Abstract

Clarke sets out to constructively add to the debate on corporate surveillance as a source of business by outlining a new research agenda. It includes reflections on the choice of methods to tackle the relevant research questions on a societal level. Throughout his article, Clarke demonstrates a remarkably positive attitude on the effectiveness of Information Systems research in shaping societal reality, which leads him to hold the researcher community responsible, at least partly, for the—in his undisguised opinion—sorry state of affairs. Consistent with this mindset, he urges us to rethink what questions we research in order to shape a more desirable future. His role model of the researcher is clearly not the neutral observer, but rather the judge about business practices, the advocate of underrepresented interests, or even the architect of a future utopia. Against the backdrop of reoccurring relevance crises in the discipline, this optimistic lens promises an intellectually stimulating read.
Clarke uses the first two-thirds of the paper to set the scene, a task he is very familiar with given his long list of relevant position papers, evidenced in a total of 18 self-citations. But he rightly does not claim ownership of critical thinking on the societal risks caused by information systems in general, or the massive collection of personal data specifically. He cites Weizenbaum and establishes connections to Zuboff’s notion of surveillance capitalism. He also mentions cursorily that calls for critical research as well as methods that can best address value conflicts are a reoccurring, albeit thankfully not dominant, theme in the theoretical Information Systems literature (e.g. Klein & Hirschheim, 2001).
Still, the picture is not complete. Given my cultural and educational background, I would argue that Wilhelm Steinmüller (1934–2013), the “father of German data protection” should not be left out. And I shamelessly use this opportunity to plug him here. Steinmüller, a trained lawyer, theologian, economist, and later psychotherapist, predicted many of the developments with impeccable technical background before the uptake of the commercial Internet (Steinmüller, 1993). For instance, he was much more precise than Clarke in distinguishing between the economic effects of automation in general and the consequences of easier personal data processing. Steinmüller’s policy analyses became the blueprint for German data protection law. Together with a landmark court decision on the right to informational self-determination, derived from the freedom of personality, this law defined the foundations for the European Union’s General Data Protection Regulation (GDPR). This supranational regulation sets standards of global reach to become effective at the time of writing. While the omission of Steinmüller’s work may be due to space constraints, language barriers, and Clarke’s general choice of focus, I cannot make much sense of the decision to not mention the GDPR, or similar developments in other countries, at all.
Different readers may have other salient reactions to the way Clarke sets the scene. What is more interesting is to move on to the “meat” of the article, his research agenda. This section has a slow start, with page-long meta-reflections on and criticisms of the very notion of a research agenda. After digressions into more or less topical complaints about the editorial processes in the Information Systems domain, scenario analysis is finally introduced as the method of choice in order to structure the agenda. Besides the obvious distribution over three subsections, I must admit that I have difficulties identifying a finer structure in the sets of very broad, partly ill-defined, partly ambiguous, and almost always untestable—let alone falsifiable—open questions. For example, the answer to “will digitalisation change human communications and give rise to new and involving media forms” is almost certainly: yes, for almost all definitions of new and involving media forms. Riepl’s (1913) law has withstood the test of time so far. Or, “will parliaments and oversight agencies intervene and impose regulatory measures that are designed to moderate corporate dependence on consumer surveillance”—yes, look at the GDPR, for instance. (Caveat: “designed to” does not imply any judgment on the effectiveness nor broader second round consequences.)
This list could continue for long, but space is too scarce to be filled with my disappointment, which not only concerns the naivety of this research agenda, but also his apparent unawareness or disregard of existing work tackling and partially answering more precisely posed forms of Clarke’s general questions. David Chaum, pioneer of privacy-enhancing technologies, is not mentioned. Instead of studying the argument of Alessandro Acquisti’s manifold contributions to the nascent field of privacy economics, the entire line of pretty diverse work is summarized by his allegedly most-cited paper (which in fact relies on pretty preliminary evidence and, according to Google Scholar, is by far not his most cited one). Clarke seems unaware of work trying to formalize the hypothesized chilling effect (Jann & Schottmüller, 2016) or the evolutionary dynamics of privacy preferences (Dodds, 2007). And I myself happen to have contributed to studies of redistributive effects of future privacy-enhancing technologies, using micro-economic modeling (Böhme & Koble, 2007), and lately of unstable phenomena in the Information Systems domain, using proxies of adopted technologies to predict adoption and avoidance dynamics of newer technologies with empirical methods (Riek, Abramova, & Böhme, 2017). While the latter works are certainly not mainstream, and bear acknowledged limitations of their chosen methods, I would expect a meticulous scholar to find at least some of those relevant precursors when compiling a research agenda. The field is not as unexplored as Clarke makes us believe.
I was keen to read and comment on Clarke’s position because I occasionally cite his distinctive phrases and metaphors in my lectures on privacy-enhancing technologies. When reading the draft, I enjoyed disagreeing with Clarke in many details, and I found it challenging to identify my key point for this commentary. I finally found it in the very last paragraph of the concluding section, where he makes the surprising claim that “empirical research is useless.”
This aversion to empirical methods might in hindsight explain some choices in Clarke’s approach, but it was never substantiated with argument or evidence. Instead, it is a norm in itself, reminding me of initial objections of 19th-century humanists to Adolphe Quetelet’s first application of statistics to quantifiable properties of human beings. Since then, the empirical social sciences have established conventions that allow the processing of personal data in ethical manners. The results of these endeavors have substantially improved our understanding of social phenomena, offering the closest approximation to truth we can get in this imprecise science.
Over the past 50 years, advances in information technology have enabled businesses to collect, store, process, and exchange digital data concerning human beings at unprecedented low cost, undoubtedly raising concerns about businesses’ priorities between ethical behavior and profit. Corrections may be needed, adequate protection technology must be engineered and adopted, incentives as well as consequences must be studied. This should happen with rigor, across disciplinary borders, employing theoretical as well as empirical research methods. Yes, surveillance risks are real, but we cannot mitigate them merely by stopping to do empirical research. Clarke fails to provide a good reason for categorically discrediting empirical research in an age of unprecedented data availability and quality. A research agenda for the future should not limit itself to the methods of the middle ages.
Footnotes
Acknowledgements
All references to Clarke in this paper relate to the target article of this debate published in the current issue of JIT.
Declaration of conflicting interests
The author(s) declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) received no financial support for the research, authorship, and/or publication of this article.
