Google COVID-19 Exposure Notifications Service COVID Cards Requirements

To aid in their response to the coronavirus disease 2019 (COVID-19) pandemic, some public health authorities are turning to digital solutions that provide evidence of vaccination, test results, or infection history (“COVID Cards”). We recommend that Exposure Notification (EN) apps do not include this type of functionality within their EN app. However, in the interest of public safety, information integrity, and user privacy,  and to support health authorities in their continuing efforts to manage the pandemic, this document lays out the minimum requirements for the implementation of COVID Card features in EN apps, consistent with the Google COVID-19 Exposure Notifications Service Additional Terms (“Additional Terms”). Exposure Notification Apps that include COVID Card functionality must comply with the Additional Terms, Play Store Developer Policies, Requirements for coronavirus disease 2019 (COVID-19) apps, and the following requirements:

App Requirements 

The use of COVID Card functionality cannot be mandatory and must be clearly separated from EN functionality.

End users must not be required to use the COVID Card functionality in their EN app. It must be an optional feature requiring an independent, separate opt-in by the user to activate. End users must be able to enable and disable exposure notifications in the EN app independently from adding and displaying their COVID Card. An end user who wants to use EN solely for exposure notifications or solely for COVID Cards must have clearly delineated options.

The COVID Card functionality in the EN app cannot be the only method available for users to display evidence of vaccination, test results, or infection history; it must be one among other available options. 

 

Collect and Display the Minimum Amount of End User Data Necessary.

COVID Card features may only be used for the purposes of managing the pandemic and must collect and display only the minimum amount of personally identifiable information (e.g. name, date of birth) necessary to achieve that purpose. Submission of personally identifiable information in order to use the Exposure Notifications functionality must be optional: while collecting/displaying this data may be necessary to use the COVID Card feature, the COVID Card feature must be optional within the EN app. 

In line with the requirements for Google Pay COVID Cards (contained in the Google Pay Passes API’s Acceptable Use Policy), COVID Cards may, but are not required to, reveal the below data types. Other data types (e.g. Patient ID, Government ID) are generally prohibited. If you would like to request any data type not listed below, you must submit a request through your Google point of contact, including a rationale for why this is required for your use case.

Permitted data types:

  • COVID-19 Vaccine Information 
    • Vaccine code (e.g., CVX), vaccine generic description, or vaccine manufacturer 
    • Date of vaccination 
    • Lot number
    • Dose number 
    • Administering facility
    • Future dose appointment details
  • COVID-19 Test Information
    • Test code (e.g., LOINC) or test description  
    • Test result 
    • Date of testing 
    • Administering facility 
  • Issuer information (name in plaintext, public key, digital signature, contact information)
  • Patient Name
  • Patient Date of Birth
  • Entry Eligibility Recommendation - An interpretation of a user’s: COVID-19 Vaccine Information, COVID-19 Testing Information, or COVID-19 Recovery Information to determine eligibility to enter a particular space or participate in a particular activity.
  • Expiration Date and Time 
  • Identity Assurance Level (IAL)

 

Maintain EN app feature data separately.

You may not link data collected for COVID Card features to any other app, or other feature in the EN app (even if you own or operate that app or feature), or otherwise combine data across features (Additional Terms 3(b)(vii) and 3(c)(iii)). Data from the EN API may not be an input into or displayed in the COVID Card, and the COVID Cards must not display any exposure notification-related information related to the EN app’s exposure notification features.

These requirements are subject to review and change by Google at its discretion.

Was this helpful?

How can we improve it?
false
Search
Clear search
Close search
Main menu
4287155031150711906
true
Search Help Center
true
true
true
true
true
92637
false
false