<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4361742269119622426</id><updated>2011-04-21T19:19:02.557+01:00</updated><category term='identification'/><category term='data protection'/><category term='control'/><category term='privacy'/><category term='solutions'/><category term='trust'/><category term='phone'/><category term='security'/><category term='fraud'/><category term='personal data'/><category term='telephone'/><title type='text'>Information Security Futures</title><subtitle type='html'>Tim Williams blogs on current and future trends in Information Security.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://timdwilliams.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4361742269119622426/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://timdwilliams.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Tim D Williams</name><uri>http://www.blogger.com/profile/14377948130159867436</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_Adly1WML9Rg/SMMPSod6nFI/AAAAAAAAACk/-vXzgKgAXjs/s1600-R/tim_d_williams3.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4361742269119622426.post-4663897622489145787</id><published>2009-03-22T00:22:00.004Z</published><updated>2009-03-22T00:39:42.401Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='trust'/><category scheme='http://www.blogger.com/atom/ns#' term='data protection'/><category scheme='http://www.blogger.com/atom/ns#' term='control'/><category scheme='http://www.blogger.com/atom/ns#' term='personal data'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><title type='text'>Next Generation Data Protection Laws</title><content type='html'>&lt;span style="font-family:arial;color:#000066;"&gt;Right now, even if you live in a European country (so compared with many other countries, you benefit from above-average data protection legislation), in reality you have very little control over what companies actually do with your data.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;span style="color:#000066;"&gt;Once companies have your data, in most cases they control: &lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;why your data is used? for what purposes?&lt;/span&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;how your data is used? what is it linked to? how is it processed? how is it presented?&lt;/span&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;whether it is backed up? when it is deleted i.e how long they keep it ?&lt;/span&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;which fields they change?&lt;/span&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;who can access it internally? which departments/roles/individuals?&lt;/span&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;who they share it with externally? which companies? which government departments?&lt;/span&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;where it is stored? where they share it? which countries it is exported to?#&lt;/span&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;what level of protection is applied? &lt;/span&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;what level of auditing is done?&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span style="color:#000066;"&gt;The current state of affairs is clearly not good for individuals/consumers ... but I happen to think it is not good for business either...&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#000066;"&gt;If individuals have no control over what happens to their data then it is difficult for them to trust the companies they are dealing with. If they don't trust who they are dealing with then they probably do less business with them than they would do if trust was there.&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#000066;"&gt;What I am proposing in this blog is that far-sighted companies who want to build maximum levels of trust with their customers (thereby positioning the company to sell a broader range of products and services to their customers) will start to provide their customers with more control over what happens to their personal data.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#000066;"&gt;In these days of customer-self service where most customers already know how to 'point and click' on a web page to create and update their own profiles, it would not take much effort to provide customers with better fine-grained controls over what happens to their data.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#000066;"&gt;How about these for features that every self-respecting company should in future want to include in their 'update profile' customer web pages:&lt;/span&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;table listing trading partners including checkboxes that allow the customer to choose which partners their data may/may not be shared with&lt;/span&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;table listing countries including checkboxes that allow the customer to choose which countries their data may/may not be exported to&lt;/span&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="color:#000066;"&gt;a drop-down list for how long the customer allows the data to be retained without asking again?&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;span style="color:#000066;"&gt;Please comment if you have any view(s) on this....&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4361742269119622426-4663897622489145787?l=timdwilliams.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://timdwilliams.blogspot.com/feeds/4663897622489145787/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4361742269119622426&amp;postID=4663897622489145787' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4361742269119622426/posts/default/4663897622489145787'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4361742269119622426/posts/default/4663897622489145787'/><link rel='alternate' type='text/html' href='http://timdwilliams.blogspot.com/2009/03/next-generation-data-protection-laws.html' title='Next Generation Data Protection Laws'/><author><name>Tim D Williams</name><uri>http://www.blogger.com/profile/14377948130159867436</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_Adly1WML9Rg/SMMPSod6nFI/AAAAAAAAACk/-vXzgKgAXjs/s1600-R/tim_d_williams3.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4361742269119622426.post-5392327428423738565</id><published>2009-03-21T22:27:00.000Z</published><updated>2009-03-21T22:36:09.115Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='telephone'/><category scheme='http://www.blogger.com/atom/ns#' term='solutions'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='phone'/><category scheme='http://www.blogger.com/atom/ns#' term='personal data'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='identification'/><category scheme='http://www.blogger.com/atom/ns#' term='fraud'/><title type='text'>Identifying Phone Callers</title><content type='html'>Why is it that companies think it's OK to call their customers and ask customers for their ID, but they don't have any way to prove their ID?&lt;br /&gt;&lt;br /&gt;Isn't it just asking for trouble if companies 'train' their customers to give out their ID to unidentified callers?&lt;br /&gt;&lt;br /&gt;Wouldn't it be so easy for companies making outbound calls to let their potential customers ask them safe confidence building questions first, like what's the first digit and the fifth digit of my account number?   &lt;br /&gt;&lt;br /&gt;Even if such minor details were occasionally disclosed to someone who wasn't actually their customer, the data would not be useful to any wrong-doer, and the benefits of all customers not giving out sensitive data to random callers would far exceed any risks.&lt;br /&gt;&lt;br /&gt;I'm very interested to know what other people think about this idea. Please comment...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4361742269119622426-5392327428423738565?l=timdwilliams.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://timdwilliams.blogspot.com/feeds/5392327428423738565/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4361742269119622426&amp;postID=5392327428423738565' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4361742269119622426/posts/default/5392327428423738565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4361742269119622426/posts/default/5392327428423738565'/><link rel='alternate' type='text/html' href='http://timdwilliams.blogspot.com/2009/03/identifying-phone-callers.html' title='Identifying Phone Callers'/><author><name>Tim D Williams</name><uri>http://www.blogger.com/profile/14377948130159867436</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_Adly1WML9Rg/SMMPSod6nFI/AAAAAAAAACk/-vXzgKgAXjs/s1600-R/tim_d_williams3.jpg'/></author><thr:total>0</thr:total></entry></feed>
