| The promise | What it cost when it failed |
|---|---|
| Mobile money reaches the unbanked | Agent networks thin out exactly where cash is scarcest |
| Biometric ID ends duplicate claims | A worn fingerprint means no ration today |
| Direct transfer removes the middleman | A wrong account number is discovered a quarter later |
| E-governance makes the state reachable | Reachable by anyone who can use a form in English |
| Asked at the design meeting | Asked at the launch review |
|---|---|
| Do we need this field at all? | How do we secure the field we already collect? |
| What happens to someone the system rejects? | What is our exception-handling backlog? |
| Who can refuse this, and at what cost? | What does the consent form say? |
| Cost to change: an hour | Cost to change: a rebuild |
| Failed experiment in a startup | Failed experiment in a welfare system |
|---|---|
| Lost revenue, recoverable | A missed meal, not recoverable |
| Users churn, and are replaced | Users cannot leave; there is no second ration shop |
| Rollback in an afternoon | Rollback needs a policy decision and months |
| Failure shows up in the metrics | Failure shows up as an absence nobody logs |
| Claim made for a deployment | Question that tests it |
|---|---|
| “It cuts leakage” | How many genuine claimants were removed alongside the ghosts? |
| “It reaches the last mile” | Reaches, or requires the last mile to come to it? |
| “It gives people a voice” | Who reads what they say, and what happens next? |
| “It enables real-time monitoring” | Monitoring of the service, or of the people receiving it? |
| Paper system | Digital system |
|---|---|
| Many local rulesets; errors are local | One ruleset; errors replicate everywhere |
| Discretion allows a clerk to fix an edge case | Discretion is designed out, so edge cases fail hard |
| Failure is visible and local | Failure is distributed and invisible |
| Corruption is retail | Errors are wholesale — and so are fixes |
| As a deployer, you decide | As a user of others’ systems, you can |
|---|---|
| Which fields the survey app collects | Document the failures your participants hit |
| How long the beneficiary database is kept | Report exclusion upward with numbers, not anecdotes |
| Whether there is an offline route | Ask a vendor the questions in Section 11 |
| Who can export the data, and to where | Refuse to require an ID the programme does not need |
| Question | A bad answer sounds like |
|---|---|
| Who benefits, who bears the risk? | “Everyone benefits” |
| Who does the design exclude? | “Coverage is 98 per cent” |
| What data, and could it be turned on people? | “It is all anonymised” |
| Who decides, and can it be contested? | “The system decides objectively” |
| What if it breaks? | “It has 99.9 per cent uptime” |
| Section | What you will be able to do |
|---|---|
| 2 · Privacy | Apply the proportionality test; know your DPDP obligations |
| 3–4 · Bias and AI | Ask for disaggregated error rates; match oversight to stakes |
| 5–6 · Identity and surveillance | Insist on a manual fallback; spot function creep early |
| 7–8 · Divide and platforms | Design for the unconnected; avoid rented-rails dependence |
| 9–11 · Harms and governance | Run a procurement conversation and an ethics checklist |
| Field | Alone | Combined with two others |
|---|---|---|
| Village | Thousands of people | Frequently one household, and sometimes one person |
| Age and gender | Broad categories | |
| Caste and occupation | Common in the district |
| “Nothing to hide” assumes | Which fails when |
|---|---|
| The watcher is benign | Governments and employers change |
| The rules stay as they are | Data outlives the law that permitted it |
| Information is read in context | A clinic visit becomes a note in a file elsewhere |
| Everyone faces the same scrutiny | The poor are watched far more, for far less |
| What Puttaswamy settled | What it left open |
|---|---|
| Privacy is a fundamental right under Article 21 | How the proportionality test applies case by case |
| It is not absolute; intrusion must be justified | Who decides whether a justification is adequate |
| It covers informational privacy, not only bodily | What remedy an excluded person actually has |
| Nine judges, unanimous | Later benches have applied it with varying strictness |
| Step | Where programmes usually fail it |
|---|---|
| Legality | Collection authorised by a circular rather than a law |
| Legitimate aim | The aim is real, but stated so broadly it justifies anything |
| Necessity | A less intrusive option existed and was never assessed |
| Proportionality | The benefit is measured; the harm to the excluded is not |
| Consent theatre | What would make it real |
|---|---|
| A thumbprint on an unexplained form | An explanation in the person’s language, before the form |
| “Agree to continue” with no alternative | A route to the service for someone who declines |
| Consent to “partners and affiliates” | Named purposes, with a stated retention period |
| Withdrawal that requires a district office visit | Withdrawal by the same channel as consent |
| Collected for | Later used for |
|---|---|
| Immunisation follow-up | Locating families for an unrelated enforcement drive |
| A livelihoods survey | Targeting lists shared with a funder or a vendor |
| Attendance monitoring | Evidence in a disciplinary or eligibility decision |
| Grievance records | Identifying complainants to the people complained about |
| Obligation | What a small NGO actually has to do |
|---|---|
| Lawful purpose and notice | Write down why each field is collected, in plain language |
| Consent or legitimate use | Know which basis you are relying on, per dataset |
| Access, correction, erasure | Have a named person who can act on a request |
| Breach notification | Know who you would tell, and within what time |
| Children’s data | Stricter treatment; verify before collecting from minors |
| Technique | What it protects against |
|---|---|
| Drop direct identifiers | Casual lookup only — the weakest step |
| Coarsen quasi-identifiers (age bands, district not village) | Combination attacks, which are the real risk |
| Aggregate before release | Individual re-identification, at the cost of detail |
| Restrict access rather than publish | Everything — and it is the most-skipped option |
| Human choice | Where it enters |
|---|---|
| What to predict | “Risk of default” or “need for credit” are different models of the same people |
| What data to use | Whatever was already recorded, which is whatever was already served |
| What counts as success | Overall accuracy, or the error rate for the worst-served group |
| Where to set the threshold | A pure value judgement, usually made by whoever ships it |
| Where bias shows up in our sector | Form it takes |
|---|---|
| Credit and microfinance scoring | Thin-file applicants scored as risky for having been excluded |
| Beneficiary targeting models | Households missed by past surveys stay missing |
| Speech and language tools | Accuracy falls sharply outside dominant languages and accents |
| Facial recognition | Higher error rates for darker skin and for women, repeatedly measured |
| Fraud detection | Flags correlate with poverty markers, so the poor are investigated more |
| Gap in the data | What the model concludes |
|---|---|
| Fewer loans recorded to women | Women are a weaker lending prospect |
| Remote villages surveyed less often | Those villages have less need |
| Disability rarely recorded at all | Disability is not a relevant feature |
| Complaints logged only where offices exist | Service is satisfactory where there are no offices |
| Removed field | What still carries it |
|---|---|
| Caste | Surname, pincode, occupation, school attended |
| Religion | Name, locality, dietary fields, festival-linked activity |
| Gender | Name, occupation, phone-ownership patterns, time of use |
| Disability | Claim history, service-usage patterns, employment gaps |
| Definition | What it equalises | What it gives up |
|---|---|---|
| Equal selection rate | Same share chosen from each group | May select less-qualified from one group |
| Equal error rates | Same chance of being wrongly rejected | Selection rates will differ |
| Equal precision | A positive means the same thing for everyone | Conflicts with equal error rates |
| Audit step | What to ask for |
|---|---|
| Disaggregate performance | Error rates by gender, caste, region, language — not overall accuracy |
| Test for proxies | Can a removed trait be predicted from the remaining fields? |
| Document the training data | Who is in it, who is missing, and over what period |
| Re-audit on a schedule | Populations drift; a model correct in 2024 is not therefore correct now |
| Record the decisions | Which fairness definition, which threshold, and who signed it off |
| Question to settle before a pilot | Why it decides everything after |
|---|---|
| Is the model advising or deciding? | Sets the entire oversight requirement |
| Who is accountable when it is wrong? | If the answer is “the system”, nobody is |
| Was it evaluated on our population? | Performance elsewhere transfers poorly, especially across languages |
| What is the fallback when it is unavailable? | Uptime failures land on the same people as model failures |
| What “explainable” has to mean | Test |
|---|---|
| To the affected person, not the engineer | Could a field officer say it aloud in the person’s language? |
| Specific to this decision | Not “the model considers many factors” |
| Actionable | Does it tell them what would change the outcome? |
| Available before the appeal deadline | An explanation that arrives late is not a remedy |
| Error type | Who notices | What follows |
|---|---|---|
| False positive — wrongly included | Auditors, quickly | Tightening, and press coverage about leakage |
| False negative — wrongly excluded | Only the person excluded | Usually nothing; they stop coming |
| Where fluency is most dangerous | Because |
|---|---|
| Health and medication advice | A confident wrong dose is acted on |
| Legal entitlement and rights | Invented sections and deadlines are unverifiable by the user |
| Scheme eligibility | A plausible answer stops someone applying |
| Translation into a low-resource language | Nobody in the room can check it |
| Use | Stakes | Guardrail |
|---|---|---|
| Draft a report summary | Low | Human edits before sending |
| Translate a notice | Medium | Native speaker verifies |
| Screen a medical scan | High | Clinician confirms every case |
| Decide benefit eligibility | Very high | Human decides; appeal route open |
| What to check at each level of stakes |
|---|
| Low — is a human reading it before it leaves? |
| Medium — is the reviewer competent in the language and the subject? |
| High — does every case get human confirmation, and is that logged? |
| Very high — does a person decide, and can the affected person reach a human who can reverse it? |
| Question | What an inadequate answer looks like |
|---|---|
| Harm if confidently wrong? | “It is only a suggestion” — check whether anyone overrides it |
| Can we explain a decision? | “It uses many signals” |
| Tested on people like ours? | Benchmarks from another country, in another language |
| Human fallback and appeal? | A helpline number that rings in a city office |
| Who is accountable? | “The vendor”, with no clause saying so |
| What Aadhaar is | What it is often assumed to be |
|---|---|
| A number linked to biometrics, proving one person = one number | Proof of citizenship — it is not |
| An authentication service others can query | A database of everything about you — it holds a limited set |
| Statutorily backed, with a designated authority | Unregulated — there is a legal framework, contested but real |
| Voluntary in law, near-universal in practice | Formally compulsory — the pressure is practical, not statutory |
| Who gains most | Why |
|---|---|
| People with no documents at all | Migrants, the landless and many women held nothing in their own name |
| Women opening an account independently | An identity not mediated through a husband or father |
| Inter-state migrants | Portability matters most to people who move |
| Anyone previously invisible to the state | Being countable is a precondition for being served |
| Failure | Who it hits hardest |
|---|---|
| Worn or damaged fingerprints | Manual labourers, older people — precisely the entitled |
| No connectivity at the point of sale | Remote villages, which are also the poorest |
| Server or service downtime | Everyone in that district, on that day |
| Demographic mismatch in records | People whose names are transliterated inconsistently |
| No linked mobile for the OTP fallback | Women, who own phones at markedly lower rates |
| Dimension | Benefit | Harm |
|---|---|---|
| Identity | The undocumented become visible | Errors make the visible disappear |
| Delivery | Faster transfers, fewer ghosts | Failed auth blocks real beneficiaries |
| Mandate | One ID, many services | Function creep, no real opt-out |
| Bodies | Biometrics are hard to forge | Worn fingerprints exclude labourers |
| A fallback that works | A fallback that does not |
|---|---|
| The dealer can issue today, and reconcile later | “Come back tomorrow” |
| Exception register the dealer is expected to use | An exception route that counts against the dealer |
| Logged and monitored centrally | Undocumented discretion, which invites abuse |
| Known to the claimant before they arrive | Known only to officials |
| “Voluntary” system | What happens if you decline |
|---|---|
| ID for a subsidised ration | No ration |
| ID for a school scholarship | No scholarship |
| ID for a SIM card | No phone, and so no OTP for anything else |
| Biometric attendance for a wage | No wage that day |
| Metric that flatters | Metric that tests |
|---|---|
| Enrolment coverage | Authentication success rate, by district and by age |
| Transactions completed | Transactions attempted and failed |
| Savings from removed duplicates | Genuine claimants removed alongside them |
| Average uptime | Outage hours in the lowest-connectivity blocks |
| Built to deliver | Also produces |
|---|---|
| Ration transactions | A record of where a person was, and when, weekly |
| Attendance systems | Movement and association patterns |
| Health programme registers | Conditions, pregnancies, treatment histories |
| Grievance portals | A list of who complained, about whom |
| Guard against creep | How |
|---|---|
| Bind the purpose in writing | State it at collection, and require a new basis for any new use |
| Set a deletion date | At collection, not later — retention only ever gets extended |
| Separate the identifier | Hold service data and identity data apart, joinable only under a rule |
| Log every access | Who read this record, when, and why |
| To receive a subsidy, a poor household provides | To access their own savings, a wealthy person provides |
|---|---|
| Biometrics, at every transaction | A card, usually once |
| Household composition and income declarations | Nothing recurring |
| Location, weekly, by collection point | Not recorded as a condition |
| Justification for any change in circumstances | None required |
| Condition | Who fails it, and why |
|---|---|
| Minimum attendance, biometrically verified | Sick, caring for someone, or without transport that week |
| Bank account linkage | People without documents, or with an account in another name |
| Repeated re-verification | Migrants, who are not present when the check runs |
| Digital grievance filing | The non-literate and the unconnected — the likeliest to have a grievance |
| What people avoid when they suspect a record | Consequence |
|---|---|
| A clinic visit for a stigmatised condition | Untreated illness; onward transmission |
| A meeting of a union or a rights group | Weaker collective action, which is often the point |
| Filing a complaint against an official | Abuse continues, and appears to be absent |
| Seeking help after violence | The gravest, and the least visible in any dataset |
| They can | You cannot |
|---|---|
| Link your records across agencies | See what has been linked |
| Act on an inference about you | Learn what the inference was |
| Change the rules retrospectively | Withdraw data already given |
| Decline to explain a decision | Contest a reason you were never told |
| Where consent is weakest | Because |
|---|---|
| Welfare enrolment | Refusal means losing the entitlement |
| Employment conditions | Refusal means losing the job |
| NGO programme participation | Refusal is read as ingratitude, or as disqualification |
| Research participation | The researcher is often also the service provider |
| Safeguard | What makes it real rather than stated |
|---|---|
| Purpose-binding and deletion | A date in the system, not a sentence in a policy |
| Separating delivery from policing | Different databases, different access, no shared key |
| Minimising linkage | Joins require an approval that is logged and refusable |
| Independent oversight | Power to compel disclosure and to stop processing |
| A complaint route | One a person without a smartphone can actually use |
| Level | What it takes to clear |
|---|---|
| A device in the household | Money, once — and whose device it is matters |
| A device you control | Frequently fails for women and younger family members |
| Affordable data and charging | Recurring cost, and reliable electricity |
| Skills and language | Literacy, and an interface in a language you read |
| Meaningful use | Something on the device that improves your life |
| Axis | What it excludes in a typical service |
|---|---|
| Income | Recurring data cost, which is the binding constraint more often than the device |
| Language | Interfaces in English or one dominant state language |
| Literacy | Text-heavy flows with no voice or icon path |
| Disability | Apps that break screen readers; no captions; low-contrast text |
| Age | Small targets, jargon, and no assisted-use mode |
| Level | Typical intervention | What it leaves unsolved |
|---|---|---|
| 1 Access | Distribute devices; build towers | Cost of use, skills, relevance |
| 2 Affordability | Subsidised data | Skills, language, relevance |
| 3 Skills | Digital literacy training | Whether anything useful is there |
| 4 Meaningful use | Services worth using, in the right language | Nothing — this is the point of the other three |
| Gone digital-only | Who is pushed out |
|---|---|
| Scheme applications | Anyone without a device, data or the literacy to use it |
| Grievance filing | The people with the most grievances |
| Appointment booking | Walk-in users, who were the majority |
| Payment and verification | Households where the phone belongs to someone else |
| What the intermediary makes possible | What it costs |
|---|---|
| Completing a transaction at all | Handing over the OTP, and so the account |
| Reading and filling the form | Disclosure of income, health, family details |
| Reaching a service that is far away | An informal fee, unregulated and unrecorded |
| Help for those with a trusted relative | Nothing for those without one |
| Design choice | Who it brings in |
|---|---|
| Voice and IVR alongside text | Non-readers, and anyone on a feature phone |
| Works on low-end devices and 2G | The poorest, and most rural users |
| Local languages, including script choice | Most of the country |
| Screen-reader compatibility and contrast | Users with disabilities, and everyone in sunlight |
| An assisted-use mode | The majority who need help, safely |
| Layer | What it controls |
|---|---|
| Operating system and app store | What can be installed, and what a developer must pay |
| Search and feed ranking | What is findable, and therefore what exists in practice |
| Cloud hosting | Whether your service runs at all tomorrow |
| Payments and identity | Who can transact, and on what terms |
| The analogy holds | Where it strains |
|---|---|
| Raw material extracted; value added elsewhere | Data is not depleted by being taken |
| Terms set by the extracting party | Users receive a real service in return |
| Infrastructure and expertise stay abroad | No territorial control or coercion in the historical sense |
| The producing region holds little of the upside | Some local firms capture value too |
| What makes the region attractive | What it means locally |
|---|---|
| Very large, fast-growing user base | Scale gives the platform leverage in any dispute |
| Rich behavioural and language data | Valuable for training models sold back into the region |
| Lighter or newer regulation | Practices tested here before markets with older law |
| Price-sensitive users | “Free” wins, and free is paid for in data |
| Dependency | What a change would do to your programme |
|---|---|
| A messaging app as the delivery channel | A policy change ends your outreach, without notice |
| A cloud provider holding beneficiary data | A pricing change or account action freezes operations |
| An ad platform for recruitment | A category ban removes your reach overnight |
| A proprietary data format | Migration costs exceed the value of moving |
| What data sovereignty can mean | Trade-off |
|---|---|
| Data localisation — stored in-country | Also makes it easier for the local state to reach |
| Public digital infrastructure | Reduces platform dependence; concentrates state power |
| Open-source and open standards | Portability, at the cost of engineering capacity to maintain it |
| Community control over community data | The strongest version, and the hardest to institutionalise |
| Practice | Effort |
|---|---|
| Export your data in an open format, on a schedule | A recurring job; set it once |
| Read the terms for what the platform takes from your users | An afternoon, once per platform |
| Prefer formats and standards you could move | A choice at procurement, free at that moment |
| Use public or community infrastructure for critical paths | Real work, and only where it is viable |
| Why the same message spreads further here |
|---|
| It arrives from a relative, so it carries their credibility rather than a source’s |
| There is no like-count, no label and no visible correction inside a closed group |
| Encryption hides the origin, so “who started this” has no answer |
| Fact-checking capacity is thinnest in the languages with the most users |
| Open platform | Closed group |
|---|---|
| Researchers can see what circulates | Nothing is observable from outside |
| Content can be labelled or down-ranked | There is nothing to label |
| A correction can reach the same audience | You cannot post into a group you are not in |
| Credibility comes from the source | Credibility comes from the sender |
| What turned a message into violence | What has helped |
|---|---|
| A rumour circulating faster than any check | Forward limits, which cut velocity without reading content |
| No authoritative account for hours or days | Police and administration publishing verified facts early |
| A stranger present in an unfamiliar place | Local volunteers who can say “this is not from here” |
| Recaptioned footage from elsewhere | Reverse image search, taught at community level |
| Scam | Why new users are the target |
|---|---|
| Fake KYC-update messages | Real KYC requests exist, so the pretext is plausible |
| Bogus scheme or lottery fees | Genuine schemes do transfer money unexpectedly |
| Loan apps with hidden charges | Formal credit is unavailable, so the offer is welcome |
| OTP requests from a “bank officer” | Assisted use has trained people to share OTPs |
| What makes moderation weak in a language | Consequence |
|---|---|
| Few trained human reviewers | Escalations sit unread, or are auto-closed |
| Little training data for classifiers | Automated detection performs poorly or not at all |
| Code-mixing and Roman script | Text falls outside whatever model exists |
| Local slurs and dog-whistles unmapped | The most dangerous content is the least detectable |
| Over-removal | Under-removal |
|---|---|
| Dissent and minority speech disappear first | Harmful content spreads unchecked |
| Automated systems misread satire and reclaimed slurs | Coordinated campaigns operate freely |
| Rules become a tool against critics | Targeted groups bear the cost |
| Appeal routes are slow or absent | Reports go unanswered |
| Response | Evidence and cost |
|---|---|
| Forward limits and friction | Reduces velocity measurably; needs no content decisions |
| Prebunking — teach the technique before the lie | Generalises to claims not yet invented; effects decay |
| Local fact-checking in the right language | Essential, and always second to the rumour |
| Trusted community messengers | The strongest single factor; slow to build, cheap to keep |
| Decision | Cost to change at design | Cost to change after launch |
|---|---|---|
| Which fields to collect | A conversation | Data already held; schema migration |
| Whether there is an offline route | A requirement line | New staffing, budget and policy |
| What the model optimises | A choice | Retraining, and a year of decisions to revisit |
| Whether decisions can be appealed | A workflow step | A new institution |
| Default that protects | Default that harms |
|---|---|
| Sharing off unless chosen | Sharing on with an opt-out buried in settings |
| Retention set at collection | Keep indefinitely, review never |
| Access limited to those who need it | Whole-team access because it is simpler |
| Optional fields genuinely optional | Required fields with no operational purpose |
| Principle | The question it forces |
|---|---|
| Design with the user | Did anyone affected see this before it was built? |
| Understand the existing ecosystem | What is already working that we are about to replace? |
| Design for scale and sustainability | Who runs this when the grant ends? |
| Be data-driven | What would tell us this is not working? |
| Address privacy and security | What is the worst use of this data, and by whom? |
| Be collaborative; use open standards | Could someone else take this over? |
| Ask | Concretely |
|---|---|
| Who could be harmed? | Name groups, not “users”: women, minorities, undocumented migrants |
| How could the data be misused? | By a future government, an employer, a family member, a hostile neighbour |
| What is the safeguard? | Something in the architecture, not the policy document |
| Is the residual risk worth it? | A decision someone signs, on a date, in writing |
| Field routinely collected | Is it used? |
|---|---|
| Caste | Only if disaggregation is actually reported; otherwise a liability |
| Full date of birth | Age band is almost always sufficient |
| Precise GPS of a household | Village or block is usually enough, and far safer |
| Phone number of every member | One contact serves the purpose |
| Photograph | Rarely used after collection, and hard to secure |
| What participation surfaces | That outsiders miss |
|---|---|
| Who in the household controls the phone | Designs that assume personal device access |
| Which words the interface should use | Translations that are technically correct and unread |
| When people can actually attend or transact | Office hours that assume no wage work |
| What a failure costs them | Retry flows designed for people with time |
| Redress element | Test of whether it is real |
|---|---|
| A route to contest a decision | Usable by someone without a smartphone or literacy |
| A human who can override | They have the authority and are not penalised for using it |
| Plain-language notice | In the language spoken, at the moment data is taken |
| An exit | Correction and deletion actually happen, within a stated time |
| Layer | What it can do | What it cannot |
|---|---|---|
| Law | Set rights and obligations | Notice your specific form |
| Regulator | Investigate, penalise | Reach most small deployments |
| Organisation | Policy, review, training | Survive a change of leadership without structure |
| Practitioner | Decide what goes on the form | Fix a system designed elsewhere |
| What makes an authority effective | Warning sign |
|---|---|
| Independence in appointment and removal | Members serve at the pleasure of the executive |
| Adequate staff and technical capacity | A handful of officers for a national caseload |
| Power to compel and to penalise | Recommendations only |
| Broad remit | Wide exemptions for state processing |
| Right | What it looks like when exercised |
|---|---|
| Access | “Show me what you hold about me and who you shared it with” |
| Correction | “My name is spelled two ways; fix the record” |
| Erasure | “The programme ended; delete my data” |
| Grievance | “I was refused and nobody will tell me why” |
| Area | Ask before you deploy |
|---|---|
| Purpose | Is each data field truly necessary? |
| Consent | Is it free, informed, specific, revocable? |
| Inclusion | Who does this design exclude — and is there a fallback? |
| Bias | Have we tested outcomes across groups? |
| Security | Who can access this, and is it protected? |
| Redress | Can a person contest a decision and reach a human? |
| Ask the vendor | Put in the contract |
|---|---|
| Where is data stored, and who can access it? | Named jurisdictions; a list of sub-processors |
| Has it been tested for bias and accessibility? | Disaggregated performance, supplied annually |
| What happens to our data if we leave? | Export in an open format; deletion certified |
| What is the uptime and the fallback? | An agreed manual process during outages |
| Who is liable when it is wrong? | A clause, rather than an assurance in a meeting |
| If you do one thing | Where it is in this deck |
|---|---|
| Delete a field from your survey form | Sections 2 and 10 |
| Ask a vendor for disaggregated error rates | Sections 3 and 11 |
| Build a working manual fallback | Section 5 |
| Set a deletion date on an existing dataset | Sections 2 and 6 |
| Write down what happens to someone who says no | Sections 2 and 5 |
| Source | Read it for |
|---|---|
| Eubanks, Automating Inequality | How welfare systems automate exclusion — closest to Sections 5–6 |
| O’Neil, Weapons of Math Destruction | Feedback loops and opaque scoring, in plain language |
| D’Ignazio & Klein, Data Feminism | Power in data collection and classification |
| Couldry & Mejias, The Costs of Connection | The data-colonialism argument, from its authors |
| Principles for Digital Development | The sector framework, usable in a proposal |