The concern for location privacy in mobile applications is commonly motivated by a scenario in which a mobile device communicates personal location data, i.e. the device holder location, to a third party e.g. LBS provider, in exchange for some information service. We argue that this scenario offers a partial view of the actual risks for privacy, because in reality the information flow can be more complex. For example, more and more often location is computed by a third party, the location provider, e.g. Google Location Service. Location providers are in the position of collecting huge amounts of location data from the users of diverse applications (e.g. Facebook and Foursquare to cite a few). This raises novel privacy concerns. In this paper, we discuss two issues related to the protection from location providers. The first focuses on the compliance of emerging location services standards with European data protection norms; the latter focuses on hard privacy solutions protecting from untrusted location providers.
General rights Copyright and moral rights for the publications made accessible in the public portal are retained by the authors and/or other copyright owners and it is a condition of accessing publications that users recognise and abide by the legal requirements associated with these rights.-Users may download and print one copy of any publication from the public portal for the purpose of private study or research-You may not further distribute the material or use it for any profit-making activity or commercial gain-You may freely distribute the URL identifying the publication in the public portal Take down policy If you believe that this document breaches copyright, please contact us providing details, and we will remove access to the work immediately and investigate your claim.
The standard W3C Geolocation API can significantly facilitate geospatial data collection as it provides a simple set of operations for requesting geolocation services across indoor and outdoor spaces through the Web. Importantly, this API is privacy-aware in that it provides a basic privacy mechanism for requesting the user's consent to location acquisition. In this paper we address the question on whether this privacy mechanism is su cient to conduct a project for the collection of geospatial content, in compliance with privacy laws. The question is of practical relevance as the use of geolocation standards in line with privacy regulations would make the development of volunteered geography projects easier. In this paper we present an interdisciplinary analysis spanning across technology and law, and driven by an application case. We show the limitations of this API and discuss a possible extension in line with privacy norms. Although we confine ourselves to consider European regulations, we believe that this study can be of more general concern.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.