Need For Data Protection In Modern Sports

By Gunjan Shrivastav and Mansi Gupta









Introduction

The right to privacy has been declared a fundamental right in India.[1] However, this right is constantly breached[2] in our country where people are always under a threat of constant surveillance by government and private actors.[3] This threat escalates when the person concerned is a public figure or a sports personality, who faces severe threats to person and loss of career due to loss of sensitive personal information. To curb this unbridled privacy invasion, the government has come up with the Personal Data Protection Bill (PDPB) 2019,[4] which lays onus on both government and private parties to protect personal data of individuals and puts limits and conditions on infringement of user’s data privacy. However, the bill, with overbroad provisions, instead of protecting the user rights only weakens them.[5]

In this paper, it is argued that data protection, specifically in the context of modern sports is inadequate, and the current framework in India does not subserve the privacy interests of the players. The paper is divided into two broad sections.The first section analyses the increasing use of technology and its impact on privacy infringement of sportspersons. It highlights the ethical concerns and security risks surrounding the use of big data in sports. It also maintains that there is a need for stricter data protection regulation for all sports organizations across the world. The second sectionimplores the pathetic state of affairs surrounding the issue of surveillance in India and contextualizes the fallacies of data protection in modern sports under PDPB. Finally, it attempts to provide solutions for resolving these privacy issues while adhering to modern technology.









Technology as a cause of unethical privacy infringement

Recent technological advancements in storage capacity, sensors and computing have produced devices that could help sports-persons in improving their performance in various sports by collecting their personal data. This personal data is then used by sports franchises to determine the players that they choose taking into account their commercial viability.[6] However, with big data comes the question of maintaining security and ethics of privacy. Wearables such as fit bit which are used to track biometric data have major security flaws in them.[7] In 2017, a research conducted by the University of Edinburgh highlighted how the wearables watch like Fitbit, which tracks biometric data such as the number of steps and heart rate can be accessed using a modified code and all the data collected by it can be leaked.[8]

Moreover, such wearables and Internet of Things devices have been easy targets of data breach primarily because they are all connected by the internet and have little on-device storage. As a result, they have to transmit their data immediately over the internet, which increases the chances of data being leaked.[9] The databases of teams and sports organizations are potentially easy targets as they store all data of the athletes at one place.[10] The use of Wi-Fi to transfer biological data of athletes exposes the data to a greater risk of data hacking. This is because wireless communication incurs various types of security threats due to unattended installation of sensor nodes as the sensor network can interact with sensitive data and operate in an unattended environment.[11] For example, vital physiological signals of athletes are sensitive in nature and help teams and sportspersons in identifying if they have any career-ending disease or any other problem. If such information is leaked, it may not only be deleterious to their interest but would also result in a violation of their right to privacy.[12] The recent data leak from the World Anti-Doping Agency (WADA) is a perfect example of the same, where the information about different athletes was leaked directly from the WADA database.[13] This clearly shows that even if the personal information is provided to WADA or any other Anti-Doping Organization for ensuring fairness in a game, such data can easily be leaked or hacked which may result in the breach of the right to privacy and confidentiality.

Similarly, the use of biosensors that collect personal data to enhance performance should be regulated as the data collected by it is highly sensitive and confidential in nature. For instance, a biosensor named pulse Oximeter used to measure the amount of oxygen in an athlete’s blood works by clipping an electronic device in the index finger of an athlete, it then radiates infrared light which helps in calculating oxygen level.[14] As the information collected by such devices is personal,it is necessary that there should be a consensual agreement with respect to how the information collected is to be used, whether it is to be given to third parties such as sports agency or physicians. The main reason for having a consensual agreement or a standard regulation behind the same is the fact that such personal information of the athletes is not anonymized.[15] Moreover, there is no law or regulation that clearly explains as to whom such data belongs and how exactly does the sports organization or the individual sporting club use this information to analyze and enhance the performance of the athlete.

Another challenge that wireless sensor networks possess is of maintaining the integrity of data collected, as there are high chances of skimming and eavesdropping when the data is wirelessly transmitted. This is mainly because, in a wireless network, unauthorized users can gain access to agency systems and the information, degrade network performance, corrupt agency’s data, and use the resources of the agency to launch an attack on other networks.[16] They can also launch attacks that prohibit authorized users from accessing the network.[17] In fact, it is highly possible that the opposite team might use the athlete’s biological data for its own gain. Moreover, it distorts the boundary between a competitive edge and an unfair advantage as the increased integration of such technologies may not be a real test of an athlete’s abilities, but rather the strength of the technology systems.[18] For this may lead to an arms race of technology where the athletes and teams with the best technology will have the edge over other competitors. In fact, this has been happening in modern sports like Formula One motor racing, where the actual test is not of driving but of using the most advanced technology in order to win the race.[19] Therefore it is important that the use of technology in sports be regulated so as to ensure that the competition remains fair. It becomes imperative to have a regulation that strictly governs the use of data collected by such wearables and sports gadgets.









Data Infringement in India

National Anti-Doping Agency (NADA) has been contributing its share in the Indian Sports arena by regulating the use of drugs in sports and initiating an extensive outreach programme for awareness on Anti-Doping Sports.[20] The International Standard for Protection of Privacy and Personal Information (ISPPPI) prohibits the extraction of unnecessary personal information from players as well as third parties.[21] The standard tries to respect the consent of the players for processing the information and tries to balance it with the main objective of effective anti-doping measure.  However, in India, NADA fails to provide adequate measures for the protection of personal data of the players. This is because Anti-Doping Rules allows NADA to “collect store, process or disclose personal information relating to athlete and other persons” while conducting Anti-Doping activities without any specific requirement of consent.[22] The Information and Technology Act, 2000 mandates under Section 43A that everybody corporate handling Sensitive Personal Data for commercial or professional activity shall maintain reasonable security and follow procedures to avoid wrongful loss or gain to any person.[23] It remains mysterious whether organizations such as NADA fall under the definition of such body corporations and whether they can be penalized under Section 43A of the Act in case of any breach.[24] Additionally, just like WADA there are severe doubts regarding the lack of safety net at NADA, which has access to information of most of the players across multiple sports in the country.[25]

There have been multiple instances of data breach among the sports fraternity in India. One of the most famous incidents was the exposure of personal data of thousands of players by the Indian Cricket Board.[26] Sensitive personal data belonging to 15000 to 18000 applicants were exposed to public view with the Board of Control of Cricket India (BCCI) failing to ensure the safety of such data.[27] The data leak was due to the misconfigured Amazon Web Service Cloud storage following which anyone with an internet connection could have access to the personal information of these players. Such breach of privacy raises questions on the largest cricketing body in the world.









The Personal Data Protection Bill: Where does it stand?

There is a lack of a robust data protection framework in India, and the present acts fall short of achieving the protection required. The motive behind the introduction of PDPB 2019 was to move a step closer towards ensuring the safety of personal data.[28] Section 11 of the bill requires explicit consent of the sports personalities. This consent needs to be free, clear, specific and capable of being withdrawn.[29] This means the data fiduciaries including a club, organization, agency, team etc. have to satisfy this explicit consent requirement in order to achieve the goal of data protection. The data collected by the sporting agencies such as a player’s heart-rate, speed, temperature, sleep patterns, calorie intake etc. is sensitive personal data, thus, mandating the consent of the person concerned for the processing and use of information. However, the right to privacy against state surveillance is not granted as a complete right but is conditioned from the outset.

Any government agency is permitted to bypass privacy protections for processing data if it is for ‘reasonable purposes’ specified by the proposed Data Protection Authority (DPA).[30] The bill envisaged the creation of this authority to act as a fourth-branch independent institution to protect and regulate personal data.[31] The DPA is entrusted with this task to weigh in the interest of the data fiduciary and reasonable expectations and rights of the data principal. However, the bill still gives huge power to the Central Government and lets it have an effective control over the ownership of sensitive personal data. This is due to the lack of checks and balances to allow DPA to function independently and exercise their powers in a regulatory manner.[32]

It is suggested that the threshold for invocation of the ‘reasonable purpose’ exception to the consent rule should be the three-part test- (a) legitimate interest in data processing; (b) necessity and proportionate to the rights of the principal (c) balancing the scales and determining the risk level.[33] This is in line with the ‘Legitimate Interests Assessment’ as under the General Data Protection Regulation (GDPR), which is the regulation in EU law on data privacy. Article 6 of the GDPR provides six lawful bases for violation of this right. A similar and specific standard for privacy violation is missing in PDPB. Thus, it is argued that even though it is proposed that data processing is for athlete’s better performance, the consent requirement might be unnecessarily diluted without adequate protection to them.

Further, it is interesting to note that the principles of accountability, data minimization, data accuracy, purpose limitation, lawfulness and fairness of processing are a part of the PDPB.[34] The bill also provides crucial rights to a sports player as a data principal, namely the right to correction and erasure of any inaccurate data or the data which is no longer required for any official purposes.[35] For instance, certain sports teams and clubs require that their players wear trackers and other wearable devices which record their biometric data for training and monitoring purposes.[36] The liability falls upon these organizations to protect this data which should be deleted once the purpose is over. However, there is a lack of an independent oversight authority. The authority is supposed to act independently without the executive control. As per the current draft, the members and chairperson of the independent oversight authority are to be recommended by the selection committee composed primarily of the executive thereby, casting aspersions on the oversight function of the authority.[37] If sports players approach this authority for redressal of their grievances, for action against any club or organization for violation of provisions of the bill, it remains likely that such complaints would not be met with a stringent action against these clubs or teams. This is because the composition of the authority is devoid of independent members likely to lead them to draw partial results.









Conclusion

The use of advanced technology in sports and lack of any regulatory framework for controlling the data stored and collected by sports agencies clearly highlights that the security and confidentiality of personal data of athletes are at stake. Moreover, the possibility of tampering with sports wearables and biosensors clearly points out the need for having a stringent regulation that ensures that personal data of athletes are not transferred. For, in future, it is possible that the refereeing equipment might also get hacked by the hackers so as to change the results of a game or for any other ulterior motives. Even the teams can also intentionally tamper with its own data so as to camouflage their data to make it look that they are complying with the rules. Moreover, data breach in case of anti-doping may lead to leakage of genetic codes of athlete which can be used for various malicious purposes.

Therefore, in light of the use of biosensors and wearables used for performance analysis, it is important to have a regulatory framework that limits the usage of these electronic devices. Furthermore, a well-planned security network is required to be created and deployed so as to protect the transfer of data on these electronic devices as most of them use a wireless network. For this to happen, there needs to be a stringent national law in place which will ensure data protection in modern sports.

It is required that firstly, storage of sensitive personal data of sports players must have adequate safeguards and the players should be ensured a right to be forgotten or a right to the deletion of personal information when such information is not required; secondly, while there are no instances of sporting agencies being given a protection from the application of this act, it should be born in mind that no sporting agency whether government or private should be accorded this protection from the application of the act. Only if there are ‘reasonable purposes’ should the DPA allow the data processing by these data processors. The reasonable purpose test should not be diluted by the authorities and should satisfy the objective legitimate interest test as envisaged by the GDPR. While the GDPR does not provide an exhaustive list for the test, it states that the purpose must be specifically stated and should not be illegitimate or overbroad.[38] Thirdly, the player should have complete information and should consent to data collection as per Section 11 of the bill, and this should not just act as a formal requirement. Lastly, an independent organization should be formed for looking over the anti-doping process and overseeing the functions of fiduciaries while ensuring no leak of personal data in the process. Thus, it is crucial to revamp the current system of data protection with a robust mechanism of safeguards.









The authors, Gunjan Shrivastav and Mansi Gupta, are currently law students at the National Law School of India University (NLSIU), Bangalore.










[1] Justice Puttuswamy v. Union of India (2017) 10 SCC 1.

[2] EPW Engage, Protection v. Privacy: The Debate on Surveillance and Digital Rights in India, Economic and Political Weekly (2019) available at https://www.epw.in/engage/article/protection-vs-privacy-debate-surveillance-and-digital-rights-india, last seen 25/9/2020.

[3] PTI, Indian Organizations Lost Rs. 12.8 Crore To Data Breaches, The Hindu, (July 23, 2019) available at  https://www.thehindu.com/business/indian-organisations-lost-128-crore-to-data-breaches/article28681416.ece, last seen 25/9/2020.

[4] The Personal Data Protection bill, 2019 (373 of 2019).

[5] A. Gupta, The Data Protection Bill only weakens users’ rights, The Hindu (December 27, 2019) available at https://www.thehindu.com/opinion/lead/the-data-protection-bill-only-weakens-user-rights/article30405339.ece, last seen 25/9/2020.

[6] M. Greenwald, Cybersecurity in Sports, Question of Privacy and Ethics, Tufts University 7, 8 (2017) available at http://www.cs.tufts.edu/comp/116/aarchive/fall2017/mgreenwald.pdf last seen on 27/9/2020.

[7] Ibid.

[8] M. J. McNameel, Genetic Testing and Sports Medicine Ethics, 39(5) Sports Medicine 339, 344 (2009).

[9].M. A. Ameen, J. Liu & K. Kwak., Security and privacy issues in wireless sensor networks for healthcare applications, 36(1) Journal of Medical Systems 93,101 (2010), available at https://doi.org/10.1007/s10916-010-9449-4, last seen 27/9/2020.

[10] L Kibona & h. Ganame, Wireless Netwrok Security: Challenges, Threats and Solutions: A Critical Review, 2(1) International Journal of Academic Multidisciplinary Research (2018), available at https://philarchive.org/archive/KIBWNS#:~:text=%5B17%5D%2C%20found%20out%20the,security%20vulnerabilities%20of%20the%20802.11, last seen 2/10.2020.

[11] Ibid.

[12] P. Kumar & H. J. Lee, Security issues in healthcare applications using wireless medical sensor networks: A survey, 12(1) Journal of Sensors (Basel), 55,91 (2012) available at https://doi.org/10.3390/s120100055, last seen 27/9/2020.

[13] WADA confirms another leak of confidential athletes’ data, The New Indian Express, 2016, available at https://www.newindianexpress.com/sport/2016/sep/17/WADA-confirms-another-leak-of-confidential-athletes-data-by-hackers-1520931.html, last seen 13/11/2020.

[14] R Evans, M. McNamee & O. Guy, Ethics, Nanobiosensors and Elite Sport: The Need for a New Governance Framework, 23(6) Science and Engineering Ethics 4-7 (2016), available at https://doi.org/10.1007/s11948-016-9855-1, last seen 29/9/2020.

[15] M Meingast, T. Roosta & S. Sastry, Security and privacy issues with health care information technology in the annual international conference of the IEEE engineering in medicine and biological society, New York City USA, September, 31-3, 5453–5438 (2006) available at https://doi.org/10.1109/iembs.2006.260060, last seen 1/10/2020.

[16] Supra 10.

[17] Supra 10.

[18] S. Loland & H. Hoppeler, Justifying anti-doping: The fair opportunity principle and the biology of performance enhancement, 12(4) European Journal of Sport Science 347, 353 (2012).

[19]  Technology in sport: Competitive edge or unfair advantage?, PDD Blog 2012, available at http://www.pdd.co.uk/blog/ 2012/07/technology-in-sport-competitive-edge-or-unfair-advantage, last seen 1/10/2020.

[20] Anti-Doping Awareness Programme, NADA, Ministry of Youth &Sports, Government of India, available at https://www.nadaindia.org/en/anti-doping-awareness-programme, last seen 13/11/2020.

[21] Lovely Dasgupta & Shameek Sen, Sports Law in India: Policy Regulation and Commercialization (1st ed., 2017).

[22] Article 14 (14.6), Anti-Doping Rules, National Anti-Doping Agency 2015.

[23] Talwar Thakur and Associates, Data Protection Laws, Linklaters (2018) available at https://www.linklaters.com/en/insights/data-protected/data-protected—india, last seen 2/10/2020.

[24] Supra 18.

[25] Supra 13.

[26] Indian Cricket Board exposes personal data of thousands of players, The Centre for Internet and Society, (May 15, 2018) available at https://cis-india.org/internet-governance/news/hack-read-waqas-may-15-2018-indian-cricket-board-exposes-personal-data-of-thousands-of-players, last seen 2/10/2020.

[27] Indian Cricket Board exposes personal data of thousands of players, Hackread (May 15, 2018), available at https://www.hackread.com/indian-cricket-board-exposes-data-of-cricketers/, last seen 2/10/2020.

[28] The Personal Data Protection Bill, 2019, PRS India, available at https://www.prsindia.org/billtrack/personal-data-protection-bill-2019, last seen 13/11/2020.

[29] Section 11, The Personal Data Protection Bill, 2019.

[30] India’s Proposed Privacy Law allows government access and some data localization, Lexology (December 19, 2019) available at https://www.lexology.com/library/detail.aspx?g=9982a218-799c-4886-ad08-3b414cda6571, last seen 2/10/2020.

[31] Section 25, The Personal Data Protection Bill, 2019.

[32] Anirudh Burman, Will India’s Proposed Data Protection Law Protect Privacy and Promote Growth, Carneige India, March 9, 2020, available at https://carnegieindia.org/2020/03/09/will-india-s-proposed-data-protection-law-protect-privacy-and-promote-growth-pub-81217, last seen 13/11/2020.

[33] What is legitimate Interests basis?, Information Commission Office, UK, available at https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/legitimate-interests/what-is-the-legitimate-interests-basis/, last seen 13/11/2020.

[34] The Personal Data Protection Bill, 2019.

[35] Tejpal Singh Rathore, Privacy and how it has affected Indian sports, The Bridge (February 25, 2020) available at https://thebridge.in/law-in-sports/privacy-how-affected-indian-sports/, last seen 2/10/2020.

[36] Dhruv R Seshadri, et al, Wearable sensors for monitoring the internal and external workload of the athlete, 2 (71), NPJ digital medicine, (2019).

[37] Amar Patnaik, Why India’s Proposed data Protection Authority Needs Constitutional Entrenchments, The Wire (July 23, 2020) available at https://thewire.in/tech/india-data-protection-authority-needs-constitutional-entrenchment, last seen 2/10/2020.

[38] Article 6(1)(f), General Data Protection Regulation, 2018.

Leave a comment