Dyr og Data

Data Science ethics and the GDPR

Gavin Simpson

Aarhus University

Mona Larsen

Aarhus University

Wednesday, 19 August 2026

Ethical data science

Data, like people, can be biased

These biases can affect particular groups of individuals disproportionately

Data are often private and that privacy must be secured

While you might be able to do a thing with the data we should be asking whether it is appropriate to do so

Ethical data science

Want to promote consideration of three aspects

  1. privacy

  2. fairness

  3. bias

in data science

Ethical data science

  1. Seek to enhance the value of data science for society

  2. Avoid harm!

  3. Apply and maintain professional competencies

  4. Seek to preserver and increase trustworthiness

  5. Maintain accountability and oversight

Societal benefit

What are the potential implications of a DS project for society

Outcomes of DS should be shared with society (not paywalled)

Enhance public or societal good

  • education
  • equity & inclusion
  • employment
  • environment
  • economic empowerment
  • health & hunger
  • infrastructure

Societal benefit

Potential impact of models

  • how do models work?
  • who do model impact and how?
  • who are the relevant stakeholders
  • understand biases, errors, assumptions, risks in model predictions
  • invite peer and bias review

Act in public interest

  • Choose to do work that will have a public benefit
  • Who benefits? Who is affected?
  • Can you mitigate risks?
  • Encourage culture that values social justice and fairness

Avoid Harm!

Data science often involves sensitive data & newer sources of data may have limited capacity for informed consent

Examples of harm

  • financial loss or disadvantage
  • reputational damage
  • damage to privacy or psychological wellbeing
  • exclusion from benefits or services

Think broadly! who might be affected is broad (individuals, public bodies, private organisations)

Avoid Harm!

Use data that is ethically sourced

  • find out where your data originate
  • how was it collected?
  • was informed consent obtained / given
  • consider privacy, dignity, and fair treatment when selecting data
  • follow good data handling practices, including data security
  • consider ways to reduce need to collect, store, use, personally identifiable information
  • consider the impact of deriving demographic data or linking with other data
  • be transparent & provide evidence of privacy considerations

Avoid Harm!

Embed ethical risk management into work

  • seek independent or domain expert advice on assumptions and risks
  • monitor and communicate risks
  • regularly review

Educate workforce

  • communicate what DS can and can’t do
  • know the limitations of your analysis
  • help non-technical individuals understand ethical, technical, professional issues that are relevant

Professional competencies

Comply with relevant professional and regulatory practices

  • know what profession, legal, and regulatory requirements apply to a project
  • ensure compliance

Ensure ethical policies, procedures, governance are applied

Follow best practices

  • use appropriate statistical methods
  • take uncertainty into account in any decision-making

Validate & improve work

Preserve trustworthiness

Engage with appropriate ethical bodies

Avoid unnecessarily complex models

Build trust through transparency

Maintain accountability and oversight

Maintain human oversight

Define operating constraints

Public involvement

GDPR

GDPR

General Data Protection Regulation

Types of personal data

  • General personal data (non-sensitive)
    • name, age, height, contact info
  • Criminal convictions & offences
    • race, ethnic origin, religion, trades union, genetic, health, sexual identity, relationships, and orientation
  • Special categories of personal data
  • Confidential personal-data
    • CPR numbers

Know what types of data you are processing

GDPR

Non-sensitive data still needs ot be private and handled appropriately & securely

Sensitive data must be stored securely (higher level of security)

Considerations

  • do you need to collect each piece of data?
  • if you need the data, for how long will you need it?
  • assess risks to individuals if security were breached
  • balance risks with benefits

GDPR

AU considers 4 levels of data sensitivity

  1. public data
  2. internal data
  3. condfidential data
  4. sensitive data

Where you store data depends on the level of sensitivity

Anonymisation

Pseudonymisation of personal data

  • replace, transform, remove directly identifying information

Anonymisation of personal data

  • must not be able to be identify individuals on basis of data alone or in combination with other data sets