Advertisement

Governments must consider risks to privacy, civil rights before consolidating data, report urges

Repurposing data for other means is risky, and governments should evaluate when consolidation is more harmful than good, a recent report said.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
(Getty Images)

Although data-sharing between government agencies has long been viewed as a way to improve services, recent federal efforts to consolidate data traditionally held by state and local governments has raised privacy, civil rights and cybersecurity concerns, according to a report published last week by the Center for Democracy and Technology, a nonprofit that advocates for digital rights, free expression and privacy.

The report — “What is a Database? A Technical Guide to the Personal and Institutional Considerations of Government Data Consolidation” — points out that while efforts to improve data-sharing between government bodies have been tied to reducing administrative burdens on individuals and preventing fraud, waste and abuse, data consolidation under the current federal government — and the potential repurposing of that data for other means — should drive governments to evaluate when the practice is more harmful than good.

The report claimed that, at its core, data consolidation — which the report defines as “mingling and combining data from multiple different sources to allow it to be analyzed or viewed as a whole” — is risky regardless of the purpose. Though collecting data in the name of streamlining benefits enrollment, improving program administration or detecting fraud and abuse does have legitimate benefits, the risks grow as data is repurposed.

Using data for purposes unrelated to why it was originally collected, particularly in immigration enforcement and expanding surveillance capabilities for law enforcement that can infringe on civil liberties, can be counterproductive, the report claimed. These negative impacts can be seen across benefits adoption, service access and legal compliance, such as the payment of taxes, when data is repurposed, the report said.

Advertisement

These concerns are evidenced by the number of open lawsuits against the Trump administration’s attempts to obtain certain types of data, such as state voter rolls, as well as the court victories over those attempts, the report continued. Data consolidation efforts have also led to widespread distrust in government, the report claimed, including giving rise to allegations that the federal government is building a “mega-database” on Americans from the centralizing of this data, even though the government has claimed that this database does not exist.

Other risks, the report notes, manifest in how the data is housed. Governments often structure their data-sharing among agencies — as well as between states, local and federal governments — based on two models. One is method is centralized or “warehouse” data structure; the other is a federated system, in which data is stored by individual agencies at different locations, but provides broader access across systems. Although technically different, both approaches can create similar privacy and cybersecurity concerns if they allow unfettered access to personal information by agencies or groups that was not originally involved in the collection, the report said.

And lastly, the report noted that while inaccuracies are common across large troves of government data — which presents its own risks when that data is used widely by agencies — those risks are magnified when artificial intelligence tools are introduced. While the tools prove helpful with massive amounts of data, offering improvements to record matching and data analysis, it also can create hallucinations and inaccurate matches driven by opaque decision-making.

To counter these threats, the report suggested that governments take several steps to ensure responsible consolidation and sharing. These include: clearly defining the purpose for any data-sharing initiative; adhering to data-minimization practices; establishing clear data governance on controls and access; creating procedures to identify and correct data errors; ensuring any artificial intelligence systems used with the data are subject to cross-agency oversight and appropriate safeguards; and thoroughly evaluating whether privacy and civil liberties risks outweigh the benefits.

“Ultimately, there are legitimate reasons that agencies would wish to share data in service of furthering their missions,” the report said. “Because data consolidation can have significant impacts to the privacy and well-being of people whose data is being shared, however, data consolidation must be rigorously assessed to ensure that appropriate protections are in place, the data sharing is in service of the agencies’ missions, and there are frameworks and processes in place to ensure the data is not repurposed in ways that harm the people the agencies are meant to serve.”

Latest Podcasts