Denied by Design? Data Access Rights in Encrypted Infrastructures
Michael Veale · 2023
There are increasing demands and hopes for data access provisions to open accountability of systems. In parallel, major technology platforms and stacks are encrypting their business models and moving increasingly to privacy-enhancing technology approaches such as 'confidential computing'. These go beyond encrypting the content of communication to encrypting the very approaches that underpin their constitutive algorithmic systems, such as those used in recommendation and allocation. The motivations for these range from concerns around privacy to desires to avoid liability by seeing, hearing — and then presumably doing — no evil. Approaches to studying and improving these are nascent even for developers of these systems, who can struggle with a lack of telemetry and feedback data when trying to tweak, adjust and increase functionality of the systems they are deployed. Given that platforms themselves lack data on these systems, the task is doubly hard for external researchers. This paper characterises those challenges and suggests pathways and approaches legal regimes could take to ensure they remain accountable.