Silvana Fumega and Larissa Magalhães

The idea for the session “Datafication without Accountability: When Transparency Frameworks Fail Democracy in the Global South” started with a conversation between the two of us. We kept coming back to an asymmetry we were seeing in our work: governments were becoming much better at connecting data to deliver services, manage programs and make decisions, while the information needed to scrutinize those same governments often remained fragmented, difficult to connect or simply unavailable.

That conversation became the starting point for research supported by the Datafication and Democracy Fund, looking at Brazil, Colombia and Nigeria and drawing in part on findings from the Global Data Barometer. It also led us to a question that stayed with us as the research developed: what happens when the State becomes increasingly legible to itself through data, without becoming equally legible to the public?

We took that question to CPDP Latam 2026 in Rio de Janeiro, where Gregory Michener, Renata Avila, Otávio Moreira Neves and Fernanda Campagnucci joined the discussion.

The starting point was not that transparency reforms have failed. Over the past two decades, governments have built access to information regimes, adopted open data policies, created data protection frameworks and invested heavily in digital government. More recently, digital public infrastructure and AI have become part of the same landscape. Many of these reforms matter. But their expansion has also made visible a gap between the capacity to produce and use data and the capacity to use those data to hold government to account.

We see this in the Global Data Barometer. Countries can have relatively sophisticated governance frameworks while information that matters for public scrutiny remains unavailable or difficult to use. The cases we have been examining make the problem more concrete. In Nigeria, relatively strong formal frameworks for public finance and access to information coexist with major gaps in the actual availability of public finance data. Colombia has developed sophisticated procurement systems such as SECOP II, greatly expanding the information available about public contracting, but connecting procurement information with other data needed to follow relationships, influence or potential conflicts of interest remains difficult. Brazil has some of the region’s more developed public data infrastructures, raising a different question: whether the capacity created through those infrastructures can also make government easier to scrutinize.

These are very different cases, but the asymmetry is familiar. Governments increasingly know how to make data work together when they need them for administration or service delivery. The same is not always true of the information that journalists, legislatures, civil society or oversight bodies need to reconstruct a decision, follow public money or establish who was responsible for it.

Interoperability is a good example. It tends to be discussed as a technical problem: getting systems to communicate, agreeing on standards, making databases compatible. Yet choices are being made about which systems should communicate and which problems deserve the institutional effort needed to connect them.

Imagine a company receiving a large public contract. Information about the contract may be public. So may information about the company’s beneficial owners, political donations or lobbying activities. But if those records use different identifiers, formats or standards, each disclosure remains an isolated piece of information. Meanwhile, the State may already have built sophisticated systems for linking information about individuals across multiple databases to determine eligibility for a service or administer a program.

The capacity to connect information exists. It is simply not distributed equally across purposes.

This was where the discussion began to move beyond the availability of data itself. Otávio Moreira Neves described some of the much less visible work involved in making Brazil’s open data commitments function across government: coordinating agencies with very different capacities, deciding what gets published and keeping datasets useful and updated over time. An open data policy can create an obligation to publish, but there is still considerable institutional work between that obligation and data that someone can actually use.

Fernanda Campagnucci picked up the problem from the other side. Even when useful information is available, journalists, civil society organizations, researchers and affected communities need somewhere to take the questions it raises. Information can reveal a problem without anyone being required to explain it. Civil society can identify a pattern without an oversight body having the authority to investigate it. An investigation can establish what happened without producing correction or remedy.

Gregory Michener’s discussion of Mexico’s National Institute for Access to Information (INAI) added another part of that picture. INAI was long regarded as one of the strongest information commissions internationally, yet it was eventually dismantled as an autonomous institution. Its trajectory is a reminder that accountability chains depend on institutions with enough authority, resources and political resilience to act. Formal transparency guarantees can be strong on paper and still prove vulnerable.

AI places further demands on institutions that were often designed around access to documents and public information. They are increasingly expected to deal with automated systems, interconnected databases and technologies that may be difficult even for the public institutions using them to fully explain. Whether an access to information or oversight body formally has jurisdiction is only part of the issue. It also needs enough technical knowledge and institutional authority to exercise it.

At the same time, the systems themselves are becoming harder to draw boundaries around. Larissa brought this into the conversation through the increasingly complicated relationship between governments and private technology providers. What looks from the outside like a government service may depend on several agencies, cloud infrastructure, software contractors, an identity system and external sources of data.

The basic accountability question, who is responsible, can become surprisingly difficult to answer. If an automated system produces an unfair outcome, is responsibility with the agency using it, the institution that procured it, the company that developed it or the provider operating the infrastructure? Public responsibility does not disappear when technology is outsourced, but in practice it can become dispersed across contracts, institutions and technical systems.

AI makes this more visible, but the problem predates AI. Digital public infrastructure already requires governments to know how data move between institutions, who operates each part of a system, what was agreed through procurement and what can be independently audited. When public functions depend on private providers, those questions become part of ordinary public accountability.

There is another complication. What if the State does not fully control the infrastructure it is expected to govern?

Renata Avila warned against assuming that greater technological sophistication necessarily means greater State capacity. For developing countries in particular, architectures heavily dependent on cloud services and a small number of large technology vendors can expand what governments are able to do while creating new dependencies at the same time.

A government may acquire a sophisticated system without having the people, knowledge or resources needed to understand it, modify it or operate it independently. In that context, simplicity and maintainability are not signs of technological backwardness. They may determine whether a public institution can actually govern the technology it uses.

This also complicates the idea of openness. Public data should not simply be made available so that others can extract value from them. Governments need to retain the ability to use data themselves, to respond to local needs, improve public services and create public value. Avila described this in terms of governments acting as custodians and enablers of data while retaining enough infrastructural autonomy to perform those roles over time.

As the discussion unfolded, it became increasingly difficult to locate data governance within any single institution. A data protection authority may oversee one part of a system, an access to information body another, while procurement authorities, digital government agencies and sectoral regulators deal with others. Data, however, move across those institutional lines. Identity systems connect services. Private companies operate infrastructure used by multiple agencies. An AI application may rely on data held by one institution, infrastructure provided by another actor and a model supplied by a third.

There may be no single actor with a complete view of the system.

Nor would it make sense to govern every part of it in exactly the same way. A persistent identification system raises different concerns from a consent based data sharing mechanism, and both differ from an AI system used to support public decisions. They may require different combinations of institutional guarantees, common standards, user control, traceability, explainability and independent auditing.

The difficult questions tend to appear at the points where those systems meet. If data move from one institution to another, can their use still be traced? If a decision depends on several agencies and private providers, can someone still determine who is responsible? If an automated system affects a person, is there enough information outside the system to understand and challenge what happened?

Publishing more data will not answer those questions on its own.

This brings us back to the conversation that started the session. Governments need the capacity to use data, and better data infrastructures can produce real public value. But scrutiny needs infrastructure too. Someone has to be able to document how systems work, follow data across institutional boundaries, audit decisions and determine who is responsible when several actors are involved. Oversight institutions need the authority and knowledge to ask those questions, and people outside government need enough information to ask them in the first place.

The concern is not that the State is becoming more capable of using data. It is what happens if the capacity to scrutinize that power develops much more slowly.

A State that can connect and use data at scale, but cannot explain how those systems work or who is responsible for them, may be more datafied without being more accountable.

Posted in

Leave a Reply

Discover more from Silvana Fumega

Subscribe now to keep reading and get access to the full archive.

Continue reading