The main ethical considerations for IoT usage in an SME based on the original PAPA model
| Privacy | Accuracy | Property | Accessibility | |
|---|---|---|---|---|
| Implications for an individual employee | Does the employee have the ability to control what, how, when and why data is collected and/or distributed? | Can inaccurate data and/or false interpretations endanger the employee's professional position and/or personal life? | How is the ownership of data shared inside the organisation? | Who can view, edit or delete the data? |
| Can data be combined and attributed to a specific person within an SME? | Who can be held accountable for the accuracy and trustworthiness of the data? | Could the ownership of data be substituted or replaced with mastery of data? | Does the employee have control over who has the access to data? | |
| Implications for general management | Has the management collected informed consent for data collection and distribution from the monitored employees? | Can the data or its interpretation cause discrimination or inequality? | How does the organisational culture view the ownership issue? | Has the management studied and defined the data accessibility principles when deploying the solution? |
| Implications for data management | What information is revealed to external second/third parties? | How is the data accuracy maintained in processes? | Where, and for how long will the data be stored? | How are the access rights defined and shared between different users? |
| How is the data protected and who is responsible for the protection? | Has the data been secured from manipulation? | Who is responsible for the disposal of data? | How should the level of privacy and usage of data be balanced? | |
| Implications for communication | How is the functionality of the solution explained to the individuals and can they give an informed consent based on this information? | What kind of consequences are related to the possible inaccuracy of data? | How are the individuals informed about their rights to the data and the ownership of data? | How has privacy been considered? |
| How is the safety of information ensured? | ||||
| Implications for the regulatory environment and society | What laws and regulations enhance or decrease the employee's privacy and how? | Who can be held accountable for the physical actions of independent systems? | How does the involvement of multiple organisational stakeholders affect the ownership? | Will the data access be monitored and regulated? |
| Do the current laws and regulations support or hinder following good ethical principles? | Can the data be monetised, by whom and for what price? |
| Privacy | Accuracy | Property | Accessibility | |
|---|---|---|---|---|
| Implications for an individual employee | Does the employee have the ability to control what, how, when and why data is collected and/or distributed? | Can inaccurate data and/or false interpretations endanger the employee's professional position and/or personal life? | How is the ownership of data shared inside the organisation? | Who can view, edit or delete the data? |
| Can data be combined and attributed to a specific person within an SME? | Who can be held accountable for the accuracy and trustworthiness of the data? | Could the ownership of data be substituted or replaced with mastery of data? | Does the employee have control over who has the access to data? | |
| Implications for general management | Has the management collected informed consent for data collection and distribution from the monitored employees? | Can the data or its interpretation cause discrimination or inequality? | How does the organisational culture view the ownership issue? | Has the management studied and defined the data accessibility principles when deploying the solution? |
| Implications for data management | What information is revealed to external second/third parties? | How is the data accuracy maintained in processes? | Where, and for how long will the data be stored? | How are the access rights defined and shared between different users? |
| How is the data protected and who is responsible for the protection? | Has the data been secured from manipulation? | Who is responsible for the disposal of data? | How should the level of privacy and usage of data be balanced? | |
| Implications for communication | How is the functionality of the solution explained to the individuals and can they give an informed consent based on this information? | What kind of consequences are related to the possible inaccuracy of data? | How are the individuals informed about their rights to the data and the ownership of data? | How has privacy been considered? |
| How is the safety of information ensured? | ||||
| Implications for the regulatory environment and society | What laws and regulations enhance or decrease the employee's privacy and how? | Who can be held accountable for the physical actions of independent systems? | How does the involvement of multiple organisational stakeholders affect the ownership? | Will the data access be monitored and regulated? |
| Do the current laws and regulations support or hinder following good ethical principles? | Can the data be monetised, by whom and for what price? |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.