Showing posts with label gdpr. Show all posts
Showing posts with label gdpr. Show all posts

Friday, March 23, 2018

Keep Calm And Get A Relationship

The whole Facebook-Cambridge Analytica debacle can be read as a lot of wailing and gnashing of teeth from people who like to see the internet as a wild west awaiting their control. But there is an important lesson for anyone using data.


First - why the fuss? There are already plenty of laws and forthcoming rules to prevent the misuse of data.

The General Data Protection Regulation explicitly states that someone's data cannot be used or stored without their express permission, for example.

So, even if you were to grant a company permission to use your data, you can't grant permission to them to use your friends’ data. A company can't ask for that or use that. Even Facebook realised this was a share too far in 2014 and ended the practice (which had until then been employed by 'abusive apps').

However, the argument is that all that data has already been hoarded by the bad guys. But GDPR will make every item they hoard subject to compliance. So even in the case of old data (which  loses its salience by the second in any event) the hoarder must make it easy for anyone to remove their consent and retrieve their data.

That's going to be a challenge for bad actors. And when the auditors come calling they will face fines for every single data point. And these are fines at the scale of 'put you out of business'.

The short term issue for Facebook and, therefore, for much of digital marketing and communications, is the breach of trust. This is based on the notion that we didn't understand the scale of what could be done with the posts and likes and comments we gave away in exchange for better connection with people and information that was useful or interesting to us.

Facebook could act on this, at least re the instance of Fake News. They could set their engineers to work creating an algorithm to automatically add links to fact-checking or cross-checking validated sites.

They could of course do the same for their adverts. Imagine the potential to cut through the lies...

However, these are only solutions if you have difficulty filtering truth from deceit. In reality we humans have a brilliantly well-developed ability to see through bull.

Large parts of our brains are dedicated to sorting the trustworthy from the cheats. (Martin Novak's Super Co-operators says this was essential to our ability to live in co-operative societies). Target me with all the propoganda you like, I won't be voting Nazi.

So we do have a responsibility in this as individuals. We choose what we are willing to believe, and we must ensure we apply our innate abilities to spot the fraudulent at all times.

And naturally - any business or organisation handling data must do so with care and with all due respect for the owner. It is this respect for the owner that points to the most critical learning.

If the digital industry takes one thing from Facebook's woes, it should be this:

Since the value of data rapidly decays, the relationship with the human behind the data is always going to be of far greater value than the data assets themselves.

Data is not the relationship. It is the output of a relationship. Get one.


Thursday, February 16, 2017

Why we should embrace GDPR

The General Data Protection Regulation due to come into force next May should be regarded as the biggest hint yet for companies to reshape themselves for the digital world - aligning with The 10 Principles of Open Business.

Rather than fear at the number of sticking-plasters that need to be applied to support business as usual, forward-thinking companies will be taking the hint; data ownership is no substitute for genuine relationships.

That's the real message of GDPR - stop hoarding data to exploit customers.
In fact it's very difficult to see in a post GDPR-world why any customer would choose to allow a company to retain their data unless (and they have to be transparent about this) their is a genuine and positive partnership defined in their data notices.

Of course companies can (and many should) spend time, trouble and money ensuring compliance by (for example);

  • Appointing a Data Protection Officer
  • Reviewing each and every business process to ensure data protection is designed in
  • Ensuring default privacy settings are set to high at each and every touch point
  • Making it crystal clear exactly what data is being stored about whom, for how long and for what purpose - at every relevant interface
  • Providing complete data portability - enabling users to withdraw access to all of their data and take it with them, at any point they choose,
  • Devising Data Protection Impact Assessments
  • Developing new processes to respond to requests for data and complaints about use
  • Preparing to defend your use of logarithms for the decisions they deliver and offers they make or do not make
With up to 4% of last year's global revenue at stake as a sanction, there's much sense in taking this very seriously indeed. However, much of the data storage, privacy and permissions issues become much less onerous if you shift  the nature of your relationship with customers - and in doing so your relationship with their data.

Start to think of data as less a substitute for a relationship - and more an enabler for building one through genuine engagement. 



The start point requires three simple steps:
1. Understand the role of the customer in your business: (Hint - the passive consumer no longer exists, if they ever did).
  • Where are the benefits in partnering; how far into the centre of the organisation can customers be brought
  • How do you score for trust?
  • Set a new goal state, roadmap for organisational change and supporting technology architecture
2. Why do you want to know more about your customers - what is driving you to build engagement?
  • Is it to build trust?
  • Get direct insight?
  • Get help in decision making?
  • Find savvy co-creators?
  • Deliver a better experience, better serving need?
3. Now you should devise a customer data strategy;

  • What data could be available to you – what can you learn from customer interactions? 
  • What value for third parties and customers could that generate 
  • Consider role of Decisioning (NBA)
By now you have a handle on what you want to achieve with customer data and how you are going to 'sell' that to customers in a way they will see as a fair exchange.

And that's a far better place to start from when working towards compliance with GDPR.y 2017

*This is always the case with my writing - but given the legal complexities of the GDPR I want to make it even more clear than usual - these views are mine and mine only and should not be assumed to represent those of my employer.

FasterFuture.blogspot.com

The rate of change is so rapid it's difficult for one person to keep up to speed. Let's pool our thoughts, share our reactions and, who knows, even reach some shared conclusions worth arriving at?