With Digital Contact Tracing, Take the Middle Ground
I wrote this in July 2020 for a graduate course on data ethics at UMBC, in the first months of the pandemic, when digital contact tracing was a live proposal rather than a settled question. I have left the argument as it was, with light copyediting, because it shows how I reason about a data system whose users have not been asked. Parenthetical numbers are page numbers in the cited source, as the assignment required. Reading it five years later, I would weigh the minimal approach more favorably than I did then: the exposure-notification systems that actually shipped were the minimal kind, uptake rather than data richness seems to have been the binding constraint, and the opt-in middle ground I argued for was, as far as I know, rarely built. The question underneath the essay, what a person owes and is owed when their data is collected for the common good, is one I still work on.
The Centers for Disease Control and Prevention characterize case investigation and contact tracing as “a core disease control measure employed by local and state health department personnel for decades” and “a key strategy for preventing further spread of COVID-19” (1). This long used and accepted disease control measure involves public health officials working with suspected or confirmed infected patients to help identify all contacts of the patient who might have been at risk of exposure (in addition to providing the infected patient with appropriate resources and information). In times of outbreak or worse, contact tracing is a standard tool that public health officials use to help mitigate the damage. Given the severity of the COVID-19 pandemic and its widespread effect on the entire country, it is natural to wonder how technology might be used to rapidly increase the scope and scale of contact tracing in order to help public health officials adequately stem the spread of the virus. As it currently stands, the CDC is in the process of investigating potential digital tools for the use of contact tracing and is working with “public health agencies, healthcare organizations, academic institutions, non-profit organizations, and private companies” to develop the appropriate digital contact tracing strategy and tools (2).
According to a report on digital contact tracing for pandemic responses by the Johns Hopkins Berman Institute for Bioethics, digital contact tracing technology (DCTT) generally fits into three approaches: the maximal approach, the minimal approach, and middle ground approaches (3-4). The maximal approach looks much like the strategy used in South Korea. In his article on South Korea’s pandemic response, Max S. Kim of the New Yorker explains how South Korean public health officials are collecting (and sometimes publishing to the public) vast amounts of personal data for contact tracing. The types of data collected include “cell-phone G.P.S. data, credit-card payment information, and travel and medical records” (1). With maximal approaches like this, public health officials have a lot of information to be able to identify geographical patterns of spread while also identifying specific contacts to warn about potential exposure. While South Korea has implemented strategies to protect individuals’ privacy as much as possible, with maximal approaches, a vast degree of information that is typically considered private becomes accessible to the government (and possibly other entities as well).
Alternatively, the minimal approach is best characterized by Apple and Google’s proposed bluetooth and notification system. According to Russell Brandom of The Verge, Apple and Google have developed a system that creates randomly generated daily tracing keys for each individual device that are transmitted to any nearby devices within a “close contact” radius of the device (1). The intention is to use the tracing keys of infected patients to identify any close contacts and notify those contacts in such a way that no identifying information is made available to any entity. The minimal approach is considered minimal because it records very little private information and makes it unidentifiable (through the randomly generated tracing keys).
Finally, the middle ground approaches lie between the minimal and maximal approaches in terms of the type and amount of data collected. According to the Johns Hopkins report, middle ground approaches involve “the collection and storage of personal data—including identifying information and location data—on the user’s phone. These decentralized but personally identifiable data can then be voluntarily shared with public health officials if the user tests positive for SARS-CoV-2” (4). Unlike the minimal approach, more identifying information is collected and stored, and unlike the maximal approach, users have the option to choose whether they want to share the more personal information with public health officials.
These approaches lie on a spectrum between more privacy and less privacy. A maximal approach provides public health officials and those fighting to stem the spread of the virus with a wide array of tools and information, but this comes at the expense of the personal privacy of the citizens of the society. In the example of South Korea, Max Kim explains that for many South Koreans, “sacrificing some individual privacy was simply the upfront cost of avoiding more debilitating consequences down the line” (1). The sentiment of South Korean citizens reflects the trade-off that needs to be made: any increase in ability to stop the slow spread of COVID-19 comes with a corresponding decrease in individual privacy. Even in the case of a minimal approach, like the one proposed by Apple and Google, privacy still remains an issue. Russell Brandom in his Verge article reports how Apple and Google have released a revised bluetooth contact tracing proposal in order to address privacy concerns like the potential for tracing keys to be hacked in a way that identifies the user. Additionally, the new proposal explains how the system will be shut down at the end of the pandemic (1). Any approach to DCTT will involve privacy concerns.
Given the tension between protecting privacy and promoting the common good of society (by slowing the spread of the virus), it is worth considering how the ethical theories might adjudicate this conflict. Using a utilitarian framework to evaluate the costs and benefits of DCTT in response to COVID-19 is helpful in identifying the extent to which DCTT might be morally justified. In his article “When Will the Pandemic Cure be Worse than the Disease?”, renowned utilitarian philosopher Peter Singer questions the moral justification of global lockdowns. He proposes the idea that “a lockdown, if it goes on long enough, will bring about a smaller economy that can afford fewer doctors, nurses, and medicines.” If the economy has a smaller capacity to provide healthcare, this means that less people will receive the care they need and more people will die. Singer goes on to mention a back-of-the-envelope analysis completed by economist Paul Frijters that suggests that “it would have been better, in terms of years of healthy life lost, not to have started the lockdowns” (1). While Singer admits that these numbers are back-of-the-envelope, he shares them to demonstrate the significant long term damages caused by the lockdown that many people are not fully considering. If DCTT can assist public health officials in a way that helps meaningfully reduce the spread, then the economy can begin to open up sooner, and the types of harms Singer is worried about will be reduced. There still remain privacy costs to DCTT, depending on the approach. The question then becomes whether the privacy cost is worth it, and what obligations citizens have to each other when sacrificing autonomy and privacy for the common good.
Social contract theory provides a good framework for understanding what authority the government has to use digital data for the purposes of contact tracing, as well as what political obligations people have in terms of participating in a DCTT program. The main principle behind social contract theory is that individuals of a society agree to a social contract that gives the government legitimate jurisdictional authority over a society in exchange for all the benefits that come from living in a stable political environment. Agreeing to a social contract necessarily requires that individuals sacrifice some level of liberty, as now one is subject to the legitimate laws governing the state, and can no longer act with the type of absolute liberty inherent in a state of nature. In his book on political authority and secession, philosopher Christopher Heath Wellman argues that “because virtually all of us recognize that life in the absence of political stability would be hazardous, each of us would voluntarily pay our political dues in order to avoid the insecurity of an apolitical environment” (10). Part of paying political dues is surrendering some degree of freedom so that the government can ensure political stability. Wellman goes on to argue that “citizens have no claim-right to be free from political coercion when this will leave others in a condition of political instability” (13). In the example of DCTT and the pandemic, the state would use coercive powers to institute any DCTT program that collects private information. Even when collecting unidentifiable information, digital contact tracing is a form of mass surveillance, and all things being equal, people generally have a privacy right to not be surveilled in certain ways. However, just like citizens in a state of nature are required to sacrifice some rights in exchange for political stability, so in extreme cases (like a global pandemic) are citizens required to sacrifice some rights to help bring about greater stability. The caveat here is that political stability must be threatened. Once the pandemic is over, political stability is no longer threatened, and the coercive use of surveillance and private information collection through DCTT is no longer justified. Additionally, the political instability caused by the pandemic certainly is not as severe as an anarchic state of nature, however the types of privacy violations inherent in the DCTT systems the United States is considering are not entirely severe. Asking someone to allow the use of unidentifiable bluetooth tracing keys on their phone is not asking someone to sacrifice a great deal of liberty/autonomy/privacy, especially when a DCTT system could help open up society and the economy sooner, thus mitigating the long term harms identified by Singer.
However, just because a DCTT system might be justified under social contract theory, this does not mean that people’s privacy rights should not be protected or be of concern when using DCTT. Kant’s categorical imperative is useful when ascertaining how a DCTT should be designed to protect privacy and other rights and values. Specifically the “Formula of Humanity” formulation of the categorical imperative states: “So act that you treat humanity, whether in your own person or in the person of any other, always at the same time as an end, never merely as a means” (1). In the case of DCTT, there is a risk that the government might be using people as a means (gathering their data) to an end (stemming the spread of the virus). While the “ends” in this case are very good, this does not necessarily justify treating American citizens as a means with no respect for privacy or other values. If people should not be treated as a means, then there is an opportunity to design DCTT in ways that promote privacy. The authors of the Johns Hopkins report suggest that the concept of “privacy by design” is one way to do this. The report identifies that the principles of privacy by design “acknowledge the need to design privacy defaults into systems, while maintaining the capacity of those systems to achieve their otherwise justifiable ends” (50). The primary importance is slowing the spread of the virus, but the tools we use to accomplish that task can also be used to protect privacy. Examples of privacy by design with DCTT are decentralized privacy-preserving proximity tracking systems that provide “decentralization, anonymity of users, and bans on collection of location data” (50). With systems like this, privacy is not merely left up to the discretion of the administrators of the system, it is directly built into the functioning of the digital tools. There is less need to hope that administrators of the technology do not misuse the data or that bad actors do not acquire the data. The report continues by suggesting that we should consider other “values (aside from privacy) that individuals and groups within society—including many privacy advocates—may believe to be important. For example, at any moment, in addition to valuing their own privacy, individuals may value efficiency, equity, autonomy, economic well-being, companionship, patriotism, or solidarity” (51). A large part of Kantian thought is understanding what values are ethically important and how those values should inform how we should act. Incorporating important values, like the ones identified above, into DCTT is a Kantian way of ethical design that considers the categorical imperative. The authors of the report argue that giving users the opportunity to consent to share location data could be a mechanism which lets citizens who are interested express “selflessness, autonomy, solidarity, or patriotism” by assisting public health officials in fighting the virus. Privacy is important, but there are other opportunities to incorporate important moral values into the design of DCTT that help prevent people from being treated as a means to an end. Ultimately, when designing DCTTs, despite the noble cause, Kantianism tells us that both privacy and other values should still be emphasized.
Based on the understanding of the importance of fighting the virus while simultaneously promoting privacy and other values, the authors of the Johns Hopkins report recommend a middle-ground approach to DCTT. The authors make the case for restricted data sharing:
What would enable the most flexible and potentially robust public health response is to design DCTT so that restricted data sharing is possible. From an ethics perspective, the collection and use of sensitive data in manual contact tracing efforts is typically seen as ethically justifiable so long as there is sufficient public health benefit and need. Thus, wouldn’t it seem appropriate from both a public health and ethics perspective to design DCTT systems to enable similar data to be shared with public health authorities when and if there is ethical justification for sharing them? (52-53)
The authors are arguing that the type of information ascertained from traditional manual contact tracing is more sensitive than any data that would be collected from a minimal approach. Given that we have long found manual contact tracing to be morally acceptable during times of public health crisis, it seems like if DCTT can be designed and implemented in a similar way, then a middle ground approach might be justified during the pandemic crisis. For example, when public health officials ask an infected patient where they have been and what routes they took, this is similar to asking an infected user to provide location data.
Despite this, middle ground approaches are not immune to objection. One objection to middle ground approaches is that minimal approaches are better because they are near harmless to users. With a middle ground approach, there will be sharing of potentially identifiable data, and that risks harm to a user. The authors respond to this objection by arguing that there are other types of harms that would be more likely to occur in minimal approaches. For example, a minimal approach is more susceptible to false positives and excessive contact notification. Such an issue would severely undermine both the quality of the data and the public’s confidence that the system is accurate and useful. This is harmful because it gives public health officials less of a capacity to stop the harms of the virus. The authors acknowledge that there is more of a risk for potentially identifiable data to be monetized or misused through a middle-ground approach, however, the risk is outweighed by the incredible benefits of the more “flexible and robust public health response” that a middle-ground approach would likely allow (54-55). This type of reasoning is consistent with Moor’s just consequentialism. Moor’s just consequentialism allows certain moral concerns to override others. In the case of a middle-ground approach, the increased well being brought about by slowing the spread of the virus with a robust public health response overrides the risk of privacy harms. This is not to say that privacy is not an important concern, just that eliminating all risk for data to be misused is not worth limiting the pandemic response.
The authors specifically recommend a DCTT system that has a “base set of features that protect privacy”, much like a minimal approach, with the opportunity for users to opt-in to more data sharing (58). The opt-in option would be accompanied by information on how the data will be collected and used so that people can appropriately provide consent. It is also worth considering that there is likely a large number of people who would be willing and motivated, for either self-interested or compassionate reasons, to share more personal data like geographic location. It would not make sense to not have a technological infrastructure that would allow these people to share potentially critical information in the fight against the virus.
Another potential concern with a middle-ground approach is the issue of “surveillance creep.” The worry with DCTT and surveillance creep is that DCTT might give the government incredible capacity for mass surveillance, and it would be problematic if this capacity was used in contexts outside of the pandemic. If public health officials were to adopt a minimal approach, then this capacity for mass surveillance will be diminished, and there will be less risk of future misuse of the technology. The authors argue that this is where a “values by design” approach would help. Privacy can be built into the DCTT such that “only those data that are necessary and relevant for the public health purposes at hand are collected and used, and data should be kept only for the period of time needed for those public health purposes” (57). This means that public health officials will be technologically limited to only collecting data relevant to the pandemic crisis, and the data will have an expiration date for when the pandemic is over. If such privacy measures are built into the DCTT, then it will become much more difficult for any actors to use the technology in a different context. The authors go so far as to say that they are only willing to advocate for this approach because of the unique set of circumstances of this current time. For example, if this technology was proposed as a use for controlling seasonal flu, it would not be “ethically appropriate without significant public debate” (57). Given that this is the case, it remains important to design a DCTT to fit the specific needs of the current moment during the pandemic.
DCTT has the potential to significantly aid in public health officials’ attempts to slow the spread of the virus. While under normal circumstances there would not be a moral justification for the use of this type of surveillance technology, ethical theories like utilitarianism, social contract theory, Kantianism, and just consequentialism help us understand why there are strong moral reasons to adopt a middle-ground approach that places a strong emphasis on protecting privacy and other important relevant values during this pandemic. Ultimately, if middle-ground DCTT can assist public health officials in stemming the spread in a meaningful way and thus help increase the functioning and capacity of the economy sooner, then the privacy sacrifices and risks needed for this approach will be justified.
References
- Brandom, R. (2020, April 24). Apple and Google pledge to shut down coronavirus tracker when pandemic ends. Retrieved July 17, 2020, from https://www.theverge.com/2020/4/24/21234457/apple-google-coronavirus-contact-tracing-tracker-exposure-notification-shut-down
- Case Investigation and Contact Tracing : Part of a Multipronged Approach to Fight the COVID-19 Pandemic. (2020, April 29). Retrieved July 17, 2020, from https://www.cdc.gov/coronavirus/2019-ncov/php/principles-contact-tracing.html
- Frijters, P. (2020, May 21). The Corona Dilemma. Retrieved July 17, 2020, from https://clubtroppo.com.au/2020/03/21/the-corona-dilemma/
- Kahn, J. P. (Ed.). (2020). DIGITAL CONTACT TRACING FOR PANDEMIC RESPONSE: Ethics and governance. S.l.: JOHNS HOPKINS UNIV PRESS.
- Kerstein, S. (2019, April 13). Treating Persons as Means. Retrieved July 17, 2020, from https://plato.stanford.edu/entries/persons-means/
- Kim, M. (n.d.). Seoul’s Radical Experiment in Digital Contact Tracing. Retrieved July 17, 2020, from https://www.newyorker.com/news/news-desk/seouls-radical-experiment-in-digital-contact-tracing
- Singer, P. (2020, May 05). When Will the Pandemic Cure Be Worse Than the Disease? Retrieved July 17, 2020, from https://businessfightspoverty.org/articles/when-will-the-pandemic-cure-be-worse-than-the-disease/
- Wellman, C. H. (2005). A Theory of Secession. Cambridge: Cambridge University Press.