Wednesday, January 13, 2010

Is your customer data worth $800k?

Customer data protection is taken seriously in Europe. What a company can do with customer data, and a company's responsibility to keep the data secure is legislated and enforced. And as reported on the BBC News website, a new rule in the UK will add teeth to the threat, with "Data losses to incur fines of up to £500,000". That's over $800,000 US. But if you are a US company, what do you care? All you have to worry about is HIPAA and the new HITECH rules that protect personal health information, right?

As a company located anywhere in the world, if you contract with companies or individuals in the UK, you might want to make sure what your obligation is to UK consumers under their laws. Even if you take care to ensure that your customer information does not end up on a lost laptop and your backup tapes are secure, you may need to pay more attention to the list of names you sell to 'partners offering related services'. You may have noticed that top international travel websites, such as Travelocity, Expedia and others, now have a checkbox for you to confirm your status as an EU citizen, so they can potentially handle your data differently.

The question for many companies will be how much income or cost savings they see from trying to run with the data protection matching the lowest common denominator regulations (for most companies, the US rules), compared to the customer trust that comes with following a policy that meets the highest levels of privacy and data protection that is possible, independent of nationality. I'm not saying that the UK rules are perfect, or the EU has everything right, but when it comes to my personal data not being abused I will buy from companies that value my data as much as they value their own.

