Privacy and Relationship

Privacy .

Years ago I worked with PGP -- Pretty Good Privacy -- when it was a start-up company driven by energy around what Phil Zimmerman created in the first place: a pretty good way to keep communications private. At the time I developed the belief that privacy as a topic was equally important, difficult and and boring — especially when it came to making it work with digital technology at the personal level. What made it difficult was the very thing that made it work: crypto. Even the simplest and most straightforward form -- public key crypto -- was eye-glaze for most users. Geeky Goodness and Usability by Mortals can be strange bedfellows.

Since then I've been in countless conversations about what privacy is, how it can be maintained, whether it's synonymous with control, and other questions that get everybody tied in knots — including myself. And that's without even putting crypto on the table. While writing this I've been lurking on an Identity Commons list (one I helped start, years ago, when it was the Identity Gang list), where the topic of

Lately I've been trying to reverse that process, by wrapping the topic of privacy around another one: relationship. I've been working for the past several years on VRM, or Vendor Relationship Management. VRM will equip customers with tools (yes, open source ones) for managing relationships with vendors. Already in place is an $8+ billion business called CRM, or Customer Relationship Management. You encounter CRM every time you reach a call center, for example. The purpose of VRM is not to fight CRM, but to give customers means for driving that are at least as good

Privacy is a central issue with VRM. How do we maintain privacy on our terms, and not just on vendors' terms? After all, that's what's at stake every time we "accept" Terms of Service, End User License Agreements and other "agreements" that actually aren't. What if we are the ones asserting terms of engagement? How can we come up with terms that say, for example, that data about ourselves goes with us when a relationship ends?

In the course of working through questions like these, I have run across a legal concept called

So here are some provisional conclusions of my own:

1) The only completely private information is the kind not shared at all. For example, I'm writing this in the privacy of a hotel room. The door is locked, drapes cover the windows, and a Do Not Disturb sign hangs outside the door. This is a good example of a kind of privacy that involves zero sharing of information. It's also well understood. Closed doors and pulled drapes do the job pretty well. But this kind of privacy isn't helpful in circumstances where sharing is required.

2) Shared information can be made private only within a relationship -- through an agreement.

3) Our understanding of privacy should not be framed by the privacy policies of the companies we deal with. Since the dawn of e-commerce in 1995, privacy policies have been the exclusive province of companies that reduce the individual's choice to a checkbox: "accept" or go away. Checking that box does not constitute a relationship, or even much of an agreement. It constitutes coercioun and acquiescence. It's a terrible model for what we really need and still don't have. And by "we" I mean both sellers and buyers.

4) Sharing information involves the form of dependence we call trust. That dependence works best when it binds two or more parties that are both independent and in positions of control over the terms by which they are willing and able to share their information, and to liberate or restrict its use by the others.

At ProjectVRM we are working on equipping individuals with tools that make them both independent and better able to engage with others — that is, to create forms of dependence that are mutually agreeable and useful.

Better minds than mine are working on this stuff. Some are at the Harvard Law School, where we're putting together a project that come up with "terms of service" that any individual can assert, and which eliminate the need for vendors (or other large parties) to put us through the checkbox gauntlet — which some of our law professor friends say have never been legally square in any case, and in most cases aren't enforceable.