{"id":51,"date":"2020-07-27T11:19:00","date_gmt":"2020-07-27T10:19:00","guid":{"rendered":"https:\/\/blogs.uwe.ac.uk\/dragon\/?p=51"},"modified":"2022-07-20T11:22:08","modified_gmt":"2022-07-20T10:22:08","slug":"five-safes-or-one-plus-four-safes-musing-on-project-purpose","status":"publish","type":"post","link":"https:\/\/blogs.uwe.ac.uk\/dragon\/five-safes-or-one-plus-four-safes-musing-on-project-purpose\/","title":{"rendered":"\u2018Five Safes\u2019 or \u2018One Plus Four Safes\u2019? Musing on project purpose"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">by Felix Ritchie and Francesco Tava<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">A&nbsp;<a href=\"https:\/\/www2.uwe.ac.uk\/faculties\/BBS\/BUS\/Research\/BCEF\/Frameworks.pdf\">recent working paper<\/a>&nbsp;discusses the \u2018Fives Safes\u2019 framework for confidential data governance and management. This splits planning into a number of separate but related topics:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>safe project: is this an appropriate use of the data? Is there a public benefit, or excessive risk?<\/li><li>safe people: who will be using the data? What skills do they have?<\/li><li>safe setting: how will the data be accessed? Are there limits on transferring it?<\/li><li>safe data: can the detail in the data be reduced without excessively limiting its usefulness?<\/li><li>safe outputs: is confidentiality protected in products such as tables of statistics?<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This framework has been widely adopted, particularly in government, both as a practical guide (eg &nbsp;<a href=\"https:\/\/privacy-analytics.com\/resources\/white-papers\/unlock-the-five-safes-and-maximize-your-data\/\">this one&nbsp;<\/a>) and as a basis for legislation (eg the UK&nbsp;<a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2017\/30\/contents\/enacted\">Digital Economy Act<\/a>&nbsp;or the&nbsp;<a href=\"https:\/\/www.legislation.sa.gov.au\/LZ\/C\/A\/PUBLIC%20SECTOR%20(DATA%20SHARING)%20ACT%202016.aspx\">South Australia data sharing legislation<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a practical guide, there is one obvious limitation. There is no hierarchy among the \u2018safes\u2019, and they are all interrelated; so which should you put most emphasis on?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We use the Five Safes to structure courses in confidential data management. One of the exercises asks the attendees to rank them as \u2018what should we be most\/least concerned with?\u2019 The point of the exercise is not to come up with a definitive ranking, but to get the attendees to think about how different elements might matter in different circumstances.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This exercise generates much discussion. Over the years, we have had participants putting forward good arguments for each of the Five Safes as being the most important. Traditionally, and in the academic literature, Safe Data is seen as the most important: reduce inherent risk in the data, and all your problems go away. In contrast, in the \u2018user centred\u2019 planning we now advocate (eg&nbsp;<a href=\"https:\/\/uwe-repository.worktribe.com\/OutputFile\/908265\">here<\/a>], Safe People is key: know who your users are, and design ethical processes, IT systems, training and procedures for them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When training, this is the line we usually take, because we are training people to use systems which have already been designed. The aim of the training is to help people understand the community they are part of. Our views are therefore coloured by the need to work within existing systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our thinking on this has been challenged by the developments in Australia. The Australian federal government is proposing a cross-government data sharing strategy based on the \u2018<a href=\"https:\/\/www.pmc.gov.au\/resource-centre\/public-data\/data-sharing-principles\">Australian Data Sharing Principles<\/a>\u2019 (ADSPs). The ADSPs are based on the Five Safes but designed as a detailed practical guide to Australian government departments looking to share data for analysis. As part of the legislative process, the Australian government has engaged in an extensive consultation since 2018, including public user groups, privacy advocates, IT specialists, the security services, lawyers, academic researchers, health services, the Information Commissioner, and the media.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most of the concerns about data sharing arising in the consultation centre on the \u2018safe project\u2019 aspect. Typical questions that cropped up frequently included:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>How do we know the data sharing will be legal\/appropriate\/ethical?<\/li><li>Who decides what is in the \u2018public interest\u2019?<\/li><li>How do you prevent shared data, approved for one purpose, being passed on or re-used for another purpose without approval?<\/li><li>What sort of people will we allow to use the data? Should we trust them?<\/li><li>What will happen to the data once the sharing is no longer necessary? How is legacy data managed?<\/li><li>Do we need to lay down detailed rules, or can we allow for flexible adherence to principles?<\/li><li>Where are the checks and balances for all these processes?<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These are all questions which need to be addressed at the design stage: define the project scope, users and duration, and then assess whether the likely benefits outweigh costs and reasonable risks. If this can\u2019t be done\u2026 why would you take the project any further?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Similarly, in recent correspondence with a consulting firm, it emerged that a key part of their advice to firms on data sharing is about use: the lawfulness of the data sharing is relatively easy to establish \u2013 once you have established the uses to which that shared data will be put. Some organisations have argued that there should be an additional \u2018safe\u2019 just to highlight the legal obligations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is particularly pertinent for data sharing in the public sector, where organisations face continual scrutiny over the appropriate use of public money. A clear statement of purpose and net benefits at the beginning of any project can make a substantial difference to the acceptability of the project. And whilst well-designed and well-run projects tend to be ignored by people not involved, failures in public data sharing (eg&nbsp;<a href=\"https:\/\/www.itnews.com.au\/news\/federal-court-bins-robodebts-defective-algorithm-534677\">Robodebt<\/a>&nbsp;or&nbsp;<a href=\"https:\/\/www.bbc.com\/news\/health-26259101\">care.data<\/a>) tend to have negative repercussions far beyond the original problems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is not the only concern facing data holders in a digital age of multi-source data. Handling confidential data always involves costs and benefits. Traditional approaches that focus on Safe Data identify the data holder as the relevant metric for these costs and benefit.&nbsp;<a href=\"https:\/\/zenodo.org\/record\/3943775#.Xxg5-pMzbOQ\">A recent paper<\/a>&nbsp;shows how this vision is at odds with the most recent developments in the information society that we live in. Consider the use of social media in research: is any of the actions by the author, the distributor or the researcher sufficient in itself to establish the moral authority of an end use? In this modified context, traditional ethical notions such as individual agency and moral responsibility are gradually substituted by a framework of distributed morality, whereby multiagent systems (multiple human interactions, filtered and possibly extended by technology) are responsible for big morally-loaded actions that take place in today\u2019s society (<a href=\"https:\/\/link.springer.com\/article\/10.1007\/s11948-012-9413-4\">see on this<\/a>).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this complex scenario, taking the data holder as the only arbiter of data governance might be counterproductive, insofar as practices that are morally neutral for the data holder (for example, refusing to consider data sharing) could damage the multiagent infrastructure which that data holder is part of (eg limiting incentives to participate). On the other hand, practices that can cause a minor damage to one of the agents (such as reputational risk for the data holder) could lead to major collective advantages, whose attainment would justify that minor damage, and make acceptable on a societal basis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In order to minimise the risks, an innovative data management approach should look at the web of collective and societal bonds that links together data owners and users. In practice, this means that decision-making regarding confidential data management will not be grounded on the individual agency and responsibility of individual agents, but will rather correspond to a balance of subjective probabilities. On these premises, focusing on the Safe Project makes pre-eminent the notion that data should be made available for research purposes if the expected benefit to society outweighs the potential loss of privacy for the individual. The most challenging question is, of course, how to calculate this benefit, when so many of the costs and benefits are unmeasurable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And this is the difference between Safe Projects and the others. \u2018Safe projects\u2019 addresses the big conceptual questions. Safe people, safe settings and safe outputs are about the systems and procedure to implement those concepts, whilst Safe Data is the residual (select an appropriate level of detail once the context is defined). So rather than Five Safes perhaps there should be One Plus Four Safes\u2026<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">About the authors<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Felix Ritchie is Professor of Applied Economics in the department of Accounting Economics and Finance<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Francesco Tava is Senior Lecturer in Philosophy in the Department of Health and Applied Social Sciences<\/p>\n","protected":false},"excerpt":{"rendered":"<p>by Felix Ritchie and Francesco Tava A&nbsp;recent working paper&nbsp;discusses the \u2018Fives Safes\u2019 framework for confidential data governance and management. This splits planning into a number of separate but related topics: safe project: is this an appropriate use of the data? Is there a public benefit, or excessive risk? safe people: who will be using the &hellip; <a href=\"https:\/\/blogs.uwe.ac.uk\/dragon\/five-safes-or-one-plus-four-safes-musing-on-project-purpose\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;\u2018Five Safes\u2019 or \u2018One Plus Four Safes\u2019? Musing on project purpose&#8221;<\/span><\/a><\/p>\n","protected":false},"author":48,"featured_media":52,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"wds_primary_category":0,"footnotes":""},"categories":[5,3],"tags":[],"class_list":["post-51","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-research-access-and-governance-network","category-dragon"],"_links":{"self":[{"href":"https:\/\/blogs.uwe.ac.uk\/dragon\/wp-json\/wp\/v2\/posts\/51","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.uwe.ac.uk\/dragon\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.uwe.ac.uk\/dragon\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.uwe.ac.uk\/dragon\/wp-json\/wp\/v2\/users\/48"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.uwe.ac.uk\/dragon\/wp-json\/wp\/v2\/comments?post=51"}],"version-history":[{"count":1,"href":"https:\/\/blogs.uwe.ac.uk\/dragon\/wp-json\/wp\/v2\/posts\/51\/revisions"}],"predecessor-version":[{"id":53,"href":"https:\/\/blogs.uwe.ac.uk\/dragon\/wp-json\/wp\/v2\/posts\/51\/revisions\/53"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.uwe.ac.uk\/dragon\/wp-json\/wp\/v2\/media\/52"}],"wp:attachment":[{"href":"https:\/\/blogs.uwe.ac.uk\/dragon\/wp-json\/wp\/v2\/media?parent=51"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.uwe.ac.uk\/dragon\/wp-json\/wp\/v2\/categories?post=51"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.uwe.ac.uk\/dragon\/wp-json\/wp\/v2\/tags?post=51"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}