Dyr og Data
Data Science ethics and the GDPR
Gavin Simpson
Aarhus University
Mona Larsen
Aarhus University
Wednesday, 19 August 2026
Ethical data science
Data, like people, can be biased
These biases can affect particular groups of individuals disproportionately
Data are often private and that privacy must be secured
While you might be able to do a thing with the data we should be asking whether it is appropriate to do so
Ethical data science
Want to promote consideration of three aspects
privacy
fairness
bias
in data science
Ethical data science
Seek to enhance the value of data science for society
Avoid harm!
Apply and maintain professional competencies
Seek to preserver and increase trustworthiness
Maintain accountability and oversight
Societal benefit
What are the potential implications of a DS project for society
Outcomes of DS should be shared with society (not paywalled)
Enhance public or societal good
- education
- equity & inclusion
- employment
- environment
- economic empowerment
- health & hunger
- infrastructure
- …
Societal benefit
Potential impact of models
- how do models work?
- who do model impact and how?
- who are the relevant stakeholders
- understand biases, errors, assumptions, risks in model predictions
- invite peer and bias review
Act in public interest
- Choose to do work that will have a public benefit
- Who benefits? Who is affected?
- Can you mitigate risks?
- Encourage culture that values social justice and fairness
Avoid Harm!
Data science often involves sensitive data & newer sources of data may have limited capacity for informed consent
Examples of harm
- financial loss or disadvantage
- reputational damage
- damage to privacy or psychological wellbeing
- exclusion from benefits or services
Think broadly! who might be affected is broad (individuals, public bodies, private organisations)
Avoid Harm!
Use data that is ethically sourced
- find out where your data originate
- how was it collected?
- was informed consent obtained / given
- consider privacy, dignity, and fair treatment when selecting data
Include privacy & ethics, & follow legal requirements
- follow good data handling practices, including data security
- consider ways to reduce need to collect, store, use, personally identifiable information
- consider the impact of deriving demographic data or linking with other data
- be transparent & provide evidence of privacy considerations
Avoid Harm!
Embed ethical risk management into work
- seek independent or domain expert advice on assumptions and risks
- monitor and communicate risks
- regularly review
Educate workforce
- communicate what DS can and can’t do
- know the limitations of your analysis
- help non-technical individuals understand ethical, technical, professional issues that are relevant
Professional competencies
Comply with relevant professional and regulatory practices
- know what profession, legal, and regulatory requirements apply to a project
- ensure compliance
Ensure ethical policies, procedures, governance are applied
Follow best practices
- use appropriate statistical methods
- take uncertainty into account in any decision-making
Validate & improve work
Preserve trustworthiness
Engage with appropriate ethical bodies
Avoid unnecessarily complex models
Build trust through transparency
Maintain accountability and oversight
Maintain human oversight
Define operating constraints
Public involvement
GDPR
General Data Protection Regulation
Types of personal data
- General personal data (non-sensitive)
- name, age, height, contact info
- Criminal convictions & offences
- race, ethnic origin, religion, trades union, genetic, health, sexual identity, relationships, and orientation
- Special categories of personal data
- Confidential personal-data
Know what types of data you are processing
GDPR
Non-sensitive data still needs ot be private and handled appropriately & securely
Sensitive data must be stored securely (higher level of security)
Considerations
- do you need to collect each piece of data?
- if you need the data, for how long will you need it?
- assess risks to individuals if security were breached
- balance risks with benefits
GDPR
AU considers 4 levels of data sensitivity
- public data
- internal data
- condfidential data
- sensitive data
Where you store data depends on the level of sensitivity
Anonymisation
Pseudonymisation of personal data
- replace, transform, remove directly identifying information
Anonymisation of personal data
- must not be able to be identify individuals on basis of data alone or in combination with other data sets