|By Andy Land||
|April 7, 2013 03:00 PM EDT||
Sharing personal information is central to the way people live, work and do business with each other today. And it's only going to become more so, as the Identity Economy emerges to establish a new paradigm for commercial interactions. This raises a number of interesting questions and concerns about the privacy of personal information.
Share and Share Alike
What does the sharing of personal information mean in the context of economic transactions? It specifically refers to consumers who are sharing information with companies and receiving something in return. It may be as simple as providing their information to enable a company to offer them a better service or more personalized experience. Or it may mean providing information to a company and giving the company permission to share with a trusted affiliate or partner in exchange for some benefit to the consumer. In many cases, the consumer is already sharing their personal information, either because the consumer provided it when registering for a particular service, or because the company has derived it from the consumer's use of the service.
Savvy consumers recognize that a lot of their personal information is accessible to companies they do business with. The idea posed by an identity-driven model for commerce is that this information could be utilized to make life easier and online interactions more delightful for consumers - if it could flow more freely on the consumer's behalf. Simplifying the authentication process (by overhauling how passwords are managed, for example) is part of this. But there's more to it than just making it easier to sign up and login to a service. It's about putting the consumer's digital exhaust to work in ways that go beyond its original intended use. For example:
- What if preferences and purchases made on one site could be used to personalize the consumer's experience on another site?
- What if real-time location information could be coupled with consumer intent or interest in a product to transform the consumer's shopping experience?
These and other similar questions frame the commercial possibilities that are driving what we call the Identity Economy. Let's take a look at their implications for managing customer data privacy.
What's Fear Got to Do with It?
Using personal information to fuel commercial activity is nothing new; entire companies are built on the premise of monetizing information, primarily by selling it for targeted advertising. However, companies built on this type of business model are often perceived as gathering and using personal information in a way that's somehow sneaky or underhanded.
- Ads for remodeling companies start popping up on someone's email just after she sends a message with "home repair recommendations" in the subject line.
- A member of a social network suddenly realizes the network is posting information about what music services he's listening to - though he doesn't remember agreeing to share this information with anyone.
That's just it: these users may have given permission to use their information, but they may have done so unknowingly, perhaps because the policy that was agreed to was obscure, overly generalized, or difficult to understand.
Under these circumstances, consumers are understandably fearful about their personal information being compromised by the companies with whom they share it. And the companies are often equally fearful of acting on opportunities to use information to improve the customer's experience and/or to create new sources of revenue - because they worry about being perceived as somehow unfairly exploiting information, or running afoul of laws governing data privacy. Concerns like these make data privacy one of the most important values that must be respected in the Identity Economy.
Overcoming Fear and Embracing Opportunity
Aside from this "stealth" model of obtaining and using personal information, the broader market does not seem to believe that a lack of transparency and control over the use of personal information is the right way to run a successful business.
To the contrary, many companies pursuing use cases involving the flow of information across applications and services take the privacy of their customers' personal data very seriously. In fact, their fear of unintentionally violating that privacy can make them reluctant to share it even when doing so would benefit the customer. For some, it's not worth the risk of alienating the customer -or worse, running afoul of privacy laws and regulations.
In many cases, this fear has nothing to do with sharing data with third parties (data brokers, advertisers, etc.) but instead involves sharing data across multiple lines of business within the same company. For instance, in many regulated industries, the information a consumer provides for service X cannot be shared with service Y at the same company. Quite literally, the right hand does not know what the left hand is doing - by design. Further, if they are sharing this information, they are very concerned about how to ensure that the information is flowing according to the terms of the agreement under which it was captured, their internal privacy policies, and the laws and regulations that affect their business.
Fear, in this instance, is not entirely a bad thing. After all, the information is sensitive and could be exploited to the detriment of the individual from whom it was collected. But to embrace opportunities, companies must overcome this fear by applying technology to ensure that personal information is collected with consent, under the right circumstances and for the right reasons, and utilized according to the terms under which it was collected - all while providing control to the individual over how their information is put to good use. Companies that follow these principles will not only be able to overcome their fear of using this data to delight their customers, but also differentiate themselves from the crowd.
The opportunities to utilize personal information to create highly engaging and personalized experiences are immense, but so are the opportunities for this information to be exploited for harm. Fear, uncertainty and doubt abound, but they also signal an opportunity for innovation. Most companies that are responsible for stewarding this information take that responsibility very seriously. So, too, do the regulatory bodies and industry organizations that govern and guide these companies as they explore this new territory.
Establishing and Enforcing Evolving Privacy Rights in the U.S.
The Consumer Privacy Bill of Rights recently drafted by the White House is part of a larger US government blueprint to improve overall consumer privacy protection while still encouraging innovation in business and commerce. As the White House describes it, "this blueprint will guide efforts to give users more control over how their personal information is used on the Internet and to help businesses maintain consumer trust and grow in the rapidly changing digital environment."1 This goes directly to addressing the fears described earlier in this article that must be overcome for the Identity Economy to thrive - both consumer fear of sharing personal information and corporate fear of using that information.
The themes outlined in the Consumer Privacy Bill of Rights mimic the established "Fair Information Practice Principles" and include the following:
- Individual Control: Consumers have a right to exercise control over what personal data organizations collect from them and how they use it.
- Transparency: Consumers have a right to easily understandable information about privacy and security practices.
- Respect for Context: Consumers have a right to expect that organizations will collect, use and disclose personal data in ways that are consistent with the context in which consumers provide the data.
- Security: Consumers have a right to secure and responsible handling of personal data.
- Access and Accuracy: Consumers have a right to access and correct personal data in usable formats, in a manner that is appropriate to the sensitivity of the data and the risk of adverse consequences to consumers if the data are inaccurate.
- Focused Collection: Consumers have a right to reasonable limits on the personal data that companies collect and retain.
- Accountability: Consumers have a right to have personal data handled by companies with appropriate measures in place to ensure they adhere to the Consumer Privacy Bill of Rights.
Diving down into specific industries, there are more focused laws and regulations in place that govern and guide how companies deal with customer information. The telecommunications industry, for example, must comply with constantly evolving legislation that sets forth rules for how telcos can use what is called customer proprietary network information, or CPNI. Similarly, in the financial services industry, laws such as the Gramm- Leach-Bliley Act mandate how financial services firms can use consumers' personal information and how they communicate their use of this information. In health care, a significant portion of the Health Insurance Portability and Accountability Act (HIPAA) regulating the industry is concerned with protecting the privacy of patient information.
The View from the EU
Managing the privacy of customer data is as much a concern in other countries as it is in the United States - in fact, it's generally more of a concern. The European Union (EU), for example, has clearly established in its Charter of Fundamental Rights of the European Union that the protection of personal data is a fundamental right of European citizens. The provisions are in clear language:
Protection of personal data
- Everyone has the right to the protection of personal data concerning him or her.
- Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.
- Compliance with these rules shall be subject to control by an independent authority.
This is an important concept to grasp when considering the European environment, and the Canadian environment is not much different than Europe. The U.S. simply does not have this same, comprehensive view of privacy. There are elements of these principles sprinkled throughout various sectors (health care, finance, etc.) in our society, but we do not view the protection of personal data as a fundamental right of our society. This is key.
Still, while the Europeans are much further along in defining and enforcing comprehensive privacy laws, most companies are still just beginning to put into operation the majority of the articles or rules defined in the existing and proposed regulations. For instance, most are well on their way to building a solid Data Protection Office and raising the internal awareness of data protection issues within their organization, but few, if any, have taken the steps necessary to place the individual in full control of their personal data. While a handful of companies are more mature in their compliance, most are not much further along than some progressive U.S. companies.
Ultimately, though, it's not a matter of if, but when. While there is much work to be done on implementing policies and measures that will bring companies into compliance with existing and proposed regulations, it's only a matter of time before mass adoption. In fact, the 2012 General Data Protection Regulation2, a proposed new legal framework for protection of personal data in the EU, could become law as early as mid- to late 2014. The proposed reform provides a broader scope of enforcement as its legal basis, places greater emphasis on individual control of data and enhances the responsibility assigned to data controllers and processors to demonstrate compliance.
The Privacy Cliff
The idea of a "fiscal cliff" dominated much of the economic and government news in the U.S. in 2012. Though it's certainly not as dramatic in nature, there is a sort of impending "privacy cliff" that all European and Canadian - and, soon enough, U.S. - companies will need to avoid falling over in the next few years. There are many months yet before the EU's 2012 General Data Protection Regulation is approved, adopted and in force as law, but the policies and measures that companies will need to define and operationalize in order to comply with the rules will require many months to implement. With the Safe Harbor agreement to provide "adequate protection," this also impacts companies doing business in the EU.
This is keenly true for large multinational service providers. As an example, consider the challenges surrounding the capture and management of end-user consent. Capturing informed (explicit) consent is one thing, but leveraging that consent decision at the point of access for every piece of personal data that a company might have on an individual raises the bar on the complexity (cost) of compliance. In the current environment where personal data can be spread among hundreds of systems, how does a company ensure and prove that a user's consent is being respected? This is much more involved than writing and posting a human-readable privacy notice on a website. It involves systematically changing the way that customer data is collected and consumed.
The wheels are already in motion, and companies in Europe and Canada are faced with the need to take action now. There will likely be similar regulation(s) passed in the U.S. that embody the principles defined in the EU reform. (Some of this already exists in laws governing specific industries, but a comprehensive federal law currently does not exist.)
Whether reform comes in the strengthening of existing regulations or the passing of more sweeping reforms, it presents companies with a tremendous opportunity. They can not only get ahead of the regulatory curve, but also differentiate themselves from the pack by investing in the protection of personal data. This also presents the opportunity to leverage business models in the Identity Economy that utilize personal information, instead of declining to pursue them out of fear. As developments in this constantly and rapidly changing arena continue, UnboundID will continue to develop solutions for companies that are participating in the Identity Economy.
- "We Can't Wait: Obama Administration Unveils Blueprint for a ‘Privacy Bill of Rights' to Protect Consumers Online," White House press release, February 23, 2012
- "Commission proposes a comprehensive reform of data protection rules to increase users' control of their data and to cut costs for businesses," Europa (EU official website) press release, January 25, 2012
Early in my DevOps Journey, I was introduced to a book of great significance circulating within the Web Operations industry titled The Phoenix Project. (You can read our review of Gene’s book, if interested.) Written as a novel and loosely based on many of the same principles explored in The Goal, this book has been read and referenced by many who have adopted DevOps into their continuous improvement and software delivery processes around the world. As I began planning my travel schedule last...
Sep. 5, 2015 05:30 AM EDT Reads: 592
At the outset, Hyper convergence looks to be an attractive option seemingly providing lot of flexibility. In reality, it comes with so many limitation and curtail the flexibility to grow the hardware resources such as server, storage, etc independent of each other. In addition, performance nightmare bound to hit once the system gets loaded. In late 1990s, storage and networking came out of compute for a reason. Both networking and storage need some specialized processing and it doesn't make se...
Sep. 5, 2015 05:15 AM EDT
ElasticBox, the agile application delivery manager, announced freely available public boxes for the DevOps community. ElasticBox works with enterprises to help them deploy any application to any cloud. Public boxes are curated reference boxes that represent some of the most popular applications and tools for orchestrating deployments at scale. Boxes are an adaptive way to represent reusable infrastructure as components of code. Boxes contain scripts, variables, and metadata to automate proces...
Sep. 5, 2015 04:30 AM EDT Reads: 151
This is the first DevOps book that shows a realistic and achievable view of the full implementation of DevOps. Most of the books and other literature I have read on DevOps are all about the culture, the attitudes, how it relates to Agile and Lean practices, and a high level view of microservices. This book includes all that, but they are not its main focus, and it goes several steps further with respect to the architecture and infrastructure needed for the implementation.
Sep. 5, 2015 04:00 AM EDT Reads: 104
To support developers and operations professionals in their push to implement DevOps principles for their infrastructure environments, ProfitBricks, a provider of cloud infrastructure, is adding support for DevOps tools Ansible and Chef. Ansible is a platform for configuring and managing data center infrastructure that combines multi-node software deployment, ad hoc task execution, and configuration management, and is used by DevOps professionals as they use its playbooks functionality to autom...
Sep. 5, 2015 03:00 AM EDT Reads: 156
Skeuomorphism usually means retaining existing design cues in something new that doesn’t actually need them. However, the concept of skeuomorphism can be thought of as relating more broadly to applying existing patterns to new technologies that, in fact, cry out for new approaches. In his session at DevOps Summit, Gordon Haff, Senior Cloud Strategy Marketing and Evangelism Manager at Red Hat, discussed why containers should be paired with new architectural practices such as microservices rathe...
Sep. 5, 2015 02:00 AM EDT Reads: 464
SYS-CON Events announced today that HPM Networks will exhibit at the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. For 20 years, HPM Networks has been integrating technology solutions that solve complex business challenges. HPM Networks has designed solutions for both SMB and enterprise customers throughout the San Francisco Bay Area.
Sep. 5, 2015 01:30 AM EDT Reads: 1,005
Puppet Labs has announced the next major update to its flagship product: Puppet Enterprise 2015.2. This release includes new features providing DevOps teams with clarity, simplicity and additional management capabilities, including an all-new user interface, an interactive graph for visualizing infrastructure code, a new unified agent and broader infrastructure support.
Sep. 5, 2015 01:15 AM EDT Reads: 618
SYS-CON Events announced today that Pythian, a global IT services company specializing in helping companies leverage disruptive technologies to optimize revenue-generating systems, has been named “Bronze Sponsor” of SYS-CON's 17th Cloud Expo, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Founded in 1997, Pythian is a global IT services company that helps companies compete by adopting disruptive technologies such as cloud, Big Data, advance...
Sep. 5, 2015 01:00 AM EDT Reads: 417
All major researchers estimate there will be tens of billions devices - computers, smartphones, tablets, and sensors - connected to the Internet by 2020. This number will continue to grow at a rapid pace for the next several decades. With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo, November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Learn what is going on, contribute to the discussions, and e...
Sep. 5, 2015 01:00 AM EDT Reads: 265
The pricing of tools or licenses for log aggregation can have a significant effect on organizational culture and the collaboration between Dev and Ops teams. Modern tools for log aggregation (of which Logentries is one example) can be hugely enabling for DevOps approaches to building and operating business-critical software systems. However, the pricing of an aggregated logging solution can affect the adoption of modern logging techniques, as well as organizational capabilities and cross-team ...
Sep. 4, 2015 11:45 PM EDT Reads: 461
DevOps has traditionally played important roles in development and IT operations, but the practice is quickly becoming core to other business functions such as customer success, business intelligence, and marketing analytics. Modern marketers today are driven by data and rely on many different analytics tools. They need DevOps engineers in general and server log data specifically to do their jobs well. Here’s why: Server log files contain the only data that is completely full and accurate in th...
Sep. 4, 2015 11:45 PM EDT Reads: 486
SYS-CON Events announced today that G2G3 will exhibit at SYS-CON's @DevOpsSummit Silicon Valley, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Based on a collective appreciation for user experience, design, and technology, G2G3 is uniquely qualified and motivated to redefine how organizations and people engage in an increasingly digital world.
Sep. 4, 2015 11:00 PM EDT Reads: 585
DevOps Summit, taking place Nov 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 17th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development...
Sep. 4, 2015 07:00 PM EDT Reads: 1,670
Whether you like it or not, DevOps is on track for a remarkable alliance with security. The SEC didn’t approve the merger. And your boss hasn’t heard anything about it. Yet, this unruly triumvirate will soon dominate and deliver DevSecOps faster, cheaper, better, and on an unprecedented scale. In his session at DevOps Summit, Frank Bunger, VP of Customer Success at ScriptRock, will discuss how this cathartic moment will propel the DevOps movement from such stuff as dreams are made on to a prac...
Sep. 4, 2015 06:00 PM EDT Reads: 286
SYS-CON Events announced today that DataClear Inc. will exhibit at the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. The DataClear ‘BlackBox’ is the only solution that moves your PC, browsing and data out of the United States and away from prying (and spying) eyes. Its solution automatically builds you a clean, on-demand, virus free, new virtual cloud based PC outside of the United States, and wipes it clean...
Sep. 4, 2015 05:30 PM EDT Reads: 510
The word quantum often portends New Age mumbo-jumbo, in spite of the fact that quantum mechanics underlies many of today’s most important technologies, including lasers and the semiconductors found in every computer chip. Nevertheless, today quantum computing is becoming a reality. And while it may look to the layperson like mere mumbo-jumbo, in reality of the technology has largely moved out of the theoretical stage, as recent news indicates. In fact, two important announcements over the la...
Sep. 4, 2015 04:45 PM EDT
Any Ops team trying to support a company in today’s cloud-connected world knows that a new way of thinking is required – one just as dramatic than the shift from Ops to DevOps. The diversity of modern operations requires teams to focus their impact on breadth vs. depth. In his session at DevOps Summit, Adam Serediuk, Director of Operations at xMatters, Inc., will discuss the strategic requirements of evolving from Ops to DevOps, and why modern Operations has begun leveraging the “NoOps” approa...
Sep. 4, 2015 03:30 PM EDT Reads: 475
In today's digital world, change is the one constant. Disruptive innovations like cloud, mobility, social media, and the Internet of Things have reshaped the market and set new standards in customer expectations. To remain competitive, businesses must tap the potential of emerging technologies and markets through the rapid release of new products and services. However, the rigid and siloed structures of traditional IT platforms and processes are slowing them down – resulting in lengthy delivery ...
Sep. 4, 2015 01:45 PM EDT Reads: 667
In his session at 17th Cloud Expo, Ernest Mueller, Product Manager at Idera, will explain the best practices and lessons learned for tracking and optimizing costs while delivering a cloud-hosted service. He will describe a DevOps approach where the applications and systems work together to track usage, model costs in a granular fashion, and make smart decisions at runtime to minimize costs. The trickier parts covered include triggering off the right metrics; balancing resilience and redundancy ...
Sep. 4, 2015 11:45 AM EDT Reads: 347