Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Tuesday, 31 July 2018

Ethics Takes Centre Stage

Last night I attended an event where Ann Roberts of Badoo and Nick Lisher of Nextdoor were discussing the meaning of enterprise values and their application to governance for Digital Platform based enterprises.

In the wake of the various regulatory issues that Facebook has had with Data Privacy legislation in Europe and Uber has encountered with employment law and regulation of taxis in a number of countries and cities, including London, this was a highly relevant discussion. It was pparticulalry refresshing to hear Nick Lisher say "I find GDPR liberating." as he went on to expound the fact that Nextdoor's values and approach meant that they had not had to alter or adapt their product at all to ensure compliance, which confirms assertions that I made in an earlier post that GDPR forces you to do the things that you should do anyway. It gives a great argument to persuade finance that it is necessary to pay for them.

All in all it boils down the the issue of running a digital enterprise as an ethical concern, which is a pre-requisite that I identified in "The Way of DAU", my take on how to adopt a Business as Usual business model.

Digital Business models amplify the concepts behind customer care theory. Traditionally this has proposed that 70% of sales are repeat sales to existing customers and that it is roughly 10 times cheaper to do something to keep a disgruntled customer, by addressing complaints positively, than it is to gain a new customer. Also if you manage to delight a customer, he or she will tell 10 people and sell your company. If you annoy them, they will tell even more and damage your reputation. Badoo's business model actually relies on this, because if you successfully match someone up with another person, Badoo may lose them as customers, but they will tell everyone that it was how they met and sell Badoo positively. Conversely, there have been significant backlashes over how Facebook uses people's data, and recent slow downs in growth and consequent loss in market value, are not the first time that Facebook has suffere significant customer defections.

Google used to have a great reputation when everyone believed in its "Do no Evil" credo, but is gradually losing mindshare with significant portions of people as a result of failure to translate this into a positive corporate culture where ethical concerns are addressed and seen to be addressed by the people who work there, its customers and increasingly EU regulators.

However, whilst we were discussing this and what happens in many traditional PLCs, a penny dropped. It's not just the the Leaders of a digital enterprise who need to be focussed on instituionalising ethics as a core of company culture, but also the shareholders. The llatter need to align themselves with the long term view and how value is created. There's too much emphasis on quick results and returns and not enough on long term value and scalability. Ethics needs to be seen part of a digital business's scalability, not just the architecture of digital products and operational robustness.

Friday, 11 May 2018

What Happens To Your Business Model Under GDPR

GDPR comes into full force this month following a 2 year period for transition,in which organisations were meant to adjust operations, systems and data to comply.

Central to this is the need for explicit consent to collect and hold someone's data. The data must also be limited to that which is necessary and must not be used for any other purpose than that for which it was collected.

This has major implications for many organisations whose business is based upon consumer knowledge, such as credit rating agencies. Much of their data has historically been collected from multiple sources and aggregated. Gaps have often been interpolated and many associations have been assumed. According to a raconteur article, one industry analyst claims that people in the industry believe it to be only 50% accurate!

This probably explains, why some of the credit agencies have been keen to let people sign up and check their profiles so that they could "clean their credit history". In fact the people have been paying to correct their own data! So the credit agencies have been paid to obtain a free service, improving the quality of their data.

It is difficult to see how this model will continue in the future. As consumer trust in online use of their data is dropping rapidly and has been one of the factors why many millenials have "divorced facebook".

Another impact of GDPR is that the scope of what counts as personal data is now wider and includes things like cookies and url links. Without express permission these cannot be collected or used for things such as driving targeted advertising to your browser. This is going to affect the business model of companies like Google who rely extensively on advertising revenue.

How it all pans out will be interesting as there are other ways in which advertising can be targeted, but at least there may be more semblance of control over what happens.

Though perhaps the best benefit will be avoiding the flurry of junkmail for car insurance and house insurance when the anniversary of a purchase is imminent and traditionally insurance agreements are renewed.

Thursday, 5 April 2018

Will We Ever Get Smart Data?

Recently IDC released its analysis on trends with Smart City investment. Apparently global investment in Smart City Infrastructure and Services is growing at an annual rate in excess of 25% per year and 2018 expenditure is expected to top $80Bn.

IDC's analysis suggests that one of the leading areas of spend is on surveillance technology in China, with authorities emphasising their ability to use facial recognition to rapidly recognise and locate wanted criminals.

This news comes fast on the heels of china's recent cyber security legislation which as introduced last June. The text of China's Cyber Security Law has not been made available in English, but basically it prohibits the storage of sensitive personal data on Chinese citizens outside China. China also requires all websites operating within China to be licensed (with a Bei'An licence).

This effectively provides the authorities with strong control over what happens with data and web sites within China as access to external websites is filtered and controlled via "The Great Firewall of China", which also acts as a choke point on performance.

In Europe, GDPR is about to go live in about a month's time with its own increased controls over the management of personal data. It is probably safe to say that a lot of large corporate organisations will be struggling to be fully in control of compliance. Any company which is still recovering from legacy problems caused by cost cutting following the 2008 recession, or which has grown rapidly via Merger and Acquisition activity or has lost control of "Shadow IT" as a result of DIY acquisition of SaaS services, is likely to be struggling to get to grips with where all its personal data is, let alone to assess whether it complies with the requirements for (a) data subject consent, (b) only holding the amount of personal data that is necessary, (c) ensuring that the data is properly protected and (d) being able to deliver the right to be forgotten.

This is probably the time where we need to look for Machine Learning based approaches to help identify personal data, where it is, who accesses it and whether it meets the test of not  exceeding the minimum amount legally required to fulfil the tasks for which it is collected stored and managed. It would also help in identifying all the data associated with an individual, requesting the right to be forgotten. However, if we ever are going to trully have control, then its probably time that the concept of smart data (i.e. self managing according to policy rules) technology was introduced, so that data understands its own importance, sensitivity, context and environments and can self certify compliance (or not) when policy rules are subject to change.

Friday, 26 May 2017

GDPR, CIO issues, Lean Data & Data Portfolio Management

Last night's CIO event hosted by Harvey Nash and KPMG was held to launch their 2017 CIO Survey "Navigating Uncertainty".

In the Panel discussion afterwards, one of the key issues raised was about "knowing where your data is". GDPR is certainly driving this, for personal data in Europe and anyone who trades with organisations or consumers based there. As its difficult to implement the "right to be forgotten" if you don't know what data you hold and where it is. Similarly, SoX in the US has driven similar concerns about Financial data. The move to "Cloud First" also compounds this need, as it is core to successful integration.

So why is this such a big deal as much of GDPR is about doing things which a business really ought to be doing anyway? basically its ancient history. Most large organisations have grown partially by merging with and acquiring other organisations. Their management teams often have the tendency to declare victory before full integration occurs.

Then there are cost cutting issues. Most businesses have been through boom and bust cycles of  large investment followed by cost cutting and asset squeezing. Often this has included head count reductions or outsourcing. Each of which ensures that knowledge about where things are leaves the organisation. Many service providers tend not to document things well, if they are allowed to get away with it, as this helps keep effort and FTE (therefore costs) down. There is natural staff churn of anywhere between 5% and 20% per year in typical companies, depending upon culture, rates of pay and opportunities. Documentation does not keep pace with lost knowledge as exit processes are usually poor in knowledge transfer.

Finally, DIY activities in the business often results in unofficial applications being adopted, especially as XaaS makes this easy to do. So put this all together and it is little wonder that organisations often do not know where their data is or even what data they have. This is a situation which brings inherent risk. If an organisation does not know where its data is, how does it protect it. If no one knows what data is help and "managed", then how is it integrated, kept coherent, kept clean and timely? how does the organisation know what it is actually spending on data or even what the value of its data is. Then there is the small matter of compliance. How does the organisation know whether it is complying. These are all data hygiene issues which need to be addressed if digitisation is going to support a Digital Business Model.

So now is the time to introduce Lean Data and make sure that Data Portfolio Management (DPM) is practiced as part of any approach to Asset Portfolio Management. (Asset Portfolio Management = Application Portfolio Management + Infrastructure Portfolio Management + Data Portfolio Management).

Lean Data principles mean that:
  • Organisations know what data they hold and manage;
  • Data is classified according to subject area and criticality;
  • Only the minimum data necessary to Add Value to the business is held;
  • Data replication is kept to the minimum level necessary to optimise business performance;
  • Data Value is determined by its utility in Serving the Customer, Supporting Essential Capability, Protecting the Organisation, Providing Insight for Business Decision Making.
Data Portfolio Management is concerned with:
  • Knowing what data is held and where it is;
  • Understanding the quality of the data;
  • Knowing what technology is used to manage the data and its overall condition;
  • Being able to address questions concerning issues such as criticality, protection, archiving, cost of management;
  • Understanding how Master Data Management (MDM) and integration occurs;
  • Knowing who has Stewardship responsibility and consumer rights for the data;
  • Regularly reviewing management actions to improve Data Value and address Lean Data principles.




Tuesday, 27 September 2016

GDPR Bricks and Mortar Defence or Digital Viking's Inspiration

GDPR - the General Data Protection Regulation - is the next wave of personal data privacy regulation from the EU and is expected to go live mid 2018, i.e. pre-Brexit. This generally tightens up privacy requirements in a number of areas and has been a theme of discussion at a number of Cyber Security events this year, including today's InfoSecurity Magazine event.

Anyone interested in "Things Digital" should ask themselves, will this act as a regulatory defensive wall for old fashioned Bricks and Mortar / Industrial Age companies to shelter behind, or is it a new discipline or challenge for digital Vikings to embrace?

A couple of today's speakers made some interesting observations and comments: 
  • GDPR means that you need to know the What, Where and Why of Personal Data, especially customer data;
  • Regulation should not drive data security, Security Should Drive Regulatory Compliance;
  • There is a strong case for Digital Companies to adopt Social Digital Responsibility as Part of their Brand.
In a way, it should be easier for purely Digital companies to do this, as they are mostly starting from scratch with few of the problems of IT Estate Sprawl that many established companies have, with legacy systems, infrastructure and the typical complications inherited from previous defunct strategies as well as mergers and acquisitions. 

Also, in a previous blog, I mentioned that many digital companies actually regard this data as part of their IPR. So addressing GDPR (& other jurisdictional requirements) should be core to their business activity. Although future approaches toward collection and explicit consent may have to be sharpened up to meet the new requirements.

The implication is that Digital company that plans and builds Privacy Protection in from Day 1, will actually be building its own competitive advantage over traditional companies who mainly will be playing catch up.