What does Data Ethics mean?
Data ethics deals with the question of which uses of data are justifiable, even where they would be legally permitted. It picks up exactly where the law leaves room for judgment: in choosing the purpose, in the volume of data collected, in weighing the consequences. It differs from data protection in that it does not check compliance with a rule but calls for a weighing of interests.
In practice, data ethics comes down to a few recurring questions. Who benefits from the analysis, who bears the risk, and would the outcome still be justifiable if the people affected knew about it? These questions are supplemented by impact assessments, by involving the affected groups, and by a written record of the alternatives that were rejected. Timing is what matters: the assessment belongs before implementation, not after.
Such an assessment pays off wherever an analysis is technically possible and legally permitted but affects people who cannot opt out of it. Typical cases include analyzing employee data, building customer profiles, and passing entire datasets on to third parties. For technical analyses with no personal reference, the question does not arise.
The benefit of a documented assessment becomes clear as soon as a project is publicly questioned: the reasoning is on record and does not need to be reconstructed after the fact. Such an assessment also prevents technical feasibility alone from being the deciding factor. And anyone who records the alternatives they rejected does not have to have the same debate again from scratch on the next project.
Data ethics does not replace a legal review and is not binding on its own. It becomes effective through its timing: the assessment happens before implementation. Its outcome feeds into the decision, not into a project report filed away afterward.