North Dakota's COVID-19 app shares user data, raising privacy alarms

A privacy audit of North Dakota's Care19 app reveals it transmits user data to Foursquare and Google, contradicting its stated policy. Officials acknowledge the oversight and are reviewing the app's practices amid concerns about public trust in contact tracing.

North Dakota's COVID-19 app shares user data, raising privacy alarms

Compiled by the editorial desk with reference to official statements, public filings and industry data.

North Dakota's official COVID-19 contact-tracing application, Care19, has been found to transmit user data to third-party firms, including Foursquare and Google, according to a privacy analysis by Jumbo, a consumer privacy company. The disclosure, first reported by The Washington Post, contradicts the app's stated privacy policy, which assures users that their information will not be shared.

The finding has raised concerns not only about the immediate privacy breach but also about the broader implications for public trust in digital health initiatives. Contact-tracing apps are a key tool in the fight against the pandemic, but their effectiveness depends on widespread adoption, which is undermined when users feel their data is not secure.

Jumbo's analysis of Care19, which was developed by ProudCrowd, found that the app sends an advertising identifier along with an anonymous code to these third parties. The company acknowledged the data transmission but maintained that it is not used for commercial purposes. A Foursquare spokesperson told The Washington Post that the data is not used and is promptly discarded.

Despite these assurances, the fact remains that the app's users were explicitly told their data would not be sent to anyone. "Sharing what is supposed to be an anonymous code along with an Advertising Identifier has serious privacy risks," Jumbo's analysis noted.

Privacy breach could undermine COVID-19 response

The incident has prompted a response from state officials. Vern Dosch, North Dakota's contact-tracing facilitator, acknowledged the oversight, stating, "Should this have been vetted? Yes. We are following up on that as we speak. We know that people are very sensitive."

The privacy violation is particularly concerning because it could erode public confidence in the state's handling of the pandemic. If citizens lose trust in the security of contact-tracing apps, they may be less willing to participate in future tracing efforts, which could hamper the state's ability to control the spread of the virus.

This is not the first time that contact-tracing apps have raised privacy questions. In China, a similar app has been criticized for its extensive surveillance capabilities, highlighting the global challenge of balancing public health needs with individual privacy rights.

As North Dakota reviews the app's data practices, the incident serves as a reminder of the importance of rigorous vetting and transparency in the deployment of digital health tools. The state's response to this breach will be closely watched, as it may set a precedent for how other jurisdictions handle similar privacy concerns.