Despite qualms from some experts, Google and Apple's exposure notification API enables the most privacy-respecting approach to contact tracing in history
Apple and Google have now released their update to their mobile operating systems to include a new capability for COVID-19 exposure notification.
Context & Ripple Effects
The public rollout caps a rapid arc: after confirming in mid-April that the system would run on iOS 13 and Android 6+ devices with access restricted to health authorities, Apple and Google spent the following weeks publishing an FAQ addressing privacy concerns and pledging to switch the APIs off once the pandemic is contained, then detailed app policies that bar location data collection. Today's OS updates make the capability real for end users, with at least three US states already building apps against it.
What makes this notable is the delivery mechanism: rather than leaving contact tracing to dozens of bespoke government apps with uneven privacy practices, the two platform holders embedded the protocol at the operating-system layer, where their existing developer rules — not health-agency procurement — set the terms.
First-order effects
- State health agencies get a standardized, interoperable Bluetooth exposure-notification backbone without writing their own low-level code, but only for users on iOS 13/Android 6 or newer — anyone on older hardware is simply outside the system.
Second-order effects
- Health authorities designing their own tracing tools now face a fork: adopt Apple and Google's decentralized protocol and its no-location-data rules, or build outside the OS layer and forfeit the reach that comes with it.
Third-order effects
- If the pattern holds, platform vendors' published policies — like the prohibition on location collection — become de facto regulation for public-health software, and the pledged post-pandemic shutdown becomes the test case for whether OS-level emergency powers actually get switched off.
The trend: Public-interest software is increasingly governed by Apple and Google's OS-layer policies rather than by legislation, making the two platforms the de facto privacy regulators for crisis-response technology.