Ethical Secondary Use of Service Data: Governance for Analytics, Performance, and AI

Community services increasingly rely on secondary use of data: analytics for performance, segmentation for outreach, predictive risk flags, and—more recently—AI-assisted decision support. Done well, this improves equity and outcomes. Done poorly, it feels like extraction: data taken from people in vulnerable circumstances and used in ways they did not expect. Ethical secondary use is therefore both a governance requirement and a service quality strategy. This article sits within Trust, Transparency & Ethical Data Use and connects to system expectations described in Health and Social Care Interoperability Frameworks.

What makes secondary use “ethical” in operational terms

Ethical use is not a philosophical label; it is a set of decisions that can be evidenced. At minimum, organizations should be able to show: a defined purpose (and purpose limits), proportionality (the minimum data needed), appropriate de-identification or access controls, a fairness and harm review (especially for algorithms), and a feedback loop that shows benefits flow back into service improvement rather than disappearing into dashboards.

Ethics also includes the human experience. If people feel judged by invisible scoring, or if outreach is based on sensitive inferences, engagement may collapse even if the activity is technically permissible. Ethical governance therefore must include trust impact assessment, not only legal compliance.

Oversight expectations for analytics and AI in community settings

Expectation 1: Purpose limitation and proportionality are explicit and evidenced

Funders, auditors, and system partners increasingly expect organizations to define what analytics or AI is for, what it is not for, and why the data used is proportionate. “We use data to improve services” is not specific enough for review.

Expectation 2: Automated insights do not replace accountable human decision-making

Where analytics drives prioritization, eligibility pathways, or risk flags, reviewers expect a clear human-in-the-loop model: who can override, how disagreements are handled, and how the organization checks that automated signals do not create inequitable outcomes.

Operational building blocks for ethical secondary use

Ethical secondary use is easier when it is built on standard components: a request-and-approval process for new analytics, a data minimization template, a de-identification and access-control checklist, a fairness review for segmentation or models, and a communications approach that explains secondary use in a way people can understand. The goal is to make ethical checks routine rather than exceptional.

Operational examples

Operational Example 1: Analytics request workflow with documented purpose limits

What happens in day-to-day delivery: When a team proposes a new dashboard, segmentation, or model, they submit an analytics request describing the purpose, decision(s) it will support, data fields required, retention period, and intended recipients. A governance reviewer checks proportionality and confirms purpose limits (for example “outreach prioritization” is permitted, “eligibility denial automation” is not). Approved requests are logged with version control so future audits can see what was approved and when.

Why the practice exists (failure mode it addresses): The failure mode is analytics sprawl—reports and extracts created informally, reused for new purposes, and shared beyond the original intent. Over time, no one can explain what a dataset is being used for or whether it remains appropriate.

What goes wrong if it is absent: Staff share extracts widely “because it’s helpful,” people experience unexpected outreach or decisions, and the organization cannot credibly demonstrate purpose limitation under scrutiny. Trust damage follows even if the analysis was well-intended.

What observable outcome it produces: The organization can evidence purpose limitation, show approvals and constraints, and demonstrate that secondary use is governed. It also reduces unnecessary data fields in analytics because proportionality is reviewed at the start.

Operational Example 2: Ethical outreach segmentation with fairness checks

What happens in day-to-day delivery: A program team uses segmentation to identify people who may benefit from proactive outreach (for example missed appointments or repeated crisis contacts). Before deployment, the team runs a fairness check: reviewing whether the segmentation disproportionately targets specific demographic groups, whether outreach scripts could be perceived as punitive, and whether alternative explanations exist (transport barriers, language needs, unstable housing). The outreach workflow includes a “reason for outreach” explanation and a mechanism to record objections or preferences.

Why the practice exists (failure mode it addresses): The failure mode is inequitable targeting—where analytics inadvertently concentrates surveillance-like attention on certain communities or creates stigma through the way outreach is framed.

What goes wrong if it is absent: People feel profiled, decline services, and negative word-of-mouth spreads through communities and professional networks. Even helpful programs can be labeled coercive if segmentation is not governed and explained.

What observable outcome it produces: Outreach acceptance improves, complaint rates reduce, and teams can evidence that segmentation was reviewed for fairness and trust impact. Adjustments become data-driven (e.g., removing sensitive proxy variables, changing thresholds, improving scripts).

Operational Example 3: Human-in-the-loop model governance for AI-assisted risk flags

What happens in day-to-day delivery: If an AI or rules-based model generates a risk flag (for example potential deterioration or safeguarding concern), it is treated as a prompt, not a decision. The workflow requires a human review: a clinician or designated supervisor assesses supporting evidence, contacts the person if appropriate, and documents whether the flag was confirmed, rejected, or deferred. The organization monitors false positives/negatives, tracks override patterns, and reviews whether model performance differs across populations.

Why the practice exists (failure mode it addresses): The failure mode is automation bias—staff treating a flag as “the truth,” leading to unnecessary escalation, stigma, or restrictive responses. It also addresses the risk of hidden model drift and uneven performance across groups.

What goes wrong if it is absent: People may be escalated unnecessarily, services may allocate scarce resources based on unreliable signals, and staff may become dependent on automated outputs without understanding limitations. Under review, the organization cannot show accountable decision-making.

What observable outcome it produces: Decisions remain accountable and auditable. The organization can evidence how model outputs were used, how humans reviewed them, and how equity impacts were monitored. Trust improves because the system can explain that automation supports, rather than replaces, professional judgment.

Making benefit visible: the trust dividend

Ethical secondary use is strengthened when organizations can show tangible benefits: reduced missed follow-ups, fewer preventable escalations, improved timeliness, or more equitable access. Where possible, organizations should communicate these benefits in plain language to communities and partners. When people can see that data use improves service quality, trust becomes easier to sustain.

Secondary use will continue to expand. The organizations that succeed are those that treat ethics as an operating model: purpose limits, proportionality, fairness checks, human accountability, and evidence that the benefits of data use flow back to the people whose lives generated the data in the first place.