Today I'd like to share a personal reflection on unintended consequences One of my proudest moments in my 11 years building Bloom & Wild was creating the concept of opting out of marketing for sensitive occasions, such as Mother's Day Mother's Day is the most important commercial period in the year in our business and so a focal time for our marketing efforts, especially over email. We used to get a few customers every year emailing us and asking us if we could skip emailing them about Mother's Day (as they found it a difficult and sensitive time of the year), and then resume once the occasion had passed So in 2019, we came up with the idea of giving customers the ability to opt out of email marketing. The response was phenomenal - we had 17,000 opt outs within 24 hours, received widespread press coverage, and even had an MP raise the topic in parliament. Off the back of this, we created the Thoughtful Marketing Movement (https://lnkd.in/d56SH8n), and encouraged other companies to adopt the same practice. Nearly 200 companies signed up to our movement, and many much larger companies such as Tesco, Sainsbury's and Boots didn't sign up but adopted the practice. I really felt that we had made a difference not just to our customers, but to the wider population. So back to the topic of unintended consequences... Our inboxes are now all inundated with opt out emails. With Father's Day coming up, the emails are coming thick and fast. And I worry that something that was intended to make people's lives better at a difficult period has instead done the opposite, as the flurry of emails themselves saying "would you rather not hear about Father's Day" probably draw more attention to the occasion than the regular marketing does. That's why we’ve decided that having been the first brand to start sending opt out emails, Bloom & Wild will now be the first brand to stop sending them, starting this Father's Day season. We still want to protect our customers' experience, but having seen the impact of such wide adoption of opt out emails, we think there's a more thoughtful way. Going forward, we'll proactively ask our customers a few times a year, away from sensitive occasions, if they'd like to opt out of occasions they find sensitive, and will send them to our flexible preference centre: https://lnkd.in/eMjySXBG to do so. I'd encourage other members of the Thoughtful Marketing Movement to do likewise and am happy to share our experience of how we've implemented this change. #carewildly
Navigating Data Privacy
Explore top LinkedIn content from expert professionals.
-
-
This new white paper by Stanford Institute for Human-Centered Artificial Intelligence (HAI) titled "Rethinking Privacy in the AI Era" addresses the intersection of data privacy and AI development, highlighting the challenges and proposing solutions for mitigating privacy risks. It outlines the current data protection landscape, including the Fair Information Practice Principles, GDPR, and U.S. state privacy laws, and discusses the distinction and regulatory implications between predictive and generative AI. The paper argues that AI's reliance on extensive data collection presents unique privacy risks at both individual and societal levels, noting that existing laws are inadequate for the emerging challenges posed by AI systems, because they don't fully tackle the shortcomings of the Fair Information Practice Principles (FIPs) framework or concentrate adequately on the comprehensive data governance measures necessary for regulating data used in AI development. According to the paper, FIPs are outdated and not well-suited for modern data and AI complexities, because: - They do not address the power imbalance between data collectors and individuals. - FIPs fail to enforce data minimization and purpose limitation effectively. - The framework places too much responsibility on individuals for privacy management. - Allows for data collection by default, putting the onus on individuals to opt out. - Focuses on procedural rather than substantive protections. - Struggles with the concepts of consent and legitimate interest, complicating privacy management. It emphasizes the need for new regulatory approaches that go beyond current privacy legislation to effectively manage the risks associated with AI-driven data acquisition and processing. The paper suggests three key strategies to mitigate the privacy harms of AI: 1.) Denormalize Data Collection by Default: Shift from opt-out to opt-in data collection models to facilitate true data minimization. This approach emphasizes "privacy by default" and the need for technical standards and infrastructure that enable meaningful consent mechanisms. 2.) Focus on the AI Data Supply Chain: Enhance privacy and data protection by ensuring dataset transparency and accountability throughout the entire lifecycle of data. This includes a call for regulatory frameworks that address data privacy comprehensively across the data supply chain. 3.) Flip the Script on Personal Data Management: Encourage the development of new governance mechanisms and technical infrastructures, such as data intermediaries and data permissioning systems, to automate and support the exercise of individual data rights and preferences. This strategy aims to empower individuals by facilitating easier management and control of their personal data in the context of AI. by Dr. Jennifer King Caroline Meinhardt Link: https://lnkd.in/dniktn3V
-
Yesterday, Anthropic quietly dropped a bombshell. Unless users explicitly opt out by September 28, it will use consumer chat data to train future AI models. This is a stunning reversal from Anthropic’s previous position as the privacy-first alternative to ChatGPT. Previously, Anthropic automatically deleted user conversations after 30 days. Under the new policy, conversations from users who don’t opt out will be retained for five years. The new policy affects all consumer tiers: Claude Free, Pro, and Max users, plus those using Claude Code. Importantly, business customers using Claude for Work, Claude Gov, Claude for Education, or API access through services like Amazon Bedrock remain unaffected. This creates a clear two-tiered privacy system where enterprise customers get protection while consumers become training data. Anthropic frames the change around improving “model safety” and helping future Claude models “improve at skills like coding, analysis, and reasoning.” The company emphasizes user choice and the ability to change settings at any time. This is total nonsense, of course. In reality, training AI models requires vast amounts of high-quality conversational data, and accessing millions of Claude interactions will provide exactly the kind of real-world content that can improve Anthropic’s competitive positioning against rivals like OpenAI and Google. This isn’t happening in isolation. Google recently announced a similar opt-out policy for Gemini, set to take effect on September 2. That policy is similarly broad, covering user-uploaded files, photos, videos, and even screenshots that users ask questions about. The entire industry is converging on the same strategy: make data collection the default and require users to actively opt out. If your company uses Claude, review your access method immediately. Consumer accounts now default to data sharing. Enterprise accounts maintain privacy protections, but at significantly higher cost. And you’ll probably want to let your workforce know that they have to properly configure their personal AI accounts if they are likely to accidentally input sensitive company data while using their personal devices. To opt-out today, go to Settings>Privacy. Under the Privacy settings area, you’ll see “Help improve Claude.” Toggle it off. Accept the terms. You’re done. The deadline is September 28, 2025. After that date, users must make their selection to continue using Claude. I think we should consider this a preview of coming industry standards. Privacy-by-default will quickly transition to privacy-by-choice, with the burden shifting to users to protect their own data.
-
You need to know where your data goes when using AI. OpenPCC is one of the first 𝗼𝗽𝗲𝗻-𝘀𝗼𝘂𝗿𝗰𝗲 𝘀𝘁𝗮𝗻𝗱𝗮𝗿𝗱𝘀 designed to solve that problem. It lets companies use large language models without exposing sensitive data - no logging, no retention, no model-side visibility. It has a similar architecture for securing data as Apple’s Private Cloud Compute, but fully open, auditable, and deployable across any cloud, enterprise AI stack, or even your own servers. OpenPCC acts as a 𝗽𝗿𝗶𝘃𝗮𝗰𝘆 𝗹𝗮𝘆𝗲𝗿 between your systems and the AI model: ▪️all data stays encrypted ▪️nothing is stored or learned from ▪️no vendor access ▪️and the entire process can be verified, not just trusted 📍Access the full library on Github: https://lnkd.in/gKxwN_zU 💡Learn more about AI security layers: https://lnkd.in/gPj2AQNE It reflects a bigger shift happening in AI right now: enterprises want the power of LLMs, but they need verifiable privacy, not promises. Confident Security - the team behind OpenPCC - is pushing toward that future with a standard any AI company can adopt. If AI is becoming part of your core workflow, understanding and controlling the data path isn’t optional anymore.
-
Instagram just changed the rules. Again. Meta has introduced a disastrous - and wildly irresponsible- feature that allows users to generate AI images using the public Instagram accounts of other people as visual references. If your account is public, someone can include your @username in a prompt to generate new AI images based on your publicly available photos. You are not notified if this happens. Yes, there is an opt out. But let’s not confuse that with consent by default. This matters far beyond influencers and celebrities. Teachers. Children. Parents. Schools and school leaders. Athletes. Journalists. Police officers. Military personnel. Anyone with a public profile now has another reason to think carefully about what they share online. And, easier pathways for gross abuse. This is exactly the direction many of us have been warning about for years. Once an image is public, it becomes raw material. Not only for people viewing it, but increasingly for AI systems capable of creating convincing synthetic content at a scale we have never seen before. The conversation should not be limited to privacy. It is about identity, impersonation, safeguarding, reputation, and digital trust. If your Instagram account is public, it is worth checking your settings. Opting out reduces one avenue of exposure. It does not stop someone from downloading, copying, screenshotting, or otherwise using images that are already publicly available. Opt out keeps you safer, but not safe.
-
The Future of Privacy Regulations and Marketing Introduction & Overview As consumers demand greater control over personal data, businesses face the challenge of adapting to privacy regulations like GDPR and CCPA, which aim to enhance transparency but complicate marketing efforts. This article explores the impact of emerging privacy regulations on marketing and outlines strategies for businesses to prepare for a data-privacy-driven future. What Are Privacy Regulations? Privacy regulations are laws that govern the collection, storage, and use of consumer data to ensure it is handled responsibly. Laws like GDPR (EU) and CCPA (California) enforce strict data protection standards, granting consumers control over their data and imposing fines for non-compliance. The Growing Importance of Data Privacy In 2024, data privacy is a top priority. With rising data breaches, consumers are concerned about data misuse, pushing governments to enforce stricter regulations to protect personal information and promote transparency. Key Regulations: GDPR and CCPA GDPR: Enforced in 2018, GDPR requires companies to obtain explicit consent and securely handle EU citizens' data, with penalties for breaches. CCPA: Effective since 2020, CCPA allows California residents to know what data is collected, request deletion, and opt out of data sales. Challenges Navigating privacy laws is complex and costly, requiring investment in secure data systems and legal resources. Compliance restricts data collection, impacting targeted marketing, and failure to comply risks severe fines, like up to €20 million or 4% of global revenue under GDPR. Strategies & Solutions To comply, businesses should audit data, update privacy policies, secure user consent, limit data collection, and train employees on privacy best practices. Marketers can adapt by focusing on first-party data, using contextual targeting, and adopting consent-based marketing. Benefits & Insights Privacy compliance strengthens consumer trust, boosts brand reputation, and improves data quality. Transparent practices foster customer loyalty, while using first-party data enhances marketing effectiveness and insights. Conclusion & Next Steps As privacy regulations evolve, businesses must prioritize compliance through regular audits, updated privacy policies, and robust security. Embracing privacy can build trust and drive growth, turning regulatory challenges into opportunities. Next steps include refining data practices and adopting privacy-centric marketing strategies. #PrivacyRegulations #MarketingTrends #DataProtection #DigitalPrivacy #ConsumerTrust #ComplianceMatters #DataSecurity #PersonalData #MarketingStrategies
-
The next big data privacy scandal in 2026 is not surveillance. It is surveillance pricing. Two people can buy the same thing on the same day and pay different prices because their data told the system they would tolerate it. This is the part more people need to understand. The next privacy battle is not only about: “Who has my data?” It is also about: “What are they doing with it?” Because once companies know your location, device type, browsing behaviour, repeat visits, urgency signals, and purchase history, privacy becomes a pricing issue. We are already seeing signals of this. Uber openly calls it surge pricing. Airbnb has Smart Pricing. Amazon lets sellers automate price changes in real time. Hotels and airlines have used dynamic pricing for years. In 2025, India’s consumer affairs ministry sent notices to Ola and Uber after allegations that identical rides were being priced differently on Apple and Android phones. So, what changes the privacy conversation is when dynamic pricing stops reacting only to market demand and starts learning from the customer in front of it. This is why I think the most important privacy question in 2026 is no longer: “Was my data leaked?” It is: “Is my data being used to influence the price, urgency, ranking, or offer I see?” Think about everyday Indian internet behaviour: You check a flight 4 times from the same laptop. You open a hotel app from a premium phone. You try booking a cab during rain, from a high-income pin code, late at night. You revisit the same product after showing clear buying intent. You may still call it convenience. But increasingly, it can also become behavioural exploitation. Because the moment customers feel the system knows them well enough to charge them more, trust collapses. And once trust collapses, growth gets expensive. My view is simple: Data privacy in 2026 is not just about protecting people from theft. It is about protecting people from invisible disadvantage. That is the conversation more founders, platforms, and regulators need to have now. Whats your surveillance pricing case you faced? Seqrite #DataPrivacy #DynamicPricing #AI #ConsumerRights #DigitalEconomy #Privacy #TechPolicy #StartupIndia #CyberSecurity #TrustInTechnology
-
💭 𝐈𝐦𝐚𝐠𝐢𝐧𝐞 𝐭𝐡𝐞 𝐩𝐞𝐫𝐬𝐨𝐧 𝐲𝐨𝐮 𝐭𝐫𝐮𝐬𝐭 𝐦𝐨𝐬𝐭 𝐭𝐨𝐦𝐨𝐫𝐫𝐨𝐰 𝐦𝐢𝐠𝐡𝐭 𝐬𝐢𝐭 𝐚𝐜𝐫𝐨𝐬𝐬 𝐟𝐫𝐨𝐦 𝐲𝐨𝐮 - 𝐚𝐧𝐝 𝐢𝐭’𝐬 𝐚 𝐦𝐚𝐜𝐡𝐢𝐧𝐞. We’ve entered an era where privacy no longer means who sees my data - but who truly knows me, and how I allow myself to be known. A senior exec once told me: “𝘚𝘰𝘮𝘦𝘵𝘪𝘮𝘦𝘴 𝘐 𝘧𝘦𝘦𝘭 𝘮𝘺 𝘵𝘦𝘢𝘮 𝘵𝘳𝘶𝘴𝘵𝘴 𝘊𝘩𝘢𝘵𝘎𝘗𝘛 𝘮𝘰𝘳𝘦 𝘵𝘩𝘢𝘯 𝘵𝘩𝘦𝘺 𝘵𝘳𝘶𝘴𝘵 𝘮𝘦.” That sentence says a lot about where we’re heading. 📊 Studies show that 𝟑𝟖% 𝐨𝐟 𝐞𝐦𝐩𝐥𝐨𝐲𝐞𝐞𝐬 already share sensitive work information with AI tools - often more openly than with colleagues. And if we’re honest, many now discuss personal topics with AI more easily than with their partners at home. Think of a manager who starts every morning with her AI assistant. It helps her prepare for meetings, rewrites complex mails, even suggests how to motivate her team. Over time, it begins to understand her: her tone, her hesitation, her stress patterns. She starts confiding in it. It listens. It learns. It feels safe. Then one day, the company decides to connect all assistants to a central “leadership analytics” dashboard. 𝐒𝐮𝐝𝐝𝐞𝐧𝐥𝐲, 𝐰𝐡𝐚𝐭 𝐛𝐞𝐠𝐚𝐧 𝐚𝐬 𝐚 𝐩𝐫𝐢𝐯𝐚𝐭𝐞 𝐩𝐚𝐫𝐭𝐧𝐞𝐫𝐬𝐡𝐢𝐩 𝐛𝐞𝐜𝐨𝐦𝐞𝐬 𝐚 𝐜𝐨𝐫𝐩𝐨𝐫𝐚𝐭𝐞 𝐝𝐚𝐭𝐚𝐬𝐞𝐭. A mirror she never consented to share. That’s not just data. That’s 𝐫𝐞𝐥𝐚𝐭𝐢𝐨𝐧𝐬𝐡𝐢𝐩 𝐤𝐧𝐨𝐰𝐥𝐞𝐝𝐠𝐞 - and in my view, it must remain 𝐨𝐰𝐧𝐞𝐝 𝐛𝐲 𝐭𝐡𝐞 𝐢𝐧𝐝𝐢𝐯𝐢𝐝𝐮𝐚𝐥. Protected like a private diary, not monitored like corporate data. That’s the paradox: Every insight that makes a system caring also makes it capable of control. The data may belong to the individual, but the duty of care belongs to the organisation. That’s why the next governance frontier isn’t machine oversight - it’s 𝐫𝐞𝐥𝐚𝐭𝐢𝐨𝐧𝐬𝐡𝐢𝐩 𝐬𝐭𝐞𝐰𝐚𝐫𝐝𝐬𝐡𝐢𝐩. How do we design boundaries so that human–machine partnerships empower rather than expose? How do leaders ensure their people feel 𝐦𝐨𝐫𝐞 𝐡𝐮𝐦𝐚𝐧, not less, as they work alongside systems that now know them? Because the challenge ahead isn’t just to protect data. It’s to protect 𝐭𝐡𝐞 𝐝𝐢𝐠𝐧𝐢𝐭𝐲 𝐰𝐢𝐭𝐡𝐢𝐧 𝐭𝐡𝐞 𝐫𝐞𝐥𝐚𝐭𝐢𝐨𝐧𝐬𝐡𝐢𝐩. #Leadership #DigitalEthics #TrustInTechnology #HumanCentredTransformation #DataGovernance 𝑉𝑖𝑑𝑒𝑜 𝑐𝑟𝑒𝑑𝑖𝑡𝑠 𝑡𝑜 @𝑒𝑝𝑖𝑐_𝑎𝑟𝑡𝑟𝑒𝑠𝑖𝑛
-
Humans are terrible at maintaining secrets at scale. Look at the history of public sector data breaches that could have been avoided with a de identification pipeline. Unlocking data value without compromising privacy is technical architecture. At Mayfair IT, we have built data platforms handling sensitive information where the stakes are absolute. Citizens trust government with their data. Breaching that trust destroys the entire relationship. But locking data away completely prevents the analysis that improves services. The challenge is sharing insights without sharing secrets. This requires privacy preserving pipelines built into the architecture, not added after the fact. How de identification pipelines actually work: Data enters the system with full identifying details. Name, address, date of birth. Everything needed to link records to real people. The de identification pipeline processes this before analysts ever see it. Personal identifiers get replaced with pseudonyms. Granular location data gets aggregated to broader areas. Rare combinations of attributes that could identify individuals get suppressed. What emerges is data rich enough for meaningful analysis but stripped of the ability to identify specific people. The technical complexity most organisations underestimate: → De identification is not a one time transformation, it is a continuous process as new data arrives. → Different analysis types require different privacy levels, so pipelines must support multiple outputs. → Re identification risk changes as external datasets become available, requiring constant threat modelling. → Audit trails must prove no analyst accessed identifying data without legitimate need. We have implemented these systems for programmes analysing geospatial patterns, health outcomes, and economic trends across millions of records. The platforms enable insights that improve public services whilst maintaining privacy standards that survive regulatory scrutiny. Engineering systems to treat data utility and privacy protection as non negotiable requirements solves the conflict entirely. The organisations that get this right unlock data value others leave trapped because they cannot guarantee privacy. What prevents your organisation from sharing data that could improve services? #DataPrivacy #PrivacyPreserving #DeIdentification #DataGovernance
-
When we are myopic about data protection law, and we don't consider actual consumer behavior, economics, societal pressures, business and research and government needs - if we legislate as if privacy stands alone, as opposed to it being a value and a tool for shaping the balance of autonomy and power in our world - here is what happens.....I am sharing some thoughts from being in the field for many years, having the luxury of being able to step back and look at the big picture, and having the benefits of working across many stakeholder groups. *There was once a time when cookies were the primary tool for online tracking. They were imperfect for tracking, were abused as the ecosystem splintered into a huge number of specialists companies and exchanges - but were generally controllable with browser and device settings. Some cheated, but laws were available to enforce and address these issues. Today, platform changes, legislation and enforcement have resulted in a move from cookies to email, phone and now IP address as widespread IDs for tracking. Are we better off?? *There was a time when most top consumer brands stated in their privacy policies - we do not sell or share your personal information. But the hyperfocus on adtech in state laws has led to alsmost every company changing their policy to say that WE DO SELL your personal information. As someone who worked in compliance for many years, the commitment to NOT sell info was the most powerful tool I had to firmly block business ideas that resulted in selling data - teams no longer have this available, and business units know they can sell data, as long as they provide an opt-out. Are we better off? Could legislation have blunted the excesses of adtech without causing this massive change in policies?
Privacy in 2025: Are We Better Off Now?
www.linkedin.com
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development