In an article discussing the European Union’s (EU) General Data Protection Regulation (GDPR), Danny Palmer discusses the many ways the GDPR empowers ordinary citizens to take control of their private data. In a first of its kind regulation, the GDPR looks to hold organizations more accountable and provide additional avenues to pursue legal action for EU citizens. While in stark contrast, The United States appears to have a less than desirable structured approach to protecting citizens’ private data that seem to vary from state to state. Palmer argues that without some sort of adaptation of the GDPR in the United States, there will forever remain ethical concerns regarding how private data is collected, stored, and accessed. For this case analysis, I will utilize a Kantian Deontology perspective to argue that the United States should follow the European Union’s lead and adopt similar privacy laws not only because individuals deserve to have their privacy respected, but because businesses and organizations have the moral obligation to respect the autonomous existence of individuals and place ethics over the pursuit of generating profits.
The basis of Kantian Deontology, applied to this case analysis, is best explained through the idea that all individuals possess inherent moral worth, and in many ways, this can be directly applied to the debate on whether or not the U.S should adapt GDPR-like laws to protect its citizens’ personal data. From this perspective, the autonomy of an individual should be first respected, protected, and each individual should be empowered to maintain meaningful control over the processes of how their information is collected, stored, and ultimately used. Throughout this analysis, I will explore separate articles that, similarly to Palmer, highlight the need for the United States of America to adopt legislation similar to the EU in order to advocate and protect the private data of its citizens. Although Palmer’s article is broad in scope, there are many intricacies interwoven throughout his points of view. It is through the lens of Kantian Deontology along with other contributors that Palmer’s argument becomes united in solidarity in the effort to advocate for privacy rights of all of mankind.
In Zimmer’s article “But the Data Is Already Public”, the very ethical dilemma of privacy is highlighted with the existence of social media, and what is to reasonably be expected to be private in a public forum (such as Facebook). One of the key components of Zimmer’s article is his challenge to the notion that posting information on a publicly accessible website does not automatically eliminate the user’s expectation of privacy. Zimmer’s main argument towards this concept is that because the information is accessible, it does not constitute nor ethically justify the collection and use of said information. Zimmer’s concept of public availability not eliminating ethical obligations pairs well with Palmer’s justification of adopting GDPR adjacent legislation and policies within the United States. Taking this very concept and applying it to this case study, it appears that Zimmer would likely find many justifications for the GDPR to be adopted and ratified into law. The foundation of Zimmer’s concept applies directly to the core principles of the GDPR and why Palmer finds the GDPR to be beneficial to United States citizens. Part of Palmer’s arguments in favor of GDPR-like legislation is that individuals should have greater control over the protection of their personal information, and provide a means to exercise more meaningful control over their data. This directly coincides with Zimmer’s argument that the accessibility of information does not necessarily provide an ethical reasoning for its use nor does it dissolve the individual’s right to privacy. From the Kant perspective, both the arguments of Palmer and Zimmer align under the ethical principle of treating the individual as an end, and not the means of potential monetary gain. Both Zimmer’s concept of public data and Kant Deontology would both argue that the adaptation of GDPR legislation would likely raise the ethical standards across the board, and would ultimately bring about transparency and standardize this practice, while also creating a means to hold establishments and organizations accountable.
Similarly to Zimmer, Buchanan’s Ethics of Big Data Research cross examines the nuances of ethics within the field of data research. While she agrees that the standard ethics involved in its current form are likely sub-optimal, Buchanan provides a defensible approach to this dilemma by offering several concepts and ideas that further explain the inherent problems with the field itself. Of the many concepts Buchanan offers, there is one in particular that requires further examination. Her concept of ethical decision-making being a continuous process sheds light on one of the most fundamental issues within the field of data research ethics. Buchanan argues that as technology continues to evolve, there is a significant ethical problem primarily caused by how previously collected data may be re-used, that may have deviated from its original and intended use. As a result of this, her stance of businesses having a moral obligation to continuously evaluate their ethics with regard to how individuals’ privacy is treated. Consider the following: if you were to give your consent to have your data collected only for research purposes at an academic institution, and then at some point in the future, that academic institution was then giving your private data to additional organizations or businesses, would you have agreed to that in the beginning? Does your consent no longer require consignment, and is it freely given to separate purposes years down the road? These are the issues Buchanan brings to light, and they directly coincide with what Palmer’s data handling concerns are.
While Palmer wanted to bring about legislation to protect the individual, Buchanan succinctly pointed out the many challenges that legislators would likely face when trying to draft sensible and impactful policies, especially as they pertain to enforcing continuous ethical evaluations on how data is handled in the future. As technologies continue to advance in just about every field, so does the transmitting of data. While GDPR policies would likely create greater protection for individuals’ private information, Buchanan would argue that additional ethical protections be considered; additionally, Buchanan would raise ethical concerns regarding how original consent is handled as technologies or services evolve from their initial conception or agreed upon use. From a Kant perspective, the consent of an individual should not be assumed to be given at any point in the future solely because it was given prior. It is quite the opposite; Kant would agree with Buchanan that consent is a continuous ethical process to obtain. Individuals must be made aware of any sort of deviation from the original intent of their data being used. Similarly to Zimmer, Buchanan’s arguments in defense of data protection are highlighting the need of ethical and moral obligations from the technology industry to each end-user. Both the concepts of public data consent and continuous ethical decision making tie in directly with a fundamental concept from Kantian Deontology: individuals should always be treated as ends in themselves rather than a means; by violating consent, be it from public posting or repurposing consent, individual autonomy is infringed upon, and this violates all moral and ethical rights.
Throughout this case analysis, several examples of the many issues involved in protecting individual rights were discussed. While things such as social media posting and consent were discussed, the overarching theme of the need for legislation is reinforced. Palmer’s argument of adapting the European Union’s GDPR policies is further bolstered by Zimmer and Buchanan’s discussion of the importance of consent, and the need to enforce accountability should that consent be used in contrast to previously agreed upon usage of data. Lastly, the Kant perspective of Palmer’s argument aligns upon the concept that each individual should not be used by organizations as means to an end (be it profit or other). While the topic of consent is routinely used throughout this article, it is not lost upon me that it is a highly nuanced process, and the very implementation of such a mechanism of accountability would likely be of great burden to legislators and ultimately the justice system. Much like Palmer, I firmly believe that analyzing this case study through Zimmer, Buchanan, and Kant’s perspective affirms that Palmer’s argument is a just and correct cause.