Skip to content

DBAzine.com

Sections
Personal tools
You are here: Home » Blogs » Craig Mullins Blog » Craig Mullins: Perspectives on Database Management » Data Privacy Policies
Who Are You?
I am a:
Mainframe True Believer
Distributed Fast-tracker

[ Results | Polls ]
Votes : 1984
 

Data Privacy Policies Data Privacy Policies

Have you ever read those inserts that your bank, your credit cards, your insurance company, your mutual fund company, and others slip inside your statements and bills?
We all get them. Those inserts in our bills and financial statements printed in small type and written in convoluted English. I have started collecting them – sort of like baseball cards. But I doubt they’ll ever be valuable. They are entertaining, though. And disheartening.

You really should read them. There are all sorts of interesting language written on those little pieces of paper – and some companies are a lot better than others in terms of what their privacy policy promises.

One thing you’ll see in just about every one of these little documents is the phrase “…unless otherwise permitted by law.” So, basically they are telling us this: “We’ll do what we say here unless we can find some law that allows us not to.” Oh great! I guess we all have to read every law on the books before we can trust this policy. I’d feel a lot better if the document had the phrase “…unless otherwise forbidden by law” in it. That way we could (hopefully) feel confident trusting the policy to be as strong as what is actually written there, if not moreso. As it is, we should feel confident that the policy is not anywhere near as strong as what is actually written there until it is proven otherwise. I guess I’m a pessimist, but I think I’m actually more of a realist with the sad state of data security and protection these days.

Hopefully the above statement refers to the more useful and explicit information found in another privacy policy: “For example, federal law permits us to share information about you with consumer reporting agencies, service providers and financial institutions with which we have joint marketing agreements.” At least this company tries to explain their intentions instead of just appending “…unless otherwise permitted by law” all over the place.

Here is another line that I despise from a different privacy policy: “When required by law, we will ask your permission before we share your information for this type of marketing.” The type of marketing referenced here is with “nonaffiliated service providers and joint marketing programs.” So, this policy is basically saying that this company will take your information and share it with anyone they want unless the law forbids it. Oh, it does say that they require the folks they share the data with to “keep our investor information confidential and secure and to use it only as authorized by us.” But I wonder how strict this requirement is? And what is the stated privacy policy of these partners?

Here is a classic taken verbatim right out of one of the privacy policy of a large bank: “Even if you do tell us not to share, we may share other types of information within our family.” So, why would I even waste my time to try to stop you? If this company were honest they would change the name of this policy to the “lack of privacy policy,” because that is what it is.

A better privacy policy would protect their customer’s information much better. If there are specific things that will always be shared these should be explicitly stated and referenced. And it should be clear what is meant.

It is interesting to compare the privacy policies for the same company as (if) they change each year. One trend seems to be the addition of Chief Privacy Officers. This could be a good trend. But I bet the Chief Privacy Officer is more concerned with furthering the interests of the company s/he works for than actually protecting the privacy of the company’s customers. But maybe I’m being a pessimist again.

Our privacy is evaporating. We should try to do as much as we can to stop that evaporation. So should the companies that we do business with. And so should DBAs and data management professionals who deal with corporate data on a daily basis.

© 2006, Mullins Consulting, Inc.

Saturday, March 04, 2006  |  Permalink |  Comments (7)
trackback URL:   http://www.dbazine.com/blogs/blog-cm/craigmullins/blogentry.2006-03-04.7587002706/sbtrackback

Even Uncle Same Not Trusted With Data Privacy

Posted by cmullins at 2006-03-09 01:42 PM
Just a quick note to post this blurb from USA Today, March 6, 2006:

"Most Americans don't trust the government to protect their personal information, says a new survey by research group Ponemon Institute. On average, 46% of people surveyed trust U.S. agencies to guard their data, down from 52% two years ago."

The illusion of data privacy just continues to disappear!

RE: Company Policies?

Posted by howardfci at 2006-03-10 08:32 PM
I'd be very interested to know what percentage of DBA readers' companies secure their data and how they do it. Perhaps DBAZine could hold one of their Polls on this topic?

For example, how many companies keep their customers personal data (financial, medical, whatever) encrypted?

How many companies have policies against keeping query results with such data unencrypted on portable laptops?

How many companies spend the time required to actually manage user ids to sensitive databases (for example, actually deleting old user id's when they are obsolete)?

I've seen a significant shift towards these more secure practices over the past year (given all the attention data theft now receives in the press).

But I also still run into firms that do not even do the minimal to protect personal data. My favorite example is one place I worked at as a contractor -- they kept the request forms for new "user ids" in un-encrypted form on the LAN, accessible to everyone one the floor! It took months for me to convince them to delete my SSN off their open database.
Craig Mullins
Data Management Specialist
Bio & Writings
Subscribe to my blog Subscribe to my blog
« February 2007 »
Su Mo Tu We Th Fr Sa
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28      
 
 

Powered by Plone