scieee AI-readable full text Open interactive document viewer

Standards for digital cooperation

Girard, Michel

Abstract

EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.

Full text

Girard, Michel Working Paper Standards for digital cooperation CIGI Papers, No. 237 Provided in Cooperation with: Centre for International Governance Innovation (CIGI), Waterloo, Ontario Suggested Citation: Girard, Michel (2020) : Standards for digital cooperation, CIGI Papers, No. 237, Centre for International Governance Innovation (CIGI), Waterloo (Ontario) This Version is available at: https://hdl.handle.net/10419/299709 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by-nc-nd/3.0/ CIGI Papers No. 237 — January 2020 Standards for Digital Cooperation Michel Girard CIGI Papers No. 237 — January 2020 Standards for Digital Cooperation Michel Girard About CIGI We are the Centre for International Governance Innovation: an independent, non-partisan think tank with an objective and uniquely global perspective. Our research, opinions and public voice make a difference in today’s world by bringing clarity and innovative thinking to global policy making. By working across disciplines and in partnership with the best peers and experts, we are the benchmark for influential research and trusted analysis. Our research initiatives focus on governance of the global economy, global security and politics, and international law in collaboration with a range of strategic partners and have received support from the Government of Canada, the Government of Ontario, as well as founder Jim Balsillie. À propos du CIGI Au Centre pour l'innovation dans la gouvernance internationale (CIGI), nous formons un groupe de réflexion indépendant et non partisan doté d’un point de vue objectif et unique de portée mondiale. Nos recherches, nos avis et nos interventions publiques ont des effets réels sur le monde d'aujourd’hui car ils apportent de la clarté et une réflexion novatrice pour l’élaboration des politiques à l’échelle internationale. En raison des travaux accomplis en collaboration et en partenariat avec des pairs et des spécialistes interdisciplinaires des plus compétents, nous sommes devenus une référence grâce à l’influence de nos recherches et à la fiabilité de nos analyses. Nos projets de recherche ont trait à la gouvernance dans les domaines suivants : l’économie mondiale, la sécurité et les politiques internationales, et le droit international. Nous comptons sur la collaboration de nombreux partenaires stratégiques et avons reçu le soutien des gouvernements du Canada et de l’Ontario ainsi que du fondateur du CIGI, Jim Balsillie. Credits Director, Global Economy Robert Fay Program Manager Heather McNorgan Publisher Carol Bonnett Senior Publications Editor Jennifer Goyder Graphic Designer Melodie Wakefield Copyright © 2020 by the Centre for International Governance Innovation The opinions expressed in this publication are those of the author and do not necessarily reflect the views of the Centre for International Governance Innovation or its Board of Directors. For publications enquiries, please contact publications@ cigionline.org. This work is licensed under a Creative Commons Attribution — Non-commercial — No Derivatives License. To view this license, visit (www.creativecommons.org/licenses/by-nc-nd/3.0/). For re-use or distribution, please include this copyright notice. Printed in Canada on Forest Stewardship Council® certified paper containing 100% post-consumer fibre. Centre for International Governance Innovation and CIGI are registered trademarks. 67 Erb Street West Waterloo, ON, Canada N2L 6C2 www.cigionline.org Table of Contents vi About the Author vi About Global Economy vii Acronyms and Abbreviations 1 Executive Summary 1 Introduction 2 The Need for International Digital Cooperation 4 What Standards Are and Why They Matter 4 The Case for Global Data Standards 6 No New UN Body in Sight 8 Elusive Standards for Data Value Chains and Governance 12 Designing a New Approach 14 DSTF 17 Looking Forward 18 Works Cited vi CIGI Papers No. 237 — January 2020 • Michel Girard About the Author Michel Girard is a CIGI senior fellow. Michel’s work at CIGI relates to standards for big data and artificial intelligence (AI). His research strives to drive a dialogue on what standards are and why they matter in these emerging sectors of the economy. He highlights issues that should be examined in the design of new technical standards governing big data and AI in order to spur innovation while also respecting privacy, security and ethical considerations. He will offer policy recommendations to facilitate the use of big data and AI standards and their incorporation into regulatory and procurement frameworks. In addition to his work at CIGI, Michel provides standardization advice to help innovative companies in their efforts to access international markets. He contributes to the CIO Strategy Council’s standardization activities and the Chartered Professional Accountants of Canada's Foresight Initiative on data governance. Michel has 22 years of experience as an executive in the public and not-for-profit sectors. Prior to joining CIGI, Michel was vice president, strategy at the Standards Council of Canada where he worked from 2009 to 2018. Previously, he was director of the Ottawa office at the Canadian Standards Association, director of international affairs at Environment Canada, corporate secretary at Agriculture Canada, and acting director of education and compliance at the Canadian Environmental Assessment Agency. He holds a Ph.D. and a master’s degree in history from the University of Ottawa. About Global Economy Addressing the need for sustainable and balanced economic growth, the global economy is a central area of CIGI expertise. The Global Economy initiative examines macroeconomic regulation (such as fiscal, monetary, financial and exchange rate policies), trade policy and productivity and innovation policies, including governance around the digital economy (such as big data and artificial intelligence). We live in an increasingly interdependent world, where rapid change in one nation’s economic system and governance policies may affect many nations. CIGI believes improved governance of the global economy can increase prosperity for all humankind. viiStandards for Digital Cooperation Acronyms and Abbreviations 5G fifth-generation AI artificial intelligence APIs Application Programming Interfaces COGOV co-governance architecture CSTD Commission on Science and Technology for Development DNS Domain Name System DSB Digital Stability Board DSTF Data Standards Task Force DTP Data Transfer Project ETSI European Technology Standards Institute FAAMG Facebook, Amazon, Apple, Microsoft and Google FAO Food and Agricultural Organization FSB Financial Stability Board IAB Internet Architecture Board ICAO International Civil Aviation Organization ICT information and communications technology IEC Electrotechnical Commission IEEE Institute of Electrical and Electronics Engineers IEEE SA Institute of Electrical and Electronics Engineers Standards Association IETF Internet Engineering Task Force IGC International Grand Committee IGF Internet Governance Forum IMO International Maritime Organization IoT Internet of Things IP intellectual property ISO International Organization for Standardization ITU International Telecommunications Union JTC1 Joint Technical Committee 1 SARPs standards and recommended practices SDGs Sustainable Development Goals SDOs standards development organizations TC Technical Committee UNCTAD United Nations Conference on Trade and Development W3C World Wide Web Consortium WHO World Health Organization WMO World Meteorological Organization WTO World Trade Organization 7Standards for Digital Cooperation technology to be deployed globally, such as the rise of the internet and the World Wide Web. Early on, a number of independent and, in some cases, competing communication networks were created, which could not connect to one another. Over time, each constituent agreed to be bound by technical standards developed and maintained by a small number of standard-setting bodies that were created for the sole purpose of setting one set of rules to launch one internet. Through these technical standards, one global physical network layer was established, setting the base for one global transport network layer. A loose governance structure was set up through the following standard-setting bodies: → The Internet Society is the overall coordination body for the Internet. It was created in 1992 at the bequest of the US Department of Defense. Its global headquarters are located in the United States, with an office in Switzerland and regional bureaus covering Latin America and the Caribbean, Africa, Asia, North America and Europe. It operates as a not-for-profit organization and has a global membership base of more than 100,000 organizational and individual members.13 → The Internet Society houses the IETF and the Internet Architecture Board (IAB): – The IETF provides technical direction for the internet. It develops technical standards through an open and consensus-based process that is often described as rough consensus and running code. In 2014, a search identified 10,263 normative documents produced by the IETF.14 – The IAB oversees the work of the Internet Research Task Force, which also develops technical standards.15 → World Wide Web standards are set up by the W3C, which is open to both organizations and individuals.16 → Internet Protocol Numbers are managed bythe Internet Assigned Numbers Authority using a standardized protocol.17 13 See www.internetsociety.org/internet/who-makes-it-work. 14 See www.internetsociety.org/about-the-ietf/; http://www.arkko.com/ tools/allstats/. 15 See www.iab.org/; https://irtf.org/. 16 See www.w3.org/. 17 See www.iana.org/. → The internet DNS is based on IETF standards and recommendations.18 It should be noted that these engineering standardsetting bodies are not mandated to address the policy and governance issues that began to surface as the internet grew in popularity and as new applications and global social media and e-commerce platforms were deployed. The governance issues identified by the CSTD have therefore not found a “home” and have not been addressed since the report’s publication in 2015. UN High-level Panel on Digital Cooperation In 2018, UN Secretary-General António Guterres convened a High-Level Panel on Digital Cooperation to take a fresh look at this issue. Co-chaired by Melinda Gates (Bill & Melinda Gates Foundation) and Jack Ma (Alibaba Group), the panel looked at ways to strengthen cooperation in the digital space among governments, the private sector, civil society, international organizations, academia, the technical community and other relevant stakeholders (Guterres 2019). The panel’s report notes the lack of global standards supporting data value chains and data governance. It acknowledges that standards are needed to create international digital collaboratives in support of the UN SDGs. It states that ad hoc responses could fragment the interconnectedness that defines the digital age and that competing standards and approaches would reduce trust and discourage cooperation. It therefore proposes “upholding open standards and interoperability to facilitate collaboration” as one of the values that should shape the development of global digital cooperation (Digital Cooperation 2019, 12). The high-level panel examined the need for technical standards to create new value chains and address interoperability issues. The following statements in the report are noted: → It acknowledged that new technical standards for data value chains are needed in order to pool data from around the world and create data commons to resolve problems in areas such as health, agriculture and the environment. 18 See www.ietf.org/rfc/rfc1035.txt. 8CIGI Papers No. 237 — January 2020 • Michel Girard → Data commons require standards for interoperability, rules on access and safeguards to ensure privacy and security. → There is scope to launch collaborative projects to test the interoperability of data, standards and safeguards across the globe. → There is an opportunity to take another look at existing digital infrastructure protocols and standards in order to bring more people online. The report also calls for the development of new data governance standards to address critical gaps: → It proposes the creation of audits and certification schemes to monitor compliance of AI systems with technical and ethical standards. → Regarding consumer protection issues, it points to the lack of international standards and effective compliance mechanisms for the exchange of data in order to better manage data flows; standards regarding the interoperability of mobile money systems; as well as standards for managing data consent when children use devices. → Regarding cyber security, it notes that while many best practices and standards exist, they often address only narrow parts of a vast and diverse universe that ranges from talking toys to industrial control systems. → It proposes the development of credible data governance standards to rebuild consumer trust in big data analytics given recent privacy breaches. The report examined what the United Nations could do to enhance digital cooperation. It noted the growing number of mechanisms accountable to generate norms, standards, policies and protocols in the digital space. In 2015, as noted above, the CSTD identified 680 distinct organizations operating around the internet. Four years later, the estimated number had risen to more than a thousand, resulting in an even more fragmented and diffuse standards cooperation and governance landscape (ibid., 6). The report refrains from recommending the creation of a new, stand-alone body accountable to coordinate the development of suitable data standards for data value chains and data governance. There does not seem to be the appropriate level of support to warrant the creation of a new UN-based organization to coordinate data standards (both technical and governance), even though they are understood to be distinct from internet standards. Rather, the report examined three options (outlined below) and proposes the launch of a bottom-up stakeholder engagement process to design an appropriate global digital cooperation architecture, including governance mechanisms, funding models and modes of operation. It is not clear how the proposed options would address the need for new technical standards to frame data value chains and manage data governance. Following the release of the report, organizations such as the Geneva-based Digital Watch Observatory took a closer look at the recommendations and organized an international workshop entitled Unpacking the High-Level Panel’s report: Contributions from Geneva.19 A number of actions were proposed to make progress on the key recommendations of the report and to test the international appetite for pursuing one of the three proposed governance mechanisms. Unfortunately, no specific action was put forward on the need to enhance coordination and collaboration on the standards front. Standards and conformity assessment, the foundation upon which international digital cooperation mechanisms must be articulated, appears to have been left for others to settle. Elusive Standards for Data Value Chains and Governance Global technical and governance data standards will contribute to lowering the costs of setting up and operating digital collaboration platforms and, through interoperability standards, will facilitate data sharing between users and between platforms. However, without an international standards coordination body focused on developing the right standards, digital cooperation will remain a pipe dream. Thousands of global technical standards were necessary to support the creation of the internet and the World Wide Web. A large number of standards will also be required to create international digital cooperation platforms in all major sectors of the economy and manage a broad range of data governance issues. 19 See https://dig.watch/events/unpacking-high-level-panels-reportcontributions-geneva. 9Standards for Digital Cooperation Box 3: Three Options Proposed by the UN High-level Panel on Digital Cooperation for the Establishment of a Data Governance Mechanism Using Existing Institutions Option 1: Internet Governance Forum (IGF) Plus (IGF Plus) would build on the existing IGF, which was established by the World Summit on Information Society in Tunis in 2005. The IGF is a forum for policy dialogue. It represents the main global space convened by the United Nations for addressing internet governance and digital policy issues. It has a small secretariat based in Geneva, Switzerland, and has been designed to be seen as a neutral, non-duplicative and non-binding process to facilitate the exchange of information and best practices and to identify issues and make known its findings, to enhance awareness and build consensus and engagement. It achieves this dialogue through its annual meetings, topic-specific workshops, dynamic coalitions, best practice forums and other engagement mechanisms. A Best Practices Working Forum on IoT, big data and AI was created in 2018 and meets regularly. The highlevel panel proposed that the mandate of the IGF could be expanded by adding a Policy Incubator, which would create necessary policies and norms for public discussion and adoption by regulators. Although its focus is currently articulated around the internet in general, its mandate could presumably be broadened to data governance, data value chains and the regulation of the FAAMG platforms. The IGF Trust Fund would be a dedicated fund for the IGF Plus. There is no mention of the need for data standards coordination. Option 2: Distributed co-governance architecture (COGOV) relies on the self-forming “horizontal” network approach used by the IETF, the Internet Corporation for Assigned Names and Numbers, the W3C, the Regional Internet Registries, the Institute of Electrical and Electronics Engineers (IEEE) and others to host networks to design norms and policies. This proposal would extend a network approach to issues affecting the broader digital economy and society. The COGOV architecture decouples the design of digital norms from their implementation and enforcement. It seeks to rapidly produce shared digital cooperation solutions, including norms, and publish them for stakeholders to consider and potentially adopt. These norms would be voluntary solutions rather than legal instruments. In themselves, the COGOV networks would not have governing authority or enforcement powers. However, the norms could be taken up by government agencies as useful blueprints to establish policies, regulations or laws. The COGOV would aim to establish clear guardrails for digital technologies. It would identify digital governance issues, form digital cooperation networks and support networks through digital cooperation platforms. Once developed, norms would be deployed by nation-states through laws and regulations. Governments would adjudicate resolve disputes and conflicts. Option 3: The proposed Digital Commons Architecture would aim to synergize efforts by governments, civil society and businesses to ensure that digital technologies promote the UN SDGs and to address risks of social harm. It would comprise multi-stakeholder tracks to create dialogue around emerging issues and communicate use cases and problems to be solved to stakeholders, and an annual meeting to act as a clearing house. Each track could be owned by a lead organization. Light coordination of the tracks, and servicing of the annual meeting where their reports are considered, could be ensured by a small secretariat housed within the United Nations. Setting norms would be coordinated through the annual meetings where the output of the various tracks would be discussed as well as implementation of the governance guidance produced by these tracks through a “soft” review of reports by stakeholders. Once again, this falls short of the creation of new standards bodies for the coordination or development of data standards, such as the IETF and W3C did for the internet. 10 CIGI Papers No. 237 — January 2020 • Michel Girard Standard-setting activities in the ICT sector can only be described as extraordinarily complex, opaque, evolutionary, bottom up and unpredictable. In addition to hundreds of established SDOs, the sector also relies an even larger number of standard consortia and open-source software development platforms. As a result, making sense of standardization activities covering data value chains and data governance around the globe will require a large-scale effort. There are no registries of standards and conformity assessment programs in place and academic studies on the subject are sparse. In Canada, the Standards Council of Canada recently announced the creation of a standardization collaborative on big data analytics in order to assemble an inventory of available standards and report on standardization activities currently taking place in the sector.20 This inventory is undertaken manually. Armed with that information, four working groups will identify standardization gaps and propose a standards road map to fill some of the critical gaps identified through the inventory. The inventory work will prove to be labour intensive given the absence of a central registry on data standards and conformity assessment programs. A cursory review reveals a dozen major international standards bodies and consortia involved in developing standards and specifications related to big data analytics and some of the key data governance issues that need to be addressed, notably ethical dimensions of AI and privacy. However, no comprehensive standards development activities supporting digital cooperation and the creation of data value chains have been uncovered. SDOs In 1987, the ISO and the International Electrotechnical Commission (IEC) established the Joint Technical Committee 1 (JTC1) by merging the ISO Technical Committee (TC) 97 (Information Technology) and the IEC TC 83 (Information Technology Equipment). The JTC1 is seen by many as the leading body making progress in coordinating activities for data management, big data and AI. Its purpose is to develop, maintain and promote standards in the fields of information technology and ICT. Since its creation, the JTC1 has published more than 3,200 standards and publicly available specifications covering a wide array of subjects including programming 20 See www.scc.ca/en/news-events/news/2019/leading-experts-join-scceffort-transform-data-governance-landscape. languages, interconnection of information technology equipment, user interfaces, cloud computing, cyber security, data security, big data, data management and interchange and, more recently, the IoT and AI.21 The JTC1 manages a substantive proportion of the two organizations’ standards catalogue (ISO maintains more than 20,000 standards and the IEC more than 10,000). The JTC1 operates through a matrix of subcommittees, working groups and advisory groups, which are connected to more than 100 liaison bodies. For example, Subcommittee 42 focuses on big data and AI through four working groups: → Working Group 1: Foundational standards (concepts and terminology) → Working Group 2: Big data (overview, definitions, reference architecture) → Working Group 3: Trustworthiness (biases in AI systems, overview, robustness of neural networks) → Working Group 4: Use cases and applications The Institute of Electrical and Electronics Engineers Standards Association (IEEE SA) has been active in the ICT sector for decades through a large number of technical standards for electronic products, such as the Ethernet and WiFi, as well as software engineering management. In 2017, the IEEE had more than 1,100 active standards, with over 600 standards under development. Regarding big data analytics, the IEEE launched in 2017 a global consultation and outreach initiative called Ethically Aligned Design: A Vision for Prioritizing Human Well-being with Autonomous and Intelligent Systems. The IEEE is now spearheading the development of 15 ethical AI standards under its 7000 series ranging from algorithmic bias consideration to automated facial analysis technology with the help of more than 2,000 participants.22 The IEEE SA also launched the development of an Ethics Certification Program for Autonomous and Intelligent Systems, which represents the first attempt to design and deploy an international compliance mechanism toward ethical AI standards. If successful, the new program could provide certification for algorithmic bias, accountability and transparency.23 21 See www.iso.org/isoiec-jtc-1.html. 22 See https://ethicsinaction.ieee.org/. 23 See https://standards.ieee.org/industry-connections/ecpais.html. 11Standards for Digital Cooperation In 2018, the IEEE led the creation of OCEANIS, the Open Community for Ethics in Autonomous and Intelligent Systems, along with 15 SDOs that joined as founding members and 19 members from the private sector. It is designed to act as a high-level global forum for discussion, debate and collaboration for organizations interested in the development and use of standards to further the development of autonomous and intelligent systems. Its creation could spur greater collaboration and cooperation among standardsetting bodies focusing on algorithms, sensors, big data, ubiquitous networking and technologies.24 The ITU, the UN agency accountable for global standards covering telecommunications and ICT is the custodian of the International Telecommunication Regulations treaty. It maintains more than 4,000 normative documents, including standards. The ITU is an active player in the development of data sharing, IoT and smart cities standards. In 2017, the ITU created a focus group on machine learning for future networks, including 5G, in order to create a unified architecture framework. In 2018, it initiated a focus group on AI for health to create standardized benchmarks to evaluate AI algorithms used in health-care applications.25 The European Technology Standards Institute (ETSI) produces standards and specifications for ICT-enabled systems and is focusing on issues such as blockchain, AI, augmented reality and autonomous networks standards. ETSI has published more than 45,000 standards and specifications, which are routinely incorporated by reference in European regulations. It has an ambitious work program related to big data analytics.26 The IETF is actively engaged in standardization efforts for Application Programming Interfaces (APIs), IoT devices, privacy considerations, cyber security and metadata insertion. 24 See https://ethicsstandards.org/. 25 See www.itu.int/en/ITU-T/AI/Pages/default.aspx. 26 See www.etsi.org/committee/1640-sai. Standards Consortia and Open Source Platforms The ICT sector needed a myriad of standards and specifications to deploy digital technologies, hardware, software and the internet. This resulted in the creation of many hundreds of standards consortia. Studies have identified more than 400 ICT consortia operating in that space in the late 1990s (Biddle et al. 2012, 179). As policy research on standards is scarce, it is impossible to know how many data service providers, from IoT device manufacturers, API platforms and AI firms, are managing standards and specifications requirements in the big data analytics space. There is also a wide array of consortia bodies involved in the development of data standards, some focusing on data architecture, others engaged in sector-specific applications. For example, the Third Generation Partnership Project is developing standards underpinning 5G, IoT narrow-band radio technology and streaming.27 The Trusted Computer Group develops standards for APIs28 and The Open Group develops standards for architecture frameworks.29 Examples of standards consortia focusing on sector-specific applications include theClinical Data Interchange Standards Consortium,which deals with medical research data linked with health care, to enable information system interoperability and to improve medical research and related areas of health care;30 Energistics, which focuses on the development, adoption and maintenance of open data exchange standards for the oil and gas exploration and production industry;31 and SAE International is creating a consortium to develop best practices and standards for storing and sharing data acquired from shared micro-mobility services.32 Following the entry into force of the General Data Protection Regulation, a growing number of bodies have been created to develop appropriate standards regarding personal data privacy, portability and consent. Among the most promising projects is the 27 See www.3gpp.org/news-events/1607-iot. 28 See https://trustedcomputinggroup.org/wp-content/uploads/TSS_FAPI_ v0.94_r04_pubrev.pdf. 29 See https://publications.opengroup.org/standards/togaf. 30 See www.cdisc.org/newsletter/issue/third-quarter-2019/letter-presidentand-ceo. 31 See www.energistics.org/solutions/#streamline. 32 See www.sae.org/micromobility/. 12 CIGI Papers No. 237 — January 2020 • Michel Girard Data Transfer Project (DTP) from Google, Facebook, Microsoft and Twitter. The DTP started in 2018 and aims to develop technical standards for personal data portability “so that all individuals across the web could easily move their data between online service providers whenever they want.”33 Once these standards are in place, they could also be used to manage direct and automated data transfers between a source and a data access point, which is a necessary pre-condition for digital collaboratives to operate securely. The objective of another important data privacy standards development project called Solid is to decouple data from applications by offering a new architecture for the web. The project is led by Tim Berners-Lee, the inventor of the World Wide Web. It would allow individuals to choose where their data can be used and for what purpose by creating individual Solid PODs.34 The European Internet Privacy Engineering Network is also looking at standards development for data privacy.35 Finally, open-source platforms have become the main conduit to develop applications for big data analytics, from designing new algorithms to building data-sharing platform software. GitHub, the largest open-source software and coding development platform in the world, now boasts 40 million developers working together to host and review code, manage projects and build software. For example, GitHub hosts more than 34,000 public repositories focusing on machine learning, 25,000 devoted to APIs and 900 projects aimed at building collaborative digital platforms. It has become a major player in defining how big data analytics and digital cooperation will be shaped in the future.36 As this cursory review shows, standards activities are fragmented among many organizations. Better coordination would help ensure that the right interoperability standards are developed in order to create data value chains and international digital collaboration platforms. Additionally, data governance issues are not addressed in a systematic way. The current standards corpus would not be sufficient for organizations to develop corporate data policies that propose best practices for pervasive issues such as data ownership, intellectual 33 See https://datatransferproject.dev/dtp-overview.pdf. 34 See https://solid.inrupt.com/how-it-works. 35 See https://edps.europa.eu/data-protection/ipen-internet-privacyengineering-network_en. 36 See https://github.com/marketplace/category/api-management. property (IP) and copyright; data tagging and traceability; digital identity management; privacy and the protection of human rights; ethics; data security; and data residency requirements. Designing a New Approach Robust global standards and third-party certification programs are essential to launch an inclusive digital economy. Credible and enforceable global standards are needed for consumers and civil society to regain trust in big tech platforms. They are required to create a level playing field, where smaller firms can compete fairly against big tech platforms, and they represent the only available pathway to avoid an unwieldy patchwork of national regulations. With the right global data standards, the benefits of digitization to society can be maximized while the potential harms from global platforms managed by the private sector are minimized. It is unlikely, however, that a new UN data standard-setting body will be formed, as indicated earlier. There is no international consensus for a convention on digital cooperation and the creation of a stand-alone agency. The best-case scenario proposed by the United Nations would be to expand the role of existing agencies or networks. At first glance, neither the proposed IGF Plus, COGOV or the Digital Commons Architecture would be as effective as a dedicated data standards agency. Under a status quo scenario, where existing SDOs, consortia and open-source software platforms compete to develop industry standards and specifications, the current fragmented approach will continue. In the absence of a concerted effort on the part of regulators to play an active role in setting and enforcing global data governance standards through established organizations, software engineers and data scientists could be expected to continue to migrate away from traditional standard-setting bodies toward GitHub and the like. The sentiment among many software engineers toward traditional SDOs is that a system that retains strong roots in the nineteenth century is ill-suited to meet the demands of the twenty-first century. As a result, a patchwork of national regulations reflecting the divergent interests and value systems will be created. Over time, we may find ourselves with 13Standards for Digital Cooperation three or four mutually exclusive blocs between which little data will be willingly shared. In the absence of a global commitment to regulate data governance, there is little appetite among stakeholders to create a new data standards coordination body. Peter Cihon (2019), in a technical report entitled Standards for AI Governance: International Standards to Enable Global Coordination in AI Research and Development, argued that the JTC1 is in a better position to coordinate ethical AI standards work compared to other, non-World Trade Organization (WTO) sanctioned bodies such as the IEEE. Cihon argued that the challenge will be to attract AI scientists and researchers to participate in standards setting; many feel the field of AI safety is too young to engage in creating norms and compliance mechanisms (ibid.). It may, however, be possible to create a regional data standards coordination body. In a CIGI paper entitled A Plurilateral “Single Data Area” Is the Solution to Canada’s Data Trilemma, Susan Ariel Aaronson and Patrick Leblond (2019) proposed the creation of an International Data Standards Board. The organization would initially cover Canada, the European Union, the United States and Japan, but could expand to other nation-states. It would be accountable for devising common technical and governance standards. The standards would ensure a high degree of trust in the data-driven economy among individuals, consumers, workers, businesses and governments so that all forms of data could flow freely across borders. The International Data Standards Board would also be responsible for monitoring the single data area. Regular assessments would determine if participating member states are in compliance with the standards. The authors argued that such a body could not operate under the WTO as the issues requiring standardization are not limited to trade. The organization could be set up as a not-for-profit organization and report to a board of directors composed of representatives from participating nation-states and industry (ibid.). A similar diagnostic and approach were recently proposed by Ian Bremmer (2019) of the Eurasia Group. In his remarks at the GZERO Summit in Tokyo, Japan, Bremmer argued that the market for data and information is no longer global and is breaking in two. We are facing the development of two distinct tech ecosystems: one built by the private sector and loosely regulated by governments under US leadership, and another ecosystem dominated by the state in China. A fault line between the two emerging systems can be seen in data collection, the development of AI, the rollout of 5G, the deployment of IoT devices and defence and retaliation against cyber attacks. Bremmer called for the creation of a “digital WTO” to set future standards for AI, data, privacy, citizens’ rights and IP. The United States, Europe, Japan and like-minded countries that believe in online openness and transparency would lead the way in creating such an organization. China would have an economic and security incentive to want to join, “especially if it’s the only way Beijing can secure access to developed markets” (ibid.). Others are looking at creating global standards for data governance mechanisms to focus on core issues. In Europe, a collaborative called A New Governance: Standardization for Data Empowerment is calling for a new international agency to develop global data standards for personal data protection, circulation and portability. Members of the collaborative are concerned that many sectors are developing stand-alone privacy standards. They have noted initiatives in mobility, health care, administration, commerce, finance and insurance, entertainment, energy, telecom, human resources and education. These initiatives are recreating silos, which will be highly detrimental to the main goal of fostering personal data circulation and protection across sectors and boundaries (Privacy Tech 2019, 247). The organization proposed by the collaborative would be an independent and international standard coordination body. Members would define priorities for technological standards, terminologies and guidelines to allow free flow of data under the individuals’ control. The approach would combine a horizontal view with expert work groups (technical, design, legal, business, and so on), a sectoral approach with sector hubs (mobility, finance, health, administration, retail, and so on) and a cross-sectoral group. A technical board would coordinate the hubs and work groups with other standards organizations, legislators, regulators, academics, users, and so on (ibid., 252). Robert Fay, Global Economy director at CIGI, has also recently suggested the creation of a data governance body with a broad mandate. In a recent essay entitled “Digital Platforms Require a Global Governance Framework,” he proposed a new organization structured like the Financial Stability Board (FSB). The FSB, created after the 2008 financial crisis, was given a mandate by the Group of Twenty to “promote the reform of international financial regulation and supervision” with a role in standard 14 CIGI Papers No. 237 — January 2020 • Michel Girard setting and in promoting members’ implementation of international standards (Fay 2019, 28). Fay’s proposed Digital Stability Board (DSB) would be composed of a plenary body, which would set objectives and oversee the work of the board. It would consist of officials from countries that initially join the organization. It would work with standardsetting bodies, governments and policy makers, regulators, civil society and the platforms themselves via a set of working groups with clear mandates that would report back to the plenary. Funding would come from its member countries alongside voluntary donations and in-kind contributions via participation in the DSB working groups. It could report to the International Grand Committee on Big Data, Privacy and Democracy (IGC). The IGC, made up of a diverse set of 12 countries and more than 400 million citizens, has been active in investigating the behaviour of the FAAMG platforms, including their role in disseminating fake news. DSTF Given the need for data standards coordination to enhance digital cooperation, the lack of a clear mandate to create one under the UN umbrella and the fragmentation of standardization activities related to big data analytics, this paper proposes the creation a new institution that could be named the DSTF. Reporting to the proposed DSB plenary, it would be similar in structure to the IETF. The DSTF would be entrusted with a dual mandate: enabling the development of technical standards to create data value chains, and being accountable for the development of data governance standards to properly frame data collaboration platforms and the FAAMG platforms. The ultimate objective of the DSTF would be to create the required architecture for a “single data zone” where data can circulate freely between participating jurisdictions through a series of data collaboration platforms. Digital cooperation will involve the creation of complex data value chains. Just as with traditional supply chains for tangible products, each segment of a given data value chain will have specific roles and responsibilities, which will have to be described and categorized. In addition, data will go through a life cycle from creation to disposal, which will also have to be described and categorized. It should be anticipated that many standards and specifications will be required to properly frame data value chains. Codes, standards, guidelines, best practices and model technical regulations will be required to cover both the technical and governance layers. The structuring of the DSTF would need to reflect the new realities of the digital age. Classical forms of governance do not apply. Technology moves so fast that by the time decision makers gather to prepare, discuss, approve, ratify and implement a convention or new agreement, the landscape has changed entirely. Analogue policy making will not work in a digital world. In order to be responsive, the DSTF would need to develop standards in a shorter time frame than the two to three years generally required in traditional standard-setting bodies. Once developed, some of the standards could be expected to be “evergreen,” that is, to be updated on an ongoing basis in order to reflect new technologies and approaches and remain relevant. Traditional standard-setting bodies require a published standard to be reviewed every five years. Ontology, Semantics, DefinitionsandTerminology When industrial sectors were mostly vertical in nature, SDOs developed standards in silos. As a result, a multiplicity of domain-specific semantics, including product terminology, classification and properties were created and maintained, sometimes for many decades. With digitization, information is being generated and exchanged across sectors. This leads to a demand for universal semantics, which should follow a common ontological foundation. Big data analytics are, by definition, higher-level functions and will need to be based on a common ontology. It is a prerequisite for interoperability. The DSTF would create a working group to lead the development and adoption of the right set of foundational standards covering ontology, semantics, definitions and terminology. These would be used by other working groups to ensure consistency across data value chains. They could also be used by regulators within the single data zone. Technical Standards for Data Value Chains The internet and the World Wide Web will provide the infrastructure backbone on which data value chains will be built. As outlined in a 15Standards for Digital Cooperation recent CIGI paper entitled Standards for the Digital Economy, data value chains are composed of three segments: data collection and grading; data access, exchange and storage; and data analytics and solutions (Girard 2019b). Detailed standards, specifications and guidance are needed to achieve interoperability and make it possible for data collected in one data collaboration platform to be used by another within the single data zone. As a first task, the DSTF would constitute working groups to articulate the roles and responsibilities associated with each of the three segments of a typical data value chain. It would identify standardization needs, adopt or adapt appropriate standards that have been developed, identify gaps and coordinate the development of new standards to fill these gaps. The task force could opt to mandate a limited number of existing bodies, such as the IETF, to develop the required technical standards and specifications. It could also issue requests for proposals and select appropriate SDOs to develop standards on its behalf. Once developed, technical standards and specifications would be adopted by the DSTF and added to a registry of compliant standards. As technology evolves quickly, data value chain standards should be updated as needed and a preference may be given to organizations that commit to evergreen standards. Data Collection and Grading Digital cooperation projects will require data from a multiplicity of sources to be successful. Existing data sets in analog format will be used in addition to digitized data sets stored in various databases in a multiplicity of formats. Traditional organizational data originates from various operational systems such as enterprise resource planning, customer relationship management, finance and human resources systems of record. In addition to traditional data sets, digital collaboratives will increasingly rely on streaming data from IoT devices, industrial sensors, cameras, clickstreams, servers and user app activity. Metadata standards will be required to provide information about the characteristics of the data collection apparatus and about data set attributes, in order to precisely describe the features of available data sets; categorize and apply a grade to the data to make inferences about its quality; and label data sets and ensure they are tagged with appropriate IP and copyright mechanisms for traceability. Data Access, Sharing, Exchange and Storage This second segment of the data value chain is needed to make data accessible. It will serve as the interface to connect data sets with data users. New data collaboration platforms will be created to manage and track data flows on behalf of the participants making data available. They will also manage data access for AI and machine-learning organizations looking to generate new insights. Depending on the needs and constraints of participating organizations, the operations of this segment could be decentralized across a supply chain (for example, through data access models based on credentials) or centralized by physically pooling available data into data lakes, commons, trusts, marts, pools, libraries and so on. Standards will be required to describe and frame these different data access methods. In addition to choices about data access modalities, interoperability issues will have to be addressed by data access organizations. Central to interoperability is the choice of an appropriate API to allow for data transmission, use and tracking. In 2018, there were more than 450 different IoT platforms available in the global marketplace, but the number could soon reach close to 1,000 different available platforms (McClelland 2018). Standards will be needed to set performance requirements of APIs to be used in the single data zone and ensure interoperability between platforms. Operators of data collaboration platforms will need to manage four core functions: data integration; systems interoperability; data provisioning; and data quality control. Tasks will include managing authentication and data access filters among participants; managing data integration; administering data cleansing and aggregation functions to meet privacy and other regulatory requirements; managing data cloud, residency and retention policies; designing and operating appropriate data dashboards for access and queries; monitoring data flows and transactions and managing smart contracts between participants; enforcing rules regarding data reuse and data transfers, managing connections with other APIs, and reporting on activities and outcomes. In some cases, data access organizations may also manage the IP and the licensing of algorithms and solutions on behalf of all participants. 16 CIGI Papers No. 237 — January 2020 • Michel Girard Data Analytics and Solutions This third segment of activities will be undertaken by a number of organizations from civil society, governments, academic and research organizations, and small and medium-sized enterprises engaged in AI and machine learning. Analytics functions could operate in a central location in an “IoT lab” in order to foster collaboration between participants. They could also operate in a decentralized way where each organization negotiates appropriate access rights to data in order to access data and determine how best to use it. By relying on IoT labs or commercialization incubators as vehicles for generating data insights, supply chain participants would be able to articulate to AI specialists the most urgent problems to solve. They could provide guidance on data availability and quality, and test solutions and insights as they get developed. Organizations engaged in data analytics will need standards to ensure that algorithms and solutions respect applicable regulations and ethical guidelines and are seen as trustworthy. Data Governance Standards Advances in digitization allow organizations to gather and store more data, enabling smarter and quicker decisions, but they are also giving rise to a new series of issues. How do organizations collect and distribute the right data at the right time? How should organizations deal with data ownership and copyright? How should personal information be treated? What rules should organizations follow regarding data residency? What are acceptable practices for the use of automated decision systems relying on AI? Although some of these issues can be handled solely by organizations, many are framed by governments through enabling laws, regulations and policies. As regulators are not equipped to keep pace with rapid technological advancement, the DSTF would create a series of standards committees to develop and maintain the necessary foundational data governance standards. These standards would frame how digital cooperation initiatives and big tech platforms operate in the single data area. The standards committees would be composed of representatives from governments, industry, civil society and academics. They would operate through the established standards development process. Jurisdictions participating in the DSTF should follow an approach similar to the one in place in the European Commission whereby they are accountable to make standardization requests to the DSTF regarding data governance issues that should be standardized, giving a clear mandate to the DSTF to launch standards committees as needed. Regulators would be called on to play a central role in the development of data governance standards to ensure they meet their policy objectives. Once a standard is developed, there would then be a presumption of conformity on the part of governments to adopt the standards and incorporate them by reference in regulations. This process would establish minimal standards that nation-states would agree to adhere to, which is paramount in order to establish a single data area. Data governance issues that will likely require standardization support include: → guidance on asserting ownership/IP/copyright over data collected by organizations and on tagging and tracking data use in the single data area; → guidance on data valuation for the purposes of financial reporting and taxation; → ensuring compliance to relevant privacy/ digital identity requirements; → ensuring compliance with relevant labour rights; → facilitating personal data portability between data collaboration platforms; → ensuring compliance with human rights regulations and requirements; → establishing and enforcing relevant safe use, ethics and trustworthiness principles to data analytics, AI, machine learning and solutions; → choosing and applying appropriate cyber security controls to data collection/access/analytics architecture, which may include encryption; → defining appropriate data sovereignty and residency requirements to meet requirements under the single data area; and → guidance on appropriate professional credentials and accountability for chief data officers accountable for data governance in organizations as well as data engineers (responsible for data collection and grading), data controllers (responsible for data access, sharing, exchange and storage), data scientists (responsible for AI, machine learning and algorithms) and data valuation professionals and data auditors.