Ensuring the safety and security of data relating to victims of terrorism in connected systems.
Problem Statement
Digital connectivity can be a double-edged sword for victims of terrorism. While integrated digital victim registries and referral systems are essential for providing joined-up services, they carry risks. A data breach is rarely just a technical failure; it can result in serious and, in some cases, irreversible harm through the unauthorized disclosure of personal or sensitive information. Such harm may include re-traumatization, exposure to physical or security risks. In the absence of widely agreed standards for data handling, robust audit mechanisms, and clear accountability frameworks, trust in digital systems is difficult to establish, and well-intentioned technological solutions may inadvertently cause more harm than benefit.
Toward secure victim registries
As discussed in the Gap Analysis of Digital Tools to Support Victims of Terrorism, an international discussion is emerging on greater information connectivity and integrated digital services, for example through Digital Public Infrastructure (DPI). One use-case we explore in our analysis is developing Digital Victim Registries that can work with Digital ID and Data Exchange to allow victims to access multiple services without the need to re-authenticate or repeatedly "re-tell" their stories to different providers. Combined with privacy-by-design techniques like homomorphic encryption and metadata-only on-chain storage, these systems could allow for secure, auditable, and victim-controlled data sharing. If tools are designed from the outset to meet court-admissible evidentiary standards for the collection, handling and storage of data, these victim registries could also help support access to justice, including by contributing to criminal justice proceedings, subject to appropriate safeguards for privacy and data protection.
Core Questions for the Working Group
To build a secure and trustworthy digital architecture for the data of victims of terrorism, this working group will address questions such as: • How can we ensure that digitizing victim records and connecting them to government or third-party services does not increase the risk of harm for persons whose data is shared, including vulnerable individuals and communities? • What shared standards or audit mechanisms can be implemented to prevent unauthorized access, data misuse and data breaches and ensure transparency and accountability in the event of such incidents? • What are the minimum technical and legal standards required to ensure that data stored in Digital Victim Registries meets evidentiary standards for use in justice settings? • How do we design "trauma-informed" consent mechanisms so that victims can set, amend, or withdraw permissions for data-sharing, through meaningful control in realtime and throughout the data lifecycle? • Given the costs of maintaining blockchain-based ledgers, are there simpler high-integrity digital audit trails that may be more suited to resource-constrained settings?


Comments
Post a Comment