| The promise | What it cost when it failed |
|---|---|
| Mobile money reaches the unbanked | Agent networks thin out exactly where cash is scarcest |
| Biometric ID ends duplicate claims | A worn fingerprint means no ration today |
| Direct transfer removes the middleman | A wrong account number is discovered a quarter later |
| E-governance makes the state reachable | Reachable by anyone who can use a form in English |
| Asked at the design meeting | Asked at the launch review |
|---|---|
| Do we need this field at all? | How do we secure the field we already collect? |
| What happens to someone the system rejects? | What is our exception-handling backlog? |
| Who can refuse this, and at what cost? | What does the consent form say? |
| Cost to change: an hour | Cost to change: a rebuild |
| Failed experiment in a startup | Failed experiment in a welfare system |
|---|---|
| Lost revenue, recoverable | A missed meal, not recoverable |
| Users churn, and are replaced | Users cannot leave; there is no second ration shop |
| Rollback in an afternoon | Rollback needs a policy decision and months |
| Failure shows up in the metrics | Failure shows up as an absence nobody logs |
| Claim made for a deployment | Question that tests it |
|---|---|
| “It cuts leakage” | How many genuine claimants were removed alongside the ghosts? |
| “It reaches the last mile” | Reaches, or requires the last mile to come to it? |
| “It gives people a voice” | Who reads what they say, and what happens next? |
| “It enables real-time monitoring” | Monitoring of the service, or of the people receiving it? |
| Paper system | Digital system |
|---|---|
| Many local rulesets; errors are local | One ruleset; errors replicate everywhere |
| Discretion allows a clerk to fix an edge case | Discretion is designed out, so edge cases fail hard |
| Failure is visible and local | Failure is distributed and invisible |
| Corruption is retail | Errors are wholesale, and so are fixes |
| As a deployer, you decide | As a user of others’ systems, you can |
|---|---|
| Which fields the survey app collects | Document the failures your participants hit |
| How long the beneficiary database is kept | Report exclusion upward with numbers, not anecdotes |
| Whether there is an offline route | Ask a vendor the questions in Section 11 |
| Who can export the data, and to where | Refuse to require an ID the programme does not need |
| Question | A bad answer sounds like |
|---|---|
| Who benefits, who bears the risk? | “Everyone benefits” |
| Who does the design exclude? | “Coverage is 98 per cent” |
| What data, and could it be turned on people? | “It is all anonymised” |
| Who decides, and can it be contested? | “The system decides objectively” |
| What if it breaks? | “It has 99.9 per cent uptime” |
| Section | What you will be able to do |
|---|---|
| 2 · Privacy | Apply the proportionality test; know your DPDP obligations |
| 3–4 · Bias and AI | Ask for disaggregated error rates; match oversight to stakes |
| 5–6 · Identity and surveillance | Insist on a manual fallback; spot function creep early |
| 7–8 · Divide and platforms | Design for the unconnected; avoid rented-rails dependence |
| 9–11 · Harms and governance | Run a procurement conversation and an ethics checklist |
| Field | Alone | Combined with two others |
|---|---|---|
| Village | Thousands of people | Frequently one household, and sometimes one person |
| Age and gender | Broad categories | |
| Caste and occupation | Common in the district |
| “Nothing to hide” assumes | Which fails when |
|---|---|
| The watcher is benign | Governments and employers change |
| The rules stay as they are | Data outlives the law that permitted it |
| Information is read in context | A clinic visit becomes a note in a file elsewhere |
| Everyone faces the same scrutiny | The poor are watched far more, for far less |
| What Puttaswamy settled | What it left open |
|---|---|
| Privacy is a fundamental right under Article 21 | How the proportionality test applies case by case |
| It is not absolute; intrusion must be justified | Who decides whether a justification is adequate |
| It covers informational privacy, not only bodily | What remedy an excluded person actually has |
| Nine judges, unanimous | Later benches have applied it with varying strictness |
| Step | Where programmes usually fail it |
|---|---|
| Legality | Collection authorised by a circular rather than a law |
| Legitimate aim | The aim is real, but stated so broadly it justifies anything |
| Necessity | A less intrusive option existed and was never assessed |
| Proportionality | The benefit is measured; the harm to the excluded is not |
| Consent theatre | What would make it real |
|---|---|
| A thumbprint on an unexplained form | An explanation in the person’s language, before the form |
| “Agree to continue” with no alternative | A route to the service for someone who declines |
| Consent to “partners and affiliates” | Named purposes, with a stated retention period |
| Withdrawal that requires a district office visit | Withdrawal by the same channel as consent |
| Collected for | Later used for |
|---|---|
| Immunisation follow-up | Locating families for an unrelated enforcement drive |
| A livelihoods survey | Targeting lists shared with a funder or a vendor |
| Attendance monitoring | Evidence in a disciplinary or eligibility decision |
| Grievance records | Identifying complainants to the people complained about |
| Obligation | What a small NGO actually has to do |
|---|---|
| Lawful purpose and notice | Write down why each field is collected, in plain language |
| Consent or legitimate use | Know which basis you are relying on, per dataset |
| Access, correction, erasure | Have a named person who can act on a request |
| Breach notification | Know who you would tell, and within what time |
| Children’s data | Stricter treatment; verify before collecting from minors |
| Technique | What it protects against |
|---|---|
| Drop direct identifiers | Casual lookup only: the weakest step |
| Coarsen quasi-identifiers (age bands, district not village) | Combination attacks, which are the real risk |
| Aggregate before release | Individual re-identification, at the cost of detail |
| Restrict access rather than publish | Everything, and it is the most-skipped option |
| Human choice | Where it enters |
|---|---|
| What to predict | “Risk of default” or “need for credit” are different models of the same people |
| What data to use | Whatever was already recorded, which is whatever was already served |
| What counts as success | Overall accuracy, or the error rate for the worst-served group |
| Where to set the threshold | A pure value judgement, usually made by whoever ships it |
| Where bias shows up in our sector | Form it takes |
|---|---|
| Credit and microfinance scoring | Thin-file applicants scored as risky for having been excluded |
| Beneficiary targeting models | Households missed by past surveys stay missing |
| Speech and language tools | Accuracy falls sharply outside dominant languages and accents |
| Facial recognition | Higher error rates for darker skin and for women, repeatedly measured |
| Fraud detection | Flags correlate with poverty markers, so the poor are investigated more |
| Gap in the data | What the model concludes |
|---|---|
| Fewer loans recorded to women | Women are a weaker lending prospect |
| Remote villages surveyed less often | Those villages have less need |
| Disability rarely recorded at all | Disability is not a relevant feature |
| Complaints logged only where offices exist | Service is satisfactory where there are no offices |
| Removed field | What still carries it |
|---|---|
| Caste | Surname, pincode, occupation, school attended |
| Religion | Name, locality, dietary fields, festival-linked activity |
| Gender | Name, occupation, phone-ownership patterns, time of use |
| Disability | Claim history, service-usage patterns, employment gaps |
| Definition | What it equalises | What it gives up |
|---|---|---|
| Equal selection rate | Same share chosen from each group | May select less-qualified from one group |
| Equal error rates | Same chance of being wrongly rejected | Selection rates will differ |
| Equal precision | A positive means the same thing for everyone | Conflicts with equal error rates |
| Audit step | What to ask for |
|---|---|
| Disaggregate performance | Error rates by gender, caste, region, language, not overall accuracy |
| Test for proxies | Can a removed trait be predicted from the remaining fields? |
| Document the training data | Who is in it, who is missing, and over what period |
| Re-audit on a schedule | Populations drift; a model correct in 2024 is not therefore correct now |
| Record the decisions | Which fairness definition, which threshold, and who signed it off |
| Question to settle before a pilot | Why it decides everything after |
|---|---|
| Is the model advising or deciding? | Sets the entire oversight requirement |
| Who is accountable when it is wrong? | If the answer is “the system”, nobody is |
| Was it evaluated on our population? | Performance elsewhere transfers poorly, especially across languages |
| What is the fallback when it is unavailable? | Uptime failures land on the same people as model failures |
| What “explainable” has to mean | Test |
|---|---|
| To the affected person, not the engineer | Could a field officer say it aloud in the person’s language? |
| Specific to this decision | Not “the model considers many factors” |
| Actionable | Does it tell them what would change the outcome? |
| Available before the appeal deadline | An explanation that arrives late is not a remedy |
| Error type | Who notices | What follows |
|---|---|---|
| False positive: wrongly included | Auditors, quickly | Tightening, and press coverage about leakage |
| False negative: wrongly excluded | Only the person excluded | Usually nothing; they stop coming |
| Where fluency is most dangerous | Because |
|---|---|
| Health and medication advice | A confident wrong dose is acted on |
| Legal entitlement and rights | Invented sections and deadlines are unverifiable by the user |
| Scheme eligibility | A plausible answer stops someone applying |
| Translation into a low-resource language | Nobody in the room can check it |
| Use | Stakes | Guardrail |
|---|---|---|
| Draft a report summary | Low | Human edits before sending |
| Translate a notice | Medium | Native speaker verifies |
| Screen a medical scan | High | Clinician confirms every case |
| Decide benefit eligibility | Very high | Human decides; appeal route open |
| What to check at each level of stakes |
|---|
| Low: is a human reading it before it leaves? |
| Medium: is the reviewer competent in the language and the subject? |
| High: does every case get human confirmation, and is that logged? |
| Very high: does a person decide, and can the affected person reach a human who can reverse it? |
| Question | What an inadequate answer looks like |
|---|---|
| Harm if confidently wrong? | “It is only a suggestion”, check whether anyone overrides it |
| Can we explain a decision? | “It uses many signals” |
| Tested on people like ours? | Benchmarks from another country, in another language |
| Human fallback and appeal? | A helpline number that rings in a city office |
| Who is accountable? | “The vendor”, with no clause saying so |
| What Aadhaar is | What it is often assumed to be |
|---|---|
| A number linked to biometrics, proving one person = one number | Proof of citizenship: it is not |
| An authentication service others can query | A database of everything about you: it holds a limited set |
| Statutorily backed, with a designated authority | Unregulated: there is a legal framework, contested but real |
| Optional to obtain (Aadhaar Act s3), but the government may require it for any subsidy, benefit or service paid from the Consolidated Fund (s7), which the Supreme Court upheld in 2018 | Required for everything: banks and telecom companies may not refuse a service to someone who declines to use it (s4(6), after the 2018 judgment) |
| Who gains most | Why |
|---|---|
| People with no documents at all | Migrants, the landless and many women held nothing in their own name |
| Women opening an account independently | An identity not mediated through a husband or father |
| Inter-state migrants | Portability matters most to people who move |
| Anyone previously invisible to the state | Being countable is a precondition for being served |
| Failure | Who it hits hardest |
|---|---|
| Worn or damaged fingerprints | Manual labourers, older people: precisely the entitled |
| No connectivity at the point of sale | Remote villages, which are also the poorest |
| Server or service downtime | Everyone in that district, on that day |
| Demographic mismatch in records | People whose names are transliterated inconsistently |
| No linked mobile for the OTP fallback | Women, who own phones at markedly lower rates |
| Dimension | Benefit | Harm |
|---|---|---|
| Identity | The undocumented become visible | Errors make the visible disappear |
| Delivery | Faster transfers, fewer ghosts | Failed auth blocks real beneficiaries |
| Mandate | One ID, many services | Function creep, no real opt-out |
| Bodies | Biometrics are hard to forge | Worn fingerprints exclude labourers |
| A fallback that works | A fallback that does not |
|---|---|
| The dealer can issue today, and reconcile later | “Come back tomorrow” |
| Exception register the dealer is expected to use | An exception route that counts against the dealer |
| Logged and monitored centrally | Undocumented discretion, which invites abuse |
| Known to the claimant before they arrive | Known only to officials |
| “Voluntary” system | What happens if you decline |
|---|---|
| ID for a subsidised ration | No ration |
| ID for a school scholarship | No scholarship |
| Aadhaar for a SIM card | In law, nothing: since the 2018 judgment the operator must accept another ID (Aadhaar Act s4(6)). The test is whether the person at the counter knows that |
| Biometric attendance for a wage | No wage that day |
| Metric that flatters | Metric that tests |
|---|---|
| Enrolment coverage | Authentication success rate, by district and by age |
| Transactions completed | Transactions attempted and failed |
| Savings from removed duplicates | Genuine claimants removed alongside them |
| Average uptime | Outage hours in the lowest-connectivity blocks |
| Built to deliver | Also produces |
|---|---|
| Ration transactions | A record of where a person was, and when, weekly |
| Attendance systems | Movement and association patterns |
| Health programme registers | Conditions, pregnancies, treatment histories |
| Grievance portals | A list of who complained, about whom |
| Guard against creep | How |
|---|---|
| Bind the purpose in writing | State it at collection, and require a new basis for any new use |
| Set a deletion date | At collection, not later: retention only ever gets extended |
| Separate the identifier | Hold service data and identity data apart, joinable only under a rule |
| Log every access | Who read this record, when, and why |
| To receive a subsidy, a poor household provides | To access their own savings, a wealthy person provides |
|---|---|
| Biometrics, at every transaction | A card, usually once |
| Household composition and income declarations | Nothing recurring |
| Location, weekly, by collection point | Not recorded as a condition |
| Justification for any change in circumstances | None required |
| Condition | Who fails it, and why |
|---|---|
| Minimum attendance, biometrically verified | Sick, caring for someone, or without transport that week |
| Bank account linkage | People without documents, or with an account in another name |
| Repeated re-verification | Migrants, who are not present when the check runs |
| Digital grievance filing | The non-literate and the unconnected: the likeliest to have a grievance |
| What people avoid when they suspect a record | Consequence |
|---|---|
| A clinic visit for a stigmatised condition | Untreated illness; onward transmission |
| A meeting of a union or a rights group | Weaker collective action, which is often the point |
| Filing a complaint against an official | Abuse continues, and appears to be absent |
| Seeking help after violence | The gravest, and the least visible in any dataset |
| They can | You cannot |
|---|---|
| Link your records across agencies | See what has been linked |
| Act on an inference about you | Learn what the inference was |
| Change the rules retrospectively | Withdraw data already given |
| Decline to explain a decision | Contest a reason you were never told |
| Where consent is weakest | Because |
|---|---|
| Welfare enrolment | Refusal means losing the entitlement |
| Employment conditions | Refusal means losing the job |
| NGO programme participation | Refusal is read as ingratitude, or as disqualification |
| Research participation | The researcher is often also the service provider |
| Safeguard | What makes it real rather than stated |
|---|---|
| Purpose-binding and deletion | A date in the system, not a sentence in a policy |
| Separating delivery from policing | Different databases, different access, no shared key |
| Minimising linkage | Joins require an approval that is logged and refusable |
| Independent oversight | Power to compel disclosure and to stop processing |
| A complaint route | One a person without a smartphone can actually use |
| Level | What it takes to clear |
|---|---|
| A device in the household | Money, once, and whose device it is matters |
| A device you control | Frequently fails for women and younger family members |
| Affordable data and charging | Recurring cost, and reliable electricity |
| Skills and language | Literacy, and an interface in a language you read |
| Meaningful use | Something on the device that improves your life |
| Axis | What it excludes in a typical service |
|---|---|
| Income | Recurring data cost, which is the binding constraint more often than the device |
| Language | Interfaces in English or one dominant state language |
| Literacy | Text-heavy flows with no voice or icon path |
| Disability | Apps that break screen readers; no captions; low-contrast text |
| Age | Small targets, jargon, and no assisted-use mode |
| Level | Typical intervention | What it leaves unsolved |
|---|---|---|
| 1 Access | Distribute devices; build towers | Cost of use, skills, relevance |
| 2 Affordability | Subsidised data | Skills, language, relevance |
| 3 Skills | Digital literacy training | Whether anything useful is there |
| 4 Meaningful use | Services worth using, in the right language | Nothing: this is the point of the other three |
| Gone digital-only | Who is pushed out |
|---|---|
| Scheme applications | Anyone without a device, data or the literacy to use it |
| Grievance filing | The people with the most grievances |
| Appointment booking | Walk-in users, who were the majority |
| Payment and verification | Households where the phone belongs to someone else |
| What the intermediary makes possible | What it costs |
|---|---|
| Completing a transaction at all | Handing over the OTP, and so the account |
| Reading and filling the form | Disclosure of income, health, family details |
| Reaching a service that is far away | An informal fee, unregulated and unrecorded |
| Help for those with a trusted relative | Nothing for those without one |
| Design choice | Who it brings in |
|---|---|
| Voice and IVR alongside text | Non-readers, and anyone on a feature phone |
| Works on low-end devices and 2G | The poorest, and most rural users |
| Local languages, including script choice | Most of the country |
| Screen-reader compatibility and contrast | Users with disabilities, and everyone in sunlight |
| An assisted-use mode | The majority who need help, safely |
| Layer | What it controls |
|---|---|
| Operating system and app store | What can be installed, and what a developer must pay |
| Search and feed ranking | What is findable, and therefore what exists in practice |
| Cloud hosting | Whether your service runs at all tomorrow |
| Payments and identity | Who can transact, and on what terms |
| The analogy holds | Where it strains |
|---|---|
| Raw material extracted; value added elsewhere | Data is not depleted by being taken |
| Terms set by the extracting party | Users receive a real service in return |
| Infrastructure and expertise stay abroad | No territorial control or coercion in the historical sense |
| The producing region holds little of the upside | Some local firms capture value too |
| What makes the region attractive | What it means locally |
|---|---|
| Very large, fast-growing user base | Scale gives the platform leverage in any dispute |
| Rich behavioural and language data | Valuable for training models sold back into the region |
| Lighter or newer regulation | Practices tested here before markets with older law |
| Price-sensitive users | “Free” wins, and free is paid for in data |
| Dependency | What a change would do to your programme |
|---|---|
| A messaging app as the delivery channel | A policy change ends your outreach, without notice |
| A cloud provider holding beneficiary data | A pricing change or account action freezes operations |
| An ad platform for recruitment | A category ban removes your reach overnight |
| A proprietary data format | Migration costs exceed the value of moving |
| What data sovereignty can mean | Trade-off |
|---|---|
| Data localisation: stored in-country | Also makes it easier for the local state to reach |
| Public digital infrastructure | Reduces platform dependence; concentrates state power |
| Open-source and open standards | Portability, at the cost of engineering capacity to maintain it |
| Community control over community data | The strongest version, and the hardest to institutionalise |
| Practice | Effort |
|---|---|
| Export your data in an open format, on a schedule | A recurring job; set it once |
| Read the terms for what the platform takes from your users | An afternoon, once per platform |
| Prefer formats and standards you could move | A choice at procurement, free at that moment |
| Use public or community infrastructure for critical paths | Real work, and only where it is viable |
| Why the same message spreads further here |
|---|
| It arrives from a relative, so it carries their credibility rather than a source’s |
| There is no like-count, no label and no visible correction inside a closed group |
| Encryption hides the origin, so “who started this” has no answer |
| Fact-checking capacity is thinnest in the languages with the most users |
| Open platform | Closed group |
|---|---|
| Researchers can see what circulates | Nothing is observable from outside |
| Content can be labelled or down-ranked | There is nothing to label |
| A correction can reach the same audience | You cannot post into a group you are not in |
| Credibility comes from the source | Credibility comes from the sender |
| What turned a message into violence | What has helped |
|---|---|
| A rumour circulating faster than any check | Forward limits, which cut velocity without reading content |
| No authoritative account for hours or days | Police and administration publishing verified facts early |
| A stranger present in an unfamiliar place | Local volunteers who can say “this is not from here” |
| Recaptioned footage from elsewhere | Reverse image search, taught at community level |
| Scam | Why new users are the target |
|---|---|
| Fake KYC-update messages | Real KYC requests exist, so the pretext is plausible |
| Bogus scheme or lottery fees | Genuine schemes do transfer money unexpectedly |
| Loan apps with hidden charges | Formal credit is unavailable, so the offer is welcome |
| OTP requests from a “bank officer” | Assisted use has trained people to share OTPs |
| What makes moderation weak in a language | Consequence |
|---|---|
| Few trained human reviewers | Escalations sit unread, or are auto-closed |
| Little training data for classifiers | Automated detection performs poorly or not at all |
| Code-mixing and Roman script | Text falls outside whatever model exists |
| Local slurs and dog-whistles unmapped | The most dangerous content is the least detectable |
| Over-removal | Under-removal |
|---|---|
| Dissent and minority speech disappear first | Harmful content spreads unchecked |
| Automated systems misread satire and reclaimed slurs | Coordinated campaigns operate freely |
| Rules become a tool against critics | Targeted groups bear the cost |
| Appeal routes are slow or absent | Reports go unanswered |
| Response | Evidence and cost |
|---|---|
| Forward limits and friction | Reduces velocity measurably; needs no content decisions |
| Prebunking: teach the technique before the lie | Generalises to claims not yet invented; effects decay |
| Local fact-checking in the right language | Essential, and always second to the rumour |
| Trusted community messengers | The strongest single factor; slow to build, cheap to keep |
| Decision | Cost to change at design | Cost to change after launch |
|---|---|---|
| Which fields to collect | A conversation | Data already held; schema migration |
| Whether there is an offline route | A requirement line | New staffing, budget and policy |
| What the model optimises | A choice | Retraining, and a year of decisions to revisit |
| Whether decisions can be appealed | A workflow step | A new institution |
| Default that protects | Default that harms |
|---|---|
| Sharing off unless chosen | Sharing on with an opt-out buried in settings |
| Retention set at collection | Keep indefinitely, review never |
| Access limited to those who need it | Whole-team access because it is simpler |
| Optional fields genuinely optional | Required fields with no operational purpose |
| Principle | The question it forces |
|---|---|
| Design with people | Did anyone affected see this before it was built? |
| Understand the existing ecosystem | What is already working that we are about to replace? |
| Build for sustainability | Who runs this when the grant ends? |
| Use evidence to improve outcomes | What would tell us this is not working? |
| Establish people-first data practices; anticipate and mitigate harms | What is the worst use of this data, and by whom? |
| Share, reuse and improve; create open and transparent practices | Could someone else take this over? |
| Ask | Concretely |
|---|---|
| Who could be harmed? | Name groups, not “users”: women, minorities, undocumented migrants |
| How could the data be misused? | By a future government, an employer, a family member, a hostile neighbour |
| What is the safeguard? | Something in the architecture, not the policy document |
| Is the residual risk worth it? | A decision someone signs, on a date, in writing |
| Field routinely collected | Is it used? |
|---|---|
| Caste | Only if disaggregation is actually reported; otherwise a liability |
| Full date of birth | Age band is almost always sufficient |
| Precise GPS of a household | Village or block is usually enough, and far safer |
| Phone number of every member | One contact serves the purpose |
| Photograph | Rarely used after collection, and hard to secure |
| What participation surfaces | That outsiders miss |
|---|---|
| Who in the household controls the phone | Designs that assume personal device access |
| Which words the interface should use | Translations that are technically correct and unread |
| When people can actually attend or transact | Office hours that assume no wage work |
| What a failure costs them | Retry flows designed for people with time |
| Redress element | Test of whether it is real |
|---|---|
| A route to contest a decision | Usable by someone without a smartphone or literacy |
| A human who can override | They have the authority and are not penalised for using it |
| Plain-language notice | In the language spoken, at the moment data is taken |
| An exit | Correction and deletion actually happen, within a stated time |
| Layer | What it can do | What it cannot |
|---|---|---|
| Law | Set rights and obligations | Notice your specific form |
| Regulator | Investigate, penalise | Reach most small deployments |
| Organisation | Policy, review, training | Survive a change of leadership without structure |
| Practitioner | Decide what goes on the form | Fix a system designed elsewhere |
| What makes an authority effective | Warning sign |
|---|---|
| Independence in appointment and removal | Members serve at the pleasure of the executive |
| Adequate staff and technical capacity | A handful of officers for a national caseload |
| Power to compel and to penalise | Recommendations only |
| Broad remit | Wide exemptions for state processing |
| Right | What it looks like when exercised |
|---|---|
| Access | “Show me what you hold about me and who you shared it with” |
| Correction | “My name is spelled two ways; fix the record” |
| Erasure | “The programme ended; delete my data” |
| Grievance | “I was refused and nobody will tell me why” |
| Area | Ask before you deploy |
|---|---|
| Purpose | Is each data field truly necessary? |
| Consent | Is it free, informed, specific, revocable? |
| Inclusion | Who does this design exclude, and is there a fallback? |
| Bias | Have we tested outcomes across groups? |
| Security | Who can access this, and is it protected? |
| Redress | Can a person contest a decision and reach a human? |
| Ask the vendor | Put in the contract |
|---|---|
| Where is data stored, and who can access it? | Named jurisdictions; a list of sub-processors |
| Has it been tested for bias and accessibility? | Disaggregated performance, supplied annually |
| What happens to our data if we leave? | Export in an open format; deletion certified |
| What is the uptime and the fallback? | An agreed manual process during outages |
| Who is liable when it is wrong? | A clause, rather than an assurance in a meeting |
| If you do one thing | Where it is in this deck |
|---|---|
| Delete a field from your survey form | Sections 2 and 10 |
| Ask a vendor for disaggregated error rates | Sections 3 and 11 |
| Build a working manual fallback | Section 5 |
| Set a deletion date on an existing dataset | Sections 2 and 6 |
| Write down what happens to someone who says no | Sections 2 and 5 |
| Source | Read it for |
|---|---|
| Eubanks, Automating Inequality | How welfare systems automate exclusion: closest to Sections 5–6 |
| O’Neil, Weapons of Math Destruction | Feedback loops and opaque scoring, in plain language |
| D’Ignazio & Klein, Data Feminism | Power in data collection and classification |
| Couldry & Mejias, The Costs of Connection | The data-colonialism argument, from its authors |
| Principles for Digital Development | The sector framework, usable in a proposal |