Privacy

IPRI’s privacy research connects privacy policy and technological innovation. We undertake research to understand privacy needs, and then build tools and platforms that protect privacy and the information of individuals while still allowing for technological innovation.

Accountable systems

 

Accountable systems are a subset of privacy enhancing technologies (PETs) that promise to provide users control over their own data and can set and enforce rules for when data can be accessed – even when it moves between institutions. We identify and put into service technical infrastructure for enterprises seeking to handle personal data in a trustworthy and lawful manner with guardrails to enable the traceable, accountable, and scalable use of data. IPRI’s work on accountable systems includes OTrace, LAChS, and MIT’s Future of Data Consortium.

OTrace
In order to improve trust in the open banking ecosystem, the OTrace protocol provides the ability for consumers to track how data is being used and shared, even (and especially) across organizational boundaries. Traceability will help achieve reliable, scalable detection of data misuse, leading to both better internal processes and more effective intervention by enforcement authorities when necessary.

 

LAChS
We combine current legal scholarship on digital systems regulation with applied cryptography and software engineering to develop new software methods and tools to enable better accountability to legal rules. This includes a novel software engineering approach called “Policy concepts” based on high-level, rigorously described design patterns, to help software developers build systems that take legal compliance into account at the time of design. Our work systematizes a conceptual and logical link between legal requirements on the one hand and software artifacts on the other.

MIT Future of Data
To address these global privacy challenges, IPRI and the Computer Science and Artificial Intelligence Laboratory (CSAIL) founded the MIT Future of Data, with the goal of bringing state-of-the-art MIT computer science research together with world-leading public policy expertise and engagement. Industry partners work with MIT researchers on new policy-informed, technical approaches to today’s privacy challenges. To advance accountable systems, our mission includes the development of royalty-free privacy protocols that enable the traceable, accountable sharing of personal data in new, consumer-facing data environments.

Future of Data Initiative logo

Human Computer Interaction (HCI)

 

Human-Computer Interaction (HCI) research plays a crucial role in the development of systems that are not only transparent and explainable but also user-friendly and trustworthy. As systems become increasingly complex and pervasive, it is essential to design them in a way that is transparent, explainable, and fair. User-centered design can help identify and mitigate biases, and by involving users in the design process and incorporating their feedback, IPRI HCI researchers help ensure that systems are aligned with human values and are accountable for their actions.

Privacy-Preserving COVID Notifications (PACT)

The mission of PACT (Private Automated Contact Tracing) is to enhance contact tracing in pandemic response by designing exposure detection functions in personal digital communication devices that have maximal public health utility while preserving privacy. PACT is a collaboration led by IPRI, the MIT Computer Science and Artificial Intelligence Laboratory (CSAIL), Massachusetts General Hospital Center for Global Health and MIT Lincoln Laboratory. It includes close collaborators from Boston University, Brown University, Carnegie Mellon University, the MIT Media Lab, the Weizmann Institute and a number of public and private research and development centers. The PACT team is a partnership among cryptographers, physicians, privacy experts, scientists and engineers.

Privacy and public policy

 

PETs Policy

IPRI research helps policy makers better take into account the most recent technological and policy developments around privacy enhancing technologies for privacy, data protection, and data governance. This helps support the  adoption of complementary and converging policies in this complex area. Privacy enhancing technologies (PETs) are a collection of digital technologies, approaches, and tools that permit processing, analysis and sharing of information while protecting the confidentiality, and in some cases also the integrity and availability, of personal data. PETs represent a fundamental shift in how data can be collected and processed that is moving society closer to the goal of privacy by design. However not all policy makers and regulators may yet be able to realize the full potential of PETs in their respective domains. This is owed mainly to the highly technical nature of these technologies and to a significant “language barrier” between the engineers building these systems and the policy makers and regulators who will ultimately determine how they may be used. IPRI research takes stock of current technological developments related to PETs and presents the main regulatory and policy approaches to PETs. In so doing, the report aims to assist policy makers and regulators, most notably PEAs, to better take into account the most recent technological and policy developments around PETs for privacy and data protection, and data governance more broadly, thus supporting the adoption of complementary and converging policies in this complex area.

Privacy policy
IPRI’s research provides policy guidance for privacy issues. For example, IPRI researchers argue that the Consumer Privacy Bill of Rights, if it had been enacted, could have prevented such abuses. This bill proposed two key consumer protections: a right of individual control and respect for context. The former would empower users to control their data, while the latter would prevent companies from repurposing it for uses beyond the original consent. Overall, strong legislation and effective enforcement are crucial to safeguarding individual privacy in the digital age.

People – Privacy

People – Alumni – Privacy

Research and Events

3rd Annual Conference to Address Cyber Risk Measurement and Action in the Financial Sector (CRFS)

The Board of Governors of the Federal Reserve System, the Federal Reserve Bank of Richmond, and the Massachusetts Institute of Technology will convene their third conference on measuring and tracking cyber risk on Oct 7-8 at the Federal Reserve Bank of Boston. The event will bring together participants from industry, government, and academia to examine the application of cyber risk metrics for the financial sector. Session topics will include threat intelligence, emerging technology risks, and global policy.

Read More »

AI Strategy in Developing Economies

In this new working paper, we re-evaluate the standard “factors of production”—Land, Labor, Capital, and Entrepreneurship—through an AI-specific lens to identify strategic areas for AI investment in developing countries.

Read More »