Hello, dear friend, you can consult us at any time if you have any questions, add WeChat: THEend8_
HKUST ISOM 5230 Privacy management
in the digital age
Assignment
Assignment on Privacy Analysis
Distribution of this assignment publicly or to third-party is not authorised
(Due by the fourth week on 20 September 2023)
The case
COVID-19 Tracker App
1. COVID 19 Omicron (Omicron) is hitting hard in many places and the mortality rate is
still high.
2. There is a mandated government policy to combat Omicron by identifying and isolating
those infected or possibly infected in order to break the chain of infection.
3. Hypothetically the health authority in a jurisdiction has decided to build an app and
mandate all its citizens to install and use it.
4. Self-reporting of whereabout by the infected, and voluntary checking and isolation by
close contacts have proved to be unacceptably ineffective. The app is therefore
considered necessary to address the issue, and be mandated to be used by everyone.
5. During installation, the app shows the following privacy notice (or Personal
Information Collection Statement):
i. This app collects your location information for the purpose of identifying those
who are in close contact with the infected.
ii. Your mobile service provider will pass your name and residential addresses to
the health authority. If you are at risk, the health authority can then locate you.
iii. You must allow the collection of your locations.
6. Once the app user accepts the privacy notice, the mobile service provider will upload
the subscriber information (all the details obtained by the mobile service provider
during the initial service registration/subscription) to a central database in the public
cloud. This jurisdiction requires, by law, all mobile service users to provide verified
real name/ID and residential address during service registration.
7. Using GPS and A-GPS, the app, even when it is not running in the foreground, will
track the positions of where its holder goes, and upload the locations (including date,
time and duration) to the central database in the public cloud.
8. When anyone is diagnosed with Omicron by the health authority, the information will
be uploaded by the relevant health authority clinic to the central database in the public
cloud, and the system will disclose the names of the infected to those who have been
identified as having close contact with the infected (by SMS) and advise them to stay
HKUST ISOM 5230 Privacy management
i