3 ms·
The ICO addresses the issue of MAC addresses in: https://ico.org.uk/media/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/what-is-persona
by Cynddl 8y ago
The ICO addresses the issue of MAC addresses in:
https://ico.org.uk/media/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/what-is-personal-data-1-0.pdf https://ico.org.uk/media/for-organisations/guide-to-the-gene...
> A business uses Wi-Fi analytics data to count the number of visitors per hour across different retail
outlets. It is not necessary to know whether an individual has visited an individual store (or multiple
stores) before.
> This involves the business processing the Media Access Control (MAC) addresses of mobile devices
that broadcast probe requests to its public Wi-Fi hotspots. MAC addresses are intended to be unique
to the device (although they can be modified or spoofed using software).
> If an individual can be identified from that MAC address, or other information in the possession of
the network operator (the business, in this example), then the data is personal data.
Indeed, collecting unique MAC addresses, potentially from multiple endpoints, can reveal a lot of personal, sensitive, information (location, trips, time you go to the coffee shop or which hospital you visit, etc.).
The only ways to properly collect and store MAC addresses are either using privacy-protecting methods (e.g. cutting the last bits of the MAC address, potentially using bloom filters) or immediately aggregating the collected MAC addresses.