Tuesday, November 7, 2006

Protect Your Customers’ Privacy Ethically, Not Legally

Following the recent posts about privacy and web analytics, it appears that ChangeThis was at it too with a new Manifesto entitled "The Seven Principles of Privacy: Protect Your Customers’ Privacy Ethically, Not Legally", authored by David Holtzman. I guess this will be covered in depth in his book "Privacy Lost: How Technology is Endangering Your Privacy". The manifesto highlights 7 ethical principles which might be worth looking at:
  1. Don't spy on me because you can
  2. Thou shall erase my data: Don’t keep data any longer than you have to; you can’t give up what you don’t have.
  3. Keep my information to thyself: Require customers to opt-in for each additional use of their information.
  4. Don't judge me: Never create a profiling system that labels your customers in a way that you’d have trouble justifying if they ever saw their file, because some day they probably will.
  5. Protect my data like it were thine own: Provide the best computer security that you can afford.
  6. I am who I say I am: Let your customers pick their own demographics.
  7. Don't humiliate me: Avoid embarrassing your customers by mishandling their data.
Some of those points really focus on corporate employees, while others could be applied to anonymous data, and some are really closely tied to personal information management.

I really like the conclusion of the manifesto:
Laws make poor privacy guidelines. Business people need better directions when navigating their customer relationships than simply to be told to steer around legal roadblocks. Boardroom discussions should be less about what is permissible and prohibited and more about what is positive and proactive—in short, what is ethical. The question should not be “Can we do this?” but “Should we do this?” “What’s the right thing to do?” If your company handles the electronic representation of the customer the way that they’d deal with them if they were standing face-to-face, you’ll do fine.
It is more a general view on privacy and anonymity not specific to web analytics, however, there are some good tidbits in the complete article (plus, the ChangeThis format is fantastic, check it out if you never had the chance before!).

Monday, November 6, 2006

Web 2.0 Measurement Working Group

This week-end I really experienced for the first time the power of social networking. I submitted my point of view entitled "Google growing larger than Microsoft?" to Digg and within hours, my site traffic skyrocketed to about 40 times its usual traffic. The post made the top 10 ranks of the Tech Industry News for November 6th.

From an analytical standpoint, this is interesting for many reasons:
  • I got a huge increase in traffic, but it turned out to be narrowed to that single post. There was a 84% bounce rate on that post, clearly reflecting the way people use services such as Digg: get an interesting newsbit, scan it (and sometimes read it!), and get out. At least, that's the way I'm using Digg, Technorati, Reddit and even Google Reader.
  • My page view/visit ratio went down from over 4 to barely over 1. If I had a visit/conversion KPIs, they would be totally out of control.
  • The average attention span on that post was slightly over 2 minutes, which is barely enough to scan this long article and focus on the most interesting paragraphs.
With the number of people blogging and competing to get their share of attention, simply measuring blog traffic with Google Analytics is certainly not enough, and making the long run to get the stats out of every tools is tedious, if even possible. Casual bloggers faces the same data convergence challenge company do: how to retrieve value out of disseminated interaction points stocked in heterogeneous systems, in different formats, and different units of measure?

This boils down to the fact that measuring page views is not enough. We need to start thinking in terms of "significant user event", be it an RSS read, social network posts and their ratings, a specific user action within a page or more conventionally allowing some of our attention for reading a page or looking at a product. And thats where the "Web 2.0 Measurement Working Group" can contribute: what should be measured, and how?

In this respect, measuring "Attention", as defined by Beck & Davenport, might be a good path to investigate.

Saturday, November 4, 2006

Web Analytics and Privacy

The heat is on again: an activist group is asking the US Federal Trade Commission to investigate the use of personal information, which, in my view, is already well governed by existing laws not only in the US, but in most countries, including Canada. The problem is this group mixes personally identified data collection and includes web analytics and anonymous data collection in the same bag.

The Web Analytics blogosphere is likely to have passionate views in regard to this opinion. So far, one of the most interesting post comes from the Web Analytics Yahoo group. The argument is simple, evident, and clearly expressed: there is already a user consent for anonymous data collection covered by privacy policies posted on any serious web site.

My contribution to this discussion is in regard to PIPEDA, the Personal Information Protection and Electronic Document Act, the Canadian law that governs the collection of private information. In a nutshell, that means the information must be:
  • gathered with the user's consent
  • collected for a reasonable purpose
  • used only for the limited purposes for which it was gathered
  • accurate
  • open for your inspection and correction
  • stored securely
This is expressed in 10 principles:
  1. Accountability
  2. Identifying purposes
  3. Consent
  4. Limiting collection
  5. Limiting use, disclosure, and retention
  6. Accuracy
  7. Safeguards
  8. Openness
  9. Individual access
  10. Challenging compliance
It is worth to note these principles not only covers the collection of personal information, but also applies to anonymous information as well. We have to admit, however, the law is not strongly enforced. Still, those who try to comply have found it reasonable and it doesn't impact the ability to use web analytics tools to better understand their user audience and preferences.

The W3C also offers some guidelines in the form of "P3P: The Platform for Privacy Preference". Although not widely used so far, I think sites offering the information about their P3P policy have an advantage:
The Platform for Privacy Preferences Project (P3P) enables Websites to express their privacy practices in a standard format that can be retrieved automatically and interpreted easily by user agents. P3P user agents will allow users to be informed of site practices (in both machine- and human-readable formats) and to automate decision-making based on these practices when appropriate. Thus users need not read the privacy policies at every site they visit.
P.S. Note the province of Quebec is governed by a similar act named "An Act respecting the protection of personal information in the private sector"