Business Unusual

Treat your personal data like cash (because that's what it is)

It appears that a database with a significant amount of information about you has been leaked. It may not have been intentional, but it does not matter really. Once the data has been leaked, it is anyone’s guess where it could end up.

It may be that the only people that accessed it, alerted the right people and the data is still safe, but we don’t know. See the piece on bug bounty hunters that explains who those people are.

The reason for this article is less about the leak and more about you and your understanding, and maybe your attitude to your personal data.

Odds are you assume it is so inherently part of you no-one could readily do anything without you knowing or easily rectify the issue should one occur.

So perhaps a different comparison will help. If you have ever had a credit card stolen you know the initial panic, followed by anger and frustration at having to cancel, hopefully be compensated and get a new card issued. Not fun.

Or perhaps you have had the misfortune to have someone copy your car registration and have a bunch of fines delivered to your door.

The point is, all that was needed to create that harm was some numbers and that is all identity theft is - the fraudulent use of some numbers. The problem is that, while you can get a new number for a licence plate and credit card, you are less likely to get a new ID number or home address.

The intention is not to scare you, or make you angry, but rather to appreciate the potential risk and respond accordingly.

If you are reading this at home, consider opening your front gate and door so anyone could enter. It would likely move you to close one or at least monitor them closely. Our understanding and attitude to our personal data is similar. We are not inviting trouble, but we certainly are not doing much to avoid it either.

There are three ways you can respond.

  • Blame others
  • Go completely offline
  • Take steps to limit your risk.

The third option is of course the right thing to do, but our anger is likely to see us opt for the first and our fear the second, neither though solve anything.

A Barclays ad illustrates how easy it is to share your private information unintentionally.

What does the law say?

South Africa is following some of the best practices already tried and tested elsewhere. The main protection will come from the Protection of Private Information Act (POPIA) - or Popi - as you are more likely to hear it referred to.

It is being enacted in parts and once fully enforceable would offer some peace of mind that larger companies would not ignore the risks of falling foul of its provisions.

But it will not only be the large well-resourced companies that will seek to collect information. In fact, it would be unfair to exclude small business from what effectively is, or will become, a digital economy.

Instead we would need to take some steps ourselves when dealing with organisations wishing to access your personal information.

There is a simple test to determine if your personal info is more important than the service being offered. If the service is provided for free, your personal info is more valuable than the service.

This article is free to read, but we hope many will read it and when they do, they will see ads posted elsewhere on the page. Our ability to get advertisers to pay us for those ads is based either on how many people will see it or who may see it.

We don’t really know too much about who will see it, but if you visited this page and you have also visited Facebook or Google then they know who you are, what you have read and how often you return.

Almost every action you do online is being tracked by someone and all that information is being analysed to maximise the potential to have you buy some service or product because companies like Facebook and Google - and many others - offer their platforms free in exchange for exposing you to advertisers that want to sell you something.

Access to your info may allow someone to hack your email and bank accounts or use them to send spam or fake money requests to your friends (or to post ads as endorsement to your social media, or get you to like posts and pages you otherwise never would). It can be used to open accounts in your name, deflect bad reviews or complaints to you and even to blackmail you should someone get access to embarrassing documents or pictures.

Some breaches would be like a mugging where you are being directly targeted. It is more common your information might simply be bundled up with millions of others and sold for a few cents to someone else to extort money or misrepresent you.

John Oliver explains what it means when you don't understand that you are actually the product. Warning: strong language

So what can you do?

Small things will make a big difference, consider carefully who you share your ID with.

There are 7 principles that you should look for.

Notice — data subjects should be given notice when their data is being collected;
Purpose — data should only be used for the purpose stated and not for any other purposes;
Consent — data should not be disclosed without the data subject’s consent;
Security — collected data should be kept secure from any potential abuses;
Disclosure — data subjects should be informed as to who is collecting their data;
Access — data subjects should be allowed to access their data and make corrections to any inaccurate data; and
Accountability — data subjects should have a method available to them to hold data collectors accountable for not following the above principles.

A random online competition from a site you have never seen before? Don’t do it.

Great deal to buy something online via an email from someone you don’t know? Nope.

Take a free personality test offered from a company you have never heard about? Pass.

An email request to update your details from a company or person you don’t know? Delete.

You get the picture. Share what is requested only when you are sure you know who you are giving it to. It would be a bridge too far to recommend you actually read the terms and conditions, because you won’t, but at least check the privacy section.

Ideally governments might take the responsibility of verifying who you are to others as you already need to verify yourself to them. See the piece on e-government about how a chapter 9 institution could do this. For there are companies like ThisIsMe who offer the service.

Lastly, and this is actually the easiest thing, get a password manager. One you pay for would be best although if you use Google and have two-factor authentication enabled then you could use their Smart Lock. It is free, and so if you are trusting that Google will be more responsible with your data despite you still being the product for their advertising machine, then at least you will be getting more services in return.


This article first appeared on 702 : Treat your personal data like cash (because that's what it is)


Recommended

by NEWSROOM AI
Read More
'Drop shipping' - the shady side of connecting buyers with sellers on the web

'Drop shipping' - the shady side of connecting buyers with sellers on the web

The web was supposed to connect buyers to sellers, but not like this.

Facebook is planning some big changes

Facebook is planning some big changes

The Facebook CEO set out his goals for 2019, and they include more encryption, less sharing and deleting your content.

Patronage can be good, just not the kind you assume

Patronage can be good, just not the kind you assume

Patronage in South Africa has negative connotations with good reason, but there is a good version.

What would happen if Government just gave everyone free money?

What would happen if Government just gave everyone free money?

Finland has ended a trial to see what impact a basic income would have on unemployment - this is what it found.

Why you should read the Bill and Melinda Gates Foundation annual letter

Why you should read the Bill and Melinda Gates Foundation annual letter

For the last decade, the letter has tracked how the world has been improving.

Robocalls: the good, the bad and the ugly

Robocalls: the good, the bad and the ugly

Before Robocops we will need to deal with Robocallers.

Popular articles
Eskom to destroy 90 000 mining jobs, warns Minerals Council SA

Eskom to destroy 90 000 mining jobs, warns Minerals Council SA

The Money Show’s Bruce Whitfield interviews Henk Langenhoven, Chief Economist at Minerals Council South Africa.

 Allow farmers to go off the Eskom grid and turn to solar power - Agri SA

Allow farmers to go off the Eskom grid and turn to solar power - Agri SA

Agri SA’s Nicol Jansen, explains how SA's agricultural industry could benefit if more farms were allowed to go off the Eskom grid.

NG Kerk minister condemned for showing solidarity with Christchurch victims

NG Kerk minister condemned for showing solidarity with Christchurch victims

NG Kerk dominee Riaan de Villiers says he was told he is not allowed to call Muslims our brother and sisters, and children of God.

'South African society even more unequal than under apartheid'

'South African society even more unequal than under apartheid'

Independent consultant at the Thabo Mbeki Foundation Professor Barney Pityana blames political leadership for the moral decay.

Suicidal SA pilot crashes plane into clubhouse

Suicidal SA pilot crashes plane into clubhouse

Khabazela shares tweets and Facebook posts that have gone viral.

Paramedics fear for their lives as attacks on EMS crews continue

Paramedics fear for their lives as attacks on EMS crews continue

An ambulance crew was held at gunpoint, assaulted and robbed of their belongings while on a call out in Khayelitsha.

DStv subscription price hikes for 2019

DStv subscription price hikes for 2019

MultiChoice will increase the prices of certain DStv packages from 1 April.