Posts filed under 'Privacy 365'
Ellen Nakashima gives a great minute-by-minute account of one woman’s digital trail in the Washington Post today. Follows the many data points collected everyday by surveillance equipment, convenience technologies such as FastTrak, and everyday online activities.
January 17th, 2007
TRUSTe just completed a survey of consumers on security breach notice and we’ll soon be releasing some data on how residents of states with breach notice requirements fared versus residents of states without breach notice requirements. Lucky for California’s stats we conducted the survey prior to the UCLA data breach. I received my first breach notice yesterday, not from my bank or credit card company, I had applied to a UCLA program in 1997.
I’ve been reading through Kim Cameron’s whitepapers on digital identity, namely the 7 Laws of Identity which I think sums up nicely what was broken at UCLA, “We should build systems that employ identifying information on the basis that a breach is always possible. Such a breach represents a risk. To mitigate risk, it is best to acquire information only on a “need to know” basis, and to retain it only on a “need to retain” basis. By following these practices, we can ensure the least possible damage in the event of a breach.”
December 15th, 2006
Great article about everyday privacy on Reuters Today called “Product Returns: Consumers balk at giving personal info”
I recently tried to exchange sizes on a cash purchase at the Children’s Place here in San Francisco. Upon the exchange I was walked through a series of questions requiring my name, address, telephone number, etc. All of which I refused, requiring store manager intervention.
There are two issues arising in these situations:
1) Retailers do not provide adequate notice and information about any type of personal data collection at the point of sale. Combined with woefully undertrained and unknowledgeable store clerks, who give misinformed or inadequate answers — how can you blame customer unease at handing over personal information? I can guess more accurately why my personal data is being collected than the store clerk who may or may not have been instructed to respond.
2) At least in cases where your infomation is collected for marketing purposes consumers can see potential value in coupons or special offers. In this case you are asking law-abiding individuals to potentially expose thier personal information to a data breach because retailers have a 9% fraudulent returns problem.
So it doesn’t surprise me at all that individuals lie about thier information when asked, or that they balk at giving thier driver’s licenses to retailers. I encourage consumers to speak up about non-essential data collection, and demand reasonable disclosure about why and how the information is being used.
August 3rd, 2006
Not everyone spends eight hours a day thinking about privacy; how to protect your information, what companies and others are up to when they collect information, and what you can do about it. But here at TRUSTe, all 25 staffers - know a thing or two about the collection and use of Personally Identifiable Information. In the Privacy 365 category, TRUSTe staff will write about everyday requests for our personal information, speculate on the intended use and how we handled that request.
April 3rd, 2006