Data protection with Alexa Amazon: How secure are we?
Alexa is Amazon's digital voice assistant, whose software is built into dozens of smart speakers (e.g., Amazon Echo, Echo Dot). Alexa offers a range of features and capabilities, including controlling and coordinating a smart home, managing to-do lists, playing music or audiobooks, shopping on Amazon, and searching for information or current events. However, alongside all the benefits of a smart home, questions are increasingly being raised about Alexa and Data protection or how data protection Alexa Amazon fit together.
As voice assistants become increasingly common in many households, the question of intrusion into Privacy and of Alexa and data protection One of the most frequent accusations concerns the ongoing Processing and linking of a lot of data and users' fear of being bugged by smart speakers.
In order to carry out voice commands, Alexa must be able to hear and recognize them. That’s why she’s always listening, so she can respond to potential voice commands. In practice, the microphones are constantly active so that Alexa can respond to the wake word (e.g., „Alexa“), which triggers the processing of the voice command. The information is processed and transmitted to Amazon’s backend servers only after the wake word is spoken.
From the point of view of Alexa data protection, there is always a risk of unintentional activation of the Data Transmission by saying a word that resembles the correct activation code (e.g., „Alexander“ instead of „Alex“), which results in an unintended intervention in the Privacy of the people being eavesdropped on (the Alexa user, their guests, or their housemates). The consumer advice centers have already pointed out these problems and risks in a comprehensive investigation/study[1].
A concern regarding the use of voice assistants also relates to the control that data subjects have over their data. According to Recital. 7 GDPR, the affected persons have control over their own data. In view of the volume, the sensitivity (the "voice" is a biometric data file within the meaning of Art. 9 GDPR) and the linking of the data processed, the original and further purposes of the Processing (e.g. the execution of the command, the improvement of the service, the creation of personalized user profiles), the number of parties involved in the data processing (the provider and third parties), the affected people lose control of their data.
Therefore, it is of the utmost importance to comply with data protection principles (Data minimizationMemory limitation, Earmarking) and to enable data subjects to exercise their data protection rights, in particular the Right to information and the right to Deletion. The voice recordings can already be managed by the individuals concerned through the Alexa app (access to the stored data; the option to automatically delete the data or set a time limit for storage, etc.).
To enable the privacy-friendly use of voice assistants, the European Data Protection Board[2] („EDPB“) and the French Regulatory Authority[3] the most important challenges in complying with the GDPR Compliance rules published and recommendations made. Alexa and data protection or data protection Alexa Amazon therefore go together under certain conditions.
Sources:
- [1] Consumer Advice Center, „Tuning Out or All Ears? Data Protection with Amazon Echo and Google Home,“ March. www.verbraucherzentrale.de/sites/default/files/2019-11/hintergrundpapier_digitale_sprachassistenten_technisch_2.pdf
- [2] The European Data Protection Board, Guidelines 02/2021 on virtual voice assistants, July 7, 2021. edpb.europa.eu/system/files/2021-07/edpb_guidelines_202102_on_vva_v2.0_adopted_en.pdf
- [3] CNIL, “Exploring the Ethical, Technical, and Legal Issues Surrounding Voice Assistants,” September 2020. www.cnil.fr/sites/default/files/atoms/files/cnil_livre-blanc-assistants-vocaux.pdf





