Manuel Velasquez/Getty Images
show image

Laurie Clarke

Reporter

Seven in ten global Covid-19 contact tracing apps run on a centralised model

Among the coronavirus contact-tracing apps for which the data model is known, 70 per cent operate on a centralised system globally. This means that the location or proximity tracing data processed by the app is funnelled into a centrally run database (most likely controlled by the government or local health service) rather than being stored locally on the user’s phone.

At present, 43 Covid-19 contact-tracing apps have launched worldwide in 23 countries. For fifteen of these, the data model is unknown, but among the remaining apps, 20 are centralised compared to only eight that are decentralised, according to data compiled by Top10VPN, an organisation that conducts independent research on privacy and security issues. 

The apps that are both state-run (rather than privately-owned) and decentralised include those in Austria, Czech Republic, Iceland, Indonesia, Israel and North Macedonia. Switzerland is also reportedly in the process of developing a decentralised app.

In Europe, the question of whether to build centralised or decentralised coronavirus contact-tracing apps has become the subject of an increasingly heated debate. On Monday, more than 300 academics signed a letter arguing against the development of centralised contact-tracing apps, because data held in a government database is more vulnerable to later misuse, for example as a state surveillance tool. In centralised models, governments (or whoever is running the backend server) are more likely to be able to de-anonymise the data to identify the individuals behind it. 

But centralisation isn’t the only privacy issue. The same data shows that 28 per cent of all contact tracing apps launched worldwide don’t come complete with a privacy policy. However, this figure is massively skewed by India, where of the 16 apps launched, half don’t have a privacy policy in place. India’s state-run contact-tracing Aarogya Setu app has racked up more than 50 million downloads – the most for any app worldwide. Although it does have a privacy policy, it’s one that leaves plenty of leeway for privacy infringements and offers very little transparency. Other countries where state-run apps without privacy policies have launched include Bahrain, Ghana, and Indonesia. 

Interestingly, the data also reveals that 64 per cent of apps have opted to track citizens using GPS data, with the remaining 36 per cent choosing Bluetooth. This is in spite of the fact that Bluetooth is widely recognised to be much more accurate.