Bibliographic record
Abstract
control is a social value deeply embedded in our societies. A global survey found that 88 % of people are worried about who has access to their data; over 80 % expect governments to regulate privacy and impose penalties on companies that do not use data re-sponsibly. But privacy regulation is not easy. The Internet’s current economics as well as national security manage-ment benefit from the collection and use of rich user profiles. Technology constantly changes. And data is like water: it flows and ripples in ways that are difficult to predict. As a result, even a well-conceived, general, and sustain-able privacy regulation, such as the European Data Protection Directive 95/46/EC, struggles to ensure its ef-fectiveness. Companies regularly test legal boundaries and many risk sanc-tions for privacy breaches to avoid con-straining their business. Against this background, the Eu-ropean Commission and other regu-latory bodies are looking for a more effective, system- and context-specific balance between citizens ’ privacy rights and the data needs of compa-nies and governments. The apparent solution proposed by regulators now, but barely specified, is Privacy by De-sign (PbD). At first sight, the power-ful term seems to suggest we simply need to take a few Privacy-Enhancing Technologies (PETs) and add a good dose of security, thereby creating a fault-proof systems ’ landscape for the future. But the reality is much more challenging. According to Ann Cavoukian, the Ontario information and privacy commissioner who first coined the term, PbD stands for a pro-active integration of technical privacy principles in a system’s design (such as privacy default settings or end-to-end security of personal data) and the recognition of privacy in a company’s risk management processes.1 PbD can thus be defined as “an engineering and strategic management approach that commits to selectively and sus-tainably minimize information sys-tems ’ privacy risks through technical and governance controls.”
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.002 | 0.007 |
| Meta-epidemiology (narrow) | 0.002 | 0.000 |
| Meta-epidemiology (broad) | 0.001 | 0.001 |
| Bibliometrics | 0.002 | 0.003 |
| Science and technology studies | 0.002 | 0.003 |
| Scholarly communication | 0.013 | 0.006 |
| Open science | 0.002 | 0.006 |
| Research integrity | 0.004 | 0.003 |
| Insufficient payload (model declined to judge) | 0.502 | 0.397 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".