Monday, April 21, 2014

Big Data, Big Abuse Potential

SMAC, n.  (1) a variation of crack-cocaine; (2) a highly addictive, volatile, potentially life-transforming multi-composite drug, sometimes used illegally, universally available in medicine, commerce, education, and family economics; (3) social, mobile, analytics and cloud computing; (4) Big Data.

On April 11, 2014, the U.S. Federal Trade Commission (FTC) announced a public “workshop” on September 15, 2014, to examine effects of Big Data on “low income and underserved consumers.”  The workshop invites comments, reports, and original research to explore current practices in the uses of Big Data on high-income consumers and privacy rights generally.  The FTC will explore concerns that been raised about whether Big Data may be used to categorize consumers in ways that may affect them unfairly, or even unlawfully. (For more info, visit their website.)

The workshop will address consumer protection issues that could result in new regulations or laws affecting virtually all companies (whether or not they are “tech companies):

How are organizations using Big Data to categorize consumers?

What benefits do consumers gain from these practices? Do these practices raise consumer protection concerns?

What benefits do organizations gain from these practices? What are the social and economic impacts, both positive and negative, from the use of Big Data to categorize consumers?

How do existing laws apply to such practices? Are there gaps in the legal framework?

Are companies appropriately assessing the impact of big data practices on low income and underserved populations? Should additional measures be considered?

This workshop comes after the FTC examined privacy issues associated with big data practices in its 2012 report Protecting Consumer Privacy In An Era of Rapid Change: Recommendations for Businesses and Policymakers, and its ongoing examination of the data broker industry.

The proliferation of smart phones, tablets, intelligent mobile devices (including wristbands, headphones, automobiles and wearable telecom devices) and online social media have enabled the collection and analysis of huge datapoints.   The Internet of Things will include sensors (some of which are mobile) that are collecting data streams in real time.  Data brokers collect different related information that can be assembled into a mosaic of demographic information that might include race, religion, national origin, sex, sexual orientation, health conditions (subject to HIPAA), disability, veteran status and other commercially “relevant” criteria.  Big Data thus enables the pinpoint analysis of individual conduct as well as the conduct of individuals according to demographic, geographical, financial, educational and economic variables.

The FTC is looking at issues of the use of insights from Big Data (including credit risk scores, demographic information and other assessments) for illegal purposes.  While the FTC has been clear about potential abuses by financial institutions, the issues apply to all companies using Big Data.

Business executives (and law departments) should be asking how their own practices of collecting, analyzing and using Big Data might be abusive or illegal.

Now is a good time to conduct an internal review of your Big Data strategies.

What criteria do you use for market segmentation?  Consider how you use any Big Data (or direct customer data) in a manner that might discriminate against certain demographics in pricing, new product availability, service priority, credit card lines of credit, retirement account services, financial services, volume discounts, “early bird” or “favored customer” sales.

What criteria do you use for making preferential offers?  Do you limit access to “unfavored” customers in terms of access to higher quality products, services or content?

What policies do you have that might create (intentionally or not) a “disparate impact” (which, under one theory of law enformceemnt, constitutes intentional wrongful discrimination)?

Have you integrated your Big Data initiatives with your corporate social responsibility (CSR) and governance, risk management and compliance (GRC) programs.

Wednesday, March 5, 2014

Darwinian Survival through Disaster Recovery and Information Governance

It seems like stock prices fall pretty quickly after a data security breach.   Just ask TJ Maxx, Target, Nieman-Marcus or Sears.   The big boys probably have their business continuity plans (BCP’s) and information governance rules.   What about you?  What’s it all about, Alfie (the CEO, CIO, GC or Webmaster or Board member)?

My dalliance with BCP and “disaster recovery’ (“DR”) started 15 years ago, when I was negotiating long-term outsourcing contracts for enterprise customers.   No BCP/DR, no deal.

Fast forward to 2014.   Now just about everyone understands BCP/DR, requires it in their cloud computing agreements and maybe even in their strategic supplier agreements for manufacture of consumer packaged goods, or whatever.  So it’s time to reinvent and look at “information governance” as a subset of BCP/DR strategy.   And everyone MUST do something about “information governance” because you can get sued, pay a lot of money and lose customers.   Did I mention you (if you are a senior officer) might get fired? 

With your job on the line, where’s the crib sheet for mastering “information governance” and building your own job security plan (“JSP”)?

First step, sound the alarm and look for a BCP.  A business continuity plan acts like the Internet: multiple nodes, multiple points of failure, resiliency.  You plan your own company’s exit (and stresses leading to exit).

Second step, focus on an information governance strategy as a mini-BCP, directed at information technology, telecom and data security, brand management and liability management (to cut your losses on “stray” or “hacked” data).  Throw in a privacy policy too, with a compliance officer to run the deal.

Here’s the plan:
  • Face the music.  You won’t hear Beethoven, Mozart or Handel being mentioned with Gramm-Leach-Bliley, Obama(Care), or the less eponymous laws like HIPAA, HITECH or regulations on banking, financial services or insurance (“BFSI”).  Frame your frameworks.
  • Do some yoga.  A little flexibility, a little strength and resilience will help your company deal with surprise encounters of the info management kind.
  • Round up your data, Cowboy!/Cowgirl!.  Identify sources, uses, flows, warehousing, processing and transmittal of data.
  • Put your data collection on a diet.  Imagine a Web without intrusive cookies (as the EU regulators are considering due to easy identification of individuals with geolocalization tools).  Collect and keep personal data (and data leading to individual identification) only if you “need” it.   Otherwise, it’s digital baggage that, if hacked, will cause legal and branding hassles.
  • Orchestrate your musicians. 
    • Identify “records custodians.” 
    • Designate an “information governance team” for all managers who will have inputs into information management and technologies.
    • Designate an “incident response team” and allocate roles, responsibilities and strategies for each team member.   Include HR, IT, marketing, legal, purchasing, compliance, finance and
  • Get political.
    • Identify all of the company’s constituencies who may be impacted by an “incident.”  Consider suppliers, licensors, licensees, customers, joint venture partners, regulators, public relations, reporters, shareholders, directors, officers, employees, lenders, courts, litigants, and anyone else affected by your business.  
    • For “B corporations,” consider your social and environmental mission and constituencies.
  • Unchain your paranoia.  Assess vulnerabilities and mitigate risks.
  • Virtualize and diversify your supply chain (through to your customer delivery service too).  Identify and plan for “disaster” scenarios and the impact on operations, legal compliance, customer loyalty and the company’s value chain.
  • Treat data like gems and rare anti-venom snake serum.  For legal issues, the plan should address preservation of legal records and evidence, engagement of forensic analysts and timely statutory notifications of security breach incidents.
  • Party hearty, but only after you successfully do your mock “disaster” (“incident”).  The “incident response team” must practice the “table top exercise” drill of data recovery, data security breach notifications and remedial public relations.
  • Be democratic.  Get everyone involved, trained and conscious.
  • Adapt.  Evaluate and continuously monitor the data security practices and compliance of your internal and external tech providers.  Revise your policies to adapt to new threats and scenarios.  Get a trip to the Galapagos Islands and see what adaptive survival looks like.
Sometimes looking at digital life in analog form makes good sense. Stay healthy.

Wednesday, February 12, 2014

Your Global Brand: Reconciling Business Models and Supply Chains

On Abe Lincoln’s birthday, we can derive inspiration from the life and lessons of “Honest Abe.” Like your parents told you, you are known by the company you keep.  This is true for each employee in a service business as well as the entrepreneur, the growing business and the global business.   Your business model and your associations with others directly impact your business success.  Increasingly, you need to orchestrate your business operations and branding messages across both individual and shared brands.

Now, more than ever, creating and managing your global brand is essential to all aspects of your business, beyond attracting and retaining loyal customers under an understood trademark.  Every business today is a service industry, and your brand reflects quality of service and user experience (UX) for everyone who touches your business.

Value Chain Branding.  Brand management means running all aspects of your business as a strategic relationship throughout the entire business value chain. Your global brand transcends across customers, employees, suppliers, outsourced service providers, investors, professional advisors and even regulators and competitors. Think of the benefits of a strong brand in terms of strong corporate culture, employee morale, investor confidence and enterprise sustainability.

Proprietary vs. Shared Brands.   In the American culture, individualism and community can collide.  A proprietary brand is owned, controlled and managed by one enterprise.   A “shared brand” is the brand of shared enterprise.  The logic of collective action suggests that individuals and small and emerging businesses should brand themselves uniquely, while joining in shared brands that may include competitors and suppliers.

Managing Your Own Brand.   In the individualistic enterprise model, managing your own brand requires trademark registration in relevant markets (including countries where you source your products and services).  Think Coca Cola®

Sharing a Brand.   The Big Four accounting firms and the global law firms might present themselves as partnerships, but they  segregate their operations for tax, legal and regulatory purposes by setting up a common brand and then licensing it to themselves.  That’s sharing a brand at the individual enterprise level.  The leaders develop the concept, the membership follows the model and markets under the shared brand. Think Ocean Spray®, a cooperative of growers of cranberries.

Sharing a brand normally means losing your individual identity.   Ironically, in the services industries, the value of a shared brand depends on the quality and integration of the components (individuals) operating under that brand.  By marketing and delivering your own unique skills, doing your own blog and having your own little team within a larger organization, you can enjoy both the economies of scale of the larger organization and the unique profile that attracts and sustains your own clientele.  For this reason, broker-dealers, law firms, consulting firms and other service enterprises encourage each individual to be a rainmaker with unique talents and to team with others offering collective and synergistic talent.

Co-Branding.  Consider possible solutions to piggy-back upon the goodwill of others:

  • Creating new venues by co-marketing (under different brands) of different goods and services to the same target clientele.
  • Advertising to your target clientele in venues that your competitors do not use.
  • Giving financial incentives to referral sources by “partner referral” or “business partner” programs.
  • Earning a “certification” from a well-respected source of trust, such as a top university or the International Standards Organization, or other non-profit or non-governmental organization.
  • Participating in the development of industry standards.
  • Building a new trademark and enlisting others to sell under it, either as licensees, franchisees or even as co-owners of the brand.
  • Becoming a strategic advisor or “resident” expert to a university, think tank, startup incubator or non-profit organization.

Interplay of Individual Brand and Your Supply Chain.  Sharing a brand can also mean building a network of trusted suppliers and service providers who are the back-end of your service delivery platform.  You need to manager your suppliers to ensure you deliver on your promises (and your regulatory compliance obligations).   Otherwise, you have no business, and you have legal liability for breached contracts.  Think about your vendor contracts and your supply and service contracts for your customers.

Joint Ventures, Strategic Alliances and Teaming.  Synergies also come from collective operations that are either new enterprises or an extension of your own enterprise using third parties as co-providers or as suppliers.  Dow Corning has been a joint venture for over 40 years and has developed its own customer.  CSC (US) just announced a partnership with HCL (India) that enables CSC to deliver data center management and cloud computing using HCL as supplier and HCL can enjoy the benefit of CSC’s sales and customer relationships.  Think about introducing a strong “partner” to return and engage clients.

Rethinking your Brand Strategy.   Effective branding strategies bear fruit upon sale of the company, since trademarks and goodwill are valuable marketable assets that can be sold separately (like Abercrombie and Fitch) or as part of a business.  These distinctions might help you rethink your brand strategy and develop and support multiple brands for yourself.

P.S.  I’m being interviewed on the relationship of business models and global brand management tomorrow at 2 PM ET, at www.global-reach.com

Thursday, January 30, 2014

President Obama’s January 28, 2014 State of the Union Address sets a nationalistic agenda for American jobs.  There are some ideas that even business people (including business lawyers like me) can warm up to in the January Polar chill.

If you have been following the changes in the law, you might find his remarks a bit hypocritical and bombastic.  At least it was an occasion to be selectively optimistic to anticipate future legislation (or executive orders, i.e., Presidential fiat).

Insourcing.  Manufacturing has been outsourced and offshored in global supply chains for a long time due to wage arbitrage, efficient global logistics, factory automation and computerized design.   Obama notes: “over half of big manufacturers say they’re thinking of insourcing jobs from abroad.”  Any reshoring of manufacturing production jobs would unlikely bring back the number of jobs lost during the offshoring years.   Re-localization of these jobs would probably require new skills as manufacturing processes have become more highly efficient. 

Tax Reform.  Obama wants to reform “our tax code [that is] is riddled with wasteful, complicated loopholes that punish businesses investing here, and [that] rewards companies that keep profits abroad.”  He wants to “close those loopholes, end those incentives to ship jobs overseas, and lower tax rates for businesses that create jobs here at home.”  What’s missing is that any tax reform should be used to raise revenue on a permanent basis for both personal and corporate income taxes.  Current proposals will only result in a temporary revenue increase, which Obama would allocate to infrastructure investment.

Small Business and Entrepreneurship.  Recognizing the role of SMB’s in job creation, economic growth and foreign trade revenue, Obama exhorted Congress to “do more” for them.   He claims that “Over the past five years, my administration has made more loans to small business owners than any other.”    How about reducing government regulations which impose onerous costs on SMBs?

International Trade.  Obama wants trade, “new trade partnerships with Europe and the Asia-Pacific” to help SMB’s create more jobs.  “We need to work together on tools like bipartisan trade promotion authority to protect our workers, protect our environment, and open new markets to new goods stamped “Made in the USA.”  China and Europe aren’t standing on the sidelines.” This is a plug to get trade negotiating authority for the Trans-Pacific Trade Partnership and the Trans-Atlantic Trade and Investment Partnership diplomatic deals. 

Innovation.    Obama claims the US is the global leader in innovation, giving us “an edge America cannot surrender.”   He wants to restore R&D tax credits, which lapsed due to the failure of his Administration and the Congress to enact a general tax law for three or four years due to dogmatic positioning.
 
Patent Trolls.  Obama wants to “pass a patent reform bill that allows our businesses to stay focused on innovation, not costly, needless litigation.”  Of course, he fails to mention that business process method patents, judicially approved in the mid 1990’s, helped create new industries in Silicon Valley.  The America Invents Act of 2010 was supposed to have protected businesses from unwarranted litigation through reforms in the processes for evaluating the patentability of pending patent applications.

Immigration.   Immigration reform offers significant economic benefits, which Obama focused on.  Pending reform legislation would open the doors to foreign entrepreneurs, investors and retirees, making the U.S. more competitive with other immigrant – favorable jurisdictions. It will also eliminate abuses of H1-B visas by foreign service companies and promote a more balanced global workforce with significant U.S. consultancies. 

Thursday, December 5, 2013

Business Compliance Strategies: Avoiding “Accidental” Software Piracy

What’s the price of “accidental” or “inadvertent” software copyright infringement?  For the U.S. Government, the cost was $50 million to settle a $224.5 million copyright infringement suit brought by Apptricity, a software firm offering supply chain management and integrated finance solutions.  In this case, the U.S. Army paid for a certain number of licenses for Apptricity software to track troops and supplies in “real-time” and then significantly “over-deployed” copies to its servers and devices to the tune of thousands.

Under the U.S. Copyright Act, the infringer is liable for either actual or statutory damages plus attorneys’ fees of the copyright owner.  However, Apptricity chose to settle and the U.S. Army remains a client, according to their press release.  I surmise that Apptricity probably got the deal it wanted from the “alternative dispute resolution” process by adding some settlement agreement conditions that were not announced, such as improved monitoring for future compliance, additional maintenance fees and some other forms of future revenues.

In civilian cases, software piracy can lead to double the licensing fees plus intrusive usage monitoring, additional penalties for future infringement and adverse publicity.  On various occasions, we have had to advise clients on the realities and risks of unlawful “over-deployment” of a similar nature, or worse. The resulting process of correcting such errors is costly, distracting and damaging to your core brand value.

Executives and entrepreneurs alike should ask themselves what does it take to manage software licensing compliance?
  • Inventory Management Practices. You maintain an updated inventory of all computers and other devices and identify the authorization rules for all licensed users. You update continuously based on needs and actual uses.
  • Pricing Management Practices. You plan future growth so you can negotiate volume licensing prices. 
  • Human Resource Management. You design a compliance process to include “adult supervision” of all personnel having access to computers. This includes both internal and external personnel and external (Cloud-based) computers. The process includes policies, training, internal auditing, enforcement and may include whistleblowing and code of conduct” procedures applicable to internal and exteral (outsourced) personnel.
  • Toolkits. Find a software tool for digital rights management.
  • Digital Asset Management. Beyond protection of third-party licensed software, every business needs to track and protect the intellectual property and competitive advantages of software developed by itself, its licensors, and its trading partners. Digital asset management starts with a trade secrets management strategy and assurance of the independence of its innovation team from inadvertent infringement using “Open Source” software or snippets “discovered” on the Internet.
$50 million is a lot of pain.  “Inadvertent” software piracy is not good for business.  The Government’s painful disclosure of such infringement is just a reminder that we each need a compliance program for digital assets