Are Mobility Data Specification Privacy Concerns Overblown?

The recent launch of the Mobility Data Specification (MDS) represents an unprecedented opportunity for cities to obtain and use actionable data collected in nearly real-time from shared micromobility operators. However, some operators and consumer advocacy groups oppose MDS’ use of individualized trip data, citing user privacy issues. How credible are MDS privacy concerns?

                   Source: LADOT

Uber’s Head of Security and Privacy Communications, Melanie Ensign recently called attention to the potential for misuse of individualized data by law enforcement, and the potential for individual users to be “stalked” using MDS trip data. Consumer advocacy organizations ranging from the Center for Democracy & Technology to the Electronic Frontier Foundation have joined Uber in criticizing MDS’ collection of individualized trip data, arguing that cities can fulfill their regulatory functions just as effectively using aggregated and anonymized trip data in MDS. (Note: several of these consumer advocacy organizations have received funding from Uber.)

LADOT, for its part, hasn’t made a particularly convincing case for why it requires individualized trip data, as opposed to aggregated and anonymized trip data, to fulfill its regulatory obligations. In an April 2019 interview, LADOT’s General Manager, Seleta Reynolds, was unable to provide a single example of a policy decision that could not be informed by aggregated trip data, before acknowledging that LADOT is taking an iterative approach to MDS implementation: “Talk to me in two months after the system is in operation, and I might have decided I really don’t need the disaggregated data. … That’s why MDS is open and versioned. We’re learning a ton as we iterate.” LADOT also recently issued an updated set of standards to guide its handling and use of individualized trip data, in the hopes this might assuage concerns expressed by privacy advocates. These standards include new rules related to inter-agency data sharing and public transparency. LADOT emphasizes that – while MDS data includes unique identifiers for each shared vehicle – it does not collect personally identifiable information on trip-takers. It has also recently waived a real-time data-sharing requirement, and allows operators to provide data after a 24-hour delay.

Uber, and other opposing voices in the operator community, may actually be more concerned about protecting competitive insights than user privacy. They might reason, for instance, that sharing individualized trip data with cities will enable other operators to poach their business; instead, many operators argue for the ability to aggregate and anonymize data. It is also logical to assume that the use of MDS might next be expanded to the ride-sharing portion of Uber’s business, a development that Uber can be expected to vociferously resist. (In this sense, Uber’s opposition to individualized data collection in the shared micromobility space may be a trial balloon. Indeed, Uber has hinted that it may legally challenge MDS’ compliance with the recently-passed California Consumer Privacy Act, when it becomes law, in January 2020.) A bill has been introduced in the California State Assembly that would prohibit cities from collecting individualized trip data, suggesting that opposition to this practice may be gaining momentum.


It’s difficult to overstate the usefulness and exportability of MDS if privacy concerns are addressed. Notwithstanding the legitimacy of the concerns regarding MDS’ individualized trip data collection, public agencies should take steps (like LADOT has, with its updated data principles) to assure users and operators alike that trip data is being collected and used safely and reasonably, and that steps are being taken to prevent misuse and safeguard data in storage.

Comments

Popular on the Blog

Final Policy Guidelines

Take to the Streets! The (AV) Revolution is Coming

In TNC wage war, econ 101 is on the driver’s side