Course:ELEC300E/CaseStudies/AutonomousVehicles
Context: Privacy in Law and Design
| Autonomous Vehicles |
|---|
![]() |
| Content / Topics |
| Axiological Design |
| AI |
| Sustainable Computing |
| Indigenous AI |
| Relevant Analysis Strategies or Tools |
| Decision Impact Assessment |
| Iceberg Model |
In Canada, several federal and provincial laws and regulations govern our right to privacy.
- The Privacy Act relates to how the government handles personal information.
- PIPEDA relates to how private businesses handle personal information (except for in Alberta, BC and Quebec - although their provincial laws are largely equivalent)
- Each province has additional provincial regulations
The focus of the Privacy Commissioner of Canada's Data Privacy Week 2026 was 'Privacy by Design', a design methodology that prioritizes privacy:
Case: Autonomous Vehicles
Autonomous vehicles promise many advantages including convenience, efficiency, and accessibility. Research also consistently shows that self driving cars are also significantly more fuel efficient.
However there are also concerns - in particular, about surveillance and privacy. According to the Electronic Frontier Foundation:
Autonomous vehicles rely on more than a dozen cameras and sensors situated around the car in order to detect other vehicles, traffic signs, obstructions, and pedestrians. Because the most visible autonomous cars are operated by private companies, there is a lot that we do not know about the storage, security, and access regarding this footage. It is unclear, for instance, how detailed the footage is of pedestrians on the street or whether that footage is run through any image recognition. What capabilities do these vehicles have to collect audio? How long is this footage stored for? Who has access to it? What protections are in place to keep the footage private and safe? How do these companies comply with local and state-wide privacy laws like the California Consumer Privacy Act?
Police (in California at least) are already using this data to investigate crimes, and critics also argue that collected data could also be accessed by hackers. If you are interested in how these systems work and how privacy and security attacks might occur, this paper offers a useful overview.
Recommended Readings and Resources
- ~5 minute read, The Impending Privacy Threat of Self Driving Cars, EFF, https://www.eff.org/deeplinks/2023/08/impending-privacy-threat-self-driving-cars
Discussion Questions
Here are a few questions to help you begin analyzing the issues discussed in this case study. The purpose of these questions is to prompt reflection and further consideration: there are no right or wrong answers!
- Positive action: What is one action that you would advocate for (either from engineers, lawmakers or consumers) when it comes to autonomous vehicles where you live?
- Personal response: Take stock of your initial reaction to this case study. How do you think your values and experiences shape your response?
- Contradictory viewpoints and outcomes: What are the most compelling arguments for and against the use of self driving cars? What underlying values or priorities inform those arguments?
- Social and Historical Context: Your personal comfort-level with governments or law enforcement having access to widespread camera footage might depend on what country you are from, your political views, and whether you have been impacted by the overpolicing of minority communities. How do you think these broader social and historical factors impact your perspectives?
- Interruptions and invitations: Whether you think autonomous vehicles should be banned, regulated or encouraged, what laws or regulations should be enacted to shape the industry?
- Physical connections: How would this play out in your neighborhood? Take a look at this map of crimes reported by the police department, and this map of surveillance devices. Does considering the problem on a more local scale change your perspective?
- Positive Practices: How could autonomous vehicle designers enact Privacy by Design? What is one example of a concrete design decision that would proactively address privacy concerns?
