Skip to content
The picture shows blurry traffic from above to symbolise the encryption of mobility data.

Anonymised Collection and Use of Mobility and Movement Data

Legal Perspective

Mobility data records how people, vehicles and goods move through traffic. This data is used by cities, local authorities, companies and mobility service providers to plan new cycle paths, identify overcrowded bus and rail routes, and set up additional bike-sharing stations in areas where they will ease traffic most effectively. However, processing this data is highly sensitive. If mobility data is not adequately anonymised, individuals can sometimes be re-identified. This poses a considerable risk to individuals' rights and freedoms, since knowledge of a person's regular movements can reveal information about their religion, workplace or state of health. For this reason, the processing of mobility data is subject to strict requirements under European data protection law. However, these requirements conflict with the potential that such data has for transport planning, innovation, research and data-driven value creation. However, it is often unclear whether a given anonymisation method actually meets the legal requirements. The question of which legal basis permits the anonymisation and sharing of such data, and when the individuals concerned must be informed about its later use, remains unresolved.

The joint research project Anonymised Collection and Use of Mobility and Movement Data for Innovative Mobility Services therefore combines technical and organisational concepts into a single procedure that allows mobility data to be collected, used, and shared securely without infringing the rights of those affected. The project relies on homomorphic encryption, which enables encrypted data to be processed without ever being decrypted. Consequently, individuals cannot be identified within the data, while the essential information about traffic patterns is retained. The aim is to keep the data usable for transport planning and research while minimising or eliminating the risks to the rights of those affected wherever possible.

Research

As a project partner, our sub-project Legal Perspective examines the extent to which anonymised mobility data still counts as personal data from a legal perspective. This determines whether it falls within the scope of European data protection law, particularly the General Data Protection Regulation (GDPR). Adopting a data protection by design approach (Article 25 GDPR), we share our interim findings with the project consortium in several iterative cycles to ensure the project's zero trust concept is implemented in a legally robust way.

Basic Research: Legal analysis and classification of modern anonymisation methods based on the encryption solution developed for processing and providing mobility data in compliance with data protection regulations.

Integration into the Use Cases: An ongoing comparison of legal analysis findings with data processing procedures used in partners' specific application scenarios, such as anonymising vehicle data within companies or usage data in car sharing.

 

Results in dialogue

We publish the findings of our research in the form of short papers and legal assessments, bringing them directly into the practice of cities, local authorities, and companies. Workshops and exchange formats with end users and practitioners aim to enable the former to understand the higher level of data protection offered by the encryption method, so they can make informed decisions. The latter can then apply the legally secure solution and gain a competitive advantage. Ultimately, we aim to provide companies with a solution that they can implement with legal confidence, and that users can trust.

Research team

Project consortium

  • Hochschule Esslingen (Coordinator)
  • Fraunhofer-Institut für Arbeitswirtschaft und Organisation (IAO), Stuttgart
  • motiontag GmbH, Berlin
  • cantamen GmbH, Hannover

Funding

Duration:1 June 2026 – 30 May 2028
Funding:Federal Ministry of Research, Technology and Space (BMFTR)

CONTACT

Maurice Stenzel, Dr.

Senior researcher: New Technologies and Future of Law

Research focus

New Technologies and the Future of Law

We examine when, how and by whom rules for technological innovations such as artificial intelligence, brain-computer interfaces and quantum technologies should be set. How can robust governance frameworks be implemented to achieve this?