Emerging Privacy Challenges

This module poses some questions for you relating to emerging or future privacy challenges. How, for example, can we build a privacy-preserving metaverse and Web 3.0? Will you soon need to wear a disguise or behave angrily in the supermarket to get the best price? And what novel privacy expectations might the first travellers to Mars have?

Virtual and Augmented Reality

“This poses a very serious privacy risk, as it potentially eliminates anonymity in the metaverse … ‘Moving around in a virtual world while streaming basic motion data would be like browsing the internet while sharing your fingerprints with every website you visit. However, unlike web-browsing, which does not require anyone to share their fingerprints, the streaming of motion data is a fundamental part of how the metaverse currently works.’”

A recent research study found that users could be uniquely identified at scale across multiple sessions using just a short sample of their head and hand motion. With a 10 second recording, accuracy was around 73%, and with 100 seconds of motion, accuracy was over 94%. This is a significant and troubling finding. It means that motion (biomechanics) data - which is of course necessary for VR to work, from initial device calibration to the user’s ongoing interactions with the VR world - would likely be considered biometric data under the EU’s GDPR. This special category of sensitive personal data requires a stronger legal basis for processing and potentially also a privacy impact assessment. And expecting your employees to come to work to your virtual office in the metaverse might be illegal under employee data protection law. This article (quoted above) discusses this in more detail and proposes some mitigations, such as adding noise to the motion data to make it less identifiable.

Web3 Privacy and Digital Identity


