2 Do No Digital Harm: Mitigating Technology Risks …
23
security can be verified. Such tools can also be continued after individual projects may
close down. Finally, aid actors should always plan for nondigital alternatives when
connectivity or electricity fail, or ICTs cannot be used for other reasons. Sometimes,
the best solution may be to opt against technology tools altogether.
Notably, mitigation happens at different levels. It can take involve impromptu
measures in the field, or standards and good practice can be developed at headquarter level. Some outspoken actors are already seeking to establish shared norms across
the field, including the ‘digital development principles,’ which were developed with
about a dozen international and UN organizations and endorsed by many more (https:
//digitalprinciples.org). In addition, several initiatives emerged around ‘responsible
data’ efforts, crafting principles and practical recommendations on how to assure data
security and adequate access (https://responsibledata.io/). And in the UAV community, a code of conduct was authored and agreed (werobotics.org/codeofconduct/).
Contributing to this work, Table 2.2 presents nine core ideas on implementing technology tools based on a ‘backwards’ analysis from risk assessment first to mitigation
measures suggestions. This list is not necessarily comprehensive, and specific recommendations would depend on specific technologies and contexts. Yet, this first
offering can help start conversations and be further refined with practitioners.
Back to low-tech—and sometimes no-tech
Broadly speaking, there are four types of circumstances when it may be better not
to use technologies for humanitarian purposes, as the inherent risk would outweigh
or overshadow possible benefits (Table 2.3).
Specifically, the following recommendations apply to the different technology
types:
When using mobile phone-based systems, do not…
• …use phone-based systems to collect sensitive data that could put beneficiaries
at risk. Information related to gender-based violence, the location of persecuted
people or financial and health information that could cause stigmatization cannot
be reliably secured when transferred through phone networks.
• …use it for short-term projects or without continuity. The set-up and familiarization costs only pay off if phone-based systems are used over a long time or for
several projects.
• …create a new mechanism where other, similar mechanisms already exist or are
planned. With too many systems in place, aid recipients can be confused and are
less likely to use any.
• …use it if you do not have the capacity to process feedback and follow-up. Beneficiaries will expect follow-up when using phone systems. Lack of response can
harm trust and reputation.
• …simply replace other monitoring or feedback approaches. Phone systems are
not sufficient in themselves as phone ownership is biased and network coverage
uneven.
23
security can be verified. Such tools can also be continued after individual projects may
close down. Finally, aid actors should always plan for nondigital alternatives when
connectivity or electricity fail, or ICTs cannot be used for other reasons. Sometimes,
the best solution may be to opt against technology tools altogether.
Notably, mitigation happens at different levels. It can take involve impromptu
measures in the field, or standards and good practice can be developed at headquarter level. Some outspoken actors are already seeking to establish shared norms across
the field, including the ‘digital development principles,’ which were developed with
about a dozen international and UN organizations and endorsed by many more (https:
//digitalprinciples.org). In addition, several initiatives emerged around ‘responsible
data’ efforts, crafting principles and practical recommendations on how to assure data
security and adequate access (https://responsibledata.io/). And in the UAV community, a code of conduct was authored and agreed (werobotics.org/codeofconduct/).
Contributing to this work, Table 2.2 presents nine core ideas on implementing technology tools based on a ‘backwards’ analysis from risk assessment first to mitigation
measures suggestions. This list is not necessarily comprehensive, and specific recommendations would depend on specific technologies and contexts. Yet, this first
offering can help start conversations and be further refined with practitioners.
Back to low-tech—and sometimes no-tech
Broadly speaking, there are four types of circumstances when it may be better not
to use technologies for humanitarian purposes, as the inherent risk would outweigh
or overshadow possible benefits (Table 2.3).
Specifically, the following recommendations apply to the different technology
types:
When using mobile phone-based systems, do not…
• …use phone-based systems to collect sensitive data that could put beneficiaries
at risk. Information related to gender-based violence, the location of persecuted
people or financial and health information that could cause stigmatization cannot
be reliably secured when transferred through phone networks.
• …use it for short-term projects or without continuity. The set-up and familiarization costs only pay off if phone-based systems are used over a long time or for
several projects.
• …create a new mechanism where other, similar mechanisms already exist or are
planned. With too many systems in place, aid recipients can be confused and are
less likely to use any.
• …use it if you do not have the capacity to process feedback and follow-up. Beneficiaries will expect follow-up when using phone systems. Lack of response can
harm trust and reputation.
• …simply replace other monitoring or feedback approaches. Phone systems are
not sufficient in themselves as phone ownership is biased and network coverage
uneven.
