You are on page 1of 8

Articles

European Union Regulations on


Algorithmic Decision Making and
a “Right to Explanation”

Bryce Goodman, Seth Flaxman

I
I We summarize the potential impact n April 2016, for the first time in more than two
that the European Union’s new General decades, the European Parliament adopted a set of
Data Protection Regulation will have on comprehensive regulations for the collection, storage,
the routine use of machine-learning and use of personal information, the General Data Pro-
algorithms. Slated to take effect as law
tection Regulation (GDPR)1 (European Union, Parlia-
across the European Union in 2018, it
will place restrictions on automated
ment and Council 2016). The new regulation has been
individual decision making (that is, described as a “Copernican Revolution” in data-protec-
algorithms that make decisions based tion law, “seeking to shift its focus away from paper-
on user-level predictors) that “signifi- based, bureaucratic requirements and towards compli-
cantly affect” users. When put into ance in practice, harmonization of the law, and
practice, the law may also effectively cre- individual empowerment” (Kuner 2012). Much in the
ate a right to explanation, whereby a
regulations is clearly aimed at perceived gaps and incon-
user can ask for an explanation of an
sistencies in the European Union’s (EU) current approach
algorithmic decision that significantly
affects them. We argue that while this to data protection. This includes, for example, the codi-
law may pose large challenges for indus- fication of the “right to be forgotten” (Article 17), and
try, it highlights opportunities for com-
puter scientists to take the lead in
designing algorithms and evaluation
frameworks that avoid discrimination
and enable explanation.

50 AI MAGAZINE Copyright © 2017, Association for the Advancement of Artificial Intelligence. All rights reserved. ISSN 0738-4602
Articles

… for the first time in more than two decades, the


European Parliament adopted a set of comprehensive
regulations for the collection, storage, and use of
personal information

© pepifoto, IStock

regulations for foreign companies collecting data Background


from European citizens (Article 44).
However, while the bulk of language deals with The General Data Protection Regulation is slated to
how data is collected and stored, the regulation con- go into effect in April 2018 and will replace the EU’s
tains Article 22: Automated individual decision mak- 1995 Data Protection Directive (DPD). On the surface,
ing, including profiling (see figure 1) potentially pro- the GDPR merely reaffirms the DPD’s right to expla-
nation and restrictions on automated decision mak-
hibiting a wide swath of algorithms currently in use
ing. However, this reading ignores a number of criti-
in recommendation systems, credit and insurance
cal differences between the two pieces of legislation
risk assessments, computational advertising, and
(Goodman 2016a, 2016b).
social networks, for example. This prohibition raises
First, it is important to note the difference between
important issues that are of particular concern to the a directive and a regulation. While a directive “set[s] out
machine-learning community. In its current form, general rules to be transferred into national law by
the GDPR’s requirements could require a complete each country as they deem appropriate,” a regulation
overhaul of standard and widely used algorithmic is “similar to a national law with the difference that
techniques. The GDPR’s policy on the right of citizens it is applicable in all EU countries” (European Docu-
to receive an explanation for algorithmic decisions mentation Centre 2016). In other words, the 1995
highlights the pressing importance of human inter- directive was subject to national interpretation and
pretability in algorithm design. If, as expected, the was only ever indirectly implemented through subse-
GDPR takes effect in its current form in mid-2018, quent laws passed within individual member states
there will be a pressing need for effective algorithms (Fromholz 2000). The GDPR, however, requires no
that can operate within this new legal framework. enabling legislation to take effect. It does not direct

FALL 2017 51
Articles

authority” (Article 77), which individuals can exercise


in his or her place of residence, place of work, or place
Article 22. Automated individual of the alleged infringement.
decision making, including profiling
The “right to an effective judicial remedy against a
supervisory authority” (Article 78), which may be
1. The data subject shall have the right not to be subject
to a decision based solely on automated processing,
enforced against any supervisory authority that “does
including profiling, which produces legal effects not handle a complaint or does not inform the data
concerning him or her or similarly significantly subject within three months on the progress or out-
affects him or her. come of the complaint lodged.”
2. Paragraph 1 shall not apply if the decision:
(a) is necessary for entering into, or performance
The “right to an effective judicial remedy against a
of, a contract between the data subject and a controller or processor” (Article 79) which, in the case
data controller; of more than one processors and/or controllers, speci-
(b) is authorised by Union or Member State law to fies that each violating party has liability (see Para-
which the controller is subject and which also graph 4).
lays down suitable measures to safeguard the
data subject’s rights and freedoms and legiti- The “right to compensation and liability” (Article 82),
mate interests; or
which creates an obligation for both data controllers
(c) is based on the data subject’s explicit consent.
and processors to compensate “any person who has
3. In the cases referred to in points (a) and (c) of suffered material or nonmaterial damages as a result of
paragraph 2, the data controller shall implement
[their] infringement of this Regulation.”
suitable measures to safeguard the data subject’s
rights and freedoms and legitimate interests, at The “right of representation by a body, organization or
least the right to obtain human intervention on
the part of the controller, to express his or her association” (Article 80), which allows an individual to
point of view and to contest the decision. designate a qualified not-for-profit body (such as pri-
4. Decisions referred to in paragraph 2 shall not be vacy advocacy groups) to exercise data protection
based on special categories of personal data rights on his or her behalf, including lodging com-
referred to in Article 9(1), unless point (a) or (g) plaints and pursuing compensation.
of Article 9(2) apply and suitable measures to safe-
guard the data subject’s rights and freedoms and Taken together, these rights greatly strengthen indi-
legitimate interests are in place. viduals’ actual (as opposed to nominal) ability to pur-
sue action against companies that fail to comply with
the GDPR (Pastor and Lawrence 2016).
Before proceeding with analysis, we summarize
Figure 1. Excerpt from the General some of the key terms employed in the GDPR as
Data Protection Regulation. defined in Article 4: Definitions:
Personal data is “any information relating to an iden-
(European Union, Parliament and Council 2016)
tified or identifiable natural person.”

Data subject is the natural person to whom data


the law of EU member states, it simply is the law for relates.
member states (or will be, when it takes effect).2 Processing is “any operation or set of operations which
Second, the DPD and GDPR are worlds apart in is performed on personal data or on sets of personal
terms of the fines that can be imposed on violators. data, whether or not by automated means.”
Under the DPD, there are no explicit maximum fines.
Profiling is “any form of automated processing of per-
Instead, fines are determined on a country by coun-
sonal data consisting of the use of personal data to
try basis. By contrast, the GDPR introduces EU-wide evaluate certain personal aspects relating to a natural
maximum fines of 20 million euros or 4 percent of person.”
global revenue, whichever is greater (Article 83, Para-
Thus profiling should be construed as a subset of
graph 5). For companies like Google and Facebook,
processing, under two conditions: the processing is
this could mean fines in the billions. automated, and the processing is for the purposes of
Third, the scope of the GDPR is explicitly global evaluation.
(Article 3, Paragraph 1). Its requirements do not just The GDPR calls particular attention to profiling
apply to companies that are headquartered in the EU aimed at “analys[ing] or predict[ing] aspects concern-
but, rather, to any companies processing EU resi- ing that natural person’s performance at work, eco-
dents’ personal data. For the purposes of determining nomic situation, health, personal preferences, inter-
jurisdiction, it is irrelevant whether that data is ests, reliability, behavior, location or movements”
processed within the EU territory or abroad. (Article 4, Paragraph 4). Given the breadth of cate-
In addition, the GDPR introduces a number of gories, it stands to reason that the GDPR’s desidera-
explicit rights that increase the ability of individuals tum for profiling errs on the side of inclusion, to say
to lodge complaints and receive compensation for the least.
violations. These rights include the following: Article 22: Automated individual decision making,
The “right to lodge a complaint with a supervisory including profiling, Paragraph 1 (see figure 1) pro-

52 AI MAGAZINE
Articles

hibits any “decision based solely on automated pro- deny members of vulnerable groups full participation
cessing, including profiling” which “produces legal in society” (Barocas and Selbst 2016). Indeed,
effects...or similarly significantly affects” a data sub- machine learning can reify existing patterns of dis-
ject. Paragraph 2 specifies that exceptions can be crimination — if they are found in the training data
made “if necessary for entering into, or performance set, then by design an accurate classifier will repro-
of, a contract,” authorized by “Union or Member duce them. In this way, biased decisions are present-
State law” or “based on the data subject’s explicit con- ed as the outcome of an objective algorithm.
sent.” However, Paragraph 3 states that, even in the Paragraph 71 of the recitals (the preamble to the
case of exceptions, data controllers must “provide GDPR, which explains the rationale behind it but is
appropriate safeguards” including “the right to not itself law) explicitly requires data controllers to
obtain human intervention...to express his or her “implement appropriate technical and organization-
point of view and to contest the decision.” Paragraph al measures” that “prevents, inter alia, discriminato-
4 specifically prohibits automated processing “based ry effects” on the basis of processing sensitive data.
on special categories of personal data” unless “suit- According to Article 9: Processing of special categories
able measures to safeguard the data subject’s rights of personal data, sensitive data includes:
and freedoms and legitimate interests are in place.” personal data revealing racial or ethnic origin, political
Note that this section does not address the condi- opinions, religious or philosophical beliefs, or trade-
tions under which it is ethically permissible to access union membership, and the processing of genetic data,
sensitive data — this is dealt with elsewhere (see Arti- biometric data for the purpose of uniquely identifying
a natural person, data concerning health or data con-
cle 9). Rather, it is implicitly assumed in this section
cerning a natural person’s sex life or sexual orienta-
that the data is legitimately obtained. Thus the pro- tion...
visions for algorithmic profiling are an additional
constraint that apply even if the data processor has It is important to note that Paragraph 71 and Arti-
informed consent from data subjects.3 cle 22 Paragraph 4 specifically address discrimination
These provisions present a number of practical from profiling that makes use of sensitive data. In
unpacking this mandate, we must distinguish
challenges for the design and deployment of
between two potential interpretations. The first min-
machine-learning algorithms. This article focuses on
imal interpretation is that this requirement only per-
two: issues raised by the GDPR’s stance on discrimi-
tains to cases where an algorithm is making direct use
nation and the GDPR’s “right to explanation.”
of data that is explicitly sensitive. This would include,
Throughout, we highlight opportunities for
for example, variables that code for race, finances, or
researchers.
any of the other categories of sensitive information
referred to in Article 9. However, it is widely acknowl-
Nondiscrimination edged that simply removing certain variables from a
model does not ensure predictions that are, in effect,
In general, discrimination might be defined as the uncorrelated to those variables (Leese 2014, Hardt
unfair treatment of an individual because of his or 2014)). For example, if a certain geographic region
her membership in a particular group, race, or gender has a high number of low income or minority resi-
(Altman 2015). The right to nondiscrimination is dents, an algorithm that employs geographic data to
deeply embedded in the normative framework that determine loan eligibility is likely to produce results
underlies the EU, and can be found in Article 21 of that are, in effect, informed by race and income.
the Charter of Fundamental Rights of the European Thus a second maximal interpretation takes a
Union, Article 14 of the European Convention on broader view of sensitive data to include not only
Human Rights, and in Articles 18–25 of the Treaty on those variables that are explicitly named, but also any
the Functioning of the European Union. variables with which they are correlated. This would
The use of algorithmic profiling for the allocation put the onus on a data processor to ensure that algo-
of resources is, in a certain sense, inherently discrim- rithms are not provided with data sets containing
inatory: profiling takes place when data subjects are variables that are correlated with the “special cate-
grouped in categories according to various variables, gories of personal data” in Article 9.
and decisions are made on the basis of subjects falling This interpretation also suffers from a number of
within so-defined groups. It is thus not surprising complications in practice. With relatively small data
that concerns over discrimination have begun to take sets it may be possible to both identify and account
root in discussions over the ethics of big data. Baro- for correlations between sensitive and “nonsensitive”
cas and Selbst (2016) sum the problem up succinctly: variables. However, removing all data correlated with
“Big data claims to be neutral. It isn’t.” As the authors sensitive variables may make the resulting predictor
point out, machine learning depends upon data that virtually useless. As Calders and Verwer (2010) note,
has been collected from society, and to the extent “postal code can reveal racial information and yet at
that society contains inequality, exclusion, or other the same time, still give useful, nondiscriminatory
traces of discrimination, so too will the data.4 Conse- information on loan defaulting.”
quently, “unthinking reliance on data mining can Furthermore, as data sets become increasingly

FALL 2017 53
Articles

100
Predicted probability of repayment
white
approval threshold
80

60

40 non−white

20

0
0 10 20 30 40 50
Non−white % of population

Figure 2. An Illustration of Uncertainty Bias.


A hypothetical algorithm is used to predict the probability of loan repayment in a setting in which the ground truth is that nonwhites and
whites are equally likely to repay. The algorithm is risk averse, so it makes an offer when the lower end of the 95 percent confidence inter-
val for its predictions lie above a fixed approval threshold of 90 percent (dashed line). When nonwhites are less than 30 percent of the pop-
ulation, and assuming a simple random sample, the algorithm exhibits what we term “uncertainty bias” — the underrepresentation of
nonwhites means that predictions for nonwhites have less certainty, so they are not offered loans. As the nonwhite percentage approach-
es 50 percent the uncertainty approaches that of whites and everyone is offered loans.

large, correlations can become increasingly complex when two conditions are met: (1) one group is under-
and difficult to detect. The link between geography represented in the sample,5 so there is more uncer-
and income may be obvious, but less obvious corre- tainty associated with predictions about that group;
lations — say between IP address and race — are like- and (2) the algorithm is risk averse, so it will, all
ly to exist within large enough data sets and could things being equal, prefer to make decisions based on
lead to discriminatory effects. For example, at an predictions about which it is more confident (that is,
annual conference of actuaries, consultants from those with smaller confidence intervals [Aigner and
Deloitte explained that they can now “use thousands Cain 1977]).
of nontraditional third party data sources, such as In practice, uncertainty bias could mean that pre-
consumer buying history, to predict a life insurance dictive algorithms (such as for a loan approval) favor
applicant’s health status with an accuracy compara- groups that are better represented in the training
ble to a medical exam” (Robinson, Yu, and Rieke data, since there will be less uncertainty associated
2014). With sufficiently large data sets, the task of with those predictions. We illustrate uncertainty bias
exhaustively identifying and excluding data features in figure 2. The population consists of two groups,
correlated with “sensitive categories” a priori may be whites and nonwhites. An algorithm is used to decide
impossible. Companies may also be reluctant to whether to extend a loan, based on the predicted
exclude certain covariates — web-browsing patterns probability that the individual will repay the loan.
are a very good predictor for various recommenda- We repeatedly generated synthetic data sets of size
tion systems, but they are also correlated with sensi- 500, varying the true proportion of nonwhites in the
tive categories. population. In every case, we set the true probability
A final challenge, which purging variables from the of repayment to be independent of group member-
data set does not address, is posed by what we term ship: all individuals have a 95 percent probability of
uncertainty bias (Goodman 2016b). This bias arises repayment regardless of race. Using a logistic regres-

54 AI MAGAZINE
Articles

sion classifier, we consider a case in which loan deci- the amount of variance explained by a predictor. As
sions are made in a risk averse manner, by using the Hildebrandt (2008) writes, “correlations stand for a
following decision rule: check whether the lower end probability that things will turn out the same in the
of the 95 percent confidence interval for an individ- future. What they do not reveal is why this should be
ual is above a fixed approval threshold of 90 percent. the case.” The use of algorithmic decisions in an
In all cases, all white individuals will be offered cred- increasingly wide range of applications has led some
it since the true probability is 95 percent and the sam- (see, for example, Pasquale [2015]) to caution against
ple size is large enough for the confidence interval to the rise of a “black box” society and demand
be small. However, when the nonwhite population is increased transparency in algorithmic decision mak-
any fraction less than 30 percent of the total popula- ing. The nature of this requirement, however, is not
tion, they will not be extended credit due to the always clear.
uncertainty inherent in the small sample. Burrell (2016) distinguishes between three barriers
Note that in practice, more complicated combina- to transparency: (1) intentional concealment on the
tions of categories (occupation, location, consump- part of corporations or other institutions, where deci-
tion patterns, and others) would be considered by a sion-making procedures are kept from public scruti-
classifier and rare combinations will have very few ny; (2) gaps in technical literacy, which mean that,
observations. This issue is compounded in an active for most people, simply having access to underlying
learning setting: consider the same setting, where code is insufficient; and (3) a “mismatch between the
nonwhites and whites are equally likely to default. A mathematical optimization in high-dimensionality
small initial bias toward the better represented groups characteristic of machine learning and the demands
will be compounded over time as the active learning of human-scale reasoning and styles of interpreta-
acquires more examples of the better represented tion.”
group and their overrepresentation grows. Within the GDPR, Article 13: Information to be
The GDPR thus presents us with a dilemma with made available or given to the data subject goes some
two horns: under the minimal interpretation the way8 toward the first barrier, stipulating that data
nondiscrimination requirement is ineffective, under processors inform data subjects when and why data is
the maximal interpretation it is infeasible. However it collected, processed, and so forth. Article 12: Com-
would be premature to conclude that nondiscrimina- munication and modalities for exercising the rights
tion measures are without merit. Rather, the com- of the data subject attempts to solve the second by
plexity and multifaceted nature of algorithmic dis- requiring that communication with data subjects is
crimination suggests that appropriate solutions will in “concise, intelligible and easily accessible form.”
require an understanding of how it arises in practice. The third barrier, however, poses additional chal-
This highlights the need for human-intelligible expla- lenges that are particularly relevant to algorithmic
nations of algorithmic decision making. selection and design. As Lisboa notes, “machine
learning approaches are alone in the spectrum in
their lack of interpretability” (Lisboa 2013).
Right to Explanation Putting aside any barriers arising from technical
The provisions outlined in Articles 13–15 specify that fluency, and also ignoring the importance of training
data subjects have the right to access information col- the model, it stands to reason that an algorithm can
lected about them, and also requires data processors to only be explained if the trained model can be articu-
ensure data subjects are notified about the data col- lated and understood by a human. It is reasonable to
lected. However, it is important to distinguish between suppose that any adequate explanation would, at a
these rights, which may be termed the right to access minimum, provide an account of how input features
and notification, and additional “safeguards for the relate to predictions, allowing one to answer ques-
rights and freedoms of the data subject” required tions such as: Is the model more or less likely to rec-
under Article 22 when profiling takes place. Although ommend a loan if the applicant is a minority? Which
the article does not elaborate what these safeguards are features play the largest role in prediction?
beyond “the right to obtain human intervention,”6 There is of course a trade-off between the represen-
Articles 13 and 14 state that, when profiling takes tational capacity of a model and its interpretability,
place, a data subject has the right to “meaningful ranging from linear models (which can only represent
information about the logic involved.”7 This require- simple relationships but are easy to interpret) to non-
ment prompts the question: what does it mean, and parametric methods like support vector machines and
what is required, to explain an algorithm’s decision? Gaussian processes (which can represent a rich class
Standard supervised machine-learning algorithms of functions but are hard to interpret). Ensemble
for regression or classification are inherently based on methods like random forests pose a particular chal-
discovering reliable associations and correlations to lenge, as predictions result from an aggregation or
aid in accurate out-of-sample prediction, with no averaging procedure. Neural networks, especially with
concern for causal reasoning or explanation beyond the rise of deep learning, pose perhaps the biggest
the statistical sense in which it is possible to measure challenge — what hope is there of explaining the

FALL 2017 55
Articles

weights learned in a multilayer neural net with a com- Above all else, the GDPR is a vital acknowledge-
plex architecture? These issues have recently gained ment that, when algorithms are deployed in society,
attention within the machine-learning community few if any decisions are purely “technical.” Rather,
and are becoming an active area of research (Kim, the ethical design of algorithms requires coordination
Malioutov, and Varshney 2016). One promising between technical and philosophical resources of the
avenue of research concerns developing algorithms to highest caliber. A start has been made, but there is far
quantify the degree of influence of input variables on to go. And, with less than one year until the GDPR
outputs, given black-box access to a trained prediction takes effect, the clock is ticking.
algorithm (Datta, Sen, and Zick 2016).
Acknowledgements
Seth Flaxman was supported by the ERC (FP7/
Conclusion 617071) and EPSRC (EP/K009362/1).
This article has focused on two sets of issues raised by
Notes
the forthcoming GDPR that are directly relevant to
1. Regulation (EU) 2016/679 on the protection of natural
machine learning: the right to nondiscrimination
persons with regard to the processing of personal data and
and the right to explanation. This is by no means a on the free movement of such data, and repealing Directive
comprehensive overview of the legal landscape or the 95/46/EC (General Data Protection Regulation) [2016] OJ
potential challenges that engineers will face as they L119/1.
adapt to the new framework. The ability of humans 2. It is crucial to note, however, that the GDPR leaves a con-
to intervene in algorithmic decision making, or for siderable amount of latitude to member states. As a recent
data subjects to provide input to the decision-making article notes, while the GDPR “Europeanizes data protection
process, will also likely impose requirements on algo- and enforcement” it also “[delegates] back to Member States
rithmic design and require further investigation. a significant power to shape the regulatory landscape for the
While the GDPR presents a number of problems for processing of personal data within their jurisdiction” (May-
er-Schönberger and Padova 2016, p. 325). While this tension
current applications in machine learning, we believe
will no doubt be relevant to the GDPR’s implementation, a
that these are good problems to have. The challenges
more detailed consideration is outside our present scope.
described in this article emphasize the importance of
3. Compare with “consent of the data subject should not
work that ensures that algorithms are not merely effi-
provide in itself a legal ground for processing such sensitive
cient, but transparent and fair. Research is underway data” (European Union, Parliament and Council 2016).
in pursuit of rendering algorithms more amenable to 4. For an extended analysis of algorithmic discrimination,
ex post and ex ante inspection (Datta, Sen, and Zick see the paper by Goodman (2016b).
2016; Vellido, Martín-Guerrero, and Lisboa 2012; Jia 5. Note that the underrepresentation of a minority in a
and Liang 2016). Furthermore, a number of recent sample can arise through historical discrimination or less
studies have attempted to tackle the issue of discrim- access to technology, but it is also a feature of a random
ination within algorithms by introducing tools to sample in which groups are by construction represented at
both identify (Berendt and Preibusch 2012; Sandvig their population rates. In public health and public policy
et al. 2014) and rectify (Calders and Verwer 2010; research, minorities are sometimes oversampled to address
Hajian, Domingo-Ferrer, and Martinez-Balleste 2011; this problem.
Zliobaite, Kamiran, and Calders 2011; Berendt and 6. The exact meaning and nature of the intended interven-
Preibusch 2014; Dive and Khedkar 2014; Feldman et tion is unspecified, and the requirement raises a number of
important questions that are beyond our current scope.
al. 2015) cases of unwanted bias. It remains to be seen
whether these techniques are adopted in practice. 7. More precisely, the profiling must also result in a decision
that significantly affects an individual.
One silver lining of this research is to show that, for
certain types of algorithmic profiling, it is possible to 8. It is not clear whether companies will be required to dis-
close their learning algorithms or training data sets and, if
both identify and implement interventions to correct
so, whether that information will be made public.
for discrimination. This is in contrast to cases where
9. For an extended discussion of how the GDPR paves the
discrimination arises from human judgment. The role
way for algorithm audits, see the papers by Goodman
of extraneous and ethically inappropriate factors in (2016a, 2016b).
human decision making is well documented (see, for
example, Tversky and Kahneman [1974]; Danziger,
Levav, and Avnaim-Pesso [2011]; Abrams, Bertrand, References
and Mullainathan [2012]), and discriminatory deci- Abrams, D.; Bertrand, M.; and Mullainathan, S. 2012. Do
sion making is pervasive in many of the sectors where Judges Vary in Their Treatment of Race? Journal of Legal Stud-
algorithmic profiling might be introduced (see, for ies 41(2): 347–383. doi.org/10.1086/666006
example, Holmes and Horvitz [1994]; Bowen and Bok Aigner, D. J., and Cain, G. G. 1977. Statistical Theories of
[1998]). We believe that, properly applied, algorithms Discrimination in Labor Markets. Industrial and Labor Rela-
can not only make more accurate predictions, but tions Review 30(2): 175. doi.org/10.1177/00197939770
offer increased transparency and fairness over their 3000204
human counterparts (Laqueur and Copus 2015).9 Altman, A. 2015. Discrimination. In The Stanford Encyclope-

56 AI MAGAZINE
Articles

dia of Philosophy, Fall edition, ed. E. N. Zal- Data Privacy Directive. Berkeley Technology Machine Learning — Principles and Prac-
ta. Stanford, CA: Stanford University. Law Journal 15(1): 461–484. tice. In Fuzzy Logic and Applications. (WILF
Barocas, S., and Selbst, A. D. 2016. Big Goodman, B. 2016a. Big Data’s Crooked 2013), ed. F. Musulli, G. Pasi, and R. Yager.
Data’s Disparate Impact. California Law Timbers: Algorithmic Discrimination and Lecture Notes in Computer Science, vol
Review 104: 671. the European Union’s General Data Protec- 8256. Berlin: Springer. doi.org/10.1007/978-
Berendt, B., and Preibusch, S. 2012. Explor- tion regulation. Master’s thesis, (Computa- 3-319-03200-9_2
ing Discrimination: A User-Centric Evalua- tional Social Science) University of Oxford, Mayer-Schönberger, V., and Padova, Y. 2016.
tion of Discrimination-Aware Data Mining. Oxford, UK. Regime Change? Enabling Big Data
344–351. In 2012 IEEE 12th International Goodman, B. 2016b. Computer Says No: Through Europe’s New Data Protection Reg-
Conference on Data Mining Workshops. Pis- Economic Models of (Algorithmic) Discrim- ulation. The Columbia Science & Technology
cataway, NJ: Institute for Electrical and Elec- ination. Unpublished paper, Oxford, UK. Law Review 17(1)(Spring): 315–335
tronics Engineers. Hajian, S.; Domingo-Ferrer, J.; and Mar- Pasquale, F. 2015. The Black Box Society: The
Berendt, B., and Preibusch, S. 2014. Better tinez-Balleste, A. 2011. Discrimination Pre- Secret Algorithms That Control Money and
Decision Support Through Exploratory Dis- vention in Data Mining for Intrusion and Information. Cambridge, MA: Harvard Uni-
crimination-Aware Data Mining: Founda- Crime Detection. In 2011 IEEE Symposium versity Press. doi.org/10.4159/harvard.
tions and Empirical Evidence. Artificial Intel- on Computational Intelligence in Cyber Securi- 9780674736061
ligence and Law 22(2): 175–209. doi.org/ ty (CICS), 4754. Piscataway, NJ: Institute for Pastor, N., and Lawrence, G. 2016. Getting to
10.1007/s10506-013-9152-0 Electrical and Electronics Engineers. Know the GDPR, Part 10: Enforcement under the
Bowen, W. G.; and Bok, D. 1998. The Shape doi.org/10.1109/CICYBS.2011.5949405 GDPR — What Happens If You Get It Wrong?
of the River. Long-Term Consequences of Con- Hardt, M. 2014. How Big Data Is Unfair: Amsterdam, Netherlands: Fieldfisher.
sidering Race in College and University Admis- Understanding Sources of Unfairness in Robinson, D.; Yu, H.; and Rieke, A. 2014.
sions. Princeton, NJ: Princeton Univ. Press. Data Driven Decision Making. Unpublished Civil Rights, Big Data, and Our Algorithmic
Burrell, J. 2016. How the Machine “Thinks“: paper. (medium.com/@mrtz/how-big-data- Future: A September 2014 Report on Social
Understanding Opacity in Machine Learn- is-unfair-9aa544d739de) Justice and Technology. Unpublished
ing Algorithms. Big Data and Society 3(1). Hildebrandt, M. 2008. Defining Profiling: A Report of the Center for Media Justice, Oak-
Calders, T., and Verwer, S. 2010. Three New Type of Knowledge? In Profiling the land, CA.
Naive Bayes Approaches for Discrimination- European Citizen. Cross-Disciplinary Perspec- Sandvig, C.; Hamilton, K.; Karahalios, K.;
Free Classification. Data Mining and Knowl- tives, ed. M. Hildebrandt and S. Guthwirth, and Langbort, C. 2014. Auditing Algo-
edge Discovery 21(2): 277–292. doi.org/ 17–30. Berlin: Springer. doi.org/10.1007/ rithms: Research Methods for Detecting Dis-
10.1007/s10618-010-0190-x 978-1-4020-6914-7_2 crimination on Internet Platforms. Paper
Danziger, S.; Levav, J.; and Avnaim-Pesso, L. Holmes, A., and Horvitz, P. 1994. Mortgage presented at Data and Discrimination: Con-
2011. Extraneous Factors in Judicial Deci- Redlining: Race, Risk, and Demand. Journal verting Critical Concerns into Productive
sions. Proceedings of the National Academy of of Finance 49(1):81–100. doi.org/ 10.1111/ Inquiry, a preconference of the 64th Annu-
Sciences 108(17): 6889–6892. doi.org/10. j.1540-6261.1994.tb04421.x al Meeting of the International Communi-
1073/pnas.1018033108 Jia, R., and Liang, P. 2016. Data Recombina- cation Association. Seattle, WA, May 22.
Datta, A.; Sen, S.; and Zick, Y. 2016. Algo- tion for Neural Semantic Parsing. In Pro- Tversky, A., and Kahneman, D. 1974. Judg-
rithmic Transparency via Quantitative ceedings of the 54th Annual Meeting of the ment Under Uncertainty: Heuristics and
Input Influence. Paper presented at the 37th Association for Computational Linguistics Biases. Science 185(4157): 11241131. doi.
IEEE Symposium on Security and Privacy, (ACL 2016), 12–22. Stroudsberg, PA: Associ- org/10.1126/science.185.4157.112
23–25 May, San Jose, CA. ation for Computational Linguistics.
Vellido, A.; Martín-Guerrero, J. D.; and Lis-
Dive, R., and Khedkar, A. 2014. An doi.org/10.18653/v1/p16-1002
boa, P. J. 2012. Making Machine Learning
Approach for Discrimination Prevention in Kim, B.; Malioutov, D. M.; and Varshney, K. Models Interpretable. Paper presented at the
Data Mining. International Journal of Appli- R. 2016. Unpublished Proceedings of the European Symposium on Artificial Neural
cation or Innovation in Engineering and Man- 2016 ICML Workshop on Human Inter- Networks, Computational Intelligence, and
agement 3(6). pretability in Machine Learning (WHI Machine Learning, Bruges, Belgium, 25–27
European Documentation Centre. 2016. 2016). arXiv:1607.02531. Ithaca, NY: Cor- April.
European Commission — Legislation. nell University Library.
Zliobaite, I.; Kamiran, F.; and Calders, T.
Nicosia, Cyprus: University of Nicosia. Kuner, C. 2012. The European Commis-
2011. Handling Conditional Discrimina-
(www.library.unic.ac.cy/EDC/EU_Resources sion’s Proposed Data Protection Regulation:
tion. In Proceedings, 2011 IEEE 11th Interna-
/EU_ Legislation.html.) A Copernican Revolution in European Data
tional Conference on Data Mining, 992–1001.
European Union, Parliament and Council. Protection Law. Bloomberg BNA. Privacy and
Piscataway, NJ: Institute for Electrical and
2016. General Data Protection Regulation. Security 6(2012): 115.
Electronics Engineers. doi.org/10.1109/
Official Journal of the European Union L 119/1 Laqueur, H., and Copus, R. 2015. Machines ICDM.2011.72
April 5. Learning Justice: The Case for Judgmental
Feldman, M.; Friedler, S. A.; Moeller, J.; Schei- Bootstrapping of Legal Decisions. SSRN.
degger, C.; and Venkatasubramanian, S. Amsterdam, Netherlands: Elsevier. doi.org/
2015. Certifying and Removing Disparate 10.2139/ ssrn.2694326 Bryce Goodman is a research associate at
Impact. In Proceedings of the 21th ACM Leese, M. 2014. The New Profiling: Algo- the Oxford Internet Institute. He received
SIGKDD International Conference on Knowledge rithms, Black Boxes, and the Failure of Anti- his MSc from the University of Oxford.
Discovery and Data Mining, 259–268. New Discriminatory Safeguards in the European Seth Flaxman is a researcher in the Depart-
York: Association for Computing Machinery. Union. Security Dialogue 45(5): 494–511. ment of Statistics at the University of
doi.org/10.1145/2783258.2783311 doi.org/ 10.1177/0967010614544204 Oxford. He received his PhD from Carnegie
Fromholz, J. M. 2000. The European Union Lisboa, P. J. 2013. Interpretability in Mellon University.

FALL 2017 57

You might also like