The World Bank & social protection during crises: a privacy trade-off?

Privacy International ("PI") researched a number of social safety-net projects financed by the World Bank during the COVID-19 pandemic. To inform the World Bank's future implementation of these kinds of projects, this article reflects on how certain aspects of social protection projects can inadvertently lead to excessive surveillance of marginalised communities, impact equal access to urgent social protection disbursements, and interfere with people's dignity and right to privacy.

Key findings
  • Covid-19 highlighted an urgent, global need to strengthen social protection systems - precisely so that the poorest and most vulnerable members of our communities are protected in times of crisis.
  • Based on our research and analysis of information that is made public by the World Bank, it is not clear whether or not the World Bank systematically accounts for the risks associated with data-intensive and tech-reliant social safety-net programmes.
  • If the aim of social protection projects is to increase coverage and lay the foundation for robust emergency protection systems, especially for the most vulnerable members of our communities, it is important for these projects to be designed and implemented in a way that accounts for, and is informed by, the potential risks and harms associated with integrating tech-based solutions. For example, the risk of data being leaked, or used for political profiling, persecution or discrimination, and the erosion of the rights to privacy and equality.
  • The World Bank can get it right. It's a choice. Social protection should not have to come at the cost of people's fundamental freedoms and rights to dignity and equality. We can build agile and resilient social protection systems, without accepting disproportionate interferences with people's fundamental rights as an opportunity cost.
Long Read
photo of life-saving buoy

Image by Matthew Waring (unsplash)

Introduction

In response to the unprecedented social, economic, and public health threats posed by the Covid-19 pandemic, the World Bank financed at least 232 "Covid-19 Response" projects. The projects were implemented across countries the World Bank classifies as middle and low-income.
This article will focus on eight (8) Covid-19 Response projects which sought to deliver social assistance to individuals and families on a "non-contributory" basis (this means that the intended beneficiaries were people who had not previously "paid-in" to social insurance programmes). This will usually include people who work within informal economies, people who are unemployed, and people who, for one reason or another, do not have a registered identity in the state they live in.
Our aim is to analyse how these social assistance projects - designed and financed by the World Bank - may fail to improve access for some of the most vulnerable members of our communities, and potentially carry with them hidden costs impacting equality and human rights.
We selected a small sample of projects in order to conduct in-depth research for this report. We did this to ensure that we were able to dedicate sufficient resources to each project, while at the same time capturing a snapshot of the common features across these projects. Accordingly, the projects covered in this piece are a small sample which are not representative of all welfare projects funded by the international development sector.
Nevertheless, the conclusions we were able to draw from our analysis of these eight (8) projects remain relevant to development financing in general, and emergency social safety-net projects in particular. It is worth noting that the conclusions and observations mirror findings that PI, along with our global partners have been documenting in relation to the digitisation of access to social protection programmes around the world, not only in relation to Covid-19 but also prior to the pandemic and in non-crisis settings.
As part of this research into World Bank "Covid-19 Response" projects, we looked at projects implemented in:

To share more information about the projects we looked at, we have hyperlinked the relevant project documents we accessed in the list above. In general, information about the World Bank's projects can be found here. Our research relied predominantly on project documentation that is publicly available, including the core project documents that the World Bank makes publicly available. We also relied on reports by independent researchers in the social protection space and information shared by partner organisations. Anyone interested in learning more about the Bank's social protection projects can search projects by "theme", or using keywords such as "COVID-19". It's important to note that the project information documents we reviewed included the Bank's environmental and social reviews. While they do reference human rights risks generally, we did not find specific references to data protection and privacy.

The World Bank & social protection: a primer

The World Bank provides governments with financial products (for example, standard loans and zero-interest loans) as well as grants to fund a wide range of development projects. This includes everything from physical infrastructure projects to "social infrastructure" projects. The World Bank's stated aim is to help countries achieve "sustainable and inclusive" development and "improve life for the poorest and most vulnerable."
Researchers, policymakers, and inter-governmental organisations have all acknowledged that Covid-19 highlighted an urgent, global need to strengthen social protection systems - precisely so that the poorest and most vulnerable members of our communities are protected in times of crisis (see for example, Oxfam FP2P blog and IPCIG Report). It was quickly recognised that the Covid-19 pandemic was having a wider impact beyond a health crisis. As the United Nations noted “it was affecting societies and economies at their core, and a global socio-economic response was urgent to tackle the emerging escalation of inequality and poverty.”
Within this context, the World Bank Covid-19 Response projects that we analysed had dual aims: firstly, to respond to immediate social, economic, and healthcare needs, and secondly, to strengthen social protection systems for the future. Importantly, following a general trend observed in the last few years, a common feature of these projects was increasing integration of technological and data-intensive solutions, ostensibly, to achieve efficiency gains through automation, data centralisation, and data sharing across government agencies.
As an organisation which advocates for the right to dignity for all, and seeks to ensure governments are complying with their obligations to progressively ensure access to social protection, we agree with the World Bank that it is extremely important for countries to:

"have the capacity to integrate, administer, and evaluate social protection programs [and] invest in knowledge, data, and analysis"; and "that it is important to increase "the responsiveness of social protection programs to adapt to and meet changed needs on the ground after shocks have materialized."

We also know that there is an urgent need to increase coverage, adequacy, and comprehensiveness of social protection systems around the world.
However, we do not think over-reliance on technology and excessive data collection is the only way to achieve these goals.
Given the unprecedented impact Covid-19 had on every aspect of people's lives, it is clear that the World Bank's Covid-responsive social protection projects were not just necessary, but probably saved lives across the world.
Our analysis is aimed at reflecting on what can be improved, pre-empted, and enhanced in the future. It is designed to inform policymakers who are serious about developing projects which empower marginalised individuals and communities while also safeguarding fundamental rights.
In the table below, we have summarised six common issues we identified across the projects we looked into:
(1) building data-intensive social registry databases;
(2) using automation to target beneficiaries;
(3) lack of transparency around eligibility criteria;
(4) biometric verification or linking authentication with digital ID;
(5) digitalising payments; and
(6) interferences with people's right to privacy.
We have also provided short explanations which explain how the potential problems which may arise out of these practices, and the potential risks to beneficiaries which may result if necessary safeguards are not implemented or enforced.

Technological solutions & social protection: practices and potential problems

If the aim of social protection projects is to increase coverage and emergency protection, especially for the most vulnerable members of our communities, we think it’s important to take into account already well-documented problems associated with integrating things like automation and social registry databases - such as the risk of data being leaked, or used for political profiling, persecution or discrimination. For example, where the World Bank finances the integration of automation, there are well-known serious concerns about maintenance and sustainability of systems which rely on up-to-date and accurate data, especially in countries where social protection services are severely under resourced. Finally, where the World Bank integrates digital and biometric verification with access to urgent cash payments or other protection needs, those who need support the most might be inadvertently excluded, which is a widely-documented risk associated with such practices.
To find out more about some of the potential concerns and problems highlighted in the table above, here are further resources:

Does technology always improve social protection systems?

In some contexts, technology may contribute to accelerating processes, increasing efficiency, and providing important solutions in crisis and emergency situations. For example, implementing digital payment systems allowed agencies to disburse benefits without risking contact and transmission while countries were going into lock-down.
However, certain technologies also bring with them serious risks to fundamental rights, equality and accessibility. This is particularly concerning when important safeguards for privacy and data protection are not built in by design. These technologies also bring challenges such as costs to the environment, and, as development agencies have previously pointed out, increased financial cost, technical complexity, and challenges in relation to maintenance and sustainability.
Prior work by PI and our global partners has documented how the lack of careful consideration of the implications of increased digitalisation, automation, and intrusive data collection in social protection programmes is likely to result in the arbitrary surveillance, targeting, profiling of those seeking assistance. Importantly, this may further hinder efforts to reach those most in need, leading to exclusion and further exacerbating existing inequalities.
The programmes we looked into for this piece raise similar concerns as to whether the introduction of the technology will improve the enjoyment of the rights to social protection, dignity, and autonomy, or whether new risks have emerged which have gone unaddressed and unmitigated.
For example, in Mozambique an independent observer undertook an analysis of the emergency social protection eligibility criteria. They found that in many communities, people were frustrated by the lack of information on the program including who’s eligible, how much they’re entitled to, and the frequency with which the benefit is distributed. Additionally, throughout the roll-out of the cash-transfer programme, there were reports of people being threatened and harassed over the phone by individuals demanding that benefit claimants hand over the phones to which the benefit is linked. It is not clear how these people got hold of beneficiaries phone numbers.
In Lebanon, SMEX found that the platforms used to sign up for COVAX vaccines, request permits to move around during lock-down and store sensitive information including passport numbers and home addresses, were not properly secured.
In Angola, and in connection with a cash transfer-based social protection project which was supported by the World Bank, the government undertook a process of ‘data validation’, where government teams sought to validate provisional lists of beneficiaries which had been ‘systemically generated’ by visiting specific neighbourhoods. The government described these visits as an opportunity for people to learn if their name is on the beneficiary list or not, but the eligibility criteria and the way these lists where generated remained undisclosed.

So, what does this have to do with surveillance, privacy, and equality?

Setting up systems which continuously collect massive amounts of personal data without implementing parallel human rights safeguards, including effective data protection, increases government agencies' and 3rd parties' ability to surveil specific individuals and communities.
These risks are not theoretical or anecdotal, they reflect well-documented systemic concerns with the use of data and technology in the design and deployment of social protection programmes. The incredible efforts of civil society, academics, and investigative journalists around the world have documented various examples evidencing the risks associated with digitalising social protection programmes. This includes exclusion and invasive and undignified surveillance of people in our communities who are often living through precarious conditions.
This is especially concerning in countries such as Haiti, Lebanon, Nigeria, Jordan, and Morocco where political dissidents, human rights defenders and journalists have faced repression, work under the threat of violence and arbitrary detention and there is limited respect for the rule of law. In these contexts, in order to protect their safety and security, activists and human rights defenders who may be targeted by security forces have a particular need to protect their personal and sensitive data. They should not be prevented from accessing urgent social protection because they are unwilling to provide biometric data, for example or fear information-sharing between state agencies.
Additionally, PI has previously highlighted how minoritised communities - most notably women, trans and gender diverse people are impacted by welfare surveillance and ID systems. It is important to note that people from persecuted or marginalised communities, and people who have been subjected to discrimination and racism will often need urgent social protection in times of crisis. This includes LGBTIQ+ persons, people from ethnic minorities that have been subjected to persecution, victims of gender-based violence, people threatened with deportation (such as undocumented refugees and migrants), and people who need to access sensitive medical care such as abortions or HIV treatment. For example, in Malaysia, activists from the civil society group Justice For Sisters have highlighted that individuals from the LGBTIQ+ community are disproportionately impacted by poverty "due to criminalisation, social stigma and discrimination". They therefore argue that systems which provide access to welfare must also protect the right to privacy in order ensure LGBTIQ+ individuals are able to access welfare without increasing their vulnerability to persecution.
Biometric data collection and information-sharing across government agencies may disincentivise people from accessing much-needed social protection - particularly people who are facing extreme poverty, but at the same time, want to protect their identity from groups, institutions, or public officials that could use this data to cause harm or violate their rights. This has already been acknowledged by other development agencies such as GIZ, the German development agency.
Whilst the World Bank adopts an apolitical approach to its financing and priorities, we believe that accounting for the context in which these programmes are deployed is crucial. Not doing so fails to consider the power dynamics at play which should inform how to design and implement a project. This includes, for example, a good understanding of the communities at risk in certain contexts, and proper identification of the necessary, sometimes context-specific, safeguards required, depending on the regulatory and legal context and the role of the rule of law - which many of the safeguards built into these projects depend on in order to be effective.

Strengthening safeguards (1): due diligence, privacy, and human rights impact assessments

The World Bank has repeatedly incorporated references to data protection in its social protection work, acknowledging the importance of protecting the right to privacy in the context of progress to more equal, fair, and human rights based social contracts. Notably, based on the additional information provided by the World Bank’s Social Protection and Jobs team to PI, we also know that as part of any project planning and design process, the World Bank will undertake wide-ranging legal due diligence exercises, including around data protection legislation. In countries where the Bank considers that the data protection legislation which is in force conforms with international data protection standards, that legislation is deemed adequate. In countries where no data protection legislation has been implemented, the Bank will generally include contractual obligations requiring relevant government and implementing agencies to adhere to data protection standards.
While the existence of national legislative frameworks and contractual obligations implementing international data protection standards are certainly necessary and represent an initial step towards strengthening people’s rights to control how their data is used and processed, we are concerned with whether these legal safeguards and contractual provisions are, in fact, practically enforced or enforceable. For example, it is not generally clear which domestic authority within a state is responsible or indeed accountable when it comes to upholding these standards. Additionally, of the case studies we looked at, only Nigeria, Angola, Lebanon, and Morocco have implemented data protection legislation.

Strengthening safeguards (2): practical ways of mitigating risks to personal data and protecting human rights

Through our research, we also came across provisions within the World Bank’s project implementation documents which require grievance mechanisms to be set-up as part of the social protection programmes. This is an essential tool for individuals and communities to be able to challenge decisions around eligibility or report mistreatment.
Whilst these measures are welcome, at the same time, based on our review of publicly available project implementation documents and the related social impact assessments for the countries we looked into, it is not clear whether or not the World Bank put in place the necessary mitigations or safeguards to limit harms which result from issues such as inter-agency unauthorised use of sensitive personal data, data leaks, algorithmic bias, inaccurate data on registry systems, lack of enforcement of data protection laws, lack of transparency around automated eligibility criteria, or the lack of alternative (non-digital) means of accessing social safety-net payments.
The hardship that people who work within informal economies, those who are unemployed, and anyone who is undocumented in their state of residence faced throughout the global Covid-19 pandemic uncovered severe gaps in governments’ ability to uphold people’s socio-economic rights to health, food, and housing. We recognise that the World Bank, along with other development banks finance a diverse range of projects aimed at strengthening states’ infrastructure to deliver these rights – especially during crises. At the same time, our goal is to ensure that in the process of designing and implementing financing agreements which seek to solve these problems, we are not inadvertently laying the foundations for intrusive welfare systems.
Whilst we appreciate the urgency faced by Covid-19 and the specific needs which emerged, the rationale and approach of many of these projects were not new. Organisations like the World Bank and others have been deploying social protection projects for decades. The safeguards we are calling for should have been part of the default approach to designing and implementing social protection projects to protect people and their data which we have yet to see being put into place. Had these safeguards been already built in by design and default they would have set a better starting point to face and respond to the unprecedented socio-economic crisis which emerged with the Covid-19 pandemic.

They can get it right. It's a choice.

Social protection should not have to come at the cost of people's fundamental freedoms and rights to dignity and equality. We can build agile and resilient social protection systems, without accepting disproportionate interferences with people's fundamental rights as an opportunity cost.
Safeguards already exist and can help mitigate the risks and concerns which have been documented: from undertaking comprehensive human rights due diligence, to enforcing existing legal and regulatory obligations - including data protection and equality laws. These are just a few examples of how development institutions can reign in the ambitions of governments and companies to surveil and exploit people and their data. As part of a broader and systematic approach and governance of social protection programmes, we need to see these being built in by design and default.
Unfortunately we have not seen international institutions implementing these safeguards, even prior to the pandemic. They should be ensuring that the benefits which may emerge from technological advancements are also designed to empower and serve individuals and communities. Technology must be a tool which advances people's enjoyment of their fundamental rights and freedoms equally, freely and with dignity.
We must see entities like the World Bank (and other international agencies working on social protection and development) demonstrate how their approach and decision-making processes, in terms of design, financing, and technical assistance, are underpinned by a commitment to ensuring that social protection programmes serve the needs and realise the rights of all. In particular, they must serve the needs of the people these organisations aim to assist "the poorest and most vulnerable."" This includes ensuring that the governments they work with are committed to upholding their obligations to protect and respect people and their rights, in addition to taking pro-active steps to progressively realise these rights.