Governing privacy: systems, participants and policy instruments

AUTHOR
Charles D. Raab

ABSTRACT

In this paper, we sketch a view of the emerging system of information privacy protection as it might be developed. We use the word ‘system’ to emphasise the importance of relationships amongst the organisational, legal, personal, governmental and other elements through which the future of privacy is arbitrated. One important task is to understand these relationships better. Another task is to develop a theoretical framework through which we might explain the use and impact of different privacy protection instruments and approaches. A third task is to explore the potential for privacy protection policy in the future.

Some drivers of change are in the realm of technology, values and ethical issues, but others are identifiable groups. The main ones include the general public, who are becoming more aware of privacy risks but who – as consumers – want better services and more goods; businesses, which want to exploit personal data assets but which also need public trust; and governments, which likewise want to rationalise and co-ordinate their use of personal data but which also have to uphold certain commitments to protecting privacy. Privacy pressure group activists are also an identifiable factor.

Building upon some of our previous writings, we try to identify somewhat more precisely the participants (akin to ‘stakeholders’) who form the basic units of the system through which privacy-related decision-making takes place. A relevant and provisional minimal list of participants includes:

  • the agency(ies) that implement privacy laws and regulate practices
  • governments, which make policies and laws (including privacy laws) in which privacy is implicated
  • businesses, which use personal data
  • the public, who are data subjects
  • privacy pressure groups and other political actors, including the media
  • technology developers and providers

The following schematic diagram displays their possible categorical relationships within a system of privacy protection:

raab

This picture can be looked at in at least two ways. In one sense, it describes players and their interdependence in what might be called an implementation system for privacy protection: that is, a system which shapes the outcome, or the quality of privacy that is available in the society. In this sense, the arrows could represent mutual support, as they all pull together towards protecting privacy. We could then perhaps observe that some arrows are ‘stronger’ or more important than others – that more support is offered in some relationships than in others. Nonetheless, from this perspective one can talk about synergy.

In another sense, however, and not completely different from the first, the diagram portrays a political system in which the attitudes and actions of participants contribute significantly to the outcome, as they use resources of various kinds – formal powers, money, technical expertise, publicity, and others – in a complex set of exchanges, influences, compromises, sanctions, shifting alliances, and so on. Looked at in terms of a policy and implementation network, the diagram can draw upon as well as provide a way of illuminating contemporary general theories and models of governance. What is particularly important is the distribution of power to determine the outcome. It is also a system or network in which the relationships may vary along a continuum between consensus and conflict; therefore, it is a political system and not simply a purpose-built or synergistic mechanism for producing privacy protection.

The paper keeps both of these related perspectives in mind, whilst also noting that there is no easily identifiable ‘top’ that can ensure that the outcome satisfies its intentions or desires. Even though there are legal and formal requirements, for instance, these cannot always be imposed even if imposing them were a sensible and desirable way to protect privacy. We argue that privacy protection has to be negotiated through the system described in the diagram, rather than decreed. This is most important if, beyond simply describing what happens, we are thinking of a scenario of instruments or strategies for privacy protection. This is especially so in view of what has become, in very recent years, a conventional wisdom that protecting privacy in the ‘information age’ depends upon some combination of legislation, regulatory activity, self-regulation by data users, privacy-enhancing technologies, and individual self-help by data subjects. In most discussions, these policy instruments have been considered in isolation one from another. There is a certain amount of rhetoric about a ‘mosaic of solutions’ or a ‘regulatory mix’. With a few exceptions, a serious treatment of how these approaches relate one to another within a coherent implementation system remains to be done. That task relies upon a better understanding of the roles played by the various participants within the system for the implementation of privacy protection policy, and of the conditions affecting their performance and interaction. We draw upon relevant political science literature on the nature and choice of policy instruments to develop these theoretical arguments, including a typology of instruments and comparisons among them according to certain selected variables. We emphasise that no policy instrument can stand alone: each one depends upon action elsewhere in the system, and that action may need to be cultivated, and relationships designed, rather than simply waited for to happen.

The paper is informed by research-based evidence from two cases: the UK and Canada. The former has been implementing a data protection regime since 1984. Canada has had data protection for the public sector since the 1970s, but has only just introduced statutory protection for private sector organisations, to be enforced from 2000. The analysis of these cases allows a comparison of one developed regime and one that is less developed, although they co-exist in a policy framework that is shaped in part by international understandings, the global spread of information and communications technologies, normative guidelines and institutional machinery. The paper suggests how the ‘co-production’ of privacy protection perhaps occurs in similar ways within two political systems that otherwise differ in a large number of structural and cultural respects.

By exploring these theoretical issues and empirical developments, the paper draws implications for practice that might contribute to future developments of data protection regimes on the basis of better understanding of systemic roles, relationships and interactions, as well as of policy instruments.

Biometrics and Privacy. A note on the politics of theorizing technology

AUTHOR
Irma van der Ploeg

ABSTRACT

Two lines of argument exist regarding the question whether biometrics are the next threat IT practices pose to the privacy of people. The first is the obvious one that sees biometrics as a new and pernicious way to identify, track, and profile people in ways that surpass the already daunting possibilities of existing systems. Involving what are presented as unique, positive identifyers, biometric data promise the unequivocal coupling of ‘the digital persona’ to one particular individual body.

The second line of argument, on the other hand, sees biometrics as a potential solution to privacy problems by its potential to provide, for example, verification of identity in transactions and delivery of services without disclosing name, address, or other personal data. It stresses that biometric data do not contain much meaningful information, and that the irreversibility of the processing of biometric data required by most systems prevents misuse.

This paper will not take sides in this dispute, but, rather, analyse the opposing views within the debate on their tacit assumptions regarding the nature of ‘privacy’ and of technological development and practice. It argues that both general assessments of biometric technology rely on a concept of what the technology in itself is and implies on the basis of assumed, feared, or hoped for configurations of which the technology will become part.

When looking into the proposed and existing regulations and legislation on biometrics, rather than being reassured by the guarantees provided therein, one senses what exactly is to be feared from biometrics and how much is needed to prevent it from being damaging to privacy and liberty and equality. Faced with these threats, however, the paper argues, the politics of theorizing technology itself becomes an important issue that needs to be addressed. A specific case is presented that shows how specific attributions of inherent qualities to technology may in some contexts, actually provide a rhetoric that helps to acquire the political leverage needed to shape future technological configurations in a more socially reponsible and ethically just way.

Teaching Ethics Embbedded in Technical Subjects

AUTHOR
Rosalia Peña, Juan Botía and Javier Extremera

Published in: ETHICOMP Journal Vol 1 Issue 2

ABSTRACT

Nowadays, there is an imperative need of familiarizing future computer professionals with some basic ethical principles. It stems from the fact that in today’s world, these professionals in par with others, are exposed to growing number of ethical dilemmas concerning his/her professions.

The present article discusses a way of teaching ethics in professional fields as applied to 3 year of Computer Science and Telecommunication Engineering students. Our approach consisted on include different aspects of professional ethics into the curricula of subjects directly related to the Telecommunications and Computer Science major. This discussion is accomplished by analyzing answers from two surveys as conducted at the beginning and at the end of the Professional Data Protection, a 45 hours course, offered at Alcal University.

The time allotted to study of Ethical, Legislation and Technical aspects comprised in the course were 7, 9 and 28 respectively.

The students who are about to graduate seemed to be more interested in debates on ethical and legal issues. Linking these topics with teaching technical aspects of Protection of Information helped students realize potentially beneficial or harmful effects of computer on the society. Hopefully, after this course, the students will assimilate these issues as a constituent part of their professional responsibility and try to minimize effects that are not desirable. For the most part, the students confirmed that the debates held within the framework of the course, will influence their behavior when faced in the future with professional dilemmas.

After the course was over, students valued their training in a more positive way in all the aspects: ethical, legal and technical; expressing satisfaction that it was approached as an integrated whole. Their answers confirmed usefulness of this approach in raising standards of education toward total quality, the final objective of any teaching process.

Of all the students who have signed up for our course , less than half of that total said at the beginning that they might have chosen a course specifically devoted to ethics, which implies that our integrated approach appeals to more studets than the specialized method.

The interest in attending organized debates or lectures on the subject of Privacy and Protection of Data has diminished accordingly, yet, personal involvement and interest to those matters has eventually increased.

It is encouraging that short time is sufficient to detect a meaningful change of attitude in the students. Even the conducted surveys have proven their efficiency as didactic tools capable of invoking positive change of attitude in the name of the importance that the students of Computer Science give to privacy. Post-survey analysis yielded an added value by showing them how different are our initial reactions caused by a situation which affects us directly from soul searching response.

From all the previously results, it can be concluded that integrating ethical aspects into the subject matter of our course, enhances the students interest in the same.

Facultative must closely cooperate with and learn from Ethic and Legislation experts in order to adapt methodological tools for tutoring topics so distinct from those which are customarily dealt with and advise on themes and up to dates.

References

P. Clipsham, D. Chadwick y A. Stanley; “Teaching Information Integrity an ethical approach”. Proceedings of the Fourth International Conference on Ethical Issues of Information Technology. ETHICOMP 98. Holland (1998) pp 140-149.

R. Peña y J. Extremera. “Teaching Ethics in Computer Science. How it is approached in Spanish Universities”. Proceedings of the Fourth International Conference on Ethical Issues of Information Technology. ETHICOMP 98. Holland (1998). pp 547-554.

Project Impacts CS Steering Committee. The Consecuences of Computing: A framework for teaching the Social and Ethical Impact of Computing. First Report. The George Washington University, January 1995.

Martin, C. Dianne; Huff, Chuck; Gotterbarn, Donald and Keith Miller. “Implementing the Tenth Strand in the CS Curriculum,” Communications of the ACM. Vol. 39, No 12, December 1996, pp. 75-84.

JD. Vance. The Tavani Bibliography of Computing, Ethics, and Social Responsibility. ISWORLD. Editor: Herman Tavani, Rivier College. http://www.siu.edu/departments/coba/mgmt/iswnet/isethics/biblio/ 25/3/98

Gotterbarn, D. and Reiser. R. “Ethics Activities in Computer Science Courses: Goals and Issues,” Computers and Society, Vol. 27, No. 1, March 1997, pp. 10-15.

T. Bynum. RE: Computer Ethics in the New York Times: Privacy is dead?. Computer ethics list: COMPUTER-ETHICS@mailbase.ac.uk. 12-03-1999

Technological Mafia and “off-shore” legal activities – Existing Relationships Between Criminality And Information Society

AUTHOR
Emanuela Pauselli

ABSTRACT

The first objective of this study is to provide a general overview of the utilization of information technology and telematics for the management of economic and financial flows on the part of criminal organizations, identifying those methods most commonly employed for such purposes. The professionals involved in such activities may be dealers in the various sectors of the market, and/or members inside the Mafia itself. The second objective is to categorize such people and to analyze in behavioral and ethical terms the mechanisms underlying such conduct and how such comportment could be fought.

The relationships among economics, finance and criminality, fit into the wider social and economic scenario. Therefore, this work considers the strong influence that the development of the Information Society has on money laundering techniques. The involvement of professionals in “offshore” legal activities, leads to some reflections on ethical and deontological aspects, which should regulate such behaviour.

The paper will illustrate the history of the Mafia criminal activity, the current relationship with the economic and financial sectors and the realisation of illegal income and money laundering.

Organised crime operates essentially reinvesting illegal capital with the basic intention of separating it from its illegal origins, so as to then transform it into legal operations: this is money laundering.

In the paper we shall describe the most frequently used methods to launder money, showing their technological evolution in the bank channel, in the non-banking financial services sector, and in other channels and sectors utilized for this purpose.

Developments of I.T. applications are deemed as a great opportunity to exploit, in order to carry out illegal activity or, in any case, legal only as regards appearances and form but not in substance as they originate for wholly illegal purposes. Naturally, money laundering methods have been subject to evolution which has led to the use of technological instruments (IT), information networks (CT) and professionals who are experts also in information technology so as to be able to carry out ever more complex and obscure operations.

In the paper will be explained the relation between network money and technological Mafia activities.

In fact, ‘The Network’ is the best reliable mechanism to foster new type of “on line” transactions or “real time” payments. The growing globalisation leads toward the introduction of a kind of payment system made of byte called “network money”. There are a lot of opportunities to invest directly through the Network because of the presence of ‘Brokers on-line’ at a very low cost. Unfortunately Mafia and corrupt organisations may use network money to support their crime traffics. In fact it is easy for a criminal organisation to develop a network money parallel system: it needs to create first of all an information technology operating system, then find the right software and financial know-how to build business and create or exploit a ‘connection point’ with legal networks.

The paper will analyse the professionals features and in conclusions ethics and professional behaviour.

We are used to think of Mafia and criminal organisations as formed by violent people deeply involved in murdering, stealing and drug trafficking. When we talk instead about “money laundering” we must take into account also another kind of criminal feature: “white collars”. It’s very important to outline that Mafia and criminal organisations, as real crime corporations have to count on managers and professional skills to perform their business. Criminal organisations are obliged to employ someone who has got also financial skill. Thus it is necessary to find a strong support in financial and banking system. Money laundering is made through Banks, Investment fund, multinational corporations, brokerage firms and other financial institutions with the help of insider very skilled people knowing very well where are possible choke points in the procedure, for each type of transaction.

Considering criminal organisations and professional features, we have to understand what is the reason of the collaboration and what are the ethical limits that occur into the relationship. Talking about professionals we intend workers in the field of Information technology, software analysis, financial and banking system and brokerage firms. Professionals who get in touch with Mafia have to understand how to behave themselves in front of certain kind of offers and as far as they can push themselves without incurring in penal responsibility. What could be the right answer to these situation? First of all is the conscience, second the knowledge of the situation (know your customer) and third ethics.

Information technologies, democracy and economic power

AUTHOR
Hendrik Opdebeeck

ABSTRACT

Information technology can be defined as a medium, as a means to produce or to transfer something. The computer and television are promptly dealt with as ‘media of information’, whereas the concept of ‘mass medium’ is referred to as a ‘community means reaching the general public’. Thus the concept of information technology is very close to the concept of power, which is usually conceived as the capacity to overcome any resistance in order to reach a specific goal. The power of the television e.g. refers to the capability to break people’s resistance to buying a certain product, by advertising.

When the power of the information technologies lies in their capacity to overcome resistance in order to reach a specific goal, today it is highly important to check which goal is concerned, which targets are being set and which resistance is being overcome. Could the power of the information technologies increasingly lie in the capacity to ignore democratic values in order to reach economic purposes of the market place? According to some authors however, power is not mere possession, but a very strategy pursued within an intricate net of ever-changing relations. This approach impels us not to interpret power as something pejorative in itself. The power of the information technologies need not be a negative (ethically condemnable) phenomenon. Crucial is from which ethical motives power is framed and exercised. Utilitarianism is increasingly becoming the exclusive ethical standard of the concept of power. Utilitarianism is so dominant that consequently human activity risks to come loose off the major democratic criterion of justice. From an ethical point of view it is a task to find out, on the one hand, to what extent the power of the information technologies may contribute to bringing about more justice into our democracy and, on the other hand, to what extent justice is being used as a moral standard in these technologies, while exercising power.

It becomes obvious that, in a world in which information technologies and economic power are so prevalent, guaranteeing democratic justice has become an extremely and utmost delicate matter. The main barrier in going for a more just and equitable information society, in which the communication technologies do not threaten to undermine democracy, is apparently the tension between merits, needs and progress. Taking as a principle of distributive justice, ‘everyone his or hers in accordance to his or her needs’, into information society, one reaches more equality, though, but the homo-economicus would be stimulated too little to keep performing in an efficient and productive way. The other well-known principle of justice, ‘everyone his or hers in accordance to his or her merits’, which meets the want of a working stimulus, however implies, that the economic progress is granted ‘carte blanche’. The awareness of the bounds of progress, which has become widely accepted in recent years and which, in the transition to the 21st century, will all the more remain of topical interests on moral level, apparently puts question marks to the exclusive principle of merits in the information society. Even the most optimal forms of mixed market economy in a democratic political system, cannot apparently cope with the negative moral effects of communication technologies on work, leisure, education and regulation. All this has to do with erroneously considering justice a secluded sphere in itself: “Ethics is one thing, information technologies are another”, so it goes. The times in which we live, invite us and compel us to search for an ethical and democratic extension of the information society, beyond this dillemmic view. To the utilitarian ‘ever more’ one opts for a shared democratic responsibility.

Hendrik OPDEBEECK(1955) took his doctoral degree of Economics at the State University of Ghent in Belgium and his Bachelor’s Degree of Thomistic Philosophy at the Catholic University of Louvain. Since his arrival at the Antwerp University in 1980 he has lectured the courses ‘Philosophy of Technology’, ‘Economics and Ethics’, ‘Macro-Economics’ and ‘HRM and Ethics’. He is a staff member of the Centre for Ethics (UFSIA). He published “Schumacher is beautiful” (1986, Kok Agora) and ” Paul Ricoeur’s ethical theory”(1999, Peeters Pharos). At Ethicomp 1998 in the Erasmus University Rotterdam his lecture was on “Technnology, blessing or curse for employment and labour”.