The decision record as privacy
Decision Accounting

The decision record as privacy infrastructure

core-claim
Core claim

The privacy comparison is governed DA records versus ungoverned decision trails

The paper answers the dossier objection by changing the counterfactual. DA records add privacy risk, but the status quo already produces searchable dossiers without access controls, purpose limits, retention schedules, or individual rights.

privacy-objection
Objection

The strongest objection is that DA records create a reusable surveillance database

The paper states the civil-liberties objection in its strongest form before answering it.

equilibrium
Equilibrium error

R0 is not record-free; it is governance-free

The objection assumes the no-DA world lacks a searchable database of decision-making behavior. The paper says that assumption is false.

ungoverned-dossiers
Existing dossiers

Data brokers already assemble decision trails into large personal profiles

The paper uses data brokerage to show why undocumented records are not privacy-neutral.

welfare
Welfare claim

The paper links ungoverned broker data to a $2.0 trillion welfare loss

The economic comparison is part of the paper’s privacy answer, not a separate policy claim.

harm-mechanism
Mechanism of harm

Broker profiles turn hidden organizational records into decisions people cannot contest

The paper’s privacy harm is not only collection. It is the use of opaque profiles in employment, housing, insurance, marketing, and government contexts.

data-subject-rights
Access asymmetry

DA gives named people access to records that the current regime keeps opaque

The DA framework reduces the information gap by giving individuals rights over the records in which they appear.

termination-case
Concrete case

The termination example shows what DA replaces in practice

The paper’s example is an employee termination decision. In R0, the decision is scattered across internal records and may later be shared with background-check services, references, or data brokers.

field-8
Architecture

Field-level access control protects dissenting views from the decision-maker

The paper’s most concrete privacy safeguard is the handling of the uncertainty field, Field 8, which contains dissenter identity.

safeguards
Safeguards

The DA system limits use, content, retention, and transfer of decision records

The paper specifies safeguards as design requirements rather than after-the-fact promises.

risk-assessment
Risk register

The paper names four DA privacy risks and assigns mitigation measures

The risk assessment is specific about likelihood, severity, and controls.

falsification
Falsification

The objection wins only with evidence of net harm from a deployed DA system

The paper’s falsification condition rules out comparison to an idealized no-records world.