AI

Privacy data management innovations reduce risk, create new revenue channels

Comment

matejmo
Image Credits: matejmo (opens in a new window) / Getty Images

Mark Settle

Contributor

Mark Settle is a seven-time CIO, three-time CIO 100 award winner and two-time book author. His most recent book is “Truth from the Valley: A Practical Primer on IT Management for the Next Decade.”

More posts from Mark Settle

Privacy data mismanagement is a lurking liability within every commercial enterprise. The very definition of privacy data is evolving over time and has been broadened to include information concerning an individual’s health, wealth, college grades, geolocation and web surfing behaviors. Regulations are proliferating at state, national and international levels that seek to define privacy data and establish controls governing its maintenance and use.

Existing regulations are relatively new and are being translated into operational business practices through a series of judicial challenges that are currently in progress, adding to the confusion regarding proper data handling procedures. In this confusing and sometimes chaotic environment, the privacy risks faced by almost every corporation are frequently ambiguous, constantly changing and continually expanding.

Conventional information security (infosec) tools are designed to prevent the inadvertent loss or intentional theft of sensitive information. They are not sufficient to prevent the mismanagement of privacy data. Privacy safeguards not only need to prevent loss or theft but they must also prevent the inappropriate exposure or unauthorized usage of such data, even when no loss or breach has occurred. A new generation of infosec tools is needed to address the unique risks associated with the management of privacy data.

The first wave of innovation

A variety of privacy-focused security tools emerged over the past few years, triggered in part by the introduction of GDPR (General Data Protection Regulation) within the European Union in 2018. New capabilities introduced by this first wave of innovation were focused in the following three areas:

Data discovery, classification and cataloging. Modern enterprises collect a wide variety of personal information from customers, business partners and employees at different times for different purposes with different IT systems. This data is frequently disseminated throughout a company’s application portfolio via APIs, collaboration tools, automation bots and wholesale replication. Maintaining an accurate catalog of the location of such data is a major challenge and a perpetual activity. BigID, DataGuise and Integris Software have gained prominence as popular solutions for data discovery. Collibra and Alation are leaders in providing complementary capabilities for data cataloging.

Consent management. Individuals are commonly presented with privacy statements describing the intended use and safeguards that will be employed in handling the personal data they supply to corporations. They consent to these statements — either explicitly or implicitly — at the time such data is initially collected. Osano, Transcend.io and DataGrail.io specialize in the management of consent agreements and the enforcement of their terms. These tools enable individuals to exercise their consensual data rights, such as the right to view, edit or delete personal information they’ve provided in the past.

Privacy Operations. PrivacyOps platforms perform multiple functions, either inherently or through integrations with other tools. These platforms typically possess some combination of data discovery, cataloging and access control capabilities. They are frequently used to manage consent privileges, regulatory controls and privacy incidents. They furnish the evidence needed to achieve auditable compliance with relevant privacy regulations. OneTrust, TrustArc, Securiti.ai and Wirewheel are leading PrivacyOps vendors.

The next wave of innovation

The next generation of privacy management tools will build upon the capabilities referenced above and focus on the following functional areas. Early entrants already exist in some of these areas but additional investment and innovation is needed.

Data usage monitoring. As indicated above, privacy security tools have a higher standard of success than conventional infosec tools because they need to prevent the usage of personal data in ways that were never prescribed or implied by the consent agreements that were used to collect such data in the first place. The usage provisions of most consent agreements are too generalized to be translated into an exhaustive set of explicit use cases that can be used to detect inappropriate usage.

This is an area where the application of machine learning and artificial intelligence techniques to identify anomalous usage patterns could pay major dividends. Early detection of new, novel or suspicious data flows based upon departures from past behavior would materially improve a company’s ability to deter misuse. In much the same way that conventional Security Incident and Event Management (SIEM) tools were developed to provide early warning of security intrusions and exfiltration events, a new generation of Privacy Incident and Event Management (PIEM) tools are needed to detect seemingly benign data flows that violate the terms of usage that were guaranteed to the personal data provider. New usage insights could potentially be provided by API management platforms with more granular data inspection capabilities. Deeper insight into the delegation and usage of fine-grained end user authentication privileges could be a useful means of policing inappropriate data flows as well.

Self-service rights management. In reality, consumers rarely read or understand the rights they’ve surrendered or retained when they provide personal information to a commercial business. They simply don’t have the time, interest or knowledge to comprehend the terms or implications of the consent agreements they’ve accepted. Any technology that can provide individuals with a deeper understanding of the rights they’ve retained; the ability to exercise those rights directly without the facilitation of an intermediary agent; comparative insight into the relative stringency or laxness of the safeguards guaranteed by different agreements; or operational insight into the implementation or effectiveness of such safeguards would be hugely welcomed by most individuals. Information of this nature could be used to construct privacy scores for corporations that consumers could use to protect their personal data in much the same way that corporations use the credit scores of their customers to protect their profits.

Sophisticated self-service tools will also pay dividends for corporations by enabling them to cope with the continual expansion of data provider rights without expanding the administrative staff required to fulfill individual requests for data access, viewing, editing and deletion.

Application development tools. Privacy by design refers to the construction of IT systems using a set of architectural principles and associated business practices that automatically protect personal data from its point of collection to its point of destruction with no action required on the part of the individual providing such data. New development tools are needed to incorporate privacy-related features in the construction of applications and systems that adhere to these principles. Privacy-specific development tools such as programming kits, software widgets and API services could potentially be used to automate the maintenance of privacy data catalogs, cleanse and normalize data collected by different systems, encrypt and obfuscate specific data types, manage data rights and fulfill the requests of data providers.

Early entrants in this space are emerging. Ethyca currently offers developers a variety of data discovery, viewing, editing and deletion services that can be used to customize the way individuals interact with their personal data while navigating a consumer website or e-commerce platform. Skyflow and Evervault provide storage as a service capabilities that automate the obfuscation of privacy data. Additional tools for data modeling and provisioning would be valuable additions to this embryonic engineering toolkit.

Risk reduction or revenue opportunity?

The current and future capabilities listed above can go a long way toward reducing the business risks associated with the ever-expanding and sometimes chaotic privacy landscape confronting every enterprise. Enlightened companies may consider this landscape to be as much of a business opportunity as it is a risk. Most B2C companies have spent the last five years digitally transforming the online experiences of their customers, making online interactions more substantive, personalized and engaging.

During the next five years, B2C companies that provide their customers with a superior privacy experience are highly likely to gain a competitive edge. Investments in privacy tools and management practices now are almost certain to deliver major business dividends in the future.

More TechCrunch

Ahead of the AI safety summit kicking off in Seoul, South Korea later this week, its co-host the United Kingdom is expanding its own efforts in the field. The AI…

UK opens office in San Francisco to tackle AI risk

Companies are always looking for an edge, and searching for ways to encourage their employees to innovate. One way to do that is by running an internal hackathon around a…

Why companies are turning to internal hackathons

Featured Article

I’m rooting for Melinda French Gates to fix tech’s broken ‘brilliant jerk’ culture

Women in tech still face a shocking level of mistreatment at work. Melinda French Gates is one of the few working to change that.

13 hours ago
I’m rooting for Melinda French Gates to fix tech’s  broken ‘brilliant jerk’ culture

Blue Origin has successfully completed its NS-25 mission, resuming crewed flights for the first time in nearly two years. The mission brought six tourist crew members to the edge of…

Blue Origin successfully launches its first crewed mission since 2022

Creative Artists Agency (CAA), one of the top entertainment and sports talent agencies, is hoping to be at the forefront of AI protection services for celebrities in Hollywood. With many…

Hollywood agency CAA aims to help stars manage their own AI likenesses

Expedia says Rathi Murthy and Sreenivas Rachamadugu, respectively its CTO and senior vice president of core services product & engineering, are no longer employed at the travel booking company. In…

Expedia says two execs dismissed after ‘violation of company policy’

Welcome back to TechCrunch’s Week in Review. This week had two major events from OpenAI and Google. OpenAI’s spring update event saw the reveal of its new model, GPT-4o, which…

OpenAI and Google lay out their competing AI visions

When Jeffrey Wang posted to X asking if anyone wanted to go in on an order of fancy-but-affordable office nap pods, he didn’t expect the post to go viral.

With AI startups booming, nap pods and Silicon Valley hustle culture are back

OpenAI’s Superalignment team, responsible for developing ways to govern and steer “superintelligent” AI systems, was promised 20% of the company’s compute resources, according to a person from that team. But…

OpenAI created a team to control ‘superintelligent’ AI — then let it wither, source says

A new crop of early-stage startups — along with some recent VC investments — illustrates a niche emerging in the autonomous vehicle technology sector. Unlike the companies bringing robotaxis to…

VCs and the military are fueling self-driving startups that don’t need roads

When the founders of Sagetap, Sahil Khanna and Kevin Hughes, started working at early-stage enterprise software startups, they were surprised to find that the companies they worked at were trying…

Deal Dive: Sagetap looks to bring enterprise software sales into the 21st century

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI moves away from safety

After Apple loosened its App Store guidelines to permit game emulators, the retro game emulator Delta — an app 10 years in the making — hit the top of the…

Adobe comes after indie game emulator Delta for copying its logo

Meta is once again taking on its competitors by developing a feature that borrows concepts from others — in this case, BeReal and Snapchat. The company is developing a feature…

Meta’s latest experiment borrows from BeReal’s and Snapchat’s core ideas

Welcome to Startups Weekly! We’ve been drowning in AI news this week, with Google’s I/O setting the pace. And Elon Musk rages against the machine.

Startups Weekly: It’s the dawning of the age of AI — plus,  Musk is raging against the machine

IndieBio’s Bay Area incubator is about to debut its 15th cohort of biotech startups. We took special note of a few, which were making some major, bordering on ludicrous, claims…

IndieBio’s SF incubator lineup is making some wild biotech promises

YouTube TV has announced that its multiview feature for watching four streams at once is now available on Android phones and tablets. The Android launch comes two months after YouTube…

YouTube TV’s ‘multiview’ feature is now available on Android phones and tablets

Featured Article

Two Santa Cruz students uncover security bug that could let millions do their laundry for free

CSC ServiceWorks provides laundry machines to thousands of residential homes and universities, but the company ignored requests to fix a security bug.

3 days ago
Two Santa Cruz students uncover security bug that could let millions do their laundry for free

TechCrunch Disrupt 2024 is just around the corner, and the buzz is palpable. But what if we told you there’s a chance for you to not just attend, but also…

Harness the TechCrunch Effect: Host a Side Event at Disrupt 2024

Decks are all about telling a compelling story and Goodcarbon does a good job on that front. But there’s important information missing too.

Pitch Deck Teardown: Goodcarbon’s $5.5M seed deck

Slack is making it difficult for its customers if they want the company to stop using its data for model training.

Slack under attack over sneaky AI training policy

A Texas-based company that provides health insurance and benefit plans disclosed a data breach affecting almost 2.5 million people, some of whom had their Social Security number stolen. WebTPA said…

Healthcare company WebTPA discloses breach affecting 2.5 million people

Featured Article

Microsoft dodges UK antitrust scrutiny over its Mistral AI stake

Microsoft won’t be facing antitrust scrutiny in the U.K. over its recent investment into French AI startup Mistral AI.

3 days ago
Microsoft dodges UK antitrust scrutiny over its Mistral AI stake

Ember has partnered with HSBC in the U.K. so that the bank’s business customers can access Ember’s services from their online accounts.

Embedded finance is still trendy as accounting automation startup Ember partners with HSBC UK

Kudos uses AI to figure out consumer spending habits so it can then provide more personalized financial advice, like maximizing rewards and utilizing credit effectively.

Kudos lands $10M for an AI smart wallet that picks the best credit card for purchases

The EU’s warning comes after Microsoft failed to respond to a legally binding request for information that focused on its generative AI tools.

EU warns Microsoft it could be fined billions over missing GenAI risk info

The prospects for troubled banking-as-a-service startup Synapse have gone from bad to worse this week after a United States Trustee filed an emergency motion on Wednesday.  The trustee is asking…

A US Trustee wants troubled fintech Synapse to be liquidated via Chapter 7 bankruptcy, cites ‘gross mismanagement’

U.K.-based Seraphim Space is spinning up its 13th accelerator program, with nine participating companies working on a range of tech from propulsion to in-space manufacturing and space situational awareness. The…

Seraphim’s latest space accelerator welcomes nine companies

OpenAI has reached a deal with Reddit to use the social news site’s data for training AI models. In a blog post on OpenAI’s press relations site, the company said…

OpenAI inks deal to train AI on Reddit data

X users will now be able to discover posts from new Communities that are trending directly from an Explore tab within the section.

X pushes more users to Communities