Does Alexa comply with data protection?

Alexa and data protection
Categories:

Data protection with Alexa Amazon: How secure are we?

Alexa is Amazon's digital voice assistant, whose software is integrated into dozens of smart speakers (e.g. Amazon Echo, Echo Dot). Alexa has a range of functionalities and skills, including controlling and coordinating the smart home, managing to-do lists, playing music or audio books, shopping on Amazon or researching information or current events. In addition to all the advantages of a smart home, however, the question of Alexa and Data protection or how data protection Alexa Amazon fit together.

While voice assistants are increasingly finding their way into many households, the question of interference in the Privacy and of Alexa and data protection One of the most frequent accusations concerns the ongoing Processing and linking of a lot of data and users' fear of being bugged by smart speakers.

To be able to execute voice commands, Alexa must be able to hear and recognize them. That is why she always has an open ear to respond to possible voice commands. In practice, the microphones are permanently active so that Alexa can respond to the activation code (e.g. "Alexa"), which triggers the processing of the voice command. The information is processed and transmitted to Amazon's backend servers only after the activation code has been spoken.

From the point of view of Alexa data protection, there is always a risk of unintentional activation of the Data transmission by pronouncing a word that resembles the correct activation code (e.g. "Alexander" instead of "Alex"), resulting in an unintentional intrusion into the Privacy of those being monitored (the Alexa user, their guests or their cohabitants). The consumer advice centers have already pointed out these problems and risks in a comprehensive investigation/study[1].

A concern regarding the use of voice assistants also relates to the control that data subjects have over their data. According to Recital. 7 GDPR, the affected persons have control over their own data. In view of the volume, the sensitivity (the "voice" is a biometric data file within the meaning of Art. 9 GDPR) and the linking of the data processed, the original and further purposes of the Processing (e.g. the execution of the command, the improvement of the service, the creation of personalized user profiles), the number of parties involved in the data processing (the provider and third parties), the affected people lose control of their data.

It is therefore extremely important to comply with the data protection principles (Data minimizationMemory limitation, Earmarking) and to enable data subjects to exercise their data protection rights, in particular the Right to information and the right to Deletion. The voice recordings can already be managed by the data subjects in the Alexa app (access to the stored data; option to automatically delete the data or set a limited storage period, etc.).

In order to enable the data protection-friendly use of voice assistants, the European Data Protection Board[2] ("EDPB") and the French Supervisory authority[3] the most important challenges in complying with the GDPR Compliance rules published and recommendations made. Alexa and data protection or data protection Alexa Amazon therefore go together under certain conditions.

 

Sources:

  1. [1] Consumer advice center, "On the ball or all ears? Data protection with Amazon Echo and Google Home", March. www.verbraucherzentrale.de/sites/default/files/2019-11/hintergrundpapier_digitale_sprachassistenten_technisch_2.pdf
  2. [2] The European Data Protection Board, Guidelines 02/2021 on virtual voice assistants, July 7, 2021. edpb.europa.eu/system/files/2021-07/edpb_guidelines_202102_on_vva_v2.0_adopted_en.pdf
  3. [3] CNIL, Exploration des enjeux éthiques, techniques et juridiques des assistants vocaux, September 2020. www.cnil.fr/sites/default/files/atoms/files/cnil_livre-blanc-assistants-vocaux.pdf
Tags:
Share this post :