16 September 2013

Deconstructing Big Data

The crisp 'Three Paradoxes of Big Data' by Neil M. Richards and Jonathan H. King in (2013) 66 Stanford Law Review Online 41 comments that
Big data is all the rage. Its proponents tout the use of sophisticated analytics to mine large data sets for insight as the solution to many of our society’s problems. These big data evangelists insist that data-driven decisionmaking can now give us better predictions in areas ranging from college admissions to dating to hiring to medicine to national security and crime prevention. But much of the rhetoric of big data contains no meaningful analysis of its potential perils, only the promise.
We don’t deny that big data holds substantial potential for the future, and that large dataset analysis has important uses today. But we would like to sound a cautionary note and pause to consider big data’s potential more critically. In particular, we want to highlight three paradoxes in the current rhetoric about big data to help move us toward a more complete understanding of the big data picture.
First, while big data pervasively collects all manner of private information, the operations of big data itself are almost entirely shrouded in legal and commercial secrecy. We call this the Transparency Paradox.
Second, though big data evangelists talk in terms of miraculous outcomes, this rhetoric ignores the fact that big data seeks to identify at the expense of individual and collective identity. We call this the Identity Paradox.
And third, the rhetoric of big data is characterized by its power to transform society, but big data has power effects of its own, which privilege large government and corporate entities at the expense of ordinary individuals. We call this the Power Paradox.
Recognizing the paradoxes of big data, which show its perils alongside its potential, will help us to better understand this revolution. It may also allow us to craft solutions to produce a revolution that will be as good as its evangelists predict.

Zooveillance

'Animal Mobilegalities: The Regulation of Animal Movement in the American City' by Irus Braverman in (2013) 5(1) Humanimalia 104 comments that
The initial focus of “animobility” scholarship has been on the dynamic physical geographies of animals. This article extends the meaning of animobility to explore the ways in which animals are affected — and, in fact, constituted — by law, as well as the ways in which they affect and constitute law, which I call “mobilegalities.” Specifically, I ask how animobility in contemporary American cities translates into the animals’ legal mobility, and how laws can adapt to animobility and the ensuing mobilegality by setting “traps” that then immobilize the animals. This article demonstrates, finally, that law is not a static narrative that produces monophonic meaning, but a living process that feeds on, and depends upon, dynamic human-nonhuman assemblages. The different modes of classification discussed here — body, taxonomy, and law — provide a yardstick by which to think of the rigidity and flexibility of mobilegality itself, constituting a matrix for the mobilization of legality.
Braverman argues that
Humans purposefully bring certain animals into the city where they care for them: dogs and cats in the home, chickens and goats in the yard, and elephants and tigers in the zoo. Some animals escape their designated spaces and survive in the city to breed, such as monk parakeets in New York. Humans living in cities also intentionally create habitats for certain animals: hummingbirds, ospreys, trout, and bass. Still other animals — bedbugs, pigeons, Norway rats, gulls, squirrels, and Canadian geese, to name a few — come to the city uninvited and thrive in the urban habitat. The large mass of nonhuman animals in cities constitutes what is referred to in animal studies literature as a “shadow population” or a “subaltern animal town” (Wolch, West, and Gaines 736).
Whereas a large and growing literature is dedicated to studying the regulation and the policing of human populations in the city, not much has been written about the regulation and policing of animals in this space. Animal studies in contemporary urban theory are also quite rare (Lorimer; Wolch, West, and Gaines 735). This article contributes to the growing fascination with animals in the city by discussing the following questions: How are urban animals classified by animal laws? Which urban animals are protected, and which are unprotected, by law? And, finally, how do humans and animals work with and around the various legal classifications? While many of the animal classifications discussed in this article are not limited to cities — and, in fact, some are even defined by their occurrence outside cities — I have chosen to focus on legal classification in urban spaces because the condensed human-animal relationship in the contemporary city results in more frequent clashes between various human-animal trajectories than it does in less human-populated areas.
Legal norms are often premised on assumptions about human agency. Accordingly, the modern project of policing animals in the city does not target animals directly. Rather, it is performed through the regulation of humans. In this sense, the story of policing animals in modern time is inevitably a story about policing humans. I use the term “zooveillance,” in my article “Foucault Goes to the Zoo,” which may be useful in this context. There, I argue that traditional definitions of surveillance should expand beyond human animals to encompass nonhuman animals and inanimate things. Zooveillance — or the regulation of “bio” and “zoe” — conveys certain aspects of governing humans that are less visible otherwise. This article considers the conflicting interests that arise through the policing of humans who attempt to bring chickens back into cities, practice religious beliefs through animal sacrifice, or keep non-traditional pets such as the potbellied pig.
Furthermore, this article demonstrates that animals, too, practice some form of agency — referred to by Bruno Latour as “actancy,” the diversity of which is fully deployed without having to sort in advance the ‘true’ agencies from the ‘false’ ones” (55) — and that, at the very least, animals affect laws by their physical mobilities, or what Mike Michael refers to, in his piece “Roadkill,” as “animobilities” (279; See also Philo and Wilbert; Wolch and Emel 1998). Accordingly, wild or feral animals move about in trajectories that often bring them into zones of human settlement, where they encounter humans who move along their own trajectories. The initial focus of “animobility” scholarship has been on the physical geographies of animals. This article extends the meaning of animobility to explore the ways in which animals are affected — and, in fact, constituted — by law, as well as the ways in which they affect and constitute law. Specifically, I ask how animobility in contemporary American cities translates into the animals’ legal mobility, and how laws can adapt to animobility and the ensuing mobilegality by setting “traps” that then immobilize the animals. This article demonstrates, finally, that law is not a static narrative that produces monophonic meaning, but a living process that feeds on, and depends upon, dynamic humannonhuman assemblages. The different modes of classification discussed here — body, taxonomy, and law — provide a yardstick by which to think of the rigidity and flexibility of mobilegality itself, constituting a matrix for the mobilization of legality.
Structurally, I begin by introducing Michael’s term “animobilities,” its uses in animal studies scholarship, and my extension of this term to include animal law. Second, I present and discuss the central technology by which law governs animobility: classification. I contemplate the project of legal classification in general and the dominant legal paradigm of animal classification — the protection of animals — in particular. Third, I explore specific animal classifications: wildlife, pests, companion animals, and livestock. In each category, I discuss instances of reordering and reclassification so as to demonstrate the inherent messiness and fluidity of animal regulations. Fourth and finally, I explore the interrelations between law and animobility by studying particular classifications as these are enacted and enforced in Buffalo, New York. Throughout, I study the interrelations between “animobility” — the animal’s physical agency through movement — and the animal’s legal mobility: its mobilegality.
Braverman concludes
Animal studies scholars speak about “animobility” to express the independent physical trajectories of animals that do not always coincide with those of humans. My article contributes to this scholarship by highlighting an additional dimension of animal-human relations in the city: law. Although many perceive law as static and fixed — and its effects on human-animal relations as similarly stagnating — I have offered a more nuanced account of how animal laws work. The article first explored law’s prominent technology — classification — and its construction as a combination of science and various levels of human protection. Next, the article provided anecdotal references from four central legal animal categories (wild, pest, pet, and farm animals) and from a variety of animals (dogs, coyotes, goldfish, potbellied pigs, roosters, and skunks) to demonstrate how laws are both triggered and bound by the shifting materialities of animal-human relationships, as much as they also bind and enable these materialities in the first place. These relationships are constantly in flux, as the various factors illuminated by this article — taxonomy, law, time-space, and materiality — constantly shift. To complicate matters, this article also conceived law as a multi-sited and plural regime that encompasses official state norms, religious traditions, and enforcement practices.
Alongside the dynamic elements of law, its mobilegality, law’s classificatory regime is at the same time quite rigid and static. Indeed, law constantly pigeonholes animals into fixed classifications. Moreover, a considerable effort goes into keeping animals confined within such classificatory domains. Operating this way, law often traps animobilities. The prohibitions from keeping wild and farm animals as pets, and those that prohibit treating pets as pests or pests as pets—all point to the desire of lawmakers to keep animals under the tight controls and within the confines of their classifications so as to keep cities safe, sanitized, and free of animal nuisances. At the same time, animals and humans also express their own mobilities, transgressing and challenging their legal classifications and forcing lawmakers and enforcers to adapt or develop new legal traps. Finally, mobilegalities are themselves constrained — by their own taxonomic and legal heritage, by technological limitations, and by human and nonhuman biological capacities.

Aid, Rights and Surveillance

The 34 page 'Aiding Surveillance: An Exploration of How Development and Humanitarian Aid Initiatives are Enabling Surveillance in Developing Countries' by Gus Hosein and Carly Nyst argues that
Information technology transfer is increasingly a crucial element of development and humanitarian aid initiatives. Social protection programmes are incorporating digitized Management Information Systems and electronic transfers, registration and electoral systems are deploying biometric technologies, the proliferation of mobile phones is facilitating access to increased amounts of data, and technologies are being transferred to support security and rule of law efforts. Many of these programmes and technologies involve the surveillance of individuals, groups, and entire populations. The collection and use of personal information in these development and aid initiatives is without precedent, and subject to few legal safeguards. In this report we show that as development and humanitarian donors and agencies rush to adopt new technologies that facilitate surveillance, they may be creating and supporting systems that pose serious threats to individuals’ human rights, particularly their right to privacy. 
The authors comment that
The deployment of surveillance technologies by development actors, foreign aid donors and humanitarian organisations is conducted in the complete absence of any public debate or deliberation. The development discourse rarely considers public opinion of the target populations when approving aid programmes. Even the availability of countervailing perspectives is surprisingly low. Seminal strategy documents like the UN Office for Humanitarian Affairs’ Humanitarianism in a Networked Age or the UN High-Level Panel on the Post-­2015 Development Agenda’s A New Global Partnership: Eradicate Poverty and Transfer Economies through Sustainable Development, pay scant attention to the potential impact of the adoption of new technologies or data analysis techniques on individuals’ privacy.
In sum, there are four major problems arising from the increased use of development aid to advance surveillance in developing countries. First, technologies are being deployed that raise significant concerns with regards to privacy and other human rights. Second, such technologies may not necessarily be appropriate for achieving development goals or may have undesirable side effects. Third, these technologies are already seen as legally and technologically problematic in more developed countries. Fourth, these technologies are deployed in the absence of relevant and adequate legal frameworks, in contravention to international human rights and national constitutional requirements. Too often these are the missing dynamics in modern development discourse around the deployment of technological solutions.
They conclude -
The recent landmark UN report, Humanitarian in a Networked Age, recommended that organisations should protect individuals through the adoption of “Do No Harm” standards for the ethical use of new forms of data, including protocols for protecting privacy, and develop frameworks to hold practitioners responsible for adherence to ethical and technical standards.
It is the contention of this paper that a far more active approach is needed to ensure that the adoption of new technologies in development and humanitarian initiatives do not imperil, but rather promote, the human rights of those they purport to benefit.
The cases and examples presented in this report show that technologies are indeed a key component of modern development and humanitarian policies and programmes, and will continue to inform development policy as technologies improve and enable development actors to not only be more effective but also to monitor and assess their own effectiveness. With increased pressures on aid agencies to improve their monitoring and evaluations and to ensure the efficient disbursement of aid funds, there will be ever increasing pressure to collect data and replace expensive human resources with cheaper technological solutions. Yet it is also clear from this review that increasingly the technologies and techniques adopted by bilateral donors and international funding agencies are often supporting surveillance and undermining individual liberties. They are achieving development at the cost of human rights, particularly the right to privacy and protection of personal information.
The technologies identified in this report not only facilitate surveillance far beyond that which would be acceptable and lawful in more developed countries, but they do so in contexts in which adequate legal safeguards are all but absent. Introducing technologies to solve complex social problems in resource-­poor environments without strong democratic institutions is thus an exercise fraught with new types of risks.
It is essential that the development and humanitarian community has informed and realistic debates about whether a technological system should be developed, and deployed in a particular context. This debate is not about anti-­technology. Technologies undoubtedly have the potential to dramatically improve the provision of development and humanitarian aid and to empower populations. The expectations that are placed on technologies to solve problems, however, need to be significantly circumscribed, and the potential negative implications of technologies considered. Biometric identification systems, for example, may assist in aid disbursement, but if they also wrongly exclude whole categories of people, then the objectives of the original development intervention have not been achieved. Border surveillance and communications surveillance systems may help a government improve national security, but are equally likely to enable the surveillance of human rights defenders, political, immigrants, and other groups.
Beyond an ethical debate about whether surveillance technologies should or should not be employed, there are extensive legal debates about the compatibility of such technologies programmes with national, regional and international human rights instruments.
Privacy is of course recognized at both the international and regional levels as a fundamental human right. The right to privacy is enshrined by the Universal Declaration of Human Rights (Art. 12), the International Covenant on Civil and Political Rights (art. 17); the International Convention on the Protection of All Migrant Workers and Members of Their Families (art. 14); and the Convention on the Rights of the Child (art. 16). At regional level privacy is protected by the African Charter on Rights of the Child (art. 10), the American Convention on Human Rights (art. 11), the Arab Charter on Human Rights (art.17). The recently adopted ASEAN Human Rights Declaration also explicitly applies the right to privacy to personal data (Art. 21). Many more countries have legislation providing for data protection: at last count there are at least 100 countries with data protection laws.
Importantly, the vast majority of developing countries also have explicit constitutional requirements to ensure that their policies and practices do not unnecessarily interfere with privacy. In fact, only five Medium and Low Human Development Index countries do not have explicit mentions of privacy in their constitutions (Cameroon, Comoros, India, Indonesia, and Samoa).
The benefits of development and humanitarian assistance can be delivered without surveillance. The choice between privacy and development creates a false dichotomy and spurs over-­simplified arguments about the role of technology. The discussion reveals no nuance, no consideration of the values and priorities tied up in privacy and development, no reference to the potentials of technology or the changing nature of threats and security, and no indication of the other choices that exist. The challenge is to improve access to and understanding of technologies, ensure that policy makers and the laws they adopt respond to the challenges and potentialities of technology, and generate greater public debate to ensure that rights and freedoms are negotiated at a societal level. Technologies can be built to satisfy both objectives.
Even if privacy was deemed to be secondary to the building of effective, modern and secure States, and to the provision of basic aid, the moral question still arises: if the purpose of development is to empower those in developing countries to have access to the same rights and capabilities as those in the developed world, and if the transfer of knowledge and technology is essential to that, then why diminish those very same people by granting them lesser human rights protections? If privacy and the protection of personal information are essential as constitutional and human rights protections in developed societies, this must also be true in developing countries.

Consumer Privacy Reviews and Anonymisation

Ethics review committees for consumer research? 'Consumer Subject Review Boards: A Thought Experiment' by Ryan Calo in (2013) 66 Stanford Law Review Online comments [PDF] that
The adequacy of consumer privacy law in America is a constant topic of debate. The majority position is that United States privacy law is a “patch-work,” that the dominant model of notice and choice has broken down, and that decades of self-regulation have left the fox in charge of the henhouse. 
A minority position chronicles the sometimes surprising efficacy of our current legal infrastructure. Peter Swire describes how a much-maligned disclosure law improved financial privacy not by informing consumers, but by forcing firms to take stock of their data practices. Deirdre Mulligan and Kenneth Bamberger argue, in part, that the emergence of the privacy professional has translated into better privacy on the ground than what you see on the books. 
There is merit to each view. But the challenges posed by big data to consumer protection feel different. They seem to gesture beyond privacy’s foundations or buzzwords, beyond “fair information practice principles” or “privacy by design.” The challenges of big data may take us outside of privacy altogether into a more basic discussion of the ethics of information. The good news is that the scientific community has been heading down this road for thirty years. I explore a version of their approach here. 
Part I discusses why corporations study consumers so closely, and what harm may come of the resulting asymmetry of information and control. Part II explores how established ethical principles governing biomedical and behavioral science might interact with consumer privacy.
Calo goes on to comment that
People have experimented on one another for hundreds of years. America and Europe of the twentieth century saw some particularly horrible abuses. In the 1970s, the U.S. Department of Health, Education, and Welfare commissioned twelve individuals, including two law professors, to study the ethics of biomedical and behavioral science and issue detailed recommendations. The resulting Belmont Report — so named after an intensive workshop at the Smithsonian Institute’s Belmont Conference Center — is a statement of principles that aims to assist researchers in resolving ethical problems around human-subject research.
The Report emphasizes informed consent — already a mainstay of consumer privacy law.In recognition of the power dynamic between experimenter and subject, however, the Report highlights additional principles of “beneficence” and “justice.” Beneficence refers to minimizing harm to the subject and society while maximizing benefit — a kind of ethical Learned Hand Formula. Justice prohibits unfairness in distribution, defined as the undue imposition of a burden or withholding of a benefit. The Department of Health, Education, and Welfare published the Belmont Report verbatim in the Federal Register and expressly adopted its principles as a statement of Department policy.
Today, any academic researcher who would conduct experiments involving people is obligated to comply with robust ethical principles and guidelines for the protection of human subjects, even if the purpose of the experiment is to benefit those people or society. The researcher must justify her study in advance to an institutional, human subject review board (IRB) comprised of peers and structured according to specific federal regulations.But a private company that would conduct experiments involving thousands of consumers using the same basic techniques, facilities, and personnel faces no such obliga- tions, even where the purpose is to profit at the expense of the research subject.
Subjecting companies to the strictures of the Belmont Report and academic institutional review would not be appropriate. Firms must operate at speed and scale, protect trade secrets, and satisfy investors. Their motivations, cultures, and responsibilities differ from one another, let alone universities. And that is setting aside the many criticisms of IRBs in their original context as plodding or skewed. till, companies interested in staying clear of scandal, lawsuit, and regulatory action could stand to take a page from biomedical and behavioral science.
The thought experiment is simple enough: the Federal Trade Commission, Department of Commerce, or industry itself commissions an interdisciplinary report on the ethics of consumer research. The report is thoroughly vetted by key stakeholders at an intensive conference in neutral territory (say, the University of Washington). As with the Belmont Report, the emphasis is on the big picture, not any particular practice, effort, or technology. The articulation of principles is incorporated in its entirety in the Federal Register or an equivalent. In addition, each company that conducts consumer research at scale creates a small internal committee comprised of employees with diverse training (law, engineering) and operated according to predetermined rules. Initiatives clearly intended to benefit consumers could be fast-tracked whereas, say, an investigation of how long moviegoers will sit through commercials before demanding a refund will be flagged for further review.
The result would not be IRBs applying the Belmont Report. I suspect Consumer Subject Review Boards (CSRBs) would be radically different. I am not naïve enough to doubt that any such effort would be rife with opportunities to pervert and game the system. But the very process of systematically thinking through ethical consumer research and practice, coupled with a set of principles and bylaws that help guide evaluation, should enhance the salutary dynamics proposed by Mulligan, Bamberger, Swire, and others.
Industry could see as great a benefit as consumers. First, a CSRB could help unearth and head off media fiascos before they materialize. No company wants to be the subject of an article in a leading newspaper with the title How Companies Learn Your Secrets. Formalizing the review of new initiatives involving consumer data could help policy managers address risk. Second, CSRBs could increase regulatory certainty, perhaps forming the basis for an FTC safe harbor if sufficiently robust and transparent. Third, and most importantly, CSRBs could add a measure of legitimacy to the study of consumers for profit. Any consumer that is paying attention should feel like a guinea pig, running blindly through the maze of the market. And guinea pigs benefit from guidelines for ethical conduct. 
I offer CSRBs as a thought experiment, not a panacea. The accelerating asymmetries between firms and consumers must be domesticated, and the tools we have today feel ill suited. We need to look at alternatives. No stone, particular one as old and solid as research ethics, should go unturned.
'Privacy and Data-Based Research' by Ori Heffetz and Katrina Ligett offers a perspective on big data and deanonymisation, asking 
What can we, as users of microdata, formally guarantee to the individuals (or firms) in our dataset, regarding their privacy? We retell a few stories, well-known in data-privacy circles, of failed anonymization attempts in publicly released datasets. We then provide a mostly informal introduction to several ideas from the literature on differential privacy, an active literature in computer science that studies formal approaches to preserving the privacy of individuals in statistical databases. We apply some of its insights to situations routinely faced by applied economists, emphasizing big-data contexts.
The authors conclude
Privacy concerns in the face of unprecedented access to big data are nothing new. More than thirty-five years ago, Dalenius (1977) already discusses "the proliferation of computerized information system[s]" and "the present era of public concern about 'invasion of privacy'." But as big data get bigger, so do the concerns. Greely (2007) discusses genomic databases, concluding that
[t]he size, the cost, the breadth, the desired broad researcher access, and the likely high public pro le of genomic databases will make these issues especially important to them. Dealing with these issues will be both intellectually and politically difficult, time-consuming, inconvenient, and possibly expensive. But it is not a solution to say that "anonymity" means only "not terribly easy to identify," . . . or that "informed consent"  is satisfied by largely ignorant blanket permission.
Replacing "genomic databases" with "big data" in general, our overall conclusion may be similar. The stories in the first part of this paper demonstrate that relying on intuition when attempting to protect subject privacy may not be enough. Moreover, privacy failures may occur even when the raw data are never publicly released and only some seemingly innocuous function of the data, such as a statistic, is published. The purpose of these stories is to increase awareness.
The ideas from the differential privacy literature we introduce in the second part of this paper provide one formal way for thinking about the notion of privacy that researchers may want to guarantee to subjects. They also provide a framework, or a tool, for thinking quantitatively about privacy-accuracy tradeoff s. We would like to see more such thinking among data-based researchers. In particular, with computer scientists using phrases such as - the amount of privacy loss" and - the privacy budget," the time seems ripe for more economists to join the conversation. Is a certain lifetime amount of e a basic right? Is privacy a term in the utility function that can in principle be compared against the utility from access to accurate data? Should fungible, transferable e be allowed to be sold in markets from private individuals to potential data users, and if so, what would its price be? Should a certain privacy budget be allocated across interested users of publicly owned (e.g., Census) data, and if so, how? Such questions are beginning to receive attention, as mentioned above. Increased attention may eventually bring change to common practices.
What kind of changes could one envision? In the third part of our paper we discuss specific applications of differential privacy to concrete situations, highlighting some limitations. When big data means large n, an increasing number of common computations can be achieved in a differentially private manner, with little cost to precision. It is not inconceivable that within a few years, many of the computations that have been - and those that are yet to be - proven achievable in theory, will be applied in practice. Echoing Dwork and Smith (2010), who "would like to see a library of differentially private versions of the algorithms in R and SAS," we would be happy to have a differentially private option in estimation commands in STATA. But ready-to-use, commercial-grade applications will not be developed without sufficient demand from potential users. We hope that the incorporation of privacy considerations into the vocabulary of empirical researchers will help raise demand, and stimulate further discussion and research|including, we hope, regarding additional approaches to privacy.
Until such applications are available, it might be wise to pause and reconsider researchers' promises and, more generally, obligations to subjects. When researchers (and IRBs!) are con dent that the data pose only negligible privacy risks - e.g., some innocuous small surveys and lab experiments it may be preferable to replace promises of anonymity with promises for "not terribly easy" identification or, indeed, with no promises at all. In particular, researchers could explicitly inform consenting subjects that a determined attacker may be able to identify them in posted data, or even learn things about them merely by looking at the empirical results of a research paper. We caution against taking the naive alternate route of simply refraining from making harmless data publicly available; freedom of information, access to data, transparency, and scientific replication are all dear to us. Of course, the tradeoff s, and in particular the question of what privacy risks are negligible and what data are harmless, should be carefully considered and discussed; a useful question to ask ourselves may resemble a version of the old newspaper test: would our subjects mind if their data were identified and published in the New York Times?
'The Illusory Privacy Problem in Sorrell v. IMS Health' [PDF] from 2011 by Jane Yakowitz and Daniel Barth-Jones comments -
Those in the habit of looking for privacy invasions can find them everywhere. This phenomenon is on display in the recent news coverage of Sorrell v. IMS Health Inc., a case currently under review by the Supreme Court. The litigation challenges a Vermont law that would limit the dissemination and use of prescription drug data for the purposes of marketing to physicians by pharmaceutical companies. The prescription data at issue identify the prescribing physician and pharmacy, but provide only limited detail about the patients (for example, the patient’s age in years and gender). Nevertheless, privacy organizations like the Electronic Frontier Foundation (EFF) and the Electronic Privacy Information Center (EPIC) have filed amici curiae briefs sounding distress alarms for patient privacy. A recent New York Times article describes the case as one that puts the privacy interests of “little people” against the formidable powers of “Big Data.” The fear is that, in the information age, data subjects could be re-identified using the vast amount of auxiliary information available about each of us in commercial databases and on the internet. 
Such fears have already motivated the Federal Trade Commission to abandon the distinction between personally identifiable and anonymized data in their Privacy By Design framework. If the Department of Health and Human Services (HHS) were to follow suit, the result would be nothing short of a disaster for the public, since de-identified health data are the workhorse driving numerous health care systems improvements and medical research activities. 
Luckily, we do not actually face a grim choice between privacy and public health. This short article describes the small but growing literature on de-anonymization—the ability to re-identify a subject in anonymized research data. When viewed rigorously, the evidence that our medical secrets are at risk of discovery and abuse is scant.

CIMA and FOI in the 'Democratising World'

'Breathing Life into Freedom of Information Laws: The Challenges of Implementation in the Democratizing World' [PDF] by Craig L. LaMay, Robert J. Freeman, and Richard N. Winfield under the auspices of the Center for International Media Assistance is
intended to be a practical, useful guide for stakeholders in national and local governments, the media, civil society, and business to making freedom of information laws work. The authors’ particular emphasis is on the role public officials and journalists must play in effectively breathing life into these laws, giving meaning to their democratic intent and legal guarantees.
Most of the world’s 90-plus freedom of information (FOI) laws are recent, enacted in the last two decades, and many are exemplary on paper. But many are also poorly implemented. Surprisingly but commonly, citizens, national and local public officials, and journalists are often unaware that such laws even exist, much less how they work. Non-governmental organizations and businesses typically make more requests than journalists or citizens, but frequently the total number of requests is far below what might be expected given the scope of FOI laws, which in some developing countries apply not only to government agencies but also to private entities that receive government funds. In countries transitioning from authoritarian pasts, governments retain the habit of working in secrecy, which hobbles democracy and promotes corruption.
Often when people seek information under FOI laws and are refused, they are denied on grounds that have no basis in law, or, if denied under a statutory exemption, without explanation of why the exemption applies. Sometimes requesters are denied for reasons that amount to official inconvenience, told that the request is too time- or resource-consuming to fulfill, or that the records they want do not exist. Requesters are asked to justify their requests, or officials simply ignore them, thus saving themselves the trouble of providing any explanation. The requester’s opportunity to contest an agency’s denial or failure to respond is typically inadequate: Internal appeals are often met with cursory review and the same result. Ombudsmen or other oversight bodies responsible for monitoring the law rarely have the authority to compel compliance when a request has been improperly denied, and pursuing redress in courts is time-consuming and expensive. Where citizens lack faith in their judicial system, the problem is compounded.
This paper begins with a review of the theory and practice of FOI laws, which are universally recognized as critical components of a modern system of free expression. It follows with discussion of the obstacles to effective implementation, including in an appendix several interviews with stakeholders in six countries in which FOI laws have been introduced recently: Albania, Armenia, Indonesia, Jamaica, South Africa, and Ukraine. The paper then makes several recommendations, which can be summarized thusly:
Officials of national and local governments who are responsible for responding to citizens’ requests for information must be properly organized, trained, funded, and protected. Those officials should be prepared to take effective measures to make FOI laws work. Leaders of the media, civil society, and business should persuade government officials to develop the political will to act promptly and effectively to make FOI laws work.
Because government touches everything, an FOI law should touch everything. Every aspect of governmental functioning has been the subject of inquiries under various FOI laws. There is no end to the potential utility of an access to information law, and that should be clearly expressed to and by officials responsible for its implementation.
It should be recognized that an FOI law is most important to average citizens at the local government level. This is true for the same reason that local news is what citizens most value: It’s what actually matters to them, affecting how they raise their families, where they live, how they make their livelihoods. People are most likely to actively participate in politics and civic life at the local level. They need to be able to hold their local leaders accountable.
Many FOI laws are based on a presumption of access, stating that government records are accessible with certain exceptions; the exceptions should be based on the likelihood of harm that could arise as a result of disclosure. An FOI law should in essence state that everything is available unless disclosure would hurt an individual via an unwarranted invasion of privacy, the government in terms of its ability to do its job well on behalf of the public, or perhaps a private company vis-a-vis its competition. Embarrassment is not grounds for denial of access.
The law should not require that government officers, employees, or agencies go to unreasonable lengths to accommodate applicants. The law should not compel the government to search through the haystack for the needle, even if it is known that the needle is there, somewhere. Rather, the government should be required to respond when records can be found, generated, or extracted with reasonable effort, which is often related to the nature of the agency’s filing, record-keeping or retrieval systems.
It must be recognized that public officials and government employees are more accountable than the public generally and that they enjoy less privacy than others. For instance, it is typical that salaries of public employees are accessible, and that ethics/financial disclosure requirements are often imposed on them. There are numerous situations in which certain disclosures as they pertain to private citizens would constitute an unwarranted invasion of personal privacy but where disclosure of the same information about public officials and employees would result in a permissible invasion of their privacy, for example, records indicating attendance or misconduct.
Harness the power of information technology. Missing from most older FOI laws is proactive disclosure. It should be required that governments post material on their websites when it is significant, clearly public, and frequently requested or used by the public. The government should also now promote “smart data,” also known as “open data,” platforms that enable users to merge and analyze machine-readable data. Government should also develop its electronic information systems in a manner in which it can segregate data items that are public from those that can justifiably be withheld. This promotes maximum access, consistent with the intent of the law, while concurrently protecting privacy or the disclosure of information that is clearly exempt.
Public officials must recognize that records management and archiving are critical to sustaining the utility of an access law and, in general, the proper functioning of government. In many nations, there has been little or no policy or law concerning the management of records, and inclusion of records retention and archiving requirements in an FOI law serves as a positive element in governmental operations.
Ensure that the ombudsperson or compliance person or body is a true believer and a champion of FOI and empower that person or entity to act on behalf of the public. If providing guidance or determining rights of access is merely a job, the function will likely fail. If that person or body is passionate about FOI and is independent, even a weak law will function more effectively, and a strong law will become stronger.
Officials must regularly review the operation of the FOI law to determine its strengths and weaknesses and to recommend changes in the law to correct its deficiencies. At the very least, laws that conflict with the FOI law must be amended or repealed.

Proceeds of Crime

The Victorian Auditor-General's Office has released a 76 page report [PDF] titled  Asset Confiscation Scheme, ie on the state's proceeds of crime (aka POC) regime.

The report states that
the Asset Confiscation Scheme is not operating as effectively or efficiently as it should. Its ability to deprive people of the proceeds of crime, and to deter and disrupt further criminal activity, is hampered largely by weaknesses in Victoria Police's approach to identifying assets, and weaknesses in how the Asset Confiscation Scheme operates as a whole.
The report comments that
Asset confiscation is a tool that Victoria's law enforcement and public prosecution agencies use in response to criminal activity. The Confiscation Act 1997 (the Act) and associated regulations enable the state to confiscate property in order to deprive people of the proceeds of certain offences, to disrupt further criminal activity by preventing the use of that property, and to deter others from engaging in criminal activity. The Act also enables the state to preserve assets for victims' compensation and restitution.
Asset confiscation only applies to certain offences. These include indictable offences, as well as more serious, profit-motivated offences that contravene various Acts including the Drugs, Poisons and Controlled Substances Act 1981, Crimes Act 1958, and the Sex Work Act 1994.
Assets that the state seeks to confiscate through a forfeiture order not only need to relate to specific offences and thresholds, but also need to be tainted or reasonably suspected to be tainted. Tainted assets are those that have been derived wholly or substantially from the proceeds of crime, or have been used, or are intended to be used, in connection with a crime.
 It notes that
The Asset Confiscation Scheme  was established in 1998, following the commencement of the Act. There are three key agencies that work together to achieve the objectives of the Scheme: • Victoria Police—primarily through the Criminal Proceeds Squad (CPS) • the Office of Public Prosecutions (OPP)—through the Proceeds of Crime directorate (POC) • the Department of Justice (DOJ)—through the Asset Confiscation Operations unit (ACO). In addition, the Scheme includes two committees: the Asset Confiscation Scheme Executive Management Group (ACSEMG), which oversees the Scheme, and the Confiscation Operations Committee, which is concerned with the operational, practical and administrative aspects of the Scheme.
The Auditor General goes on to conclude 
The Scheme is not operating as effectively or efficiently as it should. Its ability to deprive people of the proceeds of crime, and to deter and disrupt further criminal activity, is hampered by weaknesses in the way that assets are identified for confiscation, and by how the Scheme is governed.
Victoria Police plays a critical role in the Scheme as it is responsible for identifying assets for confiscation through its investigative processes. However, it is not maximising opportunities to identify such assets related to profit-motivated, serious and organised crime.
Its asset confiscation functions are undermined by a failure to make the most of its investigative tools, by a lack of effective planning, and by capacity and capability weaknesses. Its current focus on victims of crime work does not directly or demonstrably contribute to the Scheme’s objectives and diverts it from focusing on profit-motivated crime.
The other Scheme agencies—OPP, and ACO within DOJ—rely on, and react to, the work that Victoria Police generates. While opportunities exist to enhance their operations—such as planning and performance management for OPP, and procedures and performance management for ACO—both agencies are generally performing their core asset confiscation functions effectively and efficiently.
Significant governance weaknesses within the Scheme limit the ability of the agencies to work together effectively to implement the government's policy objectives. For example, there are unclear objectives, a lack of planning or effective oversight, a lack of clear accountability and leadership, a failure to address known longstanding weaknesses and the inability to assess performance against objectives.
The report comments that "How well the Scheme is performing is unknown as it lacks an effective performance framework".
Exacerbating this is the absence of effective performance frameworks within the individual agencies.
The need for a performance framework to assess the effectiveness and efficiency of the Scheme was first identified in VAGO’s 2003 Report on Public Sector Agencies. The recommendation to develop overarching performance measures was accepted by DOJ. Despite its commitment ten years ago to develop such measures for the Scheme, this has not yet occurred.
The Scheme has been subjected to three commissioned reviews between 2008 and 2012. In each review, consistent findings and recommendations were made, particularly in relation to weaknesses with the Scheme’s governance and performance. While improvements to the Act have been made as a result of these reviews, little apparent action has occurred to address other significant problems, resulting in issues that have persisted unnecessarily.
While the Scheme has been operating for over 15 years, it has experienced, and continues to experience, governance problems that undermine its effectiveness and efficiency. These governance issues have been known since at least 2003, and were further identified in the 2008 and 2009 reviews, and the 2012 evaluation. While efforts have been made to address them, these have not been effective.
The objective of the Scheme is unclear, with multiple documents referencing different objectives. The current terms of reference for the Scheme's oversight committees detail objectives that differ from what the Scheme participants actually work towards. There is no documentation that provides evidence of a decision for the Scheme’s objectives to be changed to reflect the Act’s objectives.
A draft set of objectives for the Scheme was developed and approved by the oversight committee in 2006, but not adopted. It is unclear why, despite being approved, these objectives were not adopted and did not drive the activities of the Scheme. Adding to the confusion, the 2009 review recommended to ACSEMG that different objectives be approved. While there was agreement to adopt them, again this did not occur, and there is no record to explain this.
It concludes that - 
ACSEMG has failed to fulfil its oversight and leadership roles. In particular, it has not set a strategic focus for the Scheme, nor ensured that objectives are being achieved. This is because it has failed to implement a performance framework to assess the achievement of outcomes, and has not developed clear objectives or prepared a strategic plan. These are all issues that have been known since at least 2008. Between October 2010 and October 2012 ACSEMG did not meet. The lack of meetings was not planned and there is no documented or reasonable explanation for the interval. The Confiscation Operations Committee did not meet over the same two-year period. One obvious impact of not meeting for this duration is that the committees have missed opportunities to address the Scheme's weaknesses for two years.
While DOJ is ultimately accountable for the Scheme, and performs a leadership role, the unclear governance arrangements mean that accountability and leadership are only notional. In practice, the Scheme includes two statutorily independent bodies, Victoria Police and OPP, over which DOJ has no control. This is not an ideal arrangement, and undermines the Scheme's governance.
Effective planning for asset confiscation does not occur at the Scheme level, and varies across the three agencies. Despite reviews since 2008 identifying the need to improve the Scheme’s strategic planning, no effective planning has been undertaken. There is no plan that brings together information about the Scheme’s opportunities and risks, that clarifies the objectives and outcomes, or how performance will be assessed. There is also no plan that establishes the Scheme’s direction or its priorities. The absence of effective planning is most notable at Victoria Police, which is essentially the driver of Scheme activity, and which therefore has a greater need for effective planning. Regular turnover of CPS staff—particularly its management— makes strategic and business planning more critical. The overall success of the Scheme is heavily dependent on how effectively Victoria Police and CPS plan and perform.
The CPS does not have any strategic or business plans, and other than at a high level, what it is tasked with doing is not clearly documented. It is not evident that CPS has undertaken or documented any assessments of the proceeds of crime-operating environments, including where there are opportunities, priorities, gaps or challenges. POC’s role in relation to asset confiscation is necessarily a reactive one, based on the assets that Victoria Police identifies for confiscation, and the number of supporting affidavits it sends to POC. Given this, its planning is partly reliant on there being effective planning at CPS. This would enable POC to understand the priorities and the active and planned investigations across Victoria Police, and to plan both strategically and operationally around these.
Regardless of the lack of planning at CPS, POC itself does not have effective planning systems and processes in place. It has no strategic or business plans that detail the broader and longer-term issues impacting on its role, the external workload pressures, what it aims to achieve each year, its priorities or its resource needs. Like POC, ACO’s role is a reactive one as it responds to the orders that POC obtains in court. This presents the same challenges in terms of effective planning if the other stakeholders in the process are not planning. However, unlike either CPS or POC, DOJ and ACO have comprehensive planning around asset management and disposal activities—with some non-material weaknesses.
Effective risk management is fundamental to public sector operations, as well as effective governance and planning. It enables entities and agencies to identify and manage risks and opportunities that may arise while performing their functions. Risk management across the Scheme and Victoria Police is inadequate to properly manage known risks. Risk management practices within the both POC and ACO are more advanced—both POC and ACO have developed risk management frameworks that identify risks pertinent to the functions they perform.
No adequate assessment of risks for the Scheme has been undertaken, and there is no risk management plan within CPS, even though a range of problems with the squad are well known to CPS and Victoria Police management.
Victoria Police, and more specifically CPS, is responsible for identifying assets for confiscation. That Victoria Police has had a dedicated squad for many years is a positive development towards achieving the Scheme’s objectives, and it is evident that the CPS is performing asset confiscation work. However, issues relating to the type of investigations it undertakes, and how it undertakes them, along with administrative weaknesses around the prioritisation and allocation of cases, mean it is not operating as effectively or efficiently as it should.
The Scheme's focus is on profit-motivated, serious and organised crime. Similarly, CPS considers that its focus is on the ‘upper echelons of organised crime’. However, in practice, up to 60 per cent of the CPS work relates to victims of crime. While victims’ compensation is a purpose of the Act, it is unclear why CPS is performing this function, at least to the current extent. This work is time intensive and anecdotally results in few victims pursuing the offender in court. The focus on this type of work detracts from what CPS should be focusing on—profit-motivated, serious and organised crime. Consideration needs to be given to whether it remains the responsible agency for working with victims of crime—particularly if the Scheme’s objectives are to be given every chance of being achieved. CPS has adequate investigative tools and sources of information available to undertake investigations to identify assets for confiscation. However, CPS is not making full use of its investigative tools, and may therefore be missing important assets. In addition, the way that CPS prioritises and allocates its cases creates a risk that prioritisation will not be undertaken appropriately and investigative action will not start in a timely way. The consequence is that assets may dissipate before action can be taken, reducing the likelihood of the Scheme's objectives being met.
Restraining property, through the use of restraining orders, is an important stage in the asset confiscation process. Its purpose is to prevent the disposal of property so that it will be available for a potential forfeiture order, an automatic forfeiture, a pecuniary penalty order, or for restitution or compensation.
Broadly, this process involves POC applying for restraining orders in the County and Supreme Courts, and ACO identifying and securing the assets identified in the restraining order. Delays in obtaining restraining orders and securing assets increase the risk that the assets will be dissipated.
While these agencies' functions are necessarily reactive—POC reacting to the outcome of CPS investigations, and ACO reacting to the outcome of the restraining order application process—both are performing this part of their roles effectively and efficiently. Similarly, the ACO’s practices and controls around the management, maintenance and disposal of forfeited assets are generally effective and economical, therefore minimising costs and maximising financial returns to the state.
The report features several recommendations-
  • The Asset Confiscation Scheme Executive Management Group should: 
  • develop a performance framework linked to the objectives of the Asset Confiscation Scheme that includes relevant and appropriate indicators that enable reported performance to be a fair representation of actual performance 
  • identify and document actions required to improve the effectiveness and efficiency of the Asset Confiscation Scheme, including previously identified issues 
  • develop an implementation plan that details the actions, accountability, time frames, resources, implementation risks and monitoring arrangements for these actions 
  • clarify and confirm the objectives of the Asset Confiscation Scheme 
  • update the terms of reference for the Asset Confiscation Scheme Executive Management Group and Confiscation Operations Committee, and schedule routine reviews so that they remain current 
  • clarify and confirm the Asset Confiscation Scheme governance arrangements, including leadership, accountability, roles and responsibilities, and issue resolution mechanisms 
  • undertake a risk assessment for the Asset Confiscation Scheme, including the risks associated with working in a joined-up arrangement 
  • develop strategic and operational plans for the Asset Confiscation Scheme, linked to Asset Confiscation Scheme agency planning.
  • Victoria Police should:
    • develop a performance framework, independent of the Asset Confiscation Scheme, to enable Victoria Police management to assess the performance of the Criminal Proceeds Squad 
    • implement quality assurance processes around data and databases 
    • develop strategic and operational plans, linked to those of Crime Command, the Asset Confiscation Scheme and other Asset Confiscation Scheme agencies 
    • undertake a risk assessment of the Criminal Proceeds Squad and its operating environment 
    • review the resourcing model for the Criminal Proceeds Squad, including the cost-effectiveness of using Victorian Public Service staff 
    • refocus the Criminal Proceeds Squad's investigations to be predominantly focused on profit-motivated, serious and organised crime 
    • reallocate responsibility across the organisation for assisting victims of crime in identifying and restraining assets 
    • redevelop practices to ensure that investigative tools are used to their full potential 
    • develop and implement a Criminal Proceeds Squad training strategy that includes consistent, compulsory inductions for new staff members
    • establish processes for the routine and regular review of criminal proceeds guidance 
    • develop, document and enforce the consistent use of case prioritisation and allocation procedures 
    • improve the way that the Criminal Proceeds Squad records prioritisation and allocation information to enable better management reporting.
  • The Office of Public Prosecutions should:
  • develop a performance framework, independent of the Scheme, to enable the Office of Public Prosecutions' management to assess the performance of the Proceeds of Crime directorate 
  • implement quality assurance processes around data and databases
  • develop strategic and operational plans, linked to those of the Asset Confiscation Scheme and other Asset Confiscation Scheme agencies.
  •  The Department of Justice should:
  • improve the current performance framework of the Asset Confiscation Operations unit to better enable the Department of Justice's management to assess its performance
  • review and update the procedures for the Asset Confiscation Operations unit.

Trespass

In KY Enterprises Pty Ltd v Darby [2013] VSC 484 the Supreme Court of Victoria has referred to ss 8 and 18 of the Limitation of Actions Act 1958 (Vic) in denying a party's trespassing claim against an adverse possessor of vacant land, who had effectively extinguished the claimant's title by continuous and uninterrupted possession of the land for more than 15 years.

The Court also found that the claimant's conduct of erecting a fence, which prevented an otherwise available access to the bulk of that land, was inconsistent with an assertion of title to whole of the land.

It quoted Bayport Industries Pty Ltd v Watson [2002] VSC 206 -
(1) In the absence of evidence to the contrary, the owner of land with the paper title is deemed to be in possession of the land, as being the person with the prima facie right to possession. The law will thus, without reluctance, ascribe possession either to the paper owner or to persons who can establish a title as claiming through the paper owner.
(2) If the law is to attribute possession of land to a person who can establish no paper title to possession, he must be shown to have both factual possession and the requisite intention to possess (animus possidendi).
(3) Factual possession signifies an appropriate degree of physical control. It must be a single and [exclusive] possession, ... The question what acts constitute a sufficient degree of exclusive physical control must depend on the circumstances, in particular the nature of the land and the manner in which land of that nature is commonly used or enjoyed ... It is impossible to generalise with any precision as to what acts will or will not suffice to evidence factual possession ... Everything must depend on the particular circumstances, but broadly, I think what must be shown as constituting factual possession is that the alleged possessor has been dealing with the land in question as an occupying owner might have been expected to deal with it and that no-one else has done so.
(4) The animus possidendi, which is also necessary to constitute possession, ... involves the intention, in one’s own name and on one’s own behalf, to exclude the world at large, including the owner with the paper title if he be not himself the possessor, so far as is reasonably practicable and so far as the processes of the law will allow ... the courts will, in my judgment, require clear and affirmative evidence that the trespasser, claiming that he has acquired possession, not only had the requisite intention to possess, but made such intention clear to the world. If his acts are open to more than one interpretation and he has not made it perfectly plain to the world at large by his actions or words that he has intended to exclude the owner as best he can, the courts will treat him as not having had the [requisite] animus possidendi and consequently as not having dispossessed the owner.”
To those principles should be added and/or highlighted the following:
  • When the law speaks of an intention to exclude the world at large, including the true owner, it does not mean that there must be a conscious intention to exclude the true owner. What is required is an intention to exercise exclusive control: see Ocean Estates v Pinder [1969] 2 AC 19. And on that basis an intention to control the land, the adverse possessor actually believing himself or herself to be the true owner, is quite sufficient: see Bligh v Martin [1968] 1 WLR 804.
  • As a number of authorities indicate, enclosure by itself prima facie indicates the requisite animus possidendi. As Cockburn C.J. said in Seddon v. Smith (1877) 36 L.T. 168, 1609: ‘Enclosure is the strongest possible evidence of adverse possession.’ Russell L.J. in George Wimpey & Co. Ltd. v. Sohn [1967] Ch. 487, 511A, similarly observed: ‘Ordinarily, of course, enclosure is the most cogent evidence of adverse possession and of dispossession of the true owner.
  • It is well established that it is no use for an alleged adverse possessor to rely on acts which are merely equivocal as regards the intention to exclude the true owner: see for example Tecbild Ltd. v. Chamberlain, 20 P. & C.R. 633, 642, per Sachs L.J. 
  • A person asserting a claim to adverse possession may do so in reliance upon possession and intention to possess on the part of predecessors in title. Periods of possession may be aggregated, so long as there is no gap in possession. 
  • Acts of possession with respect to only part of land claimed by way of adverse possession may in all the circumstances constitute acts of possession with respect to all the land claimed. ... 
  • Where a claimant originally enters upon land as a trespasser, authority and principle are consistent in saying that the claimant should be required to produce compelling evidence of intention to possess; in which circumstances acts said to indicate an intention to possess might readily be regarded as equivocal. ... 
  • At least probably, once the limitation period has expired the interest of the adverse possessor, or of a person claiming through him, cannot be abandoned.