Internal secondary use is constrained too
Aliases: secondary data use · internal data reuse · function creep
What it is
Internal secondary use occurs when an organization repurposes service data for another internal objective, such as product analytics, employee evaluation, risk scoring, or model training. Keeping data inside the company does not preserve its purpose. Purpose limitation follows new consequences for people, so an organizational boundary cannot replace a use boundary, and existing access does not authorize unrestricted reuse.
Why it happens
Internal reuse thrives in centralized warehouses, broad role permissions, and low-cost query environments. A receiving team sees fields without necessarily understanding the disclosure context, quality limits, or user expectations, and may reinterpret operational traces as ability, preference, or risk. Because secondary use triggers neither a vendor contract nor an external-transfer cue, “same company” intuition can let it bypass scrutiny more easily than third-party sharing.
Studying it
Organizational studies can combine access graphs, query-purpose labels, lineage, and cross-team interviews to trace data from its original function into a new decision. Measures include cross-purpose access, queries without valid labels, recipient understanding of data meaning, and disparate effects of secondary outputs. Permission logs alone do not show how analyses enter decisions; reports, features, and human workflows must be followed downstream.
Where it stops holding
Diagnostics, capacity planning, and security monitoring may be closely coupled to delivering the original service, but still require limits on detail and access duration. Truly anonymous aggregates can reduce person-level purpose risks; small-cell slices, stable identifiers, or drill-down access restore linkability. A shared legal entity, account system, or employee confidentiality agreement does not by itself establish compatibility.
Applying it
- Authorize access by purpose and task, rather than granting an entire historical warehouse with membership in an internal role.
- Require secondary projects to state collection context, new output, affected people, prohibited uses, and expiry, with review by the originating data owner.
- Provide de-identified, sampled, or isolated environments for exploration and prevent provisional results from entering production decisions without assessment.
- Audit cross-team queries monthly and trace samples to reports or models; revoke unexplained paths and remove their artifacts when reviewers cannot justify the consequence as reasonably expected.
Related
- Same group: O1.03.1 Data must not be used for purposes undisclosed at collection · O1.03.2 Expanding purpose requires renewed notice and consent
- Adjacent: O1.08 Contextual integrity · O2.13 Disclosure of third-party sharing
- Search terms:
secondary data use·function creep·purpose-based access control