A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

DSK Bank
Privacy as a Competitive Advantage Rather than a Regulatory Requirement


Introduction
Recognizing the fast pace of technology and its constant evolution, the protection of an individual’s privacy is a true concern in today’s digital economy. Technological advances in recent years and related consumer expectations led to a natural change in business models and operations towards a significant increase in data collection and processing. Changes in the regulatory framework followed, introducing a broader set of consumer rights and enhancing the level of security and data protection by implementing more stringent and complex rules and requirements.
According to one McKinsey survey on consumers’ expectations of privacy and collection of data, in terms of consumers’ trust, when it comes to the protection of privacy and data, financial services come second only to healthcare, with a big margin to third-placed pharmaceutical services. Besides being a hefty responsibility to meet those expectations, it can also be considered as an opportunity to develop customer relations in a new way - by taking privacy as a baseline feature in the operational model.
Due to the nature of customer relations and the logic of regulations, it is self-evident that privacy and security risks can be managed efficiently only by designing products and services with embedded privacy and by providing secure technological infrastructure combined with enhanced vendor and crisis management. The systematic strategic approach to data – personal or otherwise protected – can strengthen the company’s ability to meet consumer expectations and ensure compliance with the relative legislative framework.
Vox Populi vox Dei or simply “Customer expectations."
In 2023, the International Association of Privacy Professionals (IAPP) published a study called ‘Privacy and Consumer Trust’ by IAPP principal researcher, privacy law and policy, MügeFazlioglu . It says that although almost 68 percent of all consumers worldwide are concerned about their privacy, more than a third of the customers (35 percent) believe that companies only pay attention to the topic because of their regulatory obligations.
"In my opinion, everything points out towards the simple fact that privacy is already become a competitive factor, at least as much as it is regulatory"
In other words, a regular Joe, which forms the backbone of many businesses, tells himself, "They do it in order not to lose money, not because they are concerned about me". That is a negative thought to place in the customer's head, which, eventually, will evolve into "I don't matter to them" and to the logical epilogue, „I will go someplace where they care”. This is indicated in the quoted article as well - "Globally, 52% of consumers have been affected by a data breach. Of those affected, over 80% say they sometimes or always stop doing business with a company after it suffers a data breach."
This represents quite a significant niche to position yourself as a company if you ask me.
Consumers' caution about sharing data, alongside regulators cranking up the heat on privacy requirements, leads to a logical conclusion - companies are learning how to create a consumer-centric business advantage using privacy, data protection and security.
SPQR or Simply “State Expectations”
The government's privacy frameworks and policies are a continuation of the overall political climate in recent decades, driven by the desire to place an ever-wider range of rights in the hands of the people. This led to significant changes, among which people have been granted enhanced tools for control over their data in the EU and UK. For example, this is headlined by a broad set of personal rights and expansion in regulatory powers. Business has met increased limitations in regard to data gathering and trading and the introduction of severe regulatory oversight, both in the form of greatly increased requirements and, inevitably, sanctions and fines.
The above can be illustrated as a main driver for the shift towards more sustainable models of doing business, as described in the article from 2021 called ‘The demise of third-party cookies and identifiers’ by McKinsey & Company .
Privacy Will Be E Key Pillar of Ethical and Responsible AI
So far, we've described what is already known, what is behind us. Theorists and day-to-day practitioners have developed complex, interconnected and somewhat - incomprehensive - frameworks and systems for risk management, security and data protection. What lies ahead is the new paradigm - so-called artificial intelligence and the activities revolving around it. In a way, a new form of an unknown known - something that exists but cannot be imagined at this point.
Let’s explore the following concept – you live in a smart AI-enhanced house. Everything is digital and automated – home appliances, security systems, infotainment systems; you name it. The AI operates with constraints, but in terms of developing optimal household environments, it has considerable freedom of choice. Imagine that your smart refrigerator can tell when the milk will go bad and that you, over the course of a fairly long observation period, have demonstrated behaviour to never finish the box of milk and it's always gone bad and in the trash eventually.
This data, of course, is stored, processed and used by the said AI. Now, from one side, the AI can decide on the next refill to order a smaller carton of milk or one with a longer shelf life. However, it may also decide that you, in the context of ecology, do not show the necessary commitment and do not order milk at all because you cannot use it according to the standards.
Those decisions, based on behavioural data, although trackable, in accordance with some decision tree, are worrying and should be addressed.
How this is going to happen is also a great question because, after all, for us, it is a programming code, no matter how well we understand it, but for AI it is a native language.
Therefore, it is no wonder that in the IAPP article quoted in the beginning, 57 percent of global consumers agree that the use of artificial intelligence in the collection and processing of personal data poses a significant threat to user privacy.
Conclusion
Most people are afraid of the unknown. And with a good reason, I may say. When we are talking about a high level of automation in collecting and processing data that is subsequently used for all kinds of purposes – from relevant advertisement to the ability to use (or not!) a specific service – it is for sure a case of ‘better safe than sorry’. As a matter of fact, the current regulatory framework leans towards that approach and mandates that something needs to meet the detailed requirements before it is operational.
Our brief journey begins with the state of play as-is – the rapid development of technology and the people's expectations coming with that. The state direction in terms of privacy continues to be the new major challenge on the horizon - AI, especially when collecting and processing data.
Things like “Give me relevant recommendations I wouldn’t have thought of myself.”, “Talk to me when I’m in shopping mode.”, “Remind me of things I want to know but might not be keeping track of.”, “Know me no matter where I interact with you.” can be perceived as appropriate for customers by now, but the more advanced algorithms that explore aspects of human behaviour that are unclear to most people are definitely something to keep an eye on.
In my opinion, everything points out the simple fact that privacy is already become competitive factor at least as much as it is regulatory. Exactly how remains to be seen.