Categories
Europe In the News Legal & Compliance Strategy and Management USA

Data privacy fears threaten $250bn transatlantic trade

us-eu-flags-2The uncertainty is being fuelled by a double whammy of scepticism about how robust Privacy Shield is and fears that the alternative method, used by 80% of companies – the so-called standard contractual clauses (SCCs) – could be soon be rendered illegal.

According to a survey of 600 data professionals in the US and EU, only 40 US firms have so far adopted Privacy Shield, with just 34% intending to use the new data privacy framework, compared with 50% which used its Safe Harbour forerunner.

The situation is not being helped by EU data regulators sitting on the Article 29 Working Party (WP29). Although they approved the framework in late July, they have set off alarm bells by pledging to keep a close eye on how Privacy Shield develops.

Data privacy Shield assessment

At the time, they released a statement which said: “The first joint annual review will be a key moment for the robustness and efficiency of the Privacy Shield mechanism to be further assessed.”

US think tank the Brookings Institution has estimated that “digitally delivered services” between the EU and the US – including customer data storage – were worth nearly $250bn (£188bn) in 2015.

IAPP president and chief executive Trevor Hughes commented: “The legal uncertainty of standard contractual clauses and the scepticism about Privacy Shield may be a hangover effect from the Max Schrems case that invalidated Safe Harbour in the European courts. Clearly, organisations face an extremely complex regulatory landscape as they look to build their businesses for the digital future.

“It will be vital for them to employ privacy professionals at the highest levels of management to help navigate that landscape and capitalise on opportunity.”

Categories
Europe Global In the News Strategy and Management UK

Sites with pop-up ads face punishment from Google

Now Google eyes up DunnHumby bid.jpg newWebsite owners are being warned that the days of big pop-up ads are drawing to a close, after Google revealed that it is updating the algorithms used to rank search results in a move which will push them down the placings.

Set to come into effect on January 10, the search giant insists the move is designed to make using some of its results less frustrating, although observers point to the ongoing battle the company is mounting against ad-blockers.

In a blog post, the company said: “Pages that show intrusive interstitials [elements that cover the content] provide a poorer experience to users than other pages where content is immediately accessible. This can be problematic on mobile devices where screens are often smaller.”

Detailing its decision, Google cited three examples of the kind of practices it wanted to eliminate:

  • Pop-ups that covered part of the main content when the user clicked on to a page
  • An intermediary webpage that had to be dismissed before the main content could be seen
  • An ad that filled the web browser’s screen so users had to scroll down ‘below the fold’ before they could see the material they wanted

Pop-up ads: alerts are the exceptions

However, some pop-ups will be exempt, including those which alert readers to the use of cookies, as well as ones which require log-in details to let visitors get behind a paywall.

Daniel Knapp, a senior director of advertising research at the IHS consultancy told the BBC: “Google is one of the largest advertising companies in the world, but it’s in a very different position to Facebook, Snapchat and other global media consumption apps.

“Google is still very reliant on the desktop and mobile web to make money, and it’s much more difficult to clean up that experience than the native app environments. That’s why it needs to tighten the screws on everyone with this crackdown.”

Categories
Data Management Europe In the News Strategy and Management UK

Consumer data shared by companies more times than you think

data mistrust 2The study suggests there are at least 100,000 copies of each individual’s personal data being held on physical devices and cloud storage platforms.

Commissioned by Ground Labs, the consumer research quizzed individuals about how many organisations they believed had access to their personal data.

The majority (84%) guessed at fewer than 20; almost a third (28%) guessed fewer than ten, but once shown a list of 50 online services and retailers, two out of five consumers realised that their original estimate was way wide of the mark. This was based on their knowledge of interactions in the past 12 months alone.

Data security company Ground Labs VP EMEA John Cassidy said: “Unless customers have an accurate idea of who has access to their data, they are unable to take the precautions necessary to protect themselves online. We only asked people to pick from 50 of the biggest online companies, in reality, the number of organisations who have access to any one individual’s data is much, much higher than our survey suggests.”

Consumer data stored on and offline

Ground Labs insists that the total number of companies consumers interact with is actually irrelevant. With automatic backups, log files, emails and legal third-party sharing, hundreds of thousands of potential copies of individual’s data is being stored both on and offline. On top of this, many companies will keep records of former customers for years.

“A conservative estimate would suggest that for any given adult, hundreds of thousands of copies of personal data reside on physical devices and cloud storage platforms both in and outside of the UK. Most people are unaware of the multiplying effect when dealing with so many service providers and so the responsibility must fall on companies to protect this sensitive data,” Cassidy concluded.

Categories
Data Strategy Europe In the News Strategy and Management UK

PwC to hire 1,000 experts as data security fears soar

gloves, data securityThe firm said the new recruits will be join its UK Risk Assurance team within the next four years and cover all industry sectors across the country. As well as cybersecurity and privacy threats, the beefed up team will cover data management, business systems and IT risks.

More than 600 jobs will be filled by external hires, while over 400 will be transferred from other PwC sites. The firm will also be recruiting at least 200 data and tech graduates.

Digital disruption

PwC UK head of assurance Hemione Hudson said: “Business models that have served clients well for decades are being disrupted or destroyed due to the speed of digital disruption, the increase of regulatory scrutiny on technology risks and the escalation of cyber threat, requiring us to respond and build a strong team of specialists.”

Although there have fewer ‘car crash’ breaches following last October’s hack on TalkTalk, there is obviously a great deal of nervousness in the market.

PwC risk assurance partner Marc Bena added: “Our clients and their customers want to know that their technology is innovative and pushing boundaries whilst being safe and delivering what is expected. We have a duty to continue to build a team of technology experts able to help our clients do business with confidence.”

Categories
Data Management Europe In the News Strategy and Management UK

Royal Mail tackles home mover data decay

The Guide to Mover Marketing will also identify those who may be looking for move-related and home improvement products and services.

It has been developed in response to research from Royal Mail Data Services, which surveyed nearly 200 leading UK marketers to discover the key business challenges surrounding the use of customer data for marketing purposes.

The research revealed that 45% of marketers say recruiting new customers is their biggest challenge. The remaining 55% struggle with re-activation, upselling, retention and cross-selling to existing customers.

Further research suggests that 65% of consumers switch suppliers or engage with new brands during the home-move period as they track down the best deals.

Data decay – trends and characteristics

Home-mover marketing presents proven opportunities for brands, particularly in the utilities, telecoms, finance, insurance, banking, DIY, retail and home improvement sectors, to increase their customer retention, acquisition and re-activation rates, the firm claims.

The guide outlines the trends and characteristics of the UK home-mover market. It also offers strategies for data-driven B2C marketers to improve their customer acquisition, retention and engagement strategies by segmenting and targeting home movers with relevant, useful marketing communications.

It also explains how businesses can quantify the value of the home-mover market through analysis of customer purchasing behaviours before, during and after their moves.

Royal Mail Data Services managing director Jim Conning said: “The combination of price-conscious consumers, the breadth of choice to be found online, and fierce competition is making it more challenging and costly for B2C marketers to improve the performance of their marketing while boosting revenues. The key to success lies in a marketer’s ability to deliver ‘right-time’, contextual marketing that anticipates what customers need before they have to ask.”

The guide draws on Royal Mail Data Services’ experience of working with many of the UK’s leading brands to help them reshape their approaches to “right-time”, contextual marketing through the use of home-mover data alongside specialist data analysis and marketing services.

Conning added: “To be successful at ‘right-time’ marketing, marketers need access to timely customer information. This data must be accurate, permission based, and sourced via a first party. But it’s not enough to just provide great-quality data.

“Businesses also need insight into home moves period to help them understand when consumers are most likely to buy a company’s products or services or, indeed, to switch to the competition. And that’s where our specialist knowledge and experience come in. Our guide offers marketers a step-by-step approach to adopting effective marketing strategies and techniques to target home movers.”

The move follows the launch of eBay Advertising’s Home Mover ‘Advanced Targeting’ scheme, which cross references insights from eBay’s 19 million monthly users with Land Registry data to predict movers months before they actually settle into their new abode.

Categories
Europe In the News Legal & Compliance Strategy and Management UK

Charities face huge fines for ignoring opt-out service

charity fundraisingCharities that ignore the Fundraising Preference Service would still be in breach of the law – and liable for fines of up to £500,000 – despite the fact that it is not a statutory requirement, the UK Information Commissioner’s Office has confirmed.

Speaking at a recent conference in London, the ICO senior policy officer Richard Marbrow said the FPS would have legal status because the regulator would view consumer sign-ups as a withdrawal of consent to receive marketing communications.

Marbrow said some professionals had suggested charities would be able to ignore the service because it was non-statutory, but the ICO could pursue them for breaching the consent requirements of the Data Protection Act. DPA breaches carry a maximum fine of £500,000.

Charities opt-out service: FPS criticised

Although former Information Commissioner Christopher Graham initially criticised the FPS for being confusing, the regulator now wants the service to apply to all marketing communications, bringing it under the Privacy & Electronic Communications Regulations. Breaches of PECR carry a maximum fine of £250,000.

One study estimated that up to 30 million people could sign up to the FPS.

The move came as Graham’s successor Elizabeth Denham (pictured) took up the role from July 18. Ms Denham said: “I am delighted to have taken up this position and am excited about the challenges ahead. I look forward to working with staff and stakeholders to promote openness by public bodies and data privacy for individuals.”Information Commissioner UK

Denham, who will serve a five-year term as Information Commissioner, has held senior positions in privacy regulation in Canada over the last 12 years. Since 2010, she has been the Commissioner at the Office of the Information & Privacy Commissioner for British Columbia, Canada.

Categories
Europe In the News Legal & Compliance Strategy and Management UK

Call for industry to shape marketing law revolution

UK-based marketers are being urged to be proactive in helping to shape new marketing law on direct, data and digital activity – included in the Digital Economy Bill – which, it is claimed, could have far greater influence on the UK sector than even the EU General Data Protection Regulation.

Parliament has already approved the first reading of the bill, a move which will lead to the Information Commissioner’s Office preparing a code of practice on direct marketing with a clear instruction that relevant parties from within the DM industry must be consulted.

In addition, Baroness Neville Rolfe, the Minister of State at the Department of Business Energy & Industrial Strategy, has called for contributions in shaping the future of regulation by declaring that she is “very much in listening mode”.

The minister has already stated there can be no way of knowing whether or not GDPR is likely to apply to the UK until trade negotiations with the EU begin, although many experts expect the UK to adopt GDPR or at least its own version of the legislation.

But given that the Government has not yet decided its timetable to establish its bargaining position, everything is still up in the air.

Marketing law: atmosphere of uncertainty

Verso Group operations and compliance director Dene Walsh said: “What is certain is that with the Digital Economy Bill being sponsored by government itself, is written into the Queen’s Speech, and is likely to come into law far more quickly than the conclusion of trade talks relating to data regulation, with the additional possibility of the Information Commissioner deciding new direct marketing rules before negotiators have finished their job.

“In the immediate and medium term the only thing certain is uncertainty, and it is this atmosphere that presents an ideal opportunity for all parties to review all regulation to take into account the interests of both business and members of the public.”

Walsh maintains that the review should include all elements of commercial communication and data relating to members of the public, including the Telephone Preference Service. He added: “After 20 years, the TPS is showing increasing signs that it is past its sell-by date. Half its files are dead and it has far more registrations than there are active telephone numbers in the UK. More important, it is not effective in stopping increasing public concern about ‘nuisance’ calls. A more effective system needs to be considered.”

Walsh maintains that now is the time for an open review to create regulation for the next decade that protects the public, and lays down unambiguous rules that allow companies to operate within clearly defined parameters. “Incorporating all regulation into the review, including that of the TPS, MOJ and ASA provides a unique opportunity to establish rules that do not overlap and contradict each other. Clashes of rules currently put companies in an unfair situation in which they have to decide which rules to break based on which regulatory authority is likely to hand out the least severe punishment,” Walsh added.

“This is a once in a lifetime opportunity to create joined up rules that are understood and work for everyone, including members of the public. The alternative is to go on as we are muddling through with multiple sets of rules that overlap leaving nobody satisfied and always with the possibility of future short-term change.”

Categories
Europe Germany In the News Legal & Compliance Strategy and Management UK

When it comes to data protection, Brits trust Germany more than UK

germanyIn what will also make interesting reading for those following the row over the new transatlantic Privacy Shield pact, most people would rather rather have companies in fellow EU countries handle their data, than non-EU regions.

Some 42% of UK workers would trust EU countries to host their data, compared to 22% of those outside the EU.
Of all the EU countries that were asked in the survey (UK, Germany, France), Germany scored the highest (26%), followed by France (21%) and the UK (20%). The Spanish, on just 6%, were bottom of the pile, suggesting that, while Spain might be a popular holiday destination, few are willing to entrust the country with their personal information.

Data protection regime

The Germans have one of the toughest data protection regimes in the world, and at one time its MEPs were demanding that the EU General Data Protection Regulation (GDPR) should go further. It also outlawed cold telemarketing back in 2010, meaning consumers have to opt in to receive calls.

The results are a part of a larger report released by Blue Coat Systems, into who do Europeans trust with their data on Dropbox, Gmail and the like.

Robert Arandjelovic, director of product marketing EMEA at Blue Coat Systems, commenting on data protectionRobert Arandjelovic (pictured), director of product marketing EMEA at Blue Coat Systems, said: “The EU regulatory landscape is set to radically change with the introduction of the GDPR legislation and this research highlights the level of distrust in countries outside the EU.

“Respondents prefer to keep their data within the EU, supporting new European data protection legislation. More concerning is the fact that almost half of respondents would trust any country to store their data, indicating too many employees simply don’t pay enough attention to where their work data is held.”

Categories
Data Protection Europe GDPR In the News Legal & Compliance Strategy and Management UK

EU: May 25 2018 is data protection rule implementation date

eu-yet-againAlthough the data protection reforms have already been passed, the date has only just been released following the GDPR’s publication in the EU Official Journal.

The move comes as the Information Commissioner’s Office has revealed it will be publishing GDPR compliance guidance in stages over the two-year implementation period – rather than as a single document – with each piece of guidance addressing a specific topic.

DMA group chief executive Chris Combemale (pictured) said: “Data is at the heart of the modern economy, so as an industry we must be responsible for our actions when handling consumer data and create new frameworks that fit with the GDPR over the next 24 months.DMA group chief executive Chris Combemale

“The new legislation will not only help protect the consumer, but also safeguard brands’ own reputations by ensuring their customers are at the heart of everything they do. The starting pistol has now fired and the two-year countdown has begun, but successful businesses will be those that treat this time as a full distance race rather than a last minute sprint.”

The ICO has also confirmed that the EU plans to have conducted its review into the ePrivacy Directive within the two-year implementation period for the GDPR, although many have described this as “ambitious”.

The Commission has launched a consultation on the current text of the Directive, as well as possible changes to the existing legal framework to make sure it is up to date with the new challenges of the digital area.

The Directive was last updated in 2009 to provide clearer rules on customers’ rights to privacy. In particular, new requirements were introduced such as on “cookies” and on personal data breaches.

Categories
CRM Data Driven Channels In the News UK

Waitrose boosts CRM with instore targeting plan

myWaitroseWorking alongside the MyWaitrose programme, Ecrebo’s marketing platform will allow Waitrose to send targeted offers and messages to its customers, based on the products they have bought.

The offers will be handed to customers instantly at the till via coupons printed alongside their receipts.

Waitrose said the technology will complement and extend the channels through which it talks to customers, including its loyalty scheme.

Offers and rewards in CRM strategy

As well as providing shoppers with money-off rewards tailored to their shopping habits, Ecrebo’s platform will give consumers offers within new and relevant product categories and provide them with recipe suggestions.

The partnership, which will form part of Waitrose’s CRM programme, follows a successful trial during 2015.

Waitrose customer loyalty manager Sam Winterson said: “Rolling out Ecrebo goes down as one of our smoothest IT implementations to date. We’ve been particularly impressed with the instant flexibility of the software which allows us to deploy or change promotions in a matter of minutes.”