27 Juli 2026 Kathrin Haimerl, Abteilung Kommunikation, University of Passau

Traditional categories of discrimination are not enough: ethicists at the University of Passau have developed policy recommendations on data protection.

The health insurance provider is offering an incentive: anyone who tracks and improves their sleep data will receive money. What may serve as a means of self-optimisation for some becomes a risk for others.

A research team at the University of Passau, led by the ethicist Professor Karoline Reinhardt, has worked with partners from the Universities of Kassel, Tübingen and Duisburg-Essen to investigate who is particularly vulnerable in the digital sphere. The key finding is that vulnerability is not a fixed characteristic in the context of data protection. It only arises within a specific context. The Passau team, which is involved in the project DiversPrivat – Diversity-Sensitive Privacy Protection in Digital Environments funded by the BMFTR, has presented its findings and recommendations in the form of a policy paper.

“Traditional categories of discrimination such as gender, ethnic origin or age often fall short when it comes to data protection,” says Professor Karoline Reinhardt, who heads the Passau sub-project as part of DiversPrivat. Dr Lukas Naegeli, research assistant and lead author, adds: “Specific vulnerability in the area of data protection is context-dependent and can vary in severity depending on technical, social and institutional circumstances.”

In the policy paper, published as part of the ‘Research Reports’ series by the Privacy Platform, the researchers illustrate this using the example of digital health applications. Whilst the use of a fitness, period-tracking or mental health app is harmless for some people, it can entail significant risks for others. For example, those in precarious employment are more reliant on ensuring that sensitive health data does not fall into the hands of third parties, as insurance companies or employers could use it as a means of exerting pressure. By contrast, people in stable circumstances often have greater scope for action. They can choose privacy-friendly alternatives, use paid services or, in the event of a conflict, change jobs.

A single person may therefore be vulnerable along different dimensions, some of which are relevant in certain situations and not in others. The research team therefore proposes combining the broader concept of diversity with that of vulnerability in order to identify protection needs that are more closely aligned with the lived realities of those affected. It is also crucial, they argue, to involve those affected in the development of concrete measures.

The policy paper sets out the following practical recommendations:

  • Ethical principle: Specific vulnerabilities arising in the area of privacy protection across a range of diversity dimensions should be recognised and addressed with appropriate protective measures.
  • User interface design: Physically perceptible stimuli, such as visual or auditory signals, could raise awareness of privacy risks.
  • Legal framework: The General Data Protection Regulation (GDPR) should be supplemented with a context-specific diversity perspective. Consent processes should be accessible, for example through information in plain language or audio output.
  • Science communication: Vulnerable groups should be actively involved. Only in this way can blind spots in research be uncovered and innovative solutions developed.

About the DiversPrivat project

The interdisciplinary DiversPrivat project is coordinated by the University of Duisburg-Essen. Researchers from the fields of psychology, law, applied ethics, media ethics and science communication are involved. The German Federal Ministry of Research, Technology and Space (BMFTR) has been funding the project for more than three years.

The team at the University of Passau is responsible for the sub-project on applied ethics. The researchers are investigating which groups of people are disadvantaged when it comes to the protection of their privacy and how this manifests itself. The policy paper is the project’s first. The recommendations from the Passau group are also being incorporated into the other sub-projects. For example, a team from the field of social psychology is testing whether and how the incorporation of physically perceptible stimuli heightens awareness of data protection.

This text was machine-translated from German.

Contact for scientific information:

Professor Karoline Reinhardt
Professorship of Applied Ethics
University of Passau

Email: Karoline.Reinhardt@uni-passau.de

Dr Lukas Naegeli
Professorship of Applied Ethics
University of Passau

Email: Lukas.Naegeli@uni-passau.de

Original publication:

Naegeli, L.; Sinn, J.; Reinhardt, K.; Geminn, C.; Heesen, J.; Hennig, M.; Schmied, L.; Strathmann, C.; Krämer, N. (2026): Diversitätsgerechter Privatheitsschutz. Empfehlungen zum Schutz der Privatheit vulnerabler Gruppen in digitalen Umgebungen. Forschungsberichte der Plattform Privatheit, Nr. 7, hrsg. v. Friedewald et al. Karlsruhe: Fraunhofer ISI. https://doi.org/10.24406/publica-7592 

Source: https://idw-online.de/de/news875132

Back to top Icon