Protecting children’s data privacy in the smart city

The devices that we use have unique identifiers. With cross-browser fingerprinting, the data we generate as users isn’t as anonymized as we believe it is. The tracking of our online activity is extensive, comprehensive and persistent, and generates marketable data shadows that do not need our personal information in order to target us as consumers.
This should be a significant concern regarding today’s children and youth, who have extremely detailed data profiles that they will carry into adulthood, creating what Google’s Eric Schmidt termed an “indelible record.”
What is key to note here is that these instances of alleged violations of children’s privacy have occurred in the private realm, where regulations exist as to how this data should be handled. As smart city projects like Sidewalk Toronto’s Quayside project grow in profile and popularity, they have yet to identify what will happen to data generated in public by minors. Because Sidewalk Toronto may set precedents shaping future smart city planning, children’s privacy in the private and public spheres should be recognized as a national issue.
Sidewalk Toronto is a subsidiary of Alphabet Inc., Google’s parent company, with several concerning precedents regarding tracking and collecting the data of minors. The findings reported here are an extension of a longer paper as to how tech and media giants are observation privacy needs of minors. “Data Science, Disney, and The Future of Children’s Entertainment” will be published in The Palgrave Handbook of Children’s Film and Television (July 2019).
Children today face unique challenges because they will be targeted by business intelligence, and shaped by this targeting to a degree that we cannot fathom. There are legal protections for minors under 13 as stated by the Office of the Privacy Commissioner of Canada (OPC) and Children’s Online Privacy Protection Rule (COPPA) in the United States. Children and youth are recognized as vulnerable and deserving of special considerations: they cannot make informed decisions as to what they are agreeing to. This makes the data tracking and mining of children under 13 a federal issue.
In Europe, the General Data Protection Regulation (GDPR) applies to minors younger than 13 or 16, depending on the country’s age of digital consent. Youth of the age of digital consent (13 or 16 years old and up) are not protected as minors in Canada, the U.S. or Europe: youth data is treated as adult data.
Given the pattern of inattention and prevarication evident in the instances noted here by Alphabet Inc.’s subsidiaries ensuring data privacy and protection of minors — the most regulated protected demographic in the U.S. — why should Sidewalk Toronto be trusted with the data of minors? For Torontonians, how exactly will Quayside ensure that the data of minors will be protected given that there has been no acknowledgement of the distinct concerns regarding minors or teens to date?
Here’s a recap of some of the complaints and alleged violations before the U.S. Federal Trade Commission (FTC), some of them still active.


