Being open about data privacy

4 min read
Curated from opensource.com →

Today is Data Privacy Day, (“Data Protection Day” in Europe), and you might think that those of us in the open source world should think that all data should be free, as information supposedly wants to be, but life’s not that simple. That’s for two main reasons:

So actually, data privacy is something that’s important for pretty much everybody.

It turns out that the starting point for what data people and governments believe should be available for organisations to use is somewhat different between the U.S. and Europe, with the former generally providing more latitude for entities—particularly, the more cynical might suggest, large commercial entities—to use data they’ve collected about us as they will. Europe, on the other hand, has historically taken a more restrictive view, and on the 25th of May, Europe’s view arguably will have triumphed.

That’s a rather sweeping statement, but the fact remains that this is the date on which a piece of legislation called the General Data Protection Regulation (GDPR), enacted by the European Union in 2016, becomes enforceable. The GDPR basically provides a stringent set of rules about how personal data can be stored, what it can be used for, who can see it, and how long it can be kept. It also describes what personal data is—and it’s a pretty broad set of items, from your name and home address to your medical records and on through to your computer’s IP address.

What is important about the GDPR, though, is that it doesn’t apply just to European companies, but to any organisation processing data about EU citizens. If you’re an Argentinian, Japanese, U.S., or Russian company and you’re collecting data about an EU citizen, you’re subject to it.

“Pah!” you may say,1 “I’m not based in the EU: what can they do to me?” The answer is simple: If you want to continue doing any business in the EU, you’d better comply, because if you breach GDPR rules, you could be liable for up to four percent of your global revenues. Yes, that’s global revenues: not just revenues in a particular country in Europe or across the EU, not just profits, but global revenues. Those are the sorts of numbers that should lead you to talk to your legal team, who will direct you to your exec team, who will almost immediately direct you to your IT group to make sure you’re compliant in pretty short order.

This may seem like it’s not particularly relevant to non-EU citizens, but it is. For most companies, it’s going to be simpler and more efficient to implement the same protection measures for data associated with all customers, partners, and employees they deal with, rather than just targeting specific measures at EU citizens. This has got to be a good thing.2

However, just because GDPR will soon be applied to organisations across the globe doesn’t mean that everything’s fine and dandy3: it’s not. We give away information about ourselves all the time—and permission for companies to use it.

There’s a telling (though disputed) saying: “If you’re not paying, you’re the product.” What this suggests is that if you’re not paying for a service, then somebody else is paying to use your data. Do you pay to use Facebook? Twitter? Gmail? How do you think they make their money? Well, partly through advertising, and some might argue that’s a service they provide to you, but actually that’s them using your data to get money from the advertisers. You’re not really a customer of advertising—it’s only once you buy something from the advertiser that you become their customer, but until you do, the relationship is between the the owner of the advertising platform and the advertiser.

Some of these services allow you to pay to reduce or remove advertising (Spotify is a good example), but on the other hand, advertising may be enabled even for services that you think you do pay for (Amazon is apparently working to allow adverts via Alexa, for instance).

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at opensource.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.