Legal considerations in collecting Wifi information - Case Study: Google Street View
In 2007, Google launched it’s Street View project where Google cars were tasked to drive around the world, collecting data to feed Google’s newest application, Google Street View.
What wasn’t disclosed clearly was that Google cars also were collecting Wifi data. Investigations were conducted and Google was found not only collecting SSID’s and locations, but also they were intercepting and parsing information from the data section of unencrypted packets.
This website provides a great summary of what has globally occurred and how each country has reacted.
In Australia, an investigation was initiated under suspicion of breaking the law under the Privacy Act (1988). Later, the investigation was handed over to the Australian Federal Police, who were investigating whether Google has violated the Telecommunications Interception Act which “prevents people from accessing electronic communications other than for authorised purposes”.
It was found that Google had violated the Privacy Act - the Act does not empower the Commissioner to impose sanctions, but Google agreed to:
Publish an apology for Australia (Global apology)
Conduct a Privacy Impact Assessment (PIA) - unclear if internally done
Provide a copy of the PIA to the Commissioner’s Office
Consult regularly with the Commissioner about personal data collection activities arising from significant product launches in Australia
Collecting a huge Wifi map of Australia and huge amounts of unencrypted personal information vs. writing a blog, doing some sort of PR investigation and have chats will what seems like a powerless Commissioner.
Seems like a pretty good trade maen.
The significant take away from this is that collecting wifi data is considered illegal in Australia, and hence, this project cannot be used outside academic research.











