N. Bharosa
Please Note
41 records found
1
Designing for Trust in Healthcare Data Sharing
Trust Anchors in the Trust Framework Lifecycle
Trust is a crucial factor in multi-actor data-sharing initiatives, particularly in sensitive domains like healthcare, where patient privacy, regulatory requirements, and organizational collaboration intersect. However, achieving trust-by-design, creating trust through intentional design choices, is challenging. To address this challenge, this paper investigates how trust frameworks in healthcare data-sharing are designed and how they evolve over time. Central to this inquiry is the conceptualization of “trust anchors”– designable components that provide a foundation for creating trust. Drawing on Technological Innovative Systems theory, this research qualitatively examines two healthcare trust frameworks, each at different lifecycle stages. The case studies reveal how trust anchors contribute to both the development and active management of trust frameworks. The contribution includes a lifecycle approach for trust frameworks and a matrix for categorizing trust anchors, providing guidance for organizations aiming to implement and maintain multi-actor data-sharing frameworks. We find that enforceable trust anchors are more important in the mature phase of a trust frameworks, while in the growing phase, less designable and enforceable trust factors assume a greater role.
From Trust Antecedents to Trust Frameworks
Co-Creating Multi-Actor Agreements for Data Sharing
Central government policy departments need to collaborate with executive agencies to provide IT-based services to society. These collaborations are complicated by the fact that the executive agencies are controlled by different ministerial hierarchies, resulting in conflicting interests. Yet, a detailed analysis of these challenges is lacking in the literature. In this paper, we analyze the challenges at several ministries through interviews focused on specific cases as well as interviews focused on expert knowledge. We identified the challenge themes and compared them with the literature, finding several new challenges in practice, including restricted procurement, a Goldilocks zone for escalation, the inability to hold an agent ultimately accountable, and the low priority the central government policy departments give to the implementation. Paradoxically, central government policy departments, as principals, are less powerful and highly dependent on executive agencies instead of the other way around, as suggested by principal-agent theory. These findings imply that there is a need for new governance mechanisms able to deal with all the challenges encountered. The overview of the challenges can serve as a sound foundation for conducting further research into cross-ministerial governance.
The wallet demarcation problem
Developing a taxonomy for classifying digital wallets
Artificial intelligence (AI) adoption by public sector organizations (PSOs) introduces various ethical risks stemming from a lack of integrating human values into AI design. Addressing these ethical risks is a complex collective responsibility among designers, developers, risk experts, and public sector managers. Embedding these risks in existing risk management practices is crucial for responsible AI adoption, as emphasized by the legal requirements of the EU AI Act. However, the responsibility for managing these ethical risks is often unclear. Public sector organizations face unique challenges due to the complex, uncertain, and rapidly evolving nature of AI technologies, further complicating the management of ethical risks. This paper explores using the Three Lines of Defense (TLoD) risk management model to understand and address these ethical risks in public sector AI adoption. The TLoD model structures risk management across three lines: operational management, risk oversight and compliance, and internal audit. This framework helps to distribute and integrate the collective responsibility for ethical AI risk management within public sector organizations, emphasizing alignment and collaboration among different actors. Through an exploratory study involving a survey and semi-structured interviews with professionals responsible for AI-related risk management in Dutch public sector organizations, we assess the TLoD model’s usefulness in addressing ethical AI risks. The study examines the challenges and opportunities in applying the TLoD model to manage ethical risks and identifies the potential gaps in responsibility and oversight. The findings suggest that while the TLoD model offers a valuable lens for distributing risk management responsibilities, there are limitations in addressing the emergent and complex nature of ethical risks in AI adoption.
Realizing quantum-safe information sharing
Implementation and adoption challenges and policy recommendations for quantum-safe transitions
By utilizing the properties of quantum mechanics, quantum computers have the potential to factor a key pair of a large prime number and break some of the core cryptographic primitives that most information infrastructures depend on. This means that today's widely used cryptographic algorithms can soon become unsafe and need to be modified with quantum-safe (QS) cryptography. While much work is still needed in developing QS cryptographic algorithms, the institutional, organizational, and policy aspects of transitioning the current infrastructures have received less attention. This paper provides an empirical analysis of QS transition challenges and policy recommendations for moving to a QS situation. We analyzed the data collected through interviews with experts and practitioners from the Dutch government. The results reveal that institutional, organizational and policy aspects of QS transitions are interconnected, and solutions for QS transitions are scattered. Consequently, organizations may face a Catch-22 loop without further actionable approaches and planning for QS transitions.
Understanding Trust Frameworks
Goals and Components Identified Through a Case Study
Digital Infrastructures for Compliance Monitoring of Circular Economy
Requirements for Interoperable Data Spaces
How does the EU Digital Identity Wallet change the risk of over-sharing data?
A Dutch perspective
The European Union (EU) Digital Identity Wallet (DIW) intends to give citizens control over personal data sharing. The DIW users will have full and sole control over their data. The EU intends to address the risk to citizens' privacy in cases where data from and about users is gathered and exchanged by online service providers. However, it is unclear how users of the EU DIW can decide what data to share and how to prevent sharing too much data with online service providers. In order to reduce this risk, we need to understand it first. Drawing on expert interviews, this paper presents a novel analysis of the risk of over sharing through the EU DIW. It defines the risk and what aspects influence the risk from literature, documentation and expert interviews. Over-sharing data occurs when users share more data than strictly required for the service or product acquired online and multiple aspects influence this risk, specifically the user capabilities and orientation, the loss of context awareness, the quality of the data and the ease of sharing.
Ensuring the secure provision of data and services using critical information infrastructures amidst the evolving technology landscape is a crucial yet recurrent task. However, these infrastructures can become vulnerable due to developments in quantum computing and modifying the infrastructures with quantum-safe (QS) technology is unlike regular control and maintenance. Organizations need to modify their cryptographic layers, which act as the fundamental building blocks of infrastructures. For organizations, many uncertainties pose challenges across technological, organizational and ecosystem areas. While QS technology is new and not yet available for implementation and adoption, changes in critical information infrastructures require collaboration among multiple public and private organizations spanning industries and borders. By understanding the roles, organizations may better understand what should be done for QS transitions. Until now, there has been no academic research examining the roles that government could or should play in QS transitions. This paper reveals 12 different roles, showing the diversity and breadth of actions needed. While there are many possible roles that still need to be allocated for coordinated efforts, there is a high reliance on the government, and organizations are waiting for and expecting governments to take more active roles in QS transitions. The results also signals that QS transition research is at its early stage with a clear governance void and lack of collective urgency in the ecosystem.
Governments struggle to harness emerging technologies to improve public services, address social needs, and produce public value. In response, we see a rise in GovTech startups and other non-government actors trying to bring innovative solutions to governments. While some public agencies welcome such help, many are reluctant to rely on external organizations to provide digital identities, data wallets and AI-based services to citizens, businesses, and the government itself. Many also fear engaging a dynamic ecosystem of small non-government actors working together and gaining more experience in the process. Consequently, the GovTech supply and demand are misaligned with each other and the public value imperative. Public tendering may help but does not protect against vendor lock-in and innovation-blocking. Co-creation of public and private solutions may be technically possible but may face institutional void, calling for trust frameworks, steward-ownership, ecosystem building or other alternative instruments. This paper presents a research challenge to examine GovTech evidence, learn about applicable theories, methods and knowledge gaps, and formulate theoretically and empirically well-grounded recommendations on GovTech and public value creation. It also outlines the response to the challenge: organizing a dg.o 2024 workshop and developing a special issue of Government Information Quarterly (GIQ).
Success Factors and Barriers of GovTech Ecosystems
A case study of GovTech ecosystems in the Netherlands and Lithuania
Policy guidelines to facilitate collective action towards quantum-safety
Recommended policy guidelines to aid and facilitate collective action in migration towards quantum-safe public key infrastructure systems
Management of National eID Infrastructure as a State-Critical Asset and Public-private Partnership
Learning from the Case of Estonia
PPPS'2023 - Proactive and Personalised Public Services
Searching for Meaningful Human Control in Algorithmic Government