Scoping review of data privacy risks in COVID-19 apps with digital vaccination certifications

Author:

Amanda Isca1ORCID,Graffin Savannah1,Grando Maria Adela1ORCID

Affiliation:

1. College of Health Solutions, Arizona State University, Phoenix, Arizona, USA

Abstract

The goal was to review mobile apps with COVID-19 digital vaccination certificates between November 2022 and March 2023 and evaluate: (a) compliance with the WHO Proof of Vaccination Scenario requirements, (b) risk levels of app permissions using a Permission Accumulated Risk Score (PARS), and (c) readability and transparency of the app's privacy policies using a Privacy Transparency Index (PTI) score. We found 49 mobile apps with COVID-19 digital vaccination certificates from across 32 countries. Most apps were developed by governments (37/49, 75.51%). We discovered a high positive correlation between the country-wide app total installs and the people vaccinated with at least one dose in the country (r = 0.93, P = <.001). Most apps (97.96%) had sources of information available for compliance with WHO Proof of Vaccination Scenario requirements. Only two apps included all the required data items, while most apps (75%) included five or more data out of nine items. We found that most (97.96%) apps had a Google Play link to generate the Exodus platform permission report, and most (95.92%) apps had an associated privacy policy available. We identified 80 unique permissions; some (23.75%) were dangerous or special. We also found 28 types of trackers. The average PARS was 28.58 (IQR 23.25, range 15–38.25). Most of the apps’ privacy policies documents were difficult or very difficult to read (median grade level 14, IQR 2.6, range 13–15.6). The average PTI was 50.43 (SD 14.73; range 22.5–75). In conclusion, higher compliance with the WHO Proof of Vaccination Scenario requirements is desirable to support interoperability. Developers should limit the number of permissions for essential needs and disclose their purpose. Developers should write privacy policies that a wider audience can understand.

Publisher

SAGE Publications

Reference25 articles.

1. WHO Director-General’s opening remarks at the media briefing on COVID-19 - 11 March 2020. Accessed January 28, 2024. https://www.who.int/director-general/speeches/detail/who-director-general-s-opening-remarks-at-the-media-briefing-on-covid-19—11-march-2020

2. Coronavirus. Accessed January 28, 2024. https://historyofvaccines.org/diseases/coronavirus

3. Digital documentation of COVID-19 certificates: vaccination status: technical specifications and implementation guidance, 27 August 2021. Accessed January 28, 2024. https://www.who.int/publications-detail-redirect/WHO-2019-nCoV-Digital_certificates-vaccination-2021.1

4. How Private Is Your Digital Vaccine Record? Accessed January 28, 2024. https://news.bloomberglaw.com/privacy-and-data-security/how-private-is-your-digital-vaccine-record

5. Privacy Risk Management. ISACA. Accessed January 28, 2024. https://www.isaca.org/resources/isaca-journal/issues/2020/volume-4/privacy-risk-management

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3