3.1. Politics and public administration: On milestones, guardrails and trust anchors

The Internet has narrowed the gap between politics and the private citizen

For politics and policymakers, the Internet is an area of increasing relevance and importance and, at the same time, not the area that many would choose to focus on. But it is no longer an option to avoid taking a hard look at both the opportunities and risks associated with the Internet, as online infrastructure and services continue to penetrate nearly all aspects of everyday life. The rise of the Pirate Party, news reports about data scandals and the copyright debate – these are all issues that require urgent attention. These issues are out on the streets; they are not just being discussed quietly in back rooms. Fellow citizens previously thought to be more apathetic than engaged are suddenly out demonstrating against ACTA. Data privacy and security is the subject of small talk – even around the grill in small town backyards.

There are new opportunities for political participation and a narrowing gap between people and politics. Policymakers have recognized that they can no longer afford to insulate themselves from the many pressing issues regarding the Internet. At the same time, they have hardly begun to tap the potential that these issues represent. With the rapid development and pace of all things on the Internet, policymakers see themselves in a competition to acquire knowledge and get up to speed (“you need to learn and get up to speed very quickly on many issues”). It is hardly surprising that Internet policy- makers often owe their success to their affinity for the Internet and to being among the first to “go online” within their respective party. But it remains an enormous new field and each individual issue requires detailed, specific knowledge.

“That goes for all areas – from copyright law, to the threat of phishing in the context of online banking; from e-commerce to business-to-business communication, machine-to-machine communication, and so on. And everywhere you look there’s this question – who is responsible? Who is going to take on responsibility? And maybe it is simply too early for this discussion, because this is a discussion that does require certain background knowledge and some grounding in the subject matter.”

An additional challenge is that policy-makers cannot afford to just concentrate on the issues being discussed and decided upon today; they need to make the effort to increase awareness and engagement on these issues within their own ranks (“politics and politicians are among the latecomers to the Internet”). In their view, Internet policy works the same as women’s policy, for example – first one must do a lot of persuading with broad strokes before addressing specific issues in a way that is relevant to the individual stakeholders.

“This is what you see in transition periods. In the early phases of industrialization there were so- called industry ministries. Today it would be reasonable to ask what the ministry of economics actually does – other than getting involved and interfering with everything. Of course you could say that the energy ministry belongs in the ministry of economics as well – and the environment ministry too – but then maybe also the ministry for social affairs and so on. That’s nonsense. In my opinion, we clearly need to try to integrate [Internet policy] into the classical branches as they exist today. And the problem we have now is that in certain of these classical branches we still have blinders on when it comes to modernity.”

Those working in public administration mainly regard the Internet as an instrument for improving workflow efficiency and speeding up processes. It is used, for example, to coordinate exchange and communication between individual departments and as a way to simplify communication with private citizens, even if it means giving up some control and letting things run their course a bit more. In this sense, the Internet is mainly regarded as a tool – a means to an end, but not an end in itself.

“A very important issue for us is participation. I believe that the Internet represents a great opportunity to significantly narrow the gap between politics and the people.”

“IT is not an end in itself. It is there to streamline administrative processes and enable other processes that were not technologically possible up until now.”

Safety and security of the people as the primary goal of public policy

Public policy and administration sees its primary duty in the care and protection of the people. With the Internet becoming more and more essential to more and more aspects of daily life, it has become one of the most important jobs of policymakers today to ensure that people can use the Internet safely, securely and with confidence.

Policymakers see themselves as the ones responsible for the framework that defines what is possible, allowed and desirable for society. They want to apply structure to the Internet, make it more tangible and understandable, and bring it in line with existing political logic. Analogies from the offline world are applied here more than in any of the other sectors (see “Analogies from the offline world”, Ch. 2). Here, the equivalence principle, i.e. the transferability of principles and processes, is applied with regard to offline and online.

“And I believe strongly that we very much need to stick to conventions and maintain consistency
– that we need things like compliance, validation, certification, and so on, to make sure this digital world becomes a bit more manageable for consumers. […] The new identification card or “De-Mail” and the like are building blocks that are relevant to certain goals that we have, to make the Internet more secure, to create trust anchors and to put up some guardrails.”

“It is the job – the obligation – of policymakers and legislators to establish regulations that are fair and reasonable. […] The government must define the rules of the road, just as they do in other areas.”

At the same time – because of the huge discrepancies in the way people use the Internet and speed with which they navigate the web – there are clear limits to what can be done. Inevitably, the political decision-making processes (the traditional march through the official channels) lag behind the development of online services and structures. A sense of obligation to time-honored democratic values and principles may in fact be out of step with a constantly changing landscape of new conditions and situations, which can then become all the more difficult to manage.

“Things are progressing so rapidly and dynamically, that every effort to create guidelines or adjust the parameters is always a step behind. We are constantly having to build a framework around something that already exists.”

“And the risk grows with each passing day that the framework for any given situation does in fact not exist, because the legislative process is much, much slower than the pace at which the Internet continues to evolve.”

When it comes to the speed and responsiveness of policy-making, an important aspect to consider is the size and scope necessary for regulations to be fair and functional. The goal should be to provide as much security and protection as possible for private citizens, while placing as few restrictions as possible on Internet culture and its innovative power. Policymakers want to function as leaders in the information society and help secure Germany’s position as a leading business location and, at all costs, avoid being perceived as an enemy of business.

 “A positive vision of the future is that we take advantage of the opportunities that our country has in this information age – and the opportunities are great – that we seize upon these opportunities and, in a country that is becoming ever smaller due to demographic change and gradually losing its ability to compete internationally in areas such as manufacturing, that we create conditions that allow people here to enjoy growth and prosperity over the long term by developing and implementing intelligent information technology systems and creating a general framework that allows people in this country to use information technologies in a way that is exceptionally safe and secure.”

The dilemma is obvious: Protecting the rights of the individual (the private citizen) means limiting the freedom of the other (the company) – a freedom which of course also must be preserved. This tension between these conflicting priorities is neither new nor surprising. But what happens when so-called “freedoms” run up against the existing laws?

“This is not a fight against business, but a fight for a part of the Internet in the sense that companies cannot be allowed to have everything. The users need to be protected. But my basic stance is to say: where would we be without Apple, YouTube and other companies? So I have a positive view of business. Business brings us forward. When businesses manage to make a profit, they invest and develop new business models. That is always positive. It becomes questionable when businesses and business models become too dominant and do not include sufficient provisions to protect users.”

Dominance of global corporations threatens the ability to keep control of the state

Political opinion-leaders focus their attention, on the one hand, on the big “players” on the Internet – their legal infringements, their growing dominance, and the speed at which they are evolving. At the same time, they concern themselves with Internet users, i.e. those individuals who need to be protected from shams and other dishonest business practices.

Policymakers see themselves up against a certain indifference on the part of global corporations, who make it difficult for them to pursue their social/political goals and defend traditional social/demo- cratic values.

“The fear that I have is that we begin to lose the accountability of our democratic institutions or that it will at least be limited as developments in the area of information technology are predetermined by market players, international developments and other forces, and that our institutions are no longer capable of putting up any opposition or resistance – that they are too slow on the European level, that we cannot agree quickly enough and that we no longer have much ability to influence developments at the national level. That is indeed a source of concern.”

From the point of view of policymakers, companies today are not investing nearly enough in security (mainly in software). They need to be held liable for damages to a much greater extent than they are today; especially since the negative impact affects not only their own company but also the interests of other members of society. There are simply too many clearly foreseeable “cracks” for hackers to get in and compromise data confidentiality or the security of Internet payment systems.

“What you need in this case is a legal framework that requires companies to meet certain requirements or take certain precautionary measures; if they fail to do this then they are liable – perhaps not for the full extent of damages, but liable for a portion of the damage to be determined. […] Certainly I could say to any company: that’s your own economic risk, whether or not you secure your data or ensure data security in your company. Except that we don’t go telling a chemical company: it’s your own economic risk whether your company functions or not, if your factory blows up in your face, then it’s your economic risk, then you face the loss of production. Instead we say: as soon as it moves beyond the factory grounds, where employees are impacted, if you contaminate the environment, when third parties are involved, then you are liable. So why shouldn’t that also apply to the large IT installations of big corporations?”

In addition, policymakers look at the business practices of the corporations – and here one often refers to the „Gang of Four“: Google, Apple, Facebook, Amazon. In their view, these dominant companies are increasingly defining their own reality, own rules and own code of values that goes against established value structures, including basic democratic values. They view this gradual concentration of power not just with concern, but with fear.

“We really do need to be careful that we don’t end up with just a few companies worldwide, who set very strict standards and whose corporate policies play a big role in shaping the Internet.”

Policymakers are also tuned into the user perspective and see themselves as mediators between business and consumer interests. And they all agree on one point: users know virtually nothing about Internet security. This is partly due to general naiveté, but in many cases, users simply cannot keep track of the consequences of their actions on the Internet (privacy settings on the social networks are often mentioned in this context). In these cases, basic legal parameters should be in place to protect the user from deception and manipulation on the part of providers – a legal frame of reference so that users know better what to expect and providers know that they will be held liable for damages. This liability also applies, of course, to users who behave unlawfully.

 “[…] aside from how the technology works, the users actually know very little about what actually happens with their data! There is a general lack of awareness on the subject of data usage. Many people who say ‘anyone can have my data’ have no idea what actually happens with their information. When you explain to them what goes on with their data, they will often say right away: ‘that should be illegal’.”

Government protection begins at the point where the user can no longer protect himself. But where do we draw the line? How much can we count on people’s ability to protect themselves? What should users be expected to know and understand? Even within the policy sector there is a broad range of opinions on these questions (see Ch. 5).

Finally, politics and administrative entities have their eye on the media as well. Because both individual users and media companies procure their information more and more online, policymakers are troubled by the lack of quality standards for journalism. But because the Internet has continued to evolve towards being the main, authoritative source of information, they consider a certain level of journalistic quality and reliability to be absolutely necessary.

 “How can we make sure that, at the end of the day, there is good journalistic content on the Internet, so that people have some orientation and access to relevant information? Of course mass information does not always correspond to relevance – it can be part of what is considered relevant. But there needs to be quality journalism as well.”

The need to define mandatory security standards and improve media literacy

The focus is on four areas:

a) Expanding participation in the digital world
b) (Technical) security standards
c) Protection from Internet crime
d) Awareness and education for greater Internet competency
Access to the Internet is considered the most important element of inclusiveness and broad participation. But policymakers also know that universal access has not yet been achieved. This is in part a technical/infrastructure issue. Especially in rural areas, fast Internet service (broadband) is not yet available to everyone. But modernizing the government and its administrative bodies is another important way to achieve better communication and more effective interaction with private citizens. This will require significantly higher acceptance among users, which is something that more user- friendly systems can help facilitate. Policymakers consider this the early phase in a process towards greater transparency and more open lines of communication between politics and private citizens. While some countries are working towards opening up all bureaucratic processes to the public and letting the people co-determine processes and outcomes, the prevailing view is that “offline channels” need to be maintained. Moreover, there is some uncertainty as to how much private citizens actually want to be involved in the political process.

The first and most urgent priority for policymakers is to define mandatory, binding security standards for the Internet – ideally on the EU level. It’s a race against time. Critical infrastructure is be- coming more and more dependent on the Internet while processes and providers are operating more and more independently. Malware is becoming a threat not only to individual networks and companies, but to entire countries. In the view of policymakers, providers have often purposely introduced faulty software to the market. And most feel that reliance on self-regulation mechanisms alone will not get the job done.

“As the Internet becomes more and more important, the government’s responsibility – to make sure everyone is playing by the rules – becomes more and more important too. This is already the case. My opinion is much different from the proponents of self-regulation who say ‘if everyone just watches out for himself it will work out in the end, the Internet is basically a big process of self- organization and government has no business getting involved.’ I think they are simply wrong. And it’s because this infrastructure has become far too critical to our lives.”

Policymakers see a critical role for education – improving people’s media literacy and overall savvy. The goal of policymakers is to establish more critical attitudes towards the Internet and a greater sense of responsibility among users when accessing the Internet and its many opportunities. Schools are considered an important facilitator and a natural way to sensitize young people to the issues as early as possible. Other institutions, such as organizations, foundations and associations, are seen as possible vehicles for imparting knowledge and raising awareness among adults.

 “Our approach is to try and teach people to take responsibility, which basically means making them competent enough so they know themselves what the actual risks are and how best to navigate the Internet so they can truly take advantage of the opportunity it offers. And that is certainly some- thing that one can influence very strongly with policy. For example, we could include a subject like ‘Risk and Opportunity in the Digital Age’ in the school curricula and make sure that kids are learning about this. After all, this is something that is just part of our lives now, and the job of the schools is to prepare people for their lives.”