For my first post as a business owner I’ve decided to reflect on the start and end of era’s.
In January 2008 I held a planning meeting with the IT director of a major high-street retailer with annual sales in excess of £150M. The conversation turned to customer and employee privacy and 2 minutes later moved on. The reason for so little focus wasn’t ignorance or lack of awareness of the potential threats. It was a simple calculation that balanced the cost and complexity of building in privacy versus the maximum possible fine of £5000. The 2 minutes spent were quite generous really.
Move forward nearly 10 years and I expect that meeting would be significantly different. The UKs implementation of the General Data Protection Regulation (GDPR) becomes enforceable in May 2018. A new position has been filled in the form of a Data Protection Officer (DPO) who can veto the project. An entire meeting would be scheduled to map the options and consent processes for the use of customer purchase information in analytics and discussing the need to anonymise the training instances. A little more than 2 minutes needed I think…
The well documented GDPR fine structure has had an increasing effect on all my engagements over the past 18 months. 20 million euros or 4% of global annual turnover as a maximum fine turns the cost calculation on its head in a way that the uplift in 2010 to £500K simply didn’t. The change of emphasis from simple data protection to data privacy means that the conversations are not restricted to IT security practices any more and my client engagements are business focused, challenging data use internally within the company and discussing software solutions that simply didn’t exist 18 months ago.
That said I’m not yet convinced attitudes have changed. I still get quizzical looks when I explain explicit consent limiting the use of private information. The prevalent belief is still that once the data is obtained it can be used without restriction within the company or even shared with a sister business without ramifications or limits.
If you are looking for assistance with GDPR and engage a consultant expect, no demand, to be challenged. If however you run a business and don’t believe or care about GDPR principles I have to question what will change attitudes if not seeing the ICO actually levy a heavy fine. In my view the only reason fines have escalated, from the £5000 of 10 years ago, is that cost effectiveness was put ahead of doing the right thing, (and not mis-using personal information).
Today Elizabeth Denham the UK’s Information Commissioner spoke to the Institute of Directors and quoted again that “..four out of five people do not trust private companies with their data”.
However the tagline I most relate to was this. “….Organisations which thrive in the changing environment will be the ones that look at the handling of personal information with a mindset that appreciates what citizens and consumers want and expect. That means moving away from looking at data protection as a tick box..”
Perhaps it really is time to spend more than 2 minutes on this.
read the full speech here
