Ethics standards and protocols are urgently needed in the data world

In the last few years, we’ve seen the proliferation—some would say explosion—of access to data and, as an extension, of data analytics. Every industry—from energy to education, from manufacturing to media—is harnessing the power of information to optimize outcomes.
At the same time, this unprecedented amount of data is creating incredible opportunities for unauthorized access or release of private information.
We’ve seen one of the worst: three billion Yahoo accounts impacted in 2013—to some of the most frequent: already in 2019, there have been an estimated 3,800 disclosed data breaches, totaling 4.1 billion records. And these breaches occur in every industry, in companies as varied as Panera Bread to Wells Fargo to Facebook.
And in many of these cases, we often saw a significant lag before people were informed that their data had been compromised. (With Yahoo, LinkedIn and others, the lag was years.) Companies often defend these lags by pointing to their own internal investigations. But let’s be honest—the negative impact to the bottom line is what keeps most of these breaches quiet.
The general public also plays a role in these data breaches. They occur with such frequency, we’ve developed data breach fatigue. As a consequence, with every new breach, the general consumer becomes desensitized, feeling powerless, thinking “so much of my data is already out there; what can I do about it now?”
We too often fail to emphasize what data breaches could really mean to the individual—e.g., financial ruin, loss of security clearance—which often have a ripple effect on the economy. In fact, a 2018 IBM study found that the average cost of a data breach globally is $3.86 million, indicating the number of breaches in the first half of 2019 total cost could rival the GDP of some countries.
Yet, it doesn’t look like the collection and use of data or the data breaches and the complacency around them are going to go away any time soon.


