Ahead of Data Privacy Day on January 28, Cisco has released its 2023 Data Privacy Benchmark Study, surveying specialists and consumers from across the globe.
Overall, the survey found that, while the importance of data privacy is well recognised, consumers and businesses are not always in alignment.
Businesses recognise the economic importance of data privacy in the modern era, with 95% saying that privacy is a business imperative and integral to their company’s culture.
94% of businesses also assume that customers won’t buy from them if their data is not properly protected.
“An organisation’s approach to privacy impacts more than compliance,” Cisco Vice President and Chief Legal Officer, Dev Stahlkopf said. “Investment in privacy drives business value across sales, security, operations, and most importantly, trust.”
Despite overall economic difficulties, privacy spending did not see a decrease in 2022, and in some cases, grew.
Investing in privacy pays: the average benefits for privacy were 1.8 times spending for the average organisation. 36% of organisations are getting returns at least twice their spending, with some even realising returns over 43 to 5 times their privacy investment.
Companies noted in the survey that besides monetary gains, their privacy investments earned them returns in consumer loyalty and trust and making their company more attractive.
Privacy spending also helped them mitigate security losses, improved their agility and innovation, as well as their operational efficiency.
In the UK, 36% of respondents said that privacy was an on the job responsibility, and all members of a team needed appropriate privacy and security skills.
This percentage is just higher than the global average (36%) but much lower than China’s (56%) and India’s (41%) responses.
Privacy legislation
70% of Uk respondents said that privacy laws had a positive impact on their organisations.
Compliance with privacy laws does require effort and cost, and keeping up with changing regulations can keep companies on their toes.
Consumer and Business Disconnect
Despite businesses reacting positively to privacy legislation, there appears to be a disconnect between them and consumers regarding priorities in data and trust.
While consumers view providing clear information as to how their data is being used as their number one way to build trust (39%), organisations say that simply complying with relevant privacy laws is enough (30%).
Transparency over compliance was a major factor for consumers, who also felt that refraining from selling consumer data was also a major factor in building trust (21%).
While organisations overwhelmingly agreed (96%) that they have an ethical obligation to treat data properly, their methodology may not be enough for consumers.
“When it comes to earning and building trust,” Harvey Jang, Vice president and Chief Privacy Officer at Cisco said, “compliance is not enough.”
The disconnect continues when the survey asked respondents about AI applications, which are becoming more and more common throughout the tech world.
Consumers said they would be much more comfortable or more comfortable with AI if they had the opportunity to opt out of AI (76%), if companies instituted an AI ethics management program (75%) explained how the application makes decisions (74%), or involved a human in the decision making process (75%).
Auditing their AI for bias (69%) and adopting AI ethics principles (65%) would make a difference for some, but would make no difference for 31% of and 35% of consumers respectively.
Organisations, on the other hand, though explaining how the AI application works (58%) and ensuring a human is involved in the process (55%) would be the best ways of ensuring consumer trust.
63% of businesses have involved a human and 60% have ensure the application is explained.
However, only 22% of businesses believed giving the opportunity to opt out of AI use would be effective in gaining consumer trust, with only 21% providing the options.
Recommended
- How Will the Met Tower Redevelopment Add to Glasgow’s Tech Sector?
- Who Do British People Trust the Most and Least With Their Data?
- SBRC: Four-day Week Could Help Close Skills Gap
Data Localisation vs Global Data
While many governments and organisations are pushing for data localisation requirements, which would require data to be kept within a region or country, the policy may not stack up economically.
While 78% of consumers in 2022 initially found the policy a good idea, only 41% still showed support once the added cost for goods and services was communicated.
Data localisation does add significant operational cost according to 89% of respondents.
This provides important context to the two contrasting statistics Cisco’s survey revealed: 88% think data would be inherently safer if it was stored within their country/region, but 90% believe global providers protect data better compared to local providers.
Combining the two – using a global provider to store data locally – would therefore be the choice of the overwhelming majority of businesses.
Cisco’s Recommendations
Cisco recommends that businesses continue to invest in privacy and privacy skills across their entire team.
Transparency will be key in gaining and retaining consumer trust – compliance is simply not enough.
As AI becomes more common place, it is vital that companies have policies that involve humans in the decision making process and increase transparency. Providing consumers with preferred management options is also recommended as this is what consumers demand the most.
While local providers may be tempting, the cost of local data providers is high and they may degrade functionality – global providers are recognised to be the current safer bet.
Get all the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





