Endpoint
6/19/2013
07:49 AM
Tim Wilson
Tim Wilson
Quick Hits
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Survey: Customers Expect To Be Asked, Compensated For Use Of Personal Data

Consumers recognize value of personal info, expect "identity etiquette," survey says

Consumers expect companies to ask their permission before using their personal information, and they expect some form of compensation for giving it, according to a study published Tuesday.

According to a study on the use of personal information (PDF) commissioned by UnboundID, consumers not only value their digital identities, but they also expect companies using that data to exhibit "Identity Etiquette."

The survey, conducted by Compass Intelligence, showed that consumers have an explicit idea of the economic value of their digital identities and expect companies to give them something in return for using it.

Results of the survey indicate that customers understand that companies use their digital identity data for marketing purposes -- and that most expect some level of etiquette from companies using this data, such as asking for permission to use it. Respondents also expect some form of compensation for the use of this data -- cash value in the form of a discount was the most popular benefit cited by respondents (47 percent), followed by value-added services, such as more content or viewing options (22 percent).

"The research shows that 62 percent of customers expect companies to ask permission, in one way or another, before using digital information," said Steve Shoaff, CEO of UnboundID. "Many of the respondents stated that they would like to determine what, if any, of their data is shared.

"Many companies worry that if they give customers the chance to opt out, they will," Shoaff said. "However, these findings indicate that customers really want more control over how and when their data is used. By practicing the right kind of etiquette, companies will ultimately get better, more realistic data from their customers."

Findings from the Compass Intelligence study show 43 percent of customers say they would "think better of and/or be thankful to companies" that give them control of how their digital information is shared. "Asking which items can be shared" was the top response (33 percent), followed by "offering a meaningful benefit for data use" (29 percent) and "the ability to update or revoke access to data at any time" (26 percent).

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

CVE-2014-2392
Published: 2014-04-24
The E-Mail autoconfiguration feature in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 places a password in a GET request, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer log...

CVE-2014-2393
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.

CVE-2011-5279
Published: 2014-04-23
CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a \n (newline) character in an HTTP header.

CVE-2012-0360
Published: 2014-04-23
Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCtn22376.

Best of the Web