EC sets out privacy requirements for smart RFID tags

By Paul Meller, IDG News Service |  Mobile & Wireless, privacy, regulation Add a new comment

The European Commission Tuesday set a code of conduct for companies using RFID (radio frequency identification) tags that it hopes will safeguard citizens' privacy and allow the quick rollout of the new technology.

Around 2.2 billion RFID tags were sold worldwide last year, a third of them in Europe, and were installed in a wide range of products including shipping containers and smart cards used in highway toll booths.

The Commission expects the use of RFID tags to grow to five times the current level over the next decade, as tags are added to common consumer items such as bus passes, refrigerators and even clothes.

There is "clear economic potential" in using RFID chips to allow communication between objects, said information society commissioner Viviane Reding in a statement. But she added that European citizens "must never be taken unawares by the new technology."

The Commission's code of conduct, which took the form of a formal recommendation to national governments, was welcomed by the industry.

"We now have clarity and a framework in which manufacturers and retailers can begin or expand deployments to deliver the benefits of RFID for consumers in Europe," said Miguel Lopera, chief executive of GS1 EPCglobal, an organization that promotes RFID standards.

Some companies have delayed development of RFID-based applications, knowing that this Commission recommendation was in progress, Lopera said. Consumers now stand to benefit from reduced prices, improved product availability, faster shipments, as well as post-sales benefits such as faster recalls and better repairs," Lopera added.

The Commission's recommendation comes after a lengthy consultation with privacy groups, consumer groups, retailers and makers of the smart chips, and is designed to allay fears that the new tags could be used to track citizens' movements or compromise their data protection.

It lays out four basic principles to protect privacy that all companies using or making RFID chips must respect:

-- The chip inside an RFID-enabled product must automatically deactivate at the point of sale once the product is bought by a consumer, unless the consumer expressly asks for it to remain active. The Commission said there could be exemptions to this "opt-in" system in cases that did not compromise consumer privacy, but only after an impact assessment and after informing the consumer that the chip would continue to work after the item is purchased.

-- Companies or public authorities using smart chips should give consumers clear and simple information so that they understand if their personal data will be used, the type of data collected (such as name, address or date of birth) and for what purpose. They should also provide clear labeling to identify readers, which are the devices that "read" the information stored in smart chips.

-- Retail associations and organizations should promote consumer awareness on products containing smart chips through a common sign to indicate when products use the technology.

-- Companies and public authorities should conduct privacy and data protection impact assessments before using smart chips. These assessments, reviewed by national data protection authorities, should ensure that personal data is secure and well protected.

The Commission's recommendation doesn't specify how RFID tags should be disposed of after being deactivated.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    Mobile & WirelessWhite Papers & Webcasts

    White Paper

    Ten Steps to an Enterprise Mobility Strategy

    Enterprise employees are more mobile, relishing the ability to work productively anywhere, at any time. They may use any means to get connected, often creating financial and security risks for your company. Discover how to get control of your enterprise mobility strategy and ensure mobile worker productivity with these ten steps.

    White Paper

    What You Need to Know About the Costs of Mobility

    Mobile workers want to get connected anywhere, at any time, often at any cost. Enterprise mobility is often a hidden "black" budget in your company. Ensure that your traveling employees are productive everywhere, even while you control cost and security, through an enterprise mobility strategy.

    White Paper

    The 2011 iPass Mobile Enterprise Report

    This industry survey covers trends, recommendations and a policy guide on managing Enterprise Mobility for IT management and CIOs. Get data on employee device liability, as well as smartphone/tablet penetration, budget control and provisioning. Find out how your organization compares, how to ensure mobile worker productivity, and control costs.

    Webcast On Demand

    Managing Enterprise Mobility Costs

    Mobile employees, especially those traveling internationally, were spending time and resources finding and making connections. Roaming costs were out of control. The IT Administrator at The Hay Group tells you how he got more control over these costs, providing management with predictable budgets and insights while ensuring employee productivity.

    Sponsor: iPass

    White Paper

    Digital Transformation: Creating New Business Models Where Digital Meets Physical

    Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil society, as well as friends and family.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question