G.A. de Reuver
Please Note
24 records found
1
Human Connection as the Design Goal
A Value-Sensitive Design Approach to Reputation and Recognition in Multi-Community Collaborative Platforms
The research question is: What design principles are needed to support value-aligned reputation and recognition mechanisms in multi-community collaborative platforms?
This thesis was conducted in collaboration with Alkemio, an EU-built platform for multi-stakeholder collaboration, using Value Sensitive Design as the research approach. The conceptual investigation drew on a structured literature review, the empirical investigation consisted of nine semi-structured interviews with three stakeholder groups and a focus group, and the technical investigation translated the findings into design requirements through value hierarchy specification.
The conceptual investigation established that reputation and recognition are deeply intertwined in practice, and that a purely ethical VSD value inventory is insufficient for motivational systems. Supplementing VSD with Self-Determination Theory produced a preliminary value inventory of thirteen values. The empirical investigation confirmed ten of those values, added respect as an empirically grounded addition, and removed benevolence, integrity, and reciprocity, producing a final inventory of eleven values: accountability, authenticity, autonomy, competence, fairness, inclusivity, privacy, relatedness, respect, transparency, and trust. Three consistent findings emerged across all stakeholder groups: personal connection and relational trust consistently outweighed formal reputation signals, automated recognition and quantitative metrics were broadly experienced as hollow and demotivating, and privacy and autonomy were the dominant values with contributors drawing a clear line between a platform that supports collaboration and one that controls it.
The technical investigation translated all eleven values into 28 consolidated design requirements through value hierarchy specification. Value conflict analysis revealed that all conflicts clustered around the privacy requirement that no profile fields are mandatory and display is always contributor-controlled.
Five design principles emerged from combining these results. The first is that the platform makes the collaboration network visible, enabling trust through trusted third parties. The second is peer recognition over platform automation, prescribing that recognition must come from people rather than platforms. The third is visibility as the default with privacy as the choice. The fourth is that the platform enables but the human chooses, keeping mechanisms non-prescriptive and non-competitive. The fifth is that respect matters but design possibilities are limited.
These principles point to one overarching conclusion: human connection is the design goal, and simultaneously the element that platform design is most limited in achieving. A platform can create the conditions that make human connection more likely, but it cannot produce it. For public interest platforms, this establishes not only what design principles are needed but also where design reaches its limit ...
The research question is: What design principles are needed to support value-aligned reputation and recognition mechanisms in multi-community collaborative platforms?
This thesis was conducted in collaboration with Alkemio, an EU-built platform for multi-stakeholder collaboration, using Value Sensitive Design as the research approach. The conceptual investigation drew on a structured literature review, the empirical investigation consisted of nine semi-structured interviews with three stakeholder groups and a focus group, and the technical investigation translated the findings into design requirements through value hierarchy specification.
The conceptual investigation established that reputation and recognition are deeply intertwined in practice, and that a purely ethical VSD value inventory is insufficient for motivational systems. Supplementing VSD with Self-Determination Theory produced a preliminary value inventory of thirteen values. The empirical investigation confirmed ten of those values, added respect as an empirically grounded addition, and removed benevolence, integrity, and reciprocity, producing a final inventory of eleven values: accountability, authenticity, autonomy, competence, fairness, inclusivity, privacy, relatedness, respect, transparency, and trust. Three consistent findings emerged across all stakeholder groups: personal connection and relational trust consistently outweighed formal reputation signals, automated recognition and quantitative metrics were broadly experienced as hollow and demotivating, and privacy and autonomy were the dominant values with contributors drawing a clear line between a platform that supports collaboration and one that controls it.
The technical investigation translated all eleven values into 28 consolidated design requirements through value hierarchy specification. Value conflict analysis revealed that all conflicts clustered around the privacy requirement that no profile fields are mandatory and display is always contributor-controlled.
Five design principles emerged from combining these results. The first is that the platform makes the collaboration network visible, enabling trust through trusted third parties. The second is peer recognition over platform automation, prescribing that recognition must come from people rather than platforms. The third is visibility as the default with privacy as the choice. The fourth is that the platform enables but the human chooses, keeping mechanisms non-prescriptive and non-competitive. The fifth is that respect matters but design possibilities are limited.
These principles point to one overarching conclusion: human connection is the design goal, and simultaneously the element that platform design is most limited in achieving. A platform can create the conditions that make human connection more likely, but it cannot produce it. For public interest platforms, this establishes not only what design principles are needed but also where design reaches its limit
Privacy Threats in MCP and A2A: Agentic AI Communication Protocols
A LINDDUN-Based Privacy Threat Analysis of MCP and A2A in a Financial Fraud Detection Context
The Model Context Protocol (MCP) and the Agent-to-Agent (A2A) protocol have quickly become the de facto standards for connecting large-language-model agents to external tools and to one another across organisational boundaries. Their security has begun to receive attention, but their privacy implications, what personal data flows where and under what controls, remain largely unexamined, even as the protocols are adopted in sensitive domains where the people whose data is processed are not parties to the exchange.
This thesis presents a data-subject-centred privacy threat analysis of MCP and A2A using the LINDDUN methodology, applied to a representative financial fraud-detection use case modelled as a multi-agent system. A data-flow model is elicited, threats are systematically derived across the LINDDUN categories, and the findings are validated through interviews with seven domain experts and discussed with a co-author of the LINDDUN framework.
The analysis identifies eight privacy threats across five LINDDUN categories. The most severe arise not from misconfiguration or attack but because the protocols operate as designed: a persistent session identifier enables linkability and cross-store aggregation, unconstrained context-passing exposes identifiable data across organisational boundaries, and the bilateral task record creates a non-repudiable trace. The threats range from protocol-inherent to use-case-inherent, and three form a cross-protocol chain in which exposure compounds as data crosses the boundary between the two protocols; the trust boundary, more than the protocol choice, amplifies severity.
This is the first privacy analysis of MCP and A2A framed from the data subject's perspective. It shows that privacy here is non-compositional, so per-flow assessments miss risks that emerge only when flows combine. Because the decisive design choices are fixed at the protocol layer, the thesis argues that effective privacy governance must engage protocol designers and standards bodies, not deploying organisations alone. ...
The Model Context Protocol (MCP) and the Agent-to-Agent (A2A) protocol have quickly become the de facto standards for connecting large-language-model agents to external tools and to one another across organisational boundaries. Their security has begun to receive attention, but their privacy implications, what personal data flows where and under what controls, remain largely unexamined, even as the protocols are adopted in sensitive domains where the people whose data is processed are not parties to the exchange.
This thesis presents a data-subject-centred privacy threat analysis of MCP and A2A using the LINDDUN methodology, applied to a representative financial fraud-detection use case modelled as a multi-agent system. A data-flow model is elicited, threats are systematically derived across the LINDDUN categories, and the findings are validated through interviews with seven domain experts and discussed with a co-author of the LINDDUN framework.
The analysis identifies eight privacy threats across five LINDDUN categories. The most severe arise not from misconfiguration or attack but because the protocols operate as designed: a persistent session identifier enables linkability and cross-store aggregation, unconstrained context-passing exposes identifiable data across organisational boundaries, and the bilateral task record creates a non-repudiable trace. The threats range from protocol-inherent to use-case-inherent, and three form a cross-protocol chain in which exposure compounds as data crosses the boundary between the two protocols; the trust boundary, more than the protocol choice, amplifies severity.
This is the first privacy analysis of MCP and A2A framed from the data subject's perspective. It shows that privacy here is non-compositional, so per-flow assessments miss risks that emerge only when flows combine. Because the decisive design choices are fixed at the protocol layer, the thesis argues that effective privacy governance must engage protocol designers and standards bodies, not deploying organisations alone.
The study adopts a hierarchical conceptual approach, integrating Teece’s (2010) value creation, delivery, and capture mechanisms with Osterwalder and Pigneur’s (2010) Business Model Canvas components. A literature review was conducted to establish working definitions and extract key dimensions. Following Nickerson et al.’s (2013) iterative taxonomy development method, 24 MLaaS platform cases were analysed in conceptual-to-empirical and empirical-to-conceptual cycles. The completed taxonomy was evaluated using Szopinski et al.’s (2020) structural validity criteria and Miles and Huberman’s (1994) practical usability guidelines. The resulting business model taxonomy systematically captures MLaaS platform business models across value creation, delivery, and capture mechanisms, revealing distinct configurations shaped by cloud infrastructure dependencies and machine learning workflow orchestration. Four archetypes (cloud orchestrator, data orchestrator, aggregator, and niche specialist) emerged, with each archetype reflecting specific priorities in scalability and specialisation.
This research presents the first classification framework for analysing the business models of MLaaS platforms, addressing a significant gap in existing literature. By identifying and distinguishing key dimensions and archetypes, this research extends platform theory to reflect the variety of business models beyond those of large technology firms, and it challenges existing views that see Big Tech dominance as inevitable. Alongside its theoretical contribution, the taxonomy provides practical value. For startups and new market entrants, it offers a structured approach to determine their strategic position before developing their business model. For established MLaaS platforms, it serves as a tool for benchmarking, supporting decisions on innovating current models or transitioning to others in line with market changes and technological developments. ...
The study adopts a hierarchical conceptual approach, integrating Teece’s (2010) value creation, delivery, and capture mechanisms with Osterwalder and Pigneur’s (2010) Business Model Canvas components. A literature review was conducted to establish working definitions and extract key dimensions. Following Nickerson et al.’s (2013) iterative taxonomy development method, 24 MLaaS platform cases were analysed in conceptual-to-empirical and empirical-to-conceptual cycles. The completed taxonomy was evaluated using Szopinski et al.’s (2020) structural validity criteria and Miles and Huberman’s (1994) practical usability guidelines. The resulting business model taxonomy systematically captures MLaaS platform business models across value creation, delivery, and capture mechanisms, revealing distinct configurations shaped by cloud infrastructure dependencies and machine learning workflow orchestration. Four archetypes (cloud orchestrator, data orchestrator, aggregator, and niche specialist) emerged, with each archetype reflecting specific priorities in scalability and specialisation.
This research presents the first classification framework for analysing the business models of MLaaS platforms, addressing a significant gap in existing literature. By identifying and distinguishing key dimensions and archetypes, this research extends platform theory to reflect the variety of business models beyond those of large technology firms, and it challenges existing views that see Big Tech dominance as inevitable. Alongside its theoretical contribution, the taxonomy provides practical value. For startups and new market entrants, it offers a structured approach to determine their strategic position before developing their business model. For established MLaaS platforms, it serves as a tool for benchmarking, supporting decisions on innovating current models or transitioning to others in line with market changes and technological developments.
Designing Incentive Controls for Federated Learning in Aviation
Implemented on-chain
Architectural Framework for Federated Learning in Aviation Maintenance
Designing and Analyzing Key Features for Data Sharing Acceptance with ArchiMate Modeling
Current Status The aviation industry is transitioning from traditional maintenance practices, typically scheduled after a specified number of flight hours, to more advanced, data-driven approaches. These predictive maintenance techniques leverage machine learning models to enhance the accuracy of assessments. These models can reduce the frequency of unscheduled maintenance and optimize inventory management. However, such models rely heavily on large datasets, which are challenging to compile in the aviation sector due to the rarity of specific operational incidents and the diverse types of data collected by different companies. When collaborating, a tradeoff arises between the level of security measures, trust in partners, and ensuring the system still functions. Federated Learning emerges as a promising solution to these challenges. Federated Learning is a novel form of machine learning that allows multiple entities to collaboratively develop a shared model while keeping their data localized, thus maintaining privacy and data sovereignty. Question The primary objective of this research is to identify and validate the critical architectural features necessary for the acceptance of Federated Learning in the aviation maintenance industry. Architectural features refer to design choices such as security protocols and governance frameworks. By focusing on these aspects, this study addresses the technical and collaborative challenges that must be overcome to develop a Federated Learning system for predictive maintenance in aviation. Resulting in the following research question:
‘What architectural features should be included in the design of the ‘Federated Learning for aircrafts’ predictive maintenance system’ to be accepted by the stakeholders in the aviation industry?’ Approach This study employs a Design Science Research methodology. The sub-questions for this research follow the steps in the Design Science Research methodology. This is not the case for the demonstration phase which was deemed not possible due to the conceptual nature of the design.
1.
What are the challenges in sharing maintenance data, and how do they impact data safety and collaboration? Through a literature review and interviews with stakeholders, the study identified concerns about data privacy, security, and competition. These challenges significantly limit data-sharing initiatives. (Problem Identification and Motivation)
2.
What specific technical requirements should the Federated Learning system have to address these challenges? Based on the interviews and thematic analysis, a list of requirements was developed. These include robust privacy mechanisms, transparent governance, ensuring model explainability, and clear accountability mechanisms. (Defining the Objectives for a Solution)
3.
What architectural features should be included in the Federated Learning design to meet these requirements? ArchiMate modeling was used to design a system incorporating these requirements. Federated Learning, combined with encryption techniques and a consortium-managed system, was the result. (Design and Development)
4.
How do stakeholders perceive the acceptability of the designed system? After the validation interviews and the expert session, three changes were implemented: Switching from
5
differentiating on the model version to differentiating on the usages. Improving explainability
by switching to Trusted Executive Environments and removing differential privacy. Traditional contracts to increase trust towards each other were also added. (Evaluation)
5.
What lessons can be learned from the development and evaluation of the Federated Learning system for future improvements? The research highlights the importance of continuously building trust among stakeholders. Furthermore, the token-based reward system based on contribution is a good incentive to be adaptable and develop long-term collaboration. (Communication) Results
To build trust, this study employs traditional methods like legal contracts and appoints a consortium as a neutral party. Transparent governance and involving a neutral, trusted entity is necessary to gain stakeholder acceptance and ensure long-term collaboration. Blockchain technology enhances the transparency of the consortium's operations, ensuring all transactions and data exchanges are recorded on an immutable database... ...
Current Status The aviation industry is transitioning from traditional maintenance practices, typically scheduled after a specified number of flight hours, to more advanced, data-driven approaches. These predictive maintenance techniques leverage machine learning models to enhance the accuracy of assessments. These models can reduce the frequency of unscheduled maintenance and optimize inventory management. However, such models rely heavily on large datasets, which are challenging to compile in the aviation sector due to the rarity of specific operational incidents and the diverse types of data collected by different companies. When collaborating, a tradeoff arises between the level of security measures, trust in partners, and ensuring the system still functions. Federated Learning emerges as a promising solution to these challenges. Federated Learning is a novel form of machine learning that allows multiple entities to collaboratively develop a shared model while keeping their data localized, thus maintaining privacy and data sovereignty. Question The primary objective of this research is to identify and validate the critical architectural features necessary for the acceptance of Federated Learning in the aviation maintenance industry. Architectural features refer to design choices such as security protocols and governance frameworks. By focusing on these aspects, this study addresses the technical and collaborative challenges that must be overcome to develop a Federated Learning system for predictive maintenance in aviation. Resulting in the following research question:
‘What architectural features should be included in the design of the ‘Federated Learning for aircrafts’ predictive maintenance system’ to be accepted by the stakeholders in the aviation industry?’ Approach This study employs a Design Science Research methodology. The sub-questions for this research follow the steps in the Design Science Research methodology. This is not the case for the demonstration phase which was deemed not possible due to the conceptual nature of the design.
1.
What are the challenges in sharing maintenance data, and how do they impact data safety and collaboration? Through a literature review and interviews with stakeholders, the study identified concerns about data privacy, security, and competition. These challenges significantly limit data-sharing initiatives. (Problem Identification and Motivation)
2.
What specific technical requirements should the Federated Learning system have to address these challenges? Based on the interviews and thematic analysis, a list of requirements was developed. These include robust privacy mechanisms, transparent governance, ensuring model explainability, and clear accountability mechanisms. (Defining the Objectives for a Solution)
3.
What architectural features should be included in the Federated Learning design to meet these requirements? ArchiMate modeling was used to design a system incorporating these requirements. Federated Learning, combined with encryption techniques and a consortium-managed system, was the result. (Design and Development)
4.
How do stakeholders perceive the acceptability of the designed system? After the validation interviews and the expert session, three changes were implemented: Switching from
5
differentiating on the model version to differentiating on the usages. Improving explainability
by switching to Trusted Executive Environments and removing differential privacy. Traditional contracts to increase trust towards each other were also added. (Evaluation)
5.
What lessons can be learned from the development and evaluation of the Federated Learning system for future improvements? The research highlights the importance of continuously building trust among stakeholders. Furthermore, the token-based reward system based on contribution is a good incentive to be adaptable and develop long-term collaboration. (Communication) Results
To build trust, this study employs traditional methods like legal contracts and appoints a consortium as a neutral party. Transparent governance and involving a neutral, trusted entity is necessary to gain stakeholder acceptance and ensure long-term collaboration. Blockchain technology enhances the transparency of the consortium's operations, ensuring all transactions and data exchanges are recorded on an immutable database...
The research question focuses on how SSI functionalities should be designed to ensure the retention of personal data sovereignty (PDS) in an LMIC context. The study employs the Design Science Research (DSR) methodology, which includes the creation and evaluation of design artifacts to advance understanding in this domain. The research process involved developing SSI interface artifacts and testing them through a qualitative study with 15 Indonesian respondents, including individuals with socially stigmatized diseases like HIV/AIDS and TB. This population was chosen to ensure the study's inclusivity, given their heightened sensitivity to data privacy issues.
The study’s findings highlight the importance of data minimization and revocation functionalities in SSI systems. Data minimization allows users to share only the necessary information, while revocation gives them the ability to withdraw their consent for data sharing. These functionalities are crucial for fostering a sense of control, which is directly linked to a feeling of ownership over one's data. The study also revealed that a user’s digital literacy and affinity with data sharing significantly affect their perception of SSI functionalities. Users with a higher understanding of data implications tend to prefer more complex interfaces that encourage careful decision-making, whereas those with limited knowledge are more comfortable with simpler interfaces.
Additionally, the study underscores the importance of trust and contractual agreements as foundational elements in a user's willingness to participate in a data ecosystem. Without these, users may be hesitant to share their data, regardless of the control mechanisms in place.
This research contributes to the growing body of knowledge on SSI, particularly in the context of an LMIC like Indonesia. By taking a user-centric approach, the study explores the link between SSI functionalities and personal data sovereignty, providing insights that are currently underrepresented in existing literature. The inclusion of vulnerable populations further enriches the study’s findings, offering a comprehensive understanding of how SSI can enhance participation in the health data ecosystem while safeguarding personal data sovereignty.
Future research should aim to broaden the respondent pool to include more diverse socio-economic backgrounds, which would improve the generalizability of the findings. Additionally, further refinement of the SSI design artifact, informed by user feedback, is recommended to enhance its usability and effectiveness. Exploring the study's hypotheses through a quantitative approach could also provide deeper insights into the relationship between digital literacy, data sharing affinity, and personal data sovereignty. ...
The research question focuses on how SSI functionalities should be designed to ensure the retention of personal data sovereignty (PDS) in an LMIC context. The study employs the Design Science Research (DSR) methodology, which includes the creation and evaluation of design artifacts to advance understanding in this domain. The research process involved developing SSI interface artifacts and testing them through a qualitative study with 15 Indonesian respondents, including individuals with socially stigmatized diseases like HIV/AIDS and TB. This population was chosen to ensure the study's inclusivity, given their heightened sensitivity to data privacy issues.
The study’s findings highlight the importance of data minimization and revocation functionalities in SSI systems. Data minimization allows users to share only the necessary information, while revocation gives them the ability to withdraw their consent for data sharing. These functionalities are crucial for fostering a sense of control, which is directly linked to a feeling of ownership over one's data. The study also revealed that a user’s digital literacy and affinity with data sharing significantly affect their perception of SSI functionalities. Users with a higher understanding of data implications tend to prefer more complex interfaces that encourage careful decision-making, whereas those with limited knowledge are more comfortable with simpler interfaces.
Additionally, the study underscores the importance of trust and contractual agreements as foundational elements in a user's willingness to participate in a data ecosystem. Without these, users may be hesitant to share their data, regardless of the control mechanisms in place.
This research contributes to the growing body of knowledge on SSI, particularly in the context of an LMIC like Indonesia. By taking a user-centric approach, the study explores the link between SSI functionalities and personal data sovereignty, providing insights that are currently underrepresented in existing literature. The inclusion of vulnerable populations further enriches the study’s findings, offering a comprehensive understanding of how SSI can enhance participation in the health data ecosystem while safeguarding personal data sovereignty.
Future research should aim to broaden the respondent pool to include more diverse socio-economic backgrounds, which would improve the generalizability of the findings. Additionally, further refinement of the SSI design artifact, informed by user feedback, is recommended to enhance its usability and effectiveness. Exploring the study's hypotheses through a quantitative approach could also provide deeper insights into the relationship between digital literacy, data sharing affinity, and personal data sovereignty.
A New Journey from Flower to Vase
Supply chain & digital design for an automated vending business concept
This study targeted the development of both a design for the physical operations in the supply chain as well as the digital system providing the coordination required for the operations in the unified chain. A systematic approach was followed to arrive at multiple design alternatives.
The physical designs were created by converting a functional design into design options on a morphological chart. The morphological chart was reviewed using SCOR performance score cards, and design alternatives were drafted from the remaining well-scoring options on the morphological chart. They were converted into a level 2 SCOR mapping. Based on the physical designs, digital designs were created using enterprise architecture modelling in Archi.
The resulting design alternatives were rated using a multiple-criteria decision analysis, by comparing them to a list of requirements and constraints, and with SWOT analyses. Based on this, a best alternative was concluded to be feasible to implement. The design alternatives were demonstrated in capability by simulating the flower journey and they were evaluated on feasibility in a workshop with clients.
The conclusion that a business concept with a unified supply chain and automated vending points could be viable to implement in the floriculture sector means that further development of the designs into practical realisation is possible for actors in the sector. Comparable industries can also take the study as an indication of possibilities in their sector when combining a data-driven approach with centralized supply chain coordination.
...
This study targeted the development of both a design for the physical operations in the supply chain as well as the digital system providing the coordination required for the operations in the unified chain. A systematic approach was followed to arrive at multiple design alternatives.
The physical designs were created by converting a functional design into design options on a morphological chart. The morphological chart was reviewed using SCOR performance score cards, and design alternatives were drafted from the remaining well-scoring options on the morphological chart. They were converted into a level 2 SCOR mapping. Based on the physical designs, digital designs were created using enterprise architecture modelling in Archi.
The resulting design alternatives were rated using a multiple-criteria decision analysis, by comparing them to a list of requirements and constraints, and with SWOT analyses. Based on this, a best alternative was concluded to be feasible to implement. The design alternatives were demonstrated in capability by simulating the flower journey and they were evaluated on feasibility in a workshop with clients.
The conclusion that a business concept with a unified supply chain and automated vending points could be viable to implement in the floriculture sector means that further development of the designs into practical realisation is possible for actors in the sector. Comparable industries can also take the study as an indication of possibilities in their sector when combining a data-driven approach with centralized supply chain coordination.
Privacy: the more, the merrier?
A case study of how Amazon uses privacy protection to expand its power over IoT manufacturers
I answered the research question “How does Amazon’s use of privacy-enhancing technologies in Sidewalk affect its power over IoT manufacturers?” by reviewing grey literature, analysing the Sidewalk technology, and elite interviewing with high-ranking employees of Sidewalk-adopting manufacturers. I have shown that Amazon leveraged PETs to mitigate public security concerns, but in the meantime reshapes how manufacturers produce their devices. Part of this ploy is cementing AWS in their production processes. Amazon also uses this leverage to mobilise manufacturers’ and silicon providers’ resources to improve Sidewalk’s public reception, technology, and governance.
These reconfigurations are expensive and complicated to realise, but manufacturers stressed the importance of Sidewalk adoption to leverage Amazon’s reputation vis-à-vis suppliers and customers, and “befriend the giant” for they rely on Amazon’s Marketplace, cloud, and logistics.
Meanwhile, Amazon’s reductionist framing of privacy and security as protecting user identity and data confidentiality, means that confidentiality of manufacturers’ business-sensitive information is not discussed. With this vantage point, Amazon can learn which endpoint types are popular and how they work; but Sidewalk might also be a vehicle for Amazon to attract more IoT developers to AWS.
In sum, I have demonstrated that strictly pursuing user privacy (or confidentiality) in digital services may have unforeseen effects on production. Therefore, I call upon privacy and competition scholars, advocates, and regulators to question how privacy protection actually augments companies’ power, and stepping away from their narrow “consumer harm” lenses. These actors should debate a right to personal control over devices. A mere consumer focus in studying these developments is insufficient: I established that business-to-business relations and businesses’ production processes are more significantly affected than consumers. The production focus of this work lays bare the novel power dynamics between Amazon and manufacturers, shaped by PETs. ...
I answered the research question “How does Amazon’s use of privacy-enhancing technologies in Sidewalk affect its power over IoT manufacturers?” by reviewing grey literature, analysing the Sidewalk technology, and elite interviewing with high-ranking employees of Sidewalk-adopting manufacturers. I have shown that Amazon leveraged PETs to mitigate public security concerns, but in the meantime reshapes how manufacturers produce their devices. Part of this ploy is cementing AWS in their production processes. Amazon also uses this leverage to mobilise manufacturers’ and silicon providers’ resources to improve Sidewalk’s public reception, technology, and governance.
These reconfigurations are expensive and complicated to realise, but manufacturers stressed the importance of Sidewalk adoption to leverage Amazon’s reputation vis-à-vis suppliers and customers, and “befriend the giant” for they rely on Amazon’s Marketplace, cloud, and logistics.
Meanwhile, Amazon’s reductionist framing of privacy and security as protecting user identity and data confidentiality, means that confidentiality of manufacturers’ business-sensitive information is not discussed. With this vantage point, Amazon can learn which endpoint types are popular and how they work; but Sidewalk might also be a vehicle for Amazon to attract more IoT developers to AWS.
In sum, I have demonstrated that strictly pursuing user privacy (or confidentiality) in digital services may have unforeseen effects on production. Therefore, I call upon privacy and competition scholars, advocates, and regulators to question how privacy protection actually augments companies’ power, and stepping away from their narrow “consumer harm” lenses. These actors should debate a right to personal control over devices. A mere consumer focus in studying these developments is insufficient: I established that business-to-business relations and businesses’ production processes are more significantly affected than consumers. The production focus of this work lays bare the novel power dynamics between Amazon and manufacturers, shaped by PETs.
In the current era, there is a prevailing trend of improper dietary intake and a growing trend of social media usage. Given this growth in social media usage, the concern about misinformation, mainly health-related misinformation, is increasing. Social media plays an essential role in the prevalence and impact of health-related misinformation. More specifically, the concern of nutritional supplement misinformation and its effect on adolescents and young adults is growing and under-researched. Adolescents and young adults have unknown preferences, and current policies fail to address the problems associated with nutritional supplement misinformation. Understanding the specific preferences of adolescents and young adults and the socio-technical system is crucial to address the issue. Therefore, as the Dutch context has not been researched, this research explicitly addresses the problem of nutritional supplement misinformation among Dutch adolescents and young adults and aims to improve public health outcomes. This thesis aims to develop interventions and design requirements within the system of nutritional supplements, social media, and public health outcomes to maximize public health. The research deploys the Value-Sensitive Design (VSD) framework to address the issue.
Results
To fully address the socio-technical system, structured literature reviews were conducted to assess the influences in the system and investigate the institutional environment. The comprehensive, structured analysis of the literature and the assessment of the institutional environment pointed out the complex nature of the system and its associated stakeholders, where social media algorithms also play a significant role. Interviews and a focus group identified the values, risks, value tensions, and possible interventions at stake in the system. This extensive value analysis identified the main values to design for. In designing, the value of public health is paramount.
Based on the identified values to design, constructing value hierarchies led to the design requirements. By including the stakeholder values, the interventions are theoretically sound. The most promising interventions identified in this thesis are certificating influencers, counter campaigns, educational campaigns, and an automated enforcement tool. This research sees all four interventions as suitable interventions to implement, where the extension to the certification of influencers and the counter campaigns are most suitable to deploy first. The research mainly showed the need for prevention interventions to boost awareness and consumer education concerning health and social media.
Contributions
This research has shown that VSD can aid design in addressing a societal and policy issue, where VSD originally stems from technology design (Friedman et al., 2006). In addition, this thesis provides grounded interventions to offer novel perspectives in addressing nutritional supplement misinformation. Furthermore, the policies implied by the study are within the context of the Netherlands but could also be considered internationally. This thesis can also fuel the broader problem of health misinformation and other problems with nutritional supplements, as well as the discussion of the responsibility of social media platforms and other industrial stakeholders within the identified socio-technical system. ...
In the current era, there is a prevailing trend of improper dietary intake and a growing trend of social media usage. Given this growth in social media usage, the concern about misinformation, mainly health-related misinformation, is increasing. Social media plays an essential role in the prevalence and impact of health-related misinformation. More specifically, the concern of nutritional supplement misinformation and its effect on adolescents and young adults is growing and under-researched. Adolescents and young adults have unknown preferences, and current policies fail to address the problems associated with nutritional supplement misinformation. Understanding the specific preferences of adolescents and young adults and the socio-technical system is crucial to address the issue. Therefore, as the Dutch context has not been researched, this research explicitly addresses the problem of nutritional supplement misinformation among Dutch adolescents and young adults and aims to improve public health outcomes. This thesis aims to develop interventions and design requirements within the system of nutritional supplements, social media, and public health outcomes to maximize public health. The research deploys the Value-Sensitive Design (VSD) framework to address the issue.
Results
To fully address the socio-technical system, structured literature reviews were conducted to assess the influences in the system and investigate the institutional environment. The comprehensive, structured analysis of the literature and the assessment of the institutional environment pointed out the complex nature of the system and its associated stakeholders, where social media algorithms also play a significant role. Interviews and a focus group identified the values, risks, value tensions, and possible interventions at stake in the system. This extensive value analysis identified the main values to design for. In designing, the value of public health is paramount.
Based on the identified values to design, constructing value hierarchies led to the design requirements. By including the stakeholder values, the interventions are theoretically sound. The most promising interventions identified in this thesis are certificating influencers, counter campaigns, educational campaigns, and an automated enforcement tool. This research sees all four interventions as suitable interventions to implement, where the extension to the certification of influencers and the counter campaigns are most suitable to deploy first. The research mainly showed the need for prevention interventions to boost awareness and consumer education concerning health and social media.
Contributions
This research has shown that VSD can aid design in addressing a societal and policy issue, where VSD originally stems from technology design (Friedman et al., 2006). In addition, this thesis provides grounded interventions to offer novel perspectives in addressing nutritional supplement misinformation. Furthermore, the policies implied by the study are within the context of the Netherlands but could also be considered internationally. This thesis can also fuel the broader problem of health misinformation and other problems with nutritional supplements, as well as the discussion of the responsibility of social media platforms and other industrial stakeholders within the identified socio-technical system.
Developing a framework to assess ELSA design points that contribute towards a Circular Economy in the industrial automotive manufacturing sector
An exploratory research applied to the case of the circular economy project “ALICIA”
In order to test and evaluate the conceptualized framework, it got applied to a case study. The Horizon Europe granted project ALICIA represents the case study environment. ALICIA intends to establish a CE for industrial automotive manufacturing equipment (machinery and robots) within Europe. Since circularity for industrial automotive manufacturing equipment constitutes, especially on this scale, an under-researched field, this research also investigates such an automotive CE approach. Through the framework’s demonstration, significant findings could be obtained. First, even though the framework manifested as effective due to the achieved insights, which are subsequently further expressed, future recommendations for further development regarding the framework's recognized limitations are suggested. Another crucial insight the case study provided emphasizes the major challenges that exist in realizing a CE for automotive production equipment. Those challenges were identified by assessing the ELSA risks of ALICIA and the design points to mitigate such. To realize equipment circularity, detailed data must be shared by companies that often contain sensitive corporational information. Originating from the automotive industry’s competitiveness, such data exchange is hard to realize as it can jeopardize companies’ privacy. To overcome this, it requires collaboration between the companies and clearly defined data-sharing policies to enable such data exchange. Such ideal data exchange should ensure that still, sufficient data is shared to realize equipment circularity but simultaneously does not infringe a corporation’s privacy which could harm their market position by disclosing it to competitors.
Additionally, since the automotive industry is a profit-driven one, socio-ethical dimensions must also be incorporated into such equipment CE from the beginning. Compared to the electric mobility transition, which is another sustainability endeavor of the automotive industry, socio-ethical dilemmas that refer to unethical origins of certain parts (e.g., lithium batteries), such as child labor or farm desiccation, are prevalent. To prevent such or similar dilemmas within the sustainability agenda of an automotive CE, it requires the embedding of socio-ethical considerations that were detected throughout the case study. These considerations contain to ensure, inter alia, an ethical origin of parts used for equipment refurbishment. Otherwise, if these socio-ethical issues are neglected from the start, potential drawbacks might be difficult to remedy during an already ongoing CE implementation. These both outlined challenges with their socio-ethical considerations must be more precisely addressed in the future by relevant experts.
Thus, this research's key findings cannot only be seen as beneficial for the methodology of assessing socio-ethical considerations in CE from the context of RRI but also for the circularity of automotive production equipment. Both results constitute fundamental groundwork for further recommended research in these lacking research fields. ...
In order to test and evaluate the conceptualized framework, it got applied to a case study. The Horizon Europe granted project ALICIA represents the case study environment. ALICIA intends to establish a CE for industrial automotive manufacturing equipment (machinery and robots) within Europe. Since circularity for industrial automotive manufacturing equipment constitutes, especially on this scale, an under-researched field, this research also investigates such an automotive CE approach. Through the framework’s demonstration, significant findings could be obtained. First, even though the framework manifested as effective due to the achieved insights, which are subsequently further expressed, future recommendations for further development regarding the framework's recognized limitations are suggested. Another crucial insight the case study provided emphasizes the major challenges that exist in realizing a CE for automotive production equipment. Those challenges were identified by assessing the ELSA risks of ALICIA and the design points to mitigate such. To realize equipment circularity, detailed data must be shared by companies that often contain sensitive corporational information. Originating from the automotive industry’s competitiveness, such data exchange is hard to realize as it can jeopardize companies’ privacy. To overcome this, it requires collaboration between the companies and clearly defined data-sharing policies to enable such data exchange. Such ideal data exchange should ensure that still, sufficient data is shared to realize equipment circularity but simultaneously does not infringe a corporation’s privacy which could harm their market position by disclosing it to competitors.
Additionally, since the automotive industry is a profit-driven one, socio-ethical dimensions must also be incorporated into such equipment CE from the beginning. Compared to the electric mobility transition, which is another sustainability endeavor of the automotive industry, socio-ethical dilemmas that refer to unethical origins of certain parts (e.g., lithium batteries), such as child labor or farm desiccation, are prevalent. To prevent such or similar dilemmas within the sustainability agenda of an automotive CE, it requires the embedding of socio-ethical considerations that were detected throughout the case study. These considerations contain to ensure, inter alia, an ethical origin of parts used for equipment refurbishment. Otherwise, if these socio-ethical issues are neglected from the start, potential drawbacks might be difficult to remedy during an already ongoing CE implementation. These both outlined challenges with their socio-ethical considerations must be more precisely addressed in the future by relevant experts.
Thus, this research's key findings cannot only be seen as beneficial for the methodology of assessing socio-ethical considerations in CE from the context of RRI but also for the circularity of automotive production equipment. Both results constitute fundamental groundwork for further recommended research in these lacking research fields.
Organisational Maturity Assessment during the Paradigm Shift from Monoliths to Data Mesh
Design Science Research in Developing a Data Mesh Maturity Assessment Model
This research shows that the developed DMMAM evaluates data mesh based on four maturity levels, classified as Level 0: Non-Initiated, Level 1: Conceptual, Level 2: Defined, and Level 3: Achieved, and that data mesh is represented by five dimensions: A. Data Foundation & Organisational Change, B. Domain Oriented Decentralised Data Ownership & Architecture, C. Data as a Product, D. Self-Serve Data Infrastructure as a Platform, and E. Federated Computational Governance. These five dimensions are collectively represented by 54 characteristics. For each characteristic, labels for the People, Process, Technology (PPT) perspectives are assigned. Additionally, questions are formulated, and criteria and requirements are provided for all characteristics at each maturity level. This enables participants to self-assess their organisation’s maturity by individually rating 54 questions based on the current and target levels. Conducting the self-assessment yields various outcomes, including an overall data mesh maturity score, individual dimensional maturity scores, and maturity scores from PPT-perspectives. Moreover, the assessment helps to identify maturity gaps and allows benchmarking to compare results across organisations, providing organisations with guidance for improvement. The demonstration and evaluation of the DMMAM through maturity assessments for three organisations have demonstrated its applicability and usefulness. However, it is important to acknowledge that this research represents the first attempt to provide a comprehensive framework for assessing data mesh maturity in organisations and is not without limitations.
Future research is proposed to further refine and improve the DMMAM, supported by data mesh SME’s and practitioners, to ensure that the model remains up-to-date with the latest available research on data mesh. In addition, including additional guidance as an outcome of the maturity assessment would make the assessment more actionable and pragmatic. Furthermore, examining the optimal assessment structure will enhance the model’s reliability and validity. Moreover, expanding the benchmark functionality will enable statistical generalisations and comparisons for organisations within and across industries. At last, it is suggested to do further research about examining the overall contribution of data mesh as a strategy element towards becoming data-driven. ...
This research shows that the developed DMMAM evaluates data mesh based on four maturity levels, classified as Level 0: Non-Initiated, Level 1: Conceptual, Level 2: Defined, and Level 3: Achieved, and that data mesh is represented by five dimensions: A. Data Foundation & Organisational Change, B. Domain Oriented Decentralised Data Ownership & Architecture, C. Data as a Product, D. Self-Serve Data Infrastructure as a Platform, and E. Federated Computational Governance. These five dimensions are collectively represented by 54 characteristics. For each characteristic, labels for the People, Process, Technology (PPT) perspectives are assigned. Additionally, questions are formulated, and criteria and requirements are provided for all characteristics at each maturity level. This enables participants to self-assess their organisation’s maturity by individually rating 54 questions based on the current and target levels. Conducting the self-assessment yields various outcomes, including an overall data mesh maturity score, individual dimensional maturity scores, and maturity scores from PPT-perspectives. Moreover, the assessment helps to identify maturity gaps and allows benchmarking to compare results across organisations, providing organisations with guidance for improvement. The demonstration and evaluation of the DMMAM through maturity assessments for three organisations have demonstrated its applicability and usefulness. However, it is important to acknowledge that this research represents the first attempt to provide a comprehensive framework for assessing data mesh maturity in organisations and is not without limitations.
Future research is proposed to further refine and improve the DMMAM, supported by data mesh SME’s and practitioners, to ensure that the model remains up-to-date with the latest available research on data mesh. In addition, including additional guidance as an outcome of the maturity assessment would make the assessment more actionable and pragmatic. Furthermore, examining the optimal assessment structure will enhance the model’s reliability and validity. Moreover, expanding the benchmark functionality will enable statistical generalisations and comparisons for organisations within and across industries. At last, it is suggested to do further research about examining the overall contribution of data mesh as a strategy element towards becoming data-driven.
The new era of breaking news
How social media impacts the dissemination of information
I discovered that TikTok's unique features like algorithm-driven content discovery and short- form video format create a space for users to voice diverse perspectives, raise awareness, and mobilize for social change. This leads to the democratization of discourse and gives voice to individuals who might have been marginalized or overlooked, particularly in the realm of activism. However, I also identified significant challenges, including the spread of misinformation, algorithmic biases, the creation of echo chambers, manipulation by malicious entities, and many more. These issues pose substantial threats to democratic values and processes, undermining trust in reliable sources and obstructing informed decision-making.
Drawing from these findings, I designed strategies to enhance the informed and ethical usage of TikTok. However, implementing these strategies demands a collective effort from a variety of stakeholders, including TikTok as a platform, its users, regulatory bodies, and wider society. A critical challenge is balancing promoting democratic values and maintaining a user-friendly, engaging environment. Implementing all the suggested strategies may not be feasible due to the platform's profitable objectives and complexity. Therefore, I recommend prioritizing the most critical and impactful measures and committing to continuous research, monitoring, and adaptation in response to the ever-changing social media landscape.
Furthermore, I highlight that the responsibility for fostering a responsible information ecosystem extends beyond TikTok. It calls for collaboration among social media platforms, regulatory bodies, educational institutions, and society at large. With concerted effort, we can envision a future where platforms like TikTok serve as spaces for entertainment, and relaxation, as well as catalysts for positive societal change, informed civic engagement, and potent activism.
As the social media landscape continues to evolve rapidly, further research into this domain is essential. We need to keep exploring and understanding the interaction between technology, legislation, and democratic processes to effectively navigate the challenges and opportunities presented by platforms like TikTok.
...
I discovered that TikTok's unique features like algorithm-driven content discovery and short- form video format create a space for users to voice diverse perspectives, raise awareness, and mobilize for social change. This leads to the democratization of discourse and gives voice to individuals who might have been marginalized or overlooked, particularly in the realm of activism. However, I also identified significant challenges, including the spread of misinformation, algorithmic biases, the creation of echo chambers, manipulation by malicious entities, and many more. These issues pose substantial threats to democratic values and processes, undermining trust in reliable sources and obstructing informed decision-making.
Drawing from these findings, I designed strategies to enhance the informed and ethical usage of TikTok. However, implementing these strategies demands a collective effort from a variety of stakeholders, including TikTok as a platform, its users, regulatory bodies, and wider society. A critical challenge is balancing promoting democratic values and maintaining a user-friendly, engaging environment. Implementing all the suggested strategies may not be feasible due to the platform's profitable objectives and complexity. Therefore, I recommend prioritizing the most critical and impactful measures and committing to continuous research, monitoring, and adaptation in response to the ever-changing social media landscape.
Furthermore, I highlight that the responsibility for fostering a responsible information ecosystem extends beyond TikTok. It calls for collaboration among social media platforms, regulatory bodies, educational institutions, and society at large. With concerted effort, we can envision a future where platforms like TikTok serve as spaces for entertainment, and relaxation, as well as catalysts for positive societal change, informed civic engagement, and potent activism.
As the social media landscape continues to evolve rapidly, further research into this domain is essential. We need to keep exploring and understanding the interaction between technology, legislation, and democratic processes to effectively navigate the challenges and opportunities presented by platforms like TikTok.
Choice Overload in E-Tourism
The influence of choice complexity and maximizing tendency on post-choice satisfaction
The Openness between Platforms
What Changes in an IoT Context?
Edge Computing on the Rise
Towards a Business Model Tool for Analyzing the Potential of Edge Computing for IoT Applications