In Palantir we trust? Regulation of data analysis platforms in public security
Abstract
EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.
Full text
Ulbricht, Lena; Egbert, Simon Article — Published Version In Palantir we trust? Regulation of data analysis platforms in public security Big Data & Society Provided in Cooperation with: WZB Berlin Social Science Center Suggested Citation: Ulbricht, Lena; Egbert, Simon (2024) : In Palantir we trust? Regulation of data analysis platforms in public security, Big Data & Society, ISSN 2053-9517, Sage, Thousand Oaks, Vol. 11, Iss. 3, pp. 1-15, https://doi.org/10.1177/20539517241255108 This Version is available at: https://hdl.handle.net/10419/310963 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by-nc/4.0/
In Palantir we trust? Regulation of data analysis platforms in public security Lena Ulbricht 1,2 and Simon Egbert 3 Abstract Organizations increasingly rely on digital technologies to perform tasks. To do so, they have to integrate data banks to make the data usable. We argue that there is a growing, academically underexplored market consisting of data integration and analysis platforms. We explain that, especially in the public sector, the regulatory implications of data integration and analysis must be studied because they affect vulnerable citizens and because it is not just a matter of state agencies overseeing technology companies but also of the state overseeing itself. We propose a platform-theory-based conceptual approach that directs our attention towards the specific characteristics of platforms—such as datafication, modularity, and multilaterality and the associated regulatory challenges. Due to a scarcity of empirical analyses about how public sector platforms are regulated, we undertake an in-depth case study of a data integration and analysis platform operated by Palantir Technologies in the German federal state of Hesse. Our analysis of the regulatory activities and conflicts uncovers many obstacles to effective platform regulation. Drawing on recent initiatives to improve intermediary liability, we ultimately point to additional paths for regulating public sector platforms. Our findings also highlight the importance of political factors in platform regulation-as-a-practice. We conclude that platform regulation in the public sector is not only about technology-specific regulation but also about general mechanisms of democratic control, such as the separation of power, public transparency, and civil rights. Keywords Palantir technologies, public security, police databanks, data protection, platform regulation, civil rights Regulatory challenges of data integration and analysis platforms in public security In many countries, public agencies want to exploit the benefits of big data, and for several years, critical data studies have considered this issue (e.g., boyd and Crawford, 2012). What has recently changed is that public agencies are increasingly relying on platforms that allow them to integrate and analyze various data sources (Bigo, 2020). This platformization of the state promises to allow better decision-making due to large databases, fast data analysis, and sophisticated data visualization (Brayne, 2021; Ferguson, 2017; Ulbricht, 2020). While much attention has been paid to the societal benefits and risks of state-agency use of big data analysis to classify citizens (e.g., Dencik et al., 2018), the same cannot be said about the regulation of state automation, especially when it comes to public sector platforms (Bellanova and De Goede, 2022). 1 Public agencies must meet high standards when using citizen data; hence, these practices are subject to democratic oversight. There are consequently many regulatory challenges associated with accessing large data banks with citizen data and using them for automated analysis. 2 For this reason, regulation has been a major research topic in platform research, which has explored how governments try to hold technology companies accountable for the activities that happen within their platforms (Borges, 2023; Gillespie, 2010). This research has not yet been connected sufficiently with the literature on state automation. More generally, studies that empirically analyze platform regulation are still rare, especially when it comes to public sector technology use and specifically to data integration and 1 Politics of Digitalization Department, WZB Berlin Social Science Center, Berlin, Germany 2 Research Group Technology, Power, and Domination, Weizenbaum Institute for the Networked Society, Berlin, Germany 3 Faculty of Sociology, Bielefeld University, Bielefeld, Germany Corresponding author: Lena Ulbricht, WZB Berlin Social Science Center, Politics of Digitalization Department, Weizenbaum Institute for the Networked Society, Research Group Technology, Power, and Domination, Hardenbergstr. 32, D-10623 Berlin, Germany. Email: [email protected] Creative Commons Non Commercial CC BY-NC: This article is distributed under the terms of the Creative Commons AttributionNonCommercial 4.0 License (https://creativecommons.org/licenses/by-nc/4.0/) which permits non-commercial use, reproduction and distribution of the work without further permission provided the original work is attributed as specified on the SAGE and Open Access page (https://us. sagepub.com/en-us/nam/open-access-at-sage). Original Research Article Big Data & Society July–September: 1–15 © The Author(s) 2024 Article reuse guidelines: sagepub.com/journals-permissions DOI: 10.1177/20539517241255108 journals.sagepub.com/home/bds
analysis platforms. These are very relevant because they are the basis upon which any kind of decision-support system relies. Consequently, in our paper, we answer the following research questions: How does platform regulation play out in public sector automation? And how do public agencies that engage in data integration and analysis platform projects ensure that the participating technology companies respect regulation? We answer these questions based on an empirical case study concerning the implementation of hessenDATA, a modified Gotham platform from Palantir Technologies, which is being used by the police force in the German federal state of Hesse. This study of the deployment of Palantir software by the German police force is relevant beyond Germany. In international comparisons, Germany is regarded as having high regulatory standards for the use of digital technologies in public affairs. Moreover, it has a long history of data protection laws, and the German government has been striving to improve the digital sovereignty of state authorities for some years now (Möllers, 2021). Palantir, in turn, has been criticized as opaque due to its business model and its unclear but seemingly close relationship with the US state security agencies (e.g., Brigham, 2020). Therefore, hessenDATA is an interesting case to study regarding whether and—if so, how—the worldwide expansion of digital security platforms can be brought in line with regulatory requirements. What makes Palantir’s Gotham software even more relevant is that it enables security authorities to conduct crossdatabase research and data analysis, which is currently a widely shared goal among public agencies around the world (Bigo, 2020; Egbert, 2019; Gates, 2019; Wilson, 2021). Last but not least, Palantir is one of the most powerful data analysis firms today—not only in security, but also in public health and potentially many other public services, including social policy and education (Taylor et al., 2020). Surprisingly, studies on academic analyses of the company and its sociotechnical infrastructure are still rare (exceptions: Brayne, 2017; Iliadis and Acker, 2022; Munn, 2018). The few existing studies focus primarily on Palantir’s US activities, emphasizing the surveillance dimension of their software, but they do not address the question (and difficulty) of regulating such platforms. Our argument begins with a review of the academic discourse on digital platforms with particular reference to public security platforms and platform regulation. We next discuss the implementation of Palantir software in German police forces and describe the study’s methodological approach. Then we analyze the empirically observed regulatory activities and related political conflicts in the case of hessenDATA. In our conclusion, we summarize our findings and call for a new regulatory approach to data integration and analysis platforms in public security that draws on liability structures as (now) known from social media platforms. Digital platforms, platformization, and regulation Unlike the many studies about data-driven policing that use the concepts of “surveillance”,“securitization”, or the “industrial-security complex”to address the subject of analysis and that zoom in on the specificities of public security (Aradau and Blanke, 2015; Ferguson, 2017; Ulbricht, 2018), we focus on characteristics that are typical for digital platforms as we assume they will engender particular regulatory challenges and dynamics. Digital platforms Digital platforms are one of the most discussed phenomena in current academic debates on digitalization. Various studies have paid attention to social media platforms like YouTube and Facebook and their curation power (Gillespie, 2010; Gorwa, 2019) and to the economic and work-related repercussions of platform companies like Google, Microsoft, Apple, Airbnb, and Uber (e.g., Vallas and Schor, 2020). While the phenomena related to the term “platform”are very diverse, they still share some basic traits: a connectivity-oriented infrastructure that aims to facilitate interactions by at least two third parties, a mode of functioning based on massive and diverse data, and a modular architecture (e.g., Andersson Schwarz, 2017; Rieder and Hofmann, 2020; van Dijck et al., 2018). Platforms are often connected to novel ways of monetizing surveillance, data, and data-driven decisionmaking (Srnicek, 2016; Zuboff, 2019). Hence, digital platforms can be understood as “infrastructural arrangements that situate digital operability on proprietary systems that are, to some degree, programmable and/or customizable by the system users, making possible oneor multi-sided market exchanges”(Andersson Schwarz, 2017: 375). Andersson Schwarz adds that, as “surfaces on which social action takes place, digital platforms mediate—and to a considerable extent—dictate economic relationships.” (Andersson Schwarz, 2017: 375). Referring to this mediating capacity, most authors agree that, although many platform companies try to convince the public otherwise (Gillespie, 2010), platforms have a performative dimension, as they “do not simply connect social and economic actors but fundamentally steer how they connect with each other”(van Dijck et al., 2018: 24, emphasis removed). This is why “a platform is a mediator rather than an intermediary”(van Dijck, 2013: 29). In summary, the platform literature agrees that platforms are characterized by three properties: datafication, modularity, and multilaterality. In addition, platforms develop in 2Big Data & Society
markets that are often transnational and oligopolistic and their public image reveals a tension within platforms as neutral intermediaries versus influential mediators. Digital platforms for public security Given this tension within platforms as intermediaries and mediators, it is crucial to take a closer look at digital platforms in the public sector. 3 As mediators, they generate steering knowledge for state agents, whose decisionmaking practices are mostly addressed to citizens and often affect their civil rights. Because state agencies are able to make decisions that impact citizens’lives, in modern democracies their powers need to be legitimate and subject to many legal and ethical norms (Bigo et al., 2011). A new level of risk arises when private actors are brought on board in the decision-making or decisionsupport process. This may occur in the form of publicprivate partnerships, which are commonly used in digital technology projects (Bossong and Wagner, 2017). Here, private corporate actors get access to data that should typically be the sole preserve of state actors and is hence subject to strict rules (Anstis, 2021: 9). Moreover, when complex technologies are the basis for a private company’s service, an information asymmetry may arise between the company and the state agency (Anstis, 2021: 9). Data integration and analysis platforms also bring about epistemic shifts in public agencies that need to be critically scrutinized. In the public security field, such epistemic shifts include the use of big data, unstructured data, and heuristics that tend to rely on correlations and good predictors instead of causal theory (e.g., Amoore, 2013). These aspects have been heatedly discussed for several years, as they have manifold implications for the rule of law in modern democracies (e.g., Ferguson, 2017). They are especially relevant for data integration and analysis platforms, as their key aim is to enhance the interoperability between databases for “smart analysis”, the “so-called smart way to connect the dots and to avoid continuing to work in ‘silos’with segmented information networks”(Bigo, 2020: 410). As a consequence, the regulation of public security platforms deserves more academic attention. Platform regulation is therefore a fruitful research topic. Platform regulation Relevant research has pointed to the many risks associated with the advent of digital platforms, for example, the proliferation of illegal or undesired online content and the discrimination, manipulation, and exploitation directed against users and workers alike. Other problems of platforms include risks linked to data protection, privacy, discrimination, and social sorting due to invasive and large-scale surveillance; the limited transparency, observability, and accountability of data-related practices of large online platforms; and the lack of clarity on governments’ data sovereignty in collaborations with (often foreign) technology companies (Helberger, 2020; van Dijk et al., 2018). These risks and problems have led to various calls for stricter regulation of platform-based companies and services (Hildebrandt, 2020; Pasquale, 2015). Much engagement with the question of platform regulation has occurred in recent years; there have been many regulatory initiatives by legislative bodies such as the European Commission, 4 increased judiciary activity, 5 and intensive academic research. The overall impetus is to make platforms accountable for practices that take place within their structures and to force them to take measures to prevent harm (Gorwa, 2019). Typical regulatory instruments associated with this intermediary liability are companies’reporting duties towards the public or towards oversight authorities, reporting and flagging systems for users, notice-and-takedown protocols, and sanctions for noncompliance (European Commission, n.d.). However, regulation is not easy: Scholars have noted many obstacles to platform regulation and pointed out that regulation is often inadequate or ineffective (Pasquale, 2015; Zuboff, 2019). One set of obstacles to platform regulation concerns the properties of digital technologies, for example, the fact that many digital services are highly opaque, making it hard to trace which data are collected, stored, and used by whom and for what purpose. This opacity can be rooted in the complexity of digital practices, which may rely on semior unsupervised machine learning. Opacity, especially when it comes to security practices, can also originate from business or state secrecy, as companies and state agencies often protect their data-related practices from public scrutiny and therefore from legal and democratic control (Bloch-Wehba, 2021). Limited accountability is a familiar problem of public-private partnerships (Bovaird, 2004). The other set of obstacles to platform regulation stems from the societal conditions in which digital platforms arise: the monopolistic features of digital markets prevent rights-preserving business models from flourishing (Colangelo and Maggiolino, 2018) and oversight agencies are understaffed such that regulation is not properly implemented (Jori, 2015). Bellanova and de Goede rightly state that (2022: 107), “concerning security algorithms as a target of regulation, there is [still] a need for greater understanding of how the operationalization and legal enforcement of values (…) take place in and through data architectures.”Further to this, we must add that analyses that study concrete practices and not just formal norms are needed to understand platform regulation. At present, most research about platform regulation focuses on the formal norms of regulation, such as existing and proposed legislation (Hildebrandt, 2020) and the terms, conditions, and codes of conduct issued by technology companies (Gorwa et al., 2020; Pasquale, 2015). Ulbricht and Egbert 3
Studies that have scrutinized the actual practices of platform regulation, including legislative processes, day-to-day rule implementation, and monitoring, are very rare. A few empirical studies have indicated that technology companies often have a large leeway to define whether and how they comply with regulation and that they are lenient towards themselves; this is evident with regard to the selfmonitoring of rule enforcement (Gillett et al., 2022), and with regard to assessing and preventing racism (Siapera and Viejo-Otero, 2021). Other studies have analyzed legislation in response to platforms—pertaining to sharing economy companies such as Uber and Airbnb (Aguilera et al., 2021)—at the national and subnational level, finding that the strictness of state regulation depends upon the overall regulatory strictness in a given policy area, and on domestic power constellations (Gorwa, 2021; Laurer and Seidl, 2021). Platform companies strongly oppose regulation and use various lobbying strategies to defeat it: For example, they lobby against new regulation (Mazur and Serafin, 2023) and in favor of corporate selfregulation (Medzini, 2022), they refuse to collaborate in implementing regulations (Colomb and Moreira de Souza, 2023), they engage in discursive legitimation of their activities (Chan and Kwok, 2022), and they mobilize users and customers in the corporate interest (Yates, 2023). Societal actors outside the company are usually not involved in regulatory implementation (Bloch-Wehba, 2022). 6 The above-mentioned studies relate to state control over technology companies; very few studies address cases where state actors make use of technology services and platforms. There is one exception, namely a study about digital governance in the smart city of Shenzhen (China), which showed that growing data centralization reduces the control that public servants at lower administrative levels have over citizen data. The study also showed that the integration of citizen data attracts technology companies (Große-Bley and Kostka, 2021). The details of data governance and regulation were, however, not comprehensively addressed in the study. We complement these studies by analyzing the rules and practices of regulation in a specific case of a public platform, more concretely in the case of police platformization. In this contribution, we understand regulation as state control—over companies, but also over public agencies, and other societal actors (Koop and Lodge, 2017). The distinctive feature of public sector platform regulation is that it implies two levels of control: first, state agencies controlling their corporate contractors, and second, state agencies (those in charge of regulation and oversight) controlling other state agencies (those who are in charge of the technology project). In principle, public platforms therefore imply both forms of regulation: traditional regulation between state agents and companies; and state self-regulation, with its many problematic implications. Studying platform regulation with regard to public sector platforms is therefore conceptually interesting because it gives insight into how this self-regulation plays out within the state. Similar laissez faire mechanisms may be evident here as in corporate self-regulation but there may be entirely different ones at play. In principle, in democracies, many institutional mechanisms are aimed at constraining the power of state agencies and establishing democratic control. These include various forms of power separation, public transparency obligations, and constitutional and civil rights. We now turn to analyzing a case where public agencies decided to closely cooperate with a corporate platform and had to find ways to comply with regulatory needs that resulted in their utilization of a data integration and analysis platform. Platformized public security in Germany Our study focuses on the data integration and analysis platform Gotham by US-based Palantir Technologies and its utilization by police forces, with special emphasis on the case of hessenDATA in the German federal state of Hesse. In this section, we will contextualize the case of hessenDATA in light of overall datafication trends in German policing. Methodological approach To understand how the hessenDATA project was implemented, what regulatory problems arose, what regulatory activities took place, and what discourses were relevant, we researched and analyzed a number of publicly available documents. The complete list includes 85 documents, mainly parliamentary and government documents, but also media articles with relevant quotes by persons involved in the regulatory process (see Annex). In addition, to validate our observations and fill the gaps in the publicly available material, we conducted a semi-structured interview with the project team of hessenDATA, which included a demonstration of the platform, and three guided interviews with members of the parliamentary opposition who were part of the parliamentary committee that investigated the tendering process (see the interview list in the Annex). These interviews especially focused on representatives of opposition parties, as we assumed that their perspective would not be sufficiently represented in the official documents, which very closely reflected the government’s framing. We combined the various types of data to obtain a comprehensive picture of the implementation process of hessenDATA and the (political) discussion that took place around it. The documents and the transcripts of the interviews were subjected to a qualitative content analysis by both authors and coded until code saturation was assumed to be achieved. The coding process was based on the content analysis method according to Kuckartz and Rädiker (2023), 4Big Data & Society
which combines both inductive and deductive coding strategies. This meant that the analysis was sufficiently focused on the topic at hand but was, at the same time, sufficiently open for unexpected insights to emerge from the empirical data. Hence, despite its thematic focus, the analysis was able to shift the researchers’preconceptions and generate new knowledge about the subject. For instance, the focus on regulatory challenges and conflicts was not anticipated at the beginning of the analytical process; it emerged in the course of the more detailed analysis of the data, as these suggested that the hessenDATA platform is particularly difficult to regulate. This, we will show, has to do with its platform character. Palantir Gotham in German policing The most prominent current trend in police datafication in Germany is the increasing use of data integration and analysis platforms by police forces. Hesse was the first to use the services of US-based Palantir Technologies and its Gotham software. The Hessian police have been using Palantir Gotham since the summer of 2017 (Beverungen, 2021). Soon, other German regions followed: starting in 2021, police in North Rhine-Westphalia piloted a “system for cross-database analysis and research”(called Datenbankübergreifende Analyse und Recherche in German, or DAR for short), also based on the Palantir Gotham platform (Landeskriminalamt Nordrhein-Westfalen, 2020), which has been in operation since spring 2022. The Bavarian police have a project called the “Cross-Procedural Search and Analysis Platform”(Verfahrensübergreifende Recherche und Analyse in German, or VeRA for short), which led to a contract with Palantir in spring 2022 (Bayerisches Landeskriminalamt, 2022). Although the original plan was to make VeRa (as “VeRa Bund“)available to all other federal states in Germany via a framework agreement, coordinated by the Federal Ministry of the Interior, the Federal Minister of the Interior recently decided to stop this plan for now and to instead aim for an in-house system (Zierer et al., 2023). Founded in 2004, Palantir is a digital technology company commonly regarded as remarkably secretive and publicly controversial, not least due to its deliberately opaque appearance and the controversial image of the company’s investor Peter Thiel 7 (e.g., Chafkin, 2021). The main service Palantir offers to security agencies is its data integration and analysis software Gotham. The company describes the scope of its software as follows: Our products serve as the connective tissue between an organization’s data, its analytics capabilities, and operational execution. Palantir’s platforms tie these together by bringing the right data to the people who need it, allowing them to make data-driven decisions, conduct sophisticated analytics, and refine operations through feedback (Palantir, 2020b). As we will illustrate in the following section, Palantir Gotham relies upon datafication, modularity, and multilaterality—thereby qualifying as a platform. Like the operators of the digital platforms described in the literature (Gillespie, 2010), the providers of data integration and analysis platforms tend to characterize their software as agnostic and neutral, often denying the mediator status of their platforms. In this vein, Palantir states that they “are not a data company”(Palantir, 2020b), since they do not use data from their clients for their purposes. Instead, they present themselves as a “software company” that is “build(ing) digital infrastructure for data-driven operations and decision-making.”Our analysis will show the distinctive regulation-related challenges connected to this form of platform policing. A platformization pioneer in Germany: hessenDATA Since the summer of 2017, the police in the state of Hesse have been using Palantir’s Gotham software, under the name hessenDATA, to generate time-critical information by means of cross-database research, to access heterogeneous sources and correlation-based context analyses, and to implement this information directly in police operations and strategies (Hessisches Ministerium für Inneres und Sport, 2018: 59). The main goal is to make the policing of “terrorists and serious criminals”more effective (Hessischer Landtag, 2019a: 1). The program was implemented comparatively quickly since the relevant authorities publicly claimed that there was a sufficiently concrete risk of terrorist attacks in Hesse at that time and a need to quickly make the program operational. Instead of issuing a call for tender, as legally required, the contract was awarded directly to Palantir for a limited time period on the grounds of special urgency; it was later granted permanent status (Hessischer Landtag, 2019b: 20). The goal of hessenDATA is to enable human analysts to find associations between entities (e.g., people, spaces, objects) with a view to preventing terrorist attacks or discovering organized crime networks. The sales argument was that an investigator interested in a suspect could either spend all their time following that person, or they could set up an alert in the software. According to the 2018 annual report of the Hessian Ministry of the Interior and Sport, before hessenDATA, much data processing was done manually and required the raw data to be forwarded to IT specialist services at the Hessian State Criminal Police Office, where the data were processed within a week or so (Hessisches Ministerium für Inneres und Sport, 2018). The use of hessenDATA purportedly made it possible to cut out these time-consuming manual steps and obtain a complete and structured overview of the data in minutes (Interview Police Hesse). Ulbricht and Egbert 5
The hessenDATA platform works as a “dragnet,”as it allows the relationships between people, objects, and places to be represented in the form of a network (see also Brayne, 2017). Investigators can use a search interface (see Figure 1) to analyze this web of relationships from any node. For example, investigators receive a message when certain entities (names of people or places, keywords, and objects) appear in a surveilled person’s telecommunications. Palantir offers additional modules that can be added to Gotham, such as Ava, a set of AI functions, and Dossier, a tool for inter-organizational collaboration. In Hesse, additional functions have been added at the police’s request, such as the integration of profile pictures and mugshots. A mobile version has also been established (Interview Police Hesse). Significantly, this type of analysis platform is characterized by the “desilozation”of databases, that is, the breaking up of “data silos,”allowing officers to access different data banks within one platform from one central virtual place. Associated with this, there is the potential to link numerous sources of data (internal police data and external data), which enables analyses at high speed. Referencing hessenDATA’s software architecture, some commentators have aptly spoken of a “Robocop-Google”(Brühl, 2018) (see also Figure 1). For police operators, hessenDATA’s desilozation function is of utmost importance since it makes it much easier to access data from different data banks. In doing so, it enhances the interoperability of different data banks and systems. The following police and nonpolice data sources are included in hessenDATA analyses: POLAS, CRIME, and ComVor. POLAS (POLizeiAuskunftsSystem [Police Information System]) stores law enforcement data. CRIME (Criminal Research Investigation Management Software) is a preventive database, a case-processing system where data necessary for investigative procedures in the future are stored. ComVor (Computergestützte Vorgangsbarbeitung) is the standard case-processing system, where all police procedures are kept and where patrol officers document their actions. Furthermore, hessenDATA can also access traffic data from telecommunications surveillance and data from telecommunications providers. In addition, data from seized cell phones can be integrated (forensic extracts). Of particular interest are the telephone numbers and communication data, such as the time of calls, the length of calls, and the people called (who can then be analyzed with the focus on associations). Police telexes, an internal police email system for formal communication, are also included in hessenDATA; these are especially used to investigate criminal cases or share important news, such as the arrest of a high-level suspect. Finally, hessenDATA can also access data from social media sites. This includes both public and nonpublic data—for example, information obtained by Facebook through a mutual legal assistance request to the United States. However, hessenDATA only has access to these networks in individual cases, after a court order. Summing up, hessenDATA is characterized by datafication, modularity, and multilaterality. Multilaterality results Figure 1. Start screen hessenDATA (Source: Author photo). 6Big Data & Society
from the linkage of databases and, hence, data. Palantir Gotham also links different police forces: Officers from diverse units maintain and evaluate data, sometimes beyond the region of Hesse. One consequence of this is that analysts in the back office are given greater power than police officers in the field, whose superior knowledge about the local context and greater field experience is ultimately devalued (Brayne, 2021: 77; Wilson, 2017: 118). The linking of databases is also a regulatory problem in view of earmarking principles and the different legal underpinnings of the databases, as will be scrutinized in the following section. Analysis: regulatory conflicts and strategies in the case of hessenDATA Given that new and integrated platforms often raise new questions when they are implemented, it is not surprising that the establishment of hessenDATA created various regulatory conflicts. Against this backdrop, in our empirical analysis, we will engage with these regulatory conflicts in more detail, especially with the concerns raised by the implementation of hessenDATA. The concerns were linked to the three defining features of platforms—datafication, multilaterality, and modularity—triggering conflicts about data protection, civil rights protection, and the overall transparency of the project. Another concern was linked to who would take responsibility for the activities within the platform and whether Palantir could be considered an intermediary; the third set of conflicts was about fair market competition and the procurement process that led to the contract with Palantir. The defenders of the hessenDATA project were mostly representatives of the Ministry of the Interior, the Hessian police, and elected members of parliament of the majoritarian Christian Democratic Union (CDU). Criticisms of the project were mainly voiced by the opposition parties in the Hessian parliament and by civil rights organizations. Datafication, multilaterality, modularity, and conflicts about data protection and civil rights Datafication and conflicts about data protection. The main regulatory challenge of the HessenDATA project emanated from datafication and the related data protection problems. One of the major concerns of the parliamentary opposition was that hessenDATA could foster potentially unlawful forms of state surveillance. The option to combine various data sources prompted particular fears that any citizen could become a target of surveillance and suspicion (Hessischer Landtag, 2019b: 2). In addition, the potential for integrating social media data raised concerns that all kinds of information could be deemed relevant for criminal investigations and lead to a huge increase in the numbers of innocent citizens under surveillance (Hessischer Landtag, 2019a: 2). To address these concerns, the government integrated a new paragraph into the existing public security law to explicitly allow automated data analysis of personal data in cases of public interest. 8 The aim was to create a legal basis for hessenDATA, because data protection law generally forbids data mining of sensitive personal information (Hessischer Landtag, 2019b: 2). Data mining, as defined by the German Federal Constitutional Court, is distinct from simple data analysis because it combines massive and multiple data sources to create unexpected insights, thereby creating “new knowledge”. According to the Federal Constitutional Court, in its interpretation of the German Federal Data Protection Act, data mining poses a threat to various civil rights and therefore must only be used to achieve important aims, for example, to deal with an imminent threat, and meet specific requirements. The Federal Data Protection Act thus establishes more stringent criteria for data mining than the European Data Protection Law Enforcement Directive (EU) 2016/680, which it implements. 9 Accordingly, the new paragraph of the Hessian Law on Public Security and Order allows for automated analysis of connected data to prevent serious crimes (such as corruption, child pornography, murder, etc.) and to ward off existential threats to the nation. However, a collective of lawyers and civil rights organizations submitted a constitutional complaint against the new legal paragraph in 2019, arguing, among other things, that the conditions for data access and analysis were too broad. In early 2023, six years after the first implementation of hessenDATA, the Federal Constitutional Court ruled mostly in favor of the plaintiffs (Bundesverfassungsgericht, 2023). Consequently, hessenDATA is currently operating on the basis of an unconstitutional law, and the Hessian government has started the process of modifying the relevant passages (Voigts, 2023). Multilaterality: data-driven policing and civil rights protection. The fact that hessenDATA is multilateral and connects data (banks), but also various units within the Hessian police and potentially links the Hessian police with other German police units—affecting citizens and society as a whole—has triggered concerns about how well citizen rights would be protected with regard to data protection, the presumption of innocence, the freedom of movement, and protection against discrimination. While the parliamentary opposition and (critical) journalists painted a picture of a society characterized by pervasive data-driven policing, frenzied prosecutions, and authoritarian aspirations (Hessischer Landtag, 2019b: 19), the government justified hessenDATA by underscoring its usefulness for prosecuting Islamic terrorists and preventing future terrorist attacks. In these justifications, it referred to the publicly noted lack of collaboration between police units in Germany in the wake of terrorist attacks like the one perpetrated in Berlin in December 2016. Ulbricht and Egbert 7
Modularity: transparency problems and modular data protection. The modularity of hessenDATA made it problematic for the public and the parliamentary opposition to keep track of the project. The unclear scope of data collection and use and their societal effects made hessenDATA a topic of public controversy, and the modular structure of Palantir’s services was perceived by the parliamentary opposition as an obstacle to financial transparency. They criticized the failure to publish the overall project budget and suspected an overrun of the budget initially stipulated in the procurement process as additional services were added to the initial service description. At the same time, the modular structure of Palantir’s services was also used as an argument in favor of the project, mainly as an element of the data protection strategy: The government stressed that Palantir’s offer to tailor a modular data protection and data security system to Hessian police’s needs had been one of the main reasons to choose Palantir (Interview Police Hesse). Palantir offers to develop data protection concepts for its customers, it has an in-house Privacy and Civil Liberties Engineering Team, and it offers data control nudges and checkpoints in its software (Palantir, 2020a). According to the Hessian police, hessenDATA has various structural and procedural features to ensure data protection and information security in daily dataintegration and data-analysis practices. One element concerns the structure of the data bank: hessenDATA limits data flows from police data to hessenDATA, thus making sure that the original police data banks remain unchanged (Interview Police Hesse). In addition, the data used by hessenDATA is still held on police servers and supposedly does not go through Palantir servers; hessenDATA is not connected to the internet but only to the police intranet (“Sondernetz”) (Hessischer Landtag, 2019b: 19); in addition, the data fed into hessenDATA are deleted after two years (Interview Police Hesse). Another data protection module facilitates the control of users by a system of access rules and control procedures (based on a “role-based access control”model). Any police analyst who wants to use the system has to request access and provide reasons that justify the use of hessenDATA, the request must be predicated on investigating or preventing some sort of serious crime, and hessenDATA cannot be used for other investigations. Access is granted for a limited period of time and can be restricted to subsets of the data. Users receive a two-day training course prior to their first use of the system. A logging system records all activity in the system, and random checks of appropriate use take place (Interview Police Hesse). Intermediary responsibility Did the Hessen government hold Palantir accountable for possible risks or harms with regard to the platform? The data protection and civil rights concerns led to a debate on whether the government and Palantir were exhibiting sufficient responsibility for the project and were accountable to the public. One aspect that attracted attention was the lack of clarity on whether hessenDATA was connected to the internet. A hessenDATA operator testified that it is indeed possible to integrate data from an internet search into hessenDATA (Interview Police Hesse). The 2018 annual report of the Hessian Ministry of the Interior also stated in a section on hessenDATA that matching with information openly viewable on the internet, such as from social networks, was possible (Hessisches Ministerium für Inneres und Sport, 2018: 58). These statements remain ambiguous, as no consistent differentiation is made between publicly viewable and non-publicly-viewable information from social networks and other sources. Also, the statements do not explain how publicly viewable data sets are discovered by the software and how they are added to hessenDATA or whether this is part of Palantir Beagle’s scope, which is described by hessenDATA officials as analysis software for the public areas of social networks (Hessisches Ministerium für Inneres und Sport, 2018: 58). Beagle functions as an integrated solution for searches in social networks and in other open sources triggered by individual cases. Another matter of public concern was whether Palantir could access police data in order to improve its products or even to share it with US intelligence agencies. In response, the Hessian government said it had established a system of regulation and oversight, but its details are not accessible to the public. The government has, for instance, stressed that the relevant data protection and information security rules are formalized in guidelines (Interview Police Hesse); however, these have not been shared with the public or with the parliamentary opposition (Interview opposition party 1, 2, 3). With regard to oversight, hessenDATA is regularly reviewed by the criminal police’s internal data protection officer and by Hesse’s independent data protection authority (Interview Police Hesse), but, again, the relevant review reports have not been made public. We contacted the data protection authority, but it did not make anyone available to talk to us about its ongoing assessment of hessenDATA; indeed, the authority did not make any public statements on the matter throughout the whole process, with the exception of those made in the oral hearings before the Federal Constitutional Court, where the data protection authority was summoned as an expert witness (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, 2022). This attitude contrasts with that of the independent data protection authority in North Rhine-Westphalia, which criticized the use of the Gotham-based DAR at an early stage—on the grounds that it represented data mining and that it allowed the use of data collected for another purpose, which would require its own legal basis (Landtag Nordrhein-Westfalen, 2021). The opposition parties in Hesse stated that the 8Big Data & Society
Vallas S and Schor JB (2020) What do platforms do? Understanding the gig economy. Annual Review of Sociology 46(1): 273–294. van Dijck J (2013) The Culture of Connectivity: A Critical History Of Social Media. Oxford ; New York: Oxford University Press. van Dijck J, Poell T and Waal Md (2018) The Platform Society: Public Values in a Connective World. New York: Oxford University Press Inc. van Dijk N, Tanas A, Rommetveit K, et al. (2018) Right engineering? The redesign of privacy and personal data protection. International Review of Law, Computers & Technology 32(2–3): 230–256. Voigts H (2023) Hessen: Eine Gesetzesreform für die Weiternutzung von „Palantir“.Frankfurter Rundschau, 21 February. Available at: https://www.fr.de/rhein-main/landespolitik/hessen-eine-geset zesreform-fuer-die-weiternutzung-von-palantir-92101651.html. Wilson D (2017) Algorithmic patrol. The futures of predictive policing. In: Završnik A (ed) Big Data, Crime and Social Control. 1st ed. Cham, Switzerland: Routledge, 108–127. Available at: https://www.taylorfrancis.com/books/ 9781315395777 (accessed 9 May 2020). Wilson D (2021) The new platform policing. In: Završnik A and Badalic V (eds) Automating Crime Prevention, Surveillance, and Military Operations. Cham, Switzerland: Springer International Publishing, 47–68. Available at: https://link. springer.com/10.1007/978-3-030-73276-9_3 (accessed 18 November 2022). Yates L (2023) How platform businesses mobilize their users and allies: Corporate grassroots lobbying and the airbnb ‘movement’for deregulation. Socio-Economic Review 21(4): 1917– 1943. Zierer M, Kartheuser B, Schöffel R, et al. (2023) Bund rückt von Software Palantir ab. tagesschau.de. Available at: https://www. tagesschau.de/investigativ/br-recherche/palantir-software-analysepolizei-100.html. Zuboff S (2019) The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power. New York: PublicAffairs. Ulbricht and Egbert 15