New paper out! A case study: Duolingo’s AI ethics approach and implementation. This is a rare example of real-world, detailed AI ethics implementation. ➤ Context: * There are so many AI ethics frameworks out there. Most of them are high level, abstract, and far from implementation. * That’s why I wanted to co-author this paper. * It showcases how an organization can write practical AI ethics principles and then implement them. * The case study is Duolingo English Test My fabulous co-authors are Jill Burstein, who led the paper, and Alina von Davier, Geoff LaFlair, and Kevin Yancey, all parts of Duolingo’s English Test team. ➤ The AI ethics principles: 1. Validity and reliability 2. Fairness 3. Privacy 4. Transparency and accountability ➤ The implementation The paper demonstrates how these principles are implemented using several examples: * A six-step process for writing exam questions, illustrating the validity and reliability and fairness standards * A process for detecting plagiarism that demonstrates the privacy principle * Quality assurance and documentation processes that demonstrate the accountability and transparency principle ➤ You can read a summary of the paper in the link in the comments ➤ Get in touch if you’d like to have a paper like this about your own company! #responsibleai #aiethics
Research Ethics Board Procedures
Explore top LinkedIn content from expert professionals.
-
-
Today, National Institute of Standards and Technology (NIST) published its finalized Guidelines for Evaluating ‘Differential Privacy’ Guarantees to De-Identify Data (NIST Special Publication 800-226), a very important publication in the field of privacy-preserving machine learning (PPML). See: https://lnkd.in/gkiv-eCQ The Guidelines aim to assist organizations in making the most of differential privacy, a technology that has been increasingly utilized to protect individual privacy while still allowing for valuable insights to be drawn from large datasets. They cover: I. Introduction to Differential Privacy (DP): - De-Identification and Re-Identification: Discusses how DP helps prevent the identification of individuals from aggregated data sets. - Unique Elements of DP: Explains what sets DP apart from other privacy-enhancing technologies. - Differential Privacy in the U.S. Federal Regulatory Landscape: Reviews how DP interacts with existing U.S. data protection laws. II. Core Concepts of Differential Privacy: - Differential Privacy Guarantee: Describes the foundational promise of DP, which is to provide a quantifiable level of privacy by adding statistical noise to data. - Mathematics and Properties of Differential Privacy: Outlines the mathematical underpinnings and key properties that ensure privacy. - Privacy Parameter ε (Epsilon): Explains the role of the privacy parameter in controlling the level of privacy versus data usability. - Variants and Units of Privacy: Discusses different forms of DP and how privacy is measured and applied to data units. III. Implementation and Practical Considerations: - Differentially Private Algorithms: Covers basic mechanisms like noise addition and their common elements used in creating differentially private data queries. - Utility and Accuracy: Discusses the trade-off between maintaining data usefulness and ensuring privacy. - Bias: Addresses potential biases that can arise in differentially private data processing. - Types of Data Queries: Details how different types of data queries (counting, summation, average, min/max) are handled under DP. IV. Advanced Topics and Deployment: - Machine Learning and Synthetic Data: Explores how DP is applied in ML and the generation of synthetic data. - Unstructured Data: Discusses challenges and strategies for applying DP to unstructured data. - Deploying Differential Privacy: Provides guidance on different models of trust and query handling, as well as potential implementation challenges. - Data Security and Access Control: Offers strategies for securing data and controlling access when implementing DP. V. Auditing and Empirical Measures: - Evaluating Differential Privacy: Details how organizations can audit and measure the effectiveness and real-world impact of DP implementations. Authors: Joseph Near David Darais Naomi Lefkovitz Gary Howarth, PhD
-
The first legal document I ever worked on was a Non-Disclosure Agreement (NDA). It took me almost 2 hours just to work through it once — not because it was long, but because I was trying to make sense of the legal language and structure. The main challenge? Understanding how the clauses fit together, what they actually meant, and why each one mattered. But once I cracked the structure, I started reading NDAs not as walls of text, but as modular documents built on purpose. Now, I can go through one in 20–30 minutes — efficiently and effectively. Here’s a quick breakdown of the typical structure and key clauses in most NDAs: 🔹 Definitions Sets the scope of terms like “Confidential Information,” “Disclosing Party,” and “Receiving Party.” Precision here determines the entire reach of the agreement. 🔹 Confidentiality Obligations Specifies how the receiving party must treat the disclosed information — non-disclosure, limited use, and care standards. 🔹 Exclusions Identifies categories of information not covered — e.g., information already in the public domain or independently developed. 🔹 Permitted Disclosures Outlines when and to whom confidential information can be disclosed (e.g., affiliates, advisors, or under legal obligation). 🔹 Term and Survival Sets the duration of the NDA and how long confidentiality obligations last — often surviving the termination of the agreement. 🔹 Return or Destruction Obligates the receiving party to return or destroy confidential information upon request or at the end of the relationship. 🔹 Remedies and Governing Law Provides for equitable remedies (like injunctive relief) in case of breach, and establishes the governing law and jurisdiction.
-
As a lawyer who often dives deep into the world of data privacy, I want to delve into three critical aspects of data protection: A) Data Privacy This fundamental right has become increasingly crucial in our data-driven world. Key features include: -Consent and transparency: Organizations must clearly communicate how they collect, use, and share personal data. This often involves detailed privacy policies and consent mechanisms. -Data minimization: Companies should only collect data that's necessary for their stated purposes. This principle not only reduces risk but also simplifies compliance efforts. -Rights of data subjects: Under regulations like GDPR, individuals have rights such as access, rectification, erasure, and data portability. Organizations need robust processes to handle these requests. -Cross-border data transfers: With the invalidation of Privacy Shield and complexities around Standard Contractual Clauses, ensuring compliant data flows across borders requires careful legal navigation. B) Data Processing Agreements (DPAs) These contracts govern the relationship between data controllers and processors, ensuring regulatory compliance. They should include: -Scope of processing: DPAs must clearly define the types of data being processed and the specific purposes for which processing is allowed. -Subprocessor management: Controllers typically require the right to approve or object to any subprocessors, with processors obligated to flow down DPA requirements. -Data breach protocols: DPAs should specify timeframes for breach notification (often 24-72 hours) and outline the required content of such notifications, -Audit rights: Most DPAs now include provisions for audits and/or acceptance of third-party certifications like SOC II Type II or ISO 27001. C) Data Security These measures include: -Technical measures: This could involve encryption (both at rest and in transit), multi-factor authentication, and regular penetration testing. -Organizational measures: Beyond technical controls, this includes data protection impact assessments (DPIAs), appointing data protection officers where required, and maintaining records of processing activities. -Incident response plans: These should detail roles and responsibilities, communication protocols, and steps for containment, eradication, and recovery. -Regular assessments: This often involves annual security reviews, ongoing vulnerability scans, and updating security measures in response to evolving threats. These aren't just compliance checkboxes – they're the foundation of trust in the digital economy. They're the guardians of our digital identities, enabling the data-driven services we rely on while safeguarding our fundamental rights. Remember, in an era where data is often called the "new oil," knowledge of these concepts is critical for any organization handling personal data. #legaltech #innovation #law #business #learning
-
UPDATED Global Practice Guide: Evaluating the Effectiveness of Ethics Programs Ethical culture is a cornerstone of effective governance. Internal auditors play a critical role in assessing whether ethics and compliance programs are well designed, effectively implemented, and operating as intended. The Institute of Internal Auditors has updated its Global Practice Guide: Evaluating the Effectiveness of Ethics Programs and released a companion tool to help internal auditors evaluate ethics and compliance programs and strengthen organizational culture. The guidance covers: • Evaluating the design and effectiveness of ethics and compliance programs • Assessing whether ethical expectations are clearly communicated and consistently reinforced throughout the organization • Identifying strengths, gaps, and opportunities for improvement in ethics-related controls and processes • Supporting oversight of organizational culture, conduct, and accountability • Providing practical considerations and tools to enhance audit coverage of ethics programs This resource is available free to IIA members. Link in the comments. #TheIIA #InternalAudit #Ethics #Governance
-
I keep seeing the term “Privacy-by-Design” everywhere. Webinars. Frameworks. ISO guides. Posts. Articles. Finally, after reading countless resources, attending classes, and engaging with domain experts, I decoded a pattern which is now a trending topic in the privacy and AI compliance world. I realized the market isn’t confused about privacy. It’s confused about how to design it. We follow policy, but what we truly need is a system which is a hidden geometry that quietly powers every mature privacy program. 1️⃣ The Compliance Triangle GDPR × ISO 27001 × NIST CSF This is the foundation of Privacy-by-Design where law defines what’s right, controls define how it’s done, and resilience ensures it lasts. ↳ GDPR defines why data must be protected. ↳ ISO 27001 structures how it’s secured. ↳ NIST CSF measures how well it’s sustained. Together, they turn compliance from paperwork into proof. 2️⃣ The Engineering Triangle Minimization × Encryption × Access Control This is the core of Privacy-by-Design ,where principles become protocols. ↳ Minimization limits what you collect. ↳ Encryption shields what you store. ↳ Access Control governs who touches what. When these align, privacy becomes a default setting, not a feature. 3️⃣ The Governance Triangle Policy × People × Proof This is the continuum that keeps privacy alive after launch. ↳ Policy defines intent. ↳ People uphold accountability. ↳ Proof (audits, DPIAs, reports) converts trust into evidence. Governance makes privacy sustainable not seasonal. Together, they create a privacy engine a continuous loop of law → design → assurance. #PrivacyByDesign #GDPR #ISO27001 #NISTCSF #AIGovernance #DataPrivacy #PrivacyEngineering #DigitalTrust #ResponsibleAI Privacy-by-Design isn’t one triangle, it’s a triad of triads. Because It isn’t a policy. It’s an architecture.
-
𝗘𝘁𝗵𝗶𝗰𝗮𝗹 𝗖𝗼𝗻𝘀𝗶𝗱𝗲𝗿𝗮𝘁𝗶𝗼𝗻𝘀 𝗶𝗻 𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 ✅ 𝗪𝗵𝘆 𝗔𝗿𝗲 𝗘𝘁𝗵𝗶𝗰𝗮𝗹 𝗖𝗼𝗻𝘀𝗶𝗱𝗲𝗿𝗮𝘁𝗶𝗼𝗻𝘀 𝗜𝗺𝗽𝗼𝗿𝘁𝗮𝗻𝘁? • Protect participants from harm • Maintain integrity of the research process • Build trust with the public and academic community • Ensure compliance with institutional and legal standards 🔑 𝗞𝗲𝘆 𝗘𝘁𝗵𝗶𝗰𝗮𝗹 𝗣𝗿𝗶𝗻𝗰𝗶𝗽𝗹𝗲𝘀 Here are the core principles you must address in your research: 𝟭. 𝗜𝗻𝗳𝗼𝗿𝗺𝗲𝗱 𝗖𝗼𝗻𝘀𝗲𝗻𝘁 𝗣𝗮𝗿𝘁𝗶𝗰𝗶𝗽𝗮𝗻𝘁𝘀 𝗺𝘂𝘀𝘁: • Be fully informed about the purpose, procedures, risks, and benefits of the research • Understand their participation is voluntary • Have the opportunity to withdraw at any time without consequences ✅̲ ̲𝙴̲𝚡̲𝚊̲𝚖̲𝚙̲𝚕̲𝚎̲:̲ “All participants were provided with an informed consent form outlining the study’s objectives, procedures, and their rights, including the right to withdraw at any point.” 𝟮. 𝗖𝗼𝗻𝗳𝗶𝗱𝗲𝗻𝘁𝗶𝗮𝗹𝗶𝘁𝘆 𝗮𝗻𝗱 𝗔𝗻𝗼𝗻𝘆𝗺𝗶𝘁𝘆 • Ensure participant data is kept confidential • Remove identifying details where possible (anonymization) • Secure data storage (e.g., encrypted files, password-protected systems) ✅̲ ̲𝙴̲𝚡̲𝚊̲𝚖̲𝚙̲𝚕̲𝚎̲:̲ “Participants’ names and identifying information were excluded from all reports, and data were stored securely in encrypted files.” 𝟯. 𝗔𝘃𝗼𝗶𝗱𝗮𝗻𝗰𝗲 𝗼𝗳 𝗛𝗮𝗿𝗺 • Protect participants from physical, psychological, emotional, or social harm • Screen for potential risks before the study begins ̲✅̲ ̲𝙴̲𝚡̲𝚊̲𝚖̲𝚙̲𝚕̲𝚎̲:̲ “The study design minimized psychological discomfort by avoiding sensitive or triggering questions. Support resources were provided if distress occurred.” 𝟰. 𝗩𝗼𝗹𝘂𝗻𝘁𝗮𝗿𝘆 𝗣𝗮𝗿𝘁𝗶𝗰𝗶𝗽𝗮𝘁𝗶𝗼𝗻 • Participation should be completely voluntary • No coercion, pressure, or manipulation • Particularly important in vulnerable populations (e.g., children, prisoners) ✅̲ ̲𝙴̲𝚡̲𝚊̲𝚖̲𝚙̲𝚕̲𝚎̲:̲ “Participation was entirely voluntary, and no incentives were used that might pressure individuals to take part.” 𝟱. 𝗘𝘁𝗵𝗶𝗰𝗮𝗹 𝗔𝗽𝗽𝗿𝗼𝘃𝗮𝗹 • Obtain approval from a recognized Ethics Review Board (ERB) or Institutional Review Board (IRB) • Submit a detailed study protocol for review before data collection ̲✅̲ ̲𝙴̲𝚡̲𝚊̲𝚖̲𝚙̲𝚕̲𝚎̲:̲ “This research received ethical approval from the University Research Ethics Committee (Ref: 2025/101).” 𝟲. 𝗥𝗲𝘀𝗽𝗲𝗰𝘁 𝗳𝗼𝗿 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗹𝗲 𝗣𝗼𝗽𝘂𝗹𝗮𝘁𝗶𝗼𝗻s If researching children, the elderly, refugees, etc., additional safeguards must be in place: • Consent from guardians • Simplified language • Ongoing monitoring of participant well-being 7. Honesty and Integrity • Report findings truthfully • Do not falsify or manipulate data • Acknowledge sources and avoid plagiarism ✅̲ ̲𝙴̲𝚡̲𝚊̲𝚖̲𝚙̲𝚕̲𝚎̲:̲ “All data were reported honestly, and no fabrication or manipulation was involved in the analysis.”
-
My words of caution to the ACF in response to their Request for Information on the Development of Interoperability Standards for Human Service Programs: I am writing in response to the practical enablers or barriers to interoperability and other equally important considerations, specifically defining desired outcomes. First, I recommend highlighting and emphasizing data privacy and patient consent for sharing health and social needs-related information because many health care stakeholders do not understand the special sensitivities related to this type of data. While health-related social needs data may be used to facilitate the provision of additional services (e.g. housing assistance and food-related assistance), they also have the potential to flag individuals and families for unnecessarily punitive child welfare services. Unfortunately, child welfare services too often focus on removing children from impoverished circumstances and providing financial assistance to support alternative “care” arrangements; this results in trauma for everyone involved, rather than the direct provision of much-needed services to struggling families. With the stated interoperability goals of “care coordination” and “improved outcomes,” it is important to define what we mean by positive outcomes. Potentially flagging individuals and families for child welfare system involvement is unlikely to result in beneficial services or improved outcomes. We need an explicit emphasis on avoiding punitive outcomes as an unintended consequence of sharing social needs data. I am concerned with the speed at which exchanging social needs data is happening relative to the speed at which the FHIR privacy and consent-related work is progressing. For example, the HL7 FAST Consent Management Implementation Guide is still under development, as are various taxonomies for accurately flagging sensitive data. This work needs time to mature and be implemented more widely before we rush to exchange data that falls into any kind of sensitive category beyond regular health care data across health and social data systems. In summary, we need additional emphasis on electronic privacy and consent standards and capabilities to protect sensitive data including social needs data before opening up interoperable data flows between health and social service data systems. More resources and technical assistance are needed to advance privacy and consent work, as well as education for health care and other stakeholders on what the desired outcomes look like. It is important to remember that “more service delivery” does not necessarily result in better outcomes (e.g. child welfare system involvement). We need to be clear about what “care coordination” and “improved outcomes” look like in practice to avoid unintended consequences of sharing data across health and social service systems and potentially ensnaring families in punitive systems. #HealthIT #Privacy #Consent #HRSN #SDOH #HIE #RiskFactor #FHIR
-
Why Health Data (Heart Rate, Height, Weight) is Classified as Sensitive under Saudi PDPL 🇸🇦as well as other privacy regulations. Health data, including biometric measurements like heart rate, height, and weight, is considered sensitive because: ⚪️ Directly linked to an individual’s physical well-being and medical history. ⚪️ Could be misused by employers, insurers, or advertisers (e.g., denying jobs/coverage based on health metrics). ⚪️ Even anonymized, combining height/weight with other data can reveal identities. 🔻Risk Scenario Example🔻 A fitness app collects users’ heart rate and weight to provide health insights. A data breach exposes this information. Risks ▪️Insurance Discrimination: Health insurers could raise premiums for users with high heart rates. ▪️Blackmail: Malicious actors target individuals with "abnormal" health data. ▪️False Medical Profiling: Employers might assume obesity = lower productivity. 🔶Best Practices When Collecting HealthData🔶 🔸Explicit Consent & Transparency** - Clearly state: *"We collect heart rate to customize workouts. Data is encrypted and never sold."* 🔸Anonymize/Aggregate Where possible Store aggregated trends (e.g., "30% of users improved heart health") instead of individual records. 🔸PDPL Compliance: Use de-identification techniques and restrict access to authorized personnel only. 🔸Secure Storage - Encrypt data in transit (SSL) and at rest (AES-256). Avoid third-party cloud storage unless certified. 🔸Right to Delete - Allow users to request permanent data deletion (e.g., PDPL’s "Right of Deletion").
-
The Council of Europe’s #Guidelines on data protection for #AML/#CFT purposes offer a timely reminder: fighting financial crime and protecting fundamental rights are not competing goals, they must reinforce each other. Key #takeaways: • AML/CFT data processing must rest on a clear legal basis and meet necessity and proportionality standards. • Purpose limitation is essential: personal data collected for due diligence, suspicious transaction reporting or beneficial ownership checks should not be reused beyond defined and compatible purposes. • “Collect everything just in case” is not compliant. Data minimisation should guide CDD, enhanced due diligence, public-private partnerships and automated monitoring. • #Transparency remains the rule, but AML/CFT-specific restrictions may apply where disclosure would undermine investigations or trigger tipping-off risks. • Data accuracy is critical: outdated or unreliable data, including from external databases or AI-based screening tools, can harm individuals and weaken AML/CFT effectiveness. • Sensitive data require heightened safeguards, especially data revealing political opinions, criminal records, biometric identifiers, health, religion or sexual orientation. • Retention periods must be legally defined, regularly reviewed and limited to what is necessary. • Security is non-negotiable: encryption, access controls, traceability, logging and privacy-by-design should be embedded in AML/CFT systems. • Public access to beneficial ownership data must be carefully balanced against privacy and data protection rights. • Stronger cooperation between AML/CFT supervisors and data protection authorities is essential to give obliged entities practical, consistent guidance. Bottom line: effective AML/CFT compliance is not only about more data. It is about lawful, proportionate, accurate, secure and accountable data processing.