Tag: data privacy

  • Location Data Privacy

    I caught a post from Bruce Schneier that references an article about a company collecting location data from numerous apps (WSJ, AndroidAuthority). This is legal, though the company has ties to the US government. As expected, there are people upset with this tracking, and we don’t have a list of applications.

    Apparently a company, Anomaly Six, provides some tracking code to app developers, whom are paid to include this in their apps. I wonder if this for specific companies or contractors. The former is bad, but if the latter, do the clients know their contractor is including this code? I suspect many software development tools wouldn’t necessarily flag this, if a client even bothered to review the code they were provided.

    This does seem creepy, and disturbing to have someone tracking your code. However, the data is supposedly anonymized, meaning that they know a phone was moved through “these” locations, but they don’t know who knows the phone. I assume the government could actually get a warrant and track your phone if you were suspected of some crime, so is this bad?

    I can’t quite think of why I dislike this, but I do. Perhaps this is to perform some sort of traffic analysis? Either physical movement of individuals or maybe the correlation of cell phone location with other data? Maybe they look for how often phones come into contact with each other? There are likely lots of uses for this anonymous data that could be useful to planners, but I also think there could be lots of more open ways of getting this data, such as asking for it from mobile providers.

    This feels like yet another place where the US is woefully disrespectful of data about humans. We seem to be way behind other countries, and it’s distressing to me. I hope that we start to enact a framework of legislation to give people more rights over this data, but I’m not sure that I will see that happen anytime soon.

    Steve Jones

  • Adapting Privacy

    Lawyers will be lawyers.

    That’s a quote from a piece at Ars Technica on how and why search engine startup Neeva changed their privacy policy. Their business model relied on users paying Neeva to keep their data private. The goal being a secure platform that considered users privacy. An admirable goal, and one that I might have been welling to fund. There is a lot of data out there, and while I don’t mind companies improving their service to me with data about me, I don’t like them sharing it.

    In this case, Neeva didn’t read their terms of service very well. I don’t think this was malicious, but it was a mistake. I’m sure they used a legal group that someone recommended to them, and the lawyers were trying to craft a document that was structured to protect the company and allow for flexibility. Sharing data with affiliates and advertisers would seem to go against their model, but it’s something lawyers might think is fine. If you read the article, you can see how Neeva has adjusted their terms.

    As the world grows more digital, and we all deal with an ever increasing number of organizations, data privacy will become more important to some, perhaps many people. The ideas of reducing data retention, limiting transfer of data, and giving users more control is an idea that may take hold, especially if a few companies start to succeed with this business model. We’ve seen pressure on companies throughout this year cause them to shift their previous stances, sometimes dramatically.

    For those of us that work with data, this might mean easier administration in some ways. Certainly we will have to alter our systems for archival or more flexibly data retention policies. We might even need to adapt our data models to include more fields that allow us to easily decide what data to keep, remove, or obfuscate things.

    In fact, I wonder if that’s the future of privacy. We de-link old users by randomly setting values for PII data and keeping other information like sales values or URLs clicked as useful information for aggregation without any risk of disclosure.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.

  • The Social Impact of Data

    Let the data drive your decisions.

    This has been something of a mantra for many technical people, and even many business people, across the last twenty or so years. The allure of business intelligence is harnessing lots of data to make decisions that are rooted in some rational analysis of what has happened. Many companies use “data driven decisions” as a way of achieving success.

    However, what about when the data is flawed? When deliberate or inadvertent actions give us data that isn’t quite as pure as we expect. In the last week we have seen many protests and complaints about the ways that many people feel they have been unfairly treated by police. That brutality, particularly for African Americans in the US, has been a problem for decades. Some of that is due to human biases, beliefs, and more. However technology plays a part, and will for some time to come.

    I have watched as algorithms have been used in sentencing, and I’ve questioned their use, as have others. There is this idea that computers will be more fair, looking at inputs and making a decision that isn’t encumbered by human biases. The problem is that humans that program the systems might have some bias. Maybe more disconcerting is that the data used to train systems is likely biased as well.

    There is also the concern that as technology advances, it can be put to new uses, perhaps in ways that the inventor regrets. Oppenheimer regretted the violent use of his work, and I wonder if technology inventors will feel the same way. Surveillance technology is controversial. It can help retails companies prevent theft, but it can also be used in ways that might enhance and reinforce bias in police work. This can be controversial, and no matter how you may feel about the technology, there are moral questions of privacy and prejudgment that are worth debating.

    The last couple weeks have saddened, upset, and angered me at different times. I am also confused and concerned, unsure of how to discuss and debate these topics. I find my position moving slightly with different stories and different information, as I should. I learn more and my views grow and change, shaped by what touches me. I do worry about how we use data in the future, and how it can be abused. There are ways in which more data can help improve our world, but the potential for abuse is high, and I do believe we need governance, transparency, and an independent appeal process for those wrongly impacted.

    Steve Jones

     

  • When Will Privacy Matter?

    More and more people are becoming concerned about data privacy. There’s more advocacy, and this shows in more laws being passed around the world. Those are good steps forward, but those rules and restrictions are just the lowest bar of what I’d hope for. Regulation will always lag behind best practices and technology, and I’d hope that organizations look to do better.

    I expect more competition to crop up again in the future as the world grows, and I wonder if some of these businesses will start to take privacy seriously. Not because of regulation, but because it might provide some competitive advantage. I ran across a short piece that has a few ideas on how you might be more competitive in your niche if you take privacy seriously. These are ways that taking privacy seriously might make you more competitive.

    I think the big one for me is transparency. Showing customers that you are open and up front with data will pay off. Most of us know that our data is being collected. We know it’s being used for marketing. Many of us don’t love the idea, but we also do get used to the value we do get from services. A few people might balk, but once they realize everyone is collecting and using data, they’ll appreciate those that are more transparent.

    Certifications are nice, and having employees work on security can help, but for privacy, we need to help customers understand how and why we use data. We need to respect their data, and learn to remove it when a business relationship goes away. It can be tough for many data pros and business people to get rid of data, but it’s prudent, it reduces the strain on live systems, and it helps build trust with customers. Plus, if you are treating customers well and they appreciate it, they’ll come back over and over, which usually means you won’t ever need to trim much of their data.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.