Joint statement on contact tracing for Norway

Joint Statement Norway
13 min readMay 19, 2020


Echoing the statement¹ signed by hundreds of scientists and researchers from across the globe, this statement reflects the view of the undersigned Norwegian technology, security and privacy experts. It is the result of many discussions, where we sought to balance important requirements and values. Our main goal has been to contribute with a unifying, realistic and constructive proposal. We believe this proposal shows a path that answers substantial concerns, and outlines a solution that will receive public support.

The current Coronavirus crisis is unprecedented, and we support innovative ways of fighting the pandemic with the aid of technology. However, we are concerned that the current mobile app solution Smittestopp that is being offered in Norway to address the crisis, can result in an unprecedented surveillance of our society. The contribution of the app is yet unproven, unlike actions such as testing and social distancing. We urge the authorities to migrate to a solution that is less privacy invasive.

Contact tracing is a well-understood tool to tackle epidemics, and has traditionally been done manually. However, manual contact tracing is time-consuming and is limited to people who can be identified.

In some situations, so-called “contact tracing apps” on smartphones can improve the effectiveness of the manual contact tracing technique. These apps would allow individuals with whom an infected person had physical interaction to be notified, and enable them to take recommended actions such as quarantine or getting tested.

In this context the Norwegian Institute of Public Health has launched a contact tracing solution to improve the effectiveness of the manual contact tracing technique. The app works by registering the identity of other nearby phones using Bluetooth and collecting movements of the phone using geolocation data in a central server. Unlike solutions from other countries, the Norwegian Smittestopp solution collects data to research the spread of the disease and the effect of actions by health authorities in addition to tracing infections. While the effectiveness of contact tracing apps is contested, it is especially important to ensure that those implemented preserve the privacy of their users, thus safeguarding against many other issues.

Collecting data about the whole population, both those infected by Covid-19 and those not, challenges trust in and acceptance of such a solution by society at large. It is crucial that citizens trust the solution in order to produce sufficient uptake to make a difference in tackling the crisis. It is vital that in coming out of the current crisis, we have not created a tool that enables large scale data collection on the population or laid ground for acceptance of such after the pandemic. Thus, solutions which allow reconstruction of invasive information about the population should be rejected. Such information can include the “social graph” of who someone has physically met over a period of time as well as the locations every person in Norway has visited.

With access to the social graph and location history, a bad actor (state, private sector, or hacker) could spy on citizens’ real-world activities. Norway is seeking to build a system which could enable them to access and process this social graph. On the other hand, highly decentralised systems have no distinct entity that can learn anything about the social graph. In such systems, matching between users who have the disease and those who do not, is performed on the non-infected users’ phones as close to anonymously as possible, while information about non-infected users is not revealed at all.

To aid the development of contact tracing without a centrally controlled database that holds personal information about individuals, Google and Apple are developing APIs on Android and iOS to support the required Bluetooth operations in a privacy preserving manner directly. Teams building the privacy protective schemes fully support this effort as it simplifies — and thus speeds up — the ability to develop contact tracing apps. We applaud this collaborative initiative, and the development teams migrating to it. We always caution against collecting private information of people using any service.

It is worth noting that the European Parliament on April 17th recommended a decentralized approach, pointing out by overwhelming majority “that […] the generated data are not to be stored in centralised databases, which are prone to potential risk of abuse and loss of trust and may endanger uptake throughout the Union” and demanding “that all storage of data be decentralised”². The Norwegian solution is also incompatible with the EDPB (European Data Protection Board) guidelines for contact tracing apps³.

The words of Wojciech Wiewiórowski, European Data Protection Supervisor, bear repeating: “Humanity does not need to commit to a trade-off between privacy and data protection from one side, and public health, on the other. Democracies in the age of Covid-19 must and can have them both”⁴.

There are a number of proposals for contact tracing methods which respect users’ privacy to a higher degree, many of which are being actively investigated for deployment by different countries. We encourage the Norwegian Institute of Public Health to migrate to and only rely on a system that is privacy preserving by design (instead of there being an expectation that they will be managed by a trustworthy party) and that is subject to public scrutiny, as a means to ensure that the citizen’s data protection rights are upheld.

The following principles should be adopted going forward:

  • Split into two apps: Usage of data for research which is beyond collecting locally stored contact tracing information must be optional, be collected by a separate application and be subject to the explicit consent of the user. In addition to giving a clear separation between the purpose of contact tracing and the purpose of research, this will also enable the use of the Exposure Notification API announced by Google and Apple for contact tracing at the OS level
  • Data minimization: Contact tracing apps must only be used to trace contact between individuals to contain the spread of SARS-CoV-2 virus. The contact tracing app must not collect, process, or transmit more data than what is necessary to achieve this purpose. A companion research app may collect additional data for research purposes subject to user consent.
  • Transparency: The governance and technical implementation must be fully transparent. The protocols and their implementations, including configuration of components provided by third parties, must be available for public scrutiny. The processed data and if, how, where, and for how long they are stored must be documented unambiguously. Such data collected should be minimal for the given purpose. There must be transparency into the governing processes for contact tracing apps during this crisis, and for its potential use in future crises.
  • Privacy by design: When multiple options to implement a certain component or functionality of the solution exist, the most privacy-preserving option must be chosen. Deviations from this principle are only permissible if this is demonstrably necessary to achieve the purpose of the solution, and must be clearly justified with sunset provisions.


1: Joint Statement on Contact Tracing: Date 19th April 2020:

2: EU coordinated action to combat the COVID-19 pandemic and its consequences:

3. EDPB guidelines on contact tracing tools in the context of the COVID-19 outbreak:

4: Carrying the torch in times of darkness:

This statement was initiated by Johannes Brodwall, Trond Arve Wasskog and Simen Sommerfeldt

Signed — in alphabetical order

Signed by form — in chronological order

