• The selected file /tmp/fileHKh3Sz could not be uploaded, because the destination sites/default/files/js/js_126876629c1edb49a4ecc4e796f948f9.js is not properly configured.
  • The selected file /tmp/fileh8Sjbv could not be uploaded, because the destination sites/default/files/js/js_f665294f70a7e34d52750562b76cee11.js is not properly configured.

Information Quality Management

Electronic Privacy Regulations - a mandate for Quality Modelling and Governance

Last month I discussed the need for organisations to step back and think about information and its meaning and purpose in the context of direct marketing suppressions. On the 1st of July the Irish Government enacted its national legislation to give effect to the Electronic Privacy Directive. Unlike the UK there is no moratorium on enforcement. Rather the Irish DPC has opted to enforce but to examine each case on its merits as the application of the legislation rolls out.

One of the interesting sections in the legislation is the definition of Electronic Communications. It is interesting to me as a hybrid lawyer/data guy because of what it requires organisations to do.

 

THINK

Doing it by Design: How thinking about the things can help you build a better suppressions model

Earlier in the week I wrote about the role of Information Governance and Information Quality principles in ensuring that an organisation meets its Data Protection obligations around the management of suppressions so that customers are not contacted in a manner which is unwelcomed or inappropriate.

This Complicated Life

Back in the old days the management of customer marketing preferences was easy. You had either a postal address or a phone number. Direct marketing was largely (if not entirely) about selling to customers. So you'd send out catalogues or brochures about your product or service and hope for the phone to ring with an order.

But, as the pizza parlour example from earlier in the week demonstrates, we now live in a complicated world where individuals have a lot of personal identifying data associated with them. Also, Customer Relationship Management and the way in which organisations interact with their customers has changed very much to a relationship based approach that helps build intimacy and, effectively, raises the barrier to customer churn (because you are in their inbox every week with something new and interesting).

This can create complications, but also it can create opportunities for organisations who have thought about the meaning and purpose of their information, how they can use it to drive value, and have invested in modelling their systems and processes accordingly.

Data Protection & Marketing Suppressions: Act on Fact

One of the areas where Information Quality, Data Governance, and Data Protection overlap significantly, with a big business impact, is the area of managing an individual's preferences for direct marketing.

Before I go any further, I think it is important to clarify what is meant by Direct Marketing in this context. Direct Marketing is a communication targetted to a specific individual by any means of communication such as email, snail mail, SMS, fax, or telephone. It could be argued that it also could include Tweets or contact via social networking.

The diagram opposite shows some of the data that an individual has about themselves that they would potentially be sharing with a service provider, in this case a Pizza parlour. Joe (the Data Subject) has a variety of contact points at which he may be contacted. Some of these he may have provided to Bob in Bob's Pizza. He will have provided these pieces of information for a variety of specific purposes.

The EU Cookies Directive: An Information Quality view

The European Union has introduced a revised and updated Electronic Privacy Directive which, amongst other things, introduces restrictions on the use of cookies. Most EU27 countries have stepped up to the markon implementing national legislation to enact the cookies, with a few exceptions. Much of the commentary about the Directive bemoans the impact on businesses using the web and on behavioural marketing etc due to the need to have consent for the use of the cookies and the fact that browser-based controls are unlikely, in and of themselves, to be sufficient.

Of course, it is easy to overlook the fact that there are exemptions where the cookie is essential to the operation of the site and the delivery of the "information age service" which the individual is trying to avail of. The oft-cited example here is the need of many on-line shopping basket systems to write cookies to your computer as you move through the sales process to remind the system what it was you were buying and keep your session active so that you can place your order seamlessly (for example if you are moved to a 3rd party site such as PayPal to do the payment bit and then go back to the company site to download a receipt etc.)

So, the cookies Directive boils down to the age old Peter Drucker conundrum: "What is the meaning and purpose of the information?"

In this context then, what is a cookie? The traditional definition is that it is a text file (or a flash local object) written to your computer by a website. However, that answers the technical "what". We are more interested now in the inforamtional and process "what" aspects of a cookie.

Think first - what do I need to achieve the goal?

In an earlier post I wrote about Information Quality being a "measure twice, cut once" type of challenge.

Today I got yet another email from "Karen", a subscription promotions robot at a large international industry publishing company, Information Week. The email (and I get them every few weeks) invites me to sign up for a free subscription to their print magazine because I've subscribed to one or more of their email newsletters. 

The invite reads:

As a valued InformationWeek newsletter subscriber, you’ve been selected to apply for a complimentary subscription to InformationWeek magazine – the source for unique editorial and in-depth analysis for the leading business technology buyers. Others pay for this must-have publication but if you take a few minutes to apply and qualify now, you will NEVER be billed. 

Now I LOVE dead tree publishing. I like being able to read things that won't need to be plugged in if I leave them down and walk away for an hour. And I LOVE industry publications becasue I can clip the good bits and recycle the rest. More than that, as a small business owner, I abso-fricking-lutely ADORE anything that is free.

Measure Twice, Cut Once (?)

I've been reading a lot of interesting blog posts in a variety of places about the importance and value of metrics for data quality and the potential for misunderstood measurements to drive misunderstood (or just plain wrong) decisions.

At the simplest level, this is yet another iteration of the age old "Carpenter's Rule" - Measure twice, cut once.

picture of a carpenter

 

But carpenters have it easy. Irrespective of your level of experience in carpentry and woodwork you intuitively know that the measures that matter to you are length, width/breadth, and height. All of those are ultimately different dimensions of the same metric (width is length from a different perspective after all). The key challenge for the carpenter is to make sure that they are measuring in the same units of measure (inches, feet, metres, centimetres). And if they are working with other carpenters they need to make sure that they have agreement on what unit of measure they are using.

Applying Information Quality Principles to Data Protection (Short Tutorial)

This video is a recording of the presentation I delivered to the Irish Computer Society's 3rd Data Protection Conference on 24th February 2011.

 

IAIDQ Blog Carnival

iaidq blog carnival 2010So, it is that time of the month again when we look back at the posts which educated and entertained us from the various data quality bloggers who are part of a community that has grown rapidly in the nearly 3 years the IAIDQ has been running the Blog Carnival.

Recent media coverage and the need to evolve your Information Architecture

At the risk of being seen to blow our own horn, we've had quite a good few weeks for media coverage in Ireland.

Hopefully this marks the beginning of a maturing of the discussion about Data Protection and Information Quality away from the technology and towards the fundamental issues of how information actually adds value to organisations and how the risks associated with Information (keeping it safe, obtaining it with clear purposes, privacy, and quality) can be managed and mitigated in a way that can ensure compliance with current laws and inform appropriate evolution of legislation and regulation to come, while at the same time enabling organisations to continue to offer innovative services and facilities to customers (and citizens) that make clever use of information to add value.

The Media Clippings section of the site is where we have planned to put examples of our mentions in the media. The assumption that was made was that everything we'd want to link to was going to be on-line in some form, therefore it is just a list of links to external sites. But that has turned out to be an incomplete solution.

Assumption is the mother of all…

There are many variations on pithy sayings about assumptions and the risk they present. They are unanimous in their admonitions that to rely just on an assumption when engaged in planning or executing tasks invites failure and headaches. Necessity may be the Mother of Invention but Assumptions are the Mother of all screw ups (diligent readers will recognise that I’ve cleaned that up for easily shocked readers).

The risk of assumption is no less apparent than in the area of Governance, and Information Governance in particular. Patently stupid and damaging decisions are taken every day on the basis of assumptions about information and the controls, regulations, and procedures that need to be in place around its use. For example, organisations assume they can use the PPSN (Ireland’s Social Insurance Number) as a unique identifier for customers, despite the fact that the uses that a PPSN can be put to lawfully (and by whom) are clearly set out in the Social Welfare Acts.

Within organisations seeking to define and execute effective controls over information it is often the case that things are done with data because they always have been done that way and, as a result, people assume that that is the way things should be done. This can result in data being processed or shared without valid lawful reasons (or conversely data not being disclosed where it might lawfully be done because someone assumes it can’t). It can result in a meaning and purpose being associated with a data field or recorded fact because people have assumed that is the case, resulting in confusion and degradation of data quality.

Over the past week I’ve been reminded of one example of Assumption at work in the management of fundamental data and another of Assumption’s influence in fundamental Governance of government…

Syndicate content