COVID Alert’s Privacy Promises and Surveillance Risks
Résumé analytique
On 31 July 2020 the federal government rolled out COVID Alert, a contact-tracing app meant to enhance manual contact tracing during the COVID-19 pandemic. Because healthcare falls under provincial jurisdiction in Canada, adoption has varied by province: the app launched first in Ontario before going national, with Quebec joining later and others, including the territories, BC, and Alberta, still deciding. This essay provides an overview of the app and assesses how well it addresses the key privacy risks that contact-tracing apps must confront, arguing that COVID Alert handles many of these risks well but that residual drawbacks and limitations remain, so both individuals and policymakers benefit from a clear picture of the resolved and remaining risks when deciding how to use or regulate it.
COVID Alert uses Bluetooth-based proximity detection with localized (decentralized) storage rather than GPS location tracking, placing it in the most privacy-protective quadrant among contact-tracing app designs, though this also limits its functionality relative to more invasive alternatives. The essay identifies risks in two broad categories. First, guarantees against surveillance are imperfect: consent is nominally voluntary, but true voluntariness is questionable given the app's complexity and the risk it becomes informally mandatory through employers or businesses; and anonymity is impossible to fully guarantee, since de-identified data can potentially be re-identified, particularly by linking IP addresses used to upload positive-test tokens, or through inference during lockdowns when contacts are few. The essay notes that at 20 percent adoption, even with perfect detection, the app would catch only about 4 percent of all contacts, and that Canada's oft-cited 60 percent effectiveness threshold would require roughly 22,554,000 people to download and use it.
Second, surveillance and its errors are unevenly distributed. False positives and false negatives carry different costs: false positives can harm mental health and business finances and erode trust in the app, while false negatives can lead infected people to skip quarantine or treatment. These errors, along with the burdens of consent and app use, fall disproportionately on economically vulnerable workers who cannot work from home and face more frequent proximity-based positives, while the most vulnerable to the virus, such as the elderly in care facilities, the homeless, migrants, refugees, and prisoners, are often left out of the app's coverage because they lack access to compatible smartphones. The essay concludes that COVID Alert has robust security measures relative to alternatives, but that policymakers should remain attentive to these risks at both federal and provincial levels, and that users can mitigate them by selectively toggling Bluetooth, understanding the app's workings, calibrating their trust in its output, and exercising judgment before drawing inferences about others.
Publications connexes

Building a Media Ecosystem Observatory from Scratch: Infrastructure, Methodology, and Insights
Lire la suite
Can-PolNews: A Multi-Platform Dataset of Political Discourse in Canada
Lire la suite
Polarization as the Technological Goal – Not the Error
Lire la suite
