Showing posts with label Daily Mail. Show all posts
Showing posts with label Daily Mail. Show all posts

Thursday, 9 April 2015

Doing Porridge for your Data?



During an election campaign it is probably natural to ask ourselves what a government is for? And the answer is to govern...to conduct the policy, actions and affairs of a state, organisation or people with authority...to quote a dictionary definition. Obviously quite a complicated business but when it comes down to it I believe it amounts to setting boundaries.

That is what laws are. You can do this but you cannot do that, and if you do we will punish you. In an ideal world, any government’s legislation should leave its people in no doubt as to how they are expected to behave, everything should be black and white, and we should therefore understand the consequences of our actions.

Data security is regulated but the legal boundaries are anything but clear. Not to the vast majority of people. If you sat your average business manager in a room and asked him what he was supposed to do with the data within his control, he would not have a clue.

To a certain extent that is our own fault. Not many people have ‘check the data protection act and how it applies to my role’ on their to-do list. But they should of course. It would make things so much easier in the long run, especially if the information available was written so that anyone not related to Steven Hawking had a chance of understanding it.

Here’s a thing. An example of what I mean. When you dispose of an old Business PC, you are being governed (that word again) by two sets of legislation...WEEE and Data Protection. One classifies your old PC as waste and therefore it must be moved under a waste transfer note, by a licensed carrier and all that jazz. Not very exciting and we could have a debate about when it becomes waste, but essentially it is, so there, live with it and get a waste transfer note. It is better than a fine.

But the data stuff is trickier. According to the law you are not throwing out an old PC, you are giving away your data. From the moment it leaves your possession, your risk is running around outside of your control and protection and legally you need to show a duty of care towards its security. If you have not and it all goes a bit Pete Tong you are in the firing line of a £500k fine. Very soon you would be opening up the doors of the Scrubs and heading for a six month stretch standing nervously with your back to the wall!

Make no mistake about it; the penalties are serious and getting worse. The misuse of data is taken very seriously in Brussels and Westminster. Mess up through negligence or criminal intent and you can expect to feel the full force of the law and the Daily Mail, not necessarily in that order.

The law is often an ass but in this case it is not. It may not be educating us in how to stay on the right side of it enough for my liking but this idea that you are transporting data is good sense. People disposing of an old piece of kit do not see the data, they see the hardware. They are well used to passwords and network security and they don’t really think about what is on the hard drive. So the law is trying to say ‘hey stupid, remember what’s on there.’

The law is trying to protect everyone. Any data a business holds will involve someone else. It may just be name, address and phone number but in many if not most cases it will include sensitive stuff like bank details, medical records, financial information or even criminal records. So the law reminds you to take care.

Hence the existence of some 800 recycling businesses in this country who will deal with IT or data-bearing equipment. Or at least say they will deal with it. And this is where I get worried about the laws. The fact is they make suggestions without defining what they mean. They say use a specialist partner to make sure but they do not help with that choice. There are no British standards, no Kitemark for data erasure or destruction.

That in itself is not unusual. There are many sectors that have no government standards and quite often the sector gets together to try and set its own. The Press Complaints Commission would be a recognisable example of an industry regulating itself. In our case ADISA or the Asset Disposition and Information Security Alliance, which is an independent body certifying members and setting standards, in conjunction with the government, who do work around the edges.

However of those 800 business less than 40 are certified by ADISA. And only 3 are approved by DIPCOG to work in the MoD/Government space. Now this does not make the other 760 or the other 797 bad of course. It just suggests that in the absence of a national standard they do not see the value of playing the game.

That is a shame. The waters are muddy enough and we could do with some clarity. Because without it, who your data walks out of the door with is rather left to chance. And it is you who will pay the fine, not them. In a few months, when the new European laws get ratified, it could be you, or one of your directors, who gets to do the porridge.

Wednesday, 1 April 2015

Our (bad) attitude to data is all wrong



Data is something we all take for granted but when you think about it, what is data really? In terms of our old friend the data protection act it would be best described as information. The sort of stuff that if someone else gets hold of it they can do something with.

Information, as we are all taught, is power.

In the last week or so we have run the full gamut of emotions with data. We have had the dear old Daily Mail screaming from the rooftops about personal data being available for sale, allegedly without the permission of the people concerned. If you believe their rather wild claims millions of people will now be mercilessly stripped of their pensions by blaggards from the data industry who all have villas in Florida and drive expensive sports cars.

Undoubtedly there are some sharp operators out there. But that is true of almost any industry or sector. However the thing that struck me throughout the furore was that no one really cares about their data, so why are the Daily Mail getting so uptight?

Quite apart from the small rather inconvenient fact that quite a lot of the data they were whining about was probably obtained perfectly legally, the people they are trying to protect throw their personal information around with such gay abandon that it is a surprise anyone has a pension left.

Social media sites like Facebook and LinkedIn are rife with stupidity. People happily give access to their information to all and sundry and are then surprised when someone nicks it, or spam’s it. And people throw away old computers and phones without wiping the data. It’s like writing your bank details on a piece of paper and putting it in the bin, rather than shredding it.

Of course there is a problem here. Most people are not totally scammed. You hear about the odd identity theft or black credit rating caused by data theft, but most people get away with being really quite dim.

And here we are back at one of my pet themes...education. Technology has outstripped education to an extent. When I was a teenager we had some practical lessons...how to write a cheque, how to boil an egg, iron a shirt, sew on a button and make phone calls. And yes we got to look at pictures of the odd male reproductive organ in sex education classes too! Nowadays kids would not know what a cheque was, and have probably seen more naked bodies on social media than I have had hot dinners.

But we should be teaching them how to be safe on these things, and not just safe from sexual predators (although that is obviously important). Their data is precious because it is information. If they learn not to release it to strangers without cause, or without knowing what will be done with it, we can eradicate all these problems. And if they learn that the hardware holds a multitude of sins waiting to bite them in the bum too, they will learn to deal with that.

Businesses suck up information, largely for no apparent reason. They do not use most of it. Ever. If you are asked a personal question that has no relevance to what you are doing, refuse to answer. It will stop it ending up as a selection criteria on some database somewhere.

Data is mostly unintelligible. Most of the crazy predictive things analysts say they can do with data do not work very well. They work in general terms, and in that sense, from a marketing point of view help identify a category of targets with a theoretical propensity to do ‘X’. Then a tele-sales exec hits the number and asks you about PPI. That is the level of sophistication we are talking about here. It is nothing sinister. Data in itself, the sort we put down on forms and the sort that ends up on those evil databases, is not really going to do us much harm.

So, actually, if you are still with my train of thought, the disposal of your old equipment without dealing with the data is the most stupid thing of all. Because this is not just the data, this is the whole shebang...your account numbers, your passwords, your photo of that girl on holiday doing that physically almost impossible thing with the banana and the sun lounger. And the Daily Mail is not getting all excited about computer recycling are they?

So it’s just me then!

Tuesday, 31 March 2015

Dodgy Data Distraction



You have to love the Daily Mail. They do love a scare story. Yesterday it was your pension data being sold for 5p to unscrupulous cold-callers by allegedly dodgy data companies. Shock horror, we will never be safe in our beds again!

I caught up with the story on the Today programme and heard Chris Graham, the Information Commissioner himself, living up to my nickname for him of Genghis Khan. He was threatening immediate investigations into B2C Data, the company the Mail outed, with his usual £500k fine and a bit of decapitation if the guilty were found guilty.

But just hang on a cotton picking minute. The accusation here was that personal financial information was being passed on (sold) without the knowledge of the individuals concerned. Well the B2C website isn’t exactly hiding its activities under a bushel, Mr Daily Mail. Their website boasts of their 38m strong database and suggests that it has been compiled from a large number of syndicate partners.

So this is not necessarily dodgy and that is what the Daily Mail, the Today programme and the man in the street fail to realise. Every time we apply for something...a mortgage, a phone, a credit card or even a holiday...we freely give lots of information, and somewhere in the small print will be a box to either tick or untick talking about sharing that data.

It’s the junk mail box if you like. You are opting in if you tick it to agree and opting out if you tick it to disagree. And whether you opt in or fail to opt out matters.

All email data to consumers ought to be opt in, by law I believe. Genghis will know this. If you agree to receive emails, lo and behold you will receive emails. Your address will be sold to all and sundry for a few pence. Mine seems to be sold to Viagra salespeople and purveyors of gentlemen’s entertainment but that might just be spam. There is a difference between unsolicited marketing communications and spam you see. One you have agreed to, the other you haven’t.

So, just what are the Daily Mail objecting to here? If B2C are selling data without the required permissions/opt-ins from their syndicated partners, everyone will be in trouble. I am not saying it doesn’t happen, because it does, but the real charlatans are not trumpeting their wares on a web site in my limited experience.

I am afraid the much more likely scenario is that this is all essentially above board. Companies like B2C amalgamate data from a variety of sources and if you as an individual appear on their database it will be because you gave your information to one or more of those sources. If those sources are legitimate they will have asked you a question about selling your data on and you will, perhaps unwittingly, have given them permission to do so. It may have been asked sneakily, it may have been an auto-ticked box on a web form that you failed to notice, but it will have been done.

So what data are they likely to have? Well, basically anything you have ever filled out on a form applying for something. Name, address, phone number, spouse, number of kids, email, mobile and middle name for sure. Salary, job title and number of years in your job. Probably. Nothing startlingly private. Ok, I know it is not stuff that you want published in the Daily Mail, but it is not really doing you any harm appearing on a database, and remember, this information is really only going to be used to select you to receive a phone call or email.

A marketing database is a prospect list, and someone trying to get you to unwisely take your pension now in cash (the threat the Mail was highlighting) will have used your salary to bracket you. He/she earns above X so he/she will likely have a pension of X so is worth a call. Or he/she is this age and earns that, so he/she is a target. Every piece of information they have on you is a selector, and really nothing else. And companies like B2C charge by selection.

The 5p the Mail quoted probably won’t get you a lot more than email, name and postcode. If you want the detailed information, you would pay more. And this information has been on the market for years, both legally and illegally. No doubt, as the Mail says, some of this information ends up in the hands of criminals, but I am not sure you can necessarily blame B2C for that.

This needs investigating of course, but if the accused company have been aggregating data from multiple sources legally, making sure that the opt-ins and outs were all done properly by their syndicate partners and then cleansing and managing their database correctly, I hope they sue the backside off the Mail.

Data is a very misunderstood commodity. We all create it and give it to people without really thinking about what we are doing. As a marketer, I want your email address and your permission to use it. In B2B, my field of expertise, there is much less regulation on this sort of thing but I still want your permission, tacit or proactive, because the communication is more rewarding that way.

The aggregation of business data is every bit as sly as the consumer stuff. For instance, Companies House happily sells its data on every business registered with it for a nice fat fee. Then the data companies start adding to this basic registered address and directors info by overlaying directory data to get trading addresses and phone numbers. Maybe some research will be done at some stage to pick up some contact names and bingo, you have a list.

You may not realise that you gave your data away. You may have been slightly tricked into not noticing the box which would have stopped it all. But you have done it dozens of times. We are all on hundreds of different lists. Just one example you probably do not realise, the Bounty rep who called on you or your partner whilst you were recovering from the birth of your baby. They gave you some nice freebies and took some information off you, and that information is one of the most valuable data sets in the country. New parents are an easy touch you see, like prospective pensioners. I wonder if the Mail will investigate that?

The moral of all this is that it is never good to give your data away. Find the box if you are filling out a form and find a responsible data security and recycling professional if you disposing of any old computers! Simples.