Apple and Google should add contact tracing functionality, similar to Singapore's TraceTogether app, in a privacy-respecting way to iOS and Android
Jon Evans / TechCrunch :
Context & Ripple Effects
Jon Evans's TechCrunch column landed at the start of the pandemic's first wave, arguing that Singapore's TraceTogether app showed the model — Bluetooth-based, opt-in contact tracing — and that only Apple and Google could make it work at population scale by building it into iOS and Android themselves rather than leaving it to fragile third-party apps. Two weeks later the companies answered: they announced a joint effort to ship iOS and Android APIs for opt-in Bluetooth exposure notification by mid-May.
That arc makes this op-ed a rare case of a policy wish list turning into shipped platform infrastructure: by late May the Exposure Notification API was live with at least three US states building apps on it, and coverage framed it as the most privacy-respecting approach to contact tracing ever deployed.
First-order effects
- Apple and Google moved from publishing no health-related APIs to committing OS-level Bluetooth exposure-notification interfaces, gated so only health authorities can access them and running only on iOS 13 and Android 6+ devices updated via Google Play.
Second-order effects
- US state health departments became the API's first customers, building official apps on top of it instead of commissioning bespoke tracing systems, which concentrates design decisions about privacy and efficacy in Cupertino and Mountain View.
Third-order effects
- The episode establishes a template for platform owners acting as de facto gatekeepers of public-health technology — deciding who may access sensitive signals and under what opt-in constraints — a role regulators have not formally claimed.
The trend: Mobile operating-system vendors are becoming the default privacy infrastructure layer for public-health and safety technology, with their API terms doing the work regulation otherwise would.