Privacy practices in the Indian technology ecosystem
A 2020 survey of the makers of products and services
The survey asked questions to test hypotheses. They are presented here along with a breakdown of responses by organization size and segment, and the respondent’s role therein. Questions are numbered by the order in which they appeared in the survey.
Sections:
Hypothesis 1: I understand the difference between privacy and security.
Question 12: How does your organization look at the relationship between privacy and security?
Authority role | R1 | R2 | R3 | R4 | Total |
---|---|---|---|---|---|
Yes | 10 | 24 | 51 | 38 | 123 |
No | 5 | 5 | 28 | 21 | 59 |
Total | 15 | 29 | 79 | 59 | 182 |
Organization size | R1 | R2 | R3 | R4 | Total |
---|---|---|---|---|---|
Small | 5 | 16 | 30 | 18 | 69 |
Medium | 5 | 4 | 19 | 13 | 41 |
Large | 3 | 6 | 26 | 22 | 57 |
Unidentified | 2 | 3 | 4 | 6 | 15 |
Total | 15 | 29 | 79 | 59 | 182 |
Security is about the safeguarding of data, whereas privacy is about the safeguarding of user identity and their right to self-determination. It is possible to have security without privacy, but not privacy without security. Or, as Paul Dourish and Ken Anderson wrote in 2006 for the journal Human-computer Interaction,1 “We read security here as the state of being free from danger; technological ‘security mechanisms’ are deployed as means to ensure this state. Risks to privacy (solitude, confidentiality, autonomy), then, are among the various risks against which we might wish to be secure.”
Privacy and security are related, and R1 represents an incorrect understanding. By bucketing these, we have:
Authority role | Unrelated (R1) | Related (R2+R3+R4) | % Related |
---|---|---|---|
Yes | 10 | 113 | 91.86% |
No | 5 | 54 | 91.52% |
Total | 15 | 167 | 91.75% |
Organization size | Unrelated (R1) | Related (R2+R3+R4) | % Related |
---|---|---|---|
Small | 5 | 64 | 92.75% |
Medium | 5 | 46 | 90.19% |
Large | 3 | 54 | 94.73% |
Unidentified | 2 | 13 | 86.66% |
Total | 15 | 167 | 91.75% |
We therefore conclude that within our samples, the hypothesis is generally true, and ≈90% of the participants agree that privacy and security are related to each other.
“In terms of differences between privacy and security I think there is a lot of overlap and at times when you talk about privacy you also talk about security but they are still distinct entities in terms of the laws that govern privacy and security. As a company we are very heavy on compliance in general on PII data to being HIPAA compliant and CCPA compliant... there is (also) a team dedicated to make sure that every single application, data flow, and platform that stores data is secure.”
—A senior engineering manager at a multinational e-commerce company, during an FGD
We believe there is room for interpretation that the ≈10% chose their answer based on the boundaries of their specific work responsibilities. For instance, an infrastructure engineer and a product manager may have non-overlapping roles handling security and privacy respectively.
Hypothesis 2: Tech engineers (senior and middle) recognise that the tech industry does not respect user privacy and believe that it needs to be more responsible.
Question 14: Which of the following statements accurately captures the attitude towards privacy in your organization/network?
Organization size | R1 | R2 | R3 | R4 | Total |
---|---|---|---|---|---|
Small | 59 | 6 | 0 | 4 | 69 |
Medium | 34 | 5 | 1 | 1 | 41 |
Large | 47 | 10 | 0 | 0 | 57 |
Unidentified | 8 | 6 | 0 | 1 | 15 |
Total | 148 | 27 | 1 | 6 | 182 |
R2 and R3 indicate not enough is being done. R4 suggests the respondent is not even aware. Putting them together:
Organization size | Does enough (R1) | Not enough (R2+R3+R4) | % Does enough |
---|---|---|---|
Small | 59 | 10 | 85.50% |
Medium | 34 | 7 | 82.92% |
Large | 47 | 10 | 82.45% |
Unidentified | 8 | 7 | 53.33% |
Total | 148 | 34 | 81.31% |
Question 15: Does your organization have Standard Operating Procedures (SOPs) for engaging and handling criticism on privacy issues in your products?
Organization size | R1 (have SOP) | R2 (no SOP) | % Have SOP |
---|---|---|---|
Small | 23 | 46 | 33.33% |
Medium | 17 | 24 | 41.46% |
Large | 34 | 23 | 59.64% |
Unidentified | 4 | 11 | 26.66% |
Total | 78 | 104 | 42.85% |
Question 16: I have a peer group within my organization, where I can discuss and freely express my views about privacy and data security.
Organization size | R1 (have peer group) | R2 (no peer group) | % Have peer group |
---|---|---|---|
Small | 45 | 24 | 65.21% |
Medium | 35 | 6 | 85.36% |
Large | 45 | 12 | 78.94% |
Unidentified | 12 | 3 | 80.00% |
Total | 137 | 45 | 75.27% |
The percentage columns in these tables show an interesting contrast:
Organization size | % Does enough | % Have SOP | % Have peer group |
---|---|---|---|
Small | 85.50% | 33.33% | 65.21% |
Medium | 82.92% | 41.46% | 85.36% |
Large | 82.45% | 59.64% | 78.94% |
Unidentified | 53.33% | 26.66% | 80.00% |
Total | 81.31% | 42.85% | 75.27% |
Across all sizes, a significant number of participants have said there are no SOPs available for handling privacy concerns, even though they think that their organizations are respectful of privacy concerns and have a peer group. Large organizations stand out for having invested in creating processes compared to other size segments.
In summary, while a large percentage of participants agree that their organization recognizes privacy concerns, they also agree that not enough is being done about it. Small organizations are significantly lagging in having a peer group and established processes.
“A lot of startups work in survival mode for a long time and these conversations often feel like (problems of) the elite in comparison to immediate survival problems you are facing. Not saying it is right but this is the attitude most of the time in these startups, it’s an elite concern. So we get around it rather than think through it, and when it is absolutely necessary is when we come to it.”
—A founder of a product-management startup, during an FGD
Hypothesis 3: Organizations can only build privacy respecting products if they have business imperative, skill, agency and competence.
Hypothesis 4: There are market segments where business imperative overrides privacy concerns.
Hypothesis 5: Tech engineers are dissatisfied with their organization’s stance/policies and efforts on building privacy respecting products.
Question 20: Which of the following best describes the product design and development practices of your organization, when it comes to Privacy?
Organization size | R1 (Privacy later) | R2 (Privacy fore) | % Privacy fore |
---|---|---|---|
Small | 05 | 55 | 91.66% |
Medium | 04 | 35 | 89.74% |
Large | 04 | 49 | 92.45% |
Unidentified | 0 | 13 | 100.00% |
Total | 13 | 152 | 92.12% |
For another perspective, we segment organizations by their respective verticals. Some organizations appear in more than one segment:
Vertical | R1 (privacy later) | R2 (privacy fore) | % Privacy fore |
---|---|---|---|
Fintech | 5 | 30 | 85.71% |
Data Security | 1 | 33 | 97.05% |
Big Data | 2 | 46 | 95.83% |
Services/Consultancy | 4 | 54 | 93.10% |
Social Media | 2 | 17 | 89.47% |
Mobile Apps | 6 | 32 | 84.21% |
In focus group discussions, the American HIPAA, the California-specific CCPA and the European GDPR were repeatedly mentioned as privacy regulations that organizations adhered to. Consequently, we asked survey respondents to select from these.
Question 30: Which of the following laws are you required to comply with? (Select all that apply)
Organization size | CCPA | GDPR | HIPAA | Other |
---|---|---|---|---|
Small | 14 | 42 | 09 | 11 |
Medium | 16 | 28 | 13 | 08 |
Large | 23 | 39 | 23 | 12 |
Unidentified | 04 | 11 | 01 | 14 |
Total | 57 | 120 | 46 | 45 |
A closer examination of the “Other” responses suggest that some respondents have confused auditing requirements such as SOC 2 and ISO 27001 with privacy regulations. Here we introduce a new column “None” for when none of CCPA, GDPR and HIPAA are applicable.
Organization size | None | Count | % of None |
---|---|---|---|
Small | 20 | 69 | 28.98% |
Medium | 07 | 41 | 17.07% |
Large | 13 | 57 | 22.80% |
Unidentified | 02 | 15 | 13.33% |
Total | 42 | 182 | 23.07% |
By cross-referencing responses to these two questions, we see which of these regimes is more effective. As Question 30 is multi-select, the total counts in this table do not match the total counts for Question 20 above.
Compliance | R1 (Privacy later) | R2 (Privacy fore) | % Privacy fore |
---|---|---|---|
CCPA | 3 | 52 | 94.54% |
GDPR | 9 | 103 | 91.96% |
HIPAA | 3 | 39 | 92.85% |
Count | 15 | 194 | n/a |
Insights:
Organization size matters, and smaller organizations (9/13 in our sample size) have a lower concern for privacy, possibly because of immature processes.
There is a distinct drop in concern in the Fintech, Social Media and Mobile App verticals (< 90%).
23% (42/182) of the organizations are not under the most commonly known privacy regulations with small and medium organizations constituting 64.28% (27 out of 42) of the population, which perhaps explains why they have immature processes compared to large organizations.
Being subject to regulation (average 93.% privacy fore) is not a significant improvement from the overall concern for privacy (92.12%). The survey does not reveal why, and suggests a deeper study is required.
“So privacy by design is still perhaps not very well adopted by the industry, it is more privacy by law at this point”
—A senior engineer and product manager at a software product and services company, during an FGD
“Certain types of information may not be essential for the application. But from a marketing standpoint and what you are selling, demographics such as geography, how the people behave, how the product is utilized - collecting this information helps us draw patterns. Everyone in the market is anyway capturing the data. It is more about whether the data is necessary for our organization, and if we have the compliance to go forward with collecting it.”
—A software engineering manager of a medium-sized fintech organization, during an FGD
“Knowing the customer’s ailment is the highest level of PII we deal with. Can I send a recommendation to the customer based on their health ailment? We are missing out on a potential business opportunity. I don’t know how much of a great business that could be, but we have just stayed away from using any of the PII to target better or up-sell, something that comes very naturally to say an e-commerce business.”
—VP of engineering of a medium-sized health-tech organization, during an FGD
“If you really care about privacy, make your (software) architectural choices robust. Policy will come later, because policy needs reinforcement and that again boils down to intent and who is in power. But if the underlying architecture is distributed, nobody can do anything because this is a foolproof system.”
—Product head at a large-sized paytech organization, during an FGD
Hypothesis 6: Middle and line management lack resources and guides to reduce the decision making overhead of regulatory compliance, and also lack agency to build privacy respecting products.
Hypothesis 7: Senior and middle management need immediate incentives for investing in building privacy respecting products.
Question 22: Which of the following statement best applies when you are building a product and make design decisions on the features:
Only respondents holding authority roles are considered here (121 of 182).
Organization size | Have process or people | Have none | % Have none |
---|---|---|---|
Small | 37 | 13 | 26.00% |
Medium | 28 | 5 | 15.15% |
Large | 30 | 2 | 6.25% |
Unidentified | 5 | 1 | 80.00% |
Total | 100 | 21 | 21.00% |
Does a regulatory compliance regime (CCPA, GDPR or HIPAA) make a difference? By only considering responses from (a) organizations that said they are regulated and (b) respondents holding positions of authority, we find that small and medium organizations have not improved.
Regulated organization size | Have process or people | Have none | % Have none |
---|---|---|---|
Small | 27 | 9 | 25.00% |
Medium | 23 | 4 | 14.81% |
Large | 25 | 0 | 0.00% |
Unidentified | 4 | 1 | 25.00% |
Total | 79 | 14 | 15.05% |
Question 29: If your organization has compliance standards imposed by regulatory authorities, which of the following best describes your development practices?
Only respondents holding authority roles are considered here (count of 121):
Regulated organization size | Have process | Have people | Have both |
---|---|---|---|
Small | 6 | 23 | 7 |
Medium | 9 | 6 | 16 |
Large | 7 | 10 | 12 |
Unidentified | 1 | 3 | 1 |
Total | 23 | 42 | 36 |
Small organizations have capacity shortcomings that do not disappear when they are subject to a regulatory regime, likely because regulation does not generate business. Larger organizations however can absorb the cost of compliance and create better processes.
“Sales and marketing are always aggressive. They love aggressive growth. So they will go to any lengths to collect whatever customer data they can lay their hands on. On the technical side of things, however, engineers and managers have to take responsibility and not leave it to the business to decide about what data can be collected and what data is off-limits. A lot depends on the management’s commitment.”
— Senior engineer working at a medium-sized Fintech startup, during an FGD
Hypothesis 8: Competence, skill and awareness together power an individual within an organization to pitch for and build privacy-respecting products.
Hypothesis 9: Tech companies do not spend enough time in training their employees on privacy and other safety issues.
Hypothesis 10: Senior and middle management need practical resources – including community support and peer reviewed knowledge – that help them to quantify RoI and risks for building privacy respecting products.
Question 21: Which of the following best describes the training and resources in your organization about privacy aspects during product design and development?
Organization size | R1 | R2 | R3 | % R3 (No info) |
---|---|---|---|---|
Small | 21 | 32 | 16 | 23.18% |
Medium | 16 | 17 | 8 | 19.51% |
Large | 34 | 16 | 7 | 12.28% |
Unidentified | 6 | 6 | 3 | 20.00% |
Total | 77 | 71 | 34 | 18.68% |
Question 23: We have a learning and development budget for our product teams to enhance our understanding of privacy and security risks, while making feature and design decisions
R4 is unclear on whether it means the respondent is not aware of a budget, or doesn’t have one. It is therefore excluded from this table.
Organization size | R1 | R2 | R3 | % R3 (Not available) |
---|---|---|---|---|
Small | 7 | 25 | 19 | 37.25% |
Medium | 2 | 20 | 10 | 31.25% |
Large | 11 | 16 | 9 | 25.00% |
Unidentified | 1 | 8 | 1 | 10.00% |
Total | 21 | 69 | 39 | 30.23% |
Insights:
Question 5: Does your role require you to think about privacy or compliance on a regular basis?
Responses are shown here classified by whether the respondent held an authority role in their organization:
With authority role | Yes | No | % Yes |
---|---|---|---|
Small | 38 | 12 | 76.00% |
Medium | 27 | 6 | 81.81% |
Large | 22 | 10 | 68.75% |
Unidentified | 5 | 1 | 83.33% |
Total | 92 | 29 | 76.03% |
Without authority | Yes | No | % Yes |
---|---|---|---|
Small | 13 | 06 | 68.42% |
Medium | 03 | 05 | 37.50% |
Large | 20 | 05 | 80.00% |
Unidentified | 07 | 02 | 77.77% |
Total | 43 | 18 | 70.49% |
Question 13: How does your organization look at privacy respecting aspects of its products or services?
Organization Size | R1 | R2 | R3 | % R1 |
---|---|---|---|---|
Small | 53 | 2 | 2 | 92.98% |
Medium | 33 | 1 | 2 | 91.66% |
Large | 47 | 2 | 0 | 95.91% |
Unidentified | 9 | 1 | 0 | 90.00% |
Total | 142 | 6 | 4 | 93.42% |
Insights:
There is near universal acknowledgement that privacy is a fundamental right and has to be built into the product development process, across organizations of all sizes.
In small and medium organizations, three out of every four authority roles require thinking about privacy and compliance issues. This number drops to two out of three for large organizations, suggesting they can afford to create specialized roles.
“The first thing we do is create a map of the data, which is called a metadata drive, so the first thing to know is what data is there in your system.”
“Nowadays every organization has something called a Chief Data Officer (CDO), especially in European companies which are GDPR compliant. The CDO lays down the rules for their organization, maps those rules to that metadata [drive], and either automates compliance for those rules, or manually encodes the rules to satisfy compliance so that all these issues will be caught in a certain timeframe. It’s the lineage of the entire data. If something goes wrong at one place, within minutes, teams are able to identify the whole datamap, and identify what went wrong.”
—A startup founder, during an FGD
“If you have to set rules for the whole company, it has to be done right at the top.”
—A VP of engineering of a medium-sized health-tech organization, during an FGD
Question 17: Do investors, customers, or other stakeholders of your company care about privacy?
R4 has been excluded as it does not convey any meaningful information.
Organization size | R1 | R2 | R3 | % R1 | % R2 | % R3 |
---|---|---|---|---|---|---|
Small | 39 | 6 | 12 | 68.42% | 10.52% | 21.05% |
Medium | 28 | 4 | 5 | 75.67% | 10.81% | 13.51% |
Large | 37 | 13 | 2 | 71.15% | 25.00% | 3.84% |
Unknown | 9 | 3 | 2 | 64.28% | 21.42% | 14.28% |
Total | 113 | 26 | 21 | 70.62% | 16.25% | 13.12% |
While intent is a good starting point, the next step is to hire competent people in authority roles to establish processes, for which stakeholders must be on board.
Question 25: Does your organization have a Chief Data Officer (CDO), or Legal department which looks into risk and compliance?
Organization size | Yes | No | Total |
---|---|---|---|
Small | 23 | 46 | 69 |
Medium | 28 | 13 | 41 |
Large | 49 | 8 | 57 |
Unknown | 11 | 4 | 15 |
Total | 111 | 71 | 182 |
Respondents who answered “Yes” were also asked for the team size as an indirect metric for a privacy and compliance budget:
Question 28: What is the approximate size of the team in your organization that looks into legal/compliance/regulatory aspects?
Organization size | 1–5 | 6–50 | > 50 |
---|---|---|---|
Small | 18 | 4 | 1 |
Medium | 28 | 0 | 0 |
Large | 6 | 31 | 12 |
Unknown | 7 | 2 | 2 |
Total | 59 | 37 | 15 |
Question 24: If you had to find out more about regulations applicable to your business, you can ask someone in your organization.
Organization size | Yes | No | Don’t know / Can’t say | Count |
---|---|---|---|---|
Small | 43 | 18 | 8 | 69 |
Medium | 31 | 6 | 4 | 41 |
Large | 51 | 3 | 3 | 57 |
Unknown | 12 | 1 | 2 | 15 |
Total | 137 | 28 | 17 | 182 |
Question 18: I have a peer group within my organization, where I can discuss and freely express my views about privacy and data security.
Organization size | Yes, good | Yes, okay | No | % No |
---|---|---|---|---|
Small | 29 | 18 | 22 | 31.88% |
Medium | 22 | 13 | 6 | 14.63% |
Large | 36 | 10 | 11 | 19.29% |
Unknown | 5 | 6 | 4 | 26.67% |
Total | 92 | 47 | 43 | 23.62% |
Question 19: I have a peer group or safe space outside my organization where I can express my views and learn from other practitioners about privacy and data security.
Organization size | Yes, good | Yes, okay | No | % No |
---|---|---|---|---|
Small | 29 | 18 | 22 | 31.88% |
Medium | 15 | 10 | 16 | 39.02% |
Large | 21 | 10 | 26 | 45.61% |
Unknown | 3 | 9 | 3 | 20.00% |
Total | 68 | 47 | 67 | 36.81% |
Insights:
Over a fifth of respondents in organizations of all sizes don’t have a peer group to learn about privacy and data security, indicating a capacity gap in the larger ecosystem. Smaller organizations fare better with external support than larger organizations, suggesting that organizations get insular as they grow.
“Why I have this mindset is because we are a healthcare company. The whole company is built on trust. Anything in healthcare, you trust the provider. Our revenues come from clients who trust us with their data. So it is ingrained into how we think about data. We’ve had multiple rounds of product audits, keeping all compliances in mind. We revisited policy, both technically and in implementation and identified legacy issues to upgrade our data governance systems when legislation changes.”
—A VP of engineering of a medium-sized health-tech organization, during an FGD
“Compliance being cosmetic and lack of care for privacy has nothing to do with India. It has to do with the organization and the people you work with. Although, in my company, we do not collect that much data from the user and the customer, but the clients who are sharing their content with us, their security matters. I think the privacy and data, it’s about the clients and the users, and the scale of the company, and the kind of folks you work with.”
—A senior engineer at a large media-tech company, during an FGD
In mature organizations, processes are well defined, and specialized officers have authority over privacy-related decisions.
Question 27: Does your organization’s CDO/Risk and Compliance/Security/Legal team have veto power over the product/engineering team when questions of data security or privacy are raised?
Organization size | Yes | No | Don’t know / Can’t say | % Yes |
---|---|---|---|---|
Small | 19 | 16 | 34 | 27.53% |
Medium | 23 | 6 | 12 | 29.26% |
Large | 26 | 1 | 30 | 52.63% |
Unidentified | 5 | 3 | 7 | 46.66% |
Total | 73 | 26 | 83 | 45.60% |
Question 31: What are the data governance practices and policies that your organization has adopted for complying with these regulations? (Multiple choice)
Some respondents did not pick any of the options, possibly implying that their organizations have no data governance practices.
Organization size | R1 | R2 | R3 | R4 | R5 | R6 | R7 | R8 | Any | None |
---|---|---|---|---|---|---|---|---|---|---|
Small | 30 | 26 | 26 | 14 | 22 | 17 | 21 | 27 | 59 | 10 |
Medium | 30 | 32 | 20 | 17 | 21 | 29 | 18 | 24 | 38 | 3 |
Large | 45 | 48 | 25 | 29 | 28 | 42 | 26 | 29 | 55 | 2 |
Unidentified | 10 | 9 | 5 | 6 | 9 | 9 | 6 | 7 | 12 | 3 |
Total | 115 | 115 | 76 | 66 | 80 | 97 | 71 | 87 | 164 | 18 |
Expressed in percentages (based on totals per row)
Organization size | R1 | R2 | R3 | R4 | R5 | R6 | R7 | R8 | Any | None |
---|---|---|---|---|---|---|---|---|---|---|
Small | 43% | 38% | 38% | 20% | 32% | 25% | 39% | 46% | 86% | 14% |
Medium | 73% | 78% | 49% | 41% | 51% | 71% | 44% | 59% | 93% | 7% |
Large | 79% | 84% | 44% | 51% | 49% | 74% | 46% | 51% | 96% | 4% |
Unidentified | 67% | 60% | 33% | 40% | 60% | 60% | 40% | 47% | 80% | 20% |
Question 32: What are the consent management policies and practices that your organization has adopted for complying with regulations?
Some respondents did not pick any of the options, possibly implying that their organizations have no consent management practices.
Organization size | R1 | R2 | R3 | R4 | R5 | Any | None |
---|---|---|---|---|---|---|---|
Small | 23 | 27 | 16 | 24 | 3 | 54 | 15 |
Medium | 17 | 16 | 12 | 29 | 4 | 38 | 3 |
Large | 38 | 20 | 17 | 35 | 9 | 51 | 6 |
Unidentified | 5 | 7 | 6 | 9 | 5 | 13 | 2 |
Total | 83 | 70 | 51 | 97 | 21 | 156 | 26 |
Expressed in percentages (based on totals per row):
Organization size | R1 | R2 | R3 | R4 | R5 | Any | None |
---|---|---|---|---|---|---|---|
Small | 33% | 39% | 23% | 35% | 4% | 78% | 22% |
Medium | 41% | 39% | 29% | 71% | 10% | 93% | 7% |
Large | 67% | 35% | 30% | 61% | 16% | 89% | 11% |
Unidentified | 33% | 47% | 40% | 60% | 33% | 87% | 13% |
“At least for the fintech organizations, it is quite important privacy is built as part of the culture. If an organization is small, boot-strapped, it can be quite tedious to look into all compliance. Generally, companies move in a self-compliant manner. But as the organization grows bigger, it is important to realize the fact that potentially you will bring in a lot of new people who probably may or may not be aware of the sensitivity of the data. So compliance processes and audits can help ensure that best practices are followed, and that the organization has better vulnerability analysis checks.”
—A software engineering manager of a medium-sized fintech organization, during an FGD
Dourish, P. and Anderson, K., 2006. Collective information practice: Exploring privacy and security as social and cultural phenomena. Human-computer interaction, 21(3), pp.319-342. http://www.douri.sh/publications/2006/DourishAnderson-InfoPractices-HCIJ.pdf ↩︎
Hosted by
Supported by
{{ gettext('Login to leave a comment') }}
{{ gettext('Post a comment…') }}{{ errorMsg }}
{{ gettext('No comments posted yet') }}