The answer to poor government is always more government, at least amongst those who are part of the Leviathan. New Zealand's National Government says it is driven by values of 'personal responsibility' and 'limited government' and Prime Minister Bill English has talked a lot about reducing state dependency and targeting services to those in highest need. He has been explicit about how he plans to do this, most recently in his statement to Parliament in February in which he said, 'the Government will this year further improve the way in which data is used to underpin decision making through initiatives like the Integrated Data Infrastructure.'
The Integrated Data Infrastructure (IDI) is a big database held by Statistics New Zealand that receives feeds from many government and some non-government organisations, including the Ministry of Social Development, Inland Revenue, Ministry of Education, Ministry of Health, Department of Internal Affairs, Ministry of Justice and New Zealand Police. There is a belief that the data in the IDI is anonymous but that is not true. The database uses a common identifier to link the records from the different agencies and, although sufficient personal information to readily identify the person is not usually provided to third parties, the IDI records are linked to real people.
I have had a great deal of experience in the use and protection of information both in the private and public sectors and I believe many people in government have little idea of the risks involved in the aggregation of data. Even if we accept that government agencies are good stewards of people's data (and, as I show below, the evidence is that they are not), the IDI opens up this data to almost anyone who wants to use it. There is an application process but few checks on those who apply. I do not believe those responsible understand the power of technology available to mine and de-anonymise the data and have little appreciation of how it might be used.
An overseas example of the risks is the United Kingdom's experience with care.data, a National Health Service initiative to aggregate health and social care data and make it available for research purposes. Soon after the initiative was launched in 2013, it was rumoured that private sector organisations such as insurance companies were de-anonymising the data to reveal whether customers were withholding information on pre-existing conditions and risk factors such as mental illness. A report into the risks concluded that 'the current care.data program is highly problematic in its flawed protection of patient anonymity, an unsuitable opt-out system, unclear criteria for accessing the collected health data, and the risk it poses to the trust between patients and general practitioners.'
There are many other examples of the lack of adequate protection for individual data in government, including here in New Zealand. The 2012 revelation that Ministry of Social Development's self-service kiosks could be used by anyone to access confidential details of at-risk children is just one example. I have personally seen other examples of significant security flaws in agencies' information systems that have not been revealed publicly. But the risk is not confined to the information falling into the wrong hands - there is also considerable scope to link the wrong data to the wrong person. Statistics NZ admits that 'some records can be linked incorrectly or the link could be missed'. I am sure I don't need to spell out the implications of a law enforcement agency using incorrectly linked data.
I think governments' increasing aggregation of personal information and policies of allowing almost unrestricted access to it, are dangerous and unnecessary. I accept that there is the potential to deliver services to people more effectively by better understanding their needs - after all, this is exactly what Amazon and every other online merchant does - but the risks with governments misusing the information are far greater. The worst Amazon can do is to try to sell you something you don't want, but if the government draws the wrong conclusion from the data, it could destroy your life.
I think it would be better to rethink the role of central government in providing many of the services for which it believes it needs aggregated data. People in need can be better served by local service providers that are closer to the people requiring the services, using information collected from the individuals concerned and those in the community who understand their needs better than any central government agency. The more government tries to manage and target the services it delivers through centralised aggregation of information, the more intrusive into all our lives it needs to become and the greater the risk of wholesale misuse of the data. Central government is always a blunt instrument when it comes to dealing with the problems in individuals' lives and trying to build a sharper sledgehammer is not the answer when what is needed is a scalpel.
Showing posts with label big data. Show all posts
Showing posts with label big data. Show all posts
Tuesday, April 18, 2017
Saturday, May 3, 2014
Big Data, Big Brother and Donald Sterling
This week I read an article about a Princeton sociology professor, Janet Vertesi, who tried to hide the fact that she was pregnant from those who use 'big data', which sounds really scary but is really just a silly neologism for an old concept - trawling databases to find correlations that are useful to marketing people, researchers, intelligence agencies and the like. This woman seemed to be most concerned about marketers targeting her with product offers, but that is not something that particularly worries me. The worst that can result from receiving emails or telephone calls from people trying to sell you things is that you buy something.
The real concern is not big data but Big Brother, such as when Vertesi's husband tried to buy $500 worth of Amazon gift vouchers on her behalf and was told the transaction would be reported to the authorities. I am aware that in New Zealand any financial transaction of more than $10,000 is required to be reported to government under the AML-CFT (Anti-Money Laundering - Counter-Financing of Terrorism) laws and I understand this is the same in most Western countries, but obviously in America the threshold is now so low it covers transactions that are the equivalent of a modestly-priced suit of clothing or a good restaurant dinner.
Why would the government be interested in such trivial transactions? In this case it was clearly the anonymity of the transaction that led to the government's interest. The purpose of AML-CFT laws, as the name suggests, is terrorism and money laundering, but as we know from the recent revelations of the likes of Edward Snowden the US Government has used the powers it has garnered under anti-terrorism laws for all manner of purposes. Initially the expanded purview of such laws was serious crime such as drug trafficking, but ultimately governments cannot resist using such powers for any purpose they deem fit. In the case of Kim Dotcom, we saw the full power of New Zealand's state security apparatus including our GCSB spy agency used in a case of alleged copyright infringement.
Another interesting case this week was that of Donald Sterling, the owner of the Los Angeles Clippers basketball team. Sterling came to our attention because his mistress released private communications in which Sterling objected to her bringing black men to Clippers' games. Clearly Sterling is a racist and, by all accounts, a sterling asshole, but as Mark Steyn points out in his blog, as bad as the comments Sterling made were, what the National Basketball Association has done to him is worse. Sterling made the comments in private and the NBA (which has fined him $2.5m and banned him from attending his own team's games for life) should have no interest in the matter. Neither should the media, especially the New Zealand media (many of which ran the story as their lead).
In the novel 1984, Winston Smith discovered that there is no freedom without privacy. If you cannot express your thoughts even to those whom you most trust without fear that you will be subject to a public witchhunt, or make a small, innocent purchase without inviting the surveillance of the authorities, then you don't have the freedom to think at all. And everything follows from that.
The real concern is not big data but Big Brother, such as when Vertesi's husband tried to buy $500 worth of Amazon gift vouchers on her behalf and was told the transaction would be reported to the authorities. I am aware that in New Zealand any financial transaction of more than $10,000 is required to be reported to government under the AML-CFT (Anti-Money Laundering - Counter-Financing of Terrorism) laws and I understand this is the same in most Western countries, but obviously in America the threshold is now so low it covers transactions that are the equivalent of a modestly-priced suit of clothing or a good restaurant dinner.
Why would the government be interested in such trivial transactions? In this case it was clearly the anonymity of the transaction that led to the government's interest. The purpose of AML-CFT laws, as the name suggests, is terrorism and money laundering, but as we know from the recent revelations of the likes of Edward Snowden the US Government has used the powers it has garnered under anti-terrorism laws for all manner of purposes. Initially the expanded purview of such laws was serious crime such as drug trafficking, but ultimately governments cannot resist using such powers for any purpose they deem fit. In the case of Kim Dotcom, we saw the full power of New Zealand's state security apparatus including our GCSB spy agency used in a case of alleged copyright infringement.
Another interesting case this week was that of Donald Sterling, the owner of the Los Angeles Clippers basketball team. Sterling came to our attention because his mistress released private communications in which Sterling objected to her bringing black men to Clippers' games. Clearly Sterling is a racist and, by all accounts, a sterling asshole, but as Mark Steyn points out in his blog, as bad as the comments Sterling made were, what the National Basketball Association has done to him is worse. Sterling made the comments in private and the NBA (which has fined him $2.5m and banned him from attending his own team's games for life) should have no interest in the matter. Neither should the media, especially the New Zealand media (many of which ran the story as their lead).
In the novel 1984, Winston Smith discovered that there is no freedom without privacy. If you cannot express your thoughts even to those whom you most trust without fear that you will be subject to a public witchhunt, or make a small, innocent purchase without inviting the surveillance of the authorities, then you don't have the freedom to think at all. And everything follows from that.
Subscribe to:
Posts (Atom)