Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, February 16, 2017

Why we should embrace GDPR

The General Data Protection Regulation due to come into force next May should be regarded as the biggest hint yet for companies to reshape themselves for the digital world - aligning with The 10 Principles of Open Business.

Rather than fear at the number of sticking-plasters that need to be applied to support business as usual, forward-thinking companies will be taking the hint; data ownership is no substitute for genuine relationships.

That's the real message of GDPR - stop hoarding data to exploit customers.
In fact it's very difficult to see in a post GDPR-world why any customer would choose to allow a company to retain their data unless (and they have to be transparent about this) their is a genuine and positive partnership defined in their data notices.

Of course companies can (and many should) spend time, trouble and money ensuring compliance by (for example);

  • Appointing a Data Protection Officer
  • Reviewing each and every business process to ensure data protection is designed in
  • Ensuring default privacy settings are set to high at each and every touch point
  • Making it crystal clear exactly what data is being stored about whom, for how long and for what purpose - at every relevant interface
  • Providing complete data portability - enabling users to withdraw access to all of their data and take it with them, at any point they choose,
  • Devising Data Protection Impact Assessments
  • Developing new processes to respond to requests for data and complaints about use
  • Preparing to defend your use of logarithms for the decisions they deliver and offers they make or do not make
With up to 4% of last year's global revenue at stake as a sanction, there's much sense in taking this very seriously indeed. However, much of the data storage, privacy and permissions issues become much less onerous if you shift  the nature of your relationship with customers - and in doing so your relationship with their data.

Start to think of data as less a substitute for a relationship - and more an enabler for building one through genuine engagement. 



The start point requires three simple steps:
1. Understand the role of the customer in your business: (Hint - the passive consumer no longer exists, if they ever did).
  • Where are the benefits in partnering; how far into the centre of the organisation can customers be brought
  • How do you score for trust?
  • Set a new goal state, roadmap for organisational change and supporting technology architecture
2. Why do you want to know more about your customers - what is driving you to build engagement?
  • Is it to build trust?
  • Get direct insight?
  • Get help in decision making?
  • Find savvy co-creators?
  • Deliver a better experience, better serving need?
3. Now you should devise a customer data strategy;

  • What data could be available to you – what can you learn from customer interactions? 
  • What value for third parties and customers could that generate 
  • Consider role of Decisioning (NBA)
By now you have a handle on what you want to achieve with customer data and how you are going to 'sell' that to customers in a way they will see as a fair exchange.

And that's a far better place to start from when working towards compliance with GDPR.y 2017

*This is always the case with my writing - but given the legal complexities of the GDPR I want to make it even more clear than usual - these views are mine and mine only and should not be assumed to represent those of my employer.

Thursday, May 13, 2010

Facebook is not a media owner - it's an enabling platform

Image representing Facebook as depicted in Cru...Image via CrunchBase
The whole Facebook privacy thing reveals a large strategic problem Facebook has created for itself.

It has become popular precisely because people feel they can trust in the control over the level of sharing they have - and the limitations on what each individual regards as 'going public'. For most Facebook users going public means sharing with friends. And for most Facebook users friends mean friends (which is why the vast majority don't have hundreds).

It's structurally a collection of hard-edged networks - silos - self-limiting communities rather than the adhoc, fuzzy-edged self-forming communities of the kind that Twitter (and the blogosphere for that matter) enjoys. It was built for privacy - so the hard-edges are a natural outcome.

I have written about the risk Facebook has built into its model, previously: Hoarding Data Can Seriously Damage Your Wealth and How Twitter is Going to Beat Facebook

I think the guys at Facebook understand this problem more and more as they scale. And I think that's why they keep introducing the Twitter-like conversation elements. But it's also why they keep pushing what they can get away with on privacy.

While I do believe in the longer term our notions of private/public will shift over time, that's not what the vast majority of their 500m (that's a guess) users have signed up for. So when what they, very seriously, regard as their private data starts getting used for FB's own purposes - serving unwelcome ads, for example - things kick off.

The guts of the problem, it seems to me, is that Facebook is developing business models as if it's a media owner. ie we've got all this great content - let's sell ads on it. Let's flog wasteful, ineffective ads on it (remember kids, click-thru rates are somewhere down round your ankles, even in uber-targeted Facebook-land).

But Facebook isn't a media owner. All the media on it is yours. You made and shared it. It's yours not theirs.

Facebook is an enabling platform. Indeed it has the potential to be a collection of any number of enabling platforms. And if it could only start believing that (Zuckerberg and co must know it) then it could start to earn a crust in an appropriate way.

When it recognises that it'll spot its business model. And it sure as hell ain't ads.

It's much closer to this kind of thing...
Facebook needs a business model in which it is working with brands and orgs to bring together people who care about the same issues to work together to fix them - and to enable them - creating real RoI (making stuff and making stuff better - think Salesforce-style Dell IdeaStorms) rather than messaging the hell out of the harvested eyeballs (that'll be ads).

And only Facebook has the data through which it could find people who care about the same stuff across all the friend-to-friend silos, and reach out to them to bring them together to surface the wikifixes for products and surfaces the brands need. No one else could do this.

That's quite some competitive advantage.

Reblog this post [with Zemanta]

Wednesday, November 21, 2007

Whoops - there goes your identity. Mass hysteria in the UK

I spoke at the high-brow but fun Digital Identity Forum at London's Clink yesterday - on the subject of Reed's Law and the Demand Curve. It was an interesting place to be when news broke of The UK Government's rather careless loss of the personal records of somewhere around half of the entire population.

For those not familiar with the story a Government department was asked for sensitive data records by another - and it chose to send them in the post on a couple of discs - unsecured. Not even recorded delivery. And they didn't arrive.

Whoops.

A story Dr Ian Brown told at Digital Identity (you might have seen him talking on the subject on Newsnight last night) reveals how/why this kind of thing will inevitably happen.
Apparently it was the case in the National Health Service that access to computer terminals involved a swipe card. This card revealed your personal level of clearance. The higher your rank, the greater your access - essentially. Great in theory. Trouble was, each day the most senior person in the department would swipe to log in and then leave the terminal open for all to use - probably because this was expediant.

And in the same way, you could make the data the Government has lost as secure as you like when you control the process, but the moment you introduce human beings, things can go wildly wrong. In this case a human took the expedient course of sticking them in the post. Not wise; But not beyond the realms of reason either.

Even so, I'm not sure there is quite the cause for all this hysteria. The kind of information about me currently available on those missing discs include bank account names and numbers, home address, my child's name etc. Sounds scary. But it's only scary if someone can do something scary with it.

Aren't our security conventions just a little screwed up when they rely on us NOT sharing the name of our child, or our home address. Isn't that just a bit inhuman? Anti-social?

It's time we changed the locking mechanisms, rather than making it the responsibility of users to be less social - to be less like, well, human beings.

It's in our nature. Technologists - design for it!

In any event - isn't my address and other details available publicly on the electoral roll? Sharing the name and number of our bank account gives no one access to remove anything from it. So what's the big deal?

The issue is for other people's security systems. For example - someone could apply for a credit card or some such with 'my' details. Great. They could apply for it. Not me. They are responsible for any bill racked up on it. Not me. So the problem is for the system which makes knowledge of a few social details about me its dirty big key. They are making a few social details equivalent to my identity. Mistake.

Those guys have the problem - get on with making better locks. Leave me to enjoy being human.

FasterFuture.blogspot.com

The rate of change is so rapid it's difficult for one person to keep up to speed. Let's pool our thoughts, share our reactions and, who knows, even reach some shared conclusions worth arriving at?