Collective data rights can prevent big technologies from obliterating privacy

[ad_1]

personal You don’t have to fight for your own data privacy, and you are responsible for all the consequences of your digital operations. To give an analogy: People have the right to obtain safe drinking water, but they are not urged to use a pipette to check the water quality every time they drink water to exercise this right. Instead, regulators act on behalf of everyone to ensure that all our water is safe. For digital privacy, the same thing must be done: this is not an individual that ordinary users should or should be considered capable of protecting.

Two parallel approaches should be taken to protect the public.

One is to make better use of class actions or class actions, also known as class compensation actions.Historically, these restrictions have been in Europe, but in November 2020, the European Parliament Passed a measure All 27 EU member states are required to take measures to allow collective remedial actions to be taken throughout the region. Compared with the United States, the European Union has stronger laws to protect consumer data and promote competition. Therefore, European class actions or class actions can be a powerful tool for lawyers and activists to force large technology companies to change their behavior, even in this case. In this case, personal injury will be very low.

In the United States, class actions are usually used to seek compensation for economic damages, but they can also be used to force changes in policies and practices. They can work with campaigns to change public opinion, especially in consumer cases (for example, by forcing Big Tobacco to recognize the link between smoking and cancer, or paving the way for car seat belt laws). When thousands (or even millions) of similar personal injuries add up to help prove cause and effect, they are powerful tools. Part of the problem is getting the correct information first to file a lawsuit.Government efforts, such as Google’s lawsuit against Facebook in December Federal Trade Commission (FTC) and 46 state groupsIs very important. As technology journalist Gilad Edelman said: “According to the lawsuit, the erosion of user privacy over time is a form of consumer harm-a social network that less protects user data. It’s an inferior product-reminding Facebook to shift from a pure monopoly to an illegal one.” In the United States, such as the New York Times Recently reported, Private lawsuits, including class actions, usually “rely on evidence found in government investigations.” However, in the EU it is another matter: private litigation can open up the possibility of regulatory action, which is limited by the gap between EU-wide laws and national regulatory agencies.

This brings us to the second method: the little-known French law of 2016 called the Digital Republic Act.This Digital Republic Act It is one of the few modern laws that focus on automated decision-making. The law currently only applies to administrative decisions made by public sector algorithm systems. But this provides a sketch for possible future laws. It said that the source code behind such systems must be made public. Anyone can request the code.

Importantly, the law enables advocacy organizations to request information about the functions of algorithms and the source code behind them, even if they do not represent specific individuals or claimants who are allegedly harmed. In order to file a lawsuit, it is necessary to find a “plaintiff” who can prove the damage, which makes it very difficult to solve the systemic problems that cause collective data damage. Laure Lucchesi, the head of Etalab, the French government office responsible for overseeing the bill, said that the law’s focus on algorithmic accountability has transcended the times. Other laws, such as the European General Data Protection Regulation (GDPR), focus too much on personal consent and privacy. But data and algorithms need to be adjusted.

In order to file a lawsuit, it is necessary to find a “plaintiff” who can prove the damage, which makes it very difficult to solve the systemic problems that cause collective data damage.

apple A promise in an advertisement: “Currently, there are more private information on your phone than at home. Your location, information, and heart rate after running. These are personal things. They should belong to you.” Apple is strengthening this individualism Myth: By not mentioning your phone, not just storing your personal data, the company obscures the fact that the truly valuable data comes from your interactions with service providers and others. The digital equivalent concept of your phone and file cabinet is a convenient fantasy. Companies don’t actually care about your personal data; this is why they can pretend to lock it in a box. The value lies in the inferences drawn from your interactions. These inferences are also stored on your phone, but the data does not belong to you.

Google’s acquisition of Fitbit is another example. Google promises that it “will not use Fitbit data for advertising,” but the profitable predictions Google needs do not depend on individual data. As a group of European economists saidIn the latest paper by the Center for Economic Policy Research, a London think tank, “For some Fitbit users who have not opted out of Fitbit, Google is sufficient to correlate overall health outcomes with non-health outcomes. Some use its data to predict all Non-Fitbit users (billions of users) health results (and thus the possibility of advertising targeting) method.” Google-Fitbit transaction is essentially a group data transaction. It positions Google as a major market for health data, while enabling it to triangulate different data sets and profit from inferences used in the health and insurance markets.

What decision makers must do

The draft bill attempts to fill this gap in the United States.In 2019, Senators Cory Booker and Ron Wyden proposed Algorithmic Accountability Method, And later stagnated in Congress. The bill will require companies to conduct algorithmic impact assessments under certain circumstances to check for bias or discrimination. But in the United States, this critical issue is likely to be resolved first in laws that apply to specific sectors (such as health care), because the different effects of the epidemic on the U.S. population group have magnified the danger of algorithmic bias.

In late January, Public Health Emergency Privacy Act Senators Mark Warner and Richard Blumenthal were reintroduced into the Senate and House of Representatives. The bill will ensure that data collected for public health purposes will not be used for any other purpose. It will prohibit the use of health data for discriminatory, irrelevant or intrusive purposes, including commercial advertising, e-commerce or efforts to control access to employment, finance, insurance, housing or education. This will be a good start. Furthermore, the law applicable to all algorithmic decisions should take France as an example, and should focus on strict accountability, strict supervision of data-driven decision-making, and the ability to audit and inspect algorithmic decisions and their impact on society.

Ensuring hard accountability requires three elements: (1) Clearly and transparently explain when and where automatic decision-making takes place and how they affect people and groups; (2) The public has the right to provide meaningful opinions and require those in power to prove it. The rationality of decision-making, and (3) the ability to implement sanctions. Crucially, as the European Union recently suggested, policymakers will need to decide what constitutes a “high-risk” algorithm that should meet higher scrutiny standards.


Transparency

The focus should be on public review of automated decision-making and the types of transparency that lead to accountability. This includes revealing the existence of the algorithm, the purpose of the algorithm and the training data behind it, as well as their impact-whether they lead to completely different results, and if they lead to different results.

public participation

The public has the basic right to require those in power to defend their decisions. This “right to ask for answers” should not be limited to consultative participation, in which people are asked to provide opinions while officials move on. It should include authorized participation, and public opinion must be sought before high-risk algorithms are introduced by both the public and private sectors.

Sanctions

Finally, sanctions are the key to the success of these reforms and the realization of accountability. It should be mandatory to establish audit requirements for data objectives, verification and management, so that auditors have this basic knowledge, and authorize supervisory agencies to impose sanctions, not only to remedy damage afterwards but also to prevent damage.


The problem of collective data-driven harm affects everyone. The first step is the Public Health Emergency Privacy Act. Then, Congress should draw lessons from the implementation of the bill and formulate laws specifically targeting collective data rights. Only through such actions can the United States avoid a situation in which the inferences drawn from data companies gather that plague people’s ability to obtain housing, work, credit, and other opportunities in the coming years.

[ad_2]

Source link