QuestionQ316

Privacy Operational Lifecycle: Protect

You have recently assumed the role of Data Governance Director at an energy corporation headquartered in London, England. The company has traded for more than 25 years, and you soon learn that, to date, it has done little to govern the use of customer information.

During your first few weeks, you determine that, despite efforts by your predecessor, the company has retained all customer records digitally across several systems, including its customer records management system, invoicing system, call-recording system, marketing database, and two different email clients.

There have been a considerable number of minor data breaches in recent months, as well as a couple of larger ones. These have not only damaged the company’s reputation, but have also required it to report some of the larger breaches to the regulator. One breach resulted in the deliberate leak of the credit risk scores of more than 150,000 customers to the company’s largest competitor.

You also find that some customers requested deletion of their data after several marketing campaigns. Although the company told these customers that it had completed what they requested, you learn that it only removed them from marketing lists—in other words, all of their data remains in the various digital systems for marketing, invoicing, and records management.

In addition, you learn that, if a customer service agent in the energy corporation’s US call center cannot find the details of the particular customer they are speaking with by phone, the agent simply adds notes from the telephone conversation to whichever customer record they can locate. Consequently, some customer records are highly inaccurate, causing delays in compensation payments, poor reviews on independent review sites, and consideration by the UK energy regulator of suspending the company’s license.

As artificial intelligence is regarded as the new energy future connected to the Internet of Things (IoT), the company has partnered with another company that specializes in ingesting vast amounts of data into cloud-based warehouses. The data is used to profile customers, to identify those most likely to purchase the new cutting-edge technology offered through the new business partner. Many of the new devices being offered will allow both companies to collect still more customer data, including geo-location, IP addresses, the electrical devices customers use in their homes, and when they use them most.

The company is very enthusiastic about the future and how this new technology can help it outperform competitors, but you have a major task ahead to ensure its privacy program is correct.

Following the marketing campaigns, which of the following should the company have prioritized?

  • A Anonymizing the customer's data within all the systems.
  • B Putting in place new processes for valid deletion requests.
  • C Stopping the sending of marketing emails to these customers.
  • D Verifying the identity of the customers who made the requests.
Explanation

A valid request for erasure requires an organisation to have processes that identify the request, determine whether the right applies, and erase applicable personal data held across its relevant systems without undue delay. Removing a person only from a marketing list does not satisfy a request to delete their data. The UK Information Commissioner’s Office states that organisations should have processes for responding to erasure requests and appropriate methods to erase information; identity evidence is needed only where there are doubts about the requester’s identity.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!