Legal base for CS projects
There are potential legal issues that may be relevant to citizen science. They should be identified and assessed before planning the projects. There are various laws that may restrict your ability to collect information necessary for the project. It is important that you check the regulations of the specific jurisdiction in which you are conducting a project. You should try to educate yourself about statutes, regulations relevant to the citizen science project.
- Legal issues related to the location of the project
- Trespassing
Trespassing is an offence when one enters into the private territory without the permission of the owner or authorized personnel. Firstly, you should ask the property owner for permission, if you need to enter or cross the private territory in order to collect samples. Avoid areas marked by fences or "Restricted access" signs. However, it would be wise to use GIS apps and know the property boundaries when conducting surveys around such a property.
- Loitering
Loitering refers to the act of lingering or staying in a public place without a specific purpose or reason. It typically involves spending an extended period of time in a particular area without any apparent intention to conduct any legitimate activity or business. In some cases, loitering may be associated with suspicious or criminal behavior, which can result in intervention by law enforcement or security personnel. Therefore, before you spend time around your designated project site, you should examine the local anti-loitering legislation.
- Stalking
Stalking is described as harassing or persecuting someone with unwanted and obsessive attention. It is good practice to keep a comfortable distance when conducting a survey and to avoid repeated contact with the same people. You might, for example, post flyers in the area informing the people that you are participating in a citizen science project. If people know what you are doing in or around their neighborhood, then they should not have reason to feel threatened by your presence.
- Invasion of privacy
Invasion of privacy refers to a violation of an individual's right to keep certain aspects of their personal life or information private. It can occur when someone intrudes on an individual's private space, accesses their private information without permission, or publicizes personal information about them without their consent. You could avoid claims of intrusion upon private affairs if you do not enter private space and be cautious when taking pictures or videos around people’s homes or publishing those pictures or videos. If the citizens science project activities take place near private residences, be sure that collected and published material do not contain any images of persons within those residences.
- Drone laws
If you plan to use the drones for your project, it is important to be aware of the laws and regulations in the specific jurisdiction in order to avoid legal trouble and ensure safe and responsible operation of the drones. Many countries require drone operators to register their drones with the government or aviation authority. Drone laws may specify where and how high drones can be flown. It may also address concerns about privacy and data protection, such as limits on the use of cameras or restrictions on where drones can be flown. It is recommended to avoid flying your drone over the same space with great frequency.
- Critical infrastructure laws
Critical infrastructure refers to the physical and virtual systems and assets that are essential for the functioning of society and the economy. Their failure or disruption can have significant consequences for public safety, national security, and economic stability. Examples of critical infrastructure include: energy systems, such as power plants, oil and gas pipelines, and electrical grids; water and wastewater systems, including treatment plants and distribution networks, transportation systems, including highways, airports, and railways, government facilities, including military bases and government buildings. You should avoid to enter forbidden territories or critical infrastructure sites, if you don't have the permission from authorities.
- Environmental laws
Citizen science projects that involve the collection of environmental data may be subject to environmental laws, such as those related to the protection of wildlife or the management of natural resources.
- Legal issues related to the data protection
- Categories of collected data
Personal data (name, e-mail address, ID number, phone number, etc.). If the information can identify you, then it falls under the category of "personal data" and will need to be protected. Personal data must be adequate, relevant and limited to what is necessary for the purposes for which they are processed (data minimization principle).
Sensitive data (religion, political views, racial and ethnic origin, trade union membership, health records, sex life or sexual orientation, etc.). Sensitive data is any information that could be harmful or damaging if accessed or disclosed by unauthorized individuals, and that requires a higher level of protection than other types of data.
- Principle of "data minimization"
The data minimization principle is a fundamental concept in data protection and privacy regulations, such as the European Union's General Data Protection Regulation (GDPR). It requires that only the minimum amount of personal data necessary for a specific purpose should be collected, processed, and retained.
- Deciding what data to collect
Different data collection methods can be used to collect the right data from the right source at the right time. How data are collected depends on a variety of factors, including accuracy, timing, cost and utility. Identify information needs, assess the full costs of obtaining and maintaining and updating new data, and then determin whether the costs are justified. It‘s advisable to collect only the data you need, to collect data to the lowest level of detail sufficient to make appropriate decisions; and to collect data only when you need it.
- Responsibility for data destiny
There are two data protection roles important to every citizen science project : "data controller" and "data processor". The data controller is exactly responsible person(s) or organization(s) entrusted with data protection legislation obligations. This responsibility combines the purpose of collecting the data, authorizing the people who can work with the data, and ensuring that procedures for working with the data comply with the legal framework. A data processor is a person who manages data on behalf of the project. The controller or processor should never hold more data than is necessary to achieve the purposes of the processing. It is also important to remember that controllers also have to respond to subject access requests, which is more difficult if old data are kept longer than necessary.
- Informed consent
Webinar on informed consent in citizen science:
- Data security/data breach
Data breaches can be a serious concern in any citizen science project, where personal or sensitive information is collected. If this information falls into the wrong hands, it can be used for identity theft, fraud, or other malicious purposes. There are multiple types of incidents that could lead to a data breach, e.g. unauthorized access, a misdirected e-mail, hacker attack, etc. To minimize the risk of a data breach, citizen science projects should implement strong data security practices. This can include using secure servers and databases to store data, encrypting sensitive information during transmission and storage, and limiting access to data to only those who need it to perform their roles in the project. Additionally, it is important to ensure that all volunteers are aware of the risks associated with collecting and submitting data, and that they are educated on how to protect sensitive information. This can include providing training on data security best practices, as well as regularly reminding volunteers of the importance of maintaining data privacy and security.
In citizen science projects, it is useful to designate a specific person to take protective action. In the event of such a situation, the supervisory authorities and/or persons whose data have been compromised must be informed as soon as possible. Conducting a thorough investigation to determine the cause of the breach, and implementing new security measures to prevent similar incidents from occurring in the future is highly recommended.

- Estonian Personal Data Protection Act
- Latvian Personal Data Processing Law
- Republic of Lithuania Law on Legal Protection of Personal Data