used the dataset for and what more they would like to be able to do with it, such as which legal processes the dataset could support and whether there were other datasets that, if combined with the legislation data, would yield deeper insights. From these interviews, we develop a list of recommendations for improving the datasets that included: • Establishing a working definition of digital rights as a foundational framework to develop criteria for which laws, cases and decisions are included. • Including context on the legal landscape that encompasses the type of legal system, relevant portions of major pieces of legislation, specific case law, and relevant international legal instruments binding on the state. • Including draft laws, because it is easier to challenge a bill than to reform legislation. • Including specific provisions of laws, such as sections or articles governing digital rights. • Including the most important of well-known court decisions to understand how the judiciary perceives the issues. • Including corporate policies, terms of service, privacy policies, etc. • Indicating the source of the law or translation, and whether it is official, as well as creating a source-ranking methodology for secondary sources (i.e., ranking of some reports would be higher than others) and categorising sources as either primary or secondary. • Refining the categorisation of the laws and adding subcategories and tags to make data more granular and searchable and in line with existing taxonomies and schema. • Noting discrepancies between international treaties and national constitutions and laws. Considering the addition of laws that impact association and assembly, social media companies and applications, such as VoIP restrictions or shutdown decrees. • Interviewees also shared ideas about specific functionalities for the dataset, as well as its design, maintenance and expansion. Even ethical considerations arose, as some warned that highlighting court cases without redacting names could potentially re-victimise people. After consulting with the legal and technical advisers, it was clear that we would not be able to include all items on the wish list. We prioritised those elements that we considered essential to building a minimum viable data product, based in part on the frequency with which they were mentioned. These included being more explicit about how we define digital rights to limit the scope of the inquiry; sourcing the documents and translations so that their provenance and whether they were official or unofficial was easily verifiable; identifying relevant provisions within documents to help users pinpoint those articles that are most directly connected to digital rights; and including draft laws, where possible. Step 2: Developing a working definition of “digital rights” Creating a database of legislation related to digital rights is a simple notion in theory; in practice, it is quite something else. To quote privacy scholar Graham Greenleaf, who has catalogued the world’s data privacy laws, “Before answering a simple question” – like, how many countries have data privacy laws? – “it is sometimes necessary to answer some more complex questions first.”16 For the purposes of his research, Greenleaf needed to define “What is a country?”, “What is a law?”, “What scope must a law have?”, “What data privacy principles must a law include?” and “How effective must a law be?” By considering and answering these questions, Greenleaf established “the minimum criteria that reasonable and impartial observers could agree constitute a ‘data privacy law’ or ‘data protection law’ when satisfied.”17 Because the datasets intend to catalogue legislation affecting digital rights we also need to ask, What are digital rights? and, How will we identify and locate a law or other legal instrument that affects digital rights? Defining “digital rights” Perhaps surprisingly, there is no commonly accepted definition of digital rights. Nor is it clear when the term first emerged.18 The European Digital 16 Greenleaf, G. (2014). Sheherezade and the 101 data privacy laws: Origins, significance and global trajectories. Journal of Law, Information & Science, Special Edition: Privacy in the Social Networking World, 23(1). https://papers.ssrn.com/sol3/papers. cfm?abstract_id=2280877 17 Ibid. 18 We theorise that it could have emerged as a derivative or truncation of the phrase “digital rights management” or DRM, a process by which code embedded into multimedia files, like movies or songs, prevents users from sharing files. Searching the archive with the term “digital rights” brought up 98 pages of results from as early as 2003. Until the late 2000s, most of the results containing “digital rights” pertained to DRM, a key advocacy issue for the Electronic Frontier Foundation. Methodology / 9

Select target paragraph3