GDPR and its Connection to the Open Data Movement

October 22, 2018 Global Data Policy
Beverley Hatcher-Mbu
Explainer, Open Data

Since this past May, you’ve probably received a flood of company emails updating terms of service and consent requests to give permission to collect your data. You also probably know that this flood is all thanks to the EU’s recent General Data Protection Regulation (GDPR), which has set us abuzz in its heightened protection of EU citizen data. But as members of the open data community, what does GDPR mean for our global movement? How can GDPR influence our clients, partners, and broader data-driven work?

What Kind of Data Are We Talking About?

GDPR covers two data types: biometric, data containing information that could be used to specifically identify a person; and personal, data that, when matched with other identifiers, could directly or indirectly identify a person. In practice, these two data types extend from a person’s IP address, to his or her political opinions, geographic location and shopping habits.

In evaluating data and its significance (should it be protected – and if so, how?), context is paramount. Plenty of data collected doesn’t reveal identity (e.g. visiting a website), but what happens when multiple data points are combined (e.g. tracking website visitors’ IP addresses and download patterns), producing results that bring up privacy questions?

How are GDPR and Open Data Connected?

GDPR isn’t the only policy taking a closer look at protecting data – a number of organizations in the development space have rigorous data access and privacy policies. Both the Bill & Melinda Gates Foundation and the UK’s Department for International Development have open access policies requiring all research they fund to be available publicly, along with raw datasets upon request during and after project conclusion.

USAID has an internal policy protecting the data of its employees and partners, as well as a Data Security Guidance resource for USAID implementing partners, outlining procedures for safeguarding beneficiaries and best practices in collecting, storing, and discarding project data. UNICEF has worked for several years to protect children’s information on- and offline, recently providing guidance to the ICT sector on creating policies to better protect children’s data.

As a data-driven organization taking a holistic approach to data collection and use, DG has tackled data privacy by prioritizing open source tools and building our flagship Aid Management Platform and geocoding tool to allow any user to use and edit our software freely. In Sudan, we worked with DFID on how to balance the aim of releasing data on humanitarian activities with the ongoing need to obtain consent in the release of sensitive information.

We’ve used ‘location fuzzing’ in Ghana to protect hospital and health service locations, and in building the resource portal for Plan International’s Missing Child Alert to protect service locations of trafficking victims. And to balance different access policies for the UNDG Information Management System, we built the API with some public pages, and others requiring a login to protect departments’ sensitive data.

PREMAND

Figure 1: The PREMAND project‘s Mapping Portal, which uses “location fuzzing” to protect health and location data of individuals.

Through our work, we’ve learned that there’s room for improvement within our community – particularly in how we keep records of explicit consent and in how we plan for data breaches. When data privacy isn’t taken seriously, it can put lives, progress, and initiatives at risk.

What Can We Do Practically to Protect Data?

When thinking about how to assess our own programs or advise partners on how to step up data privacy controls, five simple steps can be taken to improve data protection:

  • Take Stock: Determine what personal information is collected and kept in your files;
  • Scale Down: Maintain only data that is absolutely necessary;
  • Throw it Out: If you don’t need it, (safely) get rid of it;
  • Secure it: Keep data safe;
  • Plan Ahead: Create a plan to respond to data breaches.

Taking stock is about understanding context – what data is collected, why, by whom, and for how long. With a broad understanding of how you collect data and what it’s used for, you can then determine what a reasonable limit should be in collecting and storing your data.

Scaling down is about only keeping strictly necessary data. If you do this, the next steps happen naturally – safely discard unnecessary data, and ensure that what remains is secure. “Secure” can mean any combination of controls, from anonymizing data, to protecting individual identity, to installing passwords, firewalls, and “read only” features.

Lastly, in the event of a data breach, you need an established plan detailing what to do, who to notify (e.g. individuals whose data has been compromised), and any immediate steps to mitigate risks (e.g. temporary blocking access to online files).

In Sum

The open data world in particular has long been familiar with issues of data protection and access. Due to this familiarity, data and digital development partners are ideally positioned to encourage & build best practices  – it’s time for us to proactively take up this responsibility. GDPR is simply a reminder for us that open data is a balancing act: we must prioritize both the protection of individual data and increase access to vital information.

Share This Post

Related from our library

At a Glance | Tracking Climate Finance in Africa: Political and Technical Insights on Building Sustainable Digital Public Goods

In order to combat the effects of climate change, financing is needed to fund effective climate fighting strategies. Our white paper, “Tracking Climate Finance in Africa: Political and Technical Insights on Building Sustainable Digital Public Goods,” explores the importance of climate finance tracking, common barriers to establishing climate finance tracking systems, and five insights on developing climate finance tracking systems.

June 24, 2024 Data Management Systems and MEL, Global Data Policy
Great Green Wall Observatory: A New Data Platform to Support One of Africa’s Most Ambitious Efforts to Combat Climate Change

In partnership with UNCCD, GGW Accelerator, and the Pan African Agency for the GGW, DG has launched the Great Green Wall Observatory. This pioneering digital platform monitors the GGW Initiative's progress, enhancing collaboration, accountability, and transparency across 11 African countries. By providing financial and project management data, the Observatory empowers communities, stakeholders, and policymakers to combat climate change in the Sahara and Sahel regions. With over 302 projects and $15 billion in commitments, this tool promotes robust climate action and fosters local and global engagement.

June 4, 2024 Data Management Systems and MEL, Global Data Policy
Raising Awareness on World No Tobacco Day 2024: DaYTA/TCDI’s Work on Tobacco Industry Interference

As tobacco companies have aggressively deployed creative strategies to market retail nicotine and tobacco products at children and adolescents, it is imperative that tobacco control stakeholders have access to timely and high-quality data to inform robust policies, regulations, and enforcement mechanisms.

May 31, 2024 Global Data Policy, Health