Showing posts with label ethics. Show all posts
Showing posts with label ethics. Show all posts

Wednesday, March 12, 2014

Een goed Big Data plan heeft geen toestemming nodig

Big data
Deze week stond het nieuws bol van de 'Big Data'-plannen van ING om data-analyses te gaan uitvoeren op de betalingsgegevens van hun klanten om zo de klant te voorzien van mogelijk interessante aanbiedingen van bedrijven. ING haastte zich te benadrukken dat die analyse alleen met de uitdrukkelijke toestemming van de klant zou gebeuren ('opt-in'). Ook het College Bescherming Persoonsgegevens (CBP) benadrukte in zijn eerste reactie dat de plannen van ING uitsluitend toelaatbaar waren als de klant toestemming had gegeven voor de analyses. Je zou dus zeggen dat het met de plannen van ING wel goed zit. Als de klant toestemming geeft, mag het. Einde discussie! Iedereen tevreden.

Of toch niet.....? Uit de vele negatieve reacties, zowel in de pers als op social media, bleek dat veel mensen niet gediend waren van de plannen van de ING. Je zou kunnen zeggen: "Waar zeuren die mensen over? Als ze niet mee willen doen, dan geven ze toch gewoon geen toestemming?" In die visie is toestemming een panacee; een toverwoord dat in een klap alles goed maakt. Die visie is fundamenteel onjuist.

Artikel 8 van de Wet Bescherming Persoonsgegevens (WBP) bevat 'rechtvaardigingsgronden'. Een rechtvaardigingsgrond vormt niet alleen de juridische basis onder je verwerking, maar bevat ook de maatschappelijk-ethische argumenten voor je verwerking. Artikel 8 WBP bevat zes van die rechtvaardigingsgronden: toestemming, uitvoering van een contractuele verplichting, uitvoering van een wettelijke plicht, bescherming van de vitale belangen van de betrokkene, de uitvoering van een publieke taak en het gerechtvaardigd belang van het bedrijf of van een derde. Hoewel toestemming als eerste in het rijtje staat, weten doorgewinterde privacy-professionals dat toestemming eigenlijk alleen bedoeld is voor zaken die je op geen van de vijf andere gronden kan rechtvaardigen. Een laatste redmiddel dus.

Maar daar komt, zeker bij Big Data, ook een ander principe van bescherming van persoonsgegevens om de hoek kijken: de doelbinding. Dat beginsel zegt dat je de persoonsgegevens alleen voor andere dingen mag gebruiken als die andere dingen verenigbaar zijn met het doel waarvoor die gegevens zijn verzameld. Daarbij spelen de redelijke verwachtingen van de klant een belangrijke rol. Doe je dingen die de klant redelijkerwijs niet van jou zou kunnen verwachten, dan doorkruisen jouw plannen waarschijnlijk het doelbindingsbeginsel. Dat soort plannen kan je alleen rechtvaardigen met de toestemming van de klant.

Toestemming is een juridische oplossing. Het creëert een papieren schijnwerkelijkheid dat het wel goed zit met de verwerking van de persoonsgegevens. Toestemming is dan vooral een afweer tegen claims dat het niet goed zit met de verwerking. Maar juist als er geen andere (lees: betere) rechtvaardigingsgrond is voor je Big Data plan, ontbeert zo'n plan intrinsieke voordelen, zowel voor de consument als voor het bedrijf. En in de perceptie van de klant is het belang van het bedrijf dan al snel groter dan het belang voor de consument. De klant ziet zich niet meer als klant, maar als melkkoe en verliest het vertrouwen in het bedrijf. Ethici spreken in zo'n geval over het ontbreken van een equal distribution of benefits and burdens. Een bedrijf moet zich bij de verwerking van persoonsgegevens dus altijd afvragen wat er voor de klant in zit. Zeker als het kennelijke doel is om het nut te vergroten. En dat is heel vaak het geval als je het over de verwerking van klantgegevens voor Big Data doeleinden hebt.

Regels voor bescherming van persoonsgegevens zijn in essentie niets anders dan een mechanisme om belangen tegen elkaar af te wegen. Enerzijds zijn daar de (fundamentele) belangen van de klant: privacy, reputatie, veiligheid, non-discriminatie, rechtvaardige behandeling, autonomie, identiteit en menselijke waardigheid. Deze belangen zijn meestal gediend bij het niet of zo beperkt mogelijk verwerken van persoonsgegevens. En als het dan toch gebeurt, met alle noodzakelijke waarborgen daaromheen. Aan de andere kant staan de veiligheid van derden (de staat, het bedrijf, andere mensen, etc), de handhaving van regels en maatschappelijke normen, het kunnen stellen van vertrouwen in mensen en het maximeren van nut. Tot dat laatste behoort ook het nut voor de klant zelf (denk aan personalisatie van diensten en het doen van aanbiedingen op basis van Big Data analyses). En dat is nu precies waar bedrijven goed in zouden moeten zijn: hun klanten zo'n goed aanbod doen, dat vrijwel alle klanten vinden dat de waarde/nut ervan opweegt tegen het stukje privacy dat ze daarmee inleveren.

Zo zouden bedrijven ook naar hun Big Data plannen moeten kijken: "Is mijn Big Data plan met klantgegevens zo goed, dat klanten er geen nee tegen willen zeggen?" Dit vereist echter een grote mate van transparantie over wat je als bedrijf eigenlijk wil gaan doen met de klantgegevens. Het bedrijf moet daarbij alles op tafel leggen, open en eerlijk. En dan niet alleen aangeven hoe de (privacy)belangen van de klant juridisch worden beschermd, maar ook welke feitelijke beschermingsmaatregelen zijn genomen (bijv. anonimisering) en wat de voor- en nadelen van de Big Data-verwerking zijn voor de klant. En dat mogen geen loze praatjes zijn (window dressing), maar echte maatregelen en echte voordelen.

Als je dus goed hebt nagedacht over je Big Data plannen, de nodige maatregelen hebt genomen om de belangen van de klant te beschermen en open en eerlijk communiceert over de voor- en nadelen voor de klant, dan heb je in principe voldaan aan de eisen van het gerechtvaardigd belang zoals vereist door artikel 8 sub f WBP. En daarmee is je verwerking behoorlijk en zorgvuldig en in overeenstemming met de wet, de hoofdregel van de WBP. Voldoe je niet aan die eisen en heb je dus toestemming van de klant nodig, zou het dan niet beter zijn om dan maar helemaal van je Big Data plan af te zien?

Een 'gerechtvaardigd belang'-aanbod aan de klant moet immers veel beter zijn dan een 'opt-in'-aanbod, omdat de default-positie ín dat geval is dat zijn gegevens worden verwerkt tenzij hij daar bezwaar tegen maakt ('opt-out'). Dat vereist, zoals gezegd, een rechtvaardiging die intrinsiek is gelegen in het plan zelf en voor de klant als zodanig herkenbaar is. Door toestemming te vragen zeg je dus eigenlijk tegen de klant: "Mijn plan voor de verwerking van jouw persoonsgegevens is niet in jouw belang". Dat is een boodschap die geen enkel bedrijf wil communiceren naar zijn klanten.

Monday, May 5, 2008

Back to Basics: Privacy Ethics (part 1)

When I am writing this, it is May 5th, Liberation Day in Holland. On this day Holland reflects on its freedom by organizing "freedom festivals" with music, dance, and theatre performances. Each festival has a Freedom Fire, which has been lit in Wageningen, the place where the Nazi occupation in Holland was officially ended. So-called "Embassadors of Freedom" tour the festivals to talk about freedom, human rights, and the effects of war and violence. So, this looks like a perfect day to reflect on the ethics of privacy and the moral foundations of our privacy laws and freedoms in Europe..... Back to Basics - part 1.

Yesterday, May 4th, Remembrance Day, Peter Hustinx -the European Data Protection Supervisor- was interviewed in a Dutch political talkshow Buitenhof about privacy and the foundations of freedom in Europe. He did a good job. He talked about the "haystacks" that Europe is building and the little chance that somebody may ever find a needle in them. And he warned against the speed with which those haystacks were established and the lack of adequate protections for the rights of European citizens. Moreover, he warned for the dangerously blind trust in information technology: that it will always pick out the bad guys and that nothing ever will go wrong with the data and the profiles stored in those databases. When asked who is making sure that the proper protections are put in place, Hustinx referred to the European Parliament that will get co-legislative powers on crime-fighting issues on January 1, 2009, when the new European Treaty will come into effect.

However, a word of caution is justified here. The "problem" with the belief that everything will be better once the European Parliament has something to say about privacy rights in crimefighting is that the Parliament is driven by politics. This means that privacy protection will be a mix of short-term political opportunities and the political and moral views of the MEP's on how society should be shaped.

On that note, I would like to draw your attention to the excellent work of Jeroen van den Hoven, professor in ICT ethics at Delft University. He has written extensively about the moral reasons for privacy and data protection. I warmly recommend to read his contribution Information Technology, Privacy and the Protection of Personal Data in Jeroen van den Hoven/John Weckert (e.d): Information Technology and Moral Philosophy (Cambridge University Press 2008). In this mini-series on Privacy Ethics I will summarize and comment on his work:

  • Thesis #1: In modern society, there are basically two main views on privacy and data protection: Liberalism and Communitarianism.

On the one end of the spectrum, there is the Liberal view of individual rights and freedoms. In this view, the exercise of people's freedoms is limited by the freedoms of others (see also John Stuart Mill's "Harm Principle"). Privacy and personal freedom is thus very large, and state interference with personal life is limited.

On the other end of the spectrum, there is the Communitarian view of the community's norms and values that can be forced upon the group members, and the need to deal with 'free riders' in our society. In this view, information about people should be made available to the state in order to identify the 'free riders', people that enjoy the benefits of society without participating in the activities that produce those benefits, such as criminals, tax evaders, etc.

The problem for privacy protection is evident. The two views are hardly reconcilable with each other, although Van den Hoven makes a decent effort in his article. Furthermore, in this day and age, Liberal views on personal freedoms are not very popular around officials in government circles. Many take the view that modern society has become too complex to allow Liberal freedoms to prosper unconditionally. Especially where the boundaries between the public and the private sphere vanish, it becomes more difficult to justify the unconditional exercise of personal freedoms. Also, the increased focus on combatting crime and terrorism puts pressure on the Liberal view on privacy and personal freedoms. Nevertheless, Liberals such as MEP Sophie In 't Veld continue to question policies, powers, programs and systems which are put in place by the government that impact people's privacy and keep asking for protections to be put in place to prevent misuse of data and infliction of information-based harm to individuals.

On the other hand, the Communitarian views on privacy and freedom are not always acceptable either, especially not when people are confronted with norms and values of society (or of the group that they belong to) that they don't share personally. The contemporary communitarian thinker Amatai Etzioni has even defended the burqa for muslim women by suggesting that privacy could be seen as an obligation to the group or society to keep certain parts of personal life private if society or the group beliefs it should be kept private. Personal beliefs, norms and values are thus overridden by the norms, values, and needs of society or the group, the 'common good' (Etzioni, 2004).

Communitarian proposals, ideas and actions are relatively easy to spot. They are typically justified by pointing to the obvious benefits for society. Most of the 'haystacks' that Hustinx referred to in the interview have communitarian characteristics. The fact that these proposals do not from the start take into consideration the protections for the privacy and fundamental rights of citizens ("privacy by design") is an even stronger indication of their communatarian origin. Examples of such proposals include: the pan-European fingerprint database proposed by Euro-Commissioner Frattini, the pan-European system of DNA databases proposed by the German Minister for Interior Wolfgang Schäuble; the Electronic Child File with data about the development of all Dutch children and their families in order to screen for child abuse and government-funded assistance to parents for bringing up their children, proposed by André Rouvoet, the Dutch Minister for Youth and Family Affairs; or the affair in Italy just last week, when the Italian Deputy-Minister of Finance Vincenzo Visco ordered the tax data of all Italians to be published on the Internet in a bid to improve tax transparency and combat tax evasion.

Which opinion, the Liberal or the Communitarian one, is dominant in the European Parliament at the moment the voting takes place, significantly defines the nature of the protections that Hustinx and others are hoping for. For now, things seem to look fine for the privacy camp, as the Parliament is very critical about the proposals that are put forward by the Council. Question is however.... is the Parliament critical because of real concern for the privacy of European citizens? Or is the Parliament critical only because it does not like the fact that new proposals are speedily adopted by the Council, before the deadline of January 1, 2009 ......? We will see after January 1st !