DPGAlliance / DPG-Standard

Digital Public Goods Standard
Creative Commons Attribution Share Alike 4.0 International
104 stars 42 forks source link

9a and 7 overlap to be resolved #110

Closed prajectory closed 2 years ago

prajectory commented 2 years ago

With the recent updates to the standards #57 and focusing indicator 7 on strictly privacy laws, there is now a redundancy/overlap in our indicators. Indicator 7 requires the digital solution has adherence to applicable privacy laws, and indicator 9a - a subsection of do no harm dealing with privacy - requires the digital solution give clear and specific answers on how privacy is protected. The question now is how do we resolve this redundancy?

The tactical options ahead of us are i. to merge 7 & 9a ii. drop one of the two indicators (most likely 9a), or iii. keep both but clarify the language of each to remove the redundancy.

The tactical choice we make depends on our strategic vision. As a community we need to answer the following related questions.

a) What are our minimum requirements? Since only "applicable" privacy laws apply, some digital solutions may clear indicator 7 based on their context, but could still do harm in a way that locally applicable laws do not protect for. They will therefore violate indicator 9. As the alliance, do we have a stand on inalienable privacy rights that every DPG must protect? b) How do we translate the intent of these indicators into a vetting process? Is it operationally feasible? For any digital solution in our registration marked as a DPG, there is an expectation that these projects have been vetted to adhere to the standards. Often, in response to questions under indicator 9a, digital solutions reply by sharing their privacy policy. This is insufficient to determine if the digital solutions are actually anticipating and preventing privacy harms. We may need the digital solution owners to spell out the system of checks and balances, specially under areas we consider our minimum requirements. Based on our answers to the questions (a, b) we should choose between our options (i, ii, iii).

@nathanbaleeta is also putting together questions that we have received from users regarding these two indicators. That will help us with insights on b).

prajectory commented 2 years ago

This resolution led us to a very different solution captured in #116 Keeping that as the latest version of the stream of changes on this particular issue.