BeyondSingularity

← Data Privacy, Ethics and Society outline

Module 02 / 14  ·  Phase 1 — Foundations

2. Ethical frameworks as tools, not doctrines

This week in the arc

Coming from

What privacy is, and why it's contested

Going to

Consent and control at the AI frontier

Core

Some privacy violations are hard to argue: it can be difficult to say why something is wrong in terms someone else has to accept. This week introduces four tools for that. They are lenses, not doctrines — you don’t pick one and pledge allegiance; you hold a case up to each and see what it reveals.

Each lens asks a different question:

  • Consequences — What are the outcomes: who is helped, who is harmed, and by how much?

  • Duty and rights — What do we owe people regardless of outcome: were they used merely as a means to someone else’s end?

  • Virtue — What does this practice make of us: what kind of institution, profession, or person does it cultivate?

  • Justice — How are the benefits and burdens distributed, and who holds power over whom?

Alongside the lenses, one more tool — not another way to judge, but a way to locate. Data moves through a lifecycle: it is collected, stored, processed, analyzed, used, retained, and disclosed. When a harm appears, naming which stage it lives in sharpens everything the lenses then ask. It’s the vocabulary the privacy field uses, and we’ll tag every case with it from here on.

The data lifecycle: collected, stored, processed, analyzed, used, retained, disclosed
  • Collected — Data first enters a system: you type it in, a sensor records it, or a company scrapes or buys it.
  • Stored — It is kept somewhere — a database, a server, a backup — often long after its original purpose.
  • Processed — The raw data is cleaned, combined, and reshaped into something usable.
  • Analyzed — Patterns and inferences are drawn from it — scoring, profiling, prediction — producing new facts about you.
  • Used — The data, or what was inferred, drives a decision or action: an ad, a price, an approval, a denial.
  • Retained — It is held over time, sometimes indefinitely, whether or not it is still needed.
  • Disclosed — It is shared, sold, leaked, or handed to others — partners, brokers, government, or attackers.

The point is not to find the one right lens. It is to notice that the lenses sometimes disagree — and that the disagreement is information, not a failure. Reasoning well without certainty is the skill this course is built on.

Cases — tagged by category, name the kind before you react

The hospital that shared 1.6 million patients' recordsone situation, four lenses

An NHS hospital trust handed the records of 1.6 million patients to a Google-owned AI company to build a tool that flags acute kidney injury early — a genuine, life-saving aim. Patients were not meaningfully asked, and the UK regulator later found they hadn’t been properly informed. We run this one case through all four lenses and watch it change shape each time.

Worked example: Clearview AI through the four lensesworked example

A teaching example — one case run through all four lenses, to show the method before you do it live. The point isn’t the verdict; it’s where the lenses agree, where they pull apart, and what would settle it. A completed worksheet for this case is here.

The case. Clearview AI scraped billions of public photos from the open web into a facial-recognition tool sold to police: upload a face, get back where that person appears online. Every image was already public; no one consented to being indexed. (Lifecycle: the harm lives in collection — the scrape — and processing — building the biometric index.)

Consequences. Real gains: some crimes solved, victims and suspects identified. Against that: billions lose anonymity without consent, misidentification risks wrongful arrest, and the tool enables stalking and authoritarian use. Diffuse harm to everyone, weighed against a narrow, concrete benefit in some cases.

Duty & Rights. Faces were conscripted — scraped without consent to serve police and Clearview’s profit. People were used merely as a means to others’ ends. “Public” does not equal “agreed to this use.” Wrong even if the tool works.

Virtue. It cultivates a policing culture of frictionless surveillance, and a company willing to cross a line Google and Facebook saw and refused. It erodes the professional restraint democratic policing depends on — and asks what kind of society treats every face as searchable.

Justice. The burden falls on everyone, heaviest on already over-policed communities (more searched, more misidentified). Power accrues to the state and a private firm; individuals can’t opt out or even see it. It concentrates power in the already-powerful.

Where the lenses meet. Converge: Duty & Rights, Virtue, and Justice all condemn the untargeted, non-consensual scale. Diverge: only Consequences can partly defend it — real crimes solved — which is the wrestle: do the investigative wins justify conscripting everyone’s face? Question: what would change the verdict — evidence it prevents serious crime at scale, a warrant limit, a workable line between “public” and “fair to index”?

Reading

Required Nissenbaum, “Privacy as Contextual Integrity” Washington Law Review, 2004

Assessment

Your privacy agreement, through the four lenses

Pick a service you actually signed up for — an app, a store loyalty program, a genetics or fitness service, a “free” platform — and open its privacy policy or terms.

Scope it down. Don't analyze the whole company. Find one specific data flow in the policy that you find ethically live — a particular piece of data going to a particular place for a particular purpose (“my location shared with advertising partners,” “my DNA retained after I close my account”). Everything below is about that one flow.

Run that flow through all four lenses — consequences, duty & rights, virtue, justice — using the four-lenses worksheet as your format. Then name the lifecycle stage the harm lives in (collected, stored, processed, analyzed, used, retained, disclosed), and say whether the flow fits the context you thought you were entering — or crosses a boundary you never agreed to.

~1 page. You are not graded on which verdict you reach, or on finding a scandal — a mundane flow analyzed honestly beats a dramatic one hand-waved. You are graded on whether you let the lenses genuinely disagree and show where they converge, where they diverge, and what would change your verdict.

Stuck for a service that raises all four lenses? Ones that reliably do: health/fitness trackers, genetic testing, dating apps, kids' apps, ad-funded “free” services, retail loyalty programs, and financial apps. For a model of the finished shape, see the completed Clearview example.

Discussion

  • When you called something a 'privacy violation' last week, which lens were you actually using — even without a name for it?
  • Can an action have good consequences and still wrong the people involved? What would that look like?
  • Is there a lens you already distrust? Why — and is the distrust about the lens, or about where it leads?