The University of Hong Kong · FACULTY OF ARTS & HUMANITIES

PHIL7002 Chap.4 Data Ethics, Privacy, Agency and Autonomy

- one subject, every graph, every model, every mark
8 Chapters4-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 4 of 10 · PHIL7002

Data Ethics, Privacy, Agency and Autonomy

Four dimensions instead of one essence

Ask most people what a breach of privacy is and the answers describe surveillance, cameras, long lenses and intercepted messages.

Those fit a right to be let alone, and the reading is explicit that there is more to it and that no internationally settled definition exists, taking as its anchor the human-rights formulation that nobody shall be subjected to arbitrary interference with their privacy, family, home or correspondence. Rather than hunt for an essence, the course divides the subject into four dimensions.

Bodily privacy secures bodily integrity against non-consensual interference. Territorial privacy protects surrounding space against being entered or watched. Communication privacy protects the means of communicating against interception.

Informational privacy, also called data protection, prevents information about a person being gathered, handled or applied in ways that person does not want.

Purpose limitation against the business model

A founding principle of data protection law is that a purpose must be named and narrow before anything is gathered, and the reading puts the collision plainly: that principle strikes at the heart of a model in which capability is developed by accumulating data whose future uses are not yet known.

This is a genuine conflict between a legal principle and an economic one rather than a loophole to be closed, and an argument that acknowledges only one side of it reads as naive.

Two consent failures with different remedies

The first is consent that is not meaningful.

Where a service is essential, such as banking or health, agreeing in order to obtain access is not a free choice, and this failure survives a perfectly drafted notice. The second is consent that was never sought, because a fact was derived rather than collected.

Inferred data, such as a neighbourhood read off a postcode, differs in kind from data a person supplied, and machine learning can predict sensitive facts from apparently innocuous inputs, so there was nothing to consent to.

A third issue sits alongside them: re-identification from anonymised data means a claim that a set is anonymous describes a technique and a moment rather than a permanent property.

What the collection does to the person

The privacy argument concerns what others learn. The agency argument concerns what the person becomes.

As systems nudge, filter, score, recommend and decide, they shift how people choose and how readily they refuse, and the named risk is habituation to deferring, which reduces the amount of deliberation actually performed.

The reading makes the related point about visibility: someone who believes they are roaming freely online is in fact seeing a curated, filtered and narrowed selection.

The first-person audit

One reading is a journalist downloading his own platform archive. Around five hundred advertisers held his contact information. His phone address book had been uploaded.

A list of people he had removed as friends was still held, and basic details such as a birthday could not be deleted at all. The company's position was that deletion removes material from view and that retained material has functional uses.

What makes this assignable is not the numbers but that every item maps onto a different failure: onward transfer, third-party data the user could not consent to release, retention, and a limit on erasure. Four remedies, one download, and a strong answer sorts them rather than listing them.

In this chapter

What this chapter covers

  • 01

    Why no settled definition of privacy exists

  • 02

    Bodily, territorial, communication and informational privacy

  • 03

    Purpose limitation and the accumulation model

  • 04

    Consent that is not meaningful because refusal was impossible

  • 05

    Inferred data, which consent never reaches

  • 06

    Re-identification as a limit on anonymisation claims

  • 07

    Nudging, filtering and habituation to deferring

  • 08

    Sorting a real data complaint into separable failures

Worked example · free

Sort one complaint into three separable failures

Q [9 marks]. AskSia-authored practice. A study app obtains permission to access contacts in order to suggest study partners. A year later a user finds that her whole contact list was uploaded including non-users, that a likely health condition was inferred from her session times and searches and used to target reminders, and that groups she deleted are still in her account history. Separate the failures and match a remedy to each. The marks shown are an AskSia study allocation, not a University marking scheme.
  • 3Classify the contact upload, noting the third-party dimension.
  • 3Classify the inferred health condition and say why consent does not reach it.
  • 3Classify the retained deletions and state the remedy honestly.
The contact upload is a purpose-limitation failure with a third-party dimension, because people who agreed to nothing are now in a database and the user could not consent for them. The inferred condition is the harder case: nothing sensitive was collected, a sensitive attribute was derived from innocuous inputs, so consent mechanisms do not reach it and the remedy has to govern inference rather than collection. The retained deletions are a retention question, and the honest analysis allows that an operator may have a functional reason for keeping them while still owing the user a statement that they are kept and for how long.
Sia tip — Ask whether a fact was collected or derived before proposing any remedy. A notice can cure an undisclosed purpose and can do nothing about an inference.
Glossary

Key terms

Informational Privacy
The dimension of privacy concerned with information about a person being gathered, handled or applied in ways that person does not want, also called data protection.
Territorial Privacy
The dimension protecting a person's surrounding space against being entered or watched.
Purpose Limitation
The principle that a purpose must be named and narrow before anything is gathered, which conflicts directly with accumulating data for uses not yet identified.
Collected Data
Information a person supplied, whether knowingly or through use of a service, which consent mechanisms are designed to govern.
Derived Data
A fact produced about a person by processing rather than supplied by them, which escapes consent because nothing about it was ever asked.
Re-identification
Recovering an individual's identity from data that had been anonymised, which is why an anonymisation claim describes a technique and a moment rather than a permanent state.
FAQ

Data Ethics, Privacy, Agency and Autonomy FAQ

Why is agreeing to terms sometimes not real consent?

Because consent has to be a choice, and where the service is essential there is no second option. Someone opening a bank account or using a health application agrees in order to obtain access, so the agreement records a necessity rather than a preference. The important consequence is that this failure survives a clearly drafted notice, which means the remedy is not better disclosure but a limit on what may be asked for at all.

Separate whether terms were disclosed from whether refusing them was possible.

What makes inferred data a different problem from collected data?

Nothing was handed over, so there was no moment at which permission could have been sought or withheld. A model can predict a sensitive attribute from entirely innocuous inputs, which means the usual machinery of notice and agreement never engages.

That is why the remedy has to govern inference itself, by restricting which attributes may be derived or how a derived attribute may be used, rather than adding another paragraph to a consent screen.

Does the agency argument add anything to the privacy argument?

Yes, and they can come apart. Privacy asks what others learned; agency asks what the learning did to the person. A system can respect every data rule and still shift how someone chooses, by nudging, filtering, scoring and recommending until deferring becomes a habit and less deliberation is performed.

A complaint can therefore succeed on one and fail on the other, so the two are argued separately even when they arise from the same collection.

Study strategy

Exam move

Download your own data export from one service and sort every item into collected or derived, then into a dimension of privacy. The exercise takes twenty minutes and it converts an abstract chapter into a list of specific claims you could defend. Finish by writing the one remedy that would address the largest group of items, which is the move a policy brief needs.

Working through Data Ethics, Privacy, Agency and Autonomy in PHIL7002? Sia is AskSia’s AI Arts and Humanities tutor — ask any PHIL7002 Data Ethics, Privacy, Agency and Autonomy question and get a clear, step-by-step explanation grounded in how PHIL7002 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + your other The University of Hong Kong subjects - and 1,000+ Bibles across every Australian university.
Sia - your PHIL7002 tutor, unlimited, worked the way the exam marks it
The full 4-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works