GDPR and Trust

The GDPR initiative is now a thing and implementation, as always, will throw up its own curves.

Here’s what is becoming apparent however: in the age of the data grab, companies grabbed data first and tried to work out what to do with it afterwards.

The fact that they had no idea what data they needed in the first instance shows that they hadn’t worked out what they were doing exactly or what they wanted to do with their customers. The fact that they grabbed all data, forever, means they also were less than transparent in doing so.

Now the biggest of them have to workout where that data is, why, who has access to it, who can have access to it, why, and tell their customers about it so they can decide if that’s OK. There are customers who are finding out for the very first time that there is data about them stored in some database on a site they stopped visiting ten years ago.

It would have been way easier of course to have been upfront about everything and made the journey into the data age a co-shared one, building mutual trust along the way. That’s a more sensible, human approach. But that’s the wisdom that comes with retrospect.

