The Joined-Up State-

Probabilistic Record Linkage, Automated Decision-Making, and the Architecture of Institutional Impunity

Glowing data streams flowing through translucent digital panels in a control room
Glowing data streams flow through translucent digital panels in a high-tech operations center.

By Andrew Paul Klein 

Method notes- Claims are classified throughout as Established, Inference, or Speculation. Where a claim rests on material that cannot be verified against a published source, it is marked as such. The paper does not propose any entity or advocate any policy. It examines the structural conditions under which population-scale identity resolution capabilities are being assembled, and the historical record of what happens when they fail.

Abstract

This paper examines the deployment of probabilistic record linkage tools — Splink in Australia and the United Kingdom, LexisNexis in the United States — as the construction of a population-scale identity resolution capability. The legal basis is statutory “public task,” not consent. The capability is migrating from batch statistics to real-time operations. The historical record from Robodebt, Windrush, and the National Fraud Initiative demonstrates that when such systems fail, the harm is concentrated on the vulnerable, accountability is institutional rather than individual, and redress is structurally inaccessible. The paper argues that the synthesis of these threads describes a predictable trajectory toward a “joined-up state” in which the capacity for automated identification outpaces the capacity for individual contestation. The central governance question is not the accuracy of the algorithm but the nature of the interface between the individual and the system.

1. Introduction: The Quiet Joining-Up

In May 2021, the UK Court of Appeal ruled that the immigration exemption in the Data Protection Act 2018 was unlawful, finding it contained inadequate safeguards to protect individual data subject rights and was incompatible with the UK GDPR. The exemption had allowed the Home Office to bypass certain data protection obligations in immigration enforcement. The court’s ruling was a remedial response to a structural problem: the legal architecture built for one purpose was being used for another.

A similar pattern is now visible across three jurisdictions. In Australia, the Australian Bureau of Statistics has adopted Splink — an open-source probabilistic record linkage tool — as its default linking tool for all person-level linkages. In the United Kingdom, the Ministry of Justice has built the same tool and is deploying it in real time in courts and probation. In the United States, the National Accuracy Clearinghouse for SNAP benefits is built, hosted, and maintained by LexisNexis Risk Solutions, a private data broker, and is being expanded to all fifty states.

Each of these deployments is lawful. Each is documented. Each is justified by a statutory “public task” rather than individual consent. Together, they describe a capability that is quietly migrating from counting populations to identifying specific individuals in the operational moment. This paper examines that migration, the historical record of what happens when these systems fail, and the structural conditions that determine the outcomes for the individuals caught within them.

2. The Technology: Splink and the Fellegi-Sunter Model

2.1 What Splink Is

Splink is a free and open-source Python library for probabilistic record linkage and deduplication at scale, capable of linking over 100 million records. It was developed in-house at the UK Government’s Ministry of Justice as part of the Data First programme, funded by ADR UK, to link administrative datasets across the justice space. The tool implements the Fellegi-Sunter model, a statistical method first designed in the 1960s for probabilistic record linking in contexts featuring fuzzy data.

The Fellegi-Sunter model compares records across multiple fields — names, dates of birth, addresses — and produces a probability score that two records refer to the same person. Record pairs above a specified threshold are considered the same person and assigned a new linked identifier.

The mathematics is sound. Fellegi-Sunter is the industry-standard method for record linkage, estimated via Expectation-Maximisation, and Splink’s implementation is transparent, publicly documented, and auditable. The concern raised in the public-interest literature is not about the algorithm’s accuracy. It is about the governance of what the accurate output enables.

2.2 The ABS Deployment

The Australian Bureau of Statistics has adopted Splink as the default linking tool for all ABS person-level linkages. The ABS presented its experience at the 65th ISI World Statistics Congress, explaining that Splink and the Fellegi-Sunter model “gives us the opportunity to address data quality challenges across the entire Australian government” and “will assist ABS to meet the growing demand for linked data products across federal and state jurisdictions”.

The ABS used Splink to build the 2024 National Linkage Spine underpinning the National Disability Data Asset, and for the 2025 Person Linkage Spine build. The ABS is also planning to use Splink for the Post Enumeration Survey as part of the 2026 Census quality assurance process. Splink has been endorsed to replace Febrl for the 2026 PES, with testing on 2021 data showing both methods produced a similar number of high-quality links.

The change to probabilistic methodology in the 2025 Spine resulted in a marginally higher linkage rate across all three datasets. The 2025 Spine contains approximately 39.87 million unique persons, with 48.54% containing information from all three source datasets.

2.3 The MoJ Deployment

The UK Ministry of Justice operates Splink in both batch and real-time deployments. According to the MoJ’s Algorithmic Transparency Record:

· It is used weekly to refresh linked datasets for statistical analysis.

· It is used in courts to find probation records associated with individuals coming to court.

· It is being piloted as part of Core Person Record, a product that aims to create a unique identifier for persons across prisons, probation, and the criminal courts.

· It is used to find Police National Computer (PNC) numbers associated with individuals, in order to request relevant arrest information from the police.

The Core Person Record is a real-time linkage system currently being piloted that aims to create a unique identifier linking each person across the MoJ’s criminal data systems. “In this system, as records are created and updated, Splink is used to predict whether the record links to other existing records in the system“. A parallel data-sharing pilot in Essex uses Splink to identify PNC numbers associated with individuals supervised by North Essex Probation Delivery Unit; those numbers are sent to the police each day to identify if any arrests have occurred.

3. The Australian Architecture: The National Linkage Spine and the NDDA

3.1 The Person Linkage Spine

The Person Linkage Spine is the central ABS asset for person-level data integration. It is based on the combined population from three core datasets:

· Medicare Consumer Directory (MCD) — Services Australia

· DOMINO Centrelink Administrative Data — Department of Social Services

· Personal Income Tax Client Register (PIT) — Australian Taxation Office

The ABS has two main pathways to link a person-level dataset to the Spine: a direct merge using a scrambled Medicare PIN, a Centrelink CRN, or an ATO Scrambled Identifier; or probabilistic linkage where no shared identifier exists.

The Spine contains direct identifiers for each individual and maps these to reference numbers in each dataset. The ABS acquires ATO data under the Census and Statistics Act 1905 and the Tax Law Amendment (Confidentiality of Taxpayer Information) Act 2010. The ABS states that the Spine and PLIDA “are statistical and data integration assets and are not used for compliance”.

3.2 The National Disability Data Asset

The National Disability Data Asset (NDDA) brings together de-identified information from different government agencies about people with disability. The ABS and the Australian Institute of Health and Welfare are co-technical lead agencies. The asset will connect information from multiple Australian, state, and territory government sources.

The privacy framework is built on the separation principle: personal information like names and addresses is kept separate from analytical data such as employment status. Authorised people who combine the datasets access some personal information, but that information is not made available to researchers, who see only de-identified analytical data.

The critical limitation, stated on the NDDA’s own privacy documentation: “You won’t be able access, change or remove information about yourself from the National Disability Data Asset. This is because we remove personal information, including names and addresses, from the data“. A Privacy Impact Assessment was conducted in 2023, with implementation reporting in 2024.

The National Disability Data Asset Council includes members from the disability community and government. The Charter explains the rules and principles and lists what the data cannot be used for — for example, it cannot be used to make decisions about a person’s access to government funding. Only approved researchers belonging to an Australian government agency, state or territory, or an Australian university can access the data.

The separation principle is a statistical safeguard. It protects the data from the analyst. It does not give the individual any standing to challenge the link, the data, or the resulting decision.

4. The UK Architecture: Statistics, Operations, and the Core Person Record

4.1 Statistics or Operations?

The MoJ’s Algorithmic Transparency Record is explicit about the dual use. Splink is used for statistical refresh and for operational identification. The distinction matters because the governance frameworks for statistics and operations are different. Statistical use is governed by principles of anonymisation, aggregation, and non-disclosure. Operational use is governed by the requirements of real-time decision-making.

The Core Person Record is the operational endpoint. As records are created and updated across courts, prisons, and probation, Splink predicts in real time whether the record links to other existing records. The result is a unique cross-justice person identifier assigned as records are created.

The North Essex police feed is the operational twin. Splink identifies PNC numbers associated with individuals supervised by North Essex Probation Delivery Unit; those numbers are sent to the police each day to identify if any arrests have occurred.

4.2 The National Fraud Initiative

The National Fraud Initiative (NFI) is a data-matching exercise conducted by the Cabinet Office under statutory powers set out in Part 6 and Schedule 9 of the Local Audit and Accountability Act 2014. Participation in the 2024 data matching exercise is mandatory under the Act. The NFI gathers over 8,000 datasets from 1,300 organisations to detect fraud across housing, pensions, and local authority services.

The DWP uses a risk model to flag housing benefit claimants, and the department mandates local authorities to review the cases the model identifies as highest risk. This is a system where the algorithm’s output is not a suggestion; it is a directive to scrutinise individuals. The Housing Benefit Accuracy Award Initiative (HBAAI) algorithm flagged approximately 400,000 cases a year. The DWP’s position is reportedly that “some level of algorithmic bias is to be expected because of how benefit payments” work.

4.3 The DPA 2018 Immigration Exemption

The UK Court of Appeal ruled in May 2021 that the immigration exemption in the Data Protection Act 2018 was unlawful, finding it contained inadequate safeguards to protect individual data subject rights and was incompatible with the UK GDPR. The High Court had previously upheld the exemption; the Court of Appeal overturned that decision. The government introduced remedial regulations in 2022 to address the declaration of incompatibility.

The exemption was a policy shortcut, not a judicial finding. It allowed the Home Office to bypass data protection obligations in immigration enforcement. The Court of Appeal’s ruling established that the shortcut was unlawful. The remedial regulations replaced it with a narrower, more conditional framework.

5. The US Architecture: The Private-Sector Nexus and “Improper Payments”

5.1 The National Accuracy Clearinghouse

The National Accuracy Clearinghouse (NAC) is a contributory system of beneficiary information to support accurate and timely investigations for the SNAP and D-SNAP programs. It allows participating states to identify and pursue dual participation in real time and make fraud-mitigating determinations at the point of application. Congress has mandated the use of NAC by all state SNAP agencies.

The NAC is built, hosted, and maintained by LexisNexis Risk Solutions, a private data broker. It uses LexisNexis High Performance Computing Cluster technology to “uniquely and accurately resolve the identities of applicants and recipients”. Participating state agencies receive near real-time results that compare their applicant or recipient with the contributory information from other states.

The NAC is described as a “front-end, real-time, automated solution” that “reduces and eliminates improper payments“. The term “improper payments” is a euphemism that covers both fraud and simple administrative error. The system creates a pipeline from an automated flag to an investigation. Some states have created an automated fraud referral that can directly open a case against an individual based on the data match.

5.2 Palantir and ICE

Palantir Technologies, the US data analytics firm, entered into a $30 million contract with Immigration and Customs Enforcement (ICE) to build an artificial intelligence-enabled platform called ImmigrationOS to provide “near real-time visibility” into the immigration lifecycle. ICE alone has approximately $145 million worth of contracts with Palantir, according to the American Civil Liberties Union.

In the UK, Palantir holds a £330 million contract to manage healthcare data on the NHS Federated Data Platform (FDP), awarded in November 2023 to a consortium led by Palantir Technologies UK alongside Accenture, PwC, NECS, and Carnall Farrar. The contract includes a break clause that would see the deal end in 2027. Both the Science and Technology Committee and the Health and Social Care Committee have called for the government to invoke the termination clause.

The NHS national data opt-out does not apply to the FDP because the data is classified as being used for “direct care” — patient care, for example when being treated by a doctor. This means patients cannot opt out of their data being processed by the Palantir-built platform. Foxglove, a legal advocacy organisation, has argued that there is no lawful basis to create the FDP as described in procurement documents within the current legal directions.

5.3 The German Constitutional Court Ruling

On 16 February 2023, the German Federal Constitutional Court ruled that the legal bases created in Hesse (2018) and Hamburg (2019) for the use of automated data analysis software — specifically Palantir’s “Gotham” — were unconstitutional. The court declared the Hamburg provision void and the Hesse provision incompatible with the constitution. The court did not prohibit automated data analysis entirely but required legislative “improvements” regarding the proportionality of the associated fundamental rights interference.

The ruling was significant because it named Palantir explicitly and established that automated data analysis constitutes a “considerable and independent fundamental rights interference”. Following the ruling, a wave of legislative activity occurred at both federal and state levels, with numerous laws introduced to create constitutional bases for automated data analysis.

6. The Historical Precedent: Robodebt

6.1 The Scheme

Robodebt was an automated debt-collection system operated by the Australian Department of Human Services between July 2015 and November 2019. It used income averaging to raise debts against welfare recipients, a process the department’s own legal advice warned was unlawful. The scheme issued illegitimate debts to more than 500,000 welfare recipients.

The human cost was documented in the Royal Commission’s report: “The ill-effects of the Scheme were varied, extensive, devastating and continuing”. The scheme caused significant mental and economic stress, and two deaths. The Royal Commission found that vulnerable cohorts — including deceased recipients and legally blind recipients — were listed as permanently excluded from the scheme, but the vulnerability indicators were not consistently applied.

6.2 The Royal Commission Findings

The Royal Commission into the Robodebt Scheme, led by Commissioner Catherine Holmes, published its report in July 2023. The government’s response described the scheme as “a failure of government that caused damage to people and their families”. The Royal Commission found that the scheme was “a crude and cruel mechanism, neither fair nor legal”.

The Commission made 57 recommendations, including Recommendation 17.1, which called for a legislated framework for automated decision-making: “where automated decision-making is implemented […] business rules and algorithms should be made available, to enable expert scrutiny”. Recommendation 17.2 called for an auditing body.

6.3 The Accountability Outcome

The Australian Public Service Commission’s Centralised Code of Conduct Inquiry Taskforce published its report on 13 September 2024. The findings:

· 2 former Secretaries of the Department of Human Services breached the Code of Conduct on 25 occasions.

· 10 current and former public servants breached the Code on 72 occasions.

· The breaches included “lack of care and diligence, lack of integrity in performing duties, and instances of misleading others and failing to uphold the APS Values“.

· Of the 16 individuals referred, 4 were found not to be in breach or their actions did not meet the necessary threshold.

· Sanctions were recommended for 5 current public servants, including reprimands, fines, and demotions. One individual left the public service before the sanction could be imposed.

· A number of respondents who were found to have breached the Code resigned or retired prior to, or during, the inquiries.

The APS Commissioner, Dr Gordon de Brouwer, apologised to the Australian public for the role the public service played in the design and delivery of the scheme.

The National Anti-Corruption Commission’s subsequent investigation found that two of the six individuals referred by the Royal Commission engaged in serious corrupt conduct. Serena Wilson, former Deputy Secretary of the Department of Social Services, intentionally misled the Commonwealth Ombudsman during a 2017 investigation. Mark Withnell, former general manager of the Department of Human Services, intentionally misled officers of the Department of Social Services during the preparation of a cabinet submission in 2015.

The commission found there was insufficient admissible evidence to refer either individual to the Commonwealth Director of Public Prosecutions for criminal charges. The Commission was satisfied that Catherine Halbert, Annette Musolino, Kathryn Campbell, and former Prime Minister Scott Morrison did not engage in corrupt conduct.

Kate Chaney MP described the outcome: “The lack of criminal referrals are cold comfort for the hundreds of thousands of Australians wrongly pursued by Robodebt, particularly the families who lost loved ones”.

6.4 The Class Action Settlement

The Federal Court of Australia approved the settlement of the Robodebt Class Action on 11 June 2021. The Commonwealth agreed to pay $548.5 million. A further settlement of $112 million was agreed in June 2026, including an additional $475 million for eligible group members who had registered to participate. The Commonwealth also repaid all debts and interest following the first-class action.

6.5 Strategic Ignorance and the Inverse Centaur State

Academic analysis of the Royal Commission evidence has identified the role of strategic ignorance in sustaining the scheme. Hannah and Botterill (2025) analyse “the role of strategic ignorance and knowledge avoidance in sustaining the scheme,” identifying “the specific strategies used by senior public servants over the life of the program to obscure or cast doubt over legal and policy advice”.

The concept of the “inverse centaur state” has been introduced to describe the structural relationship between the algorithm and the human decision-maker. In this model, “algorithms assume substantive decision-making while frontline bureaucrats are reconfigured as procedural interfaces“. The human remains in the loop, but only as a procedural step, not as a substantive decision-maker. The human absorbs the blame when the machine gets it wrong.

7. The Human Rights Framework

7.1 The Chowdhury Analysis

Chowdhury (2024) provides the most comprehensive human rights analysis of Robodebt in the Australian Journal of Human Rights. The article argues that “government agency use of erroneous automated decision-making systems in welfare raises human rights concerns” and identifies the shortcomings of administrative law in a digital welfare context.

The central finding: “the automated and high-volume nature of executive ADM, which can mass replicate erroneous decision-making, creates systemic rather than ad-hoc issues in individual cases and challenges the foundational principles of administrative law”.

The article analyses the International Covenant on Civil and Political Rights and the International Covenant on Economic, Social and Cultural Rights, identifying several human rights concerns raised by Robodebt. It recommends an obligation on government agencies to conduct a human rights impact assessment before deploying an automated decision-making system.

7.2 The Administrative Law Deficit

The current administrative law framework appears to be incompatible with providing adequate protections to ADM subjects. The automated and high-volume nature of executive ADM creates systemic issues that are not amenable to individualised review. A system that mass-replicates erroneous decisions cannot be corrected by individual appeals, because the error is structural, not incidental.

This is the core governance gap. The legal architecture was built for a world in which decisions are made one at a time, by identifiable human decision-makers, with reasons that can be examined and contested. Automated decision-making at population scale breaks that architecture. The decision is made by an algorithm, the reasons are in the code, and the volume is too high for individual contestation.

8. The Accountability Gap

8.1 Recommendation 17.1 and the Chaney Bill

The Robodebt Royal Commission recommended a legislated framework for automated decision-making. More than two years after the Royal Commission report was published, that framework still does not exist.

On 7 September 2026, Independent Member for Curtin Kate Chaney MP introduced the Automated Decision-Making (Safeguards and Transparency) Bill 2026, a Private Member’s Bill to establish Australia’s first legislated, mandatory framework for the use of ADM in government. The Bill was seconded by Dr Monique Ryan MP and welcomed by the Australian Federation of Disability Organisations.

Chaney stated: “In July 2023, the Robodebt Royal Commission found the automated debt recovery scheme was unlawful and recommended a legislated ADM framework as a solution to prevent similar failures from recurring. More than two years on, it still doesn’t exist and vulnerable Australians are paying for it”.

The Bill sets one standard for the whole of government: transparency about where ADM is used, mandatory human oversight and override for high-risk decisions, and a fast, genuine right to review. It also establishes a public register of automated government systems, overseen by the Commonwealth Ombudsman.

8.2 The Attorney-General’s Consultation

The Attorney-General’s Department is leading work to develop a consistent framework for the use of ADM in the delivery of government services, implementing the Government’s response to Recommendation 17.1. The consultation process has drawn submissions from civil society, legal experts, and advocacy organisations.

Some submissions have opposed Recommendation 17.1’s call for algorithms to be made available for expert scrutiny. The Australian government’s own consultation process has recorded opposition to the recommendation.

8.3 The Implementation Gap

The Australian Public Service Commission reports that 47 of the 56 recommendations have been implemented, with work on the remaining nine ongoing, four of which require legislation. The ADM framework is one of the four requiring legislation. It has not been introduced as government legislation. It exists only as a Private Member’s Bill.

This is the accountability gap. The Royal Commission recommended a framework. The government accepted the recommendation. The framework has not been legislated. The Bill that would implement it is a Private Member’s Bill, not government policy.

9. The Trajectory: What Comes Next

9.1 The Migration from Batch to Real-Time

The most critical structural shift is the migration of these tools from batch-processing statistics to real-time operational identification. The MoJ already runs Splink in both modes. The Core Person Record will assign a unique cross-justice identifier as records are created. The North Essex police feed sends PNC numbers to the police daily.

The ABS is currently using Splink for the Spine build, which is a batch process. But the infrastructure — the Spine itself, containing direct identifiers mapped across Medicare, Centrelink, and ATO records — creates a latent capability for real-time operational use. The existence of the infrastructure is the governance risk. Once the Spine exists, the demand to use it for “administrative need” overrides principle.

9.2 The Joined-Up State

The endpoint of this trajectory is the “joined-up state“: a single person-level profile across health, tax, justice, benefits, and census. The Splink investigation describes the UK state as already using Splink “to join citizens’ health, tax, justice, benefits and census records into single person-level profiles, lawfully, at population scale, and with no consent, no notification and no opt-out”.

The same investigation notes that “the same tool is quietly crossing from statistics into real-time operations (court use, a daily probation→police arrest-check feed)”. The distinction between statistics and operations is held throughout the investigation because it is the governance boundary. Statistical use is subject to anonymisation and aggregation requirements. Operational use is not.

9.3 The Palantir Layer

Across the same departments sits Palantir — proprietary, US-owned, operational — the layer where “statistics” becomes action. The investigation states plainly: “no documented Splink↔Palantir technical link anywhere”. The two are not wired together. But they operate in the same departments, and the distinction between them is the distinction between the statistical tool and the operational platform.

The German Constitutional Court ruled a Palantir-run police system unconstitutional and named Palantir in the judgment. The NHS Federated Data Platform, contracted to a Palantir-led consortium for up to £330 million, is facing calls for termination. The national data opt-out does not apply because the data is classified as “direct care“.

9.4 Individual Outcomes

The historical record from Robodebt, Windrush, and the NFI demonstrates a predictable set of individual outcomes:

1. Harm is concentrated on the vulnerable. The systems are deployed in welfare, disability, immigration, and criminal justice — precisely the areas where individuals have the least power to resist an automated error and where a wrong decision has the most catastrophic consequences.

2. Accountability is institutional, not individual. As with Robodebt, the response to failure is Royal Commissions, apologies, and administrative sanctions (reprimands, fines, demotions) against low-level or retiring officials. The senior architects of the system are insulated by the procedural labyrinth and the doctrine of “public task.” The NACC found insufficient evidence for criminal referrals.

3. The erosion of redress is structural. A system designed for real-time operational identification does not have a natural built-in mechanism for appeal. The “separation principle” is a statistical safeguard, not a legal one. It protects the data from the analyst, but it does not give the individual any standing to challenge the link, the data, or the resulting decision. The NDDA confirms: “You won’t be able access, change or remove information about yourself”.

4. The “public task” justification is absolute. The legal basis of “statutory public task, not consent” creates a category of state action that is immune to the ordinary expectations of permission and individual veto. It is the administrative state’s version of sovereign immunity, and it will be used to justify the expansion of these systems into every domain of life.

10. Conclusion: The Record as Corrective

The evidence supports three conclusions.

First, the deployment of probabilistic record linkage tools in Australia, the UK, and the US constitutes the construction of a population-scale identity resolution capability. The technology is published. The deployments are documented. The legal basis is statutory “public task,” not consent.

Second, the historical record from Robodebt, Windrush, and the NFI demonstrates that when these systems fail, the harm is concentrated on the vulnerable, accountability is institutional rather than individual, and redress is structurally inaccessible. The Robodebt Royal Commission found the scheme was “a crude and cruel mechanism, neither fair nor legal.” The accountability outcome was reprimands, fines, and demotions for a handful of public servants. No one was criminally charged.

Third, the migration from batch to real-time, from statistics to operations, from counting to identifying, is the structural variable that matters most. The governance frameworks for statistics and operations are different. The statistical framework protects the data from the analyst. It does not protect the individual from the state.

The unifying principle is that the interface is the governance question. The accuracy of the algorithm is a technical matter. The nature of the interface — who can access the data, for what purpose, with what safeguards, and with what right of contestation — is the political matter. The historical record suggests that the interface is being constructed to maximise capability and minimise contestation.

The corrective is the record. The Robodebt Royal Commission published its findings. The APS Commission published its report. The NACC published its findings. Brandon Myers has compiled the Splink investigation. The ABS has published its privacy assessments. The NDDA has published its factsheet. The gap between what the documents say and what the capability enables is the space where the public-interest question lives.

Someone has to keep the record. The record is what survives the platform.

Claim Status Summary

# -Claim -Status

1 ABS uses Splink as default linking tool for all person-level linkages Established

2 ABS used Splink for 2024 National Linkage Spine and 2025 Person Linkage Spine Established

3 MoJ runs Splink in real time in courts and probation Established

4 MoJ is piloting Core Person Record for real-time cross-justice identification Established

5 Person Linkage Spine contains direct identifiers and joins Medicare, Centrelink, ATO records Established

6 NDDA privacy framework is the separation principle; no opt-out exists Established

7 Legal basis is statutory “public task,” not consent Established

8 US NAC is built and hosted by LexisNexis and expanding to all 50 states Established

9 Palantir holds £330m NHS FDP contract; national opt-out does not apply Established

10 German Constitutional Court ruled Palantir-run police system unconstitutional Established

11 Robodebt caused two deaths and significant mental and economic stress Established

12 Robodebt Royal Commission found scheme “crude and cruel,” “neither fair nor legal” Established

13 NACC found insufficient evidence for criminal referrals Established

14 Chaney Bill 2026 is a Private Member’s Bill, not government legislation Established

15 Function creep from statistics to operations is the structural governance risk Established in UK; flagged as trajectory

16 The “joined-up state” describes the endpoint of this trajectory Inference

17 The interface, not the algorithm, is the governance question Inference

References

1. Australian Public Service Commission. (2026). APS response to Robodebt Royal Commission. https://www.apsc.gov.au/sites/default/files/2026-01/Document%20Pack_LEX%201704.pdf

2. Wuolanne, A. (2025). Modernising probabilistic linking at the Australian Bureau of Statistics using Splink. 65th ISI World Statistics Congress. https://www.isi-next.org/abstracts/submission/3753/view/

3. Ministry of Justice. (2025). MoJ: Splink Master Record. Algorithmic Transparency Records. https://www.gov.uk/algorithmic-transparency-records/moj-splink-master-record

4. Chowdhury, S. (2024). Technology is never neutral: Robodebt and a human rights analysis of automated decision-making on welfare recipients. Australian Journal of Human Rights, 30(1), 20–40. https://doi.org/10.1080/1323238X.2024.2409620

5. Australian Bureau of Statistics. (2025). Person Linkage Spine [FOI response 2025-26-87]. https://brandonmyers.net/static/evidence/foi/abs-foi-2025-26-87-response.pdf

6. National Disability Data Asset. (2024). Privacy Statement. https://www.ndda.gov.au

7. Chaney, K. (2026, March 11). NACC’s report on Robodebt is cold comfort for impacted families. https://www.katechaney.com.au/nacc_s_report_on_robodebt_is_cold_comfort_for_impacted_families_11_march_2026

8. Chaney, K. (2026, September 7). Chaney to introduce Bill to stop government algorithms making unchecked life-changing decisions. https://www.katechaney.com.au/chaney_to_introduce_bill_to_stop_government_algorithms_making_unchecked_life_changing_decisions_7_sep_2026

9. Anadolu Agency. (2026, September 26). UK Labour members push to cancel Palantir health data contract. https://anadolu.agency/en/world/uk-labour-members-push-to-cancel-palantir-health-data-contract/4070180

10. Verfassungsblog. (2026, September 2). Neues Spiel, neues Glück: Rege Aktivitäten der Gesetzgeber von Bund und Ländern seit dem „Palantir-Urteil” des Bundesverfassungsgerichts. https://verfassungsblog.de/palantir-gesetzgebung/

11. Myers, B. (2026). The Splink Investigation. https://brandonmyers.net

12. National Fraud Initiative. (2024). Code of Data Matching Practice. https://assets.publishing.service.gov.uk

13. National Accuracy Clearinghouse. (2025). Case Study. https://www.nationalaccuracyclearinghouse.com

14. LexisNexis Risk Solutions. (2025). Dual Program Participation May Be More Prevalent Than You Think. https://risk.lexisnexis.com

15. Royal Commission into the Robodebt Scheme. (2023). Report. https://www.royalcommission.gov.au

16. Hannah, A., & Botterill, L. (2025). Ignoring harm, saving face: non-knowledge, senior public servants and the Robodebt scheme. Australian Journal of Political Science. https://www.tandfonline.com

17. Scilit. (2026, April 20). Algorithmic Displacement of Administrative Discretion and the Emergence of Accountability Gaps: Evidence from the Robodebt Case. https://www.scilit.com

18. Federal Court of Australia. (2021). Robodebt Class Action Settlement. https://www.servicesaustralia.gov.au

19. Big Brother Watch. (2024). DWP Housing Benefit Accuracy Award Initiative. https://bigbrotherwatch.org.uk

20. Court of Appeal. (2021). R (Open Rights Group and the3million) v Secretary of State for the Home Department [2021] EWCA Civ 800. https://www.5rb.com

21. NHS England. (2024). Federated Data Platform and National Data Opt-Out. https://www.digitalhealth.net

22. Palantir Technologies. (2025). ImmigrationOS Contract with ICE. https://iqconnect.house.gov

23. Attorney-General’s Department. (2025). OGP Commitment — implementation update (June 2025). https://www.ag.gov.au

24. Splink. (2026). MoJ Analytical Services GitHub Repository. https://github.com/moj-analytical-services/splink

Leave a comment