Australia’s bold proposals for government data sharing

Posted on

By Felix Ritchie.

In August I spent a week in Australia working with the new Office of the National Data Commissioner (ONDC). The ONDC, set up at the beginning of July, is barely two months old but has been charged with the objective of getting a whole-of-government approach to data sharing ready for legislation early in 2019.

This is a mammoth undertaking, not least because the approach set out in the ONDC’s Issues Paper proposes a new way of regulating data management. Rather than the traditional approach of trying to specify in legislation exactly what may or may not be allowed, the ONDC is proposing a principles-based approach: this focuses on setting out the objectives of any data sharing and the appropriate mechanisms by which access is governed and regulated.

In this model, the function of legislation is to provide the ground rules for data sharing and management within which operational decisions can be made efficiently. This places the onus on data managers and those wanting to share data to ensure that their solutions are demonstrably ethical, fair, appropriate and sensible. On the other hand, it also frees up planners to respond to changing circumstances: new technologies, new demands, shifts in attitudes, the unexpected…

The broad idea of this is not completely novel. In recent years, the principles-based approach to data management in government has increasingly come to be seen as operational best practice, allowing as it does for flexibility and efficiency in response to local conditions. It has even been brought into some legislation, including the UK’s Digital Economy Act 2017 and the European General Data Protection Regulation. Finally, the monumental Australian Productivity Commission report of 2017  laid out much of the groundwork, by providing an authoritative evidence base and a detailed analysis of core concepts and options.

In pulling these strands together, the ONDC proposals move well beyond current legislation but into territory which is well supported by evidence. Because of the unfamiliarity with some of the concepts, the ONDC has been carrying out an extensive consultation, some of which I was able to observe and participate in.

A key proposal is to develop five ‘Data Sharing Principles’, based on the Five Safes framework (why, who, how, with what detail, with what outcomes) as the overarching structure. The Five Safes is the most widely used model for government data access but has only been used twice before to frame legislation, in the South Australia Public Sector (Data Sharing) Act 2016 and the  UK Digital Economy Act 2017.

The most difficult issues facing the ONDC arise from the ‘why’ domain: what is the public benefit in sharing data and the concomitant risk to an individual’s privacy? How will ‘need-to-know’ for data detail be assessed? What are the mechanisms to prevent unauthorised on-sharing of data? How will shared data be managed over its lifecycle, including disposal? To what uses can shared data be put? Can data be shared for compliance purposes? How can proposals be challenged?

These are all good questions, but they are not new: any ethics or approvals board worth its salt asks similar questions, and would expect good answers before it allows data collection, sharing or analysis to proceed. A good ethics board also knows that this is not a checklist: ethical approval should be a constructive conversation to ensure a rock-solid understanding of what you’re trying to achieve and the risks you’re accepting to do so.

This is the also the crux of the principles-based approach being taken by the ONDC: it is not for the law to specify how things should be done, nor to specify what data sources can be shared. But the law does provide the mechanisms to ensure that any proposals put forward can be assessed against a clear purpose test around when data may and may not be shared and that appropriate safeguards are in place…

Finally, the law will require transparency; this has to be done in sunlight. A public body, using public money and resources for the public benefit, should be able to answer the hard questions in the public arena; otherwise, where is the accountability? The ONDC will require data sharing agreements to be publicly available, so people can see for what purpose (and with what associated protections) their data are being used.

To some, this need to justify activities on a case-by-case basis, rather than having a black-and-white yes/no rule, might seem like an extra burden. The aim of the consultation is to ensure that this isn’t the case. In fact, a transparent, multi-dimensional assessment is any project’s best friend: it provides critical input at the design stage and helps to spot gaps in planning or potential problems, as well as giving opponents a clear opportunity to raise objections.

Of course, even if the legislation is put in place, there is still no guarantee that it will turn out as planned. As I have written many times (for example in 2016), attitudes are what matter. The best legislation or regulation in the world can be derailed by individuals unwilling to accept the process. This is why the consultation process is so important. This is also why the ONDC has been charged with the broader role of changing the Australian public sector culture around data sharing, which tends to be risk-averse. The ONDC also has a role to build and maintain trust with the public through better engagement to hear their concerns.

From my perspective, this is a fascinating time. The ONDC’s proposals are bold but built on a solid foundation of evidence. In theory, they propose a ground-breaking way to offer a holy trinity of flexibility, accountability, and responsibility. If the legislation ultimately reflects the initial proposals, then I suspect many other governments will be beating a path to Australia’s door.

All opinions expressed are those of the author.

Training Researchers to Work with Confidential Data: A New Approach

Posted on

Prof Felix Ritchie of UWE’s Business School has recently spent time with the Northern Ireland Statistics and Research Agency and makes the following analysis.

I’ve just spent two days at the Northern Ireland Statistics and Research Agency (NISRA), working with them to develop training for researchers who need access to the confidential data held by NISRA for research. This training is jointly being developed by the statistical agencies of the UK (NISRA, the General Register Office for Scotland, and the Office for National Statistics in England and Wales), as well as HMRC, the UK Data Archive and academic partners. The project is being led by ONS as part of its role to accredit researchers under the new Digital Economy Act, with UWE providing key input; other statistical agencies, such as INSEE
in France and the Australian Bureau of Statistics, are being consulted and are trialling
some of the material.

Training researchers in the use of confidential data is common across statistical agencies around the world, particularly when those researchers need access to the most sensitive data only available through Controlled Access Facilities (CAFs). The growth in CAFs in recent years has mostly come from virtual desktops which allow researchers to run unlimited analyses while still operating in an environment controlled by the data holder. There are now six of these in the UK, and many countries in continental Europe, North America and Oceania operate at least one. The existence of CAFs has led to an explosion in social science research as many things that were not previously allowed because it was too risky to send out data (such as use of non-public business data, or detailed personal data) have now become feasible and cost-effective.

All agencies running CAFs provide some training for researchers; around half of these use ‘passive’ training such as handouts or web pages, but the other half require face-to-face training. Much of this training has evolved from a programme developed at ONS in the UK in the 2000s and this training was recommended as an example of ‘best practice’ for face-to-face training by a Eurostat expert group.

However, this style of training is showing its age. Such training typically has two components: firstly how to behave in the CAFs and secondly how to prevent confidential data from mistakenly showing up in research outputs (‘statistical disclosure control’, or SDC). Both are typically taught mechanistically, in the form of dos and don’ts, explanations of laws and penalties and lots of SDC exercises. Overall the aim of the courses is to impart information to the researcher.

The new training is radically different from the old training. It starts from the premise that researchers are both the biggest risk and the biggest advantage to any CAF: the biggest risk because a poorly-trained or malcontented researcher can negate any security mechanism put in place; the biggest advantage because highly-motivated researchers means cheaper system design, better and more robust security and the chance for the data holder to exploit the goodwill of researchers in methodological research, for example.

In this world the main aim of the training is to encourage the researcher to see himself or herself as part of the data community. If this can be established then the rest of the training follows as a consequence. For example, knowledge of the legal environment or SDC is shared not because it keeps you out of jail but because everyone needs to understand this so the community as a whole works. This gives the course quite a different feel to more traditional courses: much of the day is spent in open-ended facilitated discussions exploring concepts of data access.

The training was designed from the ground up in order to take advantage of recent developments in thinking about data access and SDC. This was also done to avoid being restricted by having to ‘fit’ preconceived ideas about what worked or not; material was included on its own merits, not whether “this was what we used to do…”. For example, the previous SDC component had a large number of numerical examples, developed over many years, leading to attendees remarking on afternoons spent “doing Sudoku”. We reviewed every example to identify the minimum set of principles needing to be explored and then wrote a small number of new examples based on this minimum set. On the other hand, the previous training had relatively little to say about the context for checking outputs for confidentiality breaches; this has now been expanded as it fits with the ethos of understanding why things are done.

Of course, this was not all plain sailing. The original structure, trialled in June 2017, had just one presentation before being comprehensively abandoned. Modules have dropped in and out and been moved around. The initial test for the course has been completely rewritten (a topic for a later blog). Various sections have been inserted as ‘options’ to take account of regional variations in operating practices. Throughout this, multiple organisations have been able to feed into the process so that the final product itself has a sense of community ownership.

We are now at the stage of training-the-trainers to enable independent delivery around the UK. This is already generating much feedback for the future development of the course: for example, a need has arisen for ‘crib sheets’ to help in the facilitation of certain exercises. Overall, however, we are confident that we have a well-structured, informative, course that meets the needs of 21st century data training.

Further reading: for more information on the evidential and conceptual basis for the course, see Ritchie F., Green E., Newman J. and Parker T. (2017) “Lessons Learned in Training ‘Safe Users’ of Confidential Data“. UNECE work session on Statistical Data Confidentiality 2017. Eurostat. 

Training Researchers to Work with Confidential Data: A New Approach

Posted on

Prof Felix Ritchie of UWE’s Business School has recently spent time with the Northern Ireland Statistics and Research Agency and makes the following analysis.

I’ve just spent two days at the Northern Ireland Statistics and Research Agency (NISRA), working with them to develop training for researchers who need access to the confidential data held by NISRA for research. This training is jointly being developed by the statistical agencies of the UK (NISRA, the General Register Office for Scotland, and the Office for National Statistics in England and Wales), as well as HMRC, the UK Data Archive and academic partners. The project is being led by ONS as part of its role to accredit researchers under the new Digital Economy Act, with UWE providing key input; other statistical agencies, such as INSEE
in France and the Australian Bureau of Statistics, are being consulted and are trialling
some of the material.

Training researchers in the use of confidential data is common across statistical agencies around the world, particularly when those researchers need access to the most sensitive data only available through Controlled Access Facilities (CAFs). The growth in CAFs in recent years has mostly come from virtual desktops which allow researchers to run unlimited analyses while still operating in an environment controlled by the data holder. There are now six of these in the UK, and many countries in continental Europe, North America and Oceania operate at least one. The existence of CAFs has led to an explosion in social science research as many things that were not previously allowed because it was too risky to send out data (such as use of non-public business data, or detailed personal data) have now become feasible and cost-effective.

All agencies running CAFs provide some training for researchers; around half of these use ‘passive’ training such as handouts or web pages, but the other half require face-to-face training. Much of this training has evolved from a programme developed at ONS in the UK in the 2000s and this training was recommended as an example of ‘best practice’ for face-to-face training by a Eurostat expert group.

However, this style of training is showing its age. Such training typically has two components: firstly how to behave in the CAFs and secondly how to prevent confidential data from mistakenly showing up in research outputs (‘statistical disclosure control’, or SDC). Both are typically taught mechanistically, in the form of dos and don’ts, explanations of laws and penalties and lots of SDC exercises. Overall the aim of the courses is to impart information to the researcher.

The new training is radically different from the old training. It starts from the premise that researchers are both the biggest risk and the biggest advantage to any CAF: the biggest risk because a poorly-trained or malcontented researcher can negate any security mechanism put in place; the biggest advantage because highly-motivated researchers means cheaper system design, better and more robust security and the chance for the data holder to exploit the goodwill of researchers in methodological research, for example.

In this world the main aim of the training is to encourage the researcher to see himself or herself as part of the data community. If this can be established then the rest of the training follows as a consequence. For example, knowledge of the legal environment or SDC is shared not because it keeps you out of jail but because everyone needs to understand this so the community as a whole works. This gives the course quite a different feel to more traditional courses: much of the day is spent in open-ended facilitated discussions exploring concepts of data access.

The training was designed from the ground up in order to take advantage of recent developments in thinking about data access and SDC. This was also done to avoid being restricted by having to ‘fit’ preconceived ideas about what worked or not; material was included on its own merits, not whether “this was what we used to do…”. For example, the previous SDC component had a large number of numerical examples, developed over many years, leading to attendees remarking on afternoons spent “doing Sudoku”. We reviewed every example to identify the minimum set of principles needing to be explored and then wrote a small number of new examples based on this minimum set. On the other hand, the previous training had relatively little to say about the context for checking outputs for confidentiality breaches; this has now been expanded as it fits with the ethos of understanding why things are done.

Of course, this was not all plain sailing. The original structure, trialled in June 2017, had just one presentation before being comprehensively abandoned. Modules have dropped in and out and been moved around. The initial test for the course has been completely rewritten (a topic for a later blog). Various sections have been inserted as ‘options’ to take account of regional variations in operating practices. Throughout this, multiple organisations have been able to feed into the process so that the final product itself has a sense of community ownership.

We are now at the stage of training-the-trainers to enable independent delivery around the UK. This is already generating much feedback for the future development of the course: for example, a need has arisen for ‘crib sheets’ to help in the facilitation of certain exercises. Overall, however, we are confident that we have a well-structured, informative, course that meets the needs of 21st century data training.

Further reading: for more information on the evidential and conceptual basis for the course, see Ritchie F., Green E., Newman J. and Parker T. (2017) “Lessons Learned in Training ‘Safe Users’ of Confidential Data“. UNECE work session on Statistical Data Confidentiality 2017. Eurostat. 

Happiness in Bangladesh: The Role of Religion and Connectedness

Posted on

Dr Tim Hinks, Senior Economics Lecturer at UWE, in conjunction with fellow academics Joe Devine and Arif Naveed have published this paper in the Journal of Happiness Studies


Abstract
Research into the relation between religion and happiness offers inconclusive evidence. Religion seems to matter but it is not entirely clear how and why. Moreover much of the research to date is rooted in western experiences. This article analyzes primary data from Bangladesh to examine how religion figures in people’s wellbeing and life chances. It identifies differences in reported happiness between the country’s two largest religious populations: Muslims and Hindus. Our main argument is that the significance of religion is only really understood when considered alongside social, economic and political processes. The data and analysis make an important contribution to the limited knowledge we have of the relation between religion, political connectedness and happiness in non-western societies. It also highlights the need to incorporate more contextualizing analyses into our assessments of the relation between religion and happiness.

Introduction
1.1 Religion and Wellbeing
Academic interest in the connection between religion and happiness has grown significantly over recent years, and produced an impressive body of scholarship. Many studies demonstrate a positive association between religion and happiness. The significance of this association should not be underestimated. For example Witter et al. (1985) reviewed 28 wellbeing studies and found that the majority reported a positive association between religion and subjective wellbeing. Moreover they found that religion accounted for 2–6% of the variation in subjective wellbeing. Ellison et al. (1989) went one step further arguing that the effect of religion on subjective wellbeing is as strong if not stronger than income. This finds some support in Luttmer’s claim that religion is positively correlated with measures of subjective wellbeing even when demographic variables such as income, age and marital status are taken into account (Luttmer 2005).

In what ways then does religion make us happy? The evidence offered by the literature falls broadly into two categories, reflecting a distinction first introduced by Allport and Ross’s (1967) pioneering work into religious orientation. According to Allport and Ross, people have intrinsic or extrinsic motivations in relation to religion. The latter sees religion as a means to achieve particular goals including non-religious ones while the former is autonomous and considers religion as an end in itself. Although this distinction is not without its critics (see Lavrič and Flere 2007), it has left its mark on research into religion and happiness. On the one hand therefore it is argued that religion enhances wellbeing because it offers access to support structures or enables individuals to cope with stress (Lim and Putnam 2010), or to adapt preferences or aspirations (Clark 2012). On the other hand, religion enhances wellbeing because it offers a sense of meaning and purpose, and acts as a moral compass in this as well as the ‘after-life’ (Greeley and Hout 2006). What is striking however is that we can find evidence of both intrinsic and extrinsic benefits of religion in all of the world’s major religions including Islam (Sahraian et al. 2013), Hinduism (Ganga and Kutty 2013), Judaism (Levin 2014), Buddhism (Elliot 2014), and Christianity (Steiner et al. 2010). Although the effects of religion on wellbeing are generally reported as being positive, there are important counter observations. First, religion may also be a factor in producing negative wellbeing values. Ellis (1962) for example reports that excessive religion can produce depression and mental disorders. More recently, Mookerjee and Beron’s cross country analysis of the relation between religion and happiness concluded that contexts with high levels of religious fractionalisation produce relatively lower levels of happiness (Mookerjee and Beron 2005). Second, much of the literature draws conclusions on the effects of religion from studies that focus entirely on individual level processes. As such the context is overlooked. Some recent work has warned of the dangers of this approach arguing that positive individual level effects disappear when contextualised with a country’s overall level of religiosity (Eichhorn 2012). Third, it is important to acknowledge the bias in the literature towards religious experiences and contexts in the West with relatively little attention being paid to non-western contexts where the parameters of any discussion about religion and wellbeing may be radically different (Joshanloo 2013, 2014). Finally, most of the literature rests on an assumption about the direction of causality. Thus it is assumed that religion leads to happiness as opposed to happiness leading to religion.

1.2 Religion and Wellbeing in Bangladesh
Our research focuses on the relation between religion and wellbeing in Bangladesh, and as such contributes to the nascent scholarship focusing specifically on wellbeing in countries of the Global South (Diener et al. 2013; Shams 2016). Bangladesh is a particularly appropriate location in which to examine wellbeing dynamics since it throws up a number of wellbeing puzzles which all reflect different aspects of the Easterlin paradox (Easterlin 1974). Thus in the 1990s, Bangladesh reported higher levels of happiness than many other countries, including the UK, where people enjoy significantly larger per capita incomes and access to a wider range of basic services and good (Worcester 1998). Since the 1990s, the country has made significant progress in reducing poverty and introducing socio-economic improvements (Devine and Wood 2017), and can be described as a global international development success story. Despite this however, levels of reported happiness seem to be declining (Asadullah and Chaudhury 2012). Improved living standards therefore seem to be having an impact upon the wellbeing expectations and demands of its citizens (Diener et al. 2013).

The early years of state formation in Bangladesh were anchored in a very clear commitment to secularism, and indeed early writings on religion, most notably Islam, emphasised its syncretic and malleable qualities (Uddin 2006). However since the early 1990s, a different expression of religion has emerged which has been described as neo-orthodox, militant, and extremist (Riaz 2004). These changes reflect deeper questions about what constitutes ‘proper’ Islam in Bangladesh and also what constitutes a ‘Muslim democracy’ (Devine and White 2013). The unresolved nature of these questions is etched visibly in the relations between the dominant Muslims and followers of other religions in the country. Muslims in Bangladesh constitute around 87% of the population. While the remaining 13% belong to a number of different religions, Hinduism is by far the largest minority religion in the country.

In Bangladesh religion is directly translated as dharma, a term which derives from the Sanskrit dhr meaning to sustain, support or uphold (Mahony 1987). However dharma means more than just ‘religion’, at least as understood in the West. Etymologically, dharma refers to the ‘proper cosmo-moral ordering’ of things (Inden 1985). In this sense, everything that exists, animate or inanimate, has its dharma. Even religion has its own dharma. Second, the word dharma is used in everyday speech to ask about one’s religion. So it is quite common in Bangladesh to ask: ‘apnar dharma ki?’, i.e. what is your religion?. The response to this question however reveals two things. First, it communicates a person’s religious affiliation. Second, the declaration of a religious affiliation or identity provides important implicit information on which social groups you belong to and can interact with; what practical lifestyle choices you can or cannot make; what constitutes appropriate behaviour and conduct; what aspirations you might have; who you can marry, what food you can eat, and so forth (Kotalova 1993). Dharma therefore is as much about everyday practical choices and opportunities as it is about religious affiliation.

There is very little literature on the relation between religion and wellbeing in Bangladesh. The founding research projects which inform this paper,1 found statistically significant correlations between religion and happiness, especially among older respondents (Camfield et al. 2009). In more qualitative follow-up research, we identified a number of areas where the influence of religion on wellbeing comes to the fore including the structuring of community relations (Devine and White 2013), responsibilities, obligations and expectations around marriage, gender and intergenerational relations (White 2012), and the development of political culture and democracy (Basu et al. 2017).

Recently Asadullah and Chaudhury (2012) offer a very different argument. Analysing data from 2400 households across 12 districts in Bangladesh, the authors claim that neither religion nor gender had any significant impact on happiness. Instead they found that the influence of inter-personal relations and social trust on happiness was statistically significant. This opens up a new avenue into an equally under-researched area, i.e. trust. The only study on trust we could identify was Gupta et al’s (2013) comparative analysis of the behaviour of Muslims and Hindus in Bangladesh and West Bengal in India. In the latter, Hindus constitute the majority group and Muslims the minority; whilst in the former, the opposite is true. In both sites, the authors found that identity based on status (i.e. being a member of the majority or minority group) rather than religion per se determined levels of trust and trustworthiness. We return to this finding in our  Sect. 3 below.

Our research makes three important contributions. First, to the best of our knowledge, the findings presented here are the first to quantitatively look at the impact of religious identity on people’s self-reported happiness in Bangladesh. Second, given that the analysis is anchored in Bangladesh our research offers an important contribution to a literature that is dominated by Western experiences and understandings of religion. Finally, the article contributes to the growing but still relatively thin literature on wellbeing and happiness in the Global South.

For the full paper see http://bit.ly/2FcGkGP

Back to top