24 November 2020

Privacy

'Privacy in Society: Jewish Law Insights for the Age of Big Data' by Kenneth A. Bamberger and Ariel Evan Mayse comments 

This Article makes the counterintuitive argument that Jewish law’s millennia-old approach to regulating visual and aural surveillance, the protection of communications, and information collection, sharing, and use, offers important frameworks for protecting privacy in an age of big data and pervasive surveillance. Judaism views privacy as a societal obligation, and employs categorical behavioral and architectural mandates that bind all of society’s members. It limits waiver of these rules, and rejects both technological capacity and the related notion of “expectations” as determinants of privacy’s content. It assumes the absence of anonymity, and does not depend on the confidentiality or secrecy of information or behavior witnessed or overheard; whether or not knowledge is later used or shared; or whether the privacy subject can show concrete personal harm. And when certain types of sensitive information is publicly known, or can’t help but be visible, Jewish law still provides rules against its use. 

The modern approach to privacy has failed. Notions of individual “rights to be left alone” and “informational self-determination,” offer little defense against rampant data collection and aggregation. The substantive promise of a “fundamental human right” of privacy has largely been reduced to illusory procedural safeguards of “notice” and “consent”—manipulable protections by which individuals “agree” to privacy terms with little understanding of the terms of the bargain, or power to negotiate or opt out. 

Jewish law offers a language that can enrich ongoing policy debates. It suggests a move from individual control over information as the mechanism for shaping privacy’s meaning and its enforcement, to a regime of substantive obligations on all societal members—personal and organizational—to protect privacy. It recognizes the interconnected nature of human interests, and comprehends the totality of the harm pervasive surveillance wreaks on both individuals and social relations. It offers a conceptual basis for extending traditional privacy protections to online spaces and new data uses. And it provides a language of dignity that recognizes unequal bargaining power; rejects the aggregation and use of information to create narratives and produce judgments that confine personal growth and free choice; and demands equal protection for all humans.

FRAND and the Genius in the Garret

'The Myth of the Sole Inventor' (Stanford Public Law Working Paper No. 1856610) by Mark A. Lemley comments 

The theory of patent law is based on the idea that a lone genius can solve problems that stump the experts, and that the lone genius will do so only if properly incented. We deny patents on inventions that are "obvious" to ordinarily innovative scientists in the field. Our goal is to encourage extraordinary inventions – those that we wouldn’t expect to get without the incentive of a patent. 

The canonical story of the lone genius inventor is largely a myth. Edison didn’t invent the light bulb; he found a bamboo fiber that worked better as a filament in the light bulb developed by Sawyer and Man, who in turn built on lighting work done by others. Bell filed for his telephone patent on the very same day as an independent inventor, Elisha Gray; the case ultimately went to the U.S. Supreme Court, which filled an entire volume of U.S. Reports resolving the question of whether Bell could have a patent despite the fact that he hadn’t actually gotten the invention to work at the time he filed. The Wright Brothers were the first to fly at Kitty Hawk, but their plane didn’t work very well, and was quickly surpassed by aircraft built by Glenn Curtis and others – planes that the Wrights delayed by over a decade with patent lawsuits. 

The point can be made more general: surveys of hundreds of significant new technologies show that almost all of them are invented simultaneously or nearly simultaneously by two or more teams working independently of each other. Invention appears in significant part to be a social, not an individual, phenomenon. Inventors build on the work of those who came before, and new ideas are often "in the air," or result from changes in market demand or the availability of new or cheaper starting materials. And in the few circumstances where that is not true – where inventions truly are "singletons" – it is often because of an accident or error in the experiment rather than a conscious effort to invent. 

The result is a real problem for classic theories of patent law. If we are supposed to be encouraging only inventions that others in the field couldn’t have made, we should be paying a lot more attention than we currently do to simultaneous invention. We should issuing very few patents – surely not the 200,000 per year we do today. And we should be denying patents on the vast majority of the most important inventions, since most seem to involve near-simultaneous invention. Put simply, our dominant theory of patent law doesn’t seem to explain the way we actually implement that law. 

Maybe the problem is not with our current patent law, but with our current patent theory. But the dominant alternative theories of patent law don’t do much better. Prospect theory – under which we give patents early to one company so it can control research and development – makes little sense in a world in which ideas are in the air, likely to be happened upon by numerous inventors at about the same time. And commercialization theory, which hypothesizes that we grant patents in order to encourage not invention but product development, seems to founder on a related historical fact: most first inventors turn out to be lousy commercializers who end up delaying implementation of the invention by exercising their rights. 

If patent law in its current form can be saved, we need an alternative justification for granting patents even in circumstances of near-simultaneous invention. I consider two other possibilities. First, patent rights encourage patent races, and that might actually be a good thing. Second, patents might facilitate markets for technology. Both have some logic to them, but neither fully justifies patent law in its current form. As a result, I offer some suggestions for reforming patent law to take account of the prevalence of simultaneous invention.

'Unfair Pricing and Standard Essential Patents' (EUI Working Paper RSCAS 2020/60) by Marco Botta comments 

Technical standards that are agreed within a Standard Development Organization (SDO) often cover several ‘essential’ patents for the implementation of a standard (ie, Standard Essential Patents, SEPs). In order to allow for the standard implementation, the SEP holder commits to license its patents to any potential licensee on the basis of Fair and Reasonable and Non-Discriminatory (FRAND) conditions. In view of the recent ruling of the UK Supreme Court in Unwired Planet and the judgement of the German Bundesgerichtshof in Sisvel v Haier, the paper assumes that the FRAND commitment implies a ‘range’ rather than a ‘single’ royalty rate. On the other hand, a royalty rate ‘beyond the outer boundary of the range’ should be considered ‘unfair’, and thus incompatible with the FRAND commitment. Besides representing a breach of the FRAND commitment, an ‘unfair’ royalty rate might also be considered an abuse of a dominant position by the SEP holder, in breach of Art 102(a) TFEU. This paper analyses whether, and under what circumstances, Art 102(a) TFEU can be relied upon by a competition authority in Europe to sanction a case where an ‘unfair’ royalty rate has been set by the SEP holder. To this regard, the paper provides a detailed analysis of the EU Court of Justice’s jurisprudence on Art 102(a) TFEU. In particular, the latter jurisprudence is relied as a ‘yardstick’ to assess ‘when’ competition policy should sanction a request of unfair royalty rate by the SEP holder, ‘how’ a competition agency should assess the case and, eventually, ‘what’ remedies the competition authority might adopt.

BioValue and DTC Genomics Marketing

'A tidal wave of inevitable data? Assetization in the consumer genomics testing industry' by Susi Geiger and Nicole Gross in (2021) Business & Society comments 

We bring together recent discussions on data capitalism and bio-capitalization by studying value flows in consumer genomics firms – an industry at the intersection between healthcare and technology realms. Consumer genomics companies market genomic testing services to consumers as a source of fun, altruism, belonging and knowledge. But by maintaining a multisided or platform business model, these firms also engage in digital capitalism, creating financial profit from data brokerage. This is a precarious balance to strike: If these companies’ business models consist of assetizing the pool of genomic data that they assemble, then part of their work has to revolve around obscuring to consumers any uncertainties that would potentially impinge on these processes of assembly. We reflect on the nature of these practices and the market relationships that enable them, and we relate this reflection to debates around alternative market arrangements that would potentially mitigate the extractive tendencies of these and other digital health firms.

The authors argue 

In July 2018, a number of consumer genomics companies - including the industry’s leaders Ancestry.com and 23andMe –signed up to a new data privacy protocol, which had been developed in conjunction with the data activist organization Future of Privacy Forum (FPF) (Romm & Hartwell, 2018). These best practices include provisions for express and fully consented sharing of genomic data with third party organizations (Future of Privacy Forum, 2018). While focusing attention on the firms’ privacy practices, the guidelines remain surprisingly silent of the fact that the commercial “sharing” or sale of genomic data is an intrinsic part of these firms’ business models. Questions of data privacy in consumer genomics are inseparable from questions of data ownership and the profits arising thereof; yet the former has received vastly more research and public attention than the latter. 

In this article, we broaden recent discussions on data or platform capitalism as practiced by data-driven technology firms such as Google or Facebook (Langley & Leyshon, 2017; West, 2017) by considering healthcare as a realm that is becoming increasingly entangled with data capitalist business models. As Atkinson, Glasner and Lock (2009, p. 5) point out, the bio- economy “generates a different form of value to that found in the wider economy”, namely value that always entangles economic with social and public concerns. But where and to whom does this economic value accumulate if it goes digital? What are the market arrangements and business models that enable economic value to flow in these so-called digital health industries, and are there any alternatives to the current models? 

By locating our inquiry in the consumer genomics industry, we study an industry that has been embroiled in controversies from its earliest days – in Cole and Banerjee’s (2013, p. 555) words, it is “morally contentious”. Social science commentators have raised questions around the mantle of democratization of health insights and clinical research that the consumer genomics industry likes to cover itself with (Prainsack, 2014; Regalado, 2017; Tutton & Prainsack, 2011). The industry has also encountered enduring skepticism from clinicians around the provision of worrying and even misleading information to consumers without the benefit of professional medical support (Rockwell, 2017). Despite these criticisms, judging by the industry’s growth rates (Deloitte 2015), consumer genomics companies seem to have been successful at portraying genomic information as a font of empowerment, belonging and knowledge to consumers (Turrini & Prainsack, 2016). 

While alert to these ethical debates, in this article we focus on the processes through which consumer genomic information is turned into assets, which allows these firms to operate on several markets at the same time – consumer, data licensing, venture capital and intellectual property markets. Following Birch (2017, p. 463), we define assets as “resources that generate recurring earnings”. We contend that for consumer genomics firms’ business models to work, there is a precarious balance to strike: If these companies aim to assetize the pool of genomic information that they assemble, then part of their work has to revolve around assuring an uninterrupted flow of data that can be turned into assets. We claim that this is done through three interlinked processes: of first accumulating consumer data; secondly, maintaining and augmenting it; and thirdly obscuring to consumers any uncertainties that would potentially impinge on first two processes. In tracing the value flows in this industry, we thus examine the practices that these companies engage in with regard to assetizing genomic information. More broadly, we argue that the move to assetization presents a major conceptual shift for firms that operate broadly in the healthcare realm. Conceptually, we combine theories of biocapital and data capitalism to analytically grasp and critique these processes of assetization. 

While our argument is conceptually driven, we draw on several empirical sources to inform our analysis: We examine genomic firms’ business models and market relationships through an analysis of their marketing collateral and websites, and we support this analysis through documents published either by the firms themselves or by technology journalists and analysts. We complement these documentary sources through eight interviews with industry insiders. Our investigation remains on the producer side – we study how consumer genomics firms “act in markets to affect what is valued and how it is valued” (Aspers & Beckert, 2011, p. 23), not how this value is perceived and realized by the consumer. Though we focus predominantly on economic value flows, we fully acknowledge that there are various values at play – ethical, social, and individual. Yet, as Rose and Novas (2005) point out, in markets these are often conflated with or even turned into “marketable assets” themselves. Comparing our findings with extant research, we discuss the “inevitability” of the private accumulation of economic value from consumer genomic data, to which our title refers,1 and we point to debates around alternative market arrangements in consumer genomics and the broader bio-economy. With this reflection we contribute to discussions on valuation and assetization practices at the intersection of individual, healthcare and commercial realms (Dussauge et al., 2015; Poitras & Meredith, 2009). We also add to an emerging literature scrutinizing the intersection of digital technology and healthcare practices in so-called digital health industries (Geiger & Gross, 2017; Fiore-Gartland & Neff, 2016; Saukko, 2018). Most fundamentally, our argument speaks to Birch’s (2017) question of what gets valued and how this is done in the bio-economy. 

Our article proceeds as follows. The next section introduces three strands of literature around “capitalisms” - bio-, data- and platform - bringing insights from the practices researchers have identified in data and platform capitalist firms into debates around biocapitalization. After briefly presenting our analytical approach, we use these conceptual foundations to first analyze the four value flows we have identified as constituent parts of a typical consumer genomic business model. We then explore 15 direct-to-consumer genomic testing firms’ marketing strategies to establish how these firms endeavor to create and maintain the “tidal flow” of data that underlies these value flows. Our Discussion summarizes our analysis before moving to build a research agenda for future research, centering on debates around conceiving alternative market mechanisms in the consumer genomics and related digital health industries.

Data Governance

'Democratic Data: A Relational Theory For Data Governance' bySalome Viljoen comments

 Data governance law — the law regulating how data about people is collected, processed, and used — is the subject of lively theorizing. Concerns over datafication (the transformation of information or knowledge about people into a commodity) and its harmful personal and social effects have produced an abundance of proposals for reform. Different theories advance different legal interests in information, resulting in various individualist claims and remedies. Some seek to reassert individual control for data subjects over the terms of their datafication, while others aim to maximize data subject financial gain. But these proposals share a common conceptual flaw: they miss the central importance of population-level relations among individuals for how data collection produces both social value and social harm. The data collection practices of the most powerful technology companies are primarily aimed at deriving population-level insights from data subjects for population-level applicability, not individual-level insights specific to the data subject in question. Put simply, the point of data production is to put people into population-based relations with one another; this activity drives data collection practices in the digital economy and results in some of the most pressing forms of social informational harm. Individualist data subject rights cannot represent, let alone address, these population-level effects. 

Treating data’s population-level effects as central to the task of data governance opens up new terrain. The proper aim of data governance is not to reassert individual control over the terms of one’s own datafication or to maximize personal gain, but instead to develop the institutional responses necessary to represent the relevant population-level interests at stake in data production. This shifts the task of reform from granting individuals rights to exit or payment, to securing recognition and standing to shape the purposes and conditions of data production for those with interests at stake in such choices. From this reorientation, data governance law may develop legal reforms capable of responding to the harms of datafication without foreclosing socially beneficial forms of data production. 

Part One describes the stakes and the status quo of data governance. It documents the significance of data processing for the digital economy. It then evaluates how the predominant legal regimes that govern data collection and use — contract and privacy law — code data as an individual medium. This conceptualization is referred to throughout the Article as “data as individual medium” (DIM). DIM regimes apprehend data’s capacity to cause individual harm as the legally relevant feature of datafication; from this theory of harm follows the tendency of DIM regimes to subject data to private individual ordering. Part Two presents the core argument of the Article regarding the incentives and implications of data social relations within the data political economy. Data’s capacity to transmit social and relational meaning renders data production especially capable of benefitting and harming others beyond the data subject from whom data is collected. It also results in population-level interests in data production that are not reducible to the individual interests that generally feature in data governance. Thus, data’s relationality presents both a conceptual challenge for data governance reform. Part Three evaluates two prominent legal reform proposals that have emerged in response to concerns over datafication. Propertarian proposals respond to growing wealth inequality in the data economy by formalizing individual propertarian rights over data as a personal asset. Dignitarian reforms respond to how excessive data extraction can erode individual autonomy by granting fundamental rights protections to data as an extension of personal selfhood. While propertarian and dignitarian proposals differ on the theories of injustice underlying datafication and accordingly provide different solutions, both resolve to individualist claims and remedies that do not represent, let alone address, the relational nature of data collection and use. Part Four proposes an alternative approach: data as a democratic medium (DDM). This alternative conceptual approach apprehends data’s capacity to cause social harm as a fundamentally relevant feature of datafication; from this follows a commitment to collective institutional forms of ordering. Conceiving of data as a public resource subject to democratic ordering accounts for the importance of population-based relationality in the digital economy. This recognizes a greater number of relevant interests in data production and recasts the subject of legal concern from interpersonal violation to the condition of population-level data relations under which data is produced and used. DDM therefore responds not only to salient forms of injustice identified by other data governance reforms, but also to significant forms of injustice missed by individualist accounts. In doing so, DDM also provides a theory of data governance from which to defend forms of socially beneficial data production that individualist accounts may foreclose. Part Four concludes by outlining some examples of what regimes that conceive of data as democratic could look like in practice.

21 November 2020

Plagiarism

In Medical Board of Australia v Soh (Review and Regulation) [2019] VCAT 1549 the TRibunal considered claims of forgery and practitioner by a clinician. 

The Tribunal states 

The respondent in this matter, Dr Soh, is a medical practitioner. This matter has come before us as a disciplinary matter in relation to Dr Soh and there has been an Agreed Statement of Facts and Agreed Determination. At the outset of the hearing this morning we indicated that the panel did not need to hear submissions from either party as we have read the whole file, being the Tribunal Book, and we have read the agreed statement of facts and we have also read the determination. On that basis we are of the opinion that we are able to give an oral decision in this matter and we will do so in due course. 

The following facts are set out in the agreed statement of facts: 

Facts 

Dr Bryan Min Han Soh claimed authorship of an article which was published in Annals of Medicine and Surgery on 22 March 2017, titled ‘The use of super-selective mesenteric embolization as a first-line management of acute lower-gastrointestinal bleeding’. 

That article was plagiarised from the original article titled ‘Super-Selective Mesenteric Embolization Provides Effective Control of Lower GI Bleeding’ published in the Journal of Radiology, Research and Practice on 22 January 2017, authored by Toan Pham, Ian Faragher and others and undertaken by the Colorectal Unit, Department of Surgery, Western Health. 

Dr Pham, the primary author of the original article, sent a draft of the article to Dr Soh on 5 August 2014 for him to consider whether he could make a contribution. Dr Soh undertook proof reading, basic editing, and minor additions, but Dr Pham did not consider that Dr Soh had made a sufficient contribution to be listed as a contributing author for publication of the article. 

Dr Soh used the plagiarised article to gain entry to the Surgical Education and Training (SET) in General Surgery program of the Royal Australasian College of Surgeons (RACS). 

On 31 March 2017, Dr Soh submitted an application for SET to RACS supported by a curriculum vitae which contained the plagiarised article. 

On 16 March 2017, Dr Soh was advised by letter that his result in the RACS Surgical Science Generic Examination (Examination) was a ‘FAIL’. 

Dr Soh forged his RACS Surgical Science Generic Examination result letter dated 16 March 2017 by altering the ‘FAIL’ result to a ‘PASS’ result. Dr Soh altered the Examination result letter in order to gain entry to the SET in General Surgery program of the RACS. 

On 31 March 2017, Dr Soh submitted an application for SET to RACS containing the fraudulent Examination letter. Western Health undertook an investigation into the plagiarism by Dr Soh in 2017. 

On or about 28 June 2017, Dr Soh provided copies of emails between himself and the Journal of Surgery Case Reports which were not true copies of the originals and had been altered. The alterations made it appear that Mr Pham had been copied in to the email, and inserted text into the body of the email. 

On 3 November 2017, Western Health issued Dr Soh a formal warning to be placed on his file for 12 months, and did not renew his contract of employment which was to end in January 2018. 

On 30 January 2018, the offer by RACS to Dr Soh to undertake SET was withdrawn on the basis that the information in the application was not true.

The outcome was 

 Dr Soh admits and the Tribunal finds that he engaged in the conduct particularised in the Agreed Facts and the Allegations. 
 
Dr Soh admits and the Tribunal finds that his conduct breached principles of the Good Medical Practice: A Code of Conduct for Doctors in Australia (March 2014). 
 
The Tribunal finds that the conduct of Dr Soh as particularised in the Agreed Facts and Allegations 1 and 2 constitutes ‘professional misconduct’ within the meaning of paragraphs (a) and/or (b) of the definition of professional misconduct in the Health Practitioner Regulation National Law (Victoria) Act 2009. 
 
The respondent is reprimanded pursuant to s. 196(2)(a) of the Health Practitioner Regulation National Law (Victoria) Act 2009 (National Law). 
 
The respondent is fined $10,000 (to be paid on or before 19 November 2019) pursuant to s. 196(2)(c) of the National Law. 
 
The respondent’s registration is subject to conditions requiring him to undertake education on ethics, specifically academic integrity and research ethics in the terms outlined in Annexure “A” pursuant to s. 196(2)(b)(i) of the National Law.

20 November 2020

CensusFail

Realists don't expect government agencies to be perfect. They do however expect agencies to learn from mistakes. That's a legitimate expectation. It's thus disquieting to see the ANAO report Planning For The 2021 Census, which implies the ABS has not taken on board the lessons of what people identified through the #CensusFail hashtag in 2016. 

The ANAO states 

1. The Census of Population and Housing (the Census), undertaken by the Australian Bureau of Statistics (ABS), is Australia’s largest statistical collection. The purpose of the Census is to accurately measure the number and key characteristics of all people in Australia, Norfolk Island, and the Territories of Cocos (Keeling) Islands and Christmas Island on Census night every five years. 

2. The 2016 Census was the first Census to be ‘digital first’, whereby the ABS sought to obtain 65 per cent of responses through an online eCensus form. On Census night on 9 August 2016, there was a failure of multiple information technology (IT) controls, particularly for the online eCensus form, which resulted in the closure of the Census webpage for two days. 

3. The Senate, the Department of Prime Minister and Cabinet, and the ABS initiated reviews into the events on Census night, ABS governance and the broader implications for cyber security across the Australian Public Service. In total, the reviews made 36 recommendations, 29 of which were directed at the ABS and agreed.

4. The failure of multiple IT controls during the 2016 Census reinforced the need for the ABS to implement robust planning arrangements for the 2021 Census including for cyber security, procurement, and review recommendations. An audit of the ABS’ preparedness for the 2021 Census would provide assurance on whether the ABS is on track to delivering its objectives for the Census. 

5. The objective of the audit was to assess whether the ABS is effectively preparing for the 2021 Census. 

6. In assessing this objective, the following three high-level criteria were adopted: Has the ABS established appropriate oversight frameworks for the Census? Is the ABS taking appropriate steps in developing IT systems for the Census? Is the ABS addressing key Census risks and implementing Census recommendations? 

7. The ABS’ planning for the 2021 Census is partly effective. 

8. The ABS has established largely appropriate planning and governance arrangements for the Census. The risk framework is compromised by weaknesses in the assurance arrangements. 

9. The ABS is partly effective in its development of IT systems for the 2021 Census. Generally appropriate frameworks have been established covering the Census IT systems and data handling, and the procurement of IT suppliers. The ABS has not put in place arrangements to ensure that improvements to its architecture framework, change management processes and cyber security measures will be implemented ahead of the 2021 Census. 

10. The ABS has been partly effective in addressing key Census risks, implementing past Census recommendations and ensuring timely delivery of the 2021 Census. Further management attention is required on the implementation and assessment of risk controls. 

11. The planning and governance arrangements for the Census are appropriate, except that the ABS does not have an overarching plan to coordinate activity plans and enable a clear view of progress against planned activities. 

12. The ABS largely complies with the Commonwealth Risk Management Policy and has established a risk management plan for the 2021 Census. While the ABS has engaged an external program assurer to report to its Census Executive Board, their assurance activities are not well aligned with the identified Census risks. The Audit Committee has not been well positioned to provide consistent risk oversight or assurance on the Census. 

13. The ABS has been implementing largely appropriate project management practices from December 2019. It has established monitoring processes and in July 2020 finalised arrangements to assess and approve changes to the Census project. 

14. The ABS has an efficiency measure for the Census. The ANAO was unable to provide assurance on the validity and reliability of the measure, however, it is consistent with a proxy measure developed by the ANAO from published ABS information. A report by the United Nations Economic Commission for Europe ranks Australia’s cost per capita as just under the average of a group of countries with similar Census methods. 

15. The IT framework that the ABS has established for the 2021 Census is largely appropriate. However, the ABS’ implementation of its IT framework is not complete. The ABS has not established a systematic process for managing risks associated with non-compliance. Census systems do not fully align with the ABS enterprise IT framework giving rise to risks in relation to system integration and compliance with legislation and ABS policy. The ABS has not established a process to mitigate the risk of unauthorised changes being implemented across systems supporting the Census. 

16. The ABS is establishing partly appropriate data handling practices for the 2021 Census. The ABS has designed controls and arrangements to manage risks relating to data quality and protection of privacy. The ABS has not fully implemented controls for managing the quality and protection of 2021 Census data and does not have in place appropriate arrangements to monitor control implementation. 

17. The ABS has established partly appropriate cyber security measures for the 2021 Census. The high-level measures and controls in the ABS’ cyber security strategy for the 2021 Census are sound. However, the strategy has not been fully implemented. 

18. The ABS has established IT supplier contracts that support value for money outcomes. The ABS has largely met key legal requirements for its Census IT procurements of $1 million or more. 

19. The ABS has been partly effective in addressing key Census risks. The ABS has identified, reviewed and reported risk in accordance with its Risk and Issues Management Plan and the broader ABS framework, and has mostly embedded risk management in its key business processes. The ABS has not consistently implemented key risk controls and has not fully assessed control effectiveness as required in its Risk and Issues Management Plan. 

20. ANAO analysis indicates that the ABS’ post-review activities align with 27 out of the 29 agreed recommendations. In the absence of effective governance oversight arrangements to monitor and report on the implementation of recommendations, the ABS does not have sufficient assurance that it has appropriately addressed the identified issues. 

21. Since January 2020, the ABS has been largely effective at monitoring the progress of activities for the 2021 Census. ABS Census projections in 2018 and 2019 were generally ‘on track’. Throughout 2020 the Census has been ‘at risk’. ANAO testing of 17 key tasks indicated that four were reported complete at least three months prior to actual completion. The ABS has accurately reported key activities, decisions and issues to the Minister in a timely manner. Public reporting on progress with the Census is accurate but could cover a wider range of topics.

The ANAO recommendations are -

R no.1   The Australian Bureau of Statistics strengthen its planning and governance arrangements for the 2021 Census by: establishing a high-level plan of the Census integrating the objectives, activities, and their dependencies; and ensuring that the required reporting is provided to the Census Executive Board. 

ABS response: Agreed. 

R no.2   To assist the Australian Bureau of Statistics in complying with section 16 EA of the Public Governance, Performance and Accountability Rule 2014, the Australian Bureau of Statistics: include an efficiency measure in its performance framework; and develop procedures to support the validity and reliability of the existing Census efficiency measure. 

Australian Bureau of Statistics response: Agreed. 

R no.3  The Australian Bureau of Statistics strengthen its IT framework for the Census by: assessing the impact of non-compliance with Australian Bureau of Statistics standard architectures, including the impact on meeting legislative and policy requirements; and establishing appropriate controls for mitigating unauthorised and inappropriate system changes, specifically focussing on developers that have access to migrate their own changes to Census-related systems. 

ABS response: Agreed. 

R no.4  The Australian Bureau of Statistics obtain an appropriate level of assurance that the systems supporting the 2021 Census are meeting legal and Australian Bureau of Statistics policy requirements on data quality and privacy. 

ABS response: Agreed. 

R no.5  The Australian Bureau of Statistics: define timeframes and responsibilities for implementing the 2021 Census Security Strategy and the Essential Eight Uplift Program, especially for areas that are required prior to the 2021 Census; and ensure contracted services meet Australian Bureau of Statistics specific design and cyber security requirements, and performance of security controls are regularly assessed. 

ABS response: Agreed. 

R no.6  The Australian Bureau of Statistics implement its risk controls and regularly and consistently monitor the effectiveness of those controls. 

ABS response: Agreed. 

R no.7  The Australian Bureau of Statistics: establish oversight arrangements to monitor the progress of the implementation of agreed recommendations from external reviews; and assure itself that it has fully implemented all agreed recommendations. 

ABS response: Agreed.

19 November 2020

EU Competition Policy

The European Court of Auditors' report The Commission’s EU merger control and antitrust proceedings: a need to scale up market oversight states 

I The Treaty on the Functioning of the European Union protects fair competition of companies in the EU internal market and in the interest of consumers. To this end, the Commission enjoys significant investigative and decision-making powers whereby it can prohibit anti-competitive agreements between companies or act against companies that abuse their position in the internal market (known as "antitrust proceedings"). The Commission also reviews larger concentrations of companies for their impact on competition in the internal market (known as "merger control"). 

II Both the Commission and the national competition authorities (NCAs) in the EU Member States can directly enforce EU competition rules in antitrust cases affecting trade between Member States. The Commission has defined criteria for allocating cases between the Member States and the Commission. 

III This is the first audit we carried out on the Commission’s role as enforcer in the areas of merger and antitrust. Over the last 10 years, EU competition enforcement has experienced significant changes in market dynamics and been at the centre of public interest and debate. In our audit, we looked at whether the Commission, through its Directorate General for Competition, enforced EU competition rules in its merger control and antitrust proceedings well. To this end, we examined the Commission’s detection and investigation capacity, and how it used its enforcement powers in merger control and antitrust proceedings. We also examined how the Commission cooperated with the NCAs, how it reported on the results of its enforcement activities, and how it received feedback. Our report highlights issues which may have an impact on the Commission’s success now and in the future. 

IV We found that overall the Commission made good use of its enforcement powers in merger control and antitrust proceedings and addressed competition concerns with its decisions. However, improvements are necessary in a number of areas. 

V In order not to depend solely on complaints received, the Commission acted on its own initiative to identify problems potentially affecting the internal market. However, it did not invest appropriate resources in monitoring markets. Incentives put in place to encourage self-reporting of cases worked but numbers have fallen since 2015. By prioritising cases, the Commission allocated resources to relevant investigations but this was not based on a clear weighting of criteria ensuring the selection of cases with the highest risk. 

VI Merger control absorbed a substantial part of the available resources. The Commission successfully applied a simplified procedure but still needs to act upon further streamlining measures. We also found that the turnover-based thresholds used for deciding whether a transaction would affect competition in the internal market may not ensure that all significant transactions are subject to the Commission’s review. 

VII The Commission’s antitrust decisions addressed competition concerns but investigations were generally lengthy. As antitrust enforcement only takes place after a competition problem has arisen, the duration of the proceedings might negatively affect the effectiveness of the decisions. The Commission took action to speed up its antitrust proceedings but also had to cope with complex investigations. This was particularly the case for the new digital markets where traditional assumptions of effective competition needed to be adapted and where the effectiveness of the existing legal tools for intervention had to be evaluated. The Commission has also not yet updated its guidelines and notices to improve legal certainty for companies active in these markets and to support the NCAs in their own decision-making. 

VIII Effective enforcement requires deterrent fines. The level of the fines imposed by the Commission for the infringement of competition rules is among the highest in the world. However, the impact of large fines depends on the size of the companies concerned, the probability that infringements are detected, the potential for profits associated with the infringements, and the duration of the Commission’s investigations. So far, the Commission has not evaluated the deterrent effect of its fines. 

IX NCAs take most of the decisions in cases where EU antitrust rules apply. The NCAs and the Commission cooperated well in the European Competition Network, with the exception of market monitoring and enforcement priorities which had not been closely coordinated. A mechanism for efficient allocation of antitrust cases between the Commission and NCAs was not used in an optimal way 

X The Commission defined the objectives to be achieved only in a very general way. Along with a lack of suitable data to monitor results, this made it challenging to assess the performance of the enforcement activities. Although ex post evaluations of the effectiveness of its work would support better decision-making and better allocation of resources, the Commission did not regularly carry them out. The Commission’s reporting on the results of its enforcement action still focuses on activity rather than on impact and there is currently no regular, independent assessment of the performance of competition authorities in the EU. 

XI We make a number of recommendations that aim at strengthening the Commission’s capacity to

  • increase the probability of detection of infringements; 

  • increase the effectiveness of competition enforcement; 

  • use the potential of the European Competition Network better; and 

  • improve performance reporting.