made to the venture’s data processing it stresses that “adjustments are still required”.

The authority added that its lengthy investigation ended up centered on the need for “comprehensive erasion following withdrawal of consent”; and “the associated review of the consent process”.

“With today’s decision, we are enforcing European fundamental rights standards in favor of the data subjects in a technologically demanding and legally highly complex case,” said Will.

World’s appeal against the Bavarian corrective order does not address the crux data access issue head on.

Rather it’s seeking to frame the matter as a technical question, of how European law should define anonymous data. Hence its blog post about the corrective order kicks off with the line that “World ID is anonymous by design.” But trying to build momentum for a lobbying that Europeans deserve fewer individual rights is unlikely to be regionally popular.

Worldcoin has already seen his wings clipped around the region. Enforcement action from other data protection authorities — including in Portugal and Spain — saw it subject to emergency action that shut down its eyeball scanning ops in their markets. The two DPAs raised particular concerns about the risks of children’s data being indelibly captured.

At the same time, Worldcoin — or World as it recently rebranded — has opened ops in Austria.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Worldcoin GDPR 数据隐私 生物识别 虹膜扫描
相关文章