10 Privacy and Consent for Wireless and Optical Sensing
10.1 Start With the Story
Radio Remi is asked to count people in a shared study room. The sensor stores no images, so the team first calls it anonymous. Then they notice it can reveal arrival times, long absences, sleep-like stillness, and repeated routines. Remi asks who is observed, what decision will follow, and how someone can say no. The design changes from storing raw traces to keeping short local counts with a clear sign and a review route.
10.2 Overview
Wireless and optical sensing can infer presence, movement, position, gestures, breathing, device type, routines, and room use. Personal data is not limited to names or pictures; an observation can relate to an identifiable person through location, time, device, household, or repeated behaviour. Privacy design begins before collection. Name the purpose, people, inference, lawful basis, notice, retention, access, sharing, security, error response, and less intrusive alternative. This chapter is engineering guidance, not legal advice.
10.3 Learning Objectives
By the end of this chapter, you will be able to:
- Identify people, inferences, and harms across a wireless or optical sensing flow.
- Apply purpose limitation, minimisation, notice, lawful-basis, retention, and access questions.
- Produce a downloadable decision record with an abstention and human-review path.
10.4 Start with a threat model
List everyone inside the sensing field, not only the buyer or operator. Include visitors, workers, neighbours, children, household members, and people behind walls or glass where the modality can reach. Then list observers and attackers: the local device, service provider, landlord, employer, cloud operator, maintainer, stolen account, and anyone who can combine records. A coarse count can become a routine when timestamps persist; a breathing cue can become health-related inference when linked to a person.
The field of view is part of the threat model because people can be observed without touching the device. A room sketch should mark doors, walls, shared areas, and any path that reaches beyond the intended space.
Separate the raw observable from each inference. CSI amplitude, radar phase, lidar points, and packet timing are measurements. Presence, identity, sleep, health, performance, and suspicion are interpretations with different harm and evidence. Test false positives, false negatives, protected situations, function creep, unequal impact, and what happens when a person cannot avoid the sensor.
The team should record which inference is prohibited as well as which one is needed. This boundary helps reviewers spot a later request that quietly changes the purpose.
10.5 Read the minimised data flow
Figure 10.1 compares a raw collection path with a smaller on-device decision path and keeps governance beside the data.
In Figure 10.1, begin with the red upper lane. Raw measurements, device IDs, and long histories leave the room. That path helps later reuse but makes it easier to link data to a person and raises the harm from a breach. The green lower lane keeps only the feature needed for a stated decision, deletes the raw window, and sends a short-lived count with uncertainty. Read the governance table last. Local processing cuts exposure, but it does not replace a lawful basis, clear notice, access controls, retention limits, or a real choice not to be sensed.
10.6 Minimise at the point of sensing
Collect only the modality, field of view, resolution, sample rate, and duration needed for the stated purpose. Crop space and time before storage. Prefer features or counts over raw phase, point clouds, identifiers, and continuous histories when they answer the question. Process on the device where practical, separate operational output from diagnostic logs, and make high-detail debugging an explicit temporary mode. Document deletion, not just retention.
A retention test should prove that raw windows are actually deleted after the short processing interval. The test should include local caches, diagnostics, exports, backups, and service logs.
Minimisation also applies to decisions. If a doorway counter can manage room capacity, do not infer identity or health. If a contact switch can answer whether a cabinet opened, do not deploy room-wide radar. Keep an abstain state when confidence is low, and route consequential decisions to a trained person with the source limitations visible.
The saved result should include uncertainty and the reason for any abstention. Operators need these fields to distinguish no observation from a confident empty-room result.
10.7 Make notice and choice real
Notice should say that sensing occurs, what can be inferred, why it is needed, who receives the result, how long it lasts, and how to ask questions or exercise rights. Place signage before a person enters the sensed space and provide an accessible detailed notice. Do not hide wireless sensing behind “no camera” language. Refresh notice when the purpose, range, inference, provider, or retention changes.
Consent is only one possible lawful basis, and it must be freely given, specific, informed, and withdrawable when relied upon. Power imbalance can make consent unsuitable, especially for workers, tenants, pupils, patients, or people who cannot use a real alternative. Identify and document the correct lawful basis and any extra condition for special-category data with qualified advice. A sign does not make disproportionate monitoring lawful.
10.8 Apply a UK and EU data-protection posture
For UK deployments, start with lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability. Consider a data protection impact assessment before high-risk systematic monitoring or sensitive inference. The UK framework changed through the Data (Use and Access) Act, and regulator guidance may be updated, so check the current ICO position during design and before launch. EU deployments should check the GDPR and applicable national rules rather than assuming the UK route is identical.
For worker monitoring, the ICO stresses necessity, proportionality, transparency, a lawful basis, minimisation, retention, and consultation. Network-traffic analysis can itself be high risk when used to infer behaviour. Keep the technical record linked to the legal assessment, procurement terms, security controls, operator training, complaint route, and review date.
10.9 Try the Sensing Privacy Checklist
Use the interactive to compare a proposed sensing design with a minimised alternative. It keeps identity colours separate from status colours, starts with a realistic room-occupancy preset, and produces a downloadable JSON decision record. A completed checklist is design evidence, not legal approval.
Open the checklist to download a decision record in a separate page if the embedded view is too small.
10.10 Decision and Trade-offs
Reject the sensing plan when its purpose is vague, a less intrusive sensor can meet the need, people cannot reasonably avoid it, or the team cannot support notice, rights, security, deletion, and error handling. Redesign when raw data or identity is convenient but unnecessary. Proceed only with a named owner, documented basis, bounded field and retention, tested accuracy, accessible notice, safe alternative, and a review date.
Apply this checklist to every chapter in this module: Wi-Fi CSI, RF localisation, radar, lidar, point clouds, vital-sign sensing, ISAC, and hidden-device detection.
10.11 Check Your Reasoning
10.12 Summary
Privacy follows the inference, not the sensor label. A radio or optical trace can become personal when it reveals a person’s presence, routine, location, behaviour, or health. Build the purpose, lawful basis, minimised data path, notice, retention, access, alternative, abstention, and review route before collection starts.
- Separate raw observables from every proposed inference and affected person.
- On-device processing and prompt deletion reduce exposure but do not replace transparency or a lawful basis.
- A downloadable checklist records a design decision; qualified review and current law still govern deployment.
10.13 Sources and Boundaries
- The ICO guidance on monitoring workers covers necessity, transparency, lawful basis, minimisation, retention, and impact assessment; it also notes that current guidance is under review after legislative change.
- The ICO data-minimisation guidance explains the adequate, relevant, and limited test.
- The official EU GDPR text is the starting point for EU deployments.
