14 August 2018

Algorithms

'Algorithm-assisted decision-making in the public sector: framing the issues using administrative law rules governing discretionary power' by Marion Oswald in (2018) Philosophical Transactions of the Royal Society A comments
This article considers some of the risks and challenges raised by the use of algorithm- assisted decision-making and predictive tools by the public sector. Alongside, it reviews a number of long-standing English administrative law rules designed to regulate the discretionary power of the state. The principles of administrative law are concerned with human decisions involved in the exercise of state power and discretion, thus offering a promising avenue for the regulation of the growing number of algorithm-assisted decisions within the public sector. This article attempts to re- frame key rules for the new algorithmic environment and argues that ‘old’ law – interpreted for a new context – can help guide lawyers, scientists and public sector practitioners alike when considering the development and deployment of new algorithmic tools. 
Introduction 
In 1735, in this very journal, one Reverend Barrow published a short piece, hardly a page in length, in which he surveyed births, deaths and overall population in the parish of Stoke-Damerell in Devon.  He notes that ‘the Number of Persons who died, is one more than half the Number of Children born; and that about 1 in 54 died’ in a year when the ‘General Fever’ infected almost all the inhabitants. He further points out that one of the persons buried was ‘a Foreigner brought from on board a Dutch Ship’ and two more were drowned from on board a Man of War ‘but that the Ships Companies are not included in the Number of Inhabitants.’ This data, together with ‘Experience and Observations, both of my self and better Judges’ leads him to ‘reckon the Parish of Stoke-Damerell as healthful an Air as any in England.’ Fifty-four years later, we find William Morgan (communicated by a Reverend Richard Price) promoting ‘the method of determining, from the real probabilities of life, the value of a contingent reversion in which three lives are involved in the survivorship.’ 
In an age when prospects in society – and lines of credit - might be dependent on one’s ‘great expectations’ of an inheritance, calculating the probability of achieving that inheritance (known to lawyers as contingency reversion) becomes of great interest. For instance, I might transfer a piece of land on the following basis: to my niece for her lifetime, remainder to my nephew and his heirs, but if my nephew dies in the lifetime of my niece, then the land reverts to me and my heirs; I have a ‘reversionary interest’ in the land. The question for my eighteenth century nephew is how to value the sum that might be payable on the contingency that he will survive his sister. The method and calculations proposed by Morgan are set out at length and in considerable detail so as to enable a reader to test and critique them. To this author’s non-expert eye, two points are striking. First, that the calculations appear to be based on group data i.e. on the number of persons living at the age of my nephew, and at the end of first year, second year, third year and so, from the age of my nephew. Secondly, the article goes onto criticise a rule proposed by a certain ‘Mr Simpson’ and points to its results as deviating ‘so widely from the truth as to be unfit for use’ [my emphasis] in some cases producing ‘absurd’ results. 
A modern reader might be tempted to regard these articles as illustrations of a naïve age or to a context long past, or to highlight the lack of causal evidence for Reverend Barrow’s conclusion about the ‘healthful’ nature of his parish. Yet both articles tackle issues with which we remain concerned today: the healthiness (or otherwise) of a community, the reasons behind it and the life expectancy of an individual when compared to others. Risk forecasting and predictive techniques to aid decision- making have become commonplace in our society, not least within public services such as criminal justice, security, benefit fraud detection, health, child protection and social care. We should be better at it than our eighteenth century clergymen. It has become almost unnecessary to say that we now inhabit an information society. Information technologies driven by the flow of digital data have become pervasive and everyday, often leading to the assumption that access to vast banks of (often individualised) digital data, combined with today’s networked computing power and complex algorithmic tools, will lead automatically to greater knowledge and insight, and so to better predictions. 
Knowledge, however, is not the same as information (as many before me have pointed out): Knowledge, Hassan argues, ‘emerges through the open and experiential and diverse (and often intuitive) working and interpreting of raw data and information.’  Reverend Barrow’s conclusion as to the healthfulness of his parish, for instance, was based, not only on the outcome of analysis of raw data, but on additional ‘experience and observations’ of himself and others. Some criticise such human ‘intrusion’ on the data as casting further doubt on the conclusion. Grove and Meehl, a leading proponent of the use of statistical, algorithmic methods of data analysis over clinical methods, argued that ‘To use the less efficient of two prediction procedures in dealing with such matters is not only unscientific and irrational, it is unethical. To say that the clinical-statistical issue is of little importance is preposterous.’  It is this often-claimed superiority, together with the potential for more consistent application of relevant factors often taken from large datasets, that give algorithmic tools their appeal in many public sector contexts. Although this article is written from a legal perspective, it draws attention to arguments made in the ongoing ‘algorithmic predictions versus purely human judgement’ debate and applies these to the legal principles discussed below. It is particularly concerned with algorithm-assisted decisions, whereby an algorithmic output, prediction or recommendation produced by machine learning technique is incorporated into a decision-making process requiring a human to approve or apply it. ‘Machine learning involves presenting the machine with example inputs of the task that we wish it to accomplish. In this way, humans train the system by providing it with data from which it will be able to learn. The algorithm makes its own decision regarding the operation to be performed to accomplish the task in question.’  Machine learning algorithms are ‘probabilistic...their output is always changing depending on the learning basis they were given, which itself changes in step with their use.’ 
Predictive algorithms and administrative law 
The growth in the use of intensive computational statistics, machine-learning and algorithmic methods by the UK public sector shows no sign of abating. What then should be the role of the human when these tools are planned and then deployed, particularly when the accuracy of an algorithmic prediction is claimed to be at least comparable to the accuracy of a human one? I consider this question by reference to a number of connected English administrative law rules, some of which (such as natural justice) date back to before the origins of this journal. I have done this because this body of law governs the exercise of discretionary powers and duties by state bodies, and thus the humans working within them; discretion must be exercised within boundaries or the public body is acting unlawfully. As Le Sueur explains, ‘The assumption made until comparatively recently is that the decision-maker using the executive power conferred by Parliament is a human being or an institution composed of humans and that there is a human who will be accountable and responsible for the decision.’ 
We see this today in witnesses called to give evidence to Parliamentary Select Committees. The introduction of an algorithm to replace, or even only to assist, the human decision-maker represents a challenge to this assumption and thus to the rule of law, and the power of Parliament to decide upon the legal basis of decision-making by public bodies. I argue below however that English administrative law – in particular the duty to give reasons, the rules around relevant and irrelevant considerations and around fettering discretion – is flexible enough to respond to many of the challenges raised by the use of predictive machine learning algorithms, and can signpost key principles for the deployment of algorithms within public sector settings. These principles, although derived from historic case- law, have already been applied and refined to modern government, to the development of the welfare state, privatisation, the development of executive agencies and so on. 
I then attempt to re-frame each of these rules in order to suggest how they could guide future algorithm-assisted decision-making by public bodies affecting rights, expectations and interests of individuals. In doing so, I do not recommend any particular method of building or interpreting these systems - as to do so would require consideration of many different contexts and informational needs - but to suggest principles to guide those engaged in future development work. I focus attention on the requirements of legitimate decision-making from the perspective of the public sector decision-maker, rather than from the perspective of the subject. Fair decision-making in accordance with administrative law rules by its very nature also protects the interests of the human subject of those decisions. I argue that carefully considering exactly what the algorithm is or is not predicting, and explaining to the decision-maker at the point results are displayed, is key to ensuring this fairness.

Consent

'Moving Beyond Consent For Citizen Science in Big Data Health and Medical Research' by Anne SY Cheung in (2018) 16 Northwestern Journal of Technology and Intellectual Property 15 comments
Consent has been the cornerstone of the personal data privacy regime. This notion is premised on the liberal tenets of individual autonomy, freedom of choice, and rationality. The above concern is particularly pertinent to citizen science in health and medical research, in which the nature of research is often data intensive with serious implications for individual privacy and other interests. Although there is no standard definition for citizen science, it includes generally the gathering and volunteering of data by non-professionals, the participation of non-experts in analysis and scientific experimentation, and public input into research and projects. Consent from citizen scientists determines the responsibility and accountability of data users. Yet with the advancement of data mining and big data technologies, risks and harm of subsequent data use may not be known at the time of data collection. Progress of research often extends beyond the existing data. In other words, consent becomes problematic in citizen science in the big data era. The notion that one can fully specify the terms of participation through notice and consent has become a fallacy. 
Is consent still valid? Should it still be one of the critical criteria in citizen science health and medical research which is collaborative and contributory by nature? With a focus on the issue of consent and privacy protection, this study analyzes not only the traditional informed consent model but also the alternative models. Facing the challenges that big data and citizen science pose to personal data protection and privacy, this article explores the legal, social, and ethical concerns behind the concept of consent. It argues that we need to move beyond the consent paradigm and take into account the much broader context of harm and risk assessment, focusing on the values behind consent – autonomy, fairness and propriety in the name of research.

11 August 2018

Retrospects

It's perhaps difficult for some undergraduate law students to recognise that the world predates Jusdtin Bieber. A corrective is provided in 'The information infrastructures of 1985 and 2018: The sociotechnical context of computer law and; security' by Roger Clarke and Marcus Wigan in (2018) Computer Law and Security Review.

Their incisive analysis states
This article identifies key features of the sociotechnical contexts of computer law and security at the times of this journal’s establishment in 1985, and of its 200th Issue in 2018. The infrastructural elements of devices, communications, data and actuator technologies are considered first. Social actors as individuals, and in groups, communities, societies and polities, together with organisations and economies, are then interleaved with those technical elements. This provides a basis for appreciation of the very different challenges that confront us now in comparison with the early years of post-industrialism.
 The authors comment
The field addressed by Computer Law and Security Review (CLSR) during its first 34 volumes, 1985–2018, has developed within an evolving sociotechnical context. A multi-linear trace of that context over a 35-year period would, however, be far too large a topic to address in a journal article. This article instead compares and contrasts the circumstances that applied at the beginning and at the end of the period, without any systematic attempt either to track the evolution from prior to current state or to identify each of the disruptive shifts that have occurred. This sacrifices developmental insights, but it enables key aspects of contemporary challenges to be identified in a concise manner. 
The article commences by identifying what the authors mean by ‘sociotechnical context’. The two main sections then address the circumstances of 1985 and 2018. In each case, consideration is first given to the information infrastructure whose features and affordances are central to the field of view, and then to the activities of the people and organisations that use and are used by information technologies. Implications of the present context are drawn, for CLSR, its contributors and its readers, but more critically for society. 
The text can of course be read in linear fashion. Alternatively, readers interested specifically in assessment of con- temporary IT can skip the review of the state in 1985 and go directly to the section dealing with 2018. It is also feasible to read about the implications in Section 5 first, and then return to earlier sections in order to identify the elements of the sociotechnical context that have led the authors to those inferences. 
The focus of this article is not on specific issues or incre- mental changes, because these are identified and addressed on a continuing basis by CLSR’s authors. The concern here is with common factors and particularly with discontinuities – the sweeping changes that are very easily overlooked, and that only emerge when time is taken to step back and consider the broader picture. The emphasis is primarily on social impacts and public policy issues, because the interests of business and government organisations are already strongly represented in this journal and elsewhere.

07 August 2018

Producers

'Privacy and Data Management: The User and Producer Perspectives' by Wenhong Chen, Anabel Quan-Haase, Yong Jin Park in (2018) American Behavioral Scientist comments
 Drawing on diverse theoretical and methodological approaches, this special issue takes a fresh look at the various aspects of the messy gridlock of privacy practices from the user and the producer perspectives. On the one hand, we aim to advance privacy research at the individual level in terms of scope, typology, and implications. On the other hand, we advocate for greater attention to one of the most important, yet still underdeveloped, lines of inquiry in privacy research: the perspective of producers such as governments, corporations, and tech startups, especially looking at how corporations and entrepreneurs design and develop their privacy policies, practices, and strategies. Together, these articles have numerous implications for policy makers, industry, and community practitioners. 
At the 2018 World Economic Forum, German’s chancellor Angela Merkel stated, “Data will be the raw material of the 21st Century—the question ‘who owns that data?’ will decide whether democracy, the participatory social model and economic prosperity can be combined” (Chu, 2018). As data become the new oil of the 21st century, commercial use of personal data has become the core business model of many technology firms and the administrative use of private data an integral part of all levels of governance and national and international security. The ongoing Cambridge Analytica scandal and its aftermaths have drawn tremendous attention to privacy issues and current data management practices at corporate giants such as Facebook, Google, and Twitter. The lack of transparency, accountability, and regulatory frameworks have increased privacy concerns of citizens and shown the significant work ahead toward developing much needed regulations (Yang, Quan-Haase, & Rannenberg, 2016). 
The seven articles in this special issue represent a range of theoretical and methodological approaches surveying the changing landscape of privacy practices from both user and producer perspectives in the United States, Canada, and Hong Kong. Two of the seven articles focus on the producer perspective, while the remainder five articles examine privacy from an individual perspective. Together, the articles advance our understanding of privacy broadly and specifically show the need for both user and producer perspectives. A growing number of individuals around the globe use digital media technologies for information, communication, work, and entertainment. Digital media are the devices (e.g., computers, tablets, and mobile phones) and applications (e.g., Facebook, Twitter, and Skype) used to access, produce, consume, and exchange information in a digital form, especially for supporting social interactions and finding information (Quan-Haase, Wellman, & Zhang, in press). It is thus understandable that many studies have centered on the patterns, causes, and consequences of privacy practices from the perspective of individual users. Much of the scholarly literature has examined how a user’s gender, education, or digital skills have affected their privacy management. This literature has also looked at psychological, cultural, and contextual factors at the individual level that may affect privacy decisions and attitudes. Individual-level analysis clearly offer extremely valuable insights on the implications of individuals’ psychological and demographic attributes and interpersonal relationships for their privacy concerns, calculations, and tactics. Yet individual-level examinations often provide limited understanding about the power of state and corporate actors in how users’ data are collected, used, and shared. After all, individual users, if not organized through advocacy groups or social movements, may have limited influence on national or international privacy regulations as well as on corporate policies and practices. Textual analysis of privacy laws, regulations, and policies tend to miss the interactions among a web of actors in the negotiation of privacy as a key social contract that redefines the boundary of the public and the private. That is, privacy is a social negotiation among various actors and as such privacy research needs to examine how these various actors come together to understand privacy. 
Without discounting the importance of privacy research at the individual level, we argue in this special issue that it is equally important, if not more important, to take into account the producer perspective. Privacy and data management involve a web of multiple stakeholders in a complicated data ecosystem, which includes individual users, corporations, governments, policy makers, and nongovernmental organizations. One of the most important yet still underdeveloped lines of inquiry in privacy research is the perspective of producers such as governments, corporations, and tech startups. For example, often simply vilified or treated as a uniform entity without much to contribute to the debate, technology firms and startups deserve greater and more nuanced attention in the privacy scholarly literature. As a result, we do not know much about the producer’s perspective, that is, how businesses and entrepreneurs design and develop their privacy policies, practices, and strategies.

Beyond the Binary

The Australian Human Rights Commission is conducting a project that considers
how best to protect the human rights of people born with variations in sex characteristics — in the specific context of non-consensual medical interventions.
There are currently no Australian national guidelines or legislation regarding what the Commission characterises as "the management of people born with variations in sex characteristics in Australia". Legal scholars and some of those people might respectfully suggest that "management" is an inappropriate term.

The Commission states
 The aims of the project are to:
  • identify key issues and obtain perspectives on current practice by consulting with various stakeholders, including individuals born with variations in sex characteristics, advocacy groups, medical professionals and representatives from federal, state and territory governments 
  • evaluate the current approaches taken to medical interventions in Australia and other jurisdictions using a human rights-based framework 
  • develop recommendations for a nationally consistent human-rights based approach to decision-making about medical interventions.
For this inquiry, the Commission uses the term ‘people born with variations in sex characteristics’ to refer to people born with bodies that do not align with medical norms for female or male bodies. This can include variations in sex chromosomes, hormones, reproductive organs and/or sexual anatomy. ‘Intersex’ is another term used to describe this population.

AAT Review

The Commonwealth Attorney-General Christian Porter announced on 27 July that that former High Court Justice David Callinan AC QC will undertake a statutory review of the Administrative Appeals Tribunal (AAT) in accordance with section 4 of the Tribunals Amalgamation Act 2015 (Cth).

The Administrative Appeals Tribunal (AAT) was amalgamated with the Social Security Appeals Tribunal, the Migration Review Tribunal and Refugee Review Tribunal on 1 July 2015.

Under s 4, the Attorney-General must cause a review of the operations of the amendments made under the enactment, commencing as soon as practicable three years after the Act's commencement. The Review must also consider any other related matter that the Minister specifies.

The Terms of Reference are
A review is to be commenced, in accordance with section 4 of the Tribunals Amalgamation Act 2015 (TA Act), to consider the operation of the amendments made by the TA Act to the Tribunal. 
The review shall consider:
  • whether the objectives of the TA Act have been achieved; 
  • the extent to which the Tribunal operates as a truly amalgamated body, and whether any existing levels of separation are necessary and appropriate; 
  • whether the Tribunal is meeting the statutory objectives contained in section 2A of the Administrative Appeals Tribunal Act 1975, with particular regard to:
  • the objective to promote public trust and confidence in the decision-making of the Tribunal, including: - the extent to which decisions of the Tribunal meet community expectations; and - the effectiveness of the interaction and application of legislation, Practice directions, Ministerial Directions, guides, guidelines and policies of the Tribunal;
 the degree to which legislation, processes, grounds, scope, and levels of review in, and from, the Tribunal promote timely and final resolution of matters; 
whether the Tribunal’s operations and efficiency can be improved through further legislative amendments or through non-legislative changes; and 
whether the arrangements for funding the operations of the Tribunal are appropriate, including ensuring consistent funding models across divisions.
The written report of the review is to be provided to the Attorney-General by 31 October 2018. 

06 August 2018

Guns

'3D Printing, Policing and Crime' (Crime Justice and Social Democracy Research Centre Briefing Paper Series, 1. Crime Justice and Social Democracy Research Centre, Brisbane) by Angela Daly and Monique Mann states 
This CJRC briefing paper provides background information on the intersections of three-dimensional (3D) printing technology, policing, and crime. It focuses on the opportunities and challenges of this technological innovation. Specifically, this report canvasses the role of 3D printing as a tool, as a source of evidence, and as a potential threat for police agencies and wider public safety. The emergence of 3D printed firearms is discussed in depth, and an overview of case studies where 3D firearms or firearm parts have been located and investigated by police is included. Finally, the legal and enforcement models implemented to address 3D printing technology to date in different jurisdictions are reviewed.
Worth reading