Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

0 Privacy: Does Anybody Care?

To paraphrase HL Mencken, no one ever went broke underestimating the American public's commitment to privacy. "Quit Facebook Day" reportedly generated 31,000 account closings, compared with the roughly 500,000 new accounts that Facebook adds each day.

This lack of interest in privacy is a tremendous pity, because privacy violations can cause many types of real harm:

- identity theft
- physical violations including stalking and burglary when people are known to be out
- unjustified commercial treatment (e.g. denial of credit or employment) based on irrelevant or incorrect information
- unjustified government activity (e.g., placement on a No Fly list) based on irrelevant or incorrect information

Ironically, such problems seem to generate less public concern than techniques such as "behavioral targeting", even though the consequence of that is...um...receiving a relevant advertisement. I fully understand the real issue is people feel creepy to know that someone is sort-of watching them. But it's probably a good thing to remind them because the watching will continue whether behavioral targeting is regulated or not.

As the Facebook example shows, most people really don't care enough about privacy to protect it at the cost of other benefits, even minor ones like participating in Facebook. Similarly, many Americans seem downright eager to sacrifice their privacy from government surveillance in the name of national security.

The pity is that it's not an either/or choice. In many cases, technology can be designed to preserve privacy and still give the desired benefits. As a good example of what privacy-consciousness looks like when someone really cares, consider how the gun buyers are protected: gun dealers must check buyers' names against a database of felons, but the buyers' names are erased after a few days. (Of course, loopholes apply to "gun shows" but that's another discussion.) Another example -- never implemented so far as I know -- is that instead of reading drivers license information to prove patrons are old enough to drink, bars could have devices that simply scan the license and flash a green or red light depending on whether the person is old enough.

The point in both cases is that systems can be designed to access and retain the minimum amount of information necessary to fulfill their function. Many behavioral targeting systems already work this way -- capturing relevant data but not the actual identity of an individual. These principles could be applied more broadly and more systematically, but only if the people designing and regulating these systems made them a priority.

In practice it seems that other, less rational approaches are being adopted because they are more popular. To quote Mencken again, “For every problem there is a solution which is simple, clean and wrong.”

Without being excessively cynical, I think it's relevant to point out that privacy doesn't have much of a lobby, at least compared with, say, the National Rifle Association. Businesses want to collect data for marketing purposes. Consumer-friendly government officials are the natural opponents of this collection, but are constrained because many government agencies want the data for their own social and security purposes. The only organized opposition comes from a small set of privacy activists who themselves vary considerably in their priorities and capabilities. This means that, as a marketer, I don't spend much energy worrying about seriously restrictive privacy regulations -- even though I'd actually like to see some intelligent restrictions on data gathering by both business and government.

0 Survey Looks for Hostility to Behavioral Targeting, and Finds It

Summary: a new survey found that most Americans oppose behavior-based Web targeting. The authors clearly had an agenda, but the industry still needs to present its side of the story.

A recent survey conducted by professors by UC/Berkeley and University of Pennsylvania concluded (to quote its full title) that “Contrary to what marketers say, Americans Reject Tailored Advertising and Three Activities That Enable It.” Is it just me, or do I detect a bit of hostility?

The headlined finding of the survey was that 66% of respondents said they did not want Web sites to show ads tailored to their interests. As eMarketer pointed out in its article on the study, this conflicts with other surveys have found consumers receptive to targeted Web ads.

The Berkeley/UPenn study claims it is more accurate because it is the first nationally representative telephone (rather than Internet-based) survey on the topic. I doubt that really had much impact on the results. As a detailed critique by the business-friendly Progress & Freedom Foundation points out, the answers were more likely influenced by the structure of the poll itself, which asked a variety of somewhat tendentious questions leading up to the final answers.

My own critique is that the questions all asked whether people wanted to see tailored ads, not whether they preferred tailored ads vs. non-tailored ads. People may have interpreted the unstated alternative as no advertising at all. In that case, their rejection had less to do with tailoring in particular than with the near-universal dislike of advertising in general.

Still, the answers I found most interesting have received relatively little attention. This was a set of three questions that found:

- 67% of Internet users agree they have “lost all control over how personal information is collected and used by companies”, but

- 58% feel “most businesses handle the personal information they collect about consumers in a proper and confidential way” and

- 54% agree that “existing laws and organizational practices provide a reasonable level of protection for consumer privacy today”.

In other words, people have finally accepted Scott McNealy’s famous advice from 1999: “You have zero privacy anyway. Get over it”.

I’d like to end the story there, if only for artistic reasons. But the survey also asked several questions about consumers’ understanding of current privacy laws, which basically found that most people think they have more protection than they really do. Another series of questions found support for laws giving consumers rights to insist that companies delete their information.

I don’t take the results too seriously because the questions didn’t indicate these would be new laws or balance the laws against reduced free content or the cost of more regulation. But they do suggest that people might support stronger regulation if they understood how poorly they are now protected. So there continues to be a real need for marketers to both do a good job of protecting consumer privacy and of educating the public and legislators about the benefits provided by easy access to consumer information.

0 Department of the Obvious: Anti-Terrorist Data Mining Doesn't Work

I've emerged from the cave where Osama bin Laden and I were working on the new Guide to Demand Generation Systems (oops -- the Osama part was supposed to be secret) and am now catching up with the rest of the world. One news item that caught my attention described a recent National Research Council report that concluded data mining to find terrorists "is neither feasible as an objective nor desirable as a goal of technology development efforts." See "Government report: data mining doesn't work well" from CNET.

The article pretty much speaks for itself and is no surprise to anyone who is even remotely familiar with the actual capabilities of the underlying technology. Sady, this group is a tiny minority while the rest of the world bases its notions of what's possible on movies like Minority Report and Enemy of the State, and TV shows like 24. (Actually, I've never seen 24, so I don't really know what claims it makes for technology.) So even though this is outside the normal range of topics for this blog, it's worth publicizing a bit in the hopes of stimulating a more informed public conversation.