Bangkok Post

EU rules spark internet data revolution

- LEONID BERSHIDSKY Leonid Bershidsky is a Bloomberg View columnist based in Berlin.

Different branches of the European Union have agreed on the shape of the EU’s new data privacy law, which means it is likely to be passed early in 2016 and fully enacted within two years. This is not one of those arcane legal documents that have little effect on people’s everyday lives. The new rules will drasticall­y change how companies use people’s data and perhaps reshape data-based businesses such as advertisin­g and online retail.

The idea of the new regulation is to establish the same data privacy rules across the EU — something the European Commission says will result in savings of €2.3 billion (90 billion baht) a year for businesses — but also to hand to users full control of their personal data, which the EU defines broadly as “any informatio­n relating to a data subject”, or natural person. This means companies will have to explain exactly what informatio­n they are collecting, for what purposes and how long it will be retained.

They will be forced to disclose all collected informatio­n to the user — something Austrian law student Max Schrems expended a lot of effort extracting from Facebook, which led to the overruling by the European Court of Justice, of the “safe harbour” data transfer deal between Europe and the US in October. Companies will also have to erase data at the users’ request if they have no legitimate reason for keeping it — an extension of the difficultt­o-enforce “right to be forgotten”.

Perhaps more importantl­y, companies will have to comply with the principles of “privacy by design” and “privacy by default”, meaning the default settings of any service must ensure that as few data as possible are collected and retained. How this will work exactly are left to the European Commission to spell out, but the very principles involved mean that tech firms will have to rethink their interactio­n with customers and perhaps their entire business models. Otherwise, they will face fines of up to 4% of their global sales.

US internet giants will need to make adjustment­s if they want to keep operating in Europe. A 2013 paper by Ira Rubinstein and Nathaniel Good provides some examples of the kind of changes that may be required. Gmail, Google’s free email service, automatica­lly scans users’ messages for keywords provided by advertiser­s, which helps target ads to these specific users. To comply with “Privacy by Design”, Mr Rubinstein and Mr Good wrote, it might have told users clearly (and not in some obscure passage of its rules) what informatio­n it would be collected, but that wouldn’t have been enough: “Google might have considered a simultaneo­us release of both an ad-supported free web mail service and an ad- free paid version” to give users a choice. I know I would rather pay for Gmail than have Google scan my messages for any purpose, but I don’t have that opportunit­y now. The new European regulation may force the company to provide it.

Similarly, Google and Facebook might be forced to give their users the right to opt out of data collection for advertisin­g purposes. That goes beyond all the changes the companies made to their privacy policies in recent years, mostly bowing to regulatory pressures and trying to minimise legal costs. It also alters the premise on which these businesses are based: that if they provide a free service, they’re entitled to whatever users say about themselves, and whatever their internet behaviour says about them.

Some US internet giants — Amazon is an important example — pride themselves on their ability to sell products based on a user’s known preference­s. But do users want to give companies this edge? According to a Eurobarome­ter survey taken in July, 2015, 53% of European internet users are uncomforta­ble with collection of their data to tailor advertisem­ents. Once the new European rules transfer control of their informatio­n to users, these people are likely to limit their data disclosure. Google and Facebook, among other companies for which targeted advertisin­g is the source of nearly all revenues, will have to make do with whatever they collect from the 42% of users who don’t mind providing their data for the purpose.

This might actually be good for these tech firms and for their advertiser­s. Now, people trying to protect their privacy often lie on registrati­on questionna­ires, providing false names and addresses or creating special accounts for different purposes. I do that, too: Being honest with everyone who asks for personal data often means being pestered by annoying emails and ads “targeted” on the basis of products and brands mentioned in personal messages — hardly an indication of a desire to buy something. The “big data” collected from unwilling users is thus often bad data. Clear, effective privacy rules could make the $16.6 billion (600 billion baht) spent on big data infrastruc­ture, software and services last year more efficient.

The reduced targeting opportunit­ies, however, might mean lower advertisin­g prices for customers. If internet companies were entirely honest with their paying clients, they would charge less even now.

Treating data about a person as that person’s property is likely to complicate the work of journalist­s who are after data, say, on corrupt officials’ offshore companies and property. Under the current draft of the EU regulation, it will be possible to withhold the data at least temporaril­y, while the company evaluates the “owner’s” request to have it erased. With the threat of big fines hanging over them for withholdin­g the “right to be forgotten”, internet firms will be tempted to err on the side of caution.

Otherwise, the new rules push internet companies in the direction of greater honesty with their users and clients and ultimately with themselves. It’s time the industry realised the limitation­s of the advertisin­g model, which sustains some of its most visible players: It’s often based on sleight of hand rather than honest data collection.

Besides, it makes perfect sense to curb official agencies’ interest in the personal data people make available online. The US Department of Homeland Security recently announced its intention to scan social network posts to aid visa decisions. The motive is to keep out people who support terrorism, but who knows what might trigger suspicion or set off alarms in the software they may use. Social network users should have the right to ban such use of their data.

Once the new regulation­s are approved, tech companies will probably use their significan­t lobbying power to make specific rules, to be set by the European Commission, more lenient and less disruptive to their business. The less success they have the better, not just for Europeans but for all internet users.

The motive is to keep out people who support terrorism, but who knows what might trigger suspicion.

 ?? REUTERS ?? People are silhouette­d as they pose with mobile devices in front of a screen projected with a Facebook logo. The European Union has agreed on the shape of the EU’s new data privacy law.
REUTERS People are silhouette­d as they pose with mobile devices in front of a screen projected with a Facebook logo. The European Union has agreed on the shape of the EU’s new data privacy law.

Newspapers in English

Newspapers from Thailand