White House Launches Strategy to Advance Data Privacy Tech and Processes

Thapana Onphalai/Getty Images

Absent comprehensive federal law, the strategy represents a new chapter toward regulating data privacy protocols for U.S. online users.

The White House released comprehensive new recommendations to promote user data privacy for both public and private sector entities, focusing on mitigating bias and maximizing efficiency in an equitable way.

Released by the Office of Science and Technology Policy late Thursday, the “National Strategy to Advance Privacy-Preserving Data Sharing and Analytics” formalized the administration’s goals to support the research, development, regulation and application of solutions to the ethical and sociotechnical issues with data collection and analysis—known as privacy-preserving data sharing and analytics, or PPDSA, technologies—while focusing on use cases that do not violate user confidentiality.

“PPDSA technologies have enormous potential, but their benefit is tied to how they are developed and used,” the report begins. “Consideration of how individuals may control the collection, linking and use of their data should also factor into the design and use of PPDSA technologies.”

The strategy establishes four guiding pillars that represent the foundation of its approach to privacy and data:  crafting PPDSA technologies that protect civil rights, promoting innovation alongside equity, building technologies with accountability mechanisms and minimizing exposure of vulnerable groups.

The recommendations chronicled in the OSTP’s new report advocate for continued development of data analytics technologies, but with a sociotechnical approach that characterizes current federal guidance on emerging tech. 

“Public trust will hinge on the justified assurance that government, academic and industry use of PPDSA solutions will respect privacy, civil liberties and civil rights. The future PPDSA ecosystem must be transparent and inclusive and reflect privacy principles and preferences,” the strategy states.

It also advocates competing organizations developing data analytics systems to share and process data in a way that does not violate user privacy and rights. Safely sharing sensitive data will demand approaches that include securing and copying the original dataset for dissemination, using attribute-based encryption and restricting access to shared data.

The strategy emphasizes that these protocols be incorporated into the technology during the development stage. 

“Embedding the design, development and deployment of PPDSA technologies in a larger framework that encompasses legal, regulatory, ethical and policy mechanisms will help to create this level of accountability,” the report reads. 

Part of the sociotechnical approach calls for increased research funding to examine more sophisticated use cases. Incorporating complex datasets to better produce analytics for emerging issues like smart city sustainability, social network metrics and personalized medicine development are scenarios OSTP is envisioning alongside robust privacy capabilities.

The strategy lays out 16 recommendations across five strategic priorities to advance PPDSA technologies:

  1. Establish a steering group to support PPDSA guiding principles and strategic priorities.
  2. Clarify the use of PPDSA technologies within the statutory and regulatory environments.
  3. Develop capabilities and procedures to mitigate privacy incidents.
  4. Develop a holistic scientific understanding of privacy threats, attacks and harms.
  5. Invest in foundational and use-inspired R&D for PPDSA technologies.
  6. Expand and promote interdisciplinary R&D at the intersection of science, technology, policy and law.
  7. Promote applied and translational research and systems development.
  8. Pilot implementation activities within the federal government.
  9. Establish technical standards for PPDSA technologies.
  10. Accelerate efforts to develop standardized taxonomies, tool repositories, measurement methods, benchmarking and testbeds.
  11. Improve usability and inclusiveness of PPDSA solutions.
  12. Expand institutional expertise in PPDSA technologies.
  13. Educate and train participants on the appropriate use and deployment of PPDSA technologies.
  14. Expand privacy curricula in academia.
  15. Foster bilateral and multilateral engagements related to a PPDSA ecosystem.
  16. Explore the role of PPDSA technologies to enable cross-border collaboration.

Other technical approaches the strategy calls for within PPDSA system design are secure multiparty computation, where many parties can perform analysis of private data “while allowing each party to learn only the final computational output;” synthetic data usage for training purposes; K-anonymity, which transforms datasets so that record of a particular individual is “indistinguishable from the others;” and zero-knowledge proofs, which allow one party to prove the validity of a statement without revealing sensitive information.

Scalability and cost factors were common challenges listed for more mature and secure PPDSA technologies. Unraveling these issues will require increased investments in research to advance secure approaches to data architecture. 

“Substantial and sustained investment in both the public and private sectors should support accelerated R&D that is focused on emerging PPDSA technologies and bold exploratory research targeted to create the next generation of PPDSA capabilities,” the strategy states. 

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.