All questions
Question 1
A social media platform's algorithm curates a user's news feed, creating a 'filter bubble' where the user is rarely exposed to opposing viewpoints. The primary harm associated with this phenomenon is not a direct violation of data privacy, but rather a threat to:
- the user's right to access a complete and unfiltered record of all their friends' posts.
- the commercial viability of news organizations that are not optimized for algorithmic engagement.
- the user's mental health from seeing only polarizing or emotionally charged content.
- the user's intellectual autonomy and the health of the democratic society. (correct answer)
Explanation: The concept of the 'filter bubble' points to a specific, higher-order harm. While personal data is used to create the bubble, the resulting harm is epistemic and civic. It harms the user's intellectual autonomy by limiting the information they use to form opinions. On a societal level, it harms democracy, which functions best when citizens are exposed to a range of ideas and can engage in reasoned debate. The erosion of this shared informational commons is the most significant harm identified by critics.
Question 2
A smart speaker is designed to be 'always listening' for a wake word, and the manufacturer states that no audio is processed or stored until that word is detected. However, the device sometimes misinterprets other sounds as the wake word, sending private conversations to the company's servers. From a rights-based perspective, the most salient ethical issue is that the device's operational reality:
- creates a potential for significant emotional harm if embarrassing conversations are recorded.
- undermines consumer trust, which could lead to decreased sales for the company.
- constitutes a form of surveillance within the home, where the right to privacy is strongest. (correct answer)
- demonstrates corporate negligence in failing to design a sufficiently accurate algorithm.
Explanation: A rights-based perspective focuses on the violation of fundamental rights, irrespective of intent or consequence. The home is traditionally considered a space with the highest expectation of privacy. The fact that the device is always listening and capable of transmitting private conversations, even if by accident, constitutes a breach of this private sphere. The core violation is the existence of a surveillance capability in a protected space, not the specific harms that might result from it or the technical reasons for its failure.
Question 3
A free navigation app provides real-time traffic updates by collecting and aggregating location data from all its users. From a utilitarian harm-framework perspective, under which condition is this data collection practice most ethically justifiable?
- The company provides a clear and conspicuous 'opt-out' option for users who do not wish to share their location data.
- The collective benefit of reduced traffic congestion for all users significantly outweighs the aggregated, minimal harm of individual location data being used. (correct answer)
- The data collected is fully anonymized through advanced cryptographic techniques, so no individual user can be identified.
- Users have a fundamental right to privacy over their location data that cannot be traded for a convenience like traffic updates.
Explanation: A utilitarian framework judges the morality of an action based on its consequences, specifically by weighing benefits against harms. The most justifiable condition from this perspective is when the total good (utility) produced—in this case, faster and more efficient travel for everyone—is demonstrably greater than the total harm caused by the collection of location data. Choice B directly addresses this central calculation of net benefit.
Question 4
A company suffers a data breach, exposing the names, email addresses, and encrypted passwords of millions of users. The company argues that since the passwords were encrypted and no financial data was lost, the actual harm is minimal. Which of the following presents the strongest counterargument from a harm framework?
- The breach violates the user's inherent right to have their personal information kept secure.
- The exposure of email addresses and passwords enables future harm through targeted phishing and 'credential stuffing' attacks. (correct answer)
- The company's failure to prevent the breach demonstrates a lack of respect for its customers.
- The reputational damage to the company will cause its stock price to fall, harming investors.
Explanation: A harm-based counterargument must identify concrete, probable harms to the users. The company's claim dismisses these. The strongest counterargument is that the breach creates significant future risks. Hackers use leaked email lists for sophisticated phishing campaigns. They also use the email/password combinations in 'credential stuffing' attacks, trying them on other, more sensitive websites (like banking) on the assumption that people reuse passwords. These are direct, foreseeable harms resulting from the breach.
Question 5
An AI-powered hiring tool analyzes video interviews, assessing candidates' facial expressions and tone of voice to predict job suitability. A critique grounded in a rights framework would argue that this tool is ethically problematic primarily because it:
- treats the candidate as an object to be quantified, infringing on their dignity regardless of the outcome's accuracy. (correct answer)
- may cause harm by perpetuating societal biases if the AI was trained on historically biased hiring data.
- could be inaccurate, leading to the harm of unfairly rejecting qualified candidates.
- violates the candidate's reasonable expectation of privacy by collecting their biometric data.
Explanation: When you encounter ethics questions about new technologies, pay attention to which moral framework the question emphasizes. This question specifically asks for a "rights framework" critique, which focuses on fundamental human dignity and treating people as ends in themselves, not merely as means.
A rights-based approach, rooted in Kantian ethics, argues that certain actions are wrong regardless of their consequences because they violate human dignity. The AI hiring tool treats candidates as collections of quantifiable data points—facial expressions and vocal patterns—reducing complex human beings to algorithmic inputs. This commodification violates the principle that humans possess inherent worth that transcends their utility. Even if the tool were perfectly accurate, it would still be ethically problematic because it fails to respect candidates as autonomous agents deserving of dignified treatment.
Let's examine why the other options don't align with rights framework thinking: Option B focuses on harmful consequences from bias, which is more characteristic of consequentialist ethics that judges actions by their outcomes. Option C similarly emphasizes harm from inaccuracy—again, a consequentialist concern about negative results rather than inherent rights violations. Option D raises privacy concerns, which could involve rights, but the question centers on the tool's fundamental approach to evaluating humans, not data collection methods.
The correct answer is A because it identifies the core rights-based objection: the tool's inherent disrespect for human dignity through objectification.
Remember that rights framework questions focus on whether actions respect human dignity and autonomy, not whether they produce good or bad outcomes.
Question 6
Researchers use a large, 'anonymized' dataset from a ride-sharing app to study traffic patterns. Later, it is shown that by combining this data with publicly available information, specific individuals can be re-identified. This scenario primarily demonstrates a failure in which key assumption underlying many data privacy schemes?
- The potential benefits of urban planning research outweigh the minimal privacy risks to individuals.
- Individuals do not have a reasonable expectation of privacy when they are moving through public spaces.
- The removal of direct personal identifiers is sufficient to prevent the re-identification of individuals. (correct answer)
- Data-sharing agreements between companies and researchers lack sufficient legal oversight and penalties.
Explanation: This scenario directly illustrates the problem of re-identification. The core faulty assumption is that 'anonymization' is a permanent state achieved by simply stripping out names and addresses. In reality, the remaining quasi-identifiers (like location data, time stamps, etc.) can often be linked with other datasets to unmask individuals. This demonstrates a fundamental technical and conceptual weakness in privacy protection strategies that rely solely on removing direct identifiers.
Question 7
A new law requires encrypted messaging services to provide a 'backdoor' for law enforcement to access communications of suspects with a warrant. A consequentialist argument against this law, focusing on the broadest potential harms, would most likely claim that:
- the law violates a fundamental, inalienable right to private conversation that cannot be overridden by state interests.
- creating a backdoor inherently weakens the security of the entire system, making all users vulnerable to malicious actors. (correct answer)
- law enforcement agencies might abuse their power and use the backdoor to monitor political dissidents, not just terrorists.
- compelling private companies to alter their products for government purposes represents an unjust seizure of corporate resources.
Explanation: A consequentialist argument weighs the total outcomes. The strongest consequentialist critique of encryption backdoors is that it is impossible to create a 'good guys only' key. A vulnerability created for law enforcement is a vulnerability that could be discovered and exploited by criminals, foreign governments, or other malicious actors, thus decreasing security for all users. This widespread negative consequence is a powerful argument against the policy from a harm-based, consequentialist perspective.
Question 8
A medical institute seeks to use de-identified patient data from hospitals to train a disease-prediction AI. However, combinations of rare conditions, zip code, and age could still potentially re-identify individuals. A rights-based framework would insist that, prior to using the data, the institute must prioritize:
- calculating the probability of re-identification and proceeding if the risk is below a statistical threshold.
- ensuring that the potential public health benefits are significantly greater than the potential privacy harms.
- establishing a clear governance structure that respects patient autonomy, even if it slows research. (correct answer)
- purchasing cybersecurity insurance to compensate any individuals who might be harmed by a future data leak.
Explanation: Rights-based frameworks prioritize the protection of individual rights and autonomy over calculations of risk or utility. Instead of asking 'how much risk is acceptable?' (a harm-based question), a rights-based approach asks 'what processes are required to respect the rights of the data subjects?' This leads to prioritizing things like strong governance, oversight committees, and clear rules for data access that respect the autonomy and dignity of the patients whose data is being used, treating these as necessary preconditions for the research.
Question 9
The 'Right to be Forgotten' allows individuals in some jurisdictions to request that search engines delist links to information about them that is outdated or irrelevant. This policy creates a fundamental ethical conflict between an individual's right to informational self-determination and which other competing principle?
- The financial harm caused to search engine companies by the cost of processing delisting requests.
- The public's right to access information and the principle of a comprehensive historical record. (correct answer)
- The technological difficulty of permanently erasing data from all corners of the internet.
- An individual's right to free expression, as they may wish to speak freely about their own past.
Explanation: The core of the debate over the 'Right to be Forgotten' is a clash of two significant rights or principles. On one side is the individual's right to control their digital identity and not be perpetually haunted by their past (informational self-determination). On the other side is the public's interest in accessing information and the value of maintaining a complete and unaltered public record, which are crucial for journalism, historical research, and public accountability. The other options represent practical or economic concerns, not the central rights-based conflict.
Question 10
The 'privacy paradox' is the observed discrepancy between people's stated concerns about privacy and their actual online behavior. People often say they value privacy highly, yet readily share personal information.
Which of the following ethical analyses most plausibly explains the privacy paradox without simply concluding that people are irrational?
- The digital environment is designed with information asymmetries that make abstract, long-term harms difficult to weigh against immediate, concrete benefits. (correct answer)
- Individuals have an overriding desire for social connection that is stronger than their desire for privacy, making the trade-off a rational choice.
- Privacy is a socially constructed concept that is becoming obsolete, so people's behaviors are simply adapting to a new norm.
- People correctly calculate that the harm from any single act of sharing is negligible, making each individual decision logical.
Explanation: When analyzing ethical dilemmas involving apparent contradictions in human behavior, look for structural or environmental factors that might create rational conflicts rather than assuming irrationality. The privacy paradox requires understanding how design and information contexts shape decision-making.
Answer A correctly identifies that digital platforms create information asymmetries—situations where users lack complete information about long-term consequences while facing immediate, tangible benefits. This makes seemingly contradictory behavior rational: people aren't being illogical when they can't properly evaluate risks they can't fully perceive or understand. The digital environment deliberately obscures future harms (data breaches, manipulation, surveillance) while making current benefits (convenience, social connection, personalized services) immediately apparent.
Answer B oversimplifies by suggesting social connection always outweighs privacy concerns, ignoring that people often express genuine distress about privacy violations. Answer C incorrectly assumes privacy is becoming obsolete—surveys consistently show people still value privacy highly, contradicting this claim. Answer D commits the fallacy of composition, suggesting that because individual sharing acts seem harmless, the cumulative effect is also harmless, which ignores how aggregate data creates new vulnerabilities.
The key insight is that rational behavior can appear irrational when operating within systems designed to obscure certain information. When studying ethics questions about behavioral contradictions, always consider whether environmental or structural factors might explain the apparent inconsistency before concluding that people are simply being irrational or inconsistent in their values.
Question 11
An algorithm used by a bank to approve loans has a higher rejection rate for applicants from a minority neighborhood. The bank asserts the algorithm only uses financial data and is 'color-blind,' but historical lending patterns mean that geographic data acts as a proxy for race. From a harm-framework perspective, this scenario illustrates the ethical problem of:
- malicious intent, where the algorithm's designers deliberately programmed it to be biased.
- data inaccuracy, where the financial data used by the algorithm was flawed or incomplete.
- privacy violation, where the bank collected more data about applicants than was necessary.
- disparate impact, where a formally neutral process results in discriminatory outcomes. (correct answer)
Explanation: This is a classic example of disparate impact. The process is facially neutral (it doesn't use 'race' as a variable), but its outcome is discriminatory. The harm is that the algorithm, by using data that correlates with race (like zip codes affected by historical redlining), perpetuates and even amplifies existing societal inequalities. The focus of the harm framework here is on the discriminatory effect, not the intent of the designers or the accuracy of the underlying data.
Question 12
An insurance company offers customers a discount on their health insurance premiums if they agree to wear a fitness tracker that monitors their physical activity and sleep patterns. The most significant ethical concern regarding systemic harm in this 'privacy-for-discount' trade-off is that it could:
- violate the user's right to bodily autonomy by coercing them into specific health behaviors.
- result in inaccurate health assessments due to the technical limitations of consumer-grade fitness trackers.
- fail to provide a large enough discount to make the privacy trade-off worthwhile for most consumers.
- lead to discrimination by creating a system where those with health conditions or less active lifestyles are financially penalized. (correct answer)
Explanation: While other concerns are valid, the most significant systemic harm is the potential for discrimination and the creation of a two-tiered system. Such a policy could financially penalize individuals who are unable to meet activity targets due to disability, illness, demanding jobs, or socioeconomic constraints. This moves from an insurance model based on shared risk to one based on individual behavioral monitoring, which can entrench existing health and social inequalities.
Question 13
Philosopher A argues: 'Privacy is valuable because it allows us to control how we present ourselves to the world. Constant surveillance collapses social contexts, forcing us into a single, managed identity, which harms our psychological well-being.'
Philosopher B argues: 'The primary harm of data collection is not psychological, but structural. It enables corporations to sort and score populations, creating and reinforcing social inequalities. The focus should be on power dynamics, not individual feelings.'
A social media platform introduces a feature that analyzes a user's photos and posts to generate a 'personality score' that is then sold to advertisers and potential employers. Which statement best describes how Philosopher A and Philosopher B would identify the primary harm?
- Both philosophers would agree that the primary harm is the violation of the user's property rights over their own data.
- Philosopher A would focus on the harm to self-presentation and the pressure to maintain a marketable persona, while Philosopher B would focus on how the score creates systemic discrimination. (correct answer)
- Philosopher A would focus on the economic harm to the user from job rejection, while Philosopher B would focus on the violation of the user's right to be left alone.
- Philosopher A would argue the harm is the lack of informed consent, while Philosopher B would argue the harm is the potential for data breaches.
Explanation: This question requires applying the two distinct frameworks from the passage. Philosopher A's framework is about psychological harm and context collapse, so they would focus on how the personality score forces the user into a single, quantifiable identity, harming their ability to manage their persona. Philosopher B's framework is about structural power and inequality, so they would focus on how the score is used as a tool for sorting people, leading to discriminatory outcomes in employment and reinforcing social hierarchies.
Question 14
A government proposes a system requiring citizens to use a digital ID linked to all online activities to combat anonymous online harassment. Which of the following describes the most significant potential harm according to critics who focus on the 'chilling effect' of such a policy?
- The system would create a centralized database of citizen activity, making it a high-value target for hackers.
- The policy would disproportionately burden individuals who lack the technological means to manage a digital ID.
- Individuals, fearing reprisal, would self-censor the expression of dissenting political views, weakening democratic discourse. (correct answer)
- The government could use the data to more efficiently deliver public services and identify instances of tax fraud.
Explanation: The 'chilling effect' is a specific type of harm where individuals curb their legitimate activities—especially speech and association—out of fear of surveillance. In this context, the primary chilling effect would be on political and social discourse. People might avoid exploring or expressing controversial or unpopular ideas if their real identity is attached, which could stifle dissent and weaken the robust exchange of ideas necessary for a healthy democracy.
Question 15
A user signs up for a social media platform and agrees to a lengthy and complex Terms of Service document without reading it. This document grants the platform broad rights to use their data. From an ethical perspective focused on the quality of consent, the most significant problem with this scenario is that:
- the company is legally protected by the user's formal act of clicking 'agree'.
- the user derives a significant benefit from the free service, which ethically justifies the data collection.
- the user will likely experience the harm of receiving intrusive or unwanted advertisements.
- the user's consent cannot be considered fully 'informed' due to the agreement's complexity, undermining their autonomy. (correct answer)
Explanation: For consent to be ethically meaningful, it must be informed, voluntary, and competent. In this scenario, the primary failure is on the 'informed' criterion. The length and complexity of the document (a form of 'information asymmetry') make it practically impossible for the average user to understand what they are agreeing to. This undermines their ability to make an autonomous decision, rendering the consent ethically hollow, even if it is legally binding.
Question 16
A 'smart city' initiative deploys a network of sensors and cameras to optimize traffic flow and energy usage. An analysis of this initiative using a harm framework reveals a tension between the collective good of an efficient city and the potential individual harm of:
- the financial cost of installing and maintaining the vast network of sensors and cameras.
- normative social pressure, where citizens, aware of constant monitoring, conform to publicly accepted behaviors. (correct answer)
- the violation of individuals' property rights as sensors are placed near their private homes.
- the possibility that the data could be used by private corporations for targeted advertising.
Explanation: This question asks for a harm that is in direct tension with the stated collective good. The goal is an orderly, efficient city. The harm of normative social pressure (a type of chilling effect) is that this very efficiency and orderliness comes at the cost of individual spontaneity, eccentricity, and non-conformity. Citizens may avoid harmless but unusual behaviors because they feel they are being watched, leading to a less vibrant and more homogenous public life. This represents a subtle but significant social harm.
Question 17
A free navigation app provides real-time traffic updates by collecting and aggregating location data from all its users. From a utilitarian harm-framework perspective, under which condition is this data collection practice most ethically justifiable?
- The company provides a clear and conspicuous 'opt-out' option for users who do not wish to share their location data.
- The collective benefit of reduced traffic congestion for all users significantly outweighs the aggregated, minimal harm of individual location data being used. (correct answer)
- The data collected is fully anonymized through advanced cryptographic techniques, so no individual user can be identified.
- Users have a fundamental right to privacy over their location data that cannot be traded for a convenience like traffic updates.
Explanation: A utilitarian framework judges the morality of an action based on its consequences, specifically by weighing benefits against harms. The most justifiable condition from this perspective is when the total good (utility) produced—in this case, faster and more efficient travel for everyone—is demonstrably greater than the total harm caused by the collection of location data. Choice B directly addresses this central calculation of net benefit.
Question 18
A user signs up for a social media platform and agrees to a lengthy and complex Terms of Service document without reading it. This document grants the platform broad rights to use their data. From an ethical perspective focused on the quality of consent, the most significant problem with this scenario is that:
- the company is legally protected by the user's formal act of clicking 'agree'.
- the user derives a significant benefit from the free service, which ethically justifies the data collection.
- the user will likely experience the harm of receiving intrusive or unwanted advertisements.
- the user's consent cannot be considered fully 'informed' due to the agreement's complexity, undermining their autonomy. (correct answer)
Explanation: For consent to be ethically meaningful, it must be informed, voluntary, and competent. In this scenario, the primary failure is on the 'informed' criterion. The length and complexity of the document (a form of 'information asymmetry') make it practically impossible for the average user to understand what they are agreeing to. This undermines their ability to make an autonomous decision, rendering the consent ethically hollow, even if it is legally binding.
Question 19
A government proposes a system requiring citizens to use a digital ID linked to all online activities to combat anonymous online harassment. Which of the following describes the most significant potential harm according to critics who focus on the 'chilling effect' of such a policy?
- The system would create a centralized database of citizen activity, making it a high-value target for hackers.
- The policy would disproportionately burden individuals who lack the technological means to manage a digital ID.
- Individuals, fearing reprisal, would self-censor the expression of dissenting political views, weakening democratic discourse. (correct answer)
- The government could use the data to more efficiently deliver public services and identify instances of tax fraud.
Explanation: The 'chilling effect' is a specific type of harm where individuals curb their legitimate activities—especially speech and association—out of fear of surveillance. In this context, the primary chilling effect would be on political and social discourse. People might avoid exploring or expressing controversial or unpopular ideas if their real identity is attached, which could stifle dissent and weaken the robust exchange of ideas necessary for a healthy democracy.
Question 20
Researchers use a large, 'anonymized' dataset from a ride-sharing app to study traffic patterns. Later, it is shown that by combining this data with publicly available information, specific individuals can be re-identified. This scenario primarily demonstrates a failure in which key assumption underlying many data privacy schemes?
- The potential benefits of urban planning research outweigh the minimal privacy risks to individuals.
- Individuals do not have a reasonable expectation of privacy when they are moving through public spaces.
- The removal of direct personal identifiers is sufficient to prevent the re-identification of individuals. (correct answer)
- Data-sharing agreements between companies and researchers lack sufficient legal oversight and penalties.
Explanation: This scenario directly illustrates the problem of re-identification. The core faulty assumption is that 'anonymization' is a permanent state achieved by simply stripping out names and addresses. In reality, the remaining quasi-identifiers (like location data, time stamps, etc.) can often be linked with other datasets to unmask individuals. This demonstrates a fundamental technical and conceptual weakness in privacy protection strategies that rely solely on removing direct identifiers.