When a Hearing Aid Becomes a Privacy Threat

Categories: Digital Rights
When a Hearing Aid Becomes a Privacy Threat

THERE is something delightfully South African about the latest privacy panic over AirPods: apparently, the technology has become so dangerously sophisticated that you may soon need permission to hear what is being said in the room you are standing in.

A recent MyBroadband article warns without any hint of sarcasm, that employees wearing AirPods and other AI-enabled devices could land their employers in serious trouble. The sky is about to fall on our heads?

The concern is understandable. Smart glasses can record video. Earbuds can record and transcribe conversations. AI services can process information in the cloud. Companies plainly need to know what their employees and visitors are doing with other people’s personal information.

But the argument starts becoming rather strange when hearing a conversation, recording a conversation and processing a recording are treated as essentially the same thing.

They aren’t.

South Africa already has legislation dealing specifically with interception. RICA — the Regulation of Interception of Communications and Provision of Communication-Related Information Act — expressly permits a person who is a party to a communication to intercept it, subject to its statutory limitations.

And its definition of “party to a communication” is rather interesting. It extends beyond the person actually speaking or being addressed to someone in whose immediate presence the communication takes place and is audible.

Which brings us to the privacy nightmare of the century, dreamt up by technophobic executives at Werksmans and MyBroadband with nothing better to do on a Sunday:

the lowly hearing aid.

Imagine a deaf employee sitting in a meeting. They cannot hear what is being said. They put in a hearing aid and suddenly — catastrophe — they can hear their colleagues.

Has the hearing aid violated everybody’s privacy? Obviously not.

Now give that hearing aid a live translation function. The employee speaks English, the meeting is partly in isiXhosa, and the device translates the conversation into English in real time.

Have we crossed some mysterious technological privacy Rubicon necessitating government regulators and intervention?

Well if you happen to be Myles Illidge whose line of reasoning is laid bare here, we may have.

What exactly has happened? The employee is still sitting in the room. The speakers are still speaking audibly. No new person has necessarily been introduced into the conversation. The technology has simply altered the employee’s ability to perceive information that is already being communicated in their presence.

AI has not invented the conversation. It has invented a better pair of ears. That doesn’t mean privacy law disappears. POPIA only matters when personal information is collected, processed, stored, transmitted or otherwise used. A device that secretly records a meeting, uploads the recording to a cloud provider, generates transcripts, identifies participants and retains the information for later use presents an entirely different set of questions from an earbud providing instantaneous translation and then forgetting what it heard.

The distinction matters. Indeed, if a company itself records conversations, informing people that recording takes place is hardly an insurmountable technological problem. Put up the notice. Tell people what is happening. Establish the purpose and the rules governing the information. Deal with retention, access and security.

That’s sane regulation. What becomes problematic is treating the mere capacity to perceive as though it were automatically an unlawful act of data collection. It’s a rhetorical technique consistent with earlier scare stories about mobile phones.

We have been extending human perception with technology for centuries. Glasses improve vision. Hearing aids improve hearing. Binoculars extend sight. Microphones extend hearing. Translators extend comprehension. AI is doing the same thing at considerably greater speed.

The proper legal question therefore isn’t: Does this gadget use AI?” It is:

“What information is it collecting, what is it doing with it, where does that information go, and for how long?”

Otherwise we risk arriving at the extraordinary proposition that the next great threat to privacy is not the person secretly recording the meeting. It is the deaf person who finally managed to hear it.

And somewhere, presumably, a lawyer is already drafting the notice for the door.