Tag: GDPR

  • Changing Context and Data Reuse

    One of the points of the GDPR that I thought was very interesting was the idea that users needed to give consent for data use for specific purposes. This had many companies trying to reaffirm consent last year while others assumed previous consent was valid. No matter how you viewed the law, any change in the way that a subject’s data was used required new consent.
    We don’t have a law like that in the US, and that allowed IBM to scrape images from Flickr to use in facial recognition software. This isn’t dramatically different from lots of scraping that goes on from other sites, where plenty of data is aggregated, but there is certainly some private data being used for new purposes. When Netflix created a contest to help build a recommendations engine, they shared data, albeit in a way they thought was anonymous. It wasn’t  and Netflix stopped trying to run contests.
    The article from Tim O’Reilly and Mike Loukidesi is an interesting look on privacy, rights, and consent for data use. Many of us click through overly broad rights agreements, many of which I think should be more limited by law and regulation. Unfortunately we seem to allow data to be aggregated, reused, and re-sold, often without any input or redress for the individuals to whom the data refers. The article notes that often the context of how the data is used changes, so it’s not whether the data is public or private, but rather how the data is used.
    I think this is a better way to examine data, and perhaps one that courts and arbitrators ought to be charged with protecting. Too many companies play fast and loose with data usage, and in an area of larger and larger data driven companies, I’m not sure I see a public interest for the rights of companies to trump those of individuals. Especially where privacy and security are concerned. Even when this might impact commerce.
    I rejoice in the tremendous amount of data in the world and the opportunities it brings for many to learn more about their lives. I appreciate the opportunities I have to work with data. I think data helps companies provide better services and build more efficient processes. I also think that many companies take advantage of the data to increase their revenues without understanding that there should be some rights for the people that did not agree to, and do not want to participate in the new uses of data.
    Steve Jones
    Listen to the podcast
  • Scary Data Collection

    Most of us would feel fairly creeped out by finding out an AirBnb or hotel had security cameras watching us. I’m not a woman, and I’m sure ladies are especially bothered by this, but there was an AirBnB rental where a guest found a camera using a little technology scanning. While cameras are allowed, they have to be disclosed.
    While many of us would prefer not to be surveilled, we are on a regular basis. Governments are watching our vehicles, all commercial activity is tracked in multiple ways, our locations are captured and sold to anyone. And it’s not even the carriers, it could be software that we think is innocuous and helpful. I would think most people reading this know that everything you do online is tracked, and often tracked from site to site with Facebook, Google, and other APIs, even if you don’t use those companies’ services. What’s disconcerting to me is how extensive data gathering and tracking has become and most people aren’t aware how comprehensive it has become.
    And in a wonderful set of timing. As I was writing this, I got a great article about how Google apparently isn’t perceived as invading privacy to the extent that they are. We likely trust them more than we should.
    The capture and misuse of data continues to grow. Whether this is by criminals, governments, or commercial businesses, it’s something we have to deal with. This isn’t necessarily any particular organization or situation that stands out, though the larger organizations likely have an out-sized impact and benefit from this. This is one of the reasons why the GDPR and similar legislation was passed. It’s a first attempt, and arguably weak attempt, to limit the use of data by organizations in ways that might be contrary to the wishes of the human that generated the data.
    Personally I like the GDPR, and while it might need alteration over time, it does start to to examine the idea that humans ought to be in control of data about them, just as we are often in (some) control of many of the physical items in the world we own. There are rules and regulations, restrictions, and even legal processes that provide recourse over our possessions. Those ought to be extended, and certainly adapted, to digital data, with the corresponding rights that we currently have and perhaps even new ones.
    I think this is going to impact our jobs as data professionals in the future. While we will have more requirements, more hassles from security, and more restrictions, this is also going to ensure that organizations need data professionals for a long time.
    Steve Jones
  • Treat All Sensitive Data as Important

    We know that not all the data in our company is important. We have databases that contain orders or inventory or schedules, often much of which isn’t easily or directly related to an individual. At least, it’s not if you have a normalized database. If you use SQL Server to emulate Excel spreadsheets, it’s possible that most of the rows of information in your system contain sensitive data.

    In some systems, there is definitely some data that is sensitive and needs more care than other data. We know this, and with legislation like the GDPR, we must protect this data. We also need to ensure we know where this data is, and having a good data catalog is important. This is something that few of us have, though I expect this to be a more regular part of our job as data professionals. SQL Server is building data classification into the product, which I am happy to see.

    When data is sensitive, we need to treat it carefully, even if we don’t like the content of the data. Recently there was a data breach from B&Q, a home improvement retailer in the UK, where 70,000 names were lost. These weren’t customers, but rather people that had been caught stealing from the stores. Perhaps this was an honest mistake, on a data store with poor security. Perhaps no one thought this data needed security because these were criminals, or suspected criminals. Even if these were individuals that might be prosecuted by the company, their data still deserves the same protection as any other person’s data.

    I don’t know what the fallout will be from this breach, and certainly most people would have little sympathy for criminals, but who knows just how accurate the data might be. I certainly think this is a situation where there is a high likelihood of legal action against the company if the proper GDPR notifications were not followed. Wouldn’t that insult to injury? People caught or suspected of theft suing you because you leaked their personal information. I could certainly see management getting extra upset and terminating someone that forgot to secure these systems.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 3.4MB) podcast or subscribe to the feed at iTunes and Libsyn.

  • Google’s Expensive Confusing Rules

    I worked through the Y2K crisis. I call it a crisis because so many of us were worried and millions, probably hundreds of millions of dollars were spent by companies trying to ensure their software systems would work when the date changed to 2000/01/01 00:00:00. I was on call that night, celebrating the new year at home, not drinking because I was slightly worried my paranoid boss would call me in. He didn’t and there were few issues around the world in systems, perhaps because of the build up of the crisis and lots of prep work. I went through a similar set of concerns when the Sarbanes-Oxley act was passed in the US. Not much came of it, and companies spent a lot of time and money preparing.

    Over the last two years, it has been deja vu as the GDPR moved towards the enforcement date last May. Lots of companies, including my own employer (Redgate Software) were concerned and spent time and resources getting ready. The enforcement date came, with some early complaints being filed, but few fines. Perhaps the preparation paid off, but more likely it just takes time for audits to occur and complaints to be investigated.

    It appears that the first big fine has been handed down to Google. Recently the CNIL (the French data protection regulator) fined Google 50 million euros for not compliance with the GDPR. Their reasoning was that Google didn’t provide enough information about their data consent policies and didn’t give users enough control. They complained that the data is spread out in many different places and too difficult to understand. Other countries are investigating, and Google is going to appeal.

    Personally the presentation and dissemination of information from Google should be top notch. That’s their job: to search, assemble, and present data. As someone that has paid for Google Apps and email, has used Google Analytics, and generally tried to understand some of the other products, I think too many engineers and not enough technical writers work at Google. I think they are surprisingly bad at making it easy to understand how to accomplish some task, including finding out some information about my account or my data. I’m not surprised that they were fined, since I think they have had an opt-out philosophy and the many different groups inside the company have considered the data gathered to belong to Google, not the human about which it refers.

    I don’t know how this will play out, but as a person, I do hope that companies will be asked to clearly disclose what data they have, how they use it, and to delete it when the business purpose is complete. I’d prefer that I had more control and understanding of my data, including the crazy cookies and other mechanisms that track my browsing across sites. While some companies use this to provide customization, there is plenty of potential for misuse here, and I’d like it to stop.

    As a data professional, I’d like to have clear understanding of how to treat and protect data. I’d prefer that we better secured it, didn’t use live data in development environments, and we built better habits as technology professionals. Data is truly and asset, and one that can easily help businesses grow, but it also has the power to be abused. I’d like that to stop with sensible rules that I can work within.

    Let me know how you feel today.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 4.8MB) podcast or subscribe to the feed at iTunes and Libsyn.