5.1 Legal Versus Ethical Processing and the Social Impact of Privacy-Affecting Designs
Key Takeaways
Processing can be lawful in one jurisdiction and unlawful in another; Clearview AI's face scraping drew GDPR fines of EUR 20 million each in Italy, Greece, and France and EUR 30.5 million in the Netherlands.
Ethical analysis asks whether processing respects autonomy, avoids harm, and treats people fairly, even when the law or a consent click permits it.
Cambridge Analytica showed how platform APIs exposing friends' data let one app reach up to 87 million people who never used it.
Using personal data to manipulate societal conversations is an ethical and increasingly legal concern under the EU Digital Services Act and the EU political advertising regulation.
Ethics belongs in the workflow: review gates, data ethics canvases, misuse red-teaming, and safe escalation paths for engineers.
5.1 Legal Versus Ethical Processing and the Social Impact of Privacy-Affecting Designs
Quick Summary: The law sets a floor, not a ceiling. Processing can be lawful in one jurisdiction and unlawful in another, and lawful processing can still harm people or society. The CIPT BoK asks technologists to tell legal from ethical processing, to recognize social and ethical issues such as unauthorized access to personal data and the manipulation of public debate, and to bring structured ethical review into design decisions.
Privacy technologists are often the first people to see what a system can do with data. That vantage point brings a responsibility to ask not only "is this allowed?" but also "should we do this, and who could be hurt?"
Legal Is Not the Same as Ethical
Three gaps separate legal compliance from ethical processing:
- Jurisdictional gaps. The same activity can be lawful in one country and unlawful in another. Clearview AI scraped billions of facial images from the public web to build a face-search service sold to police. European regulators found this unlawful under the GDPR: Italy's Garante, Greece's Hellenic DPA, and France's CNIL each imposed EUR 20 million fines in 2022, and the Dutch authority imposed EUR 30.5 million in 2024. In much of the United States, the same scraping faced fewer legal limits, except under laws such as the Illinois Biometric Information Privacy Act. A global product team cannot treat "legal somewhere" as "acceptable everywhere."
- Lag gaps. Technology moves faster than law. Emotion recognition, voice cloning, and inference from wearables were deployed before most laws addressed them. Waiting for regulation means building systems that later have to be dismantled.
- Consent gaps. A practice can be lawful because people clicked "I agree," yet people did not understand it, had no real choice, or could not foresee the harm. Consent obtained this way may satisfy a checklist without respecting autonomy.
A useful test when advising a team is to ask whether the processing would still be defensible if it were fully explained to the people affected and reported in a newspaper. If the honest answer is no, the design needs to change even if counsel approved it.
Foundational Ethical Frameworks for Data Technologists
Legal statutes establish a compliance baseline, not an ethical ceiling. A system can adhere strictly to statutory provisions while remaining profoundly unethical. For example, deploying emotion-recognition models in workplace environments to dock employee bonuses may circumvent certain local privacy regulations if employees sign broad consent waivers, yet it remains fundamentally coercive and harmful.
To evaluate systems ethically, privacy technologists adapt core bioethical principles—originally formulated in the Belmont Report and refined in declarations such as the Montreal Declaration for Responsible AI:
- Beneficence: Systems must actively generate positive human welfare, economic wellbeing, and societal utility.
- Non-Maleficence: "Do no harm." Systems must be designed to anticipate, prevent, and mitigate physical, financial, psychological, and dignitary injury.
- Autonomy: Preserving human agency, self-determination, and the freedom of individuals to make personal choices without algorithmic manipulation, coercive nudges, or deceptive dark patterns.
- Justice and Fairness: Ensuring that technological benefits and burdens are distributed equitably across society, preventing the entrenchment or amplification of systemic discrimination against historically disadvantaged groups.
- Accountability and Explicability: Algorithmic systems must not operate as impenetrable black boxes. Systems must be auditable, verifiable, and explainable to both regulators and the individuals affected by their decisions.
Social and Ethical Issues the BoK Highlights
Unlawful or Unauthorized Access to Personal Data
The Cambridge Analytica scandal (revealed in 2018) is the reference case. A personality-quiz app on Facebook collected data not only from about 270,000 people who installed it but, through the platform's friend permissions, from up to 87 million of their friends, who never used the app. The data was then used to build psychological profiles for political advertising. The harms were social as well as individual: people were profiled without knowledge, and the profiles were used to influence elections. Facebook later paid a $5 billion FTC penalty in 2019 under an order that also imposed board-level privacy oversight, and the UK Information Commissioner fined it £500,000, the maximum under the law that then applied.
Technical lessons: APIs that expose friends' or contacts' data turn every user into a door to other people's information; third-party developer access needs purpose limits, audits, and the ability to revoke; and "the platform allowed it" is not a defense against harm.
Manipulating Societal Conversations and Attitudes
Personal data can be used to shape what large groups of people see and believe, for example through micro-targeted political ads, recommendation systems that amplify divisive content because it drives engagement, coordinated bot networks, and synthetic media. These harms fall on society (trust in elections, public health, and journalism) as well as on individuals. Laws are responding: the EU Digital Services Act requires very large online platforms to assess and mitigate systemic risks, including negative effects on civic discourse and electoral processes (Article 34), and the EU regulation on the transparency and targeting of political advertising (Regulation (EU) 2024/900), most of which has applied since October 10, 2025, restricts targeting with personal data and bans the use of special-category data for political ad targeting.
Technologists influence these outcomes through design choices: which signals a ranking model optimizes, whether sensitive traits can be used as targeting criteria, how quickly synthetic or coordinated activity is detected, and whether ad libraries make targeting transparent.
Other Recurring Ethical Questions
- Vulnerable groups: children, patients, workers, migrants, and people in abusive relationships face greater harm from the same data practice.
- Dual use: a location feature for finding friends can also locate a domestic-abuse victim.
- Power imbalance: people cannot meaningfully refuse an employer, a government benefits system, or a dominant platform.
- Inference: models can reveal traits people never disclosed, such as sexual orientation or health conditions.
Bringing Ethics into Engineering Practice
| Practice | What It Looks Like |
|---|---|
| Ethics review gates | High-impact features (biometrics, profiling, children's data, AI decisions) go to a cross-functional review board before launch |
| Structured canvases | Tools such as the Open Data Institute's Data Ethics Canvas prompt teams to list affected people, purposes, risks, and mitigations |
| Research ethics principles | The Belmont Report (1979) offers respect for persons, beneficence, and justice; the Menlo Report (2012) adapts them to information and communications technology research and adds respect for law and public interest |
| Red-teaming for misuse | Ask how a stalker, scammer, or authoritarian government could use the feature, not only how attackers could break it |
| Escalation paths | Engineers need a safe way to raise concerns without career risk |
The connection to the rest of the CIPT is direct: ethical review feeds the privacy impact assessment (Chapter 13), shapes privacy by design choices (Chapter 14), and sets the fairness requirements for automated decision-making covered in the next section.
A U.S. startup plans to scrape publicly visible profile photos worldwide to train a face-search product. Counsel says the practice faces few legal limits in the startup's home state. What is the best response from the privacy technologist?
Proceed globally, because data that is publicly visible is outside every privacy law.
Proceed but store the photos in a home-state data center so that only the home state's law applies to them.
Flag the jurisdictional and ethical problems, citing EU fines against Clearview AI, and push for a design without mass biometric scraping.
Proceed only after adding a longer privacy notice to the startup's website describing the face-search product in detail.
In the Cambridge Analytica case, which design feature allowed one quiz app to obtain data on tens of millions of people who never installed it?
Weak password hashing on the quiz app's login page
A ransomware attack that encrypted and copied Facebook's data center storage
A misconfigured public storage bucket left open by the political advertising agency
Platform APIs that exposed installers' friends' data
A team proposes letting advertisers target political ads at users whom a model has inferred to hold particular religious beliefs. Under current EU rules, which statement is most accurate?
The practice is allowed if users clicked a general consent box at sign-up agreeing to personalized advertising.
The practice is permitted as long as the inferences are accurate.
EU rules ban using special-category data such as religion to target political ads.
The practice is regulated only by national election laws, not by any EU-level data protection or advertising rules.
Sections you finish are checked off in the contents.