Welcome!

SOA & WOA Authors: Carmen Gonzalez, Lori MacVittie, Liz McMillan, Pat Romanski, Natalie Lerner

Related Topics: SOA & WOA, Java, Web 2.0, Cloud Expo, Security, Big Data Journal

SOA & WOA: Article

Managing Customer Data Privacy: Issues, Perspectives and Possibilities

Leveraging business models in the Identity Economy

Sharing personal information is central to the way people live, work and do business with each other today. And it's only going to become more so, as the Identity Economy emerges to establish a new paradigm for commercial interactions. This raises a number of interesting questions and concerns about the privacy of personal information.

Share and Share Alike
What does the sharing of personal information mean in the context of economic transactions? It specifically refers to consumers who are sharing information with companies and receiving something in return. It may be as simple as providing their information to enable a company to offer them a better service or more personalized experience. Or it may mean providing information to a company and giving the company permission to share with a trusted affiliate or partner in exchange for some benefit to the consumer. In many cases, the consumer is already sharing their personal information, either because the consumer provided it when registering for a particular service, or because the company has derived it from the consumer's use of the service.

Savvy consumers recognize that a lot of their personal information is accessible to companies they do business with. The idea posed by an identity-driven model for commerce is that this information could be utilized to make life easier and online interactions more delightful for consumers - if it could flow more freely on the consumer's behalf. Simplifying the authentication process (by overhauling how passwords are managed, for example) is part of this. But there's more to it than just making it easier to sign up and login to a service. It's about putting the consumer's digital exhaust to work in ways that go beyond its original intended use. For example:

  • What if preferences and purchases made on one site could be used to personalize the consumer's experience on another site?
  • What if real-time location information could be coupled with consumer intent or interest in a product to transform the consumer's shopping experience?

These and other similar questions frame the commercial possibilities that are driving what we call the Identity Economy. Let's take a look at their implications for managing customer data privacy.

What's Fear Got to Do with It?
Using personal information to fuel commercial activity is nothing new; entire companies are built on the premise of monetizing information, primarily by selling it for targeted advertising. However, companies built on this type of business model are often perceived as gathering and using personal information in a way that's somehow sneaky or underhanded.

For example:

  • Ads for remodeling companies start popping up on someone's email just after she sends a message with "home repair recommendations" in the subject line.
  • A member of a social network suddenly realizes the network is posting information about what music services he's listening to - though he doesn't remember agreeing to share this information with anyone.

That's just it: these users may have given permission to use their information, but they may have done so unknowingly, perhaps because the policy that was agreed to was obscure, overly generalized, or difficult to understand.

Under these circumstances, consumers are understandably fearful about their personal information being compromised by the companies with whom they share it. And the companies are often equally fearful of acting on opportunities to use information to improve the customer's experience and/or to create new sources of revenue - because they worry about being perceived as somehow unfairly exploiting information, or running afoul of laws governing data privacy. Concerns like these make data privacy one of the most important values that must be respected in the Identity Economy.

Overcoming Fear and Embracing Opportunity
Aside from this "stealth" model of obtaining and using personal information, the broader market does not seem to believe that a lack of transparency and control over the use of personal information is the right way to run a successful business.

To the contrary, many companies pursuing use cases involving the flow of information across applications and services take the privacy of their customers' personal data very seriously. In fact, their fear of unintentionally violating that privacy can make them reluctant to share it even when doing so would benefit the customer. For some, it's not worth the risk of alienating the customer -or worse, running afoul of privacy laws and regulations.

In many cases, this fear has nothing to do with sharing data with third parties (data brokers, advertisers, etc.) but instead involves sharing data across multiple lines of business within the same company. For instance, in many regulated industries, the information a consumer provides for service X cannot be shared with service Y at the same company. Quite literally, the right hand does not know what the left hand is doing - by design. Further, if they are sharing this information, they are very concerned about how to ensure that the information is flowing according to the terms of the agreement under which it was captured, their internal privacy policies, and the laws and regulations that affect their business.

Fear, in this instance, is not entirely a bad thing. After all, the information is sensitive and could be exploited to the detriment of the individual from whom it was collected. But to embrace opportunities, companies must overcome this fear by applying technology to ensure that personal information is collected with consent, under the right circumstances and for the right reasons, and utilized according to the terms under which it was collected - all while providing control to the individual over how their information is put to good use. Companies that follow these principles will not only be able to overcome their fear of using this data to delight their customers, but also differentiate themselves from the crowd.

The opportunities to utilize personal information to create highly engaging and personalized experiences are immense, but so are the opportunities for this information to be exploited for harm. Fear, uncertainty and doubt abound, but they also signal an opportunity for innovation. Most companies that are responsible for stewarding this information take that responsibility very seriously. So, too, do the regulatory bodies and industry organizations that govern and guide these companies as they explore this new territory.

Establishing and Enforcing Evolving Privacy Rights in the U.S.
The Consumer Privacy Bill of Rights recently drafted by the White House is part of a larger US government blueprint to improve overall consumer privacy protection while still encouraging innovation in business and commerce. As the White House describes it, "this blueprint will guide efforts to give users more control over how their personal information is used on the Internet and to help businesses maintain consumer trust and grow in the rapidly changing digital environment."1 This goes directly to addressing the fears described earlier in this article that must be overcome for the Identity Economy to thrive - both consumer fear of sharing personal information and corporate fear of using that information.

The themes outlined in the Consumer Privacy Bill of Rights mimic the established "Fair Information Practice Principles" and include the following:

  • Individual Control: Consumers have a right to exercise control over what personal data organizations collect from them and how they use it.
  • Transparency: Consumers have a right to easily understandable information about privacy and security practices.
  • Respect for Context: Consumers have a right to expect that organizations will collect, use and disclose personal data in ways that are consistent with the context in which consumers provide the data.
  • Security: Consumers have a right to secure and responsible handling of personal data.
  • Access and Accuracy: Consumers have a right to access and correct personal data in usable formats, in a manner that is appropriate to the sensitivity of the data and the risk of adverse consequences to consumers if the data are inaccurate.
  • Focused Collection: Consumers have a right to reasonable limits on the personal data that companies collect and retain.
  • Accountability: Consumers have a right to have personal data handled by companies with appropriate measures in place to ensure they adhere to the Consumer Privacy Bill of Rights.

Diving down into specific industries, there are more focused laws and regulations in place that govern and guide how companies deal with customer information. The telecommunications industry, for example, must comply with constantly evolving legislation that sets forth rules for how telcos can use what is called customer proprietary network information, or CPNI. Similarly, in the financial services industry, laws such as the Gramm- Leach-Bliley Act mandate how financial services firms can use consumers' personal information and how they communicate their use of this information. In health care, a significant portion of the Health Insurance Portability and Accountability Act (HIPAA) regulating the industry is concerned with protecting the privacy of patient information.

The View from the EU
Managing the privacy of customer data is as much a concern in other countries as it is in the United States - in fact, it's generally more of a concern. The European Union (EU), for example, has clearly established in its Charter of Fundamental Rights of the European Union that the protection of personal data is a fundamental right of European citizens. The provisions are in clear language:

Protection of personal data

  • Everyone has the right to the protection of personal data concerning him or her.
  • Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.
  • Compliance with these rules shall be subject to control by an independent authority.

This is an important concept to grasp when considering the European environment, and the Canadian environment is not much different than Europe. The U.S. simply does not have this same, comprehensive view of privacy. There are elements of these principles sprinkled throughout various sectors (health care, finance, etc.) in our society, but we do not view the protection of personal data as a fundamental right of our society. This is key.

Still, while the Europeans are much further along in defining and enforcing comprehensive privacy laws, most companies are still just beginning to put into operation the majority of the articles or rules defined in the existing and proposed regulations. For instance, most are well on their way to building a solid Data Protection Office and raising the internal awareness of data protection issues within their organization, but few, if any, have taken the steps necessary to place the individual in full control of their personal data. While a handful of companies are more mature in their compliance, most are not much further along than some progressive U.S. companies.

Ultimately, though, it's not a matter of if, but when. While there is much work to be done on implementing policies and measures that will bring companies into compliance with existing and proposed regulations, it's only a matter of time before mass adoption. In fact, the 2012 General Data Protection Regulation2, a proposed new legal framework for protection of personal data in the EU, could become law as early as mid- to late 2014. The proposed reform provides a broader scope of enforcement as its legal basis, places greater emphasis on individual control of data and enhances the responsibility assigned to data controllers and processors to demonstrate compliance.

The Privacy Cliff
The idea of a "fiscal cliff" dominated much of the economic and government news in the U.S. in 2012. Though it's certainly not as dramatic in nature, there is a sort of impending "privacy cliff" that all European and Canadian - and, soon enough, U.S. - companies will need to avoid falling over in the next few years. There are many months yet before the EU's 2012 General Data Protection Regulation is approved, adopted and in force as law, but the policies and measures that companies will need to define and operationalize in order to comply with the rules will require many months to implement. With the Safe Harbor agreement to provide "adequate protection," this also impacts companies doing business in the EU.

This is keenly true for large multinational service providers. As an example, consider the challenges surrounding the capture and management of end-user consent. Capturing informed (explicit) consent is one thing, but leveraging that consent decision at the point of access for every piece of personal data that a company might have on an individual raises the bar on the complexity (cost) of compliance. In the current environment where personal data can be spread among hundreds of systems, how does a company ensure and prove that a user's consent is being respected? This is much more involved than writing and posting a human-readable privacy notice on a website. It involves systematically changing the way that customer data is collected and consumed.

The wheels are already in motion, and companies in Europe and Canada are faced with the need to take action now. There will likely be similar regulation(s) passed in the U.S. that embody the principles defined in the EU reform. (Some of this already exists in laws governing specific industries, but a comprehensive federal law currently does not exist.)

Whether reform comes in the strengthening of existing regulations or the passing of more sweeping reforms, it presents companies with a tremendous opportunity. They can not only get ahead of the regulatory curve, but also differentiate themselves from the pack by investing in the protection of personal data. This also presents the opportunity to leverage business models in the Identity Economy that utilize personal information, instead of declining to pursue them out of fear. As developments in this constantly and rapidly changing arena continue, UnboundID will continue to develop solutions for companies that are participating in the Identity Economy.

References

  1. "We Can't Wait: Obama Administration Unveils Blueprint for a ‘Privacy Bill of Rights' to Protect Consumers Online," White House press release, February 23, 2012
  2. "Commission proposes a comprehensive reform of data protection rules to increase users' control of their data and to cut costs for businesses," Europa (EU official website) press release, January 25, 2012

More Stories By Andy Land

Andy Land provides strategic marketing direction for UnboundID. In his current role as Vice President of Marketing, he is responsible for product marketing, corporate branding, and lead generation activities. Previously, Andy served as Director of Product Management for UnboundID where he owned product strategy and direction. Prior to UnboundID, Andy served as Senior Director of Product Management at Alterpoint and Director of Product Management at Sun Microsystems. His background also includes broad-based experience in marketing, product management, and sales at Motive, Vignette, Verizon, and Abbott Laboratories. Andy began his career as a United States Naval Officer and is a veteran of the first Gulf War. He is active in the Austin community, serving on the board of directors for The BeHive, a non-profit after-school program for children.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
The Internet of Things (IoT) is going to require a new way of thinking and of developing software for speed, security and innovation. This requires IT leaders to balance business as usual while anticipating for the next market and technology trends. Cloud provides the right IT asset portfolio to help today’s IT leaders manage the old and prepare for the new. Today the cloud conversation is evolving from private and public to hybrid. This session will provide use cases and insights to reinforce the value of the network in helping organizations to maximize their company’s cloud experience.
SYS-CON Events announced today that Aria Systems, the recurring revenue expert, has been named "Bronze Sponsor" of SYS-CON's 15th International Cloud Expo®, which will take place on November 4-6, 2014, at the Santa Clara Convention Center in Santa Clara, CA. Aria Systems helps leading businesses connect their customers with the products and services they love. Industry leaders like Pitney Bowes, Experian, AAA NCNU, VMware, HootSuite and many others choose Aria to power their recurring revenue business and deliver exceptional experiences to their customers.

SUNNYVALE, Calif., Oct. 20, 2014 /PRNewswire/ -- Spansion Inc. (NYSE: CODE), a global leader in embedded systems, today added 96 new products to the Spansion® FM4 Family of flexible microcontrollers (MCUs). Based on the ARM® Cortex®-M4F core, the new MCUs boast a 200 MHz operating frequency and support a diverse set of on-chip peripherals for enhanced human machine interfaces (HMIs) and machine-to-machine (M2M) communications. The rich set of periphera...

The Internet of Things (IoT) is making everything it touches smarter – smart devices, smart cars and smart cities. And lucky us, we’re just beginning to reap the benefits as we work toward a networked society. However, this technology-driven innovation is impacting more than just individuals. The IoT has an environmental impact as well, which brings us to the theme of this month’s #IoTuesday Twitter chat. The ability to remove inefficiencies through connected objects is driving change throughout every sector, including waste management. BigBelly Solar, located just outside of Boston, is trans...
SYS-CON Events announced today that Matrix.org has been named “Silver Sponsor” of Internet of @ThingsExpo, which will take place on November 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA. Matrix is an ambitious new open standard for open, distributed, real-time communication over IP. It defines a new approach for interoperable Instant Messaging and VoIP based on pragmatic HTTP APIs and WebRTC, and provides open source reference implementations to showcase and bootstrap the new standard. Our focus is on simplicity, security, and supporting the fullest feature set.
Predicted by Gartner to add $1.9 trillion to the global economy by 2020, the Internet of Everything (IoE) is based on the idea that devices, systems and services will connect in simple, transparent ways, enabling seamless interactions among devices across brands and sectors. As this vision unfolds, it is clear that no single company can accomplish the level of interoperability required to support the horizontal aspects of the IoE. The AllSeen Alliance, announced in December 2013, was formed with the goal to advance IoE adoption and innovation in the connected home, healthcare, education, aut...
SYS-CON Events announced today that Red Hat, the world's leading provider of open source solutions, will exhibit at Internet of @ThingsExpo, which will take place on November 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA. Red Hat is the world's leading provider of open source software solutions, using a community-powered approach to reliable and high-performing cloud, Linux, middleware, storage and virtualization technologies. Red Hat also offers award-winning support, training, and consulting services. As the connective hub in a global network of enterprises, partners, a...
The only place to be June 9-11 is Cloud Expo & @ThingsExpo 2015 East at the Javits Center in New York City. Join us there as delegates from all over the world come to listen to and engage with speakers & sponsors from the leading Cloud Computing, IoT & Big Data companies. Cloud Expo & @ThingsExpo are the leading events covering the booming market of Cloud Computing, IoT & Big Data for the enterprise. Speakers from all over the world will be hand-picked for their ability to explore the economic strategies that utility/cloud computing provides. Whether public, private, or in a hybrid form, clo...
Software AG helps organizations transform into Digital Enterprises, so they can differentiate from competitors and better engage customers, partners and employees. Using the Software AG Suite, companies can close the gap between business and IT to create digital systems of differentiation that drive front-line agility. We offer four on-ramps to the Digital Enterprise: alignment through collaborative process analysis; transformation through portfolio management; agility through process automation and integration; and visibility through intelligent business operations and big data.
The Transparent Cloud-computing Consortium (abbreviation: T-Cloud Consortium) will conduct research activities into changes in the computing model as a result of collaboration between "device" and "cloud" and the creation of new value and markets through organic data processing High speed and high quality networks, and dramatic improvements in computer processing capabilities, have greatly changed the nature of applications and made the storing and processing of data on the network commonplace.
Be Among the First 100 to Attend & Receive a Smart Beacon. The Physical Web is an open web project within the Chrome team at Google. Scott Jenson leads a team that is working to leverage the scalability and openness of the web to talk to smart devices. The Physical Web uses bluetooth low energy beacons to broadcast an URL wirelessly using an open protocol. Nearby devices can find all URLs in the room, rank them and let the user pick one from a list. Each device is, in effect, a gateway to a web page. This unlocks entirely new use cases so devices can offer tiny bits of information or simple i...
Things are being built upon cloud foundations to transform organizations. This CEO Power Panel at 15th Cloud Expo, moderated by Roger Strukhoff, Cloud Expo and @ThingsExpo conference chair, will address the big issues involving these technologies and, more important, the results they will achieve. How important are public, private, and hybrid cloud to the enterprise? How does one define Big Data? And how is the IoT tying all this together?
The Internet of Things (IoT) is going to require a new way of thinking and of developing software for speed, security and innovation. This requires IT leaders to balance business as usual while anticipating for the next market and technology trends. Cloud provides the right IT asset portfolio to help today’s IT leaders manage the old and prepare for the new. Today the cloud conversation is evolving from private and public to hybrid. This session will provide use cases and insights to reinforce the value of the network in helping organizations to maximize their company’s cloud experience.
TechCrunch reported that "Berlin-based relayr, maker of the WunderBar, an Internet of Things (IoT) hardware dev kit which resembles a chunky chocolate bar, has closed a $2.3 million seed round, from unnamed U.S. and Switzerland-based investors. The startup had previously raised a €250,000 friend and family round, and had been on track to close a €500,000 seed earlier this year — but received a higher funding offer from a different set of investors, which is the $2.3M round it’s reporting."
The Industrial Internet revolution is now underway, enabled by connected machines and billions of devices that communicate and collaborate. The massive amounts of Big Data requiring real-time analysis is flooding legacy IT systems and giving way to cloud environments that can handle the unpredictable workloads. Yet many barriers remain until we can fully realize the opportunities and benefits from the convergence of machines and devices with Big Data and the cloud, including interoperability, data security and privacy.
All major researchers estimate there will be tens of billions devices - computers, smartphones, tablets, and sensors - connected to the Internet by 2020. This number will continue to grow at a rapid pace for the next several decades. Over the summer Gartner released its much anticipated annual Hype Cycle report and the big news is that Internet of Things has now replaced Big Data as the most hyped technology. Indeed, we're hearing more and more about this fascinating new technological paradigm. Every other IT news item seems to be about IoT and its implications on the future of digital busines...
Cultural, regulatory, environmental, political and economic (CREPE) conditions over the past decade are creating cross-industry solution spaces that require processes and technologies from both the Internet of Things (IoT), and Data Management and Analytics (DMA). These solution spaces are evolving into Sensor Analytics Ecosystems (SAE) that represent significant new opportunities for organizations of all types. Public Utilities throughout the world, providing electricity, natural gas and water, are pursuing SmartGrid initiatives that represent one of the more mature examples of SAE. We have s...
The Internet of Things needs an entirely new security model, or does it? Can we save some old and tested controls for the latest emerging and different technology environments? In his session at Internet of @ThingsExpo, Davi Ottenheimer, EMC Senior Director of Trust, will review hands-on lessons with IoT devices and reveal privacy options and a new risk balance you might not expect.
IoT is still a vague buzzword for many people. In his session at Internet of @ThingsExpo, Mike Kavis, Vice President & Principal Cloud Architect at Cloud Technology Partners, will discuss the business value of IoT that goes far beyond the general public's perception that IoT is all about wearables and home consumer services. The presentation will also discuss how IoT is perceived by investors and how venture capitalist access this space. Other topics to discuss are barriers to success, what is new, what is old, and what the future may hold.
Swiss innovators dizmo Inc. launches its ground-breaking software, which turns any digital surface into an immersive platform. The dizmo platform seamlessly connects digital and physical objects in the home and at the workplace. Dizmo breaks down traditional boundaries between device, operating systems, apps and software, transforming the way users work, play and live. It supports orchestration and collaboration in an unparalleled way enabling any data to instantaneously be accessed on any surface, anywhere and made interactive. Dizmo brings fantasies as seen in Sci-fi movies such as Iro...