The decision record as privacy
Decision Accounting
The decision record as privacy infrastructure
core-claim
Core claim
The privacy comparison is governed DA records versus ungoverned decision trails
The paper answers the dossier objection by changing the counterfactual. DA records add privacy risk, but the status quo already produces searchable dossiers without access controls, purpose limits, retention schedules, or individual rights.
- R0 has decision trails in email, meeting minutes, employment files, screening databases, discovery systems, and broker dossiers.
- R1 standardizes the same category of records and places them under role-based access, purpose limits, retention schedules, and data subject rights.
- The paper’s claim is comparative: a governed dossier is better for privacy than the ungoverned dossier infrastructure already in use.
privacy-objection
Objection
The strongest objection is that DA records create a reusable surveillance database
The paper states the civil-liberties objection in its strongest form before answering it.
- Each material decision record can name the decision-maker, participants, dissenters, reasoning, stakeholder impacts, and implementation timeline.
- The feared users are employers, regulators, litigants, data brokers, and future governments.
- The objection turns on function creep: a database built for accountability could be reused to discipline dissenters or profile decision-makers.
equilibrium
Equilibrium error
R0 is not record-free; it is governance-free
The objection assumes the no-DA world lacks a searchable database of decision-making behavior. The paper says that assumption is false.
- R0 already includes employment records, data broker dossiers, employment screening databases, litigation discovery databases, and government records.
- Those systems are searchable, fragmented, inconsistent, and weakly governed.
- The difference in R1 is not the existence of records. It is the addition of defined access, purpose, retention, and rights.
ungoverned-dossiers
Existing dossiers
Data brokers already assemble decision trails into large personal profiles
The paper uses data brokerage to show why undocumented records are not privacy-neutral.
- The FTC-documented broker example is 3,000 data points per consumer.
- Acxiom is described as holding data on 2.5 billion consumers worldwide, with an average of 1,500 data points per consumer.
- Sources include public records, purchase histories, web browsing, location data, and organizational records such as employment, insurance, medical, and education records.
welfare
Welfare claim
The paper links ungoverned broker data to a $2.0 trillion welfare loss
The economic comparison is part of the paper’s privacy answer, not a separate policy claim.
- The data brokerage industry is estimated at approximately $200 billion in annual revenue.
- The canon’s welfare analysis assigns $6.13 in societal welfare loss per dollar of broker revenue.
- The paper says the resulting loss is approximately $2.0 trillion and concentrated among low-income people, racial and ethnic minorities, and people with health conditions or disabilities.
harm-mechanism
Mechanism of harm
Broker profiles turn hidden organizational records into decisions people cannot contest
The paper’s privacy harm is not only collection. It is the use of opaque profiles in employment, housing, insurance, marketing, and government contexts.
- Brokers aggregate organizational records into profiles sold to employers, landlords, insurers, marketers, and government agencies.
- Those profiles can influence hiring, renting, insurance, and predatory product targeting without the person’s knowledge or consent.
- The paper cites 20-30% error rates in data broker profiles and treats lack of verification and correction as a central harm.
data-subject-rights
Access asymmetry
DA gives named people access to records that the current regime keeps opaque
The DA framework reduces the information gap by giving individuals rights over the records in which they appear.
- A named decision-maker can request every DA record in which they appear as decision-maker.
- A named dissenter can request every record documenting their dissent.
- A named affected party can request every record listing them under the stakeholder impact field, and can seek correction or object to incompatible processing.
termination-case
Concrete case
The termination example shows what DA replaces in practice
The paper’s example is an employee termination decision. In R0, the decision is scattered across internal records and may later be shared with background-check services, references, or data brokers.
- R0 records include emails, performance reviews, disciplinary notices, and termination letters without standardized fields or DA-specific controls.
- R1 records the decision-maker, evidence considered, alternatives evaluated, and stakeholder impacts in a standard DA format.
- The employee gains access, correction, and objection rights over the decision record rather than waiting for litigation to surface fragments.
field-8
Architecture
Field-level access control protects dissenting views from the decision-maker
The paper’s most concrete privacy safeguard is the handling of the uncertainty field, Field 8, which contains dissenter identity.
- Field 8 is accessible only to General Counsel, the Chief Data Officer, the Audit Committee, and Internal Audit.
- The decision-maker named in the record does not have read access to the uncertainty field of their own decision record.
- All access is logged, and access logs are reviewed quarterly.
safeguards
Safeguards
The DA system limits use, content, retention, and transfer of decision records
The paper specifies safeguards as design requirements rather than after-the-fact promises.
- Purpose limitation: DA records are created for verification, learning, and redress, and other uses require consent from named individuals.
- Data minimization: the minimum fields are decision-maker identity, decision date, decision type, evidence considered, alternatives evaluated, stakeholder impacts, and dissenting views.
- Retention scheduling: records are deleted or anonymized after the period tied to decision type and legal requirements.
risk-assessment
Risk register
The paper names four DA privacy risks and assigns mitigation measures
The risk assessment is specific about likelihood, severity, and controls.
- Unauthorized access to Field 8: likelihood 3/5, severity 4/5, score 12, mitigated by role-based access, access logs, and quarterly review.
- Cross-border transfer of DA records: likelihood 3/5, severity 4/5, score 12, mitigated by transfer impact assessments for non-adequate jurisdictions.
- Employment-dispute use: likelihood 3-4/5, severity 3/5, score 9-12, mitigated by retention policy, privilege procedures, and data subject rights.
falsification
Falsification
The objection wins only with evidence of net harm from a deployed DA system
The paper’s falsification condition rules out comparison to an idealized no-records world.
- The evidence must come from an actual deployed DA system, not speculation about future misuse.
- Privacy harm must be measured net of DA benefits such as access, correction, objection, and reduced ungoverned broker supply.
- The benchmark is the real counterfactual: employment records, broker dossiers, screening databases, discovery databases, and government records without DA governance.