A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Thomson Reuters
Vivienne Artz, Chief Privacy Officer
"Just because you can, doesn't mean you should"


For many, this will be the first time that they have mapped their data in a way so they are not only able to understand what data they are processing, but also where it is being held and how it is being shared. This could include both internal and externally held data sets, as well as identifying the all-important third party relationships where processes have been outsourced or off-shored to third parties, whether that incudes technical support, cloud hosting, processing centres in third countries or outsourcing HR or payroll functions.
For many organisations, the GDPR compliance programme has meant a wake-up call to understanding just how operations and technology platforms have evolved and developed over the years, perhaps without a coherent strategy, or driven primarily by a need to achieve cost savings, efficient data centralisation, or to leverage economies of scale.
Much of this has been achieved without much thought to privacy obligations and risks, which have now become part of the fabric of companies’ decision making around what data to process, where to process the data, who has access to the data, with whom the data is shared, how should the data be safeguarded, how long should data be retained, and how to effectively respect data subject rights.
But the all-important question, is whether an organisation should be processing personal data at all. The first principle of data protection states that personal data should be processed fairly and lawfully and transparently. But what does this mean in practice?
It is the different answers to this question which has given rise to a new and evolving area of privacy, namely, Data Ethics. The European Data Protection Supervisor has recently announced that they will be focussing on Digital Ethics at the next International Conference of Data Protection and Privacy
While establishing a lawful basis for personal data processing is a general principle of privacy laws across the globe, and gives rise to concepts of consent, necessity, complying with legal obligations, public interest, legitimate interests and protecting the vital interests of the data subject, it doesn’t address the “ethics of privacy” which is creating challenges for organisations which continue to operate in a data driven world.
The first principle of data protection states that personal data should be processed fairly and lawfully and transparently
For example, a social media company recently announced that through analysing posts of users, it could determine those individuals who were at risk of committing suicide. While it might be possible to come to this conclusion with significant accuracy, the range of reactions to the capability raises the question of whether this sort of processing should take place. What is the balance between what may be seen as unwelcome intrusion into the personal lives of individuals, versus the opportunity to alert family and friends who could help a loved one in distress?
In a different context, leveraging both information provided by a customer together with publicly available information about where they live and social demographic, can enable firms to identify with a new level of accuracy their likelihood of being a low or high credit risk. However, where this sort of insight can on one hand enable firms to better price products, it could also lead to post code “black spots”, where individuals are offered different priced products just because of where they live.
In Asia, a national social credit scoring scheme launched in 2014 is aimed at determining the “trustworthiness” of the country’s citizens. With a high social credit score, citizens can benefit from a range of benefits such as no-deposit apartment and bicycle rentals, or getting faster access to doctors. The social credit score can be reduced for cheating on video games, not paying court fees, or other “black-listed” behaviours. The aim is to encourage citizens to exhibit good behaviours, but the challenge is whether it is ethical for the state to influence citizen’s behaviours in such an overt way.
Finally, the Snowden revelations and WikiLeaks raised awareness about mass surveillance and the national security debate. On the other side, social media empowered citizens in the Arab Spring to come together to liberate themselves from oppressive regimes, and to demand change.
Each of these examples reflects the reality that digital technology is not neutral, and in a world where individuals are tracked through internet searches, CCTV, swipe card access to work, card payment technologies, mobile phone data location services etc. it is increasingly important that as we further embrace technology, that we consider both the ethical dimension, and create a framework for assessing both what “can” be achieved so as not to stifle innovation, but also whether some data processing “should” take place at all, or be subject to specific controls.
As we embrace artificial intelligence, machinelearning, self-driving cars, block chain and other innovations, we need to think about whether ethical considerations should drive innovation, and consider whether ethics is something to be determined at the individual, corporate, governmental or at a broader level. The new era of privacy is at hand!
Weekly Brief
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info


