The whole world is waking up to a new reality. Privacy used to be a fundamental human right that we took for granted. Technically it still is, but the global Internet has made it easy to violate this right. Too easy as there is proof that many states and companies violate it extensively and blatantly. There’s many motives for this. Technical feasibility, commercial benefits, diplomatic and political advantages, fear of terrorism and last but not least, peoples’ lack of awareness.
The incentives to violate our privacy will not go away, but peoples’ awareness is certainly increasing. This is obvious now in the post-Snowden era. Customers start to ask how their service- and software providers guard their privacy, and make purchase decisions based on that.
Protecting our customers’ data has been F-Secure’s mission for more than 25 years. That’s why we are very worried about the current situation, and eager to raise awareness about it. But raising awareness is not enough. We also need to get our act together and make sure our own offering isn’t violating your privacy. It’s by the way a surprisingly complex task that affect all functions in a company. That’s why we have published nine privacy principles that guide our work to guard your privacy.
Let’s walk through the first 3 in this post. Stay tuned, the rest will be covered soon.
This is really the fundament of it all. Our goal is to provide you with products and services that create some value for you, but this is never done by violating your privacy. Quite the opposite, guarding your privacy is a central goal in many products. Many companies market “free” services, where the customer in reality pay by letting the provider utilize personal information. F-Secure is NOT one of them.
We handle your data in many ways, either by apps on your own device or uploaded to our services. But no matter how we get in touch with it, it is still YOUR data. We have no right to utilize it for our own purposes and we do not reserve such rights in legal-jargon user agreements that nobody reads or understands.
Your data, or data about you, may become accessible to us in several ways. You may upload it to our servers yourself. In this case it’s obvious that you are in full control of what data you transfer. Our products may also collect data to improve the service we offer, but you can opt out from much of this. Only a small part of the collected data is mandatory and not controlled by you. In short, we apply a strict minimalistic policy to automatic data uploads. We only fetch data if it’s needed to improve the service, we anonymize data when possible and we let you opt out if the data isn’t absolutely necessary.
That’s 3 fundamental privacy principles in our set of totally nine. Stay tuned, we will present the rest shortly.
This is part of a series of posts about what security experts think will happen…
December 30, 2015