19 February 2023

Identity Crime

The Manchester crown court has convicted Zholia Alemi for fraud, after she practised as psychiatrist in the UK for 20 years without necessary qualifications and after forging medical degree certificate.Alemi received income and benefits of over £1m across her career,

Manley J referred to a “deliberate and wicked deception”, noting that Alemi worked in hospitals across England, Wales and Scotland. Alemi was found guilty of 13 counts of fraud, three counts of obtaining a pecuniary advantage by deception, two counts of forgery and two counts of using a false instrument. 

Manley J commented that the deception Alemi to work with “potentially very vulnerable people over a long period of time”, questioning how Alemi had been able to practise for so long and in so many positions. The Prosecution described Alemi as “a most accomplished forger and fraudster” who had “no qualification that would allow her to be called, or in any way to be properly regarded as, a doctor.”

Reports indicate that in providing a forged certificate to the General Medical Council in 1995, Alemi claimed to have qualified at the University of Auckland, with a forged letter of verification referring to “six years medical trainee with satisfactory grade”. A vetting failure did not pick up that Alemi's  records showed that she completed only the first stage of the degree and had been excluded from re-enrolment after multiple failures. 

An investigative journalist claims

 The records showed she had the requisite medical degree, a Bachelor of Medicine, Bachelor of Surgery (referred to as MBChB), awarded in 1992 by the University of Auckland. It took only three of four phone calls to confirm that Alemi’s medical degree was a fiction.

Alemi was at times was employed by the NHS, worked at health bodies and trusts, and secured positions through recruitment agencies. 

t Alemi had been convicted of three fraud offences at Carlisle crown court in 2018 after forging an 84-year-old woman’s will to make herself the beneficiary and forging powers of attorney. She was sentenced to five years in prison in that case. 

 The UK General Medical Council (which had dealt with nine complaints, "all were investigated fully") states 

We are confident that the robust checks we use today would identify anyone attempting to join the register dishonestly. A doctor applying for registration today in the same scenario would be required to:

  • have their primary qualification verified with the relevant university by the *ECFMG – the body that verifies the credentials of healthcare professionals worldwide 

  • sit and pass both parts of Professional and Linguistic Assessments Board (PLAB) test or provide equivalent evidence of their medical knowledge and skills 

  • provide comprehensive employment history and references for the most recent five years 

  • provide a certificate of good standing from the regulator in each country they had practised in over those five years

  • attend the GMC offices in person to undergo an ID check bringing all original documentation with them. These documents are then examined in detail. This includes physical and light machine examination – each document is examined for signs of amendment, tampering or falsification.. We also use a Keesing document checker – Keesing Technologies is a specialist provider of digital anti-counterfeiting and authentication solutions. In addition, we have access to a system called PRADO – a multi-lingual site for disseminating information on security features of authentic identity and travel documents

Alemi was investigated by the Medical Practitioners Tribunal Service in 2012 after failing to disclose a conviction for careless driving. At that time the Tribunal looked into a complaint that she had wrongly sectioned a patient, issuing a warning. The GMC is unable to bring disciplinary charges against Alemi because she is not a real doctor and so cannot be struck off the medical register.

The British Medical Journal notes that in 2017 Conrad de Souza was convicted for false representations about his qualifications, employment history and previous convictions. He had been jailed in 2011 for 27 months after posing as a GP and working for nine years in NHS roles in south London. De Souza did not complete medical school, had invented his date of birth and falsely claimed to have studied at Dulwich College. Inadequate checking meant he was able to work in clinical strategy roles for the former Lewisham Primary Care Trust for nine years. The 2011 conviction appears to have been triggered by forgery regarding his manipulation of a paternity test in order to evade child support obligations.

The 2017 conviction followed him admitting six charges of fraud at Croydon Crown Court in 2016 after falsifying his employment and qualifications in an attempt to secure senior health roles in the NHS between 2013 and 2014, presumably after early release from prison.

16 February 2023

Privacy Act Review

The report of the review into the Privacy Act 1988 (Cth) features the following proposals - 

 3. Objects of the Act 

3.1 Amend the objects of the Act to clarify that the Act is about the protection of personal information. 

3.2 Amend the objects of the Act to recognise the public interest in protecting privacy. 

4. Personal information, de-identification and sensitive information 

4.1 Change the word ‘about’ in the definition of personal information to ‘relates to’. Ensure the definition is appropriately confined to where the connection between the information and the individual is not too tenuous or remote, through drafting of the provision, explanatory materials and OAIC guidance. 

4.2 Include a non-exhaustive list of information which may be personal information to assist APP entities to identify the types of information which could fall within the definition. Supplement this list with more specific examples in the explanatory materials and OAIC guidance. 

4.3 Amend the definition of ‘collection’ to expressly cover information obtained from any source and by any means, including inferred or generated information. 

4.4 ‘Reasonably identifiable’ should be supported by a non-exhaustive list of circumstances to which APP entities will be expected to have regard in their assessment. 

4.5 Amend the definition of ‘de-identified’ to make it clear that de-identification is a process, informed by best available practice, applied to personal information which involves treating it in such a way such that no individual is identified or reasonably identifiable in the current context. 

4.6 Extend the following protections of the Privacy Act to de-identified information: (a) APP 11.1 – require APP entities to take such steps as are reasonable in the circumstances to protect de-identified information: (a) from misuse, interference and loss; and (b) from unauthorised re-identification, access, modification or disclosure. (b) APP 8 – require APP entities when disclosing de-identified information overseas to take steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles in relation to de-identified information, including ensuring that the receiving entity does not re- identify the information or further disclose the information in such a way as to undermine the effectiveness of the de-identification. (c) Targeting proposals – the proposed regulation of content tailored to individuals should apply to de-identified information to the extent that it is used in that act or practice. 

4.7 Consult on introducing a criminal offence for malicious re-identification of de-identified information where there is an intention to harm another or obtain an illegitimate benefit, with appropriate exceptions. 

4.8 Prohibit an APP entity from re-identifying de-identified information obtained from a source other than the individual to whom the information relates, with appropriate exceptions. In addition, the prohibition should not apply where: (a) the re-identified information was de-identified by the APP entity itself - in this case, the APP entity should simply comply with the APPs in the ordinary way. (b) the re-identification is conducted by a processor with the authority of an APP entity controller of the information. 

4.9 Sensitive Information (a) Amend the definition of sensitive information to include ‘genomic’ information. (b) Amend the definition of sensitive information to replace the word ‘about’ with ‘relates to’ for consistency of terminology within the Act. (c) Clarify that sensitive information can be inferred from information which is not sensitive information. 

4.10 Recognise collection, use, disclosure and storage of precise geolocation tracking data as a practice which requires consent. Define ‘geolocation tracking data’ as personal information which shows an individual’s precise geolocation which is collected and stored by reference to a particular individual at a particular place and time, and tracked over time. 

5. Flexibility of the APPs 

5.1 Amend the Act to give power to the Information Commissioner to make an APP code where the AttorneyGeneral has directed or approved that a code should be made: (a) where it is in the public interest for a code to be developed, and (b) where there is unlikely to be an appropriate industry representative to develop the code. In developing an APP code, the Information Commissioner would: (a) be required to make the APP Code available for public consultation for at least 40 days, and (b) be able to consult any person he or she considers appropriate and to consider the matters specified in any relevant guidelines at any stage of the code development process. 

5.2 Amend the Act to enable the Information Commissioner to issue a temporary APP code for a maximum 12 month period on the direction or approval of the Attorney-General if it is urgently required and where it is in the public interest to do so. 

5.3 Amend the Act to enable Emergency Declarations to be more targeted by prescribing their application in relation to: (a) entities, or classes of entity (b) classes of personal information, and (c) acts and practices, or types of acts and practices. 

5.4 Ensure the Emergency Declarations are able to be made in relation to ongoing emergencies. 

5.5 Amend the Act to permit organisations to disclose personal information to state and territory authorities under an Emergency Declaration, provided the state or territory has enacted comparable privacy laws to the Commonwealth. 

6. Small business exemption 

6.1 Remove the small business exemption, but only after: (a) an impact analysis has been undertaken to better understand the impact removal of the small business exemption will have on small business - this would inform what support small business would need to adjust their privacy practices to facilitate compliance with the Act (b) appropriate support is developed in consultation with small business (c) in consultation with small business, the most appropriate way for small business to meet their obligations proportionate to the risk, is determined (for example, through a code), and (d) small businesses are in a position to comply with these obligations. 

6.2 In the short term: (a) prescribe the collection of biometric information for use in facial recognition technology as an exception to the small business exemption, and (b) remove the exemption from the Act for small businesses that obtain consent to trade in personal information. 

7. Employee records exemption 

7.1 Enhanced privacy protections should be extended to private sector employees, with the aim of: a) b) c) providing enhanced transparency to employees regarding what their personal and sensitive information is being collected and used for ensuring that employers have adequate flexibility to collect, use and disclose employees’ information that is reasonably necessary to administer the employment relationship, including addressing the appropriate scope of any individual rights and the issue of whether consent should be required to collect employees’ sensitive information ensuring that employees’ personal information is protected from misuse, loss or unauthorised access and is destroyed when it is no longer required, and d) notifying employees and the Information Commissioner of any data breach involving employee’s personal information which is likely to result in serious harm. Further consultation should be undertaken with employer and employee representatives on how the protections should be implemented in legislation, including how privacy and workplace relations laws should interact. The possibility of privacy codes of practice developed through a tripartite process to clarify obligations regarding collection, use and disclosure of personal and sensitive information should also be explored. 

8. Political exemption 

8.1 Amend the definition of ‘organisation’ under the Act so that it includes a ‘registered political party’ and include registered political parties within the scope of the exemption in section 7C. 

8.2 Political entities should be required to publish a privacy policy which provides transparency in relation to acts or practices covered by the exemption. 

8.3 The political exemption should be subject to the following requirements: (a) Political acts and practices covered by the exemption must be fair and reasonable. (b) Political entities must not engage in targeting based on sensitive information or traits which relates to an individual, with an exception for political opinions, membership of a political association, or membership of a trade union. The political exemption should include a savings clause as per Recommendation 41-2 of ALRC Report 108. 

8.4 The political exemption should be subject to a requirement that individuals must be provided with the means to: (a) opt-out of their personal information being used or disclosed for direct marketing by a political entity, and (b) opt-out of receiving targeted advertising from a political entity. 

8.5 The political exemption should be subject to a requirement that political entities must: (a) take reasonable steps to protect personal information held for the purpose of the exemption from misuse, interference and loss, as well as unauthorised access, modification or disclosure (b) take reasonable steps to destroy or de-identify the personal information it holds once the personal information is no longer needed for a purpose covered by the political exemption, and (c) comply with the NDB scheme in relation to an eligible data breach involving personal information held for a purpose covered by the political exemption. 

8.6 The OAIC should develop further guidance materials to assist political entities to understand and meet their obligations. 

9. Journalism exemption 

9.1 To benefit from the journalism exemption a media organisation must be subject to: (a) privacy standards overseen by a recognised oversight body (the ACMA, APC or IMC), or (b) standards that adequately deal with privacy. 

9.2 In consultation with industry, and the ACMA, the OAIC should develop and publish criteria for adequate media privacy standards and a template privacy standard that a media organisation may choose to adopt. 

9.3 An independent audit and review of the operation of the journalism exemption should be commenced three years after any amendments to the journalism exemption come into force. 

9.4 Require media organisations to comply with security and destruction obligations in line with the obligations set out in APP 11. 

9.5 Require media organisations to comply with the reporting obligations in the NDB scheme. There will need to be some modifications so that a media organisation would not need to notify an affected individual if the public interest in journalism outweighs the interest of affected individuals in being notified. 

10. Privacy policies and collection notices 

10.1 Introduce an express requirement in APP 5 that requires collection notices to be clear, up-to-date, concise and understandable. Appropriate accessibility measures should also be in place. 

10.2 The list of matters in APP 5.2 should be retained. OAIC guidance should make clear that only relevant matters, which serve the purpose of informing the individual in the circumstances, need to be addressed in a notice. The following new matters should be included in an APP 5 collection notice: (a) if the entity collects, uses or discloses personal information for a high privacy risk activity —the circumstances of that collection, use or disclosure (b) that the APP privacy policy contains details on how to exercise any applicable Rights of the Individual, and (c) the types of personal information that may be disclosed to overseas recipients. 

10.3 Standardised templates and layouts for privacy policies and collection notices, as well as standardised terminology and icons, should be developed by reference to relevant sectors while seeking to maintain a degree of consistency across the economy. This could be done through OAIC guidance and/or through any future APP codes that may apply to particular sectors or personal information-handling practices. 

11. Consent and privacy default settings 

11.1 Amend the definition of consent to provide that it must be voluntary, informed, current, specific, and unambiguous. 

11.2 The OAIC could develop guidance on how online services should design consent requests. This guidance could address whether particular layouts, wording or icons could be used when obtaining consent, and how the elements of valid consent should be interpreted in the online context. Consideration could be given to further progressing standardised consents as part of any future APP codes. 

11.3 Expressly recognise the ability to withdraw consent, and to do so in a manner as easily as the provision of consent. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. 

11.4 Online privacy settings should reflect the privacy by default framework of the Act. APP entities that provide online services should be required to ensure that any privacy settings are clear and easily accessible for service users. 

12. Fair and reasonable personal information handling 

12.1 Amend the Act to require that the collection, use and disclosure of personal information must be fair and reasonable in the circumstances. It should be made clear that the fair and reasonable test is an objective test to be assessed from the perspective of a reasonable person. 

12.2 In determining whether a collection, use or disclosure is fair and reasonable in the circumstances, the following matters may be taken into account: (a) (b) (c) (d) (e) (f) (g) whether an individual would reasonably expect the personal information to be collected, used or disclosed in the circumstances the kind, sensitivity and amount of personal information being collected, used or disclosed whether the collection, use or disclosure is reasonably necessary for the functions and activities of the organisation or is reasonably necessary or directly related for the functions and activities of the agency the risk of unjustified adverse impact or harm whether the impact on privacy is proportionate to the benefit if the personal information relates to a child, whether the collection, use or disclosure of the personal information is in the best interests of the child, and the objects of the Act. The EM would note that relevant considerations for determining whether any impact on an individual’s privacy is ‘proportionate’ and could include: (a) whether the collection, use or disclosure intrudes upon the personal affairs of the affected individual to an unreasonable extent (b) whether there are less intrusive means of achieving the same ends at comparable cost and with comparable benefits, and (c) any actions or measures taken by the entity to mitigate the impacts of the loss of privacy on the individual. 

12.3 The requirement that collection, use and disclosure of personal information must be fair and reasonable in the circumstances should apply irrespective of whether consent has been obtained. The requirement that collection, use and disclosure of personal information must be fair and reasonable in the circumstances should not apply to exceptions in APPs 3.4 and 6.2. The reference to a ‘fair means’ of collection in APP 3.5 should be repealed. 

13. Additional protections 

13.1 APP entities must conduct a Privacy Impact Assessment for activities with high privacy risks. (a) A Privacy Impact Assessment should be undertaken prior to the commencement of the high-risk activity. (b) An entity should be required to produce a Privacy Impact Assessment to the OAIC on request. The Act should provide that a high privacy risk activity is one that is ‘likely to have a significant impact on the privacy of individuals’. OAIC guidance should be developed which articulates factors that that may indicate a high privacy risk, and provides examples of activities that will generally require a Privacy Impact Assessment to be completed. Specific high risk practices could also be set out in the Act. 

13.2 Consider how enhanced risk assessment requirements for facial recognition technology and other uses of biometric information may be adopted as part of the implementation of Proposal 13.1 to require Privacy Impact Assessments for high privacy risk activities. This work should be done as part of a broader consideration by government of the regulation of biometric technologies. 

13.3 The OAIC should continue to develop practice-specific guidance for new technologies and emerging privacy risks. Practice-specific guidance could outline the OAIC’s expectations for compliance with the Act when engaging in specific high-risk practices, including compliance with the fair and reasonable personal information handling test. 

13.4 Include an additional requirement in APP 3.6 to the effect that where an entity does not collect information directly from an individual, it must take reasonable steps to satisfy itself that the information was originally collected from the individual in accordance with APP 3. OAIC guidelines could provide examples of reasonable steps that could be taken. 

14. Research 

14.1 Broad consent for research Introduce a legislative provision that permits broad consent for the purposes of research: (a) Broad consent should be available for all research to which the research exceptions in the Act (and proposed by this chapter) will also apply. (b) Broad consent would be given for ‘research areas’ where it is not practicable to fully identify the purposes of collection, use or disclosure of personal or sensitive information at the point when consent is being obtained. 

14.2 Consult further on broadening the scope of research permitted without consent for both agencies and organisations. 

14.3 Consult further on developing a single exception for research without consent and a single set of guidelines, including considering the most appropriate body to develop the guidelines. 

15. Organisational Accountability 

15.1 An APP entity must determine and record the purposes for which it will collect, use and disclose personal information at or before the time of collection. If an APP entity wishes to use or disclose personal information for a secondary purpose, it must record that secondary purpose at or before the time of undertaking the secondary use or disclosure. 

15.2 Expressly require that APP entities appoint or designate a senior employee responsible for privacy within the entity. This may be an existing member of staff of the APP entity who also undertakes other duties. 

16. Children 

16.1 Define a child as an individual who has not reached 18 years of age. 

16.2 Existing OAIC guidance on children and young people and capacity15 should continue to be relied upon by APP entities. An entity must decide if an individual under the age of 18 has the capacity to consent on a case-by- case basis. If that is not practical, an entity may assume an individual over the age of 15 has capacity, unless there is something to suggest otherwise. The Act should codify the principle that valid consent must be given with capacity. Such a provision could state that ‘the consent of an individual is only valid if it is reasonable to expect that an individual to whom the APP entity’s activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting.’ Exceptions should be provided for circumstances where parent or guardian involvement could be harmful to the child or otherwise contrary their interests (including, but not limited to confidential healthcare advice, domestic violence, mental health, drug and alcohol, homelessness or other child support and community services). 

16.3 Amend the Privacy Act to require that collection notices and privacy policies be clear and understandable, in particular for any information addressed specifically to a child. In the context of online services, these requirements should be further specified in a Children’s Online Privacy Code, which should provide guidance on the format, timing and readability of collection notices and privacy policies. 

16.4 Require entities to have regard to the best interests of the child as part of considering whether a collection, use or disclosure is fair and reasonable in the circumstances. 

16.5 Introduce a Children’s Online Privacy Code that applies to online services that are ‘likely to be accessed by children’. To the extent possible, the scope of an Australian children’s online privacy code could align with the scope of the UK Age Appropriate Design Code, including its exemptions for certain entities including preventative or counselling services. The code developer should be required to consult broadly with children, parents, child development experts, child- welfare advocates and industry in developing the Code. The eSafety Commissioner should also be consulted. The substantive requirements of the Code could address how the best interests of child users should be supported in the design of an online service. 

17. People experiencing vulnerability 

17.1 Introduce, in OAIC guidance, a non-exhaustive list of factors that indicate when an individual may be experiencing vulnerability and at higher risk of harm from interferences with their personal information. 

17.2 OAIC guidance on capacity and consent should be updated to reflect developments in supported decision- making. 

17.3 Further consultation should be undertaken to clarify the issues and identify options to ensure that financial institutions can act appropriately in the interests of customers who may be experiencing financial abuse or may no longer have capacity to consent.

18. Rights of the Individual Access and Explanation 

18.1 Provide individuals with a right to access, and an explanation about, their personal information if they request it, with the following features: (a) an APP entity must provide access to the personal information they hold about the individual (this reflects the existing right under the Act) (b) an APP entity must identify the source of the personal information it has collected indirectly, on request by the individual (c) an APP entity must provide an explanation or summary of what it has done with the personal information, on request by the individual (d) the entity may consult with the individual about the format for responding to a request, and the format should reflect the underlying purpose of ensuring the individual is informed, as far as is reasonable, about what is being done with their information (e) an organisation may charge a ‘nominal fee’ for providing access and explanation where the organisation has produced a product in response to an individual 

Objection 

18.2 Introduce a right to object to the collection, use or disclosure of personal information. An APP entity must provide a written response to an objection with reasons. 

Erasure 

18.3 Introduce a right to erasure with the following features: (a) An individual may seek to exercise the right to erasure for any of their personal information. (b) An APP entity who has collected the information from a third party or disclosed the information to a third party must inform the individual about the third party and notify the third party of the erasure request unless it is impossible or involves disproportionate effort. In addition to the general exceptions, certain limited information should be quarantined rather than erased on request, to ensure that the information remains available for the purposes of law enforcement. 

Correction 

18.4 Amend the Act to extend the right to correction to generally available publications online over which an APP entity maintains control. 

De-indexing 

18.5 Introduce a right to de-index online search results containing personal information which is: (a) sensitive information [e.g. medical history], or (b) information about a child, or (c) excessively detailed [e.g. home address and personal phone number], or (d) inaccurate, out-of-date, incomplete, irrelevant, or misleading. The search engine may refer a suitable request to the OAIC for a fee. The right should be jurisdictionally limited to Australia. Exceptions 

18.6 Introduce relevant exceptions to all rights of the individual based on the following categories: (a) Competing public interests: such as where complying with a request would be contrary to public interests, including freedom of expression and law enforcement activities. (b) Relationships with a legal character: such as where complying with the request would be inconsistent with another law or a contract with the individual. (c) Technical exceptions: such as where it would be technically impossible, or unreasonable, and frivolous or vexatious to comply with the request. 

18.7 Individuals should be notified at the point of collection about their rights and how to obtain further information on the rights, including how to exercise them. Privacy policies should set out the APP entity’s procedures for responding to the rights of the individual. Proposal 18.8 An APP entity must provide reasonable assistance to individuals to assist in the exercise of their rights under the Act. 

Response 

18.9 An APP entity must take reasonable steps to respond to an exercise of a right of an individual. Refusal of a request should be accompanied by an explanation for the refusal and information on how an individual may lodge a complaint regarding the refusal with the OAIC. 

18.10 An organisation must acknowledge receipt of a request to exercise a right of an individual within a reasonable time and provide a timeframe for responding. An agency and organisation must respond to a request to exercise a right within a reasonable timeframe. In the case of an agency, the default position should be that a reasonable timeframe is within 30 days, unless a longer period can be justified. 

19. Automated decision making 

19.1 Privacy policies should set out the types of personal information that will be used in substantially automated decisions which have a legal or similarly significant effect on an individual’s rights. 

19.2 High-level indicators of the types of decisions with a legal or similarly significant effect on an individual’s rights should be included in the Act. This should be supplemented by OAIC Guidance. 

19.3 Introduce a right for individuals to request meaningful information about how substantially automated decisions with legal or similarly significant effect are made. Entities will be required to include information in privacy policies about the use of personal information to make substantially automated decisions with legal or similarly significant effect. This proposal should be implemented as part of the broader work to regulate AI and ADM, including the consultation being undertaken by the Department of Industry, Science and Resources. 

20. Direct marketing, targeting and trading 

20.1 Amend the Act to introduce definitions for: (a) Direct marketing – capture the collection, use or disclosure of personal information to communicate directly with an individual to promote advertising or marketing material. (b) Targeting – capture the collection, use or disclosure of information which relates to an individual including personal information, deidentified information, and unidentified information (internet history/tracking etc.) for tailoring services, content, information, advertisements or offers provided to or withheld from an individual (either on their own, or as a member of some group or class). (c) Trading – capture the disclosure of personal information for a benefit, service or advantage. 

20.2 Provide individuals with an unqualified right to opt-out of their personal information being used or disclosed for direct marketing purposes. Similar to the existing requirements under the Act, entities would still be able to collect personal information for direct marketing without consent, provided it is not sensitive information and the individual has the ability to opt out. 

20.3 Provide individuals with an unqualified right to opt-out of receiving targeted advertising. 

20.4 Introduce a requirement that an individual’s consent must be obtained to trade their personal information. 

20.5 Prohibit direct marketing to a child unless the personal information used for direct marketing was collected directly from the child and the direct marketing is in the child’s best interests. 

20.6 Prohibit targeting to a child, with an exception for targeting that is in the child’s best interests. 

20.7 Prohibit trading in the personal information of children. 

20.8 Amend the Act to introduce the following requirements: (a) Targeting individuals should be fair and reasonable in the circumstances. (b) Targeting individuals based on sensitive information (which should not extend to targeting based on political opinions, membership of a political association or membership of a trade union), should be prohibited, with an exception for socially beneficial content. 

20.9 Require entities to provide information about targeting, including clear information about the use of algorithms and profiling to recommend content to individuals. Consideration should be given to how this proposal could be streamlined alongside the consultation being undertaken by the Department of Industry, Science and Resources. 

21. Security, retention and destruction 

21.1 Amend APP 11.1 to state that ‘reasonable steps’ include technical and organisational measures.  

21.2 Include a set of baseline privacy outcomes under APP 11 and consult further with industry and government to determine these outcomes, informed by the development of the Government’s 2023-2030 Australian Cyber Security Strategy. 

21.3 Enhance the OAIC guidance in relation to APP 11 on what reasonable steps are to secure personal information. The guidance that relates to cyber security could draw on technical advice from the Australian Cyber Security Centre. 

21.4 Amend APP 11.1 so that APP entities must also take reasonable steps to protect de-identified information. 

21.5 The OAIC guidance in relation to APP 11.2 should be enhanced to provide detailed guidance that more clearly articulates what reasonable steps may be undertaken to destroy or de-identify personal information. 

21.6 The Commonwealth should undertake a review of all legal provisions that require retention of personal information to determine if the provisions appropriately balance their intended policy objectives with the privacy and cyber security risks of entities holding significant volumes of personal information. This further work could also be considered by the proposed Commonwealth, state and territory working group at Proposal 29.3 as a key issue of concern where alignment would be beneficial. However, this review should not duplicate the recent independent review of the mandatory data retention regime under the Telecommunications (Interception and Access) Act 1979 and the independent reviews and holistic reform of electronic surveillance legislative powers. 

21.7 Amend APP 11 to require APP entities to establish their own maximum and minimum retention periods in relation to the personal information they hold which take into account the type, sensitivity and purpose of that information, as well as the entity’s organisational needs and any obligations they may have under other legal frameworks. APP 11 should specify that retention periods should be periodically reviewed. Entities would still need to destroy or de-identify information that they no longer need. 

21.8 Amend APP 1.4 to stipulate than an APP entity’s privacy policy must specify its personal information retention periods. 

22. Controllers and processors of personal information 

22.1 Introduce the concepts of APP entity controllers and APP entity processors into the Act. Pending removal of the small business exemption, a non-APP entity that processes information on behalf of an APP entity controller would be brought into the scope of the Act in relation to its handling of personal information for the APP entity controller. This would be subject to further consultation with small business and an impact analysis to understand the impact on small business processors. 

23. Overseas data flows 

23.1 Consult on an additional requirement in subsection 5B(3) to demonstrate an ‘Australian link’ that is focused on personal information being connected with Australia. 

23.2 Introduce a mechanism to prescribe countries and certification schemes as providing substantially similar protection to the APPs under APP 8.2(a). 

23.3 Standard contractual clauses for use when transferring personal information overseas should be made available to APP entities. 

23.4 Strengthen the informed consent exception to APP 8.1 by requiring entities to consider the risks of an overseas disclosure and to inform individuals that privacy protections may not apply to their information if they consent to the disclosure. 

23.5 Strengthen APP 5 in relation to overseas disclosures by requiring APP entities, when specifying the countries in which recipients are likely to be located if practicable, to also specify the types of personal information that may be disclosed to recipients located overseas. 

23.6 Introduce a definition of ‘disclosure’ that is consistent with the current definition in APP Guidelines. Further consideration should be given to whether online publications of personal information should be excluded from the requirements of APP 8 where it is in the public interest. 

24. CBPR and domestic certification 

Nil proposals. 

25. Enforcement 

25.1 Create tiers of civil penalty provisions to allow for better targeted regulatory responses: (a) Introduce a new mid-tier civil penalty provision to cover interferences with privacy without a ‘serious’ element, excluding the new low-level civil penalty provision. (b) Introduce a new low-level civil penalty provision for specific administrative breaches of the Act and APPs with attached infringement notice powers for the Information Commissioner with set penalties. 

25.2 Amend section 13G of the Act to remove the word ‘repeated’ and clarify that a ‘serious’ interference with privacy may include: (a) those involving ‘sensitive information’ or other information of a sensitive nature (b) those adversely affecting large groups of individuals (c) those impacting people experiencing vulnerability (d) repeated breaches (e) wilful misconduct, and (f) serious failures to take proper steps to protect personal data. The OAIC should provide specific further guidance on the factors that they take into account when determining whether to take action under section 13G. 

25.3 Amend the Act to apply the powers in Part 3 of the Regulatory Powers (Standard Provisions) Act 2014 to investigations of civil penalty provisions in addition to the Information Commissioner’s current investigation powers. 

25.4 Amend the Act to provide the Information Commissioner with the power to undertake public inquiries and reviews into specified matters on the approval or direction of the Attorney-General. 

25.5 Amend subparagraph 52(1)(b)(ii) and paragraph 52(1A)(c) to require an APP entity to identify, mitigate and redress actual or reasonably foreseeable loss. The current provision could be amended to insert the underlined: a declaration that the respondent must perform any reasonable act or course of conduct to identify, mitigate and redress any actual or reasonably foreseeable loss or damage suffered by the complainant/those individuals. The OAIC should publish guidance on how entities could achieve this. 

Proposal 25.6 Give the Federal Court and the Federal Circuit and Family Court of Australia the power to make any order it sees fit after a civil penalty provision relating to an interference with privacy has been established. 

25.7 Further work should be done to investigate the effectiveness of an industry funding model for the OAIC. 

25.8 Further consideration should be given to establishing a contingency litigation fund to fund any costs orders against the OAIC, and an enforcement special account to fund high cost litigation. 

25.9 Amend the annual reporting requirements in AIC Act to increase transparency about the outcome of all complaints lodged including numbers dismissed under each ground of section 41. 

25.10 The OAIC should conduct a strategic internal organisational review with the objective of ensuring the OAIC is structured to have a greater enforcement focus. 

25.11 Amend subsection 41(dc) of the Act so that the Information Commissioner has the discretion not to investigate complaints where a complaint has already been adequately dealt with by an EDR scheme. 

26. A direct right of action 

26.1 Amend the Act to allow for a direct right of action in order to permit individuals to apply to the courts for relief in relation to an interference with privacy. The model should incorporate the appropriate design elements discussed in this chapter. 

27. A statutory tort for serious invasions of privacy 

27.1 Introduce a statutory tort for serious invasions of privacy in the form recommended by the ALRC in Report 123. Consult with the states and territories on implementation to ensure a consistent national approach. 

28. Notifiable data breaches scheme 

28.1 Undertake further work to better facilitate the reporting processes for notifiable data breaches to assist both the OAIC and entities with multiple reporting obligations. 

28.2 (a) Amend paragraph 26WK(2)(b) to provide that if an entity is aware that there are reasonable grounds to believe that there has been an eligible data breach of the entity, the entity must give a copy of the statement to the Commissioner as soon as practicable and not later than 72 hours after the entity becomes so aware, with an allowance for further information to be provided to the OAIC if it is not available within the 72 hours. (b) Amend subsection 26WL(3) to provide that if an entity is aware that there are reasonable grounds to believe that there has been an eligible data breach of an entity the entity must notify the individuals to whom the information relates as soon as practicable and where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases as soon as practicable. (c) Require entities to take reasonable steps to implement practices, procedures and systems to enable it to respond to a data breach. 

28.3 Amend subsections 26WK(3) and 26WR(4) to the effect that a statement about an eligible data breach must set out the steps the entity has taken or intends to take in response to the breach, including, where appropriate, steps to reduce any adverse impacts on the individuals to whom the relevant information relates. However, this proposal would not require the entity to reveal personal information, or where the harm in providing this information would outweigh the benefit in providing this information. Consider further a requirement that entities should take reasonable steps to prevent or reduce the harm that is likely to arise for individuals as a result of a data breach. 

28.4 Introduce a provision in the Privacy Act to enable the Attorney-General to permit the sharing of information with appropriate entities to reduce the risk of harm in the event of an eligible data breach. The provision would contain safeguards to ensure that only limited information could be made available for designated purposes, and for a time limited duration. 

29. Interactions with other schemes 

29.1 The Attorney-General’s Department develop a privacy law design guide to support Commonwealth agencies when developing new schemes with privacy-related obligations. 

29.2 Encourage regulators to continue to foster regulatory cooperation in enforcing matters involving mishandling of personal information. 

29.3 Establish a Commonwealth, state and territory working group to harmonise privacy laws, focusing on key issues. 

30. Further review 

30.1 Conduct a statutory review of any amendments to the Act which implement the proposals in this Report within three years of the date of commencement of those amendments.

09 February 2023

Fiduciaries

'In Code(rs) We Trust: Software Developers as Fiduciaries in Public Blockchains' by Angela Walch in Philipp Hacker, Ioannis Lianos, Georgios Dimitropoulos and Stefan Eich (eds), Regulating Blockchain. Techno-Social and Legal Challenges (Oxford University Press, 2019 comments 

This chapter addresses the myth of decentralized governance of public blockchains, arguing that certain people who create, operate, or reshape them function much like fiduciaries of those who rely on these powerful data structures. Explicating the crucial functions that leading software developers perform, the chapter compares the role to Tamar Frankel’s conception of a fiduciary, and finds much in common, as users of these technologies place extreme trust in the leading developers to be both competent and loyal (ie, to be free of conflicts of interest). The chapter then frames the cost-benefit analysis necessary to evaluate whether, on balance, it is a good idea to treat these parties as fiduciaries, and outlines key questions needed to flesh out the fiduciary categorization. For example, which software developers are influential enough to resemble fiduciaries? Are all users of a blockchain ‘entrustors’ of the fiduciaries who operate the blockchain, or only a subset of those who rely on the blockchain? Finally, the chapter concludes with reflections on the broader implications of treating software developers as fiduciaries, given the existing accountability paradigm that largely shields software developers from liability for the code they create. 

08 February 2023

TechnoFixes and EdTech

'The Technological Fix as Social Cure-All: Origins and Implications' by Sean F Johnston in (2018) 37(1) IEEE Technology and Society Magazine 47-54 comments 

In 1966, a well-connected engineer posed a provocative question: will technology solve all our social problems? He seemed to imply that it would, and soon. Even more contentiously, he hinted that engineers could eventually supplant social scientists - and perhaps even policy-makers, lawmakers, and religious leaders - as the best trouble-shooters and problem-solvers for society [1]. The engineer was the Director of Tennessee's Oak Ridge National Laboratory, Dr. Alvin Weinberg. As an active networker, essayist, and contributor to government committees on science and technology, he reached wide audiences over the following four decades. Weinberg did not invent the idea of technology as a cure-all, but he gave it a memorable name: the “technological fix.” This article unwraps his package, identifies the origins of its claims and assumptions, and explores the implications for present-day technologists and society. I will argue that, despite its radical tone, Weinberg's message echoed and clarified the views of predecessors and contemporaries, and the expectations of growing audiences. His proselytizing embedded the idea in modern culture as an enduring and seldom-questioned article of faith: technological innovation could confidently resolve any social issue. ... 

Weinberg did not invent the idea of technology as a cure-all, but he gave it a memorable name: the “technological fix.” This article unwraps his package, identifies the origins of its claims and assumptions, and explores the implications for present-day technologists and society. I will argue that, despite its radical tone, Weinberg’s message echoed and clarified the views of predecessors and contemporaries, and the expectations of growing audiences. His proselytizing embedded the idea in modern culture as an enduring and seldom-questioned article of faith: technological innovation could confidently resolve any social issue. 

Weinberg’s rhetorical question was a call-to-arms for engineers, technologists, and designers, particularly those who saw themselves as having a responsibility to improve society and human welfare. It was also aimed at institutions, offering goals and methods for government think-tanks and motivating corporate mission-statements (e.g., [3]). 

The notion of the technological fix also proved to be a good fit to consumer culture. Our attraction to technological solutions to improve daily life is a key feature of contemporary lifestyles. This allure carries with it a constellation of other beliefs and values, such as confidence in reliable innovation and progress, trust in the impact and effectiveness of new technologies, and reliance on technical experts as general problem-solvers.  

This faith can nevertheless be myopic. It may, for example, discourage adequate assessment of side-effects — both technical and social — and close examination of political and ethical implications of engineering solutions. Societal confidence in technological problem-solving consequently deserves critical and balanced attention. 

Adoption of technological approaches to solve social, political and cultural problems has been a longstanding human strategy, but is a particular feature of modern culture. The context of rapid innovation has generated widespread appreciation of the potential of technologies to improve modern life and society. The resonances in modern culture can be discerned in the ways that popular media depicted the future, and in how contemporary problems have increasingly been framed and addressed in narrow technological terms. 

While the notion of the technological fix is straightforward to explain, tracing its circulation in culture is more difficult. One way to track the currency of a concept is via phrase-usage statistics. The invention and popularity of new terms can reveal new topics and discourse. The Google N-Gram Viewer is a useful tool that analyzes a large range of published texts to determine frequency of usage over time for several languages and dialects [4], [5]. 

In American English, the phrase technological fix emerges during the 1960s and proves more enduring and popular than the less precise term technical fix. 

We can track this across languages. In German, the term technological fix has had limited usage as an untranslated English import, and is much less common than the generic phrase technische Lösung (“technical solution”), which gained ground from the 1840s. In French, too, there is no direct equivalent, but the phrase solution technique broadly parallels German and English usage over a similar time period. And in British English, the terms technological fix and technical fix appear at about the same time as American usage, but grow more slowly in popularity. Usage thus hints that there are distinct cultural contexts and meanings for these seemingly similar terms. Its varying currency suggests that the term technological fix became a cultural export popularized by Alvin Weinberg’s writings on the topic, but related to earlier discourse about technology-inspired solutions to human problems. 

Such data suggest rising precision in writing about technology as a generic solution-provider, particularly after the Second World War. But while the modern popularization and consolidation of the more specific notion of the “technological fix” can be traced substantially to the writings of Alvin Weinberg, the idea was promoted earlier in more radical form.

In 'Automating Learning Situations in EdTech: Techno-Commercial Logic of Assetisation' by Morten Hansen and Janja Komljenovic in (2023) 5 Postdigital Science and Education 100–116 the authors comment 

 Critical scholarship has already shown how automation processes may be problematic, for example, by reproducing social inequalities instead of removing them or requiring intense labour from education institutions’ staff instead of easing the workload. Despite these critiques, automated interventions in education are expanding fast and often with limited scrutiny of the technological and commercial specificities of such processes. We build on existing debates by asking: does automation of learning situations contribute to assetisation processes in EdTech, and if so, how? Drawing on document analysis and interviews with EdTech companies’ employees, we argue that automated interventions make assetisation possible. We trace their techno-commercial logic by analysing how learning situations are made tangible by constructing digital objects, and how they are automated through specific computational interventions. We identify three assetisation processes: First, the alienation of digital objects from students and staff deepens the companies’ control of digital services offering automated learning interventions. Second, engagement fetishism—i.e., treating engagement as both the goal and means of automated learning situations—valorises particular forms of automation. And finally, techno-deterministic beliefs drive investment and policy into identified forms of automation, making higher education and EdTech constituents act ‘as if’ the automation of learning is feasible. 

 Education technology (EdTech) companies are breathing new life into an old idea: education progress through automation (Watters 2021). EdTech companies are interested in portraying these processes as complex and bringing significant value to the learner and her educational institution, even when actual practices do not always reflect such imaginaries (Selwyn 2022). For example, EdTech companies may claim that artificial intelligence (AI) is a key part of their product, when in fact, actual computations are much simpler. It is therefore vital to disentangle EdTech companies’ imagined and actual automation practices. 

We propose the concept of ‘automated learning situations’ to disentangle automation imaginaries from actual practice. ‘Learning situations’ are the relationships between students, teachers, and learning artefacts in educational contexts. ‘Automated’ learning situations refer to automated interventions in one or more of these relationships. In practice, EdTech companies automate learning situations by capturing student actions on digital platforms, such as clicks, which they then use for computational intervention. For example, an EdTech platform may programmatically capture how a student engages with digital texts before computing various engagement scores or ‘nudges’ in order to affect her future behaviour. 

It is useful to conceptualise such automation as techno-material relations mapped along two dimensions: digital objects and computing approaches. While current literature on EdTech platforms has already uncovered how platformisation reconfigures pedagogical autonomy, educational governance, infrastructural control, multisided markets, and much more (e.g. Kerssens and Van Dijck 2022; Napier and Orrick 2022; Nichols and Garcia 2022; Williamson et al. 2022), the two dimensions bring more conceptual clarity to the technological possibilities and limitations of actually existing automation practices. Furthermore, they allow us to unpack techno-commercial relationships between emergent automation and assetisation processes. 

EdTech is embedded in the broader digital economy, which is increasingly rentier (Christophers 2020). This means that there is a move from creating value via production and selling commodities in the market, to extracting value through the control of access to assets (Mazzucato 2019). Assetisation is the process of turning things into assets (Muniesa et al. 2017). Depending on the situation, different things and processes can be assetised in different ways (Birch and Muniesa 2020). This includes taking products and services previously treated as commodities—something that can be owned through purchase and consequently fully controlled—and transforming them into something that can only be accessed through payment without change in ownership (Christophers 2020). A useful example is accessing textbooks in a digital form by paying a subscription to a provider such as Pearson +, instead of purchasing and owning physical book copies. Assetising a medium of delivery changes the implications for the user. For example, when customers buy a book, they own the material object but not the intellectual property (IP) rights. With the ownership of the book itself, i.e., the physical object, comes a measure of control: they can read the textbook as many times and whenever they want, write in the book, highlight passages, sell it to someone else, use it for some other purpose entirely, or even destroy it. On the contrary, paying a fee for accessing the electronic book via a platform transforms how users can engage with the content because the platform owner holds the control and follow-through rights (cf. Birch 2018): they decide when books are added and removed, what users can do with the book and for how long, and—crucially—what happens to associated user data. Generating revenue from a thing while maintaining ownership, control, and follow-through rights is an indication that this thing has been turned into an asset for its owner. We, therefore, ask: does the automation of learning situations contribute to assetisation processes in EdTech, and if so, how? 

In what follows, we first present our conceptual and methodological approach. We then unpack the digital objects used to construct learning situations. Next, we discuss how interventions are automated differently depending on computing temporalities and complexities. We conclude by discussing three assetisation processes identified in the automation of learning situations: the alienation of digital objects from students and staff, the fetishisation of engagement, and techno-deterministic beliefs leading to acting ‘as if’ automation is feasible.

07 February 2023

AI, Regulation and Trust

Orly Lobel's 'The Law of AI for Good' (San Diego Legal Studies Paper No. 23-001) comments 

Legal policy and scholarship are increasingly focused on regulating technology to safeguard against risks and harms, neglecting the ways in which the law should direct the use of new technology, and in particular artificial intelligence (AI), for positive purposes. This article pivots the debates about automation, finding that the focus on AI wrongs is descriptively inaccurate, undermining a balanced analysis of the benefits, potential, and risks involved in digital technology. Further, the focus on AI wrongs is normatively and prescriptively flawed, narrowing and distorting the law reforms currently dominating tech policy debates. The law-of-AI-wrongs focuses on reactive and defensive solutions to potential problems while obscuring the need to proactively direct and govern increasingly automated and datafied markets and societies. Analyzing a new Federal Trade Commission (FTC) report, the Biden administration’s 2022 AI Bill of Rights and American and European legislative reform efforts, including the Algorithmic Accountability Act of 2022, the Data Privacy and Protection Act of 2022, the European General Data Protection Regulation (GDPR) and the new draft EU AI Act, the article finds that governments are developing regulatory strategies that almost exclusively address the risks of AI while paying short shrift to its benefits. The policy focus on risks of digital technology is pervaded by logical fallacies and faulty assumptions, failing to evaluate AI in comparison to human decision-making and the status quo. The article presents a shift from the prevailing absolutist approach to one of comparative cost-benefit. The role of public policy should be to oversee digital advancements, verify capabilities, and scale and build public trust in the most promising technologies. 

A more balanced regulatory approach to AI also illuminates tensions between current AI policies. Because AI requires better, more representative data, the right to privacy can conflict with the right to fair, unbiased, and accurate algorithmic decision-making. This article argues that the dominant policy frameworks regulating AI risks—emphasizing the right to human decision-making (human-in-the-loop) and the right to privacy (data minimization)—must be complemented with new corollary rights and duties: a right to automated decision-making (human-out-of-the-loop) and a right to complete and connected datasets (data maximization). Moreover, a shift to proactive governance of AI reveals the necessity for behavioral research on how to establish not only trustworthy AI, but also human rationality and trust in AI. Ironically, many of the legal protections currently proposed conflict with existing behavioral insights on human-machine trust. The article presents a blueprint for policymakers to engage in the deliberate study of how irrational aversion to automation can be mitigated through education, private-public governance, and smart policy design.

'Trustworthy artificial intelligence and the European Union AI act: On the conflation of trustworthiness and acceptability of risk' by Johann Laux, Sandra Wachter and Brent Mittelstadt in (2023) Regulation and Governance comments 

The global race to establish technological leadership in artificial intelligence (AI) is escorted by an effort to develop “trustworthy AI.” Numerous policy frameworks and regulatory proposals make principled suggestions as to which features render AI “trustworthy” [Cf. the overviews in Lucia Vesnic-Alujevic et al., 2020 and Thiebes et al., 2021], Private companies such as auditing firms are offering their clients support in designing and deploying “trustworthy AI” (Mökander & Floridi, 2021). The emphasis on trustworthiness serves a strategic purpose: induce people to place trust in AI so that they will use it more and, hence, unlock the technology's economic and social potential. 

This strategy is not unfounded. Trust cannot be created on command. Signaling trustworthiness is thus the most promising option for regulators and technologists who seek to create the initial trust needed for a broader uptake of AI (Drake et al., 2021; O'Neill, 2012). Success, however, is not guaranteed. Even allegedly trustworthy persons, institutions, and technologies might not be trusted after all. For example, populations which have historically faced discrimination may reasonably distrust broadly accepted signals of trustworthiness (Scheman, 2020). 

As part of the global trustworthiness effort, the European Commission recently proposed a legal framework for trustworthy AI, the “AI Act” (European Commission, 2021b). The AI Act explicitly pursues the dual purpose of promoting the uptake of the technology and addressing the risks associated with its use (AI Act, Recital 81 and p. 1). At the time of writing, the proposal is being discussed by the Council of the European Union and the European Parliament, both of which must agree on a common text before the AI Act can pass into law. 

As this article will show, in its proposal the Commission chose to understand “trustworthiness” narrowly in terms of the “acceptability” of AI's risks, with the latter being primarily assessed through conformity assessments carried out by technology experts (see Section 2.1). This regulatory conflation of trustworthiness with the acceptability of risks invites further reflection. 

Based on a systematic narrative literature review on trust research, this article argues that the European Union (EU) is overselling its regulatory ambition and oversimplifying a highly complex and heterogeneous set of closely related concepts. First, while there is an inherent relationship between trust, trustworthiness, and the perceived acceptability of risks (Poortinga & Pidgeon, 2005), the AI Act will itself require citizens' trust to succeed in promoting the uptake of AI. Second, the concept of trustworthiness serves an important normative function. It allows to assess whether people's actual levels of trust are normatively “justified” (Cf. Lee, 2022) or “well-placed.” This justification depends on whether their degree of trust in something matches its degree of trustworthiness. A person's trust can be “blind” or misplaced; so too can their mistrust. There is a rich philosophical debate as to whether AI even has the capacity of being a genuine object of trust. Its lack of human qualities such as intentionality could prohibit such attributions. AI may then be merely reliable, but not trustable [Miller & Freiman, 2020; for the debate, see further Rieder et al. (2021), Weydner-Volkmann and Feiten (2021), Ryan (2020), Grodzinsky et al. (2020), Nickel et al. (2010), and Taddeo (2009)]. 

Conflating trust and trustworthiness with the acceptability of risks blurs the distinction between acceptability judgments made by domain experts and the trustworthiness of AI systems implemented in society. Others have criticized before that the AI Act outsources decisions about which risks are “acceptable” to AI providers with an economic interest to market the AI system (Smuha et al., 2021). Rather than providing a seal of approval, we argue that trustworthiness is a longitudinal concept that necessitates an iterative process of controls, communication, and accountability to establish and maintain its existence across both AI technologies and the institutions using them. The AI Act suggests an unfounded bright-line distinction between acceptable and unacceptable risks and hence trustworthy and non-trustworthy AI. This approach is incompatible with the conceptualization of trustworthiness as a longitudinal process as opposed to a binary characteristic of systems and the risks they pose. This article therefore aims to provide an intervention into the EU's policy effort to develop “trustworthy AI” by risk regulation based on a review of the multi-disciplinary literature on trust. Instead of working out a coherent theory of trust, it aims to demonstrate the conceptual futility of labeling a complex AI system “trustworthy” prior to placing it on the market. 

We limit our analysis to the use of AI in public institutions. The potential of AI for the public sector is rapidly gaining interest (Gesk & Leyer, 2022; see also de Sousa et al., 2019). AI systems have already been introduced in public institutions (Desouza et al., 2017), with promises of higher quality services and increased efficiency (Sun & Medaglia, 2019). At the same time, AI's characteristics have led to considerable debate about whether and how the public sector should deploy the technology (Green, 2022). Many AI systems “reason by association”: they detect statistical patterns in data but do not offer causal explanations (Bishop, 2021). In addition, an AI system might include so many parameters that its outcome is opaque, resembling a “black box.” There is too much information to interpret its outcome clearly (Dignum, 2019). These features arguably set AI systems aside from other digital technologies already in use by public institutions. 

Through the proposed AI Act and other instruments, the European Commission nevertheless seeks to “make the public sector a trailblazer for using AI” (European Commission, 2021a). Its 2020 “White Paper” on AI (European Commission, 2020) holds it “essential” that the public sector, especially in healthcare and transport, begins to “rapidly” deploy products and services that rely on AI (White Paper, p. 8). The European Commission also supports the uptake of AI in the domain of justice (European Commission, 2018). 

While making AI trustworthy has garnered substantial political momentum, equal attention needs to be paid to AI's potential to erode the trustworthiness of public institutions and, with it, their own ability to produce trust in the population (Bodó, 2021). Without trust, the public sector risks losing support and compliance by citizens. 

Some publicly documented uses of automated decision-systems have led to widespread criticism and the cessation of operations. Consider, for example, the algorithmic prediction of social welfare fraud in marginalized neighborhoods in the Netherlands or the algorithmic profiling of families for early detection of vulnerable children in Denmark (Kayser-Bril, 2020; Vervloesem, 2020). AI in the public sector can quickly become politicized, not least because of the public sector's dual role. It is at the same time drawn to using AI to increase its efficiency and under an obligation to protect citizens from harm caused by AI (Kuziemski & Misuraca, 2020). 

Citizens' concerns about AI in the public sector have likewise been identified as one of the major obstacles to broader implementation (Gesk & Leyer, 2022, pp. 1–2). However, while the use of (non-AI-based) information and communication technology in the public sector has been widely researched—often under the rubric of “eGovernment”—the use of AI in the public sector and its acceptance by citizens is still understudied [Gesk & Leyer, 2022; drawing on Sun and Medaglia (2019); Wang and Liao (2008)]. At the same time, insights gained from the private sector cannot easily be transferred to the public sector, not least because the latter's target is not to maximize profits generated from customers [See the references in Gesk and Leyer (2022, p. 1)]. Moreover, public services' adoption of AI further differs from the private sector as it can have a coercive element. Citizens will often have no choice but to use and pay for the services (through taxes or insurance premiums) whether or not they prefer an AI system to be involved (Aoki, 2021). As the coercive power of public authority requires justification (Simmons, 1999), AI in the public sector thus also raises questions of legitimacy. 

Politicization can add further justificatory pressure. Trust researchers consider how in highly politicized contexts of AI implementation, conflicts about what constitutes a “right” or “fair” decision are likely to erupt (de Bruijn et al., 2022; drawing on Bannister & Connolly, 2011b). The stakes of implementing AI in public services are thus high, invoking the foundational concepts of trust in and legitimacy of public authority. 

This article proceeds as follows. Section 2 begins with a trust-theoretical reconstruction of the conflation of “trustworthiness” with the “acceptability of risks” in the EU's AI policy. We then turn to our review of the literature on trust in AI implemented within public institutions. One simple definition of “trust” is the willingness of one party to expose themselves to a position of vulnerability towards a second party under conditions of risk and uncertainty as regards the intentions of that second party (similarly, Bannister & Connolly, 2011b, p. 139). However, the term “trust” has found multiple definitions within and across social science disciplines, so much that the state of defining trust has been labeled as one of “conceptual confusion” (McKnight & Chervany, 2001). This makes comparing and evaluating trust research across disciplines (and sometimes even within one discipline) extremely difficult. 

Section 3, therefore, develops a prescriptive set of variables for reviewing trust-research in the context of AI. We differentiate between normative and empirical research as well as between subject, objects, and roles of trust. Section 4 then uses those variables as a structure for a narrative review of prior research on trust and trustworthiness in AI in the public sector. We identify common themes in the reviewed literature and reflect on the heterogeneity of the field and, thus, the many ways in which trust in AI can be defined, measured, incentivized, and governed. 

This article concludes in Sections 5 and 6 by relating the findings of the literature review to the EU's AI policy and especially its proposed AI Act. It states the uncertain prospects for the AI Act to be successful in engineering citizens' trust. There remains a threat of misalignment between levels of actual trust and the trustworthiness of applied AI. The conflation of “trustworthiness” with the “acceptability of risks” in the AI Act will thus be shown to be inadequate.

Privacy

'Distinguishing Privacy Law: A Critique of Privacy as Social Taxonomy' by María P Angel and Ryan Calo comments 

What distinguishes violations of privacy from other harms? This has proven a surprisingly difficult question to answer. For over a century, privacy law scholars labored to define the illusive concept of privacy. Then they gave up. Efforts at distinguishing privacy came to be superseded at the turn of the millennium by a new approach: a taxonomy of privacy problems grounded in social recognition. Privacy law became the field that simply studies whatever courts or scholars talk about as related to privacy. 

And it worked. Decades into privacy as social taxonomy, the field has expanded to encompass a broad range of information-based harms—from consumer manipulation to algorithmic bias—generating many, rich insights. Yet the approach has come at a cost. This article diagnoses the pathologies of a field that has abandoned defining its core subject matter, and offers a research agenda for privacy in the aftermath of social recognition. 

This critique is overdue: it is past time to think anew about exactly what work the concept of privacy is doing in a complex information environment, and why a given societal problem—from discrimination to misinformation—is worthy of study under a privacy framework. Only then can privacy scholars articulate what we are expert in and participate meaningfully in global policy discussions about how to govern information-based harms.

Theory

'How to do things with legal theory' by Coel Kirkby in (2022) 18(4) International Journal of Law in Context 373-382 comments 

Legal theory must not merely describe our world; it must also assist us acting in it. In this paper, I argue that teaching legal theory should show law students how to do things with legal theory. My pedagogical approach is contextual and historical. Students learn how to use theory by seeing how past jurists acted in their particular worlds by changing dominant concepts of law. Most introductory legal theory courses are organised by what I will call the usual story of jurisprudence. In this story, great thinkers in rival schools of legal thought attempt to answer perennial questions about the nature of (the concept of) law. In this story, the thick context of our world recedes beyond the horizon of theory. I argue that critical genealogy can let us critique this usual story and its unspoken assumptions of morality, politics and history. Amia Srinivasan's account of ‘worldmaking’ is especially compelling in its emphasis on critical genealogies’ capacity to transform our representational practices (and thus open up new possibilities for action). Critical genealogy also has certain pedagogical ‘uses and advantages’ for teaching legal theory in law schools. Here, context is method. The teacher must defend their political choices of context – choices that are naturalised and so beyond critique in the usual story of jurisprudence. By making these choices explicit, students are invited to both challenge the teacher's choices of context and critique their own common law education. This pedagogical approach also encourages students to experiment in ‘worldmaking’ themselves, and so cultivate a creative capacity to use legal theory to change the world through transforming their representations of it. 

Legal theory must not merely describe our world; it must also assist us acting in it. In this paper, I will argue that legal pedagogy should teach law students how to do things with legal theory. My concern is with action rather than description. Most introductory legal theory courses are organised by what I will call the usual story of jurisprudence. In this story, great thinkers in rival schools of legal thought attempt to answer perennial questions about the nature of law. In this story, the thick context of our world recedes beyond the horizon of theory. I argue that critical genealogy can let us critique this usual story and its unspoken assumptions of morality, politics and history. Amia Srinivasan provides an especially compelling account of critical genealogy as ‘worldmaking’. Her reading emphasises its capacity to transform our representational practices (and thus open up new possibilities for action) rather than its potential for epistemic shock. 

Critical genealogy also has certain pedagogical uses and advantages for teaching legal theory in law schools. Here, context is method. Teachers must defend their political choices of context – choices that are naturalised and so beyond critique in the usual story of jurisprudence. By making these choices explicit, students are invited to both challenge the teacher's choices of context and critique their own common law education. Since the choices of context are an open-ended multiplicity, this pedagogical approach also encourages students to practise ‘worldmaking’ themselves through reflective and research essays that start with critical self-reflection on their own particular standpoint and concerns in the present. Ideally, teaching jurisprudence through critical genealogy is a collaborative experiment in which the politics of context helps cultivate a creative capacity to change the world through transforming our representations of it.