4 ms·
Although there is a remark about the potential legal issues in the US, it should also be noted that capturing and storing MAC addresses without explicit consent
by Cynddl 8y ago
Although there is a remark about the potential legal issues in the US, it should also be noted that capturing and storing MAC addresses without explicit consent is not GDPR compliant, and not legal in Europe.
- hathawsh 8y agoInteresting. What if I own a shop and I want to use this technique to graph the number of people near my shop over time? Would I be in the clear if I hash the MAC addresses?
- komali2 8y agoThe operative word being "collect," the second being "store," what you do between those steps is not really relevant. In other words: no, you probably will not be in the clear. https://iapp.org/news/a/what-the-gdpr-will-mean-for-companies-tracking-location/ https://iapp.org/news/a/what-the-gdpr-will-mean-for-companie...
- thfuran 8y agoOperations before storage don't avoid any legal issues around the collection, but they certainly can obviate legal issues with storing the data. For example, if you 'hashed' them with an algorithm that always yield 0, you'd surely be in the clear as far as the storage goes. Probably you'd still be fine if the output of the hash was 1 bit. I don't know whether you'd still be in the clear for more common hash algorithms.
- jcoffland 8y agoStoring the hash is not the same as storing the actual data.
- tantalor 8y agoThe hash of PII is still PII.
- eeeeeeeeeeeee 8y agoCouldn't almost any WiFi router, and thus the user of that router, then be in violation of GDPR simply by logging which MAC addresses attempt to connect to that router? Even connections by accident (selecting the wrong SSID). I know my Netgear router has a history of basically any connection attempts and their MAC address; it does this by default, not sure I can even turn it off. And how would you even present a GDPR notice to the user prior to logging that kind of information?
- matte_black 8y agoNo one said GDPR was well thought out.
- lccarrasco 8y agoDepends if you can argue successfully that a MAC Address is Personal Data or not.
- casylum 8y agoSticker on the window? There is an issue with retailers tracking shoppers movements in a store. FTC take on the issue: https://www.ftc.gov/news-events/blogs/techftc/2015/04/privacy-trade-offs-retail-tracking https://www.ftc.gov/news-events/blogs/techftc/2015/04/privac...
- jhonkola 8y agoNo. Wifi router needs the MAC address in order to provide a service to the user, thus it is allowed to collect the MAC. GDPR allows collecting personally identifying information if it is necessary for providing the service.
- tastroder 8y agoWould you mind explaining that? I'm pretty certain doing this would get you in trouble with a range of other legislation around the EU and put you in line with similar PR nightmares in the past but I don't really see how MAC addresses alone would be covered by the GDPR (at least not in the text/precedence I'm aware of).
- tombrossman 8y agoNot legal in Europe? That's a bold claim, can you cite any documentation please? I'm in Europe and I know of many local shops, plus at least two pub chains that do this right now. The pub chains are registered with our Information Commissioners office and I am struggling to understand how every one of those people (including the ICO!) could have missed this. I note Bluetooth also uses MAC addresses, so this issue is not limited to WiFi. Spoofing your WiFi MAC on a mobile phone with Bluetooth may not be making you as anonymous as you hope to be.
- Cynddl 8y agoThe ICO addresses the issue of MAC addresses in: https://ico.org.uk/media/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/what-is-personal-data-1-0.pdf https://ico.org.uk/media/for-organisations/guide-to-the-gene... > A business uses Wi-Fi analytics data to count the number of visitors per hour across different retail outlets. It is not necessary to know whether an individual has visited an individual store (or multiple stores) before. > This involves the business processing the Media Access Control (MAC) addresses of mobile devices that broadcast probe requests to its public Wi-Fi hotspots. MAC addresses are intended to be unique to the device (although they can be modified or spoofed using software). > If an individual can be identified from that MAC address, or other information in the possession of the network operator (the business, in this example), then the data is personal data. Indeed, collecting unique MAC addresses, potentially from multiple endpoints, can reveal a lot of personal, sensitive, information (location, trips, time you go to the coffee shop or which hospital you visit, etc.). The only ways to properly collect and store MAC addresses are either using privacy-protecting methods (e.g. cutting the last bits of the MAC address, potentially using bloom filters) or immediately aggregating the collected MAC addresses.