Data ethics
Also known as: responsible use of data
Asking not only whether a use of data is legal, but whether it is fair, open and in line with what people would expect.
Draft - this entry has not been reviewed yet.
Formal
The values that guide how an organisation collects, combines and uses data, including through AI, beyond what the law demands - fairness, openness, respect for people's choices and avoiding harm. Large Danish companies must report on their data ethics policy in the annual report, or explain why they have none.
In plain English
The law is the speed limit; ethics is slowing down outside a school at home time even though the sign still says 50.
In practice
A Danish bank could legally use card data to spot customers in money trouble and offer them costly loans; its data ethics committee says no and uses the signal to offer free budget advice instead.
Why it matters
Trust breaks faster than laws change - a use of data that is legal but feels creepy can drive customers away and draw public criticism long before any rule is broken.
Technical deep dive
Denmark is one of few countries that has made data ethics a reporting item in company law. Section 99 d of the Danish Financial Statements Act (årsregnskabsloven) requires large class C companies and class D companies (listed and state-owned) to include in the management's review a statement on their data ethics policy, for financial years beginning on or after 1 January 2021. It is comply-or-explain: a company without a policy must explain why, and a group can report at consolidated level. The law does not prescribe the policy's content, and Erhvervsstyrelsen's guidance interprets "policy" broadly as internal guidelines, objectives or other descriptions of how the company works with data ethics. The provision grew out of the Danish government's expert group on data ethics, whose 2018 recommendations also led to the Data Ethics Council (Dataetisk Råd) and fed into the D-mærket criteria.
Substantively, data ethics addresses the space between legality and legitimacy. GDPR sets floors (lawful basis, purpose limitation, minimisation, transparency), but many contested uses are lawful: combining datasets that are individually harmless, profiling on legitimate interest, using non-personal or aggregated data that still affects groups, or deploying models whose errors fall unevenly. Helen Nissenbaum's contextual integrity framework captures the core intuition: a flow of information is problematic when it violates the norms of the context in which the data was shared, even if the recipient is entitled to it. The Danish Gladsaxe model, a municipal proposal from 2018 to combine registry data to flag children at risk, is a frequently cited example of a use that drew strong ethical criticism and was shelved.
For algorithmic systems, the reference points are the EU High-Level Expert Group's Ethics Guidelines for Trustworthy AI (2019), with seven requirements including human agency and oversight, transparency, diversity, non-discrimination and fairness, and accountability, and the OECD AI Principles (2019). The EU AI Act (Regulation (EU) 2024/1689) has since turned part of this into law, with prohibited practices applying since 2 February 2025, so part of what was ethics is now compliance. Fairness is also technically contested: well-known results show that common metrics such as calibration and equal error rates across groups cannot generally be satisfied simultaneously when base rates differ, so choosing a metric is itself an ethical decision that should be documented.
In practice, data ethics is operationalised through a written policy approved by the board, a review step in project governance (often combined with the DPIA, but assessing harms beyond data protection, such as manipulation, exclusion or societal effects), an ethics committee or review board for borderline cases, and transparency about purposes in plain language. A frequent failure is treating the policy as a reporting exercise without any decision it can actually stop; auditors and journalists look for examples where the policy changed or blocked a project.
What to learn first
Everything this builds on, foundations first.
- Personal data
- →Data ethics
Relationships
- Requires
- Personal data
- Don't confuse with
- GDPR
- Mitigates
- AI bias
- Used with
- D-mærket
Sources & further reading
Official documentation
- Lovpligtig redegørelse for dataetik (årsregnskabsloven § 99 d) · Erhvervsstyrelsen
- D-mærket
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 8
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…