A survey of public attitudes toward secondary research governance oversight: Evidence from Singapore's TRUST platform.
Health data platforms and biobanks worldwide face challenges in maintaining social licence to operate (SLO) while enabling beneficial research. While technical safeguards can mitigate privacy risks, public expectations for governance oversight processes remain unclear. This study examines public attitudes toward health data governance oversight using Singapore's national TRUST platform as a case study. We conducted an online survey of 453 respondents from the Health Opinion Panel Singapore (HOPS) panel in Singapore between September and October 2024. Respondents evaluated four hypothetical research scenarios involving different data users (government agencies, overseas private companies, international universities) and indicated whether additional Ministry of Health (MOH) review should be required despite 2-5 weeks procedural delays. We analysed support rates for this additional review, reasons for support or opposition, and responses about privacy-utility trade-offs. Strong public support for MOH oversight emerged across all scenarios (80-89%), with government accountability as the primary reason (68-76% of supporters). Support was the highest for research involving overseas private companies (89%) and lowest for domestic government research (80%). Respondents demonstrated sophisticated risk-benefit, context-dependent reasoning: 69% accepted privacy risks for direct personal benefits (retaining contact information for cancer risk notification), while 82% endorsed stringent protections for vulnerable populations (CCTV monitoring for rare disease research despite research impediments). The Singaporean public expects comprehensive ethical oversight extending beyond privacy protection to encompass accountability, scientific validity, and social justice considerations. Consistent acceptance of procedural delays demonstrates that SLO depends on procedural justice rather than operational efficiency. These findings support implementing risk-proportionate governance frameworks that maintain robust baseline oversight while allowing context-sensitive intensification based on research characteristics and stakeholder involvement.
- Research Article
26
- 10.1016/j.geoforum.2017.07.008
- Jul 18, 2017
- Geoforum
Social license to operate: Not a proxy for accountability in water governance
- Research Article
1
- 10.1163/22116427_009010007
- Jan 1, 2017
- The Yearbook of Polar Law Online
This article focuses on the participatory rights of local people living in the areas of extensive oil industry operations in the Izhemskii district of the Komi Republic in Russia. The district has long been suffering from oil leaks and resulting negative environmental impacts. Lukoil-Komi bought the business directly after the Soviet era and inherited the ecological threats related to old and rusty pipelines. Lukoil-Komi has promised to put things in order, but a great deal remains to be done.This article scrutinizes how statutory law and private governance interact in protecting the participatory rights of local people living in the vicinity of oil production in Komi. First, we evaluate what participatory rights Russian legislation guarantees to local people when oil production arrives in a new area or when new wells are being explored or opened. Second, we elaborate how the major oil company in the region – Lukoil-Komi – fulfills its corporate social responsibility (CSR) in the area of participatory rights and how local people feel about their possibility to exercise their participatory rights. As participatory rights, we discuss both procedural justice with public hearings and distributive justice in the form of benefit-sharing between the company and local community. The wider perspective on participation is due to Russian CSR practices. In Russia, companies tend to earn their Social License to Operate (SLO) through benefit-sharing, often within private governance. This practice is based on the social partnership agreements between authorities and companies. These contracts have path-dependent features resembling earlier Soviet solutions. The same can be claimed to apply to a wider SLO with more focus on local communities. We argue that Lukoil-Komi has not yet been able to achieve an SLO (local acceptance) due to the lack of participatory rights and continuing environmental problems. Most local people are not willing to trade a clean environment and participatory rights for the social benefits the company offers. However, the social partnership agreement concluded between Lukoil-Komi and a local NGO, Izvatas, could be a step forward in achieving a local SLO.
- Research Article
6
- 10.1080/13669877.2024.2315999
- Feb 1, 2024
- Journal of Risk Research
Cultivating seafood in water environments, global aquaculture production is on the rise. As the sector grows, however, so too do challenges in securing the necessary social license to operate (SLO): ongoing approval from various stakeholders. Previous research in both risk communication and SLO suggests that perceived justice plays a foundational role in establishing legitimacy and subsequent public acceptance and approval. Yet, gaps in our understanding of both justice and SLO – as well as the relationships between these concepts – remain. In this study, we approach SLO as a stage model, applying a four-factor model of justice (including interpersonal, procedural, distributive, and informational justice) to examine whether – and if so, how – justice factors and their associated rules may be differently salient at SLO stages among stakeholders associated with siting land-based recirculating aquaculture facilities in three U.S. communities. Results of qualitative in-depth interviews with stakeholders at each site (n = 55) demonstrate how various justice rules are distinctly embedded in certain SLO stages, and that such rules may function as stage shift factors, moving communities toward granting or withholding social license for these projects. Theoretical and practical implications of this research are presented.
- Single Report
2
- 10.18235/0003820
- Dec 1, 2021
The Latin America and the Caribbean region has benefited significantly from economic growth driven by the extractive sector. At the same time, the region has experienced high levels of conflicts related to this sector. This paper presents an overview of citizens' perceptions of the extractive industries in Bolivia, Colombia, Ecuador, Peru, and Venezuela. Using a representative sample for each country, we identify regional and country-specific determinants of the Social License to Operate (SLO). The SLO is an unwritten license of social approval accorded to extractive projects by citizens. In this paper, we investigate a generalized version of the SLO, capturing public sentiment toward the mining and the oil and gas sectors in general. While our findings confirm that perceptions vary across countries, we show that governance is the strongest predictor of trust between citizens and the extractive sector, which is consistent with the evidence in the literature. In addition, procedural justice, distributive justice, and nationalism play essential roles in shaping individuals' attitudes. These findings suggest that strengthening government institutions could contribute to the prevention of conflict around extractive industries.
- Research Article
63
- 10.1145/3106774
- Dec 11, 2017
- ACM Transactions on Intelligent Systems and Technology
Human mobility data are an important proxy to understand human mobility dynamics, develop analytical services, and design mathematical models for simulation and what-if analysis. Unfortunately mobility data are very sensitive since they may enable the re-identification of individuals in a database. Existing frameworks for privacy risk assessment provide data providers with tools to control and mitigate privacy risks, but they suffer two main shortcomings: (i) they have a high computational complexity; (ii) the privacy risk must be recomputed every time new data records become available and for every selection of individuals, geographic areas, or time windows. In this article, we propose a fast and flexible approach to estimate privacy risk in human mobility data. The idea is to train classifiers to capture the relation between individual mobility patterns and the level of privacy risk of individuals. We show the effectiveness of our approach by an extensive experiment on real-world GPS data in two urban areas and investigate the relations between human mobility patterns and the privacy risk of individuals.
- Research Article
- 10.3390/buildings14082465
- Aug 9, 2024
- Buildings
The key to obtaining the Social License to Operate (SLO) for businesses in the not-in-my-backyard (NIMBY) infrastructure projects is the justice of the process. The study constructs a model to analyze the effect of the four components of procedural justice (procedural regulations and the behavior and attitudes of the government and construction enterprises) on the SLO. A large-scale questionnaire survey is conducted to assess the role and the extent of the influence of these four components in obtaining the SLO for NIMBY infrastructures. The results of Structural Equation Modeling (SEM) and mediation effects tests show that procedural justice significantly influences the SLO for NIMBY infrastructure projects. All four components significantly improve community trust and social acceptance of the project. The construction enterprise’s informal treatment of the public’s behavior and attitudes has the largest influence, whereas the government’s formal treatment of the public’s behavior and attitudes has the least influence. The findings provide theoretical and practical guidance for improving the SLO for NIMBY infrastructure projects and promoting the sustainable development of these projects.
- Research Article
- 10.1002/pra2.1048
- Oct 1, 2024
- Proceedings of the Association for Information Science and Technology
ABSTRACTIn recent years, there has been an increase in the openness of government data. Data storytelling has emerged as a means to enhance communication by transforming mundane data into easily understandable narratives. However, it is crucial to pay attention to privacy risks. This paper delves into the concept of storytelling government data, integrating cognitive reasoning and the S‐O‐R model, and evaluates privacy risks. Through comparative experiments and interviews, this study examines how users may infer sensitive information. The research reveals that storytelling data has a positive impact on users' cognition. De‐storytelling, on the other hand, can mitigate privacy risks, reduce information relevance, simplify narratives, and strike a balance between user experience and privacy. Building on this research, the paper proposes a strategy to address privacy risks, recommends strengthening privacy protection awareness from the perspectives of both users and platforms, optimizing data presentation methods, reducing the risk of sensitive information leakage, and ensuring the convenience and security of government data disclosure.
- Book Chapter
9
- 10.1007/978-3-319-66284-8_35
- Jan 1, 2017
Mobility data are an important proxy to understand the patterns of human movements, develop analytical services and design models for simulation and prediction of human dynamics. Unfortunately mobility data are also very sensitive, since they may contain personal information about the individuals involved. Existing frameworks for privacy risk assessment enable the data providers to quantify and mitigate privacy risks, but they suffer two main limitations: (i) they have a high computational complexity; (ii) the privacy risk must be re-computed for each new set of individuals, geographic areas or time windows. In this paper we explore a fast and flexible solution to estimate privacy risk in human mobility data, using predictive models to capture the relation between an individual’s mobility patterns and her privacy risk. We show the effectiveness of our approach by experimentation on a real-world GPS dataset and provide a comparison with traditional methods.
- Research Article
13
- 10.1002/spy2.101
- Dec 13, 2019
- SECURITY AND PRIVACY
Data protection impact assessments (DPIAs) aim to identify, rank, and mitigate privacy risks. Even though DPIAs are legally mandated in some cases and privacy professionals perform DPIAs on a daily basis, facilitating the systematic measurement of privacy risks is an open problem. Research on privacy risk measurement often does not take into account the practical needs and requirements for DPIAs in real organizations. In this article, we fill this gap by reporting on focus groups we held with a diverse group of privacy professionals. Through thematic analysis, we identify three themes that emerged from the focus groups: (a) how privacy in the contemporary society affects privacy risk assessment; (b) current practices and procedures in privacy risk assessment; and (c) common issues and challenges. Based on these themes, we identify future research directions for privacy risk measurement. Our article can help to ground research on privacy risk measurement in practical challenges faced by privacy professionals.
- Book Chapter
6
- 10.1007/978-981-13-8969-6_2
- Aug 29, 2019
The imminent introduction of the Data Protection Act in India would make it necessary for almost all enterprises, dealing with personal data, to implement privacy-specific controls. These controls would serve to mitigate the risks that breach the privacy properties of user data. Hence, the first step toward implementing such controls is the execution of privacy risk assessment procedures that would help elicit the privacy risks to user data. All user data are processed/managed by one or more business processes. Hence, assessment of privacy risks to user data should consider the vulnerabilities within, and threats to, corresponding business process. It should also consider different perspectives, namely business, legal and contractual needs, and users’ expectations, during the computation of data privacy values. This paper proposes such a comprehensive methodology for identifying data privacy risks and quantifying the same. The risk values are computed at different levels (privacy property level, business process level, etc.) to help both senior management and operational personnel, in assessing and mitigating privacy risks.
- Research Article
41
- 10.1016/j.exis.2018.10.006
- Oct 19, 2018
- The Extractive Industries and Society
Unconventional gas development in Australia: A critical review of its social license
- Research Article
1
- 10.1007/s10791-025-09551-z
- Apr 30, 2025
- Discover Computing
As artificial intelligence continues to drive advancements in computer vision, particularly in areas such as image analysis, object detection, and facial recognition, the ability to accurately recognize patterns in visual data has become a central focus of research. However, alongside these advances, concerns about the privacy risks associated with the training data used in AI models have also gained prominence. Deep learning models, frequently employed in computer vision tasks, can unintentionally expose sensitive information from the data they are trained on, raising the need for comprehensive research into privacy-preserving techniques. This paper explores the intersection of AI-driven pattern recognition and the privacy risks involved in training models on image data. Existing studies show that attackers can exploit the gradients from deep learning processes to reconstruct original image data, including personal and identifiable information, such as facial features. By iteratively adjusting input data, attackers can minimize the difference between the gradients of the random and stolen data, leading to the full reconstruction of private images. Current privacy protection methods fall short of explaining the relationship between an attacker’s capacity to recover visual data and the structure of the targeted model. This paper introduces a novel privacy auditing framework that directly assesses the extent to which gradient-based attacks can reconstruct sensitive data. Unlike traditional methods, which mainly focus on mitigating privacy risks through model regularization or data obfuscation, our approach provides a systematic and quantitative evaluation of gradient leakage, filling a critical gap in existing privacy protection techniques. This paper investigates the relationships among reconstructed data, model gradients, and the original input data in the context of computer vision. By formalizing the connection between gradient similarity and data similarity, we propose a novel methodology that quantifies the vulnerability of deep learning models to data reconstruction attacks. Building on these insights, we propose a novel privacy auditing method aimed at evaluating the privacy risks associated with deep learning models used in pattern recognition for image data.
- Research Article
8
- 10.3390/sym12091576
- Sep 22, 2020
- Symmetry
It has been proven in research literature that the analysis of encrypted traffic with statistical analysis and machine learning can reveal the type of activities performed by a user accessing the network, thus leading to privacy risks. In particular, different types of traffic (e.g., skype, web access) can be identified by extracting time based features and using them in a classifier. Such privacy attacks are asymmetric because a limited amount of resources (e.g., machine learning algorithms) can extract information from encrypted traffic generated by cryptographic systems implemented with a significant amount of resources. To mitigate privacy risks, studies in research literature have proposed a number of techniques, but in most cases only a single technique is applied, which can lead to limited effectiveness. This paper proposes a mitigation approach for privacy risks related to the analysis of encrypted traffic which is based on the integration of three main components: (1) A machine learning component which proactively analyzes the encrypted traffic in the network to identify potential privacy threats and evaluate the effectiveness of various mitigation techniques (e.g., obfuscation), (2) a policy based component where policies are used to enforce privacy mitigation solutions in the network and (3) a network node profile component based on the Manufacturer Usage Description (MUD) standard to enable changes in the network nodes in the cases where the first two components are not effective in mitigating the privacy risks. This paper describes the different components and how they interact in a potential deployment scenario. The approach is evaluated on the public dataset ISCXVPN2016 and the results show that the privacy threat can be mitigated significantly by removing completely the identification of specific types of traffic or by decreasing the probability of their identification as in the case of VOIP by 50%, Chat by 40% and Browsing by 33%, thus reducing significantly the privacy risk.
- Research Article
1
- 10.47745/ausleg.2022.11.2.03
- Dec 15, 2022
- Acta Universitatis Sapientiae, Legal Studies
The development and operation of an AI solution generally requires large amounts of data. This may involve processing of personal data, which implies privacy risks for the data subjects and the obligation to comply with data protection rules for data controllers. Privacy enhancing technologies (PETs) can help enhance data collection and mitigate privacy risks posed by the development of AI solutions. In this context, this thesis proposes to present a set of emerging technologies that address privacy risks characteristic to machine learning models and enable privacy-preserving machine learning. The essay will highlight three state-of-the-art PET solutions: homomorphic encryption, secure multi-party computation and differential privacy.
- Research Article
- 10.3390/mining5040072
- Nov 6, 2025
- Mining
This study examines Panama’s 2023 mining restrictions to illuminate persistent legitimacy crises in extractive governance. Employing a qualitative case study, it draws on 25 semi-structured interviews with government officials, industry representatives, Indigenous leaders, local communities, mining critics and other civil society actors, alongside policy and document analysis. Findings suggest that legitimacy reconstruction relies on four interdependent conditions: procedural justice, institutional trust, epistemic legitimacy, and relational governance. Stakeholders consistently emphasized transparency, capacity building, and inclusive engagement as essential for future mining activity, underscoring that technical standards alone are insufficient without credible institutions. Building on—but extending beyond—frameworks such as Social License to Operate (SLO) and Free, Prior and Informed Consent (FPIC), this paper offers Social Legitimacy for Mining (SLM) as a provisional, co-produced framework. Developed through literature synthesis and refined by diverse stakeholder perspectives, SLM is applied in Panama as an illustrative proof of concept that may inform further research and practice, while recognizing the need for additional adaptation across jurisdictions.