Press Release: DataEthics4All partners with Miami Dade College for the STEAM in AI Movement
Press Release: DataEthics4All partners with Miami Dade College for the STEAM in AI Movement. Miami Dade College is the most diverse institution in the nation. There are 167 nations and 63 languages represented in its student body. The college’s eight
Share:
Written by:
Tags:
We are proud to announce and welcome Miami Dade College as the newest DataEthics4All’s official STEAM in AI Partner!
“The collaboration with DataEthics4All will allow MDC students to become well-rounded professionals in AI. We are excited to bring these resources to our students through the coming AI Centers at MDC.” Antonio Delgado, Vice President of Innovation and Technology Partnerships.
Miami Dade College is the most diverse institution in the nation. There are 167 nations and 63 languages represented in its student body. The college’s eight campuses and outreach centers offer more than 300 distinct degree pathways including associate and baccalaureate degrees, career certificates and apprenticeships. Baccalaureate degree offerings include biological sciences, engineering, data analytics, information systems technology, education, public safety, supervision and management, nursing, physician assistant studies, film and others. MDC is the recipient of many top national awards including the Aspen Prize. As Democracy’s College, MDC changes lives through accessible, high quality-teaching and learning experiences. It is the home of the Miami Culinary Institute, the Miami Animation & Gaming International Complex, the Miami Fashion Institute, the Eig-Watson School of Aviation, The Idea Center, the Cybersecurity Center of the Americas, the Cloud Computing Center, the Center for Learning, Innovation and Simulation, the School for Advanced Studies, and the New World School of the Arts, to name a few of its most innovative programs.
MDC has been named among the nation’s “Great Colleges to Work For” since the program’s inception. The College embraces its responsibility to serve as an economic, cultural, and civic leader for the advancement of our diverse global community. Its alumni and employees contribute more than $3 billion annually to the local economy, and MDC graduates occupy top leadership positions in every major industry. MDC is renowned for its rich cultural programming. It is the home of the Miami Book Fair, Miami Film Festival, the National Historic Landmark Miami Freedom Tower, the Tower Theater, Dyer Building, Koubek Center Mansion and Gardens, MDC Live Arts, the Lynn and Louis Wolfson II Florida Moving Image Archives, the Museum of Art and Design, a sculpture park and a large campus art gallery and theater system. MDC has admitted more than 2,000,000 students and counting, since it opened its doors in 1960, and more than 100,000 students are currently enrolled.
“Our students will have access to a vibrant community; they will have the possibility to share with peers with similar interests and passions about AI. This partnership will strengthen MDC endeavors to create new opportunities for learning the skills of the future”, Anabel Mederos, Artificial Intelligence for All, Grant Project Manager at Miami Dade College.
The traditional definition of STEAM includes subjects like Science, Technology, Engineering, Arts and Mathematics. Great linear paths to careers in Artificial Intelligence. But today, there are also nonlinear STEAM Paths that can lead to careers in Artificial Intelligence, Machine Learning and Deep Learning.
Since DataEthics4All is on a Mission to break down barriers of entry to tech, build diversity, inclusion and equity in Tech through a grassroots approach, DataEthics4All’s STEAM in AIᵀᴹ also includes Sociology, Technical Education in AI, Ethics, Analytics and Mentoring.
DataEthics4All hopes that the unique 10 Pillars of this Program such as Free STEM Tutoring, Career Mentoring, Project based career mentoring, Career Counseling, Essay Reviews for College Applications, help with College Applications, Career Technical Education, Internships, access to a global Community of Tech and Social Impact Leaders, Networking Opportunities, Leadership Opportunities and an Opportunity to earn the Presidential Volunteer Service Award will bring the much needed STEAM in AI through this Movement!!
“I’m pleased to announce the latest partnership between DataEthics4Allᵀᴹ and Miami Dade College for our STEAM in AI Movement and be given an opportunity to help support 100,000 students of Miami Dade in Career Mentoring, finding new Tech Jobs, Internships, Leadership opportunities and in earning the Presidential Volunteer Service Award!!” Shilpi Agarwal, Founder and CEO, DataEthics4All Foundation.
Contact [email protected] to learn more.
Share:
Written by:
Tags:
“There is a problem with that – that the minimally viable product is pushed so fast in the pipeline, that companies don’t even take the time to make sure that it is also ethically viable.”
~ Susanna Raj
TEST
“You’re now thinking about having the right team in place, having an ethics first mindset across that team and within the individuals themselves, and also looking for someone who can lead that team in ethics.”
~ Sam Wigglesworth
Expand
Talk Summary
DataEthics4All brings this Series of Ethics 1stᵀᴹ Live Talks for Leaders with an Ethics 1stᵀᴹ Mindset, those who put People above Profits. Come, Join us for this lively and informative discussion and food for thought on how to create an Ethics 1stᵀᴹ World: People, Cultures, and Solutions.
This week, in the 10th Episode of the DataEthics4All Ethics 1st Live, we discussed: MVP vs EVP – What should Startups focus on?
1. Minimal Viable Product vs Ethically Viable Product. What should be the primary focus of an Agile Startup?
2. How to build a Product with Ethics by Design?
3. How to build a Startup Team with Ethics INSIDE? Champions who put Ethics above Profits?
Come, Join us and share your perspective and best practices. If you’d like to be invited as a Panelist, please write to us before the show.
Transcription
0:39 Susanna Raj: Hello everyone! We are back again for our weekly ethics first live talks. I’m here with Sam Wigglesworth, and Shilpi unfortunately could not join us today, but we are going to run the show, and Sam is going to introduce the topic. It’s a very, very relevant topic that is very close to my heart. So Sam, go ahead.
1:07 Samantha Wigglesworth: Brilliant! Good evening, and lovely to see you again, Susanna. This is session 10, it’s January the 27th, and what we wanted to focus on this evening is looking at minimum viable products versus what is called EVP, and EVP is referring to ethically viable products. So we’re just going to discuss that this evening and what the importance of them is for startups in particular, and where we should focus our time.
1:38 Susanna: What is an ethically viable product?
1:46 Sam: From my perspective, it’s moving away from the traditional MVP, where you want to get a team together as quickly as possible, produce an idea and pull an MVP together, a minimum product together, you’re now thinking about having the right team in place, having an ethics first mindset across that team and within the individuals themselves, and also looking for someone who can lead that team in ethics.
2:15 Sam: That’s what I would say. You want to focus on responsible AI as well, that’s the core focus when you’re building responsible applications. Yeah, making sure you consider everybody’s decisions as well, and everyone’s requirements, it’s really important for the user.
2:32 Susanna: Yeah, definitely, and, you know, the minimally viable product has now been sold to everyone, and it’s a very lean, agile, framework in which to develop a product as quickly as possible – a testable product that you can push out to the public, and then the public can actually work on it, give you feedback on the failures and the flaws in your design, and you can quickly iterate, fix it and move on.
3:01 Susanna: There is a problem with that – that the minimally viable product is pushed so fast in the pipeline, that companies don’t even take the time to make sure that it is also ethically viable.
3:19 Susanna: To me, an ethically viable product is more important than a minimally viable product because in the long term, once the pilot is done, once the testing is done, it’s not possible for you to go back in time and fix what was originally a critical ethical flaw in your design.
3:41 Susanna: So, do you have any questions for us that we can answer from the audience?
3:49 Sam: Let’s have a look. Let me just check if we have any questions.
3:57 Sam: Not at the moment, we don’t at the moment, but please go ahead and ask us.
4:02 Sam: Yeah, I think you’re right though, it’s a really good point that you were making that we do need to think about it from an ethical perspective and an EVP rather than a minimum viable product.
It’s becoming more common now to do that – to think about the company’s values, how the models that we’re training and building treat the end user and how we as a business are focusing on that as an element for development.
Susanna 4:37 think, the first call about it, I think that’s the question right, you know, yeah, really cool about it. [?]
4:46 Sam: Yeah, like you were saying you want to have an agile approach. It’s not that we’re dismissing that you should still go through the process of scoping your ideas, of strategizing, and planning and going through that development life cycle and testing, deploying, and then iterating and improving.
5:09 Sam: But fundamentally, from my perspective, and from what we’ve learned so far, it’s really about the data that you decide that you’re gonna train your algorithm, your machine learning model on, and understanding that and making sure that it aligns with your end user – that it avoids as much as possible those biases that we have talked about that creep into data and into training models.
5:40 Sam: That’s really important for me, and we can look at frameworks to help us with that, whether it’s our DataEthics4All pillars, or others that are more available internationally and in companies, but the fundamental thing for me is that we consider all users and all end users when it comes to the data itself and the model. Yeah, what about you? What do you think? What’s your view?
6:05 Susanna: My view is the same, that right now there is a question within the field of ethics, you know, not in the field of ethics within the AI industry, it’s ethically costly businesses, by design, you know, trying to build ethics into the product.
Susanna: Yeah, waiting for inclusiveness, making sure that you are hiring the right person, that right the people are in the room, and also, that you are able to do market research for the target audience, making sure they are also included in the process, all of this costs money. So what do you say to that?
6:48 Sam: Yeah, it’s absolutely true, I think you have to align your product, your EVP with a funding model, as well, that aligns with your values.
Sam: I think it’s looking for those individuals that are interested in helping invest and grow that, whether that’s within the company itself, or looking for funds. Yeah, so certainly doing your research in that area, whether it’s working in an application in ed-tech, or in an ethics framework, for example, you’ve got to look for those funding avenues, and they’ve got to align with your values in your mission.
7:32 Sam: I’ve seen before that, we’ve seen in the articles that we’ll be reading, particularly from the one from TechCrunch, that Shilpi shared earlier, that for several years, a company can be developing a product, and invest millions of dollars into it, into both the marketing, and promotion of it when it’s finished, and the development, and if you don’t get it right that first time, like you said, and you don’t build it into the design from the basis, then that’s it. It just takes one mistake, absolutely. We’ve seen it before, and we don’t want that.
8:06 Sam: So aligning the right funding avenues, and making sure that that is your priority, and that comes from the team, and comes from the design.
8:17 Sam: What do you think? What’s your view?
8:19 Susanna: I don’t believe in that argument when people say it’s so expensive to build ethics into the whole design of your product. No, it is probably the most priority expense for your company at that stage, you should spend as much money on that as possible.
8:38 Susanna: If it takes time, then you should take that time and build it ethically – hire the right person, wait for the right team to form and make sure that your team is inclusive, make sure for all the discussions you have about the people who for whom you are building the product, make sure those people are also in the room with you.
8:56 Susanna: So it is an expensive avenue, but I think that is the only way to avoid the pitfalls that we are seeing now. Also, going down the road after you make a mistake, and after you see that it is no longer ethical, and then people are shouting at you and suing you and all of that, that is it is a costly endeavor, right? You might as well put the money in before into the product itself. So that’s what I think.
9:35 Sam: Knowing when it’s ready and taking time is important, I agree. I think from the very, very beginning, if you have a team that understands data, that understands the importance of privacy, that understands how to protect security and users rights, and has that perspective.
Really importantly for me, and I’ve been looking at a couple of TED talks as well about this recently, and actually we’ve had a talk on this, and we did have a talk last year during our Summit – we mentioned the importance of inclusiveness and understanding language, but it’s also about understanding culture.
10:17 Sam: If an organization can do that, and can make it a global application, thinking about the global South – we’ve talked about the global south before quite a bit.
10:28 Sam: Sometimes we have a perspective and we need that to be global. We need to look at that from many different lenses, from a language perspective, and also from a cultural perspective.
10:40 Sam: That takes time, as well, and learning. Do we have any questions?
11:12 Susanna: Yeah, anything related to this topic of an ethically viable product, this building with ethics by design into the product life cycle. Do you have any questions for us? You know, ping us? Put it in chat, and we will answer it live for you here.
11:27 Sam: I have a question then, and I think one of the questions we wanted to ask was, how do you build a team with ethics inside? So what is your view? How would you build a team up with ethics inside?
11:29 Susanna: First of all, with ethics, you can say that ethics has many different frameworks out there, but the one that is most crucial to any product’s viability, is to have inclusiveness built into it.
12:04 Susanna: You cannot have inclusiveness built into it when you don’t have representation of everyone at the table, everyone at every stage of the process, everyone who’s going to be impacted, the people are going to use your product, as well as the people who are developing a product – both of them should be from that background from the same background, should have also differences in different disciplines should come together. We don’t have that anymore. Different races and ethnicities, and different people who speak different languages. Even languages have different meanings in the same word, as a different meaning or a different connotation in another language. So you don’t know all of that unless you build a team that is more inclusive.
12:52 Susanna: So to me inclusiveness is the first first pillar of you know, building an ethically viable product. And if you cannot build an inclusive team, as of now, wait, all silver workers.
Susanna: Wait, wait until the person is there and don’t Don’t rush into it. And that waiting is not considered viable in the industry. But to build an ethically viable product, you must wait. And that is what I think and it should have. I think the next step is it should have inclusive use cases that benefit anyone, everyone everywhere. It cannot be just your product. Let’s say you’re selling something like a device, you know that is going to benefit only a certain group of people,
Susanna: you need to think how that device will be used against another group of people. So it needs to be inclusive.
These use cases are another area that I think we should have in the design itself. Any other things that you think should be there at the design stage?
13:57 Sam: Yeah certainly, I think as developers, and designers, we need to come from a perspective of knowing that we need to be agile in the way we approach products and developments. But before we get to that stage, like you said, we have to take our time, we have to understand the importance of knowing and being transparent with the technology that we’re building, and understanding how the processes of the algorithm operate, and the data that’s been captured. I keep saying that, I think that’s really important – from my perspective, from my background and from the work I’ve been doing, I think that’s really key.
14:38 Sam: Understanding the phases of development, but getting those people involved from an early stage, like you said, aligning them with the values of the company, and treating people that are part of that journey with fairness and respect and rights to privacy as you go along.
14:58 Sam: I think also you’ve got to think about, like we said, safety and security, and that it operates efficiently for everybody, and that we’re accountable to any outcomes. Like you said, we often find that, in the past, we’ve gone ahead of ourselves and developed products that are for users and very functional and well designed, but we haven’t often thought of the consequences. So we need to think about that first, before building – just know the pitfalls first and learn from that.
15:29 Susanna: Yeah, you have to think about all the use cases. I know they say that we didn’t have the imagination to think that facial recognition would be used? No, not really, you had the imagination to build the facial recognition tech, but you can’t say you did not have the imagination to think of any evil use cases, so we must have the imagination to ‘think evil’ as well so that we can avoid being evil.
16:03 Susanna: You have to think, how will this be used against an individual? Or against another country? What about countries that don’t believe in democracy? How will they use it?
16:15 Susanna: We didn’t think of all of those things, we launched facial recognition technology out there, and it is now being used in countries that don’t believe in democracy against their own people. So those are the use cases that you have to think about and all of this thinking takes time, and that is what it means to build an ethically viable product rather than a minimally viable product. A minimally viable product is easy to build and very fast, but an ethically viable product takes a longer time.
16:45 Sam: It is an investment, yeah I agree. I think what you mentioned earlier about having use cases for individuals or even countries that look at risks, and how it might be used against that particular group or individual is really important. Especially when it comes to the newer, more advanced technologies that we’ve seen in voice and facial recognition, I think both of those areas, those avenues are worth exploring.
Sam: I also found, from the research, that we often build products that are not accessible, so we need to think about accessibility.
We’ve talked about that a little bit before, but I think that’s really important for those that have multiple special educational needs, for example, that maybe need not only to read but also to have good audio, and good visuals of websites or applications.
17:51 Sam: I think we’ve got some questions coming up, let’s go into the feed. Okay, it’s not that busy on the comments feed, but I think we’ve covered most bases this evening. I know we had a couple of key questions about what we should be focusing on, what’s most important, and how do you build it? I know that in the articles that we’ve been looking at together as a team.
Sam: there’s an important requirement for an ethics first leader to lead that team, and I think sometimes you need both that and the right group, as well.
18:45 Susanna: I know that article mentioned that, you know, you should have an ethics chief officer, but I tend to disagree with that – it’s not just one person who’s being the ethical lead in the team, it doesn’t work like that.
19:03 Susanna: It has to be everybody, if we are going to build something which is ethical by design, everybody in the room has to be a voice for ethics and has to be the person to advocate for ethics from that room, it cannot be a single person – that is a model that has already failed.
19:23 Susanna: We saw with Google and all of them, you know, it’s not like you have a chief AI Ethics Officer and Chief AI ethics is such that no is doesn’t have the, you know, the ability to this another community wise, everybody in the company at every stage and every process should be talking about ethics.
19:43 Susanna: You know, in DataEthics4All, for example, all of us are advocates for ethics, so it’s not possible for the organization to do anything unethically because everyone in the room will speak up for it.
19:58 Susanna: Speak up politics, that is how I know ethics by design should be bad. What do you think?
20:06 Sam: Yeah, I think it’s it’s key, and we should be thinking about it from within as well and understanding that it’s actually part of your fabric as an organization, and it’s interwoven into design, it’s not separate. You shouldn’t just have that one individual, or that one small group, you need it to be across different teams or multiple teams, it’s part of a culture.
20:34 Sam: We’ve got our main objectives as an organization, and one of our missions is that we build it into the fabric of who we are, as an organization, I think that’s really important.
We learn and we improve, but we do want to start from that base, from the bottom up in that respect. I think we’ve covered all questions for this evening, and I’ve really enjoyed the discussion.
21:19 Susanna: Definitely, Samantha is also a founder of an organization – she is also a founder of a startup, so she knows what it means to build ethics by design into the product, into her programs, and into her organization. I am also a founder, so this is not something we just talk about, this is something we are trying to implement in our own products and in our own companies. So it’s a long journey, it’s an expensive journey, it takes time to do this the right way, and we have to break this mold of ‘minimally viable product‘, but just focus on the the agile framework that is included in that philosophy, but take it and use it for an ethically viable product, an ethically viable lifecycle of a product.
22:14 Susanna: You have to really dive deep into that, build explainability into it, build inclusiveness into it, make sure everybody is included, and every use case is also included.
Susanna: So, those are all the things that we are all trying to practice, and you can contact any of us for any more information on how to implement this in your companies. Sam is an expert in NLP so she would be able to help with how to build an ethically viable product as an NLP expert.
22:50 Susanna: So, DataEthics4All is an organization that is founded by Shilpi Agarwal, who believes in the Ethics First mindset, and everybody here is an ethics first mindset leader. So we are all here to support you in your journey to build ethically viable products. So come and ask us any questions, come and join our community.
23:30 Sam: Thank you, Susanna, who’s our chief ethics first officer, she’s our ethicist, absolutely. So thank you.
23:29 Susanna: Thank you, everyone, for joining us. It was a pleasure talking to all of you this evening. And we hope to come to you again next week for another lively ethics first discussion. Thank you.
/
Join Us in this weekly discussion of Ethics 1stᵀᴹ Live and let’s build a better AI World Together! If you’d like to be a Guest on the Show, Sponsor the Show or for Media Inquires, please email us at [email protected]
Come, Let’s Build a Better AI World Together!
Share:
Written by:
Tags:
“Whatever data you’re collecting from a user, you have to exactly notify the user what data you’re going to collect, what you’re going to use the data for, and the user should have the right to say no.”
– Shilpi Agarwal
“We need to be a bit more data-literate, know where our data is, request data if we want it, and be a bit more willing to understand some of the issues.”
– Sam Wigglesworth
Talk Summary
In this Ethics 1st Live Discussion, members of the DataEthics4All leadership team discuss the misuse of data – what it is, some examples and how you can defend yourself against it.
Transcript
0:08 Shilpi Agarwal:
Welcome to another Ethics 1st Live talk. I’m your host Shilpi Agarwal, founder of DataEthics4All, and I’m joined by my colleagues from the leadership team, Susanna Raj and Samantha Wigglesworth. Sam is joining us from the UK, and Susanna is joining us from California, sunny California! If you’ve joined us for the past five live talks or you’ve managed to see a recap of some of those, our intention with bringing these Ethics 1st Live talks to you is to bring food for thought for leaders with an ethics first mindset – those who put people above profits and have ethics in their DNA; who value ethics above all; it is not an afterthought, it is by design and it is at the forefront of everything they do. To encourage more such leaders and to bring more food for thought, this is our weekly talk series. Today’s topic is misuse of personal or private information; a really exciting topic because it is at the top of everyone’s mind. Private information and the misuse of it is very common these days and sometimes it’s a gray area and we don’t even know that we have misused it. Today’s talk will shed some light on what exactly is private or personal information, what is personal data, who has the right to use it, who has the ownership of that information and when is it okay to share or sell that information or use it publicly. I hope that our discussion today will spur up some conversation and food for thought. Let’s start with a basic question: what is personal information; what is private information?
3:27 Susanna Raj:
I believe private information is defined in very broad terms; legally even your name is considered private information. Your name – even your first name – your contact information, your home address, your IP address, and any information that can be linked to you to identify you as an individual is considered private information.
3:57 Shilpi:
Yeah, it’s called PII – Personal Identifiable Information. Any information that can identify you as a person, as opposed to being anonymous; as opposed to a female living in California aged between this and this – that is all still demographic information, there can be hundreds, thousands, millions of people with those same exact demographics. But when you put a few things together then it’s easy to identify a unique person, so this PII is a unique identifier; anything that uniquely identifies you. Sam, do you want to add anything to that?
4:45 Sam Wigglesworth:
You’re absolutely right, according to legislation personal data includes name, surname, location – anything that’s personally identifiable to you. It’s not just demographic data, it might be just a reference to health data as well, it does span quite a lot, there’s a lot to cover.
5:37 Shilpi Agarwal:
It’s also sometimes a combination of these identifiers. For example, even the first name is considered PII, but there could still be many people with the same name, like there could be many Shilpis in the world, but when you combine that with more information like my health care data or non uniquely identifiable information like my zip code, it narrows it down and then it is more easy to uniquely identify that person. That’s when that information truly becomes personal or private information. For example with healthcare data, it could be of lots of different people, but when you combine it with name and demographic and location, when in an office there’s only one person with that name, then those are the kind of things where we need to be careful of how we reveal that information. Okay, so what is considered data misuse?
7:12 Sam Wigglesworth:
I was looking at this earlier and I thought for me it’s having someone’s individual information and using it not for the intended purpose. That’s my definition. It doesn’t mean that it’s necessarily illegal, but it’s not used for the intended purpose.
7:50 Susanna Raj:
I would add to that that it’s not only for the unintended purpose, but also that any data you collect without permission, without consent or you collect it for one use case and use it for another use case, or you expand the use case without going back to the user and informing them again – all of those are considered misuses. In the realm of social media releasing someone’s private information because they have a contrarian viewpoint or a political viewpoint, and then you want to reveal their personal information – all of those are data misuses.
8:32 Shilpi Agarwal:
Yeah absolutely. I gave a talk at the DATAcated show about the ethical considerations of data collection. Consent was a major topic then – first of all you have to take explicit consent for whatever data you’re collecting from a user, and it has to have three key ingredients. It has to exactly notify the user what data you’re going to collect, what you’re going to use the data for, and the user should have the right to say no. When you’re asking for consent there should be a clear way for them to say no. If you go further, there should also be a way for them to revoke that permission so it’s not that they’ve given you the permission once and you just have it forever. You should also have a clear sunset policy, meaning you know when that data will expire, so you don’t collect somebody’s data with their permission but hold it forever and then use it for other purposes or selling it. Overall, data misuse is data being used for a purpose other than that for which it was collected without the consent of the user. Whenever as a business we want to use the data we have collected for something else, we must go and inform the users. That’s not just ethical, nowadays there are new laws that will ask you to do exactly that. So, what are some examples of data misuse that we have seen in recent times?
10:46 Susanna Raj:
There’s been a lot since 2016, there has been so many misuses of data! Cambridge Analytica is one that comes to mind; another is the time when an undercover FBI agent’s address and her name was identified. Even though she was publicly identified as a person, the fact that she had another job that was undercover was linked; both of them linked together. Sam could be a teacher in the United Kingdom, but she could also be an undercover agent – if I link that information and leak it, that puts her life in danger. That is called doxxing – if I have a disagreement with her and I know this information about her and I put it on social media. That was one of the major misuses that happened during the past administration in the United States and then it was back and forth; the far right and the far left doxxing each other and releasing private information, putting people’s lives in danger just because they are disagreed with the political viewpoint of the other person. So those are the kind of misuses that have been happening, especially on Twitter and Facebook.
12:36 Shilpi Agarwal:
And also Google and Amazon – basically all of these companies that have marketplaces. Facebook’s Cambridge Analytica started with the marketplace; there were apps collecting data from users, but those users explicitly gave information to Facebook, and then these other apps through the marketplace went and collected that data from the friends of the friends who actually owned the app. I might give permission to a mobile game app to collect my data because I want to play that game, but that doesn’t mean I’m also giving you permission to access the data of my friends! These marketplaces are a big loophole, Google got into a lot of firewalls to collect location data without explicit content from the users. Amazon’s marketplace also was doing that, although it’s still under investigation and the charges have not been formally brought, but there is an in-depth investigation going on by the EU’s antitrust authority to see if sensitive information from Amazon’s marketplace has been used by the sellers to their advantage. Sam, do you want to add something to this?
14:20 Sam Wigglesworth:
Yeah, I was going to say that Twitter is starting to review its privacy policies based on previous issues with uploading of videos and images which are then being used against individuals, so they’ve reviewed their policies based on that quite recently. In the news in the UK we know that data is being and has been in the past misused by organizations for individuals that are quite prominent, quite famous – that’s been in the news recently as well, where data’s been obtained without permission. That’s something that we’ve seen quite a lot of here. You’ve mentioned Google and the collection of data from ads, what I’m seeing is more companies now looking at solutions to make their data protection policies more stringent and strong. We talked about it last week in the previous Ethics 1st Live talk about bounties being awarded to developers who can find loopholes and gaps, whether in software or web applications; people are now actively looking to do that and they’re hiring people to do that, so that’s really positive.
16:31 Susanna Raj:
There’s been a lot going on in terms of controlling this misuse of information that each company is trying to bring up. The one that Sam mentioned was that Twitter came up with a privacy policy that said you cannot post private images and photographs without consent, but that policy was so poorly written it was used against activists trying to bring people who were causing violence and riots to justice. They posted their images and Twitter took them down thinking that it was private information posted without permission – how would they give permission to post those images? But those images were already public in another domain, so the policies are great if they are written in a proper way and take into account all the variables. It goes back to my research industry terminology – all your variables have to be defined, all your legal terms have to be well defined, so you have to define what is private and what is not private quite thoroughly.
17:47 Shilpi Agarwal:
It was a well-intentioned effort, they wanted to protect people. Social media nowadays is full of things like when you go to a party and people take pictures with you in the background and then they post it on social media – and there is no consent. What if I don’t want wherever I am publicly on social media? But it’s difficult to take consent from everyone, especially in a crowd, so what do you do? How do you put something in place where you can report to Twitter and ask them to take it down, and they will review it? It was a well-intentioned effort and something that definitely needs to be done because on social media platforms kids do it, we all do it, we want to brag about ourselves, but we forget that in the process we may be hurting someone else’s privacy or their private information. Like Susanna said, the far-right activists felt very happy that this policy is going to actually protect them because now nobody will know the face of people who are actually deliberately causing intentional harm to society. Obviously we don’t want that, but to be fair the policy said that you have to appeal to take something down, not that you can do it on your own, and Twitter will make an informed decision whether it needs to be taken down, so in this case if they see that it is an actual far-right activist group that is causing harm to society, then Twitter can decide not to take it down and let it be common knowledge that these are the kind of groups or people that are causing harm to society, and so stay away from those kind of things or protests. You gotta start somewhere, because this has become a giant beast; social media today has become a giant beast. It’s very hard no matter how well intentioned the laws you put in place are, there’s always good and bad to it. So, what is the difference between data misuse versus data theft?
20:31 Sam Wigglesworth:
They’re slightly different. Misuse as we’ve said is where data isn’t being used for its intended purpose as Susanna said, without consent. Theft is when there’s been a data breach or a cyber attack on a company or an individual’s data and it’s taken without consent. You’re not aware of it at all.
21:35 Shilpi Agarwal:
True, there’s no consent of any kind – with misuse there might be for one particular purpose, with theft there is no consent, period. Consent is not given by the user for any purpose to a particular person or company or vendor or user or app for that purpose; they decide to just steal that data and use it; that’s literally what it means, it’s basically theft. In some ways what happened with Cambridge Analytica also can be considered theft because the users only gave information consent for their own information, but that app stole data from all of their friends, so it would be considered theft. Susanna do you have anything to add to that?
22:40 Susanna Raj:
No, theft is just taking something without permission – that’s the basic definition of theft; that definition applies to data.
23:01 Shilpi Agarwal:
With misuse also, it is still our data so in both cases we are the owners of the data, but in the first case we are willingly sharing it with someone. So are there any laws today to protect us, the users, from companies misusing our personal information or stealing our data?
23:46 Sam Wigglesworth:
We do have in the UK and in Europe policies around data protections; we have the Data Protection Act in the UK which has actually been reviewed recently in 2018. That governs the use of personal data, how it’s collected and what we should be using it for. Then you’ve got the Computer Misuse Act as well which covers what we were just talking about, the risks that data in an organization could be collected illegally.
24:28 Shilpi Agarwal:
We also have GDPR and the CCPA, which is for California, but it should be everywhere; it should be applied nationwide. CCPA stands for California Consumer Privacy Act, it gives users protection for their data, so whenever you visit a website even if cookies are there, you can say ‘do not sell my information’. You can explicitly ask for a company to share whatever information they have on you; they have to actually show it to you, and if you say that you do not want that information stored, they have to abide by that and delete all the information they have collected on you. You can also fill out a form saying ‘do not sell my personal information’ and in that case they will not be allowed to make money out of your personal data. Those are some things that the California Consumer Privacy Act protects. I will let Susanna talk more about GDPR if she wants to add anything.
25:46 Susanna Raj:
Yeah, GDPR is much broader than the CCPA in that it goes further, not only with deletion of data – the right to forget your data – but also the definition in Article 48 of GDPR and also the European laws are very strict in how they define a person and personally identifiable information. A ‘living person’ versus a ‘natural person’ versus a ‘legal person’ – they have different definitions, and they also define in a granular way the difference between corporate rights and individual rights. All of those are much better in GDPR than the CCPA – which is a good start for California, as far as the whole of the United States we don’t have anything like that, so California is leading the way in that. It still falls very much behind the GDPR though in terms of defining what is a person; what the legal identity of a person is versus a company, that has been done very well by the GDPR.
27:06 Sam Wigglesworth:
What you mentioned earlier about sunset policies comes up in this particular legislation as well – if you’re going to be utilizing data it’s got to be done lawfully; it has to be time limited and limited to what it’s necessary to be used for, and accurate. You have the right to request what information is being held on you. It covers a broad range of parts of the legislation which are protected, and the UK is modeled on that – both the UK legislation and GDPR operate together.
28:00 Shilpi Agarwal:
You brought up the sunset policies; so data collection at the moment, especially with contact tracing and everything that’s happening with Covid, we have all these contact tracing apps and even the government, even schools are collecting your data. What schools are doing, for example in my kids’ schools, is they have a seating chart and they want kids to sit every day in the same exact place so that if somebody tests positive then they can inform everybody who came in contact with the kid. Again, it is well-intentioned and it is good for the purpose that it’s serving right now, but hopefully Covid is behind us and whatever data and information we have collected through contact tracing we need to let it go, we need to have a sunset policy. Basically they have minute-by-minute information on where you’re going, which stores you’re visiting; they have so much information on that person, so it could be misused in a big way. And also, while I was talking about this talk that I gave for DATAcated, there was also this use case where H&M was collecting information on their employees. Every time an employee went on a holiday or took a vacation or took personal leave, they were forced to have an interview with senior leaders, and they were asked to share more information than they needed to, and then this information was used for understanding their religious preferences among other things, also putting them on this corporate promotional ladder or whatever you want to call it. For all of these practices they were fined 41 million dollars. Maybe it was well-intentioned; maybe they only wanted to know how to better understand their employees to be able to give them better perks and create more things that will engage their employees; so maybe it was well intentioned. But the execution of that and the data that was collected was more than was needed. So coming back to data collection, everything starts with data collection, so we have to be very conscious and ethically minded when it comes to every stage of the data.
30:58 Susanna Raj:
Especially with IoT [Internet of Things] devices now, that is another whole big area of security issues. Here in California PG&E has smart meters which collect all the data about when you do your laundry, how long you do your laundry for, when your lights are on, when they’re off – it collects all kinds of information. We went through a breach in India and lost a lot of that information to thieves. Why are companies collecting this information when the purpose is to know how much energy you are using – you don’t need the granular details of each home and each individual’s user preferences. We have to be aware of what is being collected on us; I believe as individual users it’s on us.
31:57 Shilpi Agarwal:
But you know what PG&E is doing, right? They are not only seeing what time you are doing your laundry, but they actually have come up with different pricing points. Again, where they are coming from with this information is that they want to spread out the stress on the grid, because everybody comes back from work and maybe does laundry between 4-7pm, or between the morning times when there’s not that many people working and people are from working from home. So to reduce that they have different pricing strategies for people who are doing laundry from 4-7pm or on the weekends versus people who are doing it on other times of the day. So to your point, yes they are collecting that information; because they have the smart meter they can do that, and they are actually incentivizing people to do their laundry or use less electricity on the times when the grid is already overloaded. Yes it is well-intentioned, but with data comes responsibility, and with more data comes more responsibility. If we want to use the data we collect from our users, we have to secure it properly so it is not susceptible to breaches. That is an ongoing task of the security officer, it’s a nightmare these days! We talked about ethical hacking and the bounty and all of that – imagine the jobs of the privacy and the security officers, it must be hard because you never know who is going to come after your data.
Alright, last question: what can we do to better protect our data? Is there anything we can do as consumers to protect our data?
34:23 Sam Wigglesworth:
We’ve just got to realize, and I think we’re more aware of it now since the pandemic started and we started working from home using IoT devices a lot more than we used to and being on our computers at home, that actually our work and private lives have blended a little bit and we just have to be a little bit more vigilant of what we’re doing online, what we’re sharing and how we’re sharing our information. Just generally we need to be a bit more data literate; that’s what we try to do, we want to focus on that and develop those skills. Knowing where our data is and requesting data if we want it, being a bit more willing to understand the pitfalls and maybe some of the issues and if we want to know more we can find out more and build our knowledge. That all helps, definitely. Being ready, reading around the topic, visiting our community as well and learning about what we’re discussing in our community online and in these talks. That will make us more resilient, I think we’ve got to think about that going forward.
35:49 Shilpi Agarwal:
It starts with information: we have to know our rights, we have to know where we are sharing our data, what others are doing with our data; if we are signing our consent on a 45-page document, it’s our job to read it and understand it, and make sure what it is going to be used for.
36:13 Susanna Raj:
It’s also your job to demand that the 45 page be a four page document, it’s within your right to demand those things and it is also within your right to ask whether you really need a coffee maker with IoT in it? Can’t you just walk and go and put the damn switch on instead of asking Alexa to turn it on for you? All of those things – what is the convenience and what is the freedom you are paying for it? And also, incentivizing behavior is another thing that corporations are doing with our IoT information, and yes it may be to help the power grid, but also if they are changing the behavior of each individual household, and especially households that may have a disabled community member living in them, they may be using more power at different times of the day and they may not be able to transition to that incentivized behavior that PG&E wants us to have. Also thinking about other communities who may not be able to accommodate your behavior modeling practices. Including all of those things; I don’t think the burden should be only on us – it’s like it should be on you to read every 45 page document? No, no, I don’t want to read a 45 page document, I want you to give me a two page document, it’s also my right to demand those things and to make the laws work for us.
37:58 Shilpi Agarwal:
I think with that we will end this on a good note; know your rights and demand your rights, do not think that if it’s out there then it’s out of your hands, you still have control, the data belongs to you and you have ownership of that information – you alone have ownership of that information and you can now ask for the right to be forgotten, that data to be deleted and that data not be sold to anyone else. You yourself are the only person who should be able to make money out of your own data, no one else. So with that note, hope you got some good food for thought and we’ll see you next time. Thank you Susanna and Sam! For everyone who is going to watch this on demand please feel free to post your comments, we are always listening and we’d love to hear from you.
Join Us in this weekly discussion of Ethics 1stᵀᴹ Live and let’s build a better AI World Together! If you’d like to be a Guest on the Show, Sponsor the Show or for Media Inquires, please email us at [email protected]
Come, Let’s Build a Better AI World Together!
Share:
Written by:
Tags:
``Do we understand what responsible AI is?``
``Are we informing and educating all the people that might have an impact in the decision making process.`` - Diya Wynn
“I think it’s so important the work that data ethics for all is doing, and exposing young people to stem and technology and opportunities and artificial intelligence”
– Diya Wynn
I am text block. Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
“Deloitte… said that while organizations understand that there’s a risk, or understand that there may be a potential for bias and a lack of transparency, they really don’t have the skills in order to be able to address those issues.”
– Diya Wynn
Expand
We are seeing AI/ML in almost every industry and every facet of our lives. The convergence of the cloud and AI is fueling this transformation and enabling widespread innovation. And AI is expected to continue to fundamentally change industries and how we engage in the world. While the benefits of AI are being widely recognized, there are obstacles and concerns surmounting. In order to sustain the ongoing adoption and realize the full benefits of AI, we need responsible development, deployment and use to ensure risk and unintended impact are minimized. “Responsible” isn’t just defining a set of principles, but it is putting those principles into practice driving when and how AI is leveraged and experienced.
Diya Wynn has worked in technology for 25 years building, delivering, and leading in early and growth-stage companies. She has a passion for developing current and emerging leaders; promoting STEM to the underrepresented; and driving diversity, equity, and inclusion (DEI). After spending years in technology-focused roles and separately pursuing passion projects in DEI, she now has a role marrying the best of both worlds. She leads a team focused on engaging with customers to go from principles to practice – operationalizing standards for responsible use of Artificial Intelligence/Machine Learning and data.
Expand
0:00 Shilpi Agarwal:
Next up, we have Diya Wynn, Senior Practice Manager of AWS. Diya has worked in technology for 25 years, building, delivering and leading in early and growth-stage companies. She has a passion for developing current and emerging leaders, promoting STEM to the underrepresented and driving diversity, equity and inclusion. After spending years in technology-focused roles, and separately pursuing passion projects in DEI, she now has a role marrying the best of both worlds. She leads a team focused on engaging with customers to go from principles to practice, operationalizing standards for responsible use of artificial intelligence, machine learning, and data. Please welcome Diya Wynn! Hi, Diya, how are you?
1:17 Diya Wynn:
I am doing great. I’m excited to be here.
1:20 Shilpi Agarwal:
I’m excited about your talk on ‘How to accelerate AI adoption’. I’m going to give you the space.
5:00 Diya Wynn:
Greetings to everyone. As was introduced, I’m Diya Wynn, and I’m excited about having the opportunity to share a little bit today. Now, I would say I have a distinct pleasure in being on the stage with so many other amazing folks that have been talking with you over the last three days. But I also have a bit of a challenge, because we’ve had some amazing individuals come and I think I’m at the end of the day!
I just want to take a moment to share a little something with you that will hopefully give a bit of context for how I got here, and why this particular area is important. So, I have two boys and I grew up in a family of girls in the south Bronx, between Harlem and New York City. Earlier in my years, I had not been exposed to technology; I had not had the privilege to see other people who were in technology in my family. What was traditional at the time was to see women who were teachers, maybe nurses. I got a computer early in the third grade, and that actually was the catalyst for me that made me want to go into technology. It was that exposure; and I bring that up because I think the work that DataEthics4All is doing is so important, in exposing young people to STEM and technology and opportunities in artificial intelligence, and even exposing and elevating the awareness of folks that may not be as aware of some of the challenges and the things that we should be mindful of, or avenues for us to consider as we look to advanced technology. I just wanted to bring that up because for me, when I started to think about my earlier experiences, I was looking at: ‘well, what do I do with my sons? How do I prepare them for what’s going to come in the future?’ And that’s really led me to where I am today. My background is in technology, I studied computer science. I was that third grader who kept my mind focused on technology even from the start, but I wanted to make sure my sons too are able to navigate this world, because we know that there are changes on the way that we will have to live with and adjust for, when we think about technology, artificial intelligence and robots being at the forefront of how we engage and shaping how we interact with the world. This is as much an inclusion, diversity, and equity problem as it is a technology problem. So, that’s just a little bit of my introduction and why this is so important that we bring awareness and education and opportunity exposing individuals to more of what the world will look like and the opportunities we have in it.
9:14 Diya Wynn:
Now, since I’m here on the last day of this AI DIET world, I wanted to just give you a brief overview of some of the solutions that my team and I have created to help our customers at AWS in this journey to responsible AI.
Most of you are already aware of how much machine-learning and artificial intelligence has been incorporated into everything that we do. Most of our industries are exploring and using artificial intelligence in some ways. Just recently I bought some new appliances in my home, and now my Samsung refrigerator and TV and microwave all have ways of talking to each other and giving me alerts in different places. Those are some simple examples, but then we also know that organizations are starting to use it in ways that aren’t just research and development or proof-of-concept projects anymore; they’re really leveraging artificial intelligence in major ways to advance products to see greater efficiency in operations. And we know that they’re handling real-world tasks, maybe not as simplistic as my Samsung kitchen appliances, but more complex problems that we thought perhaps unachievable or unattainable in the past. And this whole idea of this increased use of machine learning and artificial intelligence technologies means that there’s an increased need for us to not only be aware of benefits and potential risks, but also be doing something about them.
12:00 Diya Wynn:
Companies and CEOs recognize that there is a potential for bias and lack of transparency, and we’re seeing this in other organizations, big and small. At the same time, there is a concern – and this came through in a Gartner study – that 85% of the projects were expected to deliver erroneous outcomes due to bias in data algorithms and the teams that produce them. So what do we do then, if we recognize that more companies are going to begin to use artificial intelligence and more applications are going to have AI and ML infused into them, and we’re going to be interacting with it more, and that there are these potential risks? There’s another study as well (from Deloitte), that said that while organizations understand that there’s a risk or a potential for bias and a lack of transparency, they don’t have the skills to be able to address those issues. So, there is some level of awareness and some people will question whether everyone is fully aware of where there may be an impact – but then, what do we do? Not everyone is sitting in circles like what we just saw over the last three days, where they’re talking about potential opportunities, and the ways in which we might look at navigating bias, or how we understand our data and look at more complete and robust options with our data. Not everyone is sitting in those environments, so what do you do when there is such great promise and opportunity when we think about the ways in which AI has been used today?
14:03 Diya Wynn:
We heard some examples – when Vivian was talking about being able to give those who were autistic the ability to be able to recognize expressions that they wouldn’t normally be able to do, amazing use case, right? Or in the case of Thorn, which is helping children that may have been pulled into child sex trafficking; helping them to be reunited with their parents. These are use cases that matter, and we want to be able to have the technology at hand for us – so then what do we do?
I think when we think about enterprises and us wanting to be able to leverage the great benefits from the technology, we also need to make sure we’re not infringing on civil liberties, and that there is inclusive technology or models that are being in used in ways that respect our rights, are fair and inclusive. In the work that I get to do, and my team as well, we understand that this is not a simple problem. Some of the things we can do to address it may in fact be simple, but this really is a multi-disciplinary problem; not just looking at the skills or the expertise from certain industries, but also bringing to bear philosophy, law and these other social sciences to begin to address some of the issues and challenges, and create opportunity. I heard someone say that the other day: consider every problem as an opportunity.
16:12 Diya Wynn:
So, what my team and I got to do is create this framework to begin to address the gaps in skills in the enterprises and organizations we’re talking about, so that they’re not just aware and wondering what to do, but they actually have the skill and capability to address problems, and begin to tap into how we operationalize responsible AI. What things do we put in place to ensure that we’re looking around corners and seeing where we didn’t notice that certain individuals may not have been at the table, and that applications aren’t necessarily meeting the needs of some of our consumers?
AWS Ratio is our responsible AI framework that helps us establish principles so we can take an intentional and strategic approach, so that we can deliver good outcomes and minimize unintended impact and risk. This is our answer for assisting organizations with building on their AI investments in ways that allow us to experience the great benefits that we get; tackling these challenges but also addressing opportunities or areas where they may be risk. Each stage in Ratio helps us highlight questions; primary considerations; areas that we need to pay attention to in order to identify where there are gaps or potential risks, and begin to address those with some best practices and actually doing the work to put them into place in the organization.
18:28 Diya Wynn:
So we help our customers look at artificial intelligence and machine learning and the way in which they’re going to employ that in a responsible way. This for us is identifying a new operating model, right? Looking at people, process and technology, so that we can really drive better outcomes and reduce risk. Defining and executing that operating model goes across every stage of what we would say is the machine learning lifecycle, but this is really a part of a holistic AI journey. Do we understand what responsible AI is? Are we informing and educating all the people that might have an impact in the decision making process, in annotating data, as well as our data scientists that are training models, who all are educated in and love their area, in ways that they actually can be accountable and responsible, and take a part in ensuring that we’re delivering, building, deploying and operating responsibly?
19:40 Diya Wynn:
We’ve defined seven pillars as a guide to help us navigate through the areas to put in place the right things in order to design, develop, deploy, and operate responsibly. This will hopefully address ethical concerns when we assess this more broadly, and help us define players that have a responsibility, so they have clarity about where they fit in and when, and then give us a relative mechanism for being able to monitor and iterate that over time. And continuing to improve the process, because the ultimate goal is that we minimize the risk, reduce unintended impact and build in an inclusive way.
20:37 Diya Wynn:
Now, I talked about this, and we started off with this first piece or definition that said: ‘Accelerating business outcomes with AI matters. Raising the bar on responsibility matters even more. And Trust is at the centre’. The reason why I say that is because this conversation ends up being one about trust, and we’ve heard a little bit about that over the course of the last couple of days, as well. As human beings, we don’t trust things that we don’t understand. Companies need to be seen as trustworthy and as building trustworthy products, and the absence of that is going to have an impact on the company, people’s perception of their products and the technology itself, which ultimately has an impact on the industry and will inhibit our ability to leverage it to get life-changing solutions or solve problems. We want organizations to be building and operating responsibly so we can continue to solve real-world problems.
A great example of that would be that of the NFL and the way in which they’re using AI to find new ways to address player safety. I told you the example of Thorn with child sex trafficking or even someone that’s using AI to start to predict how they might help heart-related issues so that they can provide more preventative care. These are the ways in which we want to be able to leverage it, so we’ve got to build a foundation of trust. That notion has to start not just with the data sciences, or those of us that are aware, but really giving opportunity and responsibility to everyone in the lifecycle. That starts in a large part with our companies and our organizations that are building and deploying the technology in this way.
22:55 Diya Wynn:
So with that, I will say thank you, because I only had a little bit of time. Our solutions really go from discovery into production, and these are ways in which our team (which is a global team) can begin to partner with our customers and take them along this journey, going through the seven pillars and highlighting areas of opportunity for us to address to really build more inclusively, and ultimately have the foundation of trust that allows us to solve more, and to address more and more.
23:39 Shilpi Agarwal:
Completely agree with you Diya, what a fantastic talk, completely agree that we have to move forward with social good as our core in order to leverage data, technology and artificial intelligence to make the world a better place. Thank you so much!
DataEthics4All hosted AI DIET World, a Premiere B2B Event to Celebrate Ethics 1st minded People, Companies and Products on October 20-22, 2021 where DIET stands for Data and Diversity, Inclusion and Impact, Ethics and Equity, Teams and Technology.
AI DIET World was a 3 Day Celebration: Champions Day, Career Fair and Solutions Hack.
AI DIET World 2021 also featured Senior Leaders from Salesforce, Google, CannonDesign and Data Science Central among others.
For Media Inquires, Please email us [email protected]
Come, Let’s Build a Better AI World Together!
Share:
Written by:
Tags:
“I don’t believe we should be paid for our data. I don’t think I’m ready to say yes to that question – to sell my privacy to people.”
– Susanna Raj
“I do not want my browsing history to be tracked, but if you are going to track, show me what you tracked, and let me be the decision maker of whether I wanted it to be stored, deleted, or paid for.”
– Shilpi Agarwal
Expand
Talk Summary
DataEthics4Allᵀᴹ brings this Series of Weekly Ethics 1stᵀᴹ Live Talks for Leaders with an Ethics 1stᵀᴹ Mindset. Food for thought for Leaders who put People above Profits!! Come, join us for this lively and informative weekly discussion on how to create an Ethics 1stᵀᴹ World with Ethics 1stᵀᴹ minded: People, Cultures, and Solutions. In this Live Talk, we discussed the topic of Get Paid for your Data.
Transcript
00:25 Shilpi Agarwal:
Hey everyone, welcome to Ethics 1st Live! I’m your host, Shilpi Agarwal, founder and CEO of DataEthics4All, and I’ll be joined by my panelists today, from the DataEthics4All Leadership Team, Susanna Raj and Samantha Wigglesworth, good evening. Today we are going to talk about whether we should we be paid for our data? It’s a very interesting question that we all have on our mind. Last week on Ethics 1st Live we talked about how our personal and private information is being misused or sold without our permission, so this is a kind of part two of that: whether we should be paid for our own data or not. As you know, Andrew Yang, who was a former presidential candidate, started the Data Dividend project because he believed that social media companies should pay a dividend to the consumers whose data they are holding and making money off. That was also a theme for California’s governor, Gavin Newsom, who also created a digital dividend project and wanted Californians to be paid something for their own data. So let’s start with what our panelists think – first of all, do you guys think that consumers should be paid for their data? We’ll start with Susanna.
3:05 Susanna Raj:
I don’t believe we should be paid for our data. I don’t think I’m ready to say yes to that question – to sell my privacy to people. I know it is already being taken over by companies; but I would like to have my ownership back, I don’t want to sell it.
3:36 Shilpi:
You don’t want to sell it, you just want the ownership back. But what would you like to do with the things that you have shared freely, on Facebook or on any other social media platform?
3:50 Susanna:
I have not yet shared anything freely, but whatever was taken without my permission I would like it back. If not, I would like to take everything back and also be informed what is being taken away from me – that is what I would like to have.
Susanna: I don’t think privacy should become a commodity; I don’t think it should become something you sell.
Susanna: I don’t believe you want to go down that path – I know what California has done is in a way empowering people, they think that is one way of being bringing data ownership back to the people by saying there is a price for the data; so that means that you become the seller and then you have ownership back. But why do I have to sell anything to have ownership back? I can keep that to myself and still have my ownership – why do I have to sell it?
5:02 Sam Wigglesworth:
Susanna has raised a really good point. For me we’ve got to a point where quite a lot of our data is already with social media companies and tech companies, and has been for quite a while, so the horse has already bolted in some respects. Initially I was thinking that yes we could certainly benefit as citizens from having some sort of reward for the utilization of our data if it’s appropriately used. But first I think let’s look at the data that is currently in the data lake, if you like; and that’s being utilized by private companies, and let’s focus on protection under legislation similar to what we were discussing last week and what you’ve just raised about the California legislation.
I think it’s important that we focus on that and that organizations have their own very robust disclaimers as well that state what data they have about you and what it’s going to be used for. Legal policy would give us that power back, which is what Susanna was saying.
Sam: There are some incentives out there in the marketplace for us to benefit financially from data, but again I don’t think it’s a great deal, that’s my view.
6:43 Shilpi:
I hear both of you, here’s where I’m coming from: the California Consumer Privacy Act is the baseline protection for consumers, right – there is some level of protection that has now been turned into the law. Unfortunately California is the only state in the United States that has adopted that as the bare minimum for privacy protection. Of course we would like all states to implement something, hopefully something standardized, not that every state comes up with their own version, because then it is a mess to do business across states and for consumers to understand. Today we have to understand GDPR as a consumer and as a business owner, and GDPR and CCPA are very different in their own ways.
Multiply this by 50, or if every country came up with their own, and there are some countries who have their own versions of it, so it would become a real nightmare to keep track of everything for consumers as well as for businesses. I agree with both of your points – at some point I was also of the opinion that it’s our data and so consumers should benefit from it. To your point Susanna, one set of data is the information that we have shared freely when we are creating an account, posting pictures, sharing posts, saying things, tagging our friends, posting group pictures, posting videos – there are things that we have freely given. Yes, these platforms are portrayed as a way to connect to people and so we thought that we are really just sharing this with our friends, our family, so we are share how we feel; our thoughts, our desires, our hopes, our ambitions.
It is different if I’m asking my friend about a car and that information is sold to a car company to say that I’m in the market to buy a car. There are some things that I shared, but then there are some tangential advantages that were taken out of that data, not only that information but also collecting third-party information like where we go to fill our car or service our car, or buy groceries or clothes, or apps that we use.
Shilpi: There are other things that we have not given explicit permission on to take that information, but now they are creating this 360 degree profile validating and accumulating information from multiple sources and then selling it to companies to target us in many different ways.
Coming back to the question on hand of whether we should be paid for it; it is a very messy situation and the more I read about it the more I feel that yes, we should have ownership of it; there should be transparency on what is out there on us, but at the same time if we also start trading our information, we could start going down a very bad path.
Shilpi: Let me ask you another question, how much would these companies pay for our data, if we went down that route?
11:25 Sam:
Very little, very little, I think.
11:28 Susanna:
Yeah, even if they paid $100,000/year that’s like a penny for them, compared to the billions that they make out of each person’s data. The amount that they are now giving, that they said that they will be giving, is not even at that level – it is around 5, 10, 20 or 30 dollars. It’s nothing compared to what they are going to make out of it.
12:00 Sam:
You’re right. There’s a couple of quotes I’ve read that the digital dividend could be something like $20-$50 per data set. There is value there but is it significant enough to warrant it being put in place? And yes, a thousand pounds is quite helpful I guess but is it sufficient to share data to that extent?
12:33 Shilpi:
One of the key factors to consider is that data is the new oil and it is an inexhaustible resource, so it’s unlike any other resource that is exhaustible; this is an inexhaustible resource. $100,000 is a very far-fetched number
13:03 Susanna:
I’m just putting it out there – challenging companies to pay $100,000 per person, haha!
13:14 Shilpi:
Yeah… I read somewhere that the statistics show that they make seven dollars profit out of every person after deducting all their own expenses and costs that come with it – so no, one thousand dollars, one thousand pounds is a very far-fetched number!
Shilpi: Even if that were true, we are giving them an inexhaustible resource to own it, and saying that we give them permission. There need to be really good laws in place to say that you have to pay every time, not just once. I just saw a lot of questions from Michael Novak – he seems to have some interesting points.
16:18 Susanna:
He mentioned ‘exchange for services’ – that’s what the medical industry uses now; you could be part of a clinical trial and for the time you spend there you are compensated for it, but you’re not exactly compensated for your data.
16:38 Shilpi:
I was reading that in these clinical research trials they pay different to different participants based on whether it’s a rare disease – one person’s disease may be different than the other – whether it’s a new area that they need more data on, based on age demographics whatever – so it’s very common.
In the same way one person’s data might be more valuable than another person’s data – it may be based on age, it may be based on ethnicity. So even if we come up with a number, it will be very difficult to make sure everybody can be paid a fair amount – and will that amount be a standard amount, will it be a one-time payment, or will it be an annual year after year payment? Will the data appreciate over time and will I be paid more or less based on now what my data is worth year after year? All those are very interesting points to consider.
18:00 Susanna:
Right now credit is given in the medical industry for using your cell line – there was a famous movie about it even recently.
18:10 Sam:
I think they do don’t they, I know that in health research because clinical studies traditionally attract payment, when you’re collating data in that area, that’s one of the things to consider – utilizing that resource. Obviously because of restrictions on patient data, it’s going to be harder for us to obtain that as researchers. I think that is a good thing; that should be in place. But there are models in place already to to get funding when you participate in a trial.
Michael mentioned that it might not necessarily attract a payment but there might be other things you could exchange, rather than it being funded through the dollar or pound, it would be a token for example. I know that that’s something that’s been discussed and thought about as well. It’s something along the lines of a token; I heard of tokenization and tokens and how they might then be exchanged for other services; so that’s some something that I’ve looked at recently, and I think companies have started to think about that as an alternative.
Sam: Like you said it’s really difficult to locate data when you’ve shared it – and I did think about this before; we’re looking at things retrospectively, so how do we follow the data itself, and what value do we give to it?
20:13 Susanna:
One of the interesting questions now is how do we retrieve back all the data that we have given – if I deactivate my Facebook account, Instagram, Whatsapp and just disappear off the grid, is my data also taken out? No, it’s not.
20:38 Shilpi:
Like they say, once on the internet, forever on the internet.
Hi Michael! I know you had so much to say, did you have trouble getting on?
21:00 Michael Novak:
… yes. But nonetheless! Thank you for having me on today, I was looking forward to it this week, I’ll put it that way. I’ve been working on several projects related to privacy, security and ethics for several groups, and it’s exciting because now is the time for us as a society to begin addressing this, so that’s why I was adding all those comments as you were talking earlier, because it’s very important.
21:40 Shilpi:
Absolutely. So what is a burning comment that you want to add for the discussion that we have had so far?
21:52 Micahel:
Yeah, if you don’t mind I’ll go back to a couple that I made previously. Regarding compensation – this is my experience, I don’t claim to know everything all the time, but it’s been raised by several groups that rather than pay money, what if companies gave you compensation? Meaning that, for example – you like to go to a certain well-known coffee store, here’s some vouchers.
Michael: Or in the medical field if I’m suffering from a condition, maybe I want to participate, but I want to control my data, so using a distributed digital identity system it is technically possible and it’s politically feasible to allow me to say: ‘okay Sam, I’m gonna give you six months of access to these physical attributes of me – my height, my weight, my mental condition, whatever it might be – and once I agree to that, it’s done. When the timer goes, I get to decide if I want to stay or go; I’m in control.
23:30 Shilpi:
I think what Michael is saying is what we touched upon last week – one, the user should have full control over their data, and two they should have the control of not just consenting to say yes, but also to say no, and there should be a clear sunset policy so if you give them permission to sell your data, they don’t get to keep it forever and sell it on again.
24:07 Michael:
Compensation could be something as simple as a gift certificate to the local bookstore – it’s what’s valuable to you, and what do I as the vendor have access to; maybe it’s a frequent flier mileage – it doesn’t have to be money for money.
24:33 Susanna:
Is this similar to the bartering system – are we going back to the bartering system, exchanging one good for another?
24:42 Michael:
Philosophically, yes, but it could include currency – I may say: ‘here’s this money, here’s 10 or 100 pounds’, it could be money. But the idea is – and you spoke about this earlier – how much does it cost for the vendors or the merchants or the entity to collect all that data, and how much is it worth to them – so again the answer is it depends on what they’re willing to barter it for, whether it’s a dollar, a mark, or a voucher.
The other part that I wrote in my comments is that I would let the market decide – for example, during the holiday season I imagine retailers would pay more to have access to what you’re looking for, what do you need this year, what do you need right now compared to March or April? So again, it’s not just a standard ‘okay this is the only rule, and that’s it’. The other part that I’ll bring up before I be quiet for a minute is… are you familiar with the privacy paradox? It’s the idea that when you sign up currently for a credit card or something, the companies will provide you with the terms and conditions: if we allow you to use the card, here are all the details. Most people, most of the time, myself included, look at and go ‘yeah, I’m not reading five pages of terms and conditions’ – I put it in a drawer, and then if something goes wrong I come back and say: ‘hey, why didn’t you tell me?’ They can respond with ‘well, you consented to this.’
So the idea of the privacy paradox is that even if companies with the best intents provide users with all the terms of the privacy – how I’m going to use your data, what I may or may not use it for, it’s such a large volume that it’s there but consumers won’t use it. So the paradox is: you’ve got the data, but you’ve made the decision: I’m not going to read that information even though you provided it to me. So when I’m talking about the ethical part of that, it’s still a dilemma because how do we provide you the user with enough information to encourage you to read it so that you know what your privacy rights are – how long will you have my data for, what do I get in return, etc – without giving you all the terms and conditions about the 2500 conditions that our lawyers put together.
27:30 Shilpi:
So, there are a couple of thoughts here – there are a few companies now that have started independently doing this sort of thing. Instead of letting the tech giants who own our data in some way or another put a number on how much our data is worth, there are independent third-party companies that have started platforms where as a consumer I can go and register there, and every so often they will say ‘oh you’ve accumulated 250 kilobytes of data this week, that is worth five dollars’. Do you think that is the right way to move in this direction?
29:38 Shilpi:
I mean like a user creates an account on their portal and then they will track how much information – just like these third-party cookies are tracking us, and the third-party cookies are browser-based; they will collect all the information and then they will say that this information you have allowed to be tracked, they can put a number on it and tell you how much your data is worth. So my question was: is that the right way to move forward?
30:36 Susanna:
That’s again somebody else deciding for me how much my data is worth. I can go on Facebook or Gmail and there are extensions and toolkits where I can download my own data and see how much is collected – now, there is an agency called Data C or something, and they are now going to track all of this information for me and then tell me whether I want to sell it or not sell it, and then they are going to get a rate for it. On what basis?
31:17 Shilpi:
What they are saying is that they are more transparent – that’s where they’re coming from, they’re showing you what information they collected, they’re giving you a choice of whether you want to sell this data or not, and they are giving you a price. You can’t say that you want more for it, they have decided a number saying the data that we’ve collected on you would probably sell in the marketplace for five dollars. Whether they make a hundred dollars out of it or not, we are willing to pay you five dollars for this data and then you are in control – do you want to sell it or not. That’s what Data C, and there’s another one called Reclaim – they both are doing that and I’m sure there are plenty more.
32:00 Michael:
Yeah, so I was going to say again – I’d let the market decide. It’s a valuable service, because as a user I don’t keep track of every single thing that happens to my information electronically by all the companies, whether it’s the utility, the apartment etc – so I have a choice as an individual, but the key is I have the option, compared to five years ago where you don’t even have the option. It’s a service if i want to use it; if I don’t I take responsibility; that does come with consequences both good and bad. If I use it maybe they do find me a better priced credit card for my use cases; maybe they find me better health insurance based on my needs etc. But if I don’t, that is a individual decision which I think is a good thing.
33:03 Shilpi:
I think I’m not hearing what I want to hear from each of you! We started this discussion with saying that I am the owner of my data and I should be paid something for it; then we came to the thought process that if I as an owner of this data sell it once, then I am commercially commoditizing my data ownership, and once it is sold, it will then be used, misused, sold, resold to other companies. And now privacy has been made into a commodity, and we will put a price tag on it, and whether that is the right thing to do or not.
Now the other end of that spectrum is if the tech giants aren’t making this decision of how much your data is worth, but a third-party company deciding – again, we are not going to ever be the decision makers, because then everybody will say: ‘I want ten dollars’ and somebody else will say twenty dollars or one thousand pounds, right? So I don’t think we are ever going to come to a point where the user is going to decide what that number will be – the best we can get is a choice whether we want to do it or not, and these third-party providers like Reclaim and Data C are moving in that direction, where they are telling us that we have collected this data with your permission – do you want to sell it or not? And if you decide to sell it, we can give you five dollars for it. My question was – and I did not hear an answer from any of the panelists! – is whether that is the right way to move forward, or we should just say that ‘it’s my data and I don’t want to sell it’ – each company should tell me what they have on me, and then don’t do anything about it.
35:13 Sam:
For me, if we have organizations like Data C and the others that you mentioned and you’re browsing online at a retail store and the cookies are tracking what you’re looking at and what your preferences are, I think there’s an assumption that from the user’s perspective that there will be some data collected, and I think it’s at that point that the individual has to decide that that’s okay, and there should be a facility there either through a disclaimer or through policy that covers that and reminds the individual that they are being tracked and that data is potentially going to be used for marketing purposes. Adding a potential additional bonus on top; if there’s a financial gain then that might be an incentive actually for a lot of people; it gives them a little bit more power back. It’s not the whole solution, but I think it’s an option definitely.
36:45 Shilpi:
I think we are still beating around the bush here – let’s go with a yes or a no!
36:47 Sam:
Yes, I think it’s a good idea.
36:50 Susanna:
No. Whether it’s a third party, the retailer themselves or whatever it is, why not go with a model where I pay for their services? If, say Facebook goes into that model where they let me take a monthly subscription of $5 or $10, I’m okay with that.
37:13 Shilpi:
That’s where the research comes in – if that happens, they will make a fraction, a very small fraction of what they’re making today; they will first of all lose a lot of their users, and they are making billions out of the information from targeting ads to us – that they cannot do.
37:47 Susanna:
This also comes down to the poverty line, and that people in different countries don’t have the same economic opportunities, so they cannot afford five dollars a month to go on Facebook – they have other priorities for that money. Maybe it’s better for all of us to move in that direction.
38:20 Shilpi:
There is a lot of value in these services – I’m half way across the world from where I’m from, I’ve left that world for almost half my life, but I’ve been able to connect with my friends there. When I go back to my native land and I get together with them, that’s a wonderful feeling, to be able to reconnect with your loved ones, your friends and family all across the globe. With subscription… who knows?
39:00 Michael:
I agree with both of you because… assume for the moment that third party, whomever it is, says they’re going to manage it; you all now have to pay five dollars or whatever the amount is – but I would push them and say that’s nice but why don’t you pay me? Every time I use your service I’m giving you a piece of my location; my time – how much time was he on, how many times did he speak to his friend in India? They’re getting data from me, so rather than me have to pay a subscription I would have them pay me, because they need me more than I can do without them. We have something here called a telephone, you may not have heard of it, but I can talk to anyone and I pay a telephone bill for that. So while we become accustomed to Zoom, I really believe it needs to be that the individual has the choice and that they could be compensated by vendors and third parties for that opportunity to use their services, because then they do collect data on us anyway.
40:28 Shilpi:
The third party is saying that it’s not a one-time thing – so every week they will pay you based on how much information they have collected – that is my understanding of what I read without signing up on their platform as a user. So it’s something similar to what you’re saying. I think this is a very fascinating discussion, and we could keep discussing this on and on and there wouldn’t be any conclusion to it! I think for me, I feel like even the third parties are not reliable in some ways – what we should have is the model that they have chosen, but I think the middle path – the Buddha’s path! – would be that Facebook decides to pay us, but keeping everything that these third parties are doing, it tells us transparency wise: this is the information I collected on you this week; that is worth five dollars to me; do you want me to sell this information or not – if you want you can delete any information on yourself at any point in time, and I’m okay with doing that.
Not just because once you’ve submitted something or shared something I will hold it forever and use it as I will; I think the middle path would be instead of us paying for subscription to Facebook and lose the connectivity of so many people, Facebook and Google and all the data lakes should be the ones to adopt the model of the third party platforms. I think that is the best way to move forward with this. Instead of us coming up with the platform; instead of the consumers coming up with the number; instead of the third party coming up with the number. And it should always be incremental and the amount should be subjective every year or every month based on what activity you did; how much data was collected; what it’s worth. The transparency and the trust will only be there when we move forward in this direction. What do you think?
43:02 Sam:
That’s a good point. Incrementally you review the data that’s stored, you agree to that and if there’s an option for you to then benefit from that as a consumer then that would be a move forward towards trust and transparency, I think. Consent is obviously the key thing too.
43:32 Shilpi:
And then ‘do not sell’ is an option – do not sell, delete my information; all of those, we should have the choice. So I think this is a middle path of all of us – Susanna said it’s my data, tell me what you have, give me the right to delete it; Sam wanted a third party – so I think with all of our views, I feel like this would be a really good way. At least with Google and Facebook. Sam you mentioned that if you are browsing, then they are going to collect some data on us – that is what is bothering me;
Shilpi: We have come to the point in society where we feel like this is the norm, this is how it’s going to happen – if you’re going to browse on the internet, information is going to be collected on you, and that is okay, that is normal.
I think that is what we have to now change; we have to say that no, that is not normal – I do not want my browsing history to be tracked with a cookie, or if you are going to track, show me what you tracked, and let me be the decision maker of whether I wanted it to be stored, deleted, or paid for. With that, I’m going to wrap up today’s discussion, I think we really hit some good points, food for thought really for ethics-first-minded leaders; leaders who have ethics in their DNA and who are always trying to make the world a better place. We are going to take a two week break for the holidays, so thank you for tuning in and happy holidays from the DataEthics4All entire team. Thank you Michael for joining us today, thank you Sam and Susanna, not just for today but your support for throughout the year, and Michael you too, you are an active community member and you’ve made DataEthics4All what it is today, thank you everyone. Happy holidays!
Join Us in this weekly discussion of Ethics 1stᵀᴹ Live and let’s build a better AI World Together! If you’d like to be a Guest on the Show, Sponsor the Show or for Media Inquires, please email us at [email protected]
Come, Let’s Build a Better AI World Together!
Share:
Written by:
Tags:
``The merit of this is that we can get to these violations or ethical problems sooner`` ~ Shilpi Agarwal.
“I think the bounty system is less damaging and it’s more beneficial. It’s one of the most practical approaches”
~ Shilpi Agarwal
TEST
“Everyone can find a vulnerability that is against their own community, and bring that to the tech companies attention”
~ Susanna Raj
Section
Talk Summary
DataEthics4Allᵀᴹ brings this Series of Weekly Ethics 1stᵀᴹ Live Talks for Leaders with an Ethics 1stᵀᴹ Mindset. Food for thought for Leaders who put People above Profits!! Come, join us for this lively and informative weekly discussion on how to create an Ethics 1stᵀᴹ World with Ethics 1stᵀᴹ minded: People, Cultures, and Solutions. In this Live Talk, we discussed Ethics Bounty Systems.
1:12 Shilpi: Thank you for joining us for this episode of the Ethics 1st live, where we bring food for thought for ethics first leaders, or leaders who put people above profits.
1:24 Shilpi: So today’s topic is a very interesting topic, it’s about the ethics bounty system, so let’s start with what an ethics bounty system is.
2:42 Susanna: Basically, the way I understood it is it’s just basically hunting for bugs, bugs in the code or bugs in a program, or a public website or in an AI model. I mean, it started with websites in the past, and now we’ve seen the AI models too, so you find a bug, or you find a vulnerability in that, and they give you a reward for it.
3:05 Shilpi: Yes, and my understanding is that too. So this ‘bugs for code’, to find bugs in the code, has been there for some time, but now they’re bringing it into the AI systems.
3:21 Shilpi: With AI systems, until you deploy them, you don’t know, not really what bugs its has, but the way it is affecting the audience or the people that it was intended for, and it can cause a lot of harm, as we both know, to the projected audience.
3:42 Shilpi: You cannot know that until you have different perspectives from different people, and so that’s why there is something called the ethics bounty system, where tech companies are coming up with ways to encourage people from different socio-economic backgrounds, gender, races, and just everyone that the software, or the app, or the platform, or the toolkit is intended for, to test it out and report bugs.
4:18 Shilpi: Bugs in terms of, you know, it’s not, ‘the algorithm is not right, the data is incorrect’, it doesn’t necessarily mean the code in this case, it’s about the AI system, right? So why do you think it’s important to have such a system in today’s AI world?
4:37 Susanna: I mean, there are lots of reasons given for that. When you try to find a bug or you try to find an ethics violation from within the team, you have a certain bias.
4:48 Susanna: Just in the same way we are not able to catch our own typos, we cannot catch our own mistakes because we are so embedded in the process itself that we can’t even see what our vulnerability is, and who the other group is that we are discriminating against.
5:07 Susanna: So, giving this to an outside group, or a group of individuals who don’t have that same loyalty to the group means that they’ll be able to actually find it quite easily. They can also be very open and transparent in how they attempt to bring this to our attention. Another great impact that I see is that because you are opening this up to a wider diversity of people, it’s not just, ‘I’m just opening this ethics bounty to only the USA’, it’s all over the world. So, everyone can find a vulnerability that is against their own community, and bring that to the tech companies attention. So I think this is a great idea.
5:47 Shilpi: Yeah, I completely agree with you, and just like you said, when this is being developed, and these AI systems are being developed, nobody develops them with a bad intention, right? It’s sometimes not even possible to think of all the scenarios in which it could create harm.
5:49 Shilpi: So having these different voices, and backgrounds, and diverse voices to be able to contribute to the project that will end with a bounty, it encourages people to spend time on it and find ethical violations.
6:20 Shilpi: So, the merit of this is that we can get to these violations or ethical problems sooner. And then instead of going through the approach of announcing it on social media, or taking the legal route, people can actually reach out to the tech companies themselves and report them, and then the tech companies can take action.
6:45 Shilpi: So it’s a win win, right? Instead of having a PR nightmare, people are helping them to find the bugs, helping them to solve these problems, and reporting it from the diverse backgrounds that they come from. So yeah, I think it’s a great idea and more of it should be implemented. What are some of the great tech companies or examples that you have seen in terms of adopting these ethics bounty systems?
7:22 Susanna: I think pretty much all the big companies now have a programme like this, including Facebook, Apple, Microsoft, Google. I mean, they all have an ethics bounty system, and Twitter is one of the major ones recently, but I think they all have this program in place.
7:40 Shilpi: Yeah. And so Twitter, their meta team, which is their machine learning, ethics, transparency and accountability team, created this recent AI algorithm bounty, and I was reading through this report about one of their algorithms that was initially for the cropping scenario of how image cropping is done, and somebody brought it to their attention that it was favoring the white faces more than the darker ones.
8:08 Shilpi: So even with Barack Obama’s photo, they proved that he was being left out of this frame. But as they created this bounty, and I read through this research, where the prizes were given, and there were so many other issues that came up, and they were awarded for those that were not even intended to surface, nor would they have surfaced unless this bounty system was created.
8:36 Shilpi: So I think it’s a wonderful idea, and now Google has also started implementing it for the Google Play Store, right? So it’s not only the code that they are implementing, they are also providing a bounty for anybody who is able to find a bug in any of their Google Play Store apps, which is the next step.
9:06 Shilpi: Apple has been doing it too – they have these rules for their normal code, which is that you must be the first to report it, and you must clearly explain and show evidence for it, and you can’t disclose it publicly unless Apple gets a chance to fix it, and you can get a bonus if the company reintroduces a known problem and a new patch.
9:30 Shilpi: All of these things are already there. They can easily take this and implement it for an ethics bounty programme for their AI systems, which makes sense. You can’t publicly slash them on social media, tarnish their reputation and get the bounty, right, you can’t have everything – your cake and eat it too. So you first have to report it to them and give them a chance to fix it. Do you want to add anything to this?
10:01 Susanna: So yeah, definitely there is one aspect of that. I mean, they get to see the vulnerability or the bias in the system, and they get to fix it.
10:12 Susanna: But I’m also wondering was there a major ethical violation because of this vulnerability? And did they quickly fix it or patch it up? If that’s the case, does the public get to know the impact of it from when it was already launched? Do they get to know the impact of it? Is there transparency around it?
10:33 Shilpi: That is a good point. So what you’re trying to say is that if somebody finds a vulnerability, and they report it directly to the tech company, and that tech company fixes it, will there be a public report after that? Or will it be just a hush-up and it will be swept under the rug?
10:48 Susanna: Yes, because it could have already impacted some communities – it could be that my data was breached, and it was sold to somebody, but they fixed the vulnerability so I didn’t know about it. So, where is the transparency there? And does the bounty system cover that? Is the system covered?
11:09 Shilpi: That’s a good question. And I think this could be a great question for our audience, as well as some of the tech companies who are coming up with such bounty systems. I guess what we are trying to say is, yes, this system works – It’s great that you are asking for our community help by crowdsourcing to find the problem, right?
11:33 Shilpi: So that is great first step, but then let’s go one step further, let’s not just sweep it under the rug, and because you say, ‘Oh, we’ll give you the bounty and you can’t say anything about it until we get this fixed’, how will this person who has raised this flag know, first of all, that you have fixed it?
11:52 Shilpi: Will you make a public statement about it? Will you let that person know privately that you’ve fixed this and that this is what you have done? And then will you release a public statement announcing to the world that this was a vulnerability that one of the people or some people found and these are the steps we have taken for it? And these are the communities affected and going forward, this will not be done?
11:53 Shilpi: So there needs to be a clear, closed-loop process for this to be a foolproof method.
12:22 Susanna: Yes, I do agree with that. I think that is the next step. I mean, this is a step in the right direction, but we need to move a little bit more further to help bring transparency to any process. Mistakes can happen, I don’t believe that we can be a society without mistakes, in building anything. We build bridges and even they have faults and they crumble and fall down, mistakes happen anywhere.
12:49 Susanna: The process and the transparency around it is what an ethical community, like our community, would demand.
12:58 Shilpi: Yes, and speaking of which, what if we started a database and asked people to report any of these ethical bounty system’s, especially for AI, that they find and also any vulnerabilities that they find?
13:18 Shilpi: I know there are some who do this already, but what if we could do something where people feel comfortable to report this, and then, we are able to work with the tech companies to figure out a way to make sure that this has been resolved.
13:33 Shilpi: So, an independent body that is saying exactly what you touched upon – it cannot just be reported to them and be done with, in that case we don’t know if any steps were taken after that.
13:46 Shilpi: So an independent body like DataEthics4All, per se, or any other independent body, would be the mediator to understand, you know, what were the steps that were taken and were they enough, and act as kind of a regulatory body to understand if it was done exactly the way it was supposed to be.
14:10 Susanna: I think that would be really great to have, because right now we have AI incident reporters and databases that track vulnerabilities and incidents or adverse impacts of AI. There are systems that track that, but there are no systems like this.
14:26 Susanna: There is a bounty hunter, and they find a vulnerability, but then what happens to the impact prior to somebody finding this vulnerability and what happens after that?
14:43 Susanna: If an independent organization can go and build the database or bring some transparency around it, that would be a great service to the public.
14:52 Shilpi: Alright, so you second that we should move in that direction. The last question for today – so you know how in software code, and I know I’m a software engineer and married to another one, there’s always these bugs that are under critical issues that you find in software development. You put them under critical issues, and there are different priority levels, red and orange zones and all of that, right, it’s all color coded, and it’s all different priority levels, and it’s supposed to be critical.If there is a bug in the code, it’s critical.
15:33 Shilpi: So, do you think it should be grouped as a critical issue if there is an ethical violation in an AI system?
15:58 Susanna: Yes, I think it should be. I think we should have a classification, like that, that tells us what are the most adverse impact ones, what are the most critical, and go down the list to the least impactful. Yes, that would be a great idea.
16:14 Shilpi: Yes, I think so too, because we may think that this code is not creating harm, but the bias in AI can cause harm to so many different protected and marginalized communities and people, so we need to make sure that this doesn’t happen. We are all looking for tech regulation, but that’s going to take time. As you know, it’s not a foolproof method to catch everything.
16:42 Shilpi: So, the ethics bounty system does not rely on either bashing the companies on social media or filing for a legal battle, or waiting for a new regulation to take place.
16:58 Shilpi: I think the bounty system is less damaging and it’s more beneficial. It’s one of the most practical approaches to regulating this than we have ever seen and used.
17:11 Shilpi: Like you touched upon, it’s a global system that can be used in non-native English speaking countries where there are things that happen that are swept under the rug, or because it’s not predominantly affecting the United States, not much action is being taken against it. So if we have an ethics bounty system, and if we are able to classify them as critical issues, things that people have crowdsourced as a community, across the globe, I think that is a great step towards moving forward in building the next generation of AI systems that are ethical and transparent, and making sure that the tech companies are accountable. Is there anything you would like to add, Susanna, before we wrap?
18:03 Susanna: Nothing, I mean, I think this is also a call for action – so anyone in the audience who wants to join us in helping build this thing, you’re welcome to come and talk to us.
18:14 Shilpi: Yes, absolutely, and a great call to action, Susanna, thank you for adding that we are always looking for very dedicated and passionate volunteers who are passionate about this mission, who are passionate about the problem and who want to bring a solution. We are not the type who will just talk about the problem, we are solution focused.
So we just touched upon one of the solutions that we would like to implement, and we would love all of your help in coming together as a community in taking this first step. So we invite you to join us, and join us in creating a better ethics first world. Thank you, everyone.
19:05 Shilpi: To join our community, its DataEthics4All.org. Please join our community, and join us for these weekly live talks when we bring food for thought for ethics first leaders every week, Thursdays at 3pm Pacific.
Join Us in this weekly discussion of Ethics 1stᵀᴹ Live and let’s build a better AI World Together! If you’d like to be a Guest on the Show, Sponsor the Show or for Media Inquires, please email us at [email protected]
Come, Let’s Build a Better AI World Together!
Share:
Written by:
Tags:
“There are people in our community who do not understand how the technology works, but trust the technology so much – and I think that is the biggest vulnerability.”
– Susanna Raj
“If we are to rely on tele-health apps, it might be that we’re not only using it for diagnosis but we’re actually using it for informing the dosage as well, and that could could put us at risk.”
– Sam Wigglesworth
Talk Summary
DataEthics4All brings this Series of Ethics 1stᵀᴹ Live Talks for Leaders with an Ethics 1stᵀᴹ Mindset, those who put People above Profits.
In this week’s discussion, we explore ‘The Ethics of Healthcare Apps. What are some Regulations when it comes to for-profit healthcare apps? Vulnerability, Trust, and Manipulation: Key Concepts for the Ethical Evaluation of For-Profit Health Apps, the important distinction between Supportive and Manipulative Digital Health Environments, as well as Health Apps and Unfair Commercial Practices.
We started out by discussing some of the key regulations are when it comes to for-profit healthcare apps.
Transcript
00:32 Susanna Raj:
Hello everyone, welcome to our Ethics 1st Live talk, where we come every week and discuss lively topics surrounding the topic of ethics and how Ethics 1st organizations, applications, companies, people and products can work together to create an environment where ethics is at the forefront of everything we do and think about. Today I am going to be the one hosting – usually Shilpi does this, she had to leave for another event today. Here with me is Sam, and you all know Sam, she is a member of our leadership team and a teacher of languages – welcome, Sam.
1:22 Sam Wigglesworth:
Hi, good evening. It’s great to be here for another Ethics 1st Live event, and the topic’s going to be really fun to discuss.
Sam: We’re focusing on the ethics of applications in healthcare, and we’re going to be looking at regulation, what applications are out there, the vulnerabilities around them and how they could be used in a supportive way – or not, as the case may be!
2:01 Susanna:
That is the topic; we all use healthcare apps on our phone, and even on our watches now – some of you may own a wearable watch like an Apple watch or a Fitbit or any of those. Healthcare tracking apps are on our wearable devices, as well as on our phones, and on our laptops – there are so many things that can track your steps, your activity level, your heart rate. My mom uses a blood pressure machine; that brand has its own app, and it seems after we upgraded to the new IOS, data was being pulled from the tab into the healthcare app and it was automatically gathering all the data from there. It was a little creepy! Then you had to go back to that app and take out that information because it was tracking her blood pressure levels. They have given you all those options where you can and cannot give access to other apps; the other medical apps – but to me this is an area of concern, because now my parents’ medical institution also uses an app to schedule all their appointments, which have been video appointments the last two years. So that app is also there; and Apple is giving me a list of all those apps in the Apple healthcare record and asking, do you want to connect all the data from all of this? I’m just wondering what are the regulations around healthcare apps – Sam, what do you think?
3:52 Sam:
It’s a really good point about monitoring patient data. From my research, I’ve not found that much around specific regulations that govern the data that’s captured on applications, particularly monitoring health data and patient data.
We know that there’s a significant amount of legislation in place in the UK and Europe when it comes to data protection – the Data Protection Act in the UK and GDPR in the EU – but I feel from what I’ve seen that there isn’t significant rigorous legislation that covers this, and it’s a grey area.
Sam: While we focus on security and data security, we’ve actually focused very little on bioethics and data. There’s a gap there, I think.
4:56 Susanna:
That is what I also found out; there’s the GDPR as you said, and all of those regulations cover personal data and privacy, but in terms of healthcare, these healthcare apps aggregate the information they have on you to create a health profile of you.
They are accumulating and aggregating information from different sources to say if you haven’t walked this many steps; if you haven’t slept this many hours; if you haven’t drank water, if your blood pressure is low – whatever it is. It’s giving you information and trying to tell you whether you are a healthy person or an unhealthy person or on the borderline, so it’s actually giving you medical information; medical feedback.
Susanna: That is such a very concerning thing to me, because if I am getting this feedback, I may decide to give it the same validity as a doctor or a health institution – many people do that, and that to me is very manipulative in a way; it is not actually very supportive of me.
I think we have a few comments here – there’s a LinkedIn user saying there are examples of sensors in your shoes also sending data – oh my goodness, shoes! I haven’t seen that, but yeah, that could track how much pressure you are putting on the ground and whether you are using your heel or the front of your foot – I could see use cases for that. People who walk putting more pressure on their heels may not be walking at the right posture, and all of those things are there – but what I am concerned about is how much this feedback influences us as individuals where we are internalizing all of this information and thinking that this is validated information coming from a knowledgeable entity like a physician or a medical institution. That to me is the point that requires more regulation.
We have another couple of questions that Shilpi usually has written out for us – what are the key concepts of the ethical evaluation of for-profit health apps? So, in terms of for-profit health apps; all of them I think are for-profit, I don’t want to name all names, but all of those health tracking apps and devices that are being introduced into the market are all very for-profit; our medical institution is also for-profit – that is my opinion, it’s not a non-profit thing! But we have so many stringent regulations on how medical services should be distributed, but that kind of regulation is not there for the for-profit health apps. What do you think, what are the vulnerabilities?
8:54 Sam:
I completely chime with what you’re saying. I think from a medical perspective if you’re working in the public sector, data is very much secured internally if it’s patient sensitive, but when it comes to commercial apps the vulnerabilities exist for users across different age groups.
Sam: I think one of the key vulnerabilities is that actually as users we all have apps on our phones, on Internet of Things devices, that we use on a daily basis that are stored on cloud servers through our mobile devices, and they’re at risk – that’s the vulnerability.
They could be exposed (we’ve talked about this before in previous discussions) to malware, or somebody may be having access to that data if they wish to. We do often find that we lose this information. IoT devices can cause risks and harms, and we’ve got to be aware of that and also the fact that data could be then utilized by third parties without permission. They’re the main vulnerabilities. Particularly when you talk about your parents as well, I know that there’s tracking of data of vulnerable people and patients, and I think we just need to be very careful that we are aware of just how much is being utilized and stored.
10:38 Susanna:
One critical area for vulnerability is that of data being leaked out and being violated, but then the other vulnerability that I see as a user who lives with elderly parents is that they trust the information so much.
They trust it so much more than I do! When your Apple watch tells you that your heart rate is going up or is going down, they trust that more than what they are actually feeling. They also feel like ‘oh, something is now wrong with me’ – so it’s like bio-feedback to them, without knowing that it could be a glitch; it could be that these devices are not so accurate in how they track movement; when you move your arms up it can show a spike in your heart rate. There are people in our community who do not understand how the technology works, but trust the technology so much – and I think that is the biggest vulnerability. We have another LinkedIn user here who is saying that ‘the consent comes at device setup, but it seems genuine consent is unrealistic – what are you going to do, say no and be unable to use the device?’ Yeah, of course, that’s the thing: it asks you to opt in or opt out, and when you opt out you are essentially locked out of the device, you are not allowed to use it.
12:37 Sam:
It’s a very good point that you made. I read a really interesting paper earlier from NIH (National Institutes of Health), and they were discussing the fact that in the past what we often did was search online about our health issues, but now we have an application that replaces that. But obviously with that comes the capture of data, and we have a significant number of data points now, because there are many apps. There’s a market, as you said earlier; there’s a commercialized arm to it, and I think we have to be very aware of that.
Sam: We want to diagnose things, we want to know a little bit more about our health, and I think applications and searches online sometimes become almost like advice. The real danger is if we take that as a diagnosis and it’s not accurate. We have highly trained qualified professionals, and that’s not something we can replace.
14:09 Susanna:
One of our commenters is saying that ‘the terms and conditions generally say ‘we are not medical providers and this should not be treated as medical information’, but the thing is when you see this information then you go and bother your medical professionals, and you go with a false positive and you overwhelm the system’. Then there is a cascading effect that comes from not having that trust – my device says this but you say it’s okay to ignore that – what is happening to me? All that stuff now happens a lot. Also, there is manipulation that goes back and forth, because this is a predictive analytic which is telling you that based on this data, we are predicting that this is going to happen; or if you don’t accumulate this many hours of sleep, this is going to you know affect your mental health or your physical health – that is another level of manipulation, I think. This is part of surveillance capitalism – that is a term that is being used now to say that there are all these healthcare for-profit apps that are out there with capitalism in mind. That is the manipulation to me; I am being manipulated by all of these data points; instead of me using the technology, the technology is telling me how I should shape my day – and that is that is a manipulation, right? And that is psychologically changing the whole community, I think. What do you think? Do you feel you are being manipulated by all the healthcare apps – is it just me?
16:01 Sam:
No, I think you make a really good point. You mentioned surveillance capitalism, and we all know well Zuboff’s publication on that, and I think it’s important to understand that as with social media, our data is a commoditized good; I do often feel that when I use a wellness app or other applications they can be sometimes a little intrusive, and I think you have to almost start managing it. It can become a little bit addictive where you start to track your activities more based on feedback, and I think it can affect your behavior. It’s a really good point that we shouldn’t be using that as a diagnosis tool – we know that sleep is good for us, we know that eating well and drinking lots of water is good; we need to be aware of our own health, but using these apps is not a replacement for that. But yeah, you do find that it will sometimes change the way that you think about your own health, and that’s not a positive thing.
17:39 Susanna:
There is a LinkedIn user asking a question – will the apps sell your data to insurance?
17:46 Sam:
For all third parties, if your data is available to be sold, then there might be a market there, What do you think Susanna, is it something that you feel is a risk?
18:13 Susanna:
That is potentially a risk, and there are no laws in place.
Susanna: The HIPAA (Health Insurance Portability and Accountability Act) protection laws say that you cannot share this information to your insurers – but what about apps that are being developed and put on the app platform by insurance companies?
Susanna: I don’t know whether that is another area that we need to look at, because I do know that in America here we have Kaiser, we have Stanford, and all of them have developed apps, and they are putting them on android, apple, IOS platforms. But will personal data be actually connected to your medical record? I think the answer is no – I think that at least is still good, but it’s a marquee area that you could change. There is another comment that I think was related to HIPAA – ‘HIPAA requires some notice, but there is not a lot of genuine thought around whether the info in the notice is actually helpful or represents a choice – have you ever been to a dentist and said “no thanks, I don’t want to sign to say I saw the policy that I didn’t really see”‘.
Susanna: Yeah, with all those consent forms, I really doubt that people are actually paying any attention. What I am worried about is the behavioural impact of all of these healthcare apps.
20:18 Sam:
I would add to that: I do think often when it comes to consent – and we talked about this before – whether it’s surfing online on a website or downloading an application, I do think a move forward would be to be quite explicit about what data would be shared with that particular third party. I think having a disclaimer available that’s really clear will give us that transparency which is what we want. You’re right, terms and conditions are not clear and we do often tick without reading.
21:05 Susanna:
And we don’t even check it when we’re at the doctor’s office – if you are in a doctor’s office you are already under stress, I don’t think you are bothering to read that document very well! A LinkedIn user is saying: ‘do the kind of people who use such apps have a higher likelihood of being active/otherwise; therefore not representing the general population and setting incorrect metrics for future use?’ Yes, that is convenience sampling; a self-selected population.
Susanna: Let’s say I am going to install a healthcare app that tracks my steps that’s available to everyone, but I’m somebody who’s more worried about my health – I am self selecting myself for the study. I might be actually giving you the wrong metrics, because not everyone who is leading a sedentary lifestyle installs that step checker.
Also, the app itself manipulates you to become more active. Here’s my personal story: my step tracker tells me that in 2020 I didn’t move at all! That was when the pandemic hit. I’m wondering whether that is reflective of the general population, I don’t have that aggregate data. When this tells me I didn’t move at all, I tend to feel like: ‘Jeez, I didn’t move the whole year, what was I doing, sitting all the time?’ But I don’t know if that was that same for the entire world; probably everyone was more sedentary. So it is actually making me feel a little guilty but if I had that aggregate information maybe I would not feel so guilty.
23:40 Sam:
I do think though that with particular applications, whether it’s your Fitbit or your Apple watch or whatever, you do find that the data is presented to you in a way that is often going to try encourage you to be more active. I do often feel that you do get put under pressure a little bit, and you don’t need that when you just want to just go out for a walk and enjoy being outdoors.
24:26 Susanna:
Yeah, if your goal is 2000 steps and you see you’ve only done 1500, you just run around for another minute just to get it to that arbitrary number, without actually making sure you enjoyed the walk – that’s enough, why am I trying to set to an arbitrary number now? Another LinkedIn user is noting here that a friend identified a trend where his blood pressure rose every day around the time he checked his blood pressure!
25:17 Sam:
Yeah, that makes sense. You do find that during holidays when you might be more sedentary and not as active that you’re not checking as much, you don’t see yourself looking at the latest feed – so it’s good to sometimes switch off from that and take a take a break from it.
25:47 Susanna:
There’s actually a well-established finding that in doctor’s offices your blood pressure is high – they actually test you twice or three times if it’s too high; for my mom it’s very high. That ‘white coat syndrome’ – even after coming to the doctor’s office and relaxing there, she would get that high blood pressure show up.
Susanna: That is a common trend for most of us, so I think now during Covid we all have not only a blood pressure machine machine, an oxymeter – it looks like a doctor’s office now, and we get into this craziness thinking ‘oh, I can find out what my oxygen saturation is!’ but in reality it’s better to see if you are a healthier person, and if you are able to breathe and do all of that then you don’t need to check your oxygen.
26:50 Sam:
Yeah; I think having something that can give you a little bit of information on the number of steps you’ve taken is okay, as long as you have that information about general health. You can go out outdoors for example and have a break without having to use an application to do it.
27:45 Susanna:
So what do you think is an unfair commercial practice when it comes to healthcare apps?
27:54 Sam:
I think an unfair commercial practice might be your data being sold to a third party because there’s a market value and that being then used to diagnose things. Certainly unethical in my eyes – our health data should be primarily protected. We talked about bio-feedback earlier, but the data that’s tracking us could be utilized to other things, not just for marketing purposes, but also to change the way that we behave.
28:54 Susanna:
I think one area where I hope it’s not coming into practice is the area of the pharmaceutical industry being tied to the healthcare app industry.
Susanna: Right now we have that on the televisions – there’s a lot of ads here, I don’t know how it is in the UK – but here all the new medications will be first shown on the TV. If there’s a new medicine for diabetes; if there’s a new beta blocker, there will be a very expensive ad campaign for it showing how it is going to help you improve your life. It has a story-like presentation and appeal; it almost looks like a PSA and then at the very end in a very fast, 2x speed paragraph they will talk about all the side effects of the new drug and also the unproven data points of that drug – but that comes at the very end, and it’s very fast so you can’t even really grasp it. The whole ad is so melodramatic and you feel like you will have this glorious life if you take this new drug, and you will be relieved of your symptoms. That is there in the television industry now, but what I’m wondering is: what if all these healthcare apps have a tie-in with the pharmaceutical industry? They could market it directly to the people without the middle man of the physicians. I don’t know if it is there already – I haven’t seen any example of that in the healthcare industry, but it could be an unfair healthcare practice, in my opinion.
30:50 Sam:
I recognize that, definitely. Dosage is one thing that was picked up earlier by one of the papers I was reading – if we are to rely on tele-health apps, it might be that we’re not only using it for diagnosis but we’re actually using it for informing the dosage as well, and that could could put us at risk.
31:22 Susanna:
Mahesh R. raises an important point here, they say: ‘I think they might do’ – in response to our prior discussion about apps selling information to the insurers – Mahesh thinks they might do that: ‘taking away the private information and sell just the metadata’. What do you think about selling just the metadata – is that okay? If it’s not individually connected to you, would it be okay to have this information sold to an insurer, and the insurance company is making an aggregate decision based on that? For example, your geographic area – would that be okay? I don’t think so.
32:23 Sam:
This is a really interesting discussion; first of all: metadata, we have to define that as opposed to PII (Personally Identifiable Information), which is absolutely out of bounds. What is metadata? We’ve discussed before – it could be not just names and ages, but also other demographic information, and that could then lead to targeted advertising; products being targeted to you that you maybe don’t need or want. It’s an additional stress, particularly on vulnerable people, and if you haven’t got the right information to make the decision it’s a lot of pressure. We’d have to define what metadata is, but certainly we have to be very careful.
33:14 Susanna:
And it could be from a very low sample size, and you could be making this generalized predictions that may not generalize to the entire population, so those kind of things are there in the use of metadata, but unless your metadata has a very large sample size, on a national or a global level, I don’t think so. I don’t know if they do that – that is something we’ll have to look into.
Susanna: But I think as of now from what I read in preparation for this talk, GDPR and the regulations that are here in America do not allow healthcare apps to sell these data to insurance providers – that’s the conclusion I came to, but I could be wrong.
Susanna: If somebody has more information on any of these topics, please feel free to come and let us know! You can reach us at https://dataethics4all.org, and you can even reach us at all of these channels – LinkedIn, Twitter and Youtube, come join our community and let us know how we can use your knowledge to make sure that everyone is well informed on all of these topics. Thank you for joining us, and thank you for a very engaged audience here!
35:20 Sam:
Thank you all for joining us for this particular talk, it’s been a really fruitful and really interesting discussion. We’ve got lots more to talk about, so please join us come to our community, join us as a member and go to dataethics4all.org if you want to find out a little bit more about what we’re doing. Thank you everyone!
Join Us in this weekly discussion of Ethics 1stᵀᴹ Live and let’s build a better AI World Together! If you’d like to be a Guest on the Show, Sponsor the Show or for Media Inquires, please email us at [email protected]
Come, Let’s Build a Better AI World Together!
Share:
Written by:
Tags:
How Can Tech Giants Using Biometric Data Be GDPR & CCPA Compliant?
RESEARCHER
Humairaa Patel
PRINCIPAL INVESTIGATORS
Shilpi Agarwal, Susanna Raj
DESIGNER
Ayomikun Bolaji

The guide provides advice for tech companies on how to become GDPR and CCPA compliant as well as recommendations on how to further enhance the ethical use of data in line with the 12-pillar framework outlined by DataEthics4All.
The focus is on the use of biometric data by the five largest technology firms: Facebook, Amazon, Apple, Netflix, and Google. The guide aims to inform tech firms of the steps they should take to be legally compliant with regulations (GDPR) and state law (CCPA) as well as raise awareness for customers about the rights they are entitled to exercise as data subjects. DataEthics4All recommends tighter rules, particularly in the event of a breach where existing GDPR regulations allow firms 72 hours to inform subjects of the breach without any rules on subsequent action.
DataEthics4All believes it is important that GDPR rules require firms to issue clear action and notices on what they will do to resolve the breach and/or compensate affected consumers, particularly in the case of biometric data.
Contents.
Executive Summary.
GDPR vs CCPA.
GDPR is a transnational measure.
GDPR has a Global effect.
Both GDPR and CCPA aim to empower consumers over their own data.
Data encryption is not mandatory for both GDPR and CCPA.
GDPR covers data privacy at the consumer level including 3rd party data providers who sell data for marketing such as marketing research, mailing lists, etc.
Data breaches and GDPR violations may result in financial penalties equivalent to four percent of the company’s annual revenue or approximately $20 million.
In Europe, they can begin with the determination of companies engaging in risky practices.
CCPA is a state law.
CCPA applies to firms operating in California or use the data of Californian residents providing they meet the three requirements.
Both GDPR and CCPA aim to empower consumers over their own data.
In CCPA violations, companies can expect a maximum of $7,500 per incident, but there is no limit on the number of violations that can be assessed.
CCPA focuses more on the first party owned data and not necessarily 3rd party data providers.
Data encryption is not mandatory for both GDPR and CCPA.
In California, incidents are considered to start at the time data is breached.

Readers of this guide will be able to see how the GDPR and CCPA work within the DataEthics4All framework.

Readers will be able to see GDPR and CCPA rules for biometric firms.

The guide includes DataEthics4All’s recommendations on where the law needs to extend further.

Issues with the GDPR and CCPA rules, where it doesn’t go far enough.

Recent trends in Big Tech firm fines.
Guide Outcomes.
Data Privacy/Security.
How can companies preserve Data Privacy?
The GDPR article 25 places responsibility of Data Privacy with the data controller. When processing data the GDPR requires implementation of appropriate technical and organisational measures such as pseudonymisation and to implement data-protection principles, such as data minimisation, as well as integrating the necessary safeguards into data processing.
METHODS TO DO THIS ARE:

THE GDPR OUTLINES MEASURES TO ENSURE SECURITY:
1.
2.
3.
4.
Security of processing data must be ensured, particularly in biometric data. This is because once leaked, the associated risk of data misuse is extensive as hackers can gain valuable data unique to individuals. Unlike passwords, biometric data cannot be changed and therefore leads to the possibility of people’s personal identity being in constant jeopardy.
CCPA Protection
Under the CCPA consumers have the right to sue over a loss of privacy resulting from a data breach.
Notification of a Personal Data Breach To The Supervisory Authority.
The GDPR allows firms 72 hours after having become aware of a breach to notify the supervisory authority.
In the event of a breach the controller/processor must:
1
Describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned.
2
Communicate the name and contact details of the data protection officer or other contact point where more information can be obtained.
3
Describe the likely consequences of the personal data breach.
4
Describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
Communication Of a Personal Data Breach to The Data Subject.
If the breach results in a high risk to the rights and freedoms of natural persons, the controller must communicate the personal data breach to the data subject without undue delay. The company must describe in clear and plain language the nature of the personal data breach.
THE CONTROLLER DOES NOT HAVE TO COMMUNICATE THE DATA SUBJECT IF:
DataEthics4All believe this is an inadequate rule which places a significantly low obligation on firms when data breaches occur. The consequences of data breaches can impact consumer of tech for long periods and therefore there ought to be stricter rulings beyond mere notification.
First, the 72-hour notice period is unnecessarily lengthy. Technology has rapidly developed and hence firms would be easily able to provide notifications within a shorter time frame.
DataEthics4All recommends a maximum 24-hour notice period. The legal obligation on tech firms using biometric data should extend to informing specific customers how they were directly impacted by the breach, with details of what data was affected and how. As well as that, the company should also outline what action they are taking to rectify or address the issue in line with compensation.
Transfers of personal data to third countries or international organisations have some regulatory restrictions.
A transfer of personal data to a third country/international organisation may take place if the Commission has decided that the third party (third country, a territory or one or more specified sectors within that third country, or the international organisation) in question ensures an adequate level of protection, then such a transfer shall not require any specific authorisation.
DataEthics4All thinks that this transfer should require authorisation by a supervisory body. This prevents the ease of spreading data to third parties.
Data controllers/processors can still transfer the data to a 3rd country without a Data Protection Implementing Act (DPIA) from the Commission if they have provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies for data subjects are available.
Data Processing.
How Can Companies Ensure Fair Data Processing?
GDPR Article 5 and 6 outlines principles firms must adhere to when processing the personal data of customers.
Personal data must be processed:
DataEthics4All recommends that this is taken to the next level, the protection needs to come with compensational measures for customers in the event of any unlawful processing or loss of data.
Be collected for a:
a) specified
b) explicit and
c) legitimate purpose not in a way that’s incompatible with those purposes
However, the GDPR introduced a limitation on the tech industry. Biometric data under the GDPR comes under a special category of data and is defined as “personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person”. Processing of such data is strictly prohibited.
DataEthics4All defines Biometric data as the unique, permanent, and collectable measurements of the physical or behavioural characteristics of an individual.
Although there are few limited and restrictive exceptions to this rule.

BIOMETRIC DATA CAN BE USED ONLY:
DataEthics4All recommends that the least intrusive type of data should be used and then consideration ought to be given to the securitisation of that data. Firms should choose the least intrusive and most secure.
Before implementing a system that processes biometric data, organizations should assess whether they can rely on an exemption to the GDPR’s prohibition to process biometric data. Big tech firms fall under the exception of being able to use the data as it is within the data subjects’ interest to protect their personal devices such as mobile phones.
ART. 13 OF THE GDPR REQUIRES THE FOLLOWING INFORMATION TO BE PROVIDED WHEN PERSONAL DATA IS COLLECTED FROM THE DATA SUBJECT:
Purposes of the processing for which the personal data are intended as well as the legal basis for the processing.
Identity and the contact details of the controller.
Contact details of the data protection office.
Legitimate interests pursued by the controller or by a third party.
Recipients of the personal data.
The fact that the controller intends to transfer personal data to a third country.
Once the data has been collected, data controllers need to ensure fair and transparent processing and provide the data subject with details on how long the data will be stored for. The regulation empowers customers with the right to request access from the controller for rectification or erasure of their data or restriction of processing concerning the data subject or to object to processing.
An area which requires greater scrutiny is a change in purpose for data processing.
DataEthics4All recommends that a fixed period of at least 1 month is given to consumers to consider any new changes to data.
CCPA and Data Privacy.
Overview of Required Notices:
Notice At Collection of Personal Information:
Firms must provide customers with a timely notice either before or at the point of data collection. The notice should be plain, straightforward avoiding legal jargon in a format that makes the notice readable and accessible for those with disabilities.
In the event a firm is collecting personal information from consumers mobile devices for a purpose not reasonably expected, the firm must provide a just in time notice.
DataEthics4All recommends the legislation should require firms to provide advance notice so consumers have time to think about whether they wish to provide consent.
Businesses must provide notices of all data and categories they will collect. They must not collect data for any purpose without issuing a notice.
DataEthics4All – The CCPA appears to be very notice heavy but has little on Data Minimisation, it appears to allow firms to collect any data if they issue a notice to the consumer.
When issuing a notice, firms must provide a link to their privacy policy.
Data Ownership.
How can companies demonstrate clear Data Ownership?
CCPA.
The privacy policy must be posted online through a conspicuous link using the word “privacy” on the business’s website homepage or on the download or landing page of a mobile application.
THIS SHOULD INCLUDE:
Customers hold the right to request deletion of personal information, the right to opt-out of the sale of personal information and the right to not be discriminated against.
Businesses must respond to your request within 45 calendar days. They can extend that deadline by another 45 days (90 days total) if they notify you.
calendar days

Netflix has been considering an enhanced use of customer data from its streaming services. It is suspected that this will involve analysis of users’ emotional behavior to understand their response to films. For instance, if any scenes from films were replayed or skipped and how frequently. Owning such data would reveal substantially unique information about specific individuals which raises concerns about how such vast volumes of data would be secured by the streaming platform.
Data Consent.
How can companies ensure they have explicit Data Consent?
As per Article 7 of the GDPR the data controller should be able to demonstrate that the data subject consented to the processing of their data. Consent is a highly contended area as often consent is obtained easily by tech giants within extensive and lengthy Terms and Conditions forms.
The GDPR aims to address this issue. It requires that in the event the data subject’s consent is given in the context of a written declaration concerning other matters, the request for consent shall be presented in a manner which is:
While the above appears to be a reasonable requirement, if a notice breaches such terms, the only consequence for firms is that the declaration is not binding. However, DataEthics4All suggests that this ought to be taken further. Many consumers of tech are unaware if a declaration is binding or not. Instead, if a firm uses a declaration in breach of the regulation the consequences should be more severe, the data subject should be made aware of the breach and consent ought to be re-obtained within a certain timeframe with firms highlighting the change explicitly. This will enhance accountability of firms as well as ensuring data subjects are fully aware of how their data is being used.
Data subjects also have the right to withdraw consent at any time and firms are required to make this easy for data subjects.
A more thorough assessment needs to be made when considering if a data subject freely consented to use of their biometric data. This is imperative as biometric data, unlike other data types, is completely unique to the individual and unchangeable, therefore, a breach could result in disastrous consequences for customers. Hence, stricter guidelines are needed when analysing if large tech firms have simple procedures in place for customers to opt out, with fines in place if they fail to do so.
CCPA and Data Consent.
The CCPA issues specific guidance on how firms must clearly inform consumers how to opt out of data collection initiatives. This includes clear links labelled as ‘Do not sell my personal information’ and instructions on how to submit preferences. The notice must also include a description of the customers right to opt out of the sale of their information.
DataEthics4All believes customers should have the option to opt out of other data collection methods other than selling info to third parties. This is because consumer consent is central to any data usage by large tech firms. Biometric data may only be used in limited circumstances under the GDPR, and users are entitled to have full autonomy on how their data is used.
Data Control.
How can companies be prevented from taking excessive control of Data?
The GDPR’s guidance on data minimisation and storage is one of the ways firms can prevent excessive use and control of biometric data.

THE DATA MUST BE:
CCPA Rights of the Subjects.
The business purposes for collection
Whether that information is sold, and for what business purpose
The third-party recipients of the data
To access their personal information
To equal service and price, even if they exercise their privacy rights
To know what information has been collected and the sources from which that data was collected
To know what information is being collected about them
To know if their personal information is sold or disclosed, and to whom
To say ‘no’ to the sale of personal information
Amazon’s introduction of the new biometric palm print scanners, Amazon One allows customers to pay for goods in stores by waving their palm prints over a scanner. The scanner can capture intricate details of the palm from lines and ridges and vein patterns. The indefinite storing of a palm signature as such provides Amazon with great control over the data. The data is only deleted if the feature is not used for two years.
DataEthics4All believe this time frame gives Amazon control over data for a longer period than necessary and instead should be reduced to a maximum of 1 year.
Transparency.
How can companies remain transparent and maintain the trust of data subjects?
Article 12 of the GDPR outlines the requirements surrounding transparent information and communication.
THE DATA CONTROLLERS NEED TO:
Further ways firms can maintain the trust of data subjects is through article 15 of the GDPR.
COMPANIES SHOULD INFORM CONSUMERS OF:
Financial Incentive Notices.

A BUSINESS NEEDS TO INCLUDE THE FOLLOWINGIN ITS NOTCIE OF FINANCIAL INCENTIVES:
1
A succinct summary of the financial incentive or price or service difference offered
2
A statement of the consumer’s right to withdraw from the financial incentive at any time and how the consumer may exercise that right
3
A good-faith estimate of the value of the consumer’s data that forms the basis for offering the financial incentive
4
Document a reasonable and good faith method for calculating the value of the consumer’s data
Transparency in the biometric sphere is imperative. Data breaches by large tech firms, for instance by Facebook in 2010, inspired mistrust within its community of users. The social media giant began automatically tagging people in photos using a tag suggestion tool, by scanning a person’s face via facial recognition and offering suggestions as to who that person is. The breach went even further as ghost profiles were created for individuals who did not have Facebook accounts. While the option to turn off the setting was available, users had not consented to activating the feature.
The controversy forced Facebook to introduce the following changes to increase user autonomy.
A FEW THINGS TO HELP GIVE YOU CONTROL:
Conclusion.
Issues with the GDPR and CCPA.
The GDPR and CCPA rules do not include substantial reference to pillar 3,8,9,10,11 and 12 of the DataEthics4All framework.
Recent Fines incurred by FAANG.
Facebook was fined $5bn by the Federal Trade Commission (FTC) for giving app developers Cambridge Analytica access to 87 million users data without clear consent. The Information Commissioner’s Office (ICO) considered this to be unfair processing of data as those who had not downloaded the app, but had friends that did, also had their data shared. The tech giant failed to secure customers personal data as it did not carry out suitable checks on third parties who were using its platform.
The Irish Data Protection Commission has launched an investigation into a data leak in which data of 533 million people from 106 countries was published online on a hacking forum earlier in April 2021. The DPC indicated that the evidence suggests more than one of the GDPR regulations have been infringed.
Amazon has been fined $886.6 million for breaking GDPR rules. At present it is unknown what breach has occurred, but a spokesperson from Amazon claims no breach has occurred and that customer data has not been leaked to third parties.
Google was fined £44 million by the regulator for ‘lack of transparency, inadequate information and lack of valid consent’ for advert personalisation. It was held that people were insufficiently informed about how Google collected data to personalise advertising. The Group argued that the firm had no valid legal basis to process user data for advert personalisation.
The fines incurred by the major tech firms appear to have an underlying theme of processing data for a purpose customers have not consented to or failing to secure the data adequately which results in a data breach and unlawful third party access to data where it is then misused.
KEY BREACHES:
CONSENT
UNFAIR DATA PROCESSING
DATA SECURITY
TRANSFERS TO THIRD PARTIES
PRIVACY
JOIN US.
Keep in touch with the latest in Data Ethics, Privacy, Compliance, Governance and Social Corporate Responsibility.
Share:
Written by:
Tags:
“I think we need to dial back and become more authentic, more real, like stop virtual handshakes and forget about the virtual reality world”
– Shilpi Agarwal
TEST
TEST
Expand
Talk Summary
5 things you must know about the @Facebook Meta re-branding and how it affects you!
00:00 Shilpi: Hello, everyone let me introduce all our participants from the DataEthics4All Leadership Council. Hi, Sam, hello Kevin, Susanna hey, hi, hello so today we are going to start a new series really excited about it, Ethics 1st LinkedIn Live talks and the first topic today is something on everyone’s mind, Facebook Meta – why did Facebook change the name to Meta and how does this affect us?
That will be the conversation of today, please join us, we are able to take your comments Live here, so please join us and leave your comments we are Live on Facebook, YouTube, as well as LinkedIn, so send us your questions comments, feedback – we have a QR code to join our community on the right if you like what you see here, and you want to be a part of this discussion, up, down here right now so my other right [Laughter] it gets mirrored so yeah please, take a look at that all right everyone ready panel is ready [Laughter]
3:57 Shilpi: Yes so let’s start with the first question that is on everyone’s mind, what do you think of Facebook Meta and why do you think Facebook decided to change its name to Facebook Metaverse, all of a sudden?
5:17 Shilpi: Okay so, Kevin thinks it’s a marketing move, Susanna what do you think?
5:22 Susanna: It is a marketing move, it is a business move and it is a legal move and it’s also a PR move – they just want to distance themselves from the product itself but it has other you know reasons behind the scenes, Susanna, Sam what do you think?
5:40 Sam: Yeah I think it is it’s a move away from the criticism they’ve faced and it’s a bit of a distraction so it’s definitely a marketing move and they’re wanting to promote new products that they’ve invested in as an organization, so VR and AR and it’s engaging younger audiences as well. So I think it’s important, for them in this area.
6:04 Shilpi: So here’s what I think, that I agree with all of you – it is yes a PR move, yes it is a legal move, yes it is a marketing move, yes it is some sort of distraction, which we will get into – in our next question, but most of all I don’t think you can come up with something like this overnight – so this might be something that they, it must have been in the pipeline for a very long time
6:39 Shilpi: That they must have been thinking about doing something beyond just the social media platform and yes, they have always invested in like different projects but none of the projects have taken such strong limelight that you know we have heard about them
6:47 Shilpi: So we all remember and associate Facebook with its one social media platform and after you know it was started in 2006 and so it has come a long way and since then I think it’s time for the next version of not just the platform but also the company to evolve as a natural progression of where it should go, it came at a time when they may have felt like there is a need to speed up that process because of the fire and the data that they have been, more so now than ever and so I feel that this might have been in the pipeline but they expedited the timeline, for the purpose that we all know and we’ll get into this next question as you know.
Shilpi: do you think it’s a diversion tactic,
Sam? We will start with you
7:38 Sam: Yeah I think it is a diversion tactic Shilpi, yeah – they, I think Facebook is starting to realize as well that they’re seeing a decline in a younger audience, I think that’s also part of it on the Facebook platform and it’s just a way for them to continue to expand this market in this area and use the data that they’ve obviously collected on the platform, as well so yeah, partly
08:08 Shilpi: Yeah, absolutely Susanna?
08:13 Susanna: it is a diverse tactic, yes but you know I don’t think the people behind Facebook are like you know idiots or anything they would actually know that when you bring up a blurry branding yeah
Susanna: re-branding at a time like this people are always going to jump on you and say, hey you are just trying to divert us from what we are doing here behind the scenes whatever is the illegal stuff we are trying to do
It’s a cover-up but they know that they know this could be a bad PR move but they still went ahead with it.
08:48 Susanna: So that tells me that it’s not just a diversion tactic, this was in the works for many years because, but from I think almost like five years ago the younger audience started leaving Facebook and the older ones
Susanna: the more radical ones took over the platform and we saw the effects of that the impact of that during this election, so they knew that this was you know coming along the way they need to somehow appeal to the younger audience
Susanna: which was moving to things that were more not real the filters on Instagram and all of that they liked that kind of stuff so now, this was you know natural progression, so you know it’s it is a distraction, you know diversion but that PR people do know that we will catch on that and we will you know bang on them in on them and say hey you’re trying to distract us they knew that but they still went ahead with that
09:43 Shilpi: so yeah it was in the pipeline, yeah I mean Snapchat came up with these filters, and like if I look at today’s younger audience from our youth council and the youth that we work with we have had these discussions on Facebook disinformation and polarization in our town hall meetings and yes, they have clearly mentioned that you know they do like to have friends who constantly post something on social media
Shilpi: and they are looking for these, how beautiful I look and they are checking it constantly for their friends to say, oh this picture of you looks, makes you look so beautiful so it is such a negative kind of connotation where you know we are looking for external validations
Shilpi: constantly, and our next generation is doing that and as you can see, as you told Susanna as you mentioned our kids are not on Facebook they don’t want to be there they are on Instagram and that’s the whole reason why Instagram and Snapchat and Tick Tok are the three main platforms or of the future generation and that’s one of the reasons why Facebook acquired Insta and who knows, wants to acquire others but and Whatsapp as well. So definitely it’s not something, Kevin do you want to add something to this?
11:04 Kevin: Yeah no I would just add to both I mean all of your points there that this was definitely a diversion tactic, it honestly doesn’t make too much sense that Facebook would be the first one to the market, especially when it’s not a technology inherent or inherently technology company, it’s it was born as a social network and then it’s competing with Google, Microsoft even Amazon is more technology, I would say so if it’s the first one there’s definitely a reason why and to me honestly I think there was never going to be a right time for them to come out with it but it was always going to happen
11:44 Kevin: So for them, it’s also a very strategic move to be the first mover to the market, I think there was never really a good time but I think the best time is was today like that’s the mentality right yeah.
11:58 Shilpi: I mean we have seen more and more of these video games and all of these that our younger generation is so addicted to like the 360s and all these gaming stations and even online video games that they like to play what are some of you know biggest ones out there?
12:17 Kevin: Roblox it is….
12:18 Shilpi: come again?
12: 20 Kevin: just, in my opinion, they are in Metaverse already because you can build games inside that game yeah, everyone’s heard of Roblox but that’s something that’s going on it’s like the Minecraft of a decade ago!
12:34 Shilpi: yeah Minecraft, and yeah so it’s like I mean AR we are augmented reality and virtual reality somebody there’s some disturbance um AR and VR is such a bigger umbrella-like, you could fit anything under that umbrella right you can have banking experience as an AR experience you could be not just playing sports or actual games but you could do real-life stuff, feed somebody or do banking or buy something shopping
Shilpi: all of these could be gamified in their own way like personified and gamified as someone else
13:18 Shilpi: So it is a very big umbrella huge universe that they are moving into um and so if do you guys think that Facebook by changing its name and they have made a claim that Facebook itself the platform will remain to be called Facebook
Shilpi: do you think at some point they are going to fold Facebook and what will happen to our dataif they do what do you think about that?
13:45 Susanna: 100% sure that it will soon reincarnate itself into something else it may even be called Facebook or not but you know because Facebook or Metaverse right now doesn’t have it has any legal liability to hold true to its word that it won’t hold Facebook away they can’t change that in any time and fold it but I’m hundred percent sure it will be folded into it into the Metaverse and it will have a digital you know virtual reality component to it okay
Susanna: And the data will be used to create digital twins of all of us who will all you know those who are not knowledgeable enough will obtain and say yes to that and that’s what they are betting on!
14:35 Shilpi: I actually don’t know if you know this, I don’t know if this is an Indian theory or in our mythology, it just said that there are seven people identical to you in the whole world like at a given time.
There are seven identical people, I mean they may be different ages, they may be at different Geo locations
14:58 Shilpi: So if that was true then who knows this Metaverse will create not just twins we already have seven out there seven Susanna’s out there already so who knows!
What do you think about the re-branding and whether it would go away? Sam?
15:15 Sam: I don’t I think Facebook will as a platform will not go away completely, I think there is still a market for Facebook and I think until obviously we know that legislation you know it gets put in place and we have legislation around data protection, more data protections the platform will be used, the data that Facebook has will potentially then be migrated over to the the mixed reality world of Metaverse, I think there’s definitely going to be demand there but I do think we’ll stay for quite some time until Metaverse is you know is realized, you know in this among its customers and I know also I also think that there’s going to be companies particularly you know we’ve mentioned Microsoft we’ve mentioned gaming organizations, gaming companies, e-commerce platforms that might be interested in working with Metaverse and being part of it that will want to continue you know utilizing the platform and also moving over to Meta as well so the data will still be the data will still be there, um so yeah I don’t think it will yet
16:33 Shilpi: I agree with you I think see at least a few of our previous generations like our parents right and our grandparents as well as our generation I think is still on the platform.
So it still makes sense until we die at least you know there is some truth to that some validity in that platform and it may still be there they may evolve they will definitely evolve.
Shilpi: I do think yeah whether they change the name or the look and feel of the GUI or the UX or whatever that may look like it they may change the features are always added and removed but yeah it will stay.
Shilpi: But one thing that Facebook has not openly said and is not doing today openly like actually selling data of customers
Shilpi: Yeah they do that through their apps or you can integrate with their APIs or their play store whatever, that may be like you can indirectly make use of the marketing that ad targeting, right
Facebook is sitting on a gold mine of data and of all of the customers of like a billion people of the world customers out of the seven we have one billion or two billion people whose customers
Shilpi: Even ghost profiles they even have ghost profiles of people who are not even on Facebook, even my grandmother might be on some kind of profile of my grandmother might be on Facebook, right?
17:55 Shilpi: So they might be able to then actually chop and chunk that data and sell it off to like different vendors for different purposes before they so, I’m sure they’re really going to milk it completely before they decide to shut it down so yeah
Shilpi: yeah it’s not going to be soon and like you said until Metaverse really takes off it’s not going to happen, they’re still making a lot of money from ad targeting and showing ads and doing all sorts of posts and things which they will continue to do
Shilpi: I just hope that they use it better you know they tweak their algorithm for everything that they have been under the fire they tweak their algorithm and for the better protect their customers and do right by them
Shilpi: so that brings us to the next question where you know the new Metaverse promises to have everything and it may have everything who knows what, all it will have like from shopping to virtual reality games and we talked about all of this, so is it, will it be like a parallel universe like we are living in this real-life universe but will it be like a parallel universe, where you know it’s it’s a virtual world and all the family and friends that I’m connected to today on Facebook, will they automatically be connected because as you all know one of the biggest pain points in adopting a new platform is building this network from scratch right you literally whether it is signals or Whatsapp or whatever maybe you have to literally manually either bring your contacts or slowly like Linkedin when we all started we know how that was like we it was hard to even get 500 people to be connected to right?
19:40 Shilpi: So it is a painstaking process to really get on that bandwagon, so is Facebook going to help us with that like I, are all my friends and family members automatically going to be on Metaverse, or what do you think?
19:56 Sam: Yeah I think you will be able to do all those things, you will be able to shop, you’ll be able to socialize with your friends as you would on the platform now but in VR and it would possible for you to invite your family or friends to join you, I think, and you’ll potentially then be able to invite your network, I don’t think you’ll need to build your network up again from you know from the beginning um but we don’t know that yet so for me my opinion I think you might have that option
20:30 Shilpi: yeah exactly yeah we will exactly, all right Kevin do you want to what are you doing?
20:38 Kevin: Okay so there’s a big technology barrier though I mean I’m hoping that in the future everyone can figure out the Metaverse one day but I still would say that some people might not have that access
Kevin: maybe it’ll be even as simple as not having access to the internet right? Something new but then that is also solving itself in the future I guess, but yeah I would say technology is key and also interest yeah I know that as an introvert I would love it if it would help me socialize better because that is one of my biggest weaknesses I would say that’s I mean that’s one way that Linkedin has helped me tremendously over the past few years is connecting with people, right it’s so easy to just connect with someone and not look like a complete creep, but I’m very curious to know what it’ll be like on the Metaverse when you just go up to someone and add them as a friend, or and I’m guessing on the Metaverse you can go up to someone’s house and like knock on their door, now I don’t know like I’m very curious to know how this will work, maybe it’ll be less awkward to knock on a stranger’s house and like for that stranger to even invite you inside because it’s the Metaverse what could go wrong right? Like I’m really curious to know how that would be
21:53 Shilpi: yeah what do you think Susanna?
21:57 Susanna: absolutely I think I know it’s easy adoption from Facebook’s point of view it’s easy adoption. So one billion users on Facebook alone and then you have Insta and then you know what’s up you know they could easily you know I have with the adopt the platform to you know
Susanna: incorporate the people who are already there it’s not like you have to now sign up it’s your entire network is already there just you know make up your own avatar world and your digital world and that is what they are betting on
Susanna: I believe I don’t think they would be creating another separate one and saying you now have to add one migrate everything I don’t think so I think it will be easy migration and that’s what they are betting on
22:40 Shilpi: Yeah and I agree with all of you, yeah, I mean that would be the simplest choice like one click of a button do you want to import all bring invite all your friends and family like your entire network to Metaverse and you just say yes without even reading the 40-page document as to what they’re going to do and how they’re going to use that and yes like yes okay, I want to meet my mom here I want to meet my best friend here and there you go there you have it right my brother my sister or my children
23:13 Susanna: especially you know the older population like my parents you know they wouldn’t even know what that means, yes and their age group every one of their friends it’s its kind of you know good for them in a way they will be able to connect and talk but you know I still like just last week ago my dad you know clicked on an Amazon 27 year anniversary coupon or something and forwarded it to everyone and it was a scam, oh and he forwarded to all of his contacts and I had to now go and clean out his account to reset the password and do that and he knows none of that and this is what’s going to be happening. So you asked you know will you have we have all your friends in the Metaverse, not Susanna she won’t come there you won’t come back
24:06 Shilpi: Facebook you better watch out the Susanna’s of the world are not going to be on your platform you better have an alternative tactic to bring them on, so I actually feel I agree with you it will either be the really elderly generation or it would be the really younger generation who will be you know kind of sucked into this world sooner, I think the younger will be the first to adopt it and with them, they will bring like the Tick Tok, the Tick Tok users will be the first users to probably adopt Meta, I mean who knows time will tell, right this is speculation but I think because they are already gaming in other worlds and other platforms to them this will feel like the natural first choice of adoption and it would be good to see their friends there
24:59 Shilpi: So they will be, they will adopt it and then we’ll see if they would want to invite their parents there and then network there and then we’ll find out all right we I mean we could go on and on
25:11 Shilpi: I’m going to end with one last question um do you think Metaverse will follow better data privacy as well as algorithmic guidelines and try to do right by their users protect the users
Put users above profits and everything that has come under the fire what is your opinion, what do you think? Are they going to change are they going to do right by their people?
25:38 Susanna: No, no
25:44 Sam: I am not confident
25:46 Kevin: Unless they become a nonprofit out of nowhere, it’s impossible for them to do that, they know that you know they’ll get money at the expense of people’s lives right? And that’s what they’re they’re kind of doing I think they’re exploiting people even further by doing this because now you have to give even more information than you had to before
26:06 Kevin: I mean one of the things I’m very curious about and concerned about is the verification process because to Susanna’s point if she decides to stay at home and not come on the Metaverse like stay in her actual real home and not the Metaverse
Kevin: What stops somebody else
from posing as her?
26:26 Kevin: Yeah, I mean they might have, I mean maybe a really close friend of hers has all of her information there’s like basic high-level personal details they can pretend to be her right, yes but I’m guessing there will be a verification process, that’s even more strict than it is right now, that’ll require you to have things like you know um your fingerprints
26:44 Shilpi: yeah like SSN and you know all these personal identifications
26: 49 Sam & Susanna: Biometric data, Biometrics, right yeah, yeah. Yeah to get the blue tick check on Twitter and Facebook, you have to give your blue social security number
27:59 Shilpi: Yeah, yeah you have to give a lot of data away yes
27:04 Kevin: And I believe that’s what the verification process will be like it has to be strict right to prevent this from happening
27:10 Shilpi: So basically what I’m hearing is that in a parallel universe which is all virtual there will there will be facts to check that we are a real person and all our personal data will be we will have to give away to get that
27: 28 Sam: yeah, yeah that is captured as well yeah, that’s true yeah
27:30 Shilpi: Oh my goodness. So we are entering a really really very perspective world where you know, who knows what’s going to happen, do you think ever the virtual and the real-life worlds are going to merge together?
27:44 Susanna: I mean I don’t think that’s a futuristic question they already have right, yeah and they already have on our social media platforms and already our you know virtual and you know real are emerged to create an expert
28:00 Shilpi: to this extent where this…
28:07 Sam: there is a there’s this completely different world where we can just transition, yeah. I do think there’s going to be a role for augmented reality in VR in our lives and but I don’t think there’ll be a full transition to it in my lifetime, I don’t think I don’t know what you guys think? I think they’ll be here
28:26 Shilpi: I think if anything we should roll back, dial it back to like becoming more authentic and more real in life
Like, first of all, I disagree with what Kevin is saying he’s not an introvert, I don’t consider him an introvert but of course, that’s what he thinks of himself and it is true like so many people have so many friends on social media and they make me they receive like such a popular personality or a person and in real life, it’s hard for them to go up and even hi to a stranger or even talk to someone right and so it’s like we live in this world where social media seems to be uh, to be guiding our life like it seems to be more popular and so if anything I think we need to dial back and become more authentic, more real, like stop virtual handshakes and forget about the virtual reality world all together go out and i
Shilpi: If Covid taught us anything it’s like you know say hello to your neighbor go in person and you never know when you will be stuck inside your home for two years right, that’s all happened
29:32 Shilpi: So for those kinds of things yes AR/VR is good but until that is not there we better start enjoying the life that we have been given
29: 49 Kevin: I think my perspective is probably it might contradict all of yours but I see a world where with all these things happening and maybe I mean hopefully god forbid another Covid breakout, um, I see a world especially with climate change um where we might not even have the luxury of stepping out anymore, yeah I mean we’ve all seen the apocalyptic movies and those things right and we’ve all seen black mirror and now we have the Metaverse, so what’s to say that we don’t live a post-apocalyptic
30: 12 Shilpi: yeah if we go on Mars and we have to do this. I agree that that that would be a good way to save ourselves to enjoy life without feeling like we’ve lost everything and other than that if no forwards nothing happens then I think we should go out and enjoy real meeting real people and enjoy the real shopping experience
30:37 Kevin; we should start by meeting each other first
30:41 Susanna: and to you know before we end it I just want to say something you know introverts are the smartest most creative people and they are not intro as a thing is not a bad thing at all it is a normal part of who you are and that is from a high functioning introvert myself so you know it’s not a bad thing
31:02 Shilpi: this might be a discussion for next time so what defines an introvert because I don’t see you both as those that you define yourselves, uh so I think that this calls for a very interesting discussion for next time join us and we’ll find out what an introvert is all right everyone thanks you for joining in and uh don’t forget to uh scan the QR code and join us, I’m not even going to try this okay Kevin has got it, yeah right oh Susanna oh all of you got it okay, all right!
31: 38 Shilpi: So well then take care, uh thanks for tuning in, take care bye! DataEthics4All Ethics 1st live LinkedIn talks, bye everyone, bye!
Join Us in this weekly discussion of Ethics 1stᵀᴹ Live and let’s build a better AI World Together! If you’d like to be a Guest on the Show, Sponsor the Show or for Media Inquiries, please email us at [email protected]
Come, Let’s Build a Better AI World Together!
Share:
Written by:
Tags:
``I decided to make a career switch``
``And this is where things got really interesting, and this is when I actually fell in love with data`` - Kate Strachnyi
I am text block. Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
“You are a great role model from you know, having young kids to running your business, to actually doing the running like you’re running a marathon tomorrow!”
– Shilpi Agarwal
I am text block. Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
``80-90% of the content you put out on social media should be on the topic that you want to be recognised for`` - Kate Strachnyi
I am text block. Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
I am text block. Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
“The more you comment, and the more you know, you put yourself out there, the more people are going to be attracted to you and sort of help you build that network.”
– Kate Strachnyi
I am text block. Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
Expand
Hear about Kate Strachnyi’s journey of transitioning from a full-time role to launching her own business and being dedicated to data…DATAcated. Kate Strachnyi is the Founder of DATAcated, providing brand amplification for companies focused on artificial intelligence (AI), machine learning (ML), and data science. She’s also the founder of the DATAcated Academy – delivering training on data visualization best practices. She’s delivered several courses on data storytelling, dashboard techniques, and visual best practices. Additionally, Kate is the host of the DATAcated Conference and the DATAcated On Air Podcast. Kate was appointed a LinkedIn Top Voice of Data Science & Analytics in 2018 & 2019.
Expand
0:00 Shilpi Agarwal:
Next we have Kate Strachnyi. She is the founder of DATAcated; if you’re on LinkedIn and you don’t know her, you must be living under a rock, she’s super active! She is the LinkedIn top voice, she’s providing brand amplification for companies that are focused on artificial intelligence, machine learning, and everything under data. She’s also the founder of DATAcated Academy, delivering training on data visualization best practices. She has delivered several courses on data storytelling, dashboard techniques, and visual best practices. Additionally, Kate is the host of the DATAcated on-air podcast and the DATAcated conference which just happened two weeks ago, and I was honored to speak at the conference! Kate was appointed a LinkedIn top voice of data science and analytics in 2018, and 2019. Welcome. Kate. It’s a fabulous honor and pleasure to have you. I am just in awe of you! I follow you on LinkedIn, I feel like you are a great role model from having young kids to running your business, to actually doing the running like you’re running a marathon tomorrow! The list goes on and on; you have an academy, you are the LinkedIn top voice; I don’t want to keep our audience waiting, so I’ll give the stage to you.
1:50 Kate Strachnyi:
Awesome, thank you so much, Shilpi, thank you so much for that very, very kind introduction. I’ll share with you my DATAcated journey and I’ll basically walk through what inspired me to get into data analytics. Also, I want to leave you with some tips in terms of building your own brand, building your own community, whatever that might be. For example if you’re in voice tech, like John was just talking about, I could talk through some tips on how you build your brand in that space. I listened to a couple of other talks earlier today, I really resonated with Linda’s talk about finding women role models. That’s something that is very close to me as well, as I am a woman and I was always looking for those role models in my career. But more so, I also have two little girls age five and seven, to whom I hope to be a role model, and I really hope that they find the right role models for them in their careers. So briefly about me, I was born in Tajikistan, that’s something most people probably don’t know about me! I moved to the United States, when I was about nine years old and lived in New York ever since, although I just moved to New Jersey about two months ago. I’ve been living on the East Coast for the past couple of decades. My journey career-wise didn’t really start in the data science and data analytic space, it actually began with a finance degree. I always thought I wanted to do finance, whatever that meant, I didn’t really have a definition for what I wanted to do, but I studied finance and graduated in 2009. And for those who have been around and looking at the news since 2009, you know that we were going through a huge financial crisis. What that led to was a hiring freeze in all of the banks, and my dream job was to work for a bank and do finance – so I kind of had no hope there. But it’s very interesting how life throws you into different directions because it’s all sort of coming full circle right now. What I ended up doing was, instead of applying to jobs that ended up going into a black hole, I started going to events, as many networking events as possible. This was way, way before COVID, so events in-person were still a thing. Now we do this virtually and if you’re attending this live right now, I definitely recommend you engage with the other people that are attending even though you can’t see them. The more you comment, and the more you put yourself out there, the more people are going to be attracted to you and help you build your network. But back in the day, I used to go to events in New York, there were plenty of them and ended up going to some Risk Management Events. There I met a person who was looking to hire somebody in business development and he noticed that I’m social, and so he told me to send him my resume. Long story short, I ended up working for GARP, which stands for Global Association of Risk Professionals. I know that has nothing to do with data, but it was a member organization, it was community-driven. They had events, they had courses, and they had all these other cool things happening like conferences, and my job was to get them clients. Fast forward: I spent the next couple of years working in risk management, focused on learning my stuff there, ended up working in a consulting company for about eight and a half years across a variety of roles. It wasn’t until I was expecting my first child that I decided to make a career switch.
This is where things got really interesting and when I actually fell in love with data, it was thanks to my children, because they motivated me to look for something that provided a bit more flexibility of my personal schedule and my location; I really wanted to work from home which was not a common thing to do. You couldn’t really just go online and find yourself a work from home gig. But after several months of digging and searching, I was able to find something that allowed me to stay home. And because of that, I was able to get into the field of data, because the opportunity that was presented for me included data analytics. At that point, I had no clue what that meant, I didn’t really even use Excel that much! But what happened was, I was given the dataset, I was given that access to Tableau Software, which is this data visualization software for those who are not familiar. I truly fell in love with all things data. This was around 2013-14. Ever since then, I’m still equally as passionate about the space as I was in those early days. But my journey didn’t really stay with that company, because I also had this knack for entrepreneurship, I really wanted to start my own company.
Fast forward to March 2020, at the height of the global pandemic, I decided to go off on my own. Because that’s what people do, right, we like to take risks, we like to have fun with it. At this point I can easily say that that was one of the best decisions I’ve personally ever made. It led to me being even more flexible with my career, with my time; I’m able to set my own schedule, set my own hours, choose my own clients.
All of that happened because I built the right brand on social media platforms. In the few minutes that we have left here together, I want to share some of my best practices, my tips and tricks on how to build your own brand. If you’re watching this either live or if you’re watching the recording, chances are you’re interested in something to do with AI or ethics or diversity; you’re interested in these topics. What Shilpi’s doing a great job with is bringing this community together – and she did a great job presenting at my DATAcated conference two weeks ago as well. All of that drives to building her brand, right? When I think of Shilpi, now I think of AI, ethics and diversity. So whenever an opportunity arises, that requires me to either go to an expert, or somebody asks, ‘Hey, who do you know in this space?’ – immediately, Shilpi would come to mind, because she speaks at conferences, she puts these events together. So she’s doing things right. Now, a lot of people have these aspirations of: ‘I’m going to start posting online’ – let’s say LinkedIn – ‘LinkedIn is one of my favorite platforms because it’s very professional; people tend to be very professional on this platform.’ But chances are, you’re going to leave the talk, and you’re not going to post anything, especially if you’ve never posted before. And that is mainly because of fear, even if we don’t call it that. We can call it lack of time, we can say, ‘oh, I don’t really think it’s important.’ But ultimately, I think it does come down to a fear of being seen by those who you know – what if your brother sees you posting, or your colleagues see you posting, what are they going to think? Other times, we have this fear that we’ll post something and nobody will see it – what if my post is so unpopular that nobody sees it? That was definitely me, at the beginning in 2014, when I was getting into data; that was also the same time that I was being more active on social media. I made a conscious decision to just put myself out there, because we do just have one life to live, right?
For me, it was an easier decision to start small with a text post, so I wasn’t really big on camera, I was very shy. For a talk like this. I would normally prepare a script and I would try to read it, which those of you who have heard scripted talks before will know are not as engaging, not as exciting. You can tell that the presenter is not fully there, not fully present. So I decided to improve on that, and the only way I found in terms of getting yourself to improve is to just put yourself out there continuously. Now, if this is something that’s interesting for you, a few tips I’ll say is, number one: be authentic. Be yourself and talk about the stuff that you want to be recognized for. For example, when people think of data analytics, data visualization, data storytelling, I want them to think of Kate, I want them to think of DATAcated, so most of my content that I put out there is all around that same topic. That doesn’t mean you can’t go away from that topic once in a while, but I’d say about 80-90% of the content you put out on social media should be on the topic that you want to be recognized for. Consistency is a second big part where you need to show up. I don’t mean showing up at 9am every single day and post some robotic message. No, I mean sporadically showing up, treating the social media platform like you would a close friend, somebody you would just call up once in a while and say: ‘hey, guess what just happened’, right? ‘I got this opportunity’, or, ‘Hey, I’m stuck with this problem’. Treating the social media platform as a friend really, really helped me. I actually ended up making friends on the platform because I treated it as a friend. So for example, at some point, I had an actual data problem where I needed to collate about 100 different spreadsheets into one. I could have Googled how to do this quickly, and what’s the best tool, but I decided to just put it quickly on LinkedIn. Now, the thing with humans, we generally love to help. So if there’s something that somebody knows really, really well, and you have this question, and they know they can help you, and it doesn’t take too much of their time, chances are, they’re going to come in and tell you: ‘Oh, well, this is how I did it. Let me help you quickly’. So that post got, I don’t know, 1000s of comments of people telling me the various ways that you can collate spreadsheets; I actually learned about a lot of tools I didn’t know existed, ended up solving a problem for myself. So I’d definitely recommend putting yourself out there, starting today.
12:21 Shilpi Agarwal:
I know I’m interrupting, but Kate your story is so fascinating, thank you for sharing so many tips. On social media, sometimes I am authentic and I post a lot, but sometimes I look at your posts, and I feel like you really put yourself out there and you really share so much of your personal as well as professional life. You ask for opinions on everything, which is great. But like you said, it’s not easy to put yourself out there all the time, to ask questions, and be okay to fail. That’s one thing I’m learning from you, Kate.
13:14 Kate Strachnyi:
Thank you so much Shilpi, that’s very kind of you. You make a really good point about sharing your journey; a lot of times when I tell people ‘hey, you can get started on LinkedIn today’, one of the main things they come back with is ‘well, I don’t know what to say’, or ‘I don’t think I’m good enough’. They just have this sense that their story, their journey isn’t as important as, let’s say, somebody who has 20 years of experience, and is an expert in the field. My opinion is, and I think this is very accurate, is that that’s not true; people care about your story. Let’s say you’re a student, or you just graduated college, and you’re in this space where you’re interviewing for jobs, or you’ve just started a job; there are so many people that are in the same boat as you that would love to hear your journey. Not everybody wants to hear about the biggest success story of somebody who had everything go right for them, and they’re multibillionaires on boats somewhere, riding around never having to work again. A lot of times people want to know that, ‘wow, this person is like me. This person also has fears and struggles, and if they can do it, maybe I can do it’. If I leave you with anything today, I think if you’re wanting to start building a brand, it’s authenticity, being consistent, and starting today. There’s nothing that stops you from doing it, right? Doesn’t mean you have to post every day; consistency really means just showing up and caring about the content. So Shilpi had a good point when she said I post a lot of things and ask people for opinions. I never post something just to post something; when I post something I truly care about the feedback. So when I ask a question about, for example, which logo should I use for the DATAcated circle, which is this new community thing I’m launching next week, I actually care because I’m, a team of one. I just hired a couple of people to help me out, but I don’t have a huge team of people who I can ask ‘hey, what do you guys think about this versus this’, I have to rely on this community to get their input. And if my work that I’m focused on serves the community, I might as well bring them on that journey with me and get their input along the way. So Shilpi, if you’ve got questions, I’m happy to take them.
15:43 Shilpi Agarwal:
Yes, Girish says “I like Shilpi’s statement, ‘it’s okay to fail’, and love Kate’s approach of using social media as a platform or path to connect with others. Ask for advice, tell stories and learn”, and you do a fantastic job at that, Kate.
16:02 Kate Strachnyi:
Yeah, I think of LinkedIn as my personal diary, where people can also, you know, give me their feedback on that as well.
16:14 Shilpi Agarwal:
Muniesh says: “Wonderful reflections, you are an amazing mentor.” So I know we wanted to connect on the community thing, so we’ll connect right after this is over. I heard that you’re already launching it next week. I’m eager to hear, what platform did you finally narrow it down to?
16:34 Kate Strachnyi:
Yes, I finally narrowed it down, and that was another question I asked the community. I ended up going with Circle. It was very interesting because I’m calling my community ‘The DATAcated Circle’, and interestingly, I came up with that name before I ever discovered the platform called Circle! I’m very excited about that, we have about 55 members in there now. They’re our founding members, but we’ll open it up to the broader community.
17:04 Shilpi Agarwal:
Please do let us know, we’ll share it in our community as well. One of my other friends from Growth Blazers, a community vessel, has also used Circle to build his community. That’s how I just learned about this brand new platform, like a month ago. I’ve heard great things, so it’ll be awesome. So what made you think that you need an actual community? I know, there is LinkedIn and all of that, but what made you realize you needed more of an inner circle?
17:41 Kate Strachnyi:
Yeah, that’s a great question. You said inner circle, there’s going to be something that comes out a few months later that I am calling ‘the inner circle’! You mentioned in the beginning I have this DATAcated Academy where I have courses, and then I have my email list, and then I have all these social media platforms. I don’t have as much control in terms of what my community sees, or things that I think are a priority. And I also wanted to make sure that I serve the community and really talk about the topics that they care about, so what I decided to do was bring all of that altogether. Even the course content is all going to sit on Circle. That’s going to be a premium membership where you can pay an annual fee and then be in that inner circle where you get to see all the content, whereas you know, the broader, wider circle can still have all those engaging conversations.
18:34 Shilpi Agarwal:
Yeah, that was exactly the reason why we chose the Mighty Networks platform for DataEthics4All. You can have groups, private groups, public groups, secret groups, you can have the Data Institute there, we have the courses there. It’s an all in one platform for all our community members, premium, freemium, everything’s there. I’m so looking forward to your community, and good luck with your marathon! All the best for Circle, DATAcated Circle, and whatever is in store for DATAcated next.
20:32 Kate Strachnyi:
Thank you so much! Bye.
DataEthics4All hosted AI DIET World, a Premiere B2B Event to Celebrate Ethics 1st minded People, Companies and Products on October 20-22, 2021 where DIET stands for Data and Diversity, Inclusion and Impact, Ethics and Equity, Teams and Technology.
AI DIET World was a 3 Day Celebration: Champions Day, Career Fair and Solutions Hack.
Join Us in this weekly discussion of Ethics 1stᵀᴹ Live and let’s build a better AI World Together! If you’d like to be a Guest on the Show, Sponsor the Show or for Media Inquires, please email us at [email protected]









