I think it’s absolutely the right direction for private companies though. I know, I know, a lot of you are distrustful of government, but I’m Danish and we generally trust our public sector in to an extend that would truly surprise a lot of you.
So with that out of the way, I think it’s a shame that we spend so much public funding burying public data in silos. I think we should absolutely keep citizen data safe, but I think we should also use it and perhaps work to make some of it less sensitive. Because some of it frankly doesn’t have to be sensitive.
In my country we have a social security number. You get it 1-5 minutes after you’re born, and in the olden days, it was used to identify you when you wanted to do things like open a bank account. It’s still used for that to some extend, but in the meantime we’ve created this thing called NemID (soon to be mitID), which is a national 2-factor secure digital identity, that we use to enter online agreements because it turned out that your social security number wasn’t actually safe. We’ve also had leaks and hacks exposing nearly half of the current social security numbers over the past 25 years.
Because a social security number is deemed sensitive by the GDPR, we’re spending hundred of millions on the bureaucracy around it. It’s by far the most reported thing to our national data protection agency, I think almost 80% of the public cases involve it. And it makes no sense.
Why the hell didn’t we make it illegal to use it as an identifying number instead? It would have saved us so much money.
And that’s just one issue with the GDPR. Another is machine learning and data. This is obviously a sensitive area. I don’t personally think we should troll through citizen cases to try and find possible alcoholics. Maybe someday, but society has to deem it morally acceptable first.
I do think we should use citizen data to schedule shifts though. It makes no sense to me, to have 10 nurses and 15 teachers do full time scheduling in a city of 60,000-100,000 citizens when an algorithm can do it instead. But we can’t, because the GDPR prevents us from using data that way.
I like the GDPR, but I think it needs a revision for the modern public sector, and I think we should really ask ourselves what we want with our data.
Do we want to spend trillions on a bureaucracy guarding it, or do we want to demystify some of it and put it to good use, so we can spend the trillions on nurses, teachers and better infrastructure?
/disclaimer I work in the public sector.