Well, you probably know that this is a very sensitive issue for us and that we cannot just answer it like that. You should have given us a longer deadline; a week is not enough for us, a long weekend is approaching, I hope you understand – this could summarize the series of responses that Lider received to inquiries from certain business organizations that handle very sensitive data of their users regarding how they protect it or, if they sell it, to whom and under what conditions. We are aware that we live in a world where data, even very personal and indeed sensitive data, is very valuable and can be well monetized, so we cannot say that we have no reason for concern.
However, even in this torrent woven from refusals, there are companies that want to transparently disclose this information, and these are mostly the organizations that are often pointed at first. Telecoms not only want to remove that reputational stigma from themselves but also want to convey to the public, and above all to their users, that their data is indeed safe with them.
– Hrvatski Telekom does not buy or sell personal data of its users and protects it according to the best industry standards. Hrvatski Telekom applies technical and organizational measures in accordance with current standards and best practices in the field of security, personal data protection, and privacy. We have introduced and apply the PSA (privacy and security assessment) procedure, which ensures privacy by design and security by design, meaning that all relevant requirements for personal data protection and security are embedded in Hrvatski Telekom’s products and services from the very beginning – stated Dragan Gudeljević, head of the Personal Data Protection and Privacy Department at Hrvatski Telekom.
Limited Opportunities
He also mentioned that everything happening in that company with data is fully compliant with the internationally recognized standard Information Technology – Security Techniques – Information Security Management Systems (ISO/IEC 27001:2017), and in addition, their main data center holds a Tier III certificate. However, Gudeljević notes that, despite all of the above, opportunities for data monetization exist, but they are limited since appropriate legal grounds prescribed by the General Data Protection Regulation are required for processing personal data.
—
Ordinary citizens have various platforms available that promise them profit if they provide their personal data and thus bypass consent, and that someone else handles their data. They are being tested somewhere outside Croatia.
—
– The potential for monetization lies in anonymized user data, meaning there are opportunities to create new value based on statistical data and their trends on a daily and geographical level – explained Gudeljević.
As we learn, A1 Hrvatska has never and will never share or trade user data, and it uses it exclusively under the conditions and in the manner specified in the Personal Data Protection Statement, which is compliant with the General Data Protection Regulation and is publicly available on its website.
At A1 Hrvatska, they apply and continuously improve security protocols for protecting user data, aligning them with the highest global standards, and they will continue to do so, emphasized Sven Škrgatić, director of cybersecurity and the technological operations center at A1 Hrvatska.
Idea from the Island
– In this context, we apply advanced security measures to protect information systems that are continuously revised. We are aware that absolute protection does not exist, which is why compromises of information systems in the world are almost daily occurrences, and there is no company or institution that has not faced them. Therefore, comprehensive development and investment in information security is a continuous process. Our focus is on active measures such as frequent vulnerability checks of systems, implementing multi-factor authentication, and monitoring systems based on machine learning and AI technologies, as well as educating all employees about computer security – listed Škrgatić.
But what about the others? Where is their confirmation that they are not doing what they should not? Well, it seems that, at least for now, we have to take their word for it. However, are there examples where we, the users, have control over the data we want to share and not only can decide to whom and how we give it, but we can also earn from it ourselves? Namely, the Irish fintech Unbanx launched a free application at the beginning of the year that allows consumers to own, control, and earn rewards from their personal banking data using Open Banking. Although such an option is only available to users of that application in the United Kingdom and Ireland, they can share, anonymously and securely, so the creators of the application claim, their spending history to earn Unbanx’s ‘points’, which can be used at several vendors. When asked where they got the idea to launch such a tool, Unbanx’s CEO and co-founder Alan McDonald said that banks had ‘secretly sold’ their clients’ banking data to the data analytics industry and made ‘profits of millions of dollars’.
—
The ‘purchase intelligence’ industry worth billions of dollars is just at the beginning, said Alan McDonald, who believes that individuals, not corporate giants, should have ownership and control over their personal data.
—
– Our research suggests that the ‘purchase intelligence’ industry is worth billions of dollars and is just at the beginning – added McDonald, who believes that individuals, not corporate giants, should have ownership and control over their personal data.
And while we wait for someone geographically closer to devise such an application for us or at least launch such an option in our market, the EU, of course, is contemplating and devising how to regulate the entire market that is currently almost entirely left to itself, especially now that it will be very easy to train artificial intelligence tools with that data, which opens a whole set of ethical questions. Thus, work is underway on the European Union’s digital strategy, which will have several regulations, one of which will be the data governance law that will be enacted in Brussels and which every country will have to implement in the same form, which is a much stronger legal tool than various regulations that countries could apply literally or interpret as they see fit, which would only create room for deviations from the original idea. This time it will not be possible because the European Union wants this act not only to protect data but also, let’s say poetically, to breathe new life into it.
Unregulated Market
‘The economic and social potential of data is enormous; it can enable new products and services based on new technologies, increase production efficiency, and provide tools to tackle social challenges. For example, in the health sector, data can contribute to better healthcare, improve personalized treatment, and treat rare or chronic diseases. This data can also be a strong driver of innovation and new jobs and a key resource for startups and small and especially medium-sized enterprises,’ states the European Commission’s explanation.
However, the Commission also notes that while the unregulated market thrives, the market where less sensitive data that does not infringe on user privacy should be shared is not realizing its potential.
‘Data exchange in the European Union remains limited due to a number of barriers, including low trust in data exchange, issues related to the reuse of public sector data and data collection for the common good, and technical barriers. To truly harness this enormous potential, it is necessary to make more data available, share with trust, and technically easily reuse,’ they emphasize in the Commission.
Examples in Practice
And how does all this look in practice in the EU? For example, Deutsche Telekom and its data center offer a data marketplace where companies can securely manage, provide, and monetize quality information, such as production data. The telecom acts as a neutral intermediary and guarantees data sovereignty through decentralized data management, and currently, more than a thousand users from over a hundred different companies operate on the platform.
—
The new Digital Strategy of the European Union will also be based on the Data Governance Law, a regulation that will be enacted in Brussels and every country will have to implement it in the same form. The EU wants not only to protect data but also, let’s say poetically, to breathe new life into it.
—
Dawex is a French company described as a ‘global data marketplace’. It does not buy or sell data but brings together companies interested in monetizing and reusing data and promotes transparency between data providers and users by ensuring they communicate and transact directly on its platform. Data users and data providers communicate using a messaging tool embedded in the platform. Additionally, Dawex supports contract negotiations according to condition models that can be automatically generated.
Data Altruism
There is room for market development and new innovative ideas, and there is also a need for further strengthening of regulation and for something that the Commission calls data altruism. Data altruism refers to individuals and companies that give their consent or permission to make the data they generate available – voluntarily and without reward – for use in the public interest. Such data has enormous potential to enhance research and develop better products and services, among other things, in the fields of health, environment, and mobility. Research shows that although there is a general willingness to participate in data altruism, the lack of data exchange tools makes it difficult in practice. Therefore, the goal of the Data Governance Act is to create reliable tools that will enable easy data exchange for the benefit of society and economic development. Let’s live and see.