Privacy is dead, long live privacy: New thinking on compliance in the era of data monetization
The EU General Data Protection Regulation (GDPR) took effect in May, but nearly three months later it has not triggered large-scale enforcement actions. Nevertheless, the regulation has driven many companies to rethink how they collect and use data. This article proposes the concept of treating data as currency and interviews experts from institutions such as Cisco and Frankfurt Kurnit Klein and Selz to analyze how this concept can help companies understand data value and address compliance challenges, while also pointing out current deficiencies in corporate data governance and the practical obstacles to achieving privacy.

Editor's note: This article was originally published in August. Due to its everyday relevance, we have pulled it from the archives.
In May of this year, the business world witnessed a Y2K redux: the European Union's General Data Protection Regulation (GDPR) took effect—yet nothing major happened. Companies across global industries scrambled to comply, fearing hefty fines and consumer backlash. But nearly three months after implementation, actual enforcement actions have been few and far between.
Although the industry has not yet seen the direct consequences of the regulation, GDPR has prompted many organizations to rethink how they collect and use data. More companies are treating privacy as a business issue worth attention, rather than an afterthought. In this context, a concept is helping people understand how datashouldbe treated, injecting more privacy considerations into the process: treating data as currency.
Pricing data
The concept of "data as currency" is the successor to the more physical metaphor of "data is the new oil." Michelle Dennedy, vice president and chief privacy officer at Cisco, proposed the idea of "data is the new oil" in Europe 20 years ago. She believes data flows through systems and is more valuable than gold or other currencies.
Dennedy told CIO Dive that if data is the new oil, companies only need security measures to manage it, ensuring it doesn't leak or cause fires. But if data is treated as currency, it becomes "entirely dependent on time, cultural understanding, conditions, and context."
Dennedy noted that every currency has "volatility." The fluctuation of the euro exchange rate, for example, illustrates how election cycles affect currency valuation. When organizations learn to assess the value of assets, they can succeed. If data is handled carelessly and internal and external factors come into play, organizations may become targets for regulators.
If data is treated as currency, it becomes "entirely dependent on time, cultural understanding, conditions, and context."
Michelle Dennedy
Vice President and Chief Privacy Officer at Cisco
"If you treat sensitive data as an asset, and if it is compromised, the damage is as severe as if your actual money (in dollars) were lost, then you will behave differently," Tanya Forsheit, partner and chair of the privacy and data security practice at Frankfurt Kurnit Klein and Selz, told CIO Dive in an interview.
Although this concept is gaining mainstream support, the industry has not fully embraced it. Companies considering treating data as currency often quickly revert to risk associations, viewing data as something that can be lost. Another limiting factor is how regulations define personal data. GDPR provides a broad definition.
In the United States, personal data is considered personally identifiable information (PII). But under GDPR, personal data is any information that can be used to identify an individual, including device IDs and IP addresses. Expanding the scope of personal data increases the complexity of treating it as currency. For example, a social security number has higher value than an email address. This means the concept of "data as currency" requires a relative value system.
Forsheit said that if there were mechanisms to treat IP addresses as pennies and social security numbers as hundred-dollar bills, the concept would make sense. "It's a mindset that is hard for people to grasp."
Corporate thirst for data
If companies did not over-collect data, the semantic debates around its handling and definition would be moot. But unfortunately, that is not the case. Rebecca Herold, CEO of consulting firm The Privacy Professor and co-founder and president of SIMBUS, a privacy and security management consultancy, said that in the mid-1990s, when the internet began shifting toward commercial use, obtaining data became easier.
Herold told CIO Dive that before the internet, companies had to rely on print ads and mail to reach potential buyers. But the rise of internet commerce completely transformed marketing; companies no longer needed to ask for customer data—people simply handed over information. The industry saw "how eager organizations were to collect more data than they actually needed."
"American companies have historically been data hoarders. That's what they do. They collect massive amounts of data, sometimes without even knowing what their end goal is."
Tanya Forsheit
Partner and Chair of Privacy and Data Security Practice at Frankfurt Kurnit Klein and Selz
The '90s were just a preview. Today, companies collect and store more data than they can process, hoping that big data analytics and artificial intelligence will make analysis easier. This over-collection has a direct impact on privacy. "American companies have historically been data hoarders. That's what they do," Forsheit said. "They collect massive amounts of data, sometimes without even knowing what their end goal is."
Forsheit believes GDPR is working to change how companies interact with data, preventing the use of personal data in ways consumers did not expect or were unaware of. By connecting different datasets, analysts can identify and profile personal information without the user's knowledge, and GDPR is trying to prevent such behavior.
Is privacy possible?
Data can have both positive and negative impacts, and organizations worried about regulatory consequences and hefty fines are working to rethink data collection and processing. More regulation beyond GDPR is also having an effect. U.S. regulators are trying to build an ecosystem that considers the privacy implications of internet giants' services, such asrecent California legislation。
Herold said industries are in a "wake-up period" regarding data use. Facebook's widely publicized data use incidents have alerted the industry. Herold said Facebook "fell asleep" when planning how to sell data; "they were too trusting."
Herold pointed out two major problems with data:
- Organizations make too many assumptions about what might be considered personal data, and these companies do not think people can analyze datasets to gain insights about individuals.
- Most app developers and many tech companies do not invest enough time in designing controls into their solutions and products, instead merely meeting the minimum legal requirements.
Herold said this highlights the gap between companies' legal obligations and what they should actually do. Of course, privacy is possible, but companies lack the motivation to make it a reality.
"Bad things happen not because of a lack of laws or a lack of caring regulators," Forsheit said, "but because companies have been data-hungry, and in some cases greedy, collecting as much as possible and then trying to exploit it as much as possible until they get caught, because that is in many ways the American way."
