Learn Labs
14. Doing the Right Thing

14.4 A practical checklist — with the caveat the chapter itself insists on

⚠️ "ETHICS IS NOT GOING THROUGH A CHECKLIST TO CONFIRM YOU COMPLY." Treat the following as prompts for the reflective, dialogic, accountable process the chapter describes — not as a box-ticking exercise. A checklist you complete without argument has told you nothing.

Before collecting:

  • What is this data for? Is the answer "we might find a use later"? That is precisely what GDPR's purpose limitation forbids, and precisely what "big data" encourages.
  • Would this still sound acceptable with "surveillance" substituted for "data"?
  • Does data about one user reveal things about non-users who never agreed to anything?
  • What is the worst outcome if this dataset leaks, is subpoenaed, is sold in a bankruptcy, or is inherited by a hostile regime? Consider all possible future governments, not today's.
  • Can we not collect it, collect less of it, or collect it in aggregate/anonymized form?

Before deciding about people:

  • Are any inputs proxies for protected traits? Postal code and IP address predict race. Purchase history predicts pregnancy, illness, sexuality.
  • Is this "how did you behave" or "how did people like you behave"? The second is stereotyping.
  • What is the recourse when the model is wrong about an individual? Not the aggregate — the individual. Is there an appeal, and does a human review it?
  • Can you explain a specific decision to the person affected, and to a judge?
  • Draw the feedback loop. Does a "no" today make a "no" tomorrow more likely? Does the system amplify existing differences or combat them?
  • Who is accountable when it's wrong? If the answer is "the algorithm," you have no answer.

Before retaining:

  • What is the retention period, and is it enforced by a job that actually runs?
  • Is there a deletion path that reaches every derived copy — caches, search indexes, warehouses, ML training sets, backups, event logs?
  • Have you tested the deletion path, the way Ch 13 says you must test restores?

On consent:

  • Could a user actually understand what they consented to? If the derived datasets are ones "users cannot meaningfully understand," consent is a fiction.
  • Can they refuse or withdraw without detriment? If not, GDPR says it isn't freely given — and more importantly, it isn't consent in any moral sense.
  • Is opting out realistically available, or does the service have network effects that make it "effectively mandatory"?