The rapidly growing quantity of health data presents researchers with ample opportunity for innovation. At the same time, exploitation of the value of Big Data poses various ethical challenges that must be addressed in order to fulfil the requirements of responsible research and innovation (Gerke et al. 2020; Howe III and Elenberg 2020). Data sovereignty and its principles of self-determination and informed consent are central goals in this endeavor. However, their consistent implementation has enormous consequences for the collection and processing of data in practice, especially given the complexity and growth of data in healthcare, which implies that artificial intelligence (AI) will increasingly be applied in the field due to its potential to unlock relevant, but previously hidden, information from the growing number of data (Jiang et al. 2017). Consequently, there is a need for ethically sound guidelines to help determine how data sovereignty and informed consent can be implemented in clinical research. Using the method of a narrative literature review combined with a design thinking approach, this paper aims to contribute to the literature by answering the following research question: What are the practical requirements for the thorough implementation of data sovereignty and informed consent in healthcare? We show that privacy-preserving technologies, human-centered usability and interaction design, explainable and trustworthy AI, user acceptance and trust, patient involvement, and effective legislation are key requirements for data sovereignty and self-determination in clinical research. We outline the implications for the development of IT solutions in the German healthcare system.
While Regulation EU 2021/887 of 20 May 2021 established the European Cybersecurity Industrial, Technology and Research Competence Centre and the Network of National Coordination Centres, it has not addressed in any detail the identification, structuring, or coordination of the cybersecurity actors in Europe. This paper proposes their structure and input, extending on work done in the project CyberSec4Europe, which was funded by the European Commission to design, test, and demonstrate potential governance structures for the European Cybersecurity community.
Identifying, classifying, and analyzing arguments in legal discourse has been a prominent area of research since the inception of the argument mining field. However, there has been a major discrepancy between the way natural language processing (NLP) researchers model and annotate arguments in court decisions and the way legal experts understand and analyze legal argumentation. While computational approaches typically simplify arguments into generic premises and claims, arguments in legal research usually exhibit a rich typology that is important for gaining insights into the particular case and applications of law in general. We address this problem and make several substantial contributions to move the field forward. First, we design a new annotation scheme for legal arguments in proceedings of the European Court of Human Rights (ECHR) that is deeply rooted in the theory and practice of legal argumentation research. Second, we compile and annotate a large corpus of 373 court decisions (2.3M tokens and 15k annotated argument spans). Finally, we train an argument mining model that outperforms state-of-the-art models in the legal NLP domain and provide a thorough expert-based evaluation. All datasets and source codes are available under open lincenses at https://github.com/trusthlt/mining-legal-arguments.
Many websites contain services from third parties. Misconfigurations of these services can lead to missing compliance with legal obligations and privacy risks for website users. Previous research indicates that one cause for such privacy issues is missing awareness. However, reasons for the missing awareness and other reasons for the prevalence of privacy issues are not widely researched; that includes website owners’ dealing with those issues. To shed light on the issue, we analyze 1043 responses from website owners to a notification about a privacy issue on their website using thematic analysis, following an exploratory and qualitative approach. Our analysis shows that, next to unawareness of the issue, incorrect technical implementation and ambiguous responsibilities are among the reasons for privacy issues. Also, website owners face different challenges, such as a lack of knowledge or slow organizational coordination and processes. In addition, our results show that the circumstances in which they operate their website influences how they act and what challenges they face. To illustrate these differences in website owners, we derive three personas from our thematic analysis: (1) the Ignorant Hobbyist, (2) the Busy Self-Employed, and (3) the Informed Multi-Stakeholder. These personas cover the majority of the aspects of the analyzed responses and represent the diversity of website owners and their backgrounds. Given the challenges and backgrounds of website owners, we discuss which prerequisites must be fulfilled to remediate privacy issues on websites. Finally, we present measures that support website owners in remediating privacy issues and show how to adapt these measures to the needs of different website owners. We hope that better support for website owners will also lead to better privacy for website visitors.
Datenschutz und IT-Sicherheit sind längst im Zentrum der öffentlichen Aufmerksamkeit angekommen. Sowohl in der Politik und im medialen Alltag, als auch in der Wissenschaft wird der „Strukturwandel des Privaten“ beobachtet, kommentiert, beschworen oder vor ihm gewarnt. Kein Zweifel jedenfalls, dass der „digitale Wandel“ umwälzend stattfindet, und dass die großen Chancen auf Lebensverbesserungen einhergehen mit dem Risiko einer Abhängigkeit von einer Informationstechnik, die wir nicht ausreichend beherrschen. Der Verlust der Privatheit durch zunehmende Beobachtung und Auswertung unserer elektronischen Spuren ist dabei ein Risiko besonderer Art. Nur Datenenthaltsamkeit zu predigen, ist keine Lösung, da zum modernen Leben eine fruchtbare und unbefangene Kommunikation gehört.
Pushes for increased power of Law Enforcement (LE) for data retention and centralized storage result in legal challenges with data protection law and courts-and possible violations of the right to privacy. This is motivated by a desire for better cooperation and exchange between LE Agencies (LEAs), which is difficult due to data protection regulations, was identified as a main factor of major public security failures, and is a frequent criticism of LE. Secure Multi-Party Computation (MPC) is often seen as a technological means to solve privacy conflicts where actors want to exchange and analyze data that needs to be protected due to data protection laws. In this interdisciplinary work, we investigate the problem of private information exchange between LEAs from both a legal and technical angle. We give a legal analysis of secret-sharing based MPC techniques in general and, as a particular application scenario, consider the case of matching LE databases for lawful information exchange between LEAs. We propose a system for lawful information exchange between LEAs using MPC and private set intersection and show its feasibility by giving a legal analysis for data protection and a technical analysis for workload complexity. Towards practicality, we present insights from qualitative feedback gathered within exchanges with a major European LEA.
Pushes for increased power of Law Enforcement (LE) for data retention and centralized storage result in legal challenges with data protection law and courts-and possible violations of the right to privacy. This is motivated by a desire for better cooperation and exchange between LE Agencies (LEAs), which is difficult due to data protection regulations, was identified as a main factor of major public security failures, and is a frequent criticism of LE. Secure Multi-Party Computation (MPC) is often seen as a technological means to solve privacy conflicts where actors want to exchange and analyze data that needs to be protected due to data protection laws. In this interdisciplinary work, we investigate the problem of private information exchange between LEAs from both a legal and technical angle. We give a legal analysis of secret-sharing based MPC techniques in general and, as a particular application scenario, consider the case of matching LE databases for lawful information exchange between LEAs. We propose a system for lawful information exchange between LEAs using MPC and private set intersection and show its feasibility by giving a legal analysis for data protection and a technical analysis for workload complexity. Towards practicality, we present insights from qualitative feedback gathered within exchanges with a major European LEA.
Zusammenfassung Forschung an und mit Daten und auf der Basis von weitergehenden Informationen zur Wissensgewinnung ist allgegenwärtig, nicht erst seit Künstliche Intelligenz und Big Data (siehe dazu Kap. 10.1007/978-3-662-63449-3_1 und 10.1007/978-3-662-63449-3_2 in diesem Band) mediale Aufmerksamkeit und Forschungsetats treiben. Wird mit Daten geforscht, stehen rechtlich vor allem Belange der Privatheit und des Datenschutzes im weiteren Sinne im Raum, rechtlich abgesichert etwa durch Datenschutzrecht, Urheberrecht, Betriebs- und Geschäftsgeheimnisrecht oder in jüngerer Zeit auch Wettbewerbsrecht. Zudem treten – rechtlich bisher kaum erfasst – weitere Problembereiche wie die Qualitätssicherung, Archivierung und Zugänglichkeit von Datenbeständen, die Zugehörigkeit von Daten zu Forscher/innen bzw. deren Forschungsinstitutionen oder die Teilbarkeit und Übertragbarkeit von Rohdaten in das Sichtfeld regulatorischer Überlegungen. Eingebettet ist die Suche nach Informationen zudem fast immer in die Problematik von privaten und staatlichen Entscheidungen unter Unsicherheit, ihrer Herstellung und ihrer Kontrolle. Regulatorische Eingriffe in die Gewinnung, Nutzung und Verbreitung von Daten und des Einsatzes von Künstlicher Intelligenz in der Wissenschaft und Forschung können also aus vielerlei Perspektiven geboten sein.
Background The separation of parents and their prematurely born children during care in a neonatal intensive care unit (NICU) can have far-reaching consequences for the well-being of the parents and also of the children. The aim of this study is to evaluate the use of webcams on NICUs and to conduct a systematic assessment of their possible effects on parents and clinical staff. In addition, it aims at determining the need for webcams in German NICUs and to identify possible barriers and moderators. The development and evaluation of practical guidance for the use of webcams will enable the comprehensive education of clinical staff and parents and, as a result, is intended to mitigate any potential undesirable consequences. Methods The study will be based on a mixed methods approach including all groups concerned in the care. Qualitative data will be collected in interviews and focus groups and evaluated using content analysis. The collection of quantitative data will be based on written questionnaires and will aim to assess the status quo as regards the use of webcams on German NICUs and the effects on parents, physicians, and nursing staff. These effects will be assessed in a randomised cross-over design. Four NICUs will be involved in the study and, in total, the parents of 730 premature babies will be invited to take part in the study. The effects on the nursing staff, such as additional workload and interruptions in workflows, will be evaluated on the basis of observation data. Discussion This study will be the largest multicentre study known to us that systematically evaluates the use of webcams in neonatal intensive care units. The effects of the implementation of webcams on both parents and care providers will be considered. The results provide evidence to decide whether to promote the use of webcams on NICUs or not and what to consider when implementing them. Trial registration The trial has been registered at the German Clinical Trial Register (DRKS). Number of registration: DRKS00017755 , date of registration: 25.09.2019,
O presente artigo tem como objetivo apresentar o direito sobre proteção de dados na Europa, expondo os seus conceitos, princípios e traços fundamentais. Como a efetivação foi tema de grande importância para a motivação do RGPD-UE, introduzem-se as estruturas da implementação, particularmente a importância das autoridades independentes de fiscalização, bem como o novo mecanismo de coerência mediante o qual atua o novo Comitê Europeu para a Proteção de Dados (European Data Protection Board – EDPB) (4). Conclui-se a contribuição com uma perspectiva referente a novos desafios e novas abordagens de regulação (5).
Der Beitrag behandelt drei zentrale Herausforderungen für den Datenschutz – Profiling, Big Data und Künstliche Intelligenz sowie die Datenverarbeitung in Sozialen Netzwerken und auf Plattformen. Er schildert die Problemlagen und zeigt auf, wo die DSGVO Regelungen trifft und wo Regelungslücken bestehen.Die Autorin dankt Loïc Reissner für die kluge Unterstützung bei der Recherche/Fußnoten.
Die Digitalisierung bietet erhebliche Potenziale für eine Stärkung der Prävention im Gesundheitswesen. Daten aus verschiedenen klinischen und außerklinischen Quellen können strukturiert erfasst und mithilfe von Algorithmen systematisch verarbeitet werden. Präventionsbedarfe lassen sich schneller und präziser ermitteln, Interventionen zielgruppenspezifisch planen, implementieren und evaluieren. Zugleich ist es jedoch erforderlich, dass die Datenverarbeitung nicht nur hohen technischen, sondern auch ethischen Standards und den gesetzlichen Datenschutzbestimmungen entspricht, um Risiken zu vermeiden oder zu minimieren. Der vorliegende Diskussionsbeitrag beleuchtet in ethischer und rechtlicher Hinsicht die Potenziale und Risiken der digitalen Prävention zum einen aus einer „Datenperspektive“, bei der es um die Nutzung von gesundheitsrelevanten Daten geht, und zum anderen aus einer „Algorithmenperspektive“, bei der der Einsatz algorithmischer Systeme, einschließlich künstlicher Intelligenz, zur Bedarfserhebung und Evaluation präventiver Maßnahmen im Mittelpunkt steht. Abschließend werden Empfehlungen für Rahmenbedingungen formuliert, die geschaffen werden sollten, um die Weiterentwicklung der Prävention im Gesundheitswesen zu stärken.
In Österreich kategorisiert ab 2019 ein Algorithmus arbeitslose Personen nach ihren Chancen auf dem Arbeitsmarkt. Kritikerinnen bezeichnen ihn als Paradebeispiel eines diskriminierenden Algorithmus. Was steckt dahinter? Und können Algortihmen überhaupt diskriminieren?
Personal user data is collected and processed at large scale by a handful of big providers of Internet services. This is detrimental to users, who often do not understand the privacy implications of this data collection, as well as to small parties interested in gaining insights from this data pool, e.g., research groups or small and middle-sized enterprises. To remedy this situation, we propose a transparent and user-controlled data market in which users can directly and consensually share their personal data with interested parties for monetary compensation. We define a simple model for such an ecosystem and identify pressing challenges arising within this model with respect to the user and data processor demands, legal obligations, and technological limits. We propose myneData as a conceptual architecture for a trusted online platform to overcome these challenges. Our work provides an initial investigation of the resulting myneData ecosystem as a foundation to subsequently realize our envisioned data market via the myneData platform.