Abstract
The use of BCI and XR-BCI devices is yet to become more widespread among the general population. These devices could pose a significant risk to the users’ privacy, as they enable the revelation of users’ emotions, beliefs, and other potentially highly sensitive details. When this information is obtained, it is possible to both invade users’ privacy as never before as well as monetize data very precisely through neuromarketing.
This work presents a review of the privacy and monetization of BCI and XR-BCI. It was discovered that many companies collect a considerable amount of data without knowing or revealing the actual purpose of the collection. This data includes sensitive information about health. One of the future risks is that emotions and generic raw brain-wave data are leaked to advertisers through neuromarketing, which is considered a valuable asset for advertisers, e.g., to reveal a person’s willingness to buy something. We urge the need to evaluate the current privacy policies and terms of service of BCIs and XR-BCIs against existing frameworks such as the General Data Protection Regulation (GDPR).
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Similar content being viewed by others
References
Adeli, H., Ghosh-Dastidar, S., Dadmehr, N.: A spatio-temporal wavelet-chaos methodology for EEG-based diagnosis of Alzheimer’s disease. Neurosci. Lett. 444(2), 190–194 (2008)
Ariely, D., Berns, G.S.: Neuromarketing: the hope and hype of neuroimaging in business. Nat. Rev. Neurosci. 11, 284–292 (2010)
Atalay, A.S., Meloy, M.G.: Retail therapy: a strategic effort to improve mood. Psychol. Mark. 28, 638–659 (2011)
Baglione, S.L., Tucci, L.A., Woock, P.: Would you pay for a facebook account to protect your privacy? J. Social Media Soc. (2020). https://www.thejsms.org/index.php/JSMS/article/download/693/405
Bellier, L., et al.: Music can be reconstructed from human auditory cortex activity using nonlinear decoding models. PLoS Biol. 21, e3002176 (2023)
Belmonte, A.: The mental health app data privacy problem is getting worse (2024). https://finance.yahoo.com/news/the-mental-health-app-data-privacy-problem-is-getting-worse-161425472.html. Accessed 15 Feb 2024
Benchetrit, Y., Banville, H., King, J.R.: Brain decoding: toward real-time reconstruction of visual perception. arXiv:2310.19812 (2023)
Birch, K., Cochrane, D., Ward, C.: Data as asset? the measurement, governance, and valuation of digital personal data by big tech. Big Data Soc. (2021)
Bonaci, T., Calo, R., Chizeck, H.J.: App stores for the brain: privacy & security in brain-computer interfaces. In: 2014 IEEE International Symposium on Ethics in Science, Technology and Engineering, pp. 1–7. IEEE (2014)
Brainaccess: Privacy policy. https://www.brainaccess.ai/privacy-policy/. Accessed 15 Apr 2024
Bryce, C.: Who invited the pay-for-privacy economy? (2019). https://medium.com/swlh/post-privacy-who-invited-the-pay-for-privacy-economy-626aecaf53e9. Accessed 20 Apr 2024
Chen, Z., Wu, J., Gan, W., Qi, Z.: Metaverse security and privacy: an overview. In: 2022 IEEE International Conference on Big Data (Big Data). IEEE (2022)
Dauwels, J., Vialatte, F., Cichocki, A.: Diagnosis of Alzheimer’s disease from EEG signals: where are we standing? Curr. Alzheimer Res. 7(6), 487–505 (2010)
Degeling, M., Utz, C., Lentzsch, C., Hosseini, H., Schaub, F., Holz, T.: We value your privacy... now take some cookies: measuring the GDPR’s impact on web privacy. arXiv preprint arXiv:1808.05096 (2018)
Dixon, S.J.: Annual revenue generated by meta platforms from 2009 to 2023 (2024). https://www.statista.com/statistics/268604/annual-revenue-of-facebook/. Accessed 17 Apr 2024
Duque-Hurtado, P., Samboni-Rodriguez, V., Castro-Garcia, M., Montoya-Restrepo, L.A., Montoya-Restrepo, I.A.: Neuromarketing: its current status and research perspectives. Estudios gerenciales (2020)
EMOTIV Inc. Emotiv privacy policy (2023). https://id.emotivcloud.com/eoidc/privacy/privacy_policy/. Accessed 15 Apr 2024
Commission, F.T.: children’s online privacy protection rule (2013). https://www.ftc.gov/system/files/2012-31341.pdf. Accessed 21 Apr 2024
Faroukhi, A.Z., El Alaoui, I., Gahi, Y., Amine, A.: Big data monetization throughout big data value chain: a comprehensive review. J. Big Data 7, 1–22 (2020)
Hargittai, E., Schultz, J., Palfrey, J., et al.: Why parents help their children lie to facebook about age: unintended consequences of the ‘children’s online privacy protection act’. First Monday (2011)
Landau, O., Puzis, R., Nissim, N.: Mind your mind: EEG-based brain-computer interfaces and their security in cyber space. ACM Comput. Surv. (CSUR) 53(1), 1–38 (2020)
Meta: Toward a real-time decoding of images from brain activity (2023). https://ai.meta.com/blog/brain-ai-image-decoding-meg-magnetoencephalography/. Accessed 20 Apr 2024
Meta: Research from meta—ar/vr (2024). https://research.facebook.com/publications/research-area/augmented-reality-virtual-reality/. Accessed 20 Apr 2024
Meta: Supplemental meta platforms technologies privacy policy (2024). https://www.meta.com/fi/en/legal/privacy-policy/. Accessed 15 Apr 2024
Mhaidli, A., Rajaram, S., Fidan, S., Herakovic, G., Schaub, F.: Shockvertising, malware, and a lack of accountability: exploring consumer risks of virtual reality advertisements and marketing experiences. IEEE Secur. Priv. 22(01), 43–52 (2024)
Mills, M.: Big tech sees neurotechnology as its next ai frontier (2024). https://finance.yahoo.com/news/big-tech-sees-neurotechnology-as-its-next-ai-frontier-100022978.html. Accessed 14 May 2024
Moens, J.: Your brain waves are up for sale. a new law wants to change that. (2024). https://www.nytimes.com/2024/04/17/science/colorado-brain-data-privacy.html. Accessed 21 Apr 2024
Morin, C.: Neuromarketing: the new science of consumer behavior. Society (2011)
Muse: Legal muse. https://choosemuse.com/pages/legal. Accessed 15 Apr 2024
Neuralink: Neuralink privacy policy (2024). https://neuralink.com/privacy-policy/. Accessed 15 Apr 2024
NeuroSky: Privacy policy (2009). https://neurosky.com/privacy-policy/. Accessed 15 Apr 2024
Nosthoff, A.V., Maschewski, F., Couldry, N.: Big tech is exploiting the mental health crisis to monetize your data (2023). https://eprints.lse.ac.uk/120934/. Accessed 15 Apr 2024
Obar, J.A., Oeldorf-Hirsch, A.: The biggest lie on the internet: ignoring the privacy policies and terms of service policies of social networking services. Inf. Commun. Soc. 23(1), 128–147 (2020)
Office of the Privacy Commissioner: Do i need to notify customers of changes to our privacy policy? (2020). https://privacy.org.nz/tools/knowledge-base/view/473. Accessed 21 Apr 2024
OpenBCI: Privacy & security (2021). https://docs.openbci.com/FAQ/Privacy/. Accessed 15 Apr 2024
Parvinen, P., Pöyry, E., Gustafsson, R., Laitila, M., Rossi, M.: Advancing data monetization and the creation of data-based business models. Commun. Assoc. Inf. Syst. (2020)
Quach, S., Thaichon, P., Martin, K.D., Weaven, S., Palmatier, R.W.: Digital technologies: tensions in privacy and data. J. Acad. Mark. Sci. 50, 1299–1323 (2022)
Reilly, C.M.: Brain-machine interfaces as commodities: exchanging mind for matter. Linacre Q. 87(4), 387–398 (2020)
Roesner, F., Kohno, T.: Security and privacy for augmented reality: our 10-year retrospective. In: VR4Sec: 1st International Workshop on Security for XR and XR for Security (2021)
Schneble, C.O., Elger, B.S., Shaw, D.M.: Google’s project nightingale highlights the necessity of data science ethics review. EMBO Mol. Med. 12(3), e12053 (2020)
Sony Interactive Entertainment LLC: Privacy policy (2024). https://www.playstation.com/en-us/legal/privacy-policy/. Accessed 15 Apr 2024
Stanton, S.J., Sinnott-Armstrong, W., Huettel, S.A.: Neuromarketing: ethical implications of its use and potential misuse. J. Bus. Ethics 144, 799–811 (2017)
Steinfeld, N.: i agree to the terms and conditions: (how) do users read privacy policies online? an eye-tracking experiment. Comput. Hum. Behav. 55, 992–1000 (2016)
Synchron: synchron privacy policy (2023). https://www.synchronbci.com/Synchron-Privacy-Policy.aspx. Accessed 15 Apr 2024
Tang, J., LeBel, A., Jain, S., Huth, A.G.: Semantic reconstruction of continuous language from non-invasive brain recordings. Nat. Neurosci. 26, 858–866 (2023)
Team EMB: the future of neuralink and marketing possibilities (2024). https://blog.emb.global/neuralink-and-marketing/#q-how-does-neuralink-collect-neural-data-for-marketing. Accessed 21 Apr 2024
Värbu, K., Muhammad, N., Muhammad, Y.: Past, present, and future of EEG-based BCI applications. Sensors 22(9), 3331 (2022)
Varjo: openbci and varjo partner to bring neurotechnology to spatial computing (2022). https://varjo.com/company-news/openbci-and-varjo-partner-to-bring-neurotechnology-to-spatial-computing/. Accessed 20 Apr 2024
Varjo HQ: terms of service for varjo xr-3 and vr-3 (2022). https://varjo.com/terms-of-service-for-varjo-xr-3-and-vr-3/. Accessed 15 Apr 2024
Varjo HQ: Privacy policy (2023). https://varjo.com/privacy-policy/. Accessed 15 Apr 2024
Wikipedia: vastaamo data breach (2024). https://en.wikipedia.org/wiki/Vastaamo_data_breach. Accessed 20 Apr 2024
Xu, Z., Chen, G., Zhang, R.: Boosters of the metaverse: a review of augmented reality-based brain-computer interface. Brain-Apparatus Commun. J. Bacomics 3(1), 2305962 (2024)
Zhang, X., Yue, W.T., Yu, Y., Zhang, X.: How to monetize data: an economic analysis of data monetization strategies under competition. Decis. Supp. Syst. 173, 114012 (2023)
Acknowledgment
(Part of) This work was supported by the European Commission under the Horizon Europe Programme, as part of the project LAZARUS (https://lazarus-he.eu/) (Grant Agreement no. 101070303). The content of this article does not reflect the official opinion of the European Union. Responsibility for the information and views expressed therein lies entirely with the authors. (Part of this work was) Funded by the European Union (Grant Agreement Nr. 101120962, RESCALE Project). Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the Health and Digital Executive Agency. Neither the European Union nor the granting authority can be held responsible for them. (Part of) This project was also supported by TED2021-132900A-I00 from the Spanish Ministry of Science and Innovation, and Guillermo Suarez-Tangil has been appointed as 2019 Ramon y Cajal fellow (RYC-2020-029401-I) both funded by MCIN/AEI/10.13039/501100011033 — with funds from the EU NextGenerationEU/PRTR and ESF Investing in your future respectively.
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2024 The Author(s), under exclusive license to Springer Nature Switzerland AG
About this paper
Cite this paper
Lahtinen, T., Costin, A., Suarez-Tangil, G., Yousefnezhad, N. (2024). A Review on Privacy and Monetization Aspects Within BCI and XR-BCI Ecosystems. In: Shishkov, B. (eds) Business Modeling and Software Design. BMSD 2024. Lecture Notes in Business Information Processing, vol 523. Springer, Cham. https://doi.org/10.1007/978-3-031-64073-5_11
Download citation
DOI: https://doi.org/10.1007/978-3-031-64073-5_11
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-031-64072-8
Online ISBN: 978-3-031-64073-5
eBook Packages: Computer ScienceComputer Science (R0)