## Customer Privacy and Consent Trends

Security teams have been focused on protecting their customers and their business for quite a while now, but the job is never finished. Bad actors are always finding new ways to exploit IT infrastructures, and they aren’t interested in slowing down. As digital commerce and operations have shifted online, so have the bad actors. Nobody is holding up banks anymore; all the fraud now happens online.

To make matters a bit more complicated, [customer privacy and consent](https://www.pingidentity.com/en/solution/privacy-consent.html) have also grown in demand, and they often fall on security teams to implement. This adds yet another set of requirements that these teams have to learn, implement, track, and update, often requiring a consent management platform (CMP). And it’s not a simple switch that can be turned on. Privacy and consent requirements vary by region, regulatory standards, customer preferences, and other factors.

Long gone are the days when convenience was the main customer driver. “You’d like access to all of my personal data for one-click access? Sure, why not, what’s the harm?” Do you still wonder what happens to those pictures you upload to social media sites and who ultimately owns them? For the longest time, it seemed like social media companies owned them, but fortunately, this trend is starting to shift as customer concern about privacy and data collection continues to grow. And the main driver of this shift is often companies’ bottom line. Customers don’t do business with companies they don’t trust, especially when there are numerous substitutions available just a few clicks away.

Did you know?

71%

[of consumers would stop doing business with a company for giving away their sensitive data without permission (PWC)](https://www.fisglobal.com/-/media/fisglobal/worldpay/docs/insights/consumer-intelligence-series-protectme.pdf)

## Why Do Privacy and Consent Matter More Today?

Customer preferences are always changing, and it’s vital to keep up with them. Otherwise, you might lose touch with what your customers expect from you as a business. Consumers speak with their wallets and, sometimes, reviews. So why do customers care about privacy and consent all of a sudden? Well, there are two reasons: increased phishing and annoying marketing. Plus, governments around the world are also stepping in big time with privacy laws that aim to protect their citizens.

### Increased Phishing

Data breaches are on the rise, but they’re often spun as harmless since no credit card information or social security numbers are stolen, which means no financial harm is done. But instead, breaches leave personal customer information in the hands of bad actors, who then use that data for more effective phishing or try to access company accounts by using personal customer data to bypass security verification steps. Personalized phishing attempts are more effective. Customer personal information being shared with so many parties has increased the attack surface on customer data, putting customers at risk and making them more susceptible to fraud.

Did you know?

[The rate of phishing attacks has increased by 61% compared with 2021 (CNBC)](https://www.cnbc.com/2023/01/07/phishing-attacks-are-increasing-and-getting-more-sophisticated.html)

### Annoying Marketing

With so many unauthorized third parties having access to customer data, unwanted marketing outreach and annoying marketing are prevalent. You can barely call it marketing since it requires little thought and creativity. Is it cheap marketing or just spam? Fortunately, many services we use today have spam blockers, but some spam still gets through. Have you ever wondered, how did this service get my email? How did this telemarketer get my phone number? Why am I getting all these unwanted texts? It’s probably because your personal data was shared with other parties without your consent. It’d be nice to have the ability to see who has access to your data and possibly even revoke that access from certain parties, right? We’re not there yet, but that’s the goal. Also, how long are cookie consent and pop-ups going to last? They’re on their last legs, right?

Did you know?

91%

[of people say ads are more intrusive today than two years ago (HUBS)](https://blog.hubspot.com/marketing/why-people-block-ads-and-what-it-means-for-marketers-and-advertisers?utm_campaign=SOI%202016&utm_source=Partner)

### Data Privacy Regulations

To accelerate the protection of customer privacy, governments are stepping in with privacy laws such as GDPR in the EU, CCPA in California, CDR in Australia, and many others. Governments have started to require organizations to implement privacy and consent management tools into their websites and mobile apps. If not, then hefty fines, penalties, and bad press follow. Data privacy laws vary a little but have the same goal in mind. Also, new laws are often added that require organizations to be flexible in order to stay compliant. We’ll cover a few of these privacy regulations in more detail later in the blog. First, though, let's learn about a few cases where companies didn’t have the best privacy and consent practices, got caught, and were penalized for it.

## Examples of Poor Privacy and Consent Practices

Italian energy company [Enel Energia was hit with a significant fine of €26 million](https://www.complianceweek.com/regulatory-enforcement/italian-dpa-fines-enel-energia-301m-under-gdpr-over-telemarketing-practices/31274.article) by the Italian data protection authority, Garante, for violations of GDPR. Enel Energia was cited for hundreds of complaints about unsolicited sales calls made without customer consent. The calls targeted users not listed in the phone directory or those who opted out of sales promotions. Additionally, the company delayed responding to customer requests for access to personal data and objections to data processing for marketing purposes, with some feedback disappearing entirely.

[Instagram, owned by Meta, was fined €405 million](https://www.bbc.com/news/technology-62800884) by Irish regulators for violating children's privacy. The fine resulted from a long-running complaint about the lack of protection of children's data, particularly their phone numbers and email addresses. Some children reportedly upgraded to business accounts unknowingly, which made more of their data public. Child-safety-online advocates, such as the National Society for the Prevention of Cruelty to Children (NSPCC), view this fine as significant, emphasizing how effective enforcement can protect children and their privacy on social media.

[Zoom Video Communications reached an $85 million settlement](https://www.reuters.com/technology/zoom-reaches-85-mln-settlement-lawsuit-over-user-privacy-zoombombing-2021-08-01/) to resolve a class-action lawsuit related to user privacy issues and "zoombombing," which is when unauthorized individuals disrupt video meetings. The lawsuit accused Zoom of sharing user data with Facebook and failing to prevent zoombombing. As part of the settlement, Zoom agreed to implement changes to improve data privacy and security, including additional encryption measures and clearer information provided to users about data-sharing practices.

## Regional Regulatory Standards

Customer identity and access management (CIAM) solutions provide key capabilities that help you not only comply with regulatory standards but fundamentally transform how you see your customers. CIAM helps you turn the challenges of adhering to privacy regulations, consent processes, data access and authorization, and application security into a unique opportunity to build customer trust.

**European Union’s GDPR**

The [General Data Protection Regulation (GDPR)](https://gdpr.eu/) has been one of the most significant worldwide pieces of consent collection and data privacy legislation for more than 20 years. By establishing strict controls on how organizations handle personal and sensitive information, GDPR ups the ante on data protection. The EU regulation imposes a series of technical and other requirements on any organization that sells or markets to EU citizens, even non-EU entities, and the consequences for non-compliance are steep.

Leading organizations see much of GDPR compliance as an extension of their existing customer experience or “know your customer” initiatives. This approach has the significant advantage of moving beyond compliance to improved trust and engagement with your organization’s most valuable asset–your customers–and toward transparency regarding the use of personal customer information.

No matter where your organization is located, if you market or sell to EU individuals, or if you collect or process EU citizen data, your organization must be GDPR-compliant or risk facing hefty fines: up to 4% of your global annual revenue or €20 million, whichever is greater. And keep in mind that personal data is defined very broadly. For instance, even if an EU citizen does nothing more than browse your website, that browsing data may be considered personal data and therefore require user consent.

**California’s CCPA**

[California Consumer Privacy Act (CCPA)](https://oag.ca.gov/privacy/ccpa) grants consumers more control over the information businesses collect, and it imposes penalties on businesses that do not comply. No matter where your company is located, you are regulated by CCPA if you do business in California and meet at least one of the three following criteria:

- You’re a for-profit company with annual gross revenues of at least $25 million
- You’re a business that buys, receives, sells, or shares the personal information of 50,000 or more consumers, households, or devices
- You’re an organization that gets at least 50% of your annual revenue from selling consumers’ personal information

Failing to fix any violations within 30 days may result in significant financial liability as CCPA grants both a civil and a private right of action. With regards to the former, the California Attorney General may bring an action against a company for up to $2,500 per negligent violation, and the fine increases to $7,500 per intentional violation. Additionally, the private right of action grants citizens the right to sue for statutory damages of $100-$750 per data breach incident if a company fails to maintain reasonable security.

CCPA protects consumers who are California residents by giving them the right to access and control their personally identifiable information (PII) that companies collect, store, and sell. PII is broadly defined as any information that can be linked to a particular consumer or household. This includes identifiers like name and address as well as browsing history, behavioral data, and more, but it does not include information that has been de-identified. CCPA goes beyond the PII definition imposed by GDPR to include household information as well as individual consumer information. CCPA requirements are spelled out in the legislation’s articles, and many of these articles relate to how data is collected, stored, accessed, modified, transported, secured, and erased.

**Australia’s CDR**

[Consumer Data Right (CDR) in Australia](https://www.cdr.gov.au/what-is-cdr) is a regulatory framework that aims to provide consumers with greater control over their personal data and enable them to securely share it with trusted third parties. The CDR has been introduced in the banking sector and is being extended to other sectors, such as energy and telecommunications. The primary points of CRD are:

- **Data Access.** Data holders, which are usually businesses that hold consumer data, are required to provide consumers with easy-to-use mechanisms to access and share their data securely. They must comply with strict privacy and security requirements to protect consumer data from unauthorized access and misuse.

- **Privacy.** The CDR emphasizes robust privacy protections to ensure that consumers have control over their data. It incorporates principles of data minimization, consent, and purpose limitation, which means data can only be used for the specific purpose it was shared for.

- **Consent.** CDR requires explicit and informed consent from consumers before sharing their data with accredited data recipients. Consumers must be fully aware of what data they are sharing, with whom, and for what purpose.

- **Individual Rights.** Consumers have the right to access specific categories of their data, such as transaction history, account information, and product usage data. Consumers can then share this data with accredited third-party providers they trust.

- **Incident Reporting.** Both data holders and accredited data recipients have obligations to report any data breaches promptly. This includes notifying the affected individuals and the Australian Information Commissioner.

**Brazil’s LGPD**

[Brazil's General Data Protection Law (LGPD)](https://usercentrics.com/knowledge-hub/brazil-lgpd-general-data-protection-law-overview/) is a comprehensive data protection legislation that governs the processing of personal data in Brazil. The main objective of the LGPD is to protect individuals' fundamental rights to privacy and their personal data and to ensure the transparency and accountability of organizations that handle such data. The regulations apply to any organization that processes personal data, regardless of where the organization is based, as long as the data processing activities are related to individuals located in Brazil or data collected within the country. Non-compliance with the LGPD can result in significant fines and penalties, which can range from warnings to fines of up to 2% of the organization's revenue, subject to a cap of 50 million Brazilian reals per violation. The primary aspects of LGPD are:

- **Protection of All Data Types.** Covers all types of personal data, which include any information that can identify an individual directly or indirectly. This includes names, identification numbers, IP addresses, geolocation data, biometric data, and any other information that could be used to identify a person.

- **Data Security and Privacy.** Organizations are required to implement security measures to protect personal data from unauthorized access, breaches, and other security incidents.

- **Cross-Border Data Transfers.** If personal data is transferred outside of Brazil, it must be done in compliance with the LGPD. Adequate safeguards or specific legal mechanisms, such as standard contractual clauses, must be used to ensure the protection of personal data during cross-border transfers.

- **Consent.**To process personal data lawfully, organizations must have a valid legal basis, such as obtaining explicit consent from the data subjects, fulfilling a contract, complying with a legal obligation, protecting the data subject's vital interests, or fulfilling the organization's legitimate interests.

- **Individual Rights.**The LGPD grants data subjects various rights, including the right to access their personal data, correct inaccurate information, delete data, and obtain information about the data processing activities performed by the organization.

## Benefits of Good Privacy and Consent Practices

There are quite a few benefits to being a good steward of customer data. Avoiding hefty fines is a good motivator to get things started, but there’s more to it than just abiding by the law. It’s similar to providing good customer service. If your customers enjoy their experience, then they’ll come back and spend more money, and maybe even recommend your brand to their friends.

**Customer Trust and Loyalty.** Believe it or not, your customers genuinely care about data privacy – it's a high priority for them. Studies reveal that unauthorized data sharing is a major turn-off, even surpassing the fear of data breaches. And guess what tops their tech concerns? That's right, data privacy takes the crown. It’s like finding a good car mechanic. If you’re lucky to find a mechanic you trust, you’ll be a loyal customer for a lifetime.

### See Video Transcript Video Transcript

Hi, it's Lauren Russin from Ping.  
I'm here with Christian.  
Christian, do you want to introduce yourself?  
Yeah, absolutely.  
So I'm Christian Al Singh.  
I run digital identity for Accenture across Europe.  
Yeah, and I run our Product Management group here at Ping Identity.  
Christian and I are here to, you know, I think invite you into our conversation we've been Having fun for a little while, and it's real around how I think we've seen.  
The way organizations are looking at consumer data, and it’s really evolved.  
I mean, it's now to the point where I think consumers really have no recourse for Protecting the privacy of their data, and it seems, it seems almost kind of an abysmal state.  
Yeah, absolutely, I think we're getting to a point where Big Data is almost like the Consumer has become a means to an end.  
The consumer has become Become a part of Something bigger, uh, which is effectively supporting big corporations, Making money, supporting advertisers, you know, direct their advertisement, But the consumer has been lost a little bit in this.  
Yeah.  
I think, you know, consumers expect something.  
I mean, they really are kind of at their wits' end, and I remember reading a report or, It was really a survey that The Guardian did, and they said 83% of the consumers really Expected organizations to protect privacy, actually control their data.  
And I thought that was kind of an interesting statistic.  
Hm.  
No, absolutely.  
I think, um, I was on a panel For cybersecurity at, at a point in time a while ago.  
And I talked about how consumers wanted to have control of their data, and actually somebody Questioned it and said, look, consumers got nothing, they've got no recalls.  
Um, what I'm seeing though, what I think is happening at the moment is that we're actually Seeing, we’re seeing that Big Tech and corporations and advertisers and digital Advertisers that they might be getting a bit greedy and, And frankly, the legitimacy of what they're doing is starting to, to, to fall a bit and regulators are starting to see this governments, State governments, and so forth.  
So we're seeing a lot of regulation at the moment, which is an attempt to try and counter the, the balance of power there between Corporations and the individuals.  
Yeah, no, that makes sense.  
I mean, it's almost like, You know, the regulations are signaling to the organizations to say, Hey, you've got to do something about this, and you know, You think about it.  
I mean, if organizations continue as is, Don't comply with regulations, you know, really what they're going to lose their consumer trust.  
And I think that translates into losing business.  
I mean consumers aren’t going to use them, they’ll go to somebody else who actually has their personal data in mind.  
Mm.  
Yeah, and I think, look, it really opens, like, it starts to open a, An opportunity, right?  
And it used to be that it was just, You know, I owe my shareholders a share to make more money.  
But, but I think a lot of proactive and progressive organizations have started moving Beyond that and looking, well, what's the impact we have on society, What's the impact we have on our customers, on, you know, On the exposed individuals in society and so forth.  
And I do think that there're a number of progressive organizations who are starting to Say, well, actually we need to be a bit on our customers' side on this.  
Um, so, so that's definitely something that's happening, it's not everywhere, But it is happening.  
You can tell I read a lot of reports and a lot of articles because it's certainly looking for Data to help make some of these decisions, and you know, I remember a report that Forrester did recently and they were talking about some of the top Trends that they were seeing, and enterprises are aware of this issue.  
And Forrester said it's roughly 66%.  
Many of their consumers now demand some change.  
They're demanding that they actually provide some kind of control or, Or at least support some of the regulations for protecting their data.  
So I think it is important, uh, but is there things that organizations can do, Do you think?  
There's definitely an opportunity for Organizations to start thinking about that customer relationship at every level, Much more holistically.  
You know, however much I like lawyers, you can’t just have your compliance people and your Lawyers, um, defining what it looks like from a security and privacy point of view.  
You should actually listen to your customers, You should be talking to your customers, Do focus group, read the reports that you mentioned.  
Um, so, so absolutely move away from this letter of the law approach and actually try and Figure out what makes a difference to the customers and the, and the psychological experience they have of their interaction with you, With your brand, your website, your channels, and so forth.  
Yeah, it’s such a good point.  
Well, I think customers or consumers really are Expecting more from these organizations and.  
Ping, we put it in simple terms, and if organizations can delight as well as protect Their consumer data, they win.  
And so you consider if they were just Protecting, that would satisfy many customers and consumers to say, "My data that I hold." Important, that I think is valuable as being protected.  
But we're starting to see some of them say, well, I'm happy if you use my data to create a Delightful experience.  
I love that moment where they, It feels like they know me, but more so they know what to protect about me and use that in a Positive way.  
So I think that is a good key.  
Are you seeing some of the same things, in your experience?  
Yeah, I was involved in some, some research for a specific client in the, In the financial services sector, and it was really interesting because, What we were told was they didn't actually mind security; they didn't mind the friction, But they wanted the friction when, when they felt it was very important.  
So paying like the first deposit for a, for a house feels very important.  
You actually want a lot of checks.  
But, you know, moving between channels when you're interacting with your bank, Moving from.  
A call center to an app shouldn't be full of Friction because it's a relatively low, low or perceived relatively low-risk action, Right?  
So, so organizations can engage in that space.  
And I think, I think there's a big opportunity there.  
Yeah, no, it, it is.  
I, I think being in the identity and access Management business is exciting right now because we see, You know, identity is that cornerstone.  
It's really that foundational element that, you know, allows companies to make those choices.  
I mean, you set policy and leverage, knowing more about that user and knowing information About that user, too either, as you said, increase the friction.  
For those high-value transactions and then reduce the friction when it's not as high value Or it's a lower-risk transaction and, um, it's interesting, you know, It's that if I know you better and I am able to understand what the consumer wants, I can personalize that experience and Identity Management really helps to do that.  
I think.  
So, Christian, you know, when we look at Identity and access management as that foundation, I mean, How does it apply?  
Like, how can we use it, I think, To improve that customer experience, essentially delight and protect them.  
And, uh, make sure that organizations are really, you know, Better protecting that consumer data.  
That's a, that's a good question.  
So from my point of view.  
You know, I think too many organizations look at at items and access management as a single sign-on problem.  
It's not, it's a, it's a whole customer Experience and a whole customer journey that you need to understand.  
And there's definitely, there's definitely a return on investment when you're actually Starting to invest in the user experience.  
Um, you start to invest in the, I would say the feedback that a customer gets around security Actions, whether it's step-up authentication, you know, Um, extra authorization for high-profile, uh, transactions and so forth.  
Um, but there's also a real tangible benefit that can be achieved in terms of actually Reducing your risk, reducing your, your exposure both to fines, Uh, with GDPR, and similar regulations, but certainly also in the reduction of, of risk of actually being hacked, having scandals, you know, Um, the reputational risk that your organization is, is subject to, um, post a breach, right?  
These are very significant challenges that all organizations should take seriously.  
Yeah, no, I think it's great.  
I mean, it’s really, they're accountable now.  
Um, for their consumer data, and I think, you know, we see quite often, You know, in the industry there's almost a social awareness.  
It's, you know, Personal Data now isn't just to collect for your own use.  
You actually have to.  
You know, be accountable, I think, for what, um, you know, That consumer data is used for and really, you know, help protect, You know, their consumers.  
I think it's, you know, If they don't, they're going to lose business.  
I don't know what you think about that, that notion of accountability.  
You know, do you think organizations and really those leaders of those organizations are now Accountable for that data?  
Well, I think it's really interesting because accountability and legitimacy, I think they are very, very close to each other.  
Legitimacy is sort of the macro, macro view of what an organization should do.  
Um, accountability is in every interaction, Are we actually helping our customer?  
Uh, our, you know, whether it's a citizen, a customer, whatever it might be, Consumer, are we actually aiding them, but also are we, Are we doing the right thing by them, and that's where accountability comes in.  
And I think, you know, for me this is really all about.  
Becoming the steward of your customers' data, right, stewardship of customer data is Absolutely where we want to go, um, and like I said, some organizations aren't ready, but the progressive organizations, the, the leaders in, In customer, um, in various customer businesses should absolutely be focusing on this.  
Yeah, I love that concept.  
I mean, what if Leaders did become the stewards Of that data, you know, how important would that be?  
And I think really how much business could it drive for them.  
So great concept.  
So Krishie, as we talked about identity and access management being really that Foundational element and how it's able to really protect and delight consumers, I mean, it does have an impact on organizations and it really, I think, um, leads into how organizations, you know, Leverage identity and access management to make this user experience better.  
What do you think?  
Yeah, so I think absolutely there's um, You know, we, we talked about a holistic approach to customers.  
Um, from my point of view, think about the customer journey end to end, Think about all the different channels, all the different products they engage with and so Forth, and there's definitely a return on investment.  
Um, and there will be a bottom line around that user experience that you can actually achieve.  
Identity and Access Management also gives you something very important around risk Reduction, you know, avoidance of, of, uh, significant breaches and the liabilities, But more importantly, around the impact that that getting this wrong can have on your brand.  
And your reputation.  
We're trying to build long-term relationships with our customers.  
Uh, we're trying to build trust with our customers; we're trying to have them connect with our brand, and if our security goes, goes, well, breaks, Um, if that happens, then we've got an issue.  
And that's, that's really where the opportunity is, actually becoming the steward of your Customer data, of the security and relevance of the data that you are serving and managing For your customers.  
Oh yeah, I considered organizational Leaders now are the stewards of their cus consumer data.  
No longer is it just the collectors or harvesters of uh consumer data, But really they're the stewards of it.  
That's a great concept.  
Well, Christian, this has been a great conversation, you know, I really appreciate it.  
I, I think I appreciate all the times you and I Get a chance to talk, um, so until next time, I'll say goodbye.  
Brilliant to see you and hopefully we get to see each other face-to-face at some point, Um, in the not too distant future.  
Yeah, I hope so too.

**Enhanced Security Posture.**Privacy and consent practices significantly bolster your cybersecurity. You reduce your attack surface by centralizing customer data, ensuring only the right stakeholders have access to it, and consistently monitoring user activity. Privacy is all about ensuring appropriate access to data, which is exactly what identity and access management platforms are built for.

**Scale Your Business Globally.** And here's the exciting part – privacy compliance goes beyond borders. It gives you an international edge, as data protection knows no boundaries. When you implement privacy and consent best practices, you become a global data guardian, elevating your brand on the world stage.

Did you know?

70%

[Over 70% of business professionals report that they are receiving “significant” or “very significant” benefits from their data privacy efforts (CSCO)](https://www.fisglobal.com/-/media/fisglobal/worldpay/docs/insights/consumer-intelligence-series-protectme.pdf)

## Privacy Deployment Challenges

**Change is hard.** Implementing new technologies and adding new features to your IT infrastructure is difficult, and it takes time away from other priorities. Plus, doing something new often leads to mistakes. Let’s review a few of the main obstacles and shortfalls of deploying privacy and consent so you won’t run into any surprises and can be better prepared.

**Inadequate Consent.** The baseline level of consent in the past is no longer sufficient. Instead of implicit or opt-out consent allowed in some cases, your customers must give unambiguous consent via a statement or clear action, such as marking an online checkbox or filling in an online form. As a data controller, the organization is required to demonstrate that the request for consent has been presented in a clear and intelligible manner.

An even higher standard of explicit consent is required if you collect special categories of data. In addition, consent is required in a wider range of scenarios than ever before. For example, user browser data is considered personal data, necessitating explicit agreement for data capture. If your enterprise does not yet support such activity, you will need to update your environment.

**Silos of Data.** Consider a customer who is shopping via your business website. Your company may be storing browsing data in an analytics system, other lead data in your e-commerce system, purchase history in an order management system, and credentials and other identity data in yet another system. This siloed data makes adhering to compliance requirements such as data access and portability much harder to carry out. Also, it is unlikely that all these disparate systems adhere to data protection and security by design requirements.

**Lack of Authorization.** Not only is it a good business practice to limit application access to customer identity and profile data needed for the app to function, but most regulations essentially require that organizations create specific policies to limit applications’ access to any unnecessary customer data. Businesses that have not done so already must adapt and enforce data access processes on an app-by-app basis via centralized data access governance policies that take consent, privacy preferences, and corporate requirements into consideration.

**Limited Self-service Access.** Do your customers have access to preference management tools to self-manage their profiles and preferences? Are these preferences consistently enforced across all devices and channels? Does your organization have the ability to easily store and retrieve different types of preference data, both structured and unstructured? If your organization answers “no” to any of these questions, you will find yourself having to beef up customer self-service access to comply with privacy regulations.

## Privacy and Consent Must-Haves

As always, your resources are limited and you have other stuff to get done. So you don’t have to boil the ocean, let’s review a few of the important privacy management and consent features. Finding a balanced approach always helps.

**Customer Consent and Communication Preferences.** Safeguarding your customers' privacy is more than just a regulatory obligation; it's a fundamental pillar for building unwavering trust. In today's data-driven world, providing customers with the autonomy to decide how their personal information is shared and their preferred communication methods is a powerful way to demonstrate that you value their privacy and respect their choices.

Every customer is unique, and their approach to sharing information varies. Some customers are open books on social media, embracing the digital spotlight, while others prefer a more discreet approach, keeping personal details close to their chest. By offering them the freedom to tailor their privacy settings, you empower them to feel in control of their data, which can deepen their sense of trust in your organization.

**Data Retention and Reporting Capabilities.** Ensuring the security of your customers' personal data is paramount. One critical aspect is guaranteeing that their data resides only in the region where they are located. Additionally, you need a well-thought-out plan for data retention to address the question of how long to keep their information. Failing to implement these considerations into your customer identity management solution can make answering such inquiries challenging, especially during audits.

The key to success lies in reliable reporting capabilities and a robust data security strategy. By having a well-defined approach in place, you can meet data residency requirements and cater to your customers' privacy preferences. This proactive stance empowers you to safeguard data, maintain compliance, and establish a bond of trust with your customers.

**Delegated User Access.** Shared accounts can be a practical solution for many families, whether it's for insurance plans or bank accounts. However, setting up access control and permissions can become a cumbersome task. Ensuring that your kids don't have the same access as you is essential to maintain privacy and security.

The solution lies in providing a smooth and secure IAM experience for your customers. By offering a user-friendly system, your customers can easily authorize and delegate access to their family members. With proper IAM implementation, families can manage their accounts effortlessly, customizing access for each member while keeping sensitive data protected. By empowering your customers to manage shared accounts effectively, you build trust and reliability in your services.

## Customer Privacy and Consent Order of Operations

Robust CIAM solutions offer key capabilities including data consolidation, consent capture and management, data access governance, and end-to-end security that will help your organization meet privacy use cases. In addition, CIAM best practices help make compliance efficient and cost-effective through consolidation of data, improved control and governance of your data, and fast integrations, while improving security and streamlining the user experience.

But organizations whose goals exceed mere compliance will be the real winners, as they deliver secure, seamless experiences across all channels and devices, resulting in increased customer trust, engagement, and loyalty.

The PingOne Cloud Platform is designed to provide key capabilities that help meet privacy and consent technical requirements out of the box. Our leading CIAM solution can transform a privacy compliance challenge into an opportunity to get closer to your customers, building trust, loyalty, and engagement along the way.

### Step 1: Capture Consent

Capturing customer consent should be done very early in the customer onboarding process, typically during registration. For added convenience, you can leverage a progressive profiling feature and capture consent the next time a user authenticates to log in. The goal here is to provide your customers with privacy and consent options and allow them to select their preferences. Customers can opt-in via a registration form and be able to make changes anytime in customer preferences or settings.

### Step 2: Store Consent

Once customer consent and preferences are captured, you should have a way to store those preferences. Storing consent preferences alongside your customer attributes is recommended. This provides your organization with a [unified directory](https://www.pingidentity.com/en/capability/directory.html) where all customer information can be obtained, allowing for consistency and reducing the sprawl of customer data in other siloed data stores. The added benefit is that it also reduces the attack surface, as your customer data isn’t replicated in various places.

### Step 3: Enforce Consent

The last step is to enforce consent. Centralized authorization policies provide fine-grained access control that uses real-time context about your customers and resources. With easy drag-and-drop controls, your admins can quickly make changes and edits. Compliance is ensured by streamlining the management of data privacy and consent with automation. For example, authorization policies will restrict a loan officer to accessing only the customer information required to evaluate and approve a loan application, and nothing else about that customer.

**Looking Past the Immediate Horizon**

[Decentralized identity](https://www.pingidentity.com/en/lp/ac/pingone-neo/decentralized-identity-101.html) is a new and quickly approaching concept that gives customers the ability to control their own identity and personal data. It gives the ultimate control of privacy and identity data back to your customers. It lets you verify IDs, documents, and identity claims like driver's licenses and issue digital credentials based on those. Users can share their digital credentials with organizations to quickly and effortlessly prove who they are without you having to store personal customer data. Instead, personal data always resides with the customer, the first-party user.

## Ensure Customer Privacy and Security with Ping Identity

Recent high-profile privacy abuses have made customers wary of how companies are using their personal information. They are increasingly reluctant to provide their data and increasingly worried about what’s being shared without their knowledge. These attitudes are reflected in the diverse geographic, industry, and corporate privacy regulations we see today.

With the right CIAM solution, you’ll be able to provide secure, cohesive customer experiences through SSO and a high-performance, scalable, unified profile that is accessible across all applications and channels. It should build the trust of your customers by providing centralized authorization policies that enforce customer consent and adhere to privacy regulations. And it should allow customers to easily register and to view and manage their account information, data-sharing consents, and preferences to facilitate a personalized experience across channels. To learn more, check out our [privacy and consent web page](https://www.pingidentity.com/en/solution/privacy-consent.html).

## What We Do

We help you protect your users and every digital interaction they have while making experiences frictionless.

3 Billion+

identities managed

50%+

of the

Fortune 100

99.99%

platform uptime

[Contact us](https://www.pingidentity.com/en/company/contact-sales.html) if you have any follow-up questions, or check out our [PingOne for Customers](https://www.pingidentity.com/en/platform/pingone-for-customers.html) solution to learn more about capabilities and solution packages to ensure customer privacy and security.