Over the last decade, a significant emphasis has been placed on the development of autonomous vehicles. The innovative technologies in autonomous vehicles significantly benefit society by reducing the number of accidents, congestion, and various socia...
Over the last decade, a significant emphasis has been placed on the development of autonomous vehicles. The innovative technologies in autonomous vehicles significantly benefit society by reducing the number of accidents, congestion, and various social and environmental issues. As a result, the Korean government aims to set the year 2027 as the target year for full commercial
autonomous vehicles, and Korean automobile manufacturers are actively planning the launch of level 3 autonomous vehicles.
As the rapid development of digital, communication and AI technology provides autonomous vehicles with the ability to create, collect, analyze, transfer, and use data, attention is now turning towards the potential privacy and data breach concerns that may arise in an autonomous driving environment.
The core autonomous vehicle technologies and functions are based on the acquisition and meticulous interpretation of an extensive swath of driving environment and personal data to enable the proper driving and control of the vehicle. The collection of such data encompasses specific data about a driver's behaviour, location, habits, and even comprehensive information on unrelated individuals, especially categorical identification of vulnerable road users, pedestrians, and the collection of facial recognition.
The collection and use of data by autonomous vehicles are seen as inevitable by some, while others argue that strict regulations must be established to protect people's privacy. Many developed countries and key industry stakeholders have dedicated efforts to set privacy and data protection standards to address potential ethical, legal and technical challenges. However, devising regulations that effectively balance innovation with privacy protection is
challenging.
In Korea, mobile video devices installed in autonomous vehicles are the most likely technology to create privacy and data breach issues. The type of data generated by mobile video devices requires the collection of pedestrian behaviors, facial recognition, random objects, roads, and vehicle exterior environment to enable proper driving and control of the vehicle in different types of conditions, environments and situations.
Historically, South Korea imposed strict laws relating to privacy and the collection of personal data and information. Accordingly, there were no specific legislative frameworks to address the privacy issues and allow the use of mobile video devices for autonomous vehicles.
However, on 15 September 2023, an amendment of the Personal Information Protection Act introduced a distinct definition for "mobile video devices," categorically encompassing autonomous vehicles. Under specific conditions, the statute permits the recording of visual imagery involving persons or objects in public spaces via mobile video devices, even without the subject’s consent, provided such recording serves a business related purpose, and the act of
recording is unequivocally communicated.
Despite this, the practical execution of satisfying legal requirements still poses many challenges. The conspicuous placement of notification signs or the utilization of LED and flashlight indicators on the surface of autonomous vehicles has practical constraints. Moreover, even when these indications are observed, pedestrians and bystanders may lack the perceptual awareness to understand and recognize the actual recording.
Furthermore, while the law governing the operation of mobile video processing devices permits recording under defined conditions, the law still requires adherence to the principle of prior consent for the use of personal information. The principle of prior consent raises questions about the effectiveness of the new regulation in developing fully autonomous vehicles in Korea without violating privacy laws and regulations.
This research proposes two simultaneous strategies. In the short term, the government should issue temporary special permits for personal information collection and encourage various stakeholders to achieve fully autonomous vehicles. In the long term, the research recommends amending the Personal Information Protection Act to introduce new mechanisms like personal information processing privacy policy certification and privacy impact assessments to protect personal information collected from diverse groups of individuals. Finally, regulatory bodies
should develop strict guidelines to enhance security on the relevant technology to strengthen data protection in autonomous vehicles.
This research aims to provide solutions to the Korean autonomous vehicle industry with actionable solutions aiming to strike an optimal balance between privacy protection amidst the active development of fully autonomous vehicles in Korea.