Showing posts with label consumer privacy. Show all posts
Showing posts with label consumer privacy. Show all posts

Thursday, May 8, 2008

Direct Marketing Dilema: Balancing Privacy and Targeting


This morning, two completely different articles from DM News caught my eye and got me thinking.

The first: CDD pushes FTC on privacy in mobile
"The Center for Digital Democracy (CDD) and the US Public Interest Research Group are taking on the Federal Trade Commission to address privacy issues in mobile marketing."
Apparently, the CDD wants the FTC to address privacy in mobile marketing, including regulating profiling and targeting.
"The new complaint addresses marketing practices from a technological level. It will examine Enpocket's Personalization Engine, a behavioral technology for the mobile device. It will also look at technologies from other companies which profile gender, age, language, income, education, country, state, ZIP/postal code, GPS coordinates, behaviors and in the context of voicemail and text messages."
When I take off my direct marketing hat and think about mobile marketing from a consumers' perspective, it can be a little frightening. Marketers can know where I am at all times. Essentially, they can track me. It does seem like an invasion of my privacy...

And, the second article: Keys to trigger-based e-mail marketing. The article discusses how marketers can take advantage of internal or external triggers to deliver the exact right message when that customer is ripe to purchase your product.
"Imagine having information regarding your customers' life-changing events, such as the purchase of a home or opening of a checking account, at your fingertips, and the dexterity to send out the right offer at precisely the right time.

Well, there's no need to imagine.

Trigger-based marketing programs are enabling e-mail marketers to communicate insightful offers in a timely fashion to both customers and prospects, yielding as much as a 400 percent improvement in response rates without costing millions of dollars."
Of course, this makes sense to us (and, in fact, we've implemented some highly effective trigger programs for our clients). But, many consumers may be creeped out thinking about the fact that their data is out there for marketers to exploit.

It's a real concern. As direct marketers, we really do need to balance consumer privacy issues with our own desires to produce effective, money-generating campaigns.

Yet, it can be done, and in my opinion, if it's done with transparency and if we communicate effectively with the customer or prospect, and ALWAYS keep their needs in mind, then we all win.

I like to use Amazon as an example. When they first started data mining and modeling to predict which products an individual would be most interested in, based on what they had purchased in the past, I remember people being irked by it. Why is this e-tailer keeping track of what I'm buying and where I'm browsing? Yet, when consumers started actually being interested in the Amazon-generated recommendations, and when we started counting on them, that's when perceptions changed.

Now, we expect our e-tailers to know about us and to treat us like the good customers we are. If they can offer suggestions, or discounts highly pertinent to us, so much the better. This builds loyalty and we keep spending our money there. The creep-factor of them knowing too much about us has been overwhelmed by the benefits we receive from them knowing a lot about us.

In my opinion, here's why it worked for Amazon:
  1. Amazon never tried to keep what they were doing a secret. They came right out and said something like: based on your past purchases, we thought you might also enjoy X and Y.
  2. The second reason this works for them: they did it right (their technology worked) and they brought real value to their customers.
Remember this each and every time you are mining customer data, or purchasing external data to mine. Ask yourself if your campaign is not only benefiting you as a marketer, but is your program benefiting your customer?

Bringing this back around to the original article about privacy concerns in the Mobile Marketing Industry--If people start receiving, for example, meaningful coupons on their cell phone, when they're shopping at that store, this might overwhelm the creep factor. But, let me tell you, those coupons better bring real value to the customer and the technology better be flawless. Or else, you're gonna have some mighty irritated customers. And, they'll be right there in your store, in your face, angry and ready to let someone have it. Yikes!

Thinking of the customer first is what is going to keep the creep-factor at bay.

Tuesday, January 15, 2008

Ten Database Security Tips


As a direct marketer, I hear about database breaches and immediately think "BIG BUSINESS". I envision large financial institutions that collect data on millions of customers and imagine a scenario where stolen data results in large-scale lawsuits and identity theft mayhem. But, honestly, it's just as important (and perhaps even more important) for smaller businesses to ensure that their customer data is secure.

This article brings that point home: 10 Database Security Tips For Smaller Businesses

While storing sensitive or regulated information puts any company at risk, smaller businesses may have more to lose. "For small businesses, the impact of data loss is much higher, because they have less infrastructure," says Mark Kraynak, senior director of strategic marketing for Imperva. "They probably don't have backups, and they don't have the organizational wherewithal or response teams to handle a big public breach, or getting sued."

The article then proceeds to share ten solid tips that smaller businesses can follow to help keep their customer data secure.

I urge you to read the whole article, but I thought the following tips were especially solid.

Tip 5: Restrict Database Access -- both to the production database, as well as underlying hardware -- on a need-to-know basis.

Tip 6: Prohibit Wholesale Database Copying. A production database typically has a designated owner or gatekeeper. Yet who watches a database after it's been copied?

We see copies made and distributed all the time in the world of direct marketing. Someone requests a copy of the customer base to be used, for example, as a suppression file for an upcoming prospect mailing. The customer list is sent to an external data processing firm, perhaps. The campaign is implemented and no one ever thinks about that customer list again. Typically, nothing bad happens, but it takes only one instance of data theft.

We urge you to make sure that you have appropriate non-disclosure agreements in place with anyone who touches your data. Make sure that they specifically talk about how the processor must keep the data secure. That way, if something does happen, the fault will be on your processing vendor, and not on you.

Tip 7: Inventory Existing Databases: Locking down databases out of the box and prohibiting wholesale duplication may sound fine, but what about securing databases and copies that already are at large?

Companies must regularly find and inventory all existing databases. Know that one production database may hide many copies. "Typically, in a lot of businesses, you have the production database, but guess what, that database usually has a lot of copies -- developers have copies, for example -- and many databases correspond and make calls to each other," says Bowker.

Knowing where your data exists is a good thing for many reasons. Namely, if a data breach does occur, you'll be very well-positioned to find out where the theft happened in the first place. You'll also be well-prepared for any subsequent lawsuit showing that your firm has stringent practices in place to prevent data theft. A simple inventory of data assets goes a long way in showing that you do put a value on customer data and that you're serious about protecting it.

Overall, it may be time for firms, small and large alike, to put some serious thought into your database practices. News about a data breach is definitely the type of news we'd like to avoid in 2008!

Wednesday, January 9, 2008

DMA's New Mail Preference Service


It's always bugged me that the Direct Marketing Association charged consumers to put themselves on a Do Not Mail suppression file, used by the industry to scrub lists of people who really don't want to receive direct mail. Yes, the fee was only one small dollar, but this fee rankled consumers who are sick of junk mail. I can't tell you how many articles I've read complaining about it.

And, believe me, direct marketers don't need more bad press...

Well, the DMA announced today that they've not only gotten rid of the $1 fee, but that they've enhanced the service.

DMA Unveils Free Online Service; Enhances DMAChoice to Meet Consumers' Needs for Choice in Catalog Mailings

In a nutshell, along with the elimination of the $1 fee, consumers can now opt-out of mailing lists by individual brand and ask not to receive specific catalogs.

“DMA’s Mail Preference Service, part of DMAChoice, is now the most effective and secure way for consumers to only receive the mail they want and to express their preferences for mailings they do not want — it’s all about relevance,” said DMA President & CEO John A. Greco, Jr."

What do we think of this? It's about time that our industry gives consumers a way to record their choices and preferences in terms of the types of direct mail they want to receive (or the type they really DON'T want). Now, marketers just need to listen and abide by these wishes.

RRW is all about respecting consumers' wishes, and we applaud the DMA for introducing this new service.

Wednesday, September 26, 2007

Another Data Breach...


This time it's at Ameritrade, where 6.3 million customer records were compromised. Yesterday's DM News reported: Ameritrade lost 6.3 million names from database

"TD Ameritrade Holding Corporation, an online brokerage company, said one of its databases was hacked into and the personal information for more than 6.3 million customers was stolen. The company found malicious code in one of its databases."

These data breaches are happening all too often. In July, we posted about a data breach at Fidelity where a disgruntled employee stole over 2 million customer records.

Now, I do realize that it's extremely difficult to stop hackers and bad people (especially in-the-know employees). However, it's so important to the direct marketing industry that we nip this in the bud. If we intend to store customer information, we absolutely better ensure its safety. We need to invest in the right people, technology and practices to make it virtually impossible for the wrong people to access sensitive information.

If we don't do it, and do it now, I guarantee that some ambitious legislators will get involved. And, I think we all would agree that we don't need to work within more rules and legislation...

Monday, September 10, 2007

More on Privacy


On Friday we posted about what the marketing world may look like in 2020, specifically how our privacy will be impacted. Interesting stuff...

Then today I came across this article that specifically addresses the wealth of information that consumers are voluntarily providing when they participate in social sites, like Facebook. From CNN, the article is titled: The sinister side of social networking.

The article discusses how consumers need to be especially careful about what we publish about ourselves. It gives examples of companies that are scouring the web for what they term "digital litter"--that is the personal tidbits of information that may be useful for direct marketers or thieves out to steal your identity.

The article pointed out that Facebook will soon be changing, and not in a way that will protect our privacy. "A soon to be added public search feature on Facebook will mean that user profiles can be found through search engines such as Yahoo and Google."

"What was once a cozy world between friends (you had to join Facebook before you could access such information) is now available to anyone.

Facebook hopes the move will drive more users to the site and boost advertising revenues, which analysts believe are being under-realized.

Technology expert Om Malik wrote in his blog this week: "This move transforms Facebook from being a social network to being a quasi-White Pages of the Web."

Facebook's public search feature has raised eyebrows among security experts. As users have to "opt out" of the service rather than opt in, it could mean up to 39 million profiles becoming viewable when the service goes live."

Although I normally see articles like this one as ways to frighten consumers and point the fingers at nosy direct marketers who are out to collect data on everyone, I do agree with the article that we need to understand and do all we can to protect our privacy by being careful about revealing our personal information.

And, I agree with the tips included within the article on steps you can take to safeguard your private information:

Equifax Top Tips for Using Social Network Sites:

• Don't include common verification such as your date of birth or your mothers maiden name

• Set up privacy on your profile so only close friends can view your information

• If you are going on holiday or you will be left in your home alone, don't put it on your site. This could leave you vulnerable to break ins

• Potential partners and employers are often searching names on these sites. Don't put anything on your site which could ruin your chances of a new job or boyfriend/girlfriend

• Be wary of anyone you meet on these sites. The photo may be deceptive and they may have different intentions

Seems like common sense, no? But, pretty important as data collection technology evolves and as social networking expands.

Friday, September 7, 2007

Privacy (or lack of it) in the Future


I'm a sucker for a good futurist. Isn't it fun to theorize about what our world will look like in 10, 15, 100+ years? I truly enjoy hearing expert takes on the future of marketing, the future of commerce, etc., etc.

That's why I was pleased to see this commentary on one man's vision of the future of consumer privacy. From DM News, check out this article written by Robert Gellman (a privacy consultant out of Washington DC), titled: "Looking out for data surveillance predictions for 2020."

Some of Gellman's predictions are fairly predictable--i.e.: that we'll be a cashless society and that all transactions will be electronic (he calls this a "penniless marketplace"--thought that was cute).

Other predictions are a tad more dire. For example, he predicts that every auto will be equipped with a tracking device which will, for example, not allow pedophiles to go near schools. This device will also record where we go and be able to issue tickets when we break a traffic rule... Interesting.

And, here's what he thinks about computing: "Very personalized PC. Every computer will have a static IP address. No one will be able to operate a computer without registering through a token, fingerprint or other identification device. All e-mail will be stored permanently, and records of other network activity, including searching and transactions, will also be retained. Stolen computers will be a hot black market item for criminals who will use them to avoid accountability for online actions."

And, of course, he has a take on direct marketing: "Direct marketing activities will be positively affected by the availability of more personal information. However, public aversion to spam, telephone calls and postal mail will make it harder to exploit the information by traditional means. Many free Internet services will remain free only to those who do not block ads."

I believe that the future of direct marketing will include a complete trend toward opt-in (it's already heading in that direction). Consumers, now empowered by their ability to get the information they need on their own, seek out companies to serve them. They look for what they want and then they buy what they want. It will get tougher and tougher to get consumers to respond to unsolicited marketing messages.

I'd love to hear your thoughts on the future, be it marketing, privacy, whatever.

Wednesday, August 15, 2007

Yet Another Reason to Hate the DMV...


I truly couldn't believe this news article: Pennsylvania Using Confidential DMV Database for its Own Marketing Purposes.

The article reports that "The Pennsylvania Department of Transportation (PennDOT) is combing through confidential Department of Motor Vehicle (DMV) database records so that it can mail targeted job offers to holders of commercial drivers' licenses."

Wow.

Talk about a misuse of power, coupled with an invasion of privacy. Consumers expect that their drivers license information will remain confidential. And, why should the DMV have the unfair advantage of using this private data to recruit truck drivers? Private firms don't get to enjoy this privilege of mis-using personal data. And, if they do (through data theft or some other unfair practice), they are definitely penalized for it--they get a big fine or they go to jail.

Let's hope that the DMV stops this practice immediately. Or, at a minimum, that they consider selling their data to the dm industry. I could make a fortune selling Jenny Craig or Weightwatchers a mailing list of overweight people, of course, as identified on their drivers license.... Hmmm, note to self: Make a call to PennDot.

Just kidding, of course :)

Tuesday, July 31, 2007

More on Consumer Privacy

It's always interesting to read how other countries are handling the same concerns that we face here in the US. Take, for instance, this article from The Toronto Star, titled: Protecting privacy makes business sense.

The article discusses how marketers "collect, use and share a consumer's personal information in the marketplace". It talks about how recent data breaches and the US legislation around privacy issues are fueling increased public scrutiny of this topic. The article makes the right conclusion and recommendation to marketers: "Companies that people see as trustworthy will be rewarded with a higher degree of customer loyalty. For this reason, consumer privacy and good data handling practices make good business sense."

All good info. But, the primary reason why I'm talking about this particular article today is because of one sentence kind of buried within the article that talks about Canadian law: "Canada's federal privacy law quite rightly gives individuals the right to control the collection, use and disclosure of their personal information. And consumers are demanding the ability to exercise that right."

So, what does this mean exactly? How does a consumer get to control the use of their public data, for example? If a mailing list compiler takes a name and phone number from a phone book, does that compiler have to offer a mechanism to the consumer to change/add/delete his info? Can that consumer control which marketers have access to his name and address? How is this regulated and how does it work?

Prior to starting my own consulting business, I worked for several of the leading data collectors/compilers such as Experian and InfoUSA. I know that it would be a logistical nightmare to let people control data that is compiled about them. It's hard enough to do this in a regulated environment (i.e.: credit bureaus are required to respond to consumer corrections about their credit reports, and rightly so). In an unregulated environment (think of all the mailing lists out there), it would be madness. But, it might be the right thing for the consumer.

I'd love to hear from Canadian direct marketers who may be dealing with this federal privacy law today, or making plans to comply with the finer points of the law tomorrow.

Consumer privacy issues are only growing. We need to face them head-on and anticipate how to keep data secure AND give control back to the consumer.

Wednesday, July 25, 2007

Protecting your Identity


As the days, months and years pass, and as consumer privacy and identity protection become pressing concerns to consumers, Direct Marketers have less and less data available to them. And, that's a good thing, I believe. We'll just have to learn to be smarter.

From today's DM News: House passes Senate SSN bill

"If the bill, HR 3046, is passed by the Senate, companies would be restricted in the ways they could use Social Security numbers.

“Federal, state and local governments would be prohibited from selling SSNs [and] displaying SSNs to the general public, including on the Internet,” the bill says. “[They would also be prohibited from] displaying SSNs on checks issued for payment and accompanying documents.”

The Direct Marketing Association expressed concern over the bill’s language in a letter to the House Ways and Means Committee.

The DMA was looking for a specific addition to the bill that would say it is acceptable for marketers and companies to use Social Security numbers as long as it’s for legitimate purposes. The DMA seeks an exemption in the bill that would preserve critical business-to-business uses of the numbers for fraud-detection purposes."

Let's assume that this bill will pass (and it really should, right?). Financial marketers will simply need to be more clever in their fight against fraud, and in their abilities to make appropriate financial offers to their customers and prospects. For example, in the pre-screen arena (where marketers access consumer credit reports to extend the appropriate credit or loan offer to a consumer), the credit bureaus will need to figure out accurate matching without the use of SSNs (and they're already there, I believe).

We cannot fight the fact that consumers are fed up with their personal information being available to hackers or other bad people. Direct marketers need to go the extra mile to develop systems and processes that protect their customer data. We need to do this BEFORE legislation happens.

It's not enough for us to reluctantly comply with new regs. As an industry with intelligent data processing tools and a long history of working with data and databases, we need to innovate NOW in the areas of consumer privacy and data security.

I'd love to hear stories of how marketers are addressing the very real needs to protect consumer information. Horror stories of how they aren't are welcome, too.

Friday, July 6, 2007

Data Breach at Fidelity

Sadly, the few times that our industry (direct marketing, data, lists) makes the news is when something bad happens. See "Direct Magazine's" article: Two-Million-Plus Names Stolen Data from Fidelity National Information Services.

Apparently a disgruntled (or just greedy) database admin decided that he, too, could get into the data business. He took a copy of 2.2 million Fidelity customers and sold the file to a direct marketing company/list broker. He was caught, fired and the data was recovered.

The original story reported over the last couple of days was that sensitive financial info was taken (not simply name and address). Did this ever make the bloggers fume, lashing out at everyone from the government to big business to (of course) junk mailers. Now it turns out that the stolen data only consisted of basic name/address info (still not a good thing, of course).

But the message I saw all over the Internet was that no one should EVER give their name and address out, or something really bad would happen to you. Identity theft, fraud, spying, etc. etc. Of course, all of these things CAN happen in today's information-rich times.

But, it's much more likely, for example, that the waiter who takes your credit card for dinner will sell that info to his friend than it is that a mail order company will jeopardize your private information. The mail order company understands that they need customers to stay in business...

Regardless, I believe that in these times, the onus is on direct marketers to be extremely sensitive to customer privacy. We need to make sure that each time we collect and use a piece of data that there is a valid benefit to the consumer. We shouldn't collect and store data just because we CAN collect that data.

And, as consumers, we should guard our personal data. We all know not to carry around our Social Security Cards. We make sure that the website we're ordering from is a reputable one, before we ever give out payment. We're onto the phishing scams and would never send any money to a strange African country, regardless of the huge payout promised.

But, there are times when it's very much in our best interest for businesses to understand things about us. When an airline remembers that you prefer an aisle seat, that's a good thing, right? Or, if your favorite restaurant sends you a free birthday dinner coupon, you're happy, correct?

Again, it all comes down to the fact that the stored data absolutely must bring value to the consumer or it needs to be deleted from the database. Yes, it is that simple :)