Consumer privacy in retail

Consumer privacy in retail:
The next regulatory and competitive frontier
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 2
Retail is at an inflection
point with consumer privacy.
The industry, leaders
included, should benefit by
striving for a new standard
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 3
Consumers are
becoming more
privacy aware
Some consumers are
concerned about data privacy
and want more control over
data as they are aware of more
data breaches
Retailers should
become data-wise
and privacy conscious
Some retailers struggle to
develop privacy policies that
align to business strategies,
keep up with data
proliferation, and deal
with system complexity
States are
enacting new
privacy regulations
New regulations are
coming as nearly half of
US states are developing
data policy legislation
Consumers are increasingly aware of threats to their privacy and personal data;
meanwhile, several states are introducing and enacting new privacy legislation
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 6
Individuals are attempting to manage significant “digital exhaust” that comes from all
aspects of their lives
Mostly user
controlled
Minimally user
controlled
Publicly-
available
information
Information
shared
voluntarily
Career
Government
issued IDs
Politics
Information
from
data
breaches
Online
and social
media
activity
Family
details
Basic
internet
profile
Login
credential
Social
security
number
Geo
location
data
Credit
score/
history
General
purchase
history
Device
ownership
Photos
Friends/
colleagues
Education
history
Personal
identifiers
Healthcare
/insurance
identifiers
Financial
history
User
account
details
Medical
prescriptions
Cross-
site
history
System
info
Shopping
preferences
Payment
processing
data
Legal
records
Customer
service logs
Third-
party
tracking
Media
preferences
Home
address
Telephone
call records
Demo-
graphic
features
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 8
3 states have
enacted dedicated privacy
laws covering
42.5M
Americans (13%)
19 other states are
debating new privacy laws
potentially covering
134M
Americans (41%)
The remaining states
have traditional breach
notification and
security laws
New privacy regulation coverage by
U.S. population (327 million)
FL
NM
DE
MD
TX
OK
KS
NE
SD
NDMT
WY
CO
UT
ID
AZ
NV
WA
CA
OR
KY
ME
NY
PA
MI
VT
NH
MA
RI
CT
VA
WV
OH
INIL
NC
TN
SC
ALMS
AR
LA
MO
IA
MN
WI
NJ
GA
DC
AK
HI
Enacted law Bill introduced and/or passed
by House or Senate (includes
“In Committee”)
No dedicated consumer or
data privacy action currently
Dedicated privacy legislation by state7
Source:
7. Deloitte analysis of legislations related to privacy passed or enacted in 50 US states.
New privacy regulations, either enacted or under consideration, will potentially cover
54% of American consumers with new protections and expose retailers to penalties
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 10
Consumer businesses may have historically had lower compliance costs than other
major industries; however, privacy regulations will likely change that dynamic
Financial
services
Healthcare Retail
$30.9
million
$19.0
million
$11.5
million
Average compliance cost
by industry8
Regulatory compliance requirements
most difficult to achieve9
90%
55%
50%
39%
33%
22%
18%
17%
11%
General Data Protection
Regulation
Payment Card Industry Data
Security Standard
US state laws
HIPAA/HiTech
Sarbanes-Oxley
Country-level regulations
Federal cybersecurity directives
New York State Department of
Financial Services regulations
Gramm-Leach-Bliley Act (GLBA)
Source: 8 & 9. Ponemon Institute LLC – “The true cost of compliance with data protection regulations” (December 2017).
Notes: HIPPA/HiTech refers to Health Insurance Portability and Accountability Act/Health Information Technology for Economic and Clinical Health Act.
Consumer privacy laws,
which are directly applicable
to retail, are complex and
challenging to implement
10
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 12
Retailers are in a challenging position: They are not highly trusted AND consumers
hold them accountable to ensure privacy
Most to least trusted businesses10 Accountability for ensuring consumer privacy
in the retail industry11
(% of shoppers)
Retailers
63%
Federal
government
41%
Technology
partners
27%
Consumers
27% State government
23% Financial partners
20%
Source: 10 & 11. Deloitte – Data Privacy Survey for US Consumers (N=2,000)
Rank Sector
% of
respondents
1 Banks 63%
2 Hospitals 37%
3 Tax prep & legal services 37%
4 Credit reporting agencies 33%
5 Government 28%
6 Insurance 24%
7 Schools and universities 15%
8 Technology companies 11%
9 Nonprofits 10%
10 Airlines 8%
11 Restaurants 7%
12 Retailers 5%
13 Automotive 4%
14 Hotels 3%
15 Manufacturers 3%
16 Social media 3%
17 Print or broadcast media 2%
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 13
The disconnect between consumer perception and how retailers use the
data fuels the trust deficit
Source: Deloitte –Retail executive survey on US Consumer Data Privacy (N=201); Deloitte – Data Privacy Survey for US Consumers (N=2,000)
believe data is being predominately
used for targeted marketing, sharing
with third parties or outright sold to
third parties
have an opportunity to engage
consumers on how data is being
used to improve in-store and online
experiences, product selection, and
efficiency of retail operations
27%28%
36%
41%
55%
68%
53%52%
49%
46%
27%
45%
Increase
efficiency of
retail operations
Improve product
selection
Improve in-
store consumer
services or
experiences
Improve online
consumer
services or
experiences
Share data with
third-parties
Target
marketing
Consumers Executives
Data usage: Consumer and retailer perceptions
Consumers
Retailers
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 17
Source: Deloitte Retail executive survey on US Consumer Data Privacy (N=201)
Based on Deloitte’s survey of retail executives, there are four major areas of focus
when comparing and contrasting retailers’ privacy culture and privacy capabilities
Deloitte surveyed 201 retail executives on data privacy to understand how
retailers differentiate across a series of privacy tenets
Data
management
• Enterprise views on what
data needs to address and
who needs to access it
• Approach to determining
how data needs to be
managed and maintained
Security and
infrastructure
• Approach to manage
security for consumer and
employee data
• Focus on the infrastructure
and cyber needs to protect
data and manage third-
party access or use of data
Strategic
alignment
• Corporate governance
structure and integration
between privacy and
business strategies
• Internal environment and
culture supporting privacy,
empowering employees,
and driving data ethics
Consumer-
centricity
• Measures to elevate the
consumer to managing their
data and preferences
• Policies developed to engage
consumers and provide
visibility into corporate
actions, data collected, and
use of data
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 18
Overall, performance of retailers varies notably across the four tenets and only a third
of them (Leaders) manage to build capabilities and also nurture a culture of privacyPrivacycapabilities
Developed a privacy culture
Leaders’ privacy policy is well integrated into corporate
strategy and privacy capabilities are optimized with focus
on consumer-centricity
Adopters (both Testers and Aspirers) are increasing their
focus on privacy, however, have not yet fully embedded it
across the organization
Laggards have not elevated privacy and, as a result, it has
not gained strategic or operational traction
Methodology: Using retailer executive survey responses, we conducted cluster analysis to identify the key attributes
differentiating retailers and were able to identify three distinct segments: ‘Leaders’, ‘Adopters’, and ‘Laggards.’ These groups
exhibit statistically significant differences in their approach and performance around privacy related activities
Source: Deloitte Retail executive survey on US Consumer Data Privacy (N=201)
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 19
There is a significant difference in how these clusters approach and manage
privacy within their organizations
Implement privacy through contracts
and notices, with minimum
processes, or even without full
documentation
Drive continuous improvement
across key privacy areas, looking to
optimize, and customizes approaches.
Privacy is imbedded within the functions,
often seen as a compliance or legal
activity
Privacy involves the C-suite with
direction set at the top levels
Internal operations and product
selection
Consumer-focused services and
experiences (stores and digital)
Security measures in place to protect
the data
Consumer rights and nature of data
collected
Laggards Leaders
Across key aspects of privacy performance, ‘Leaders’ are over 10x more likely to have optimized
capabilities and culture than ‘Laggards’
Approach
Organization
structure
Top data uses
Consumer
communication
Source: Deloitte Retail executive survey on US Consumer Data Privacy (N=201)
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 20
Purpose of consumer data collection
optimally defined 7.6x
Usage of consumer data collected
optimally defined 39.0x
Optimized privacy governance structure 5.6x
Optimal integration of privacy with
corporate or business unit strategy
planning
10.5x
Data retrieval made easy to get a
holistic view of our customer 11.2x
Data structured to limit
access on a ‘need-only’ basis 3.5x
Optimized data collection
based on ‘data minimization’ 19.0x
Optimized information
security program to prevent violations 11.3x
5%
0%
7%
4%
5%
22%
2%
4%
Leaders consistently outperform Laggards across crucial privacy areas; however, the
industry should advance the standard
18%
15%
18%
20%
30%
38%
18%
21%
38%
39%
39%
42%
56%
77%
38%
45%
Leaders
trust-focused and
consumer-centric
Adopters
testers and
aspirers
Laggards
process-focused
and tactical
Leaders vs
Laggards
Strategic
alignment
Consumer-
centricity
Data
management
Security and
infrastructure
Source: Deloitte Retail executive survey on US Consumer Data Privacy (N=201)
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 24
With increased scrutiny on consumer and data privacy, there is a call to action to
define a new standard that works for consumers and retailers
24
03
02
01Lead with consumer-centricity and
consumer experience
Treat data as an asset, someone
should own and champion it
Embrace privacy by design03
02
01 Work with leading trade associations
to set the privacy standard
Be transparent with consumers and
regulators on source and uses of data
Actively engage with state and
federal lawmakers
Internal External
Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 25
Retailers who focus on
consumer privacy as a strategic
growth driver are poised to
create more meaningful data,
enhance consumer
engagement, and reduce risk
exposure all while staying
ahead of the evolution of
privacy in consumer business
About Deloitte
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (“DTTL”), its network of member
firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as
“Deloitte Global”) does not provide services to clients. In the United States, Deloitte refers to one or more of the US member firms of DTTL, their
related entities that operate using the “Deloitte” name in the United States, and their respective affiliates. Certain services may not be available to
attest clients under the rules and regulations of public accounting. Please see www.deloitte.com/about to learn more about our global network of
member firms.
This publication contains general information only and Deloitte is not, by means of this publication, rendering accounting, business, financial,
investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services, nor
should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may
affect your business, you should consult a qualified professional advisor. Deloitte shall not be responsible for any loss sustained by any person who
relies on this publication.
Copyright © 2019 Deloitte Development LLC. All rights reserved.
1 of 15

Recommended

TMT Outlook 2017: A new wave of advances offer opportunities and challenges by
TMT Outlook 2017:  A new wave of advances offer opportunities and challengesTMT Outlook 2017:  A new wave of advances offer opportunities and challenges
TMT Outlook 2017: A new wave of advances offer opportunities and challengesDeloitte United States
307.2K views47 slides
Fintech New York: Partnerships, Platforms and Open Innovation by
Fintech New York: Partnerships, Platforms and Open InnovationFintech New York: Partnerships, Platforms and Open Innovation
Fintech New York: Partnerships, Platforms and Open Innovationaccenture
17.6K views9 slides
How fit is your capital allocation strategy? by
How fit is your capital allocation strategy? How fit is your capital allocation strategy?
How fit is your capital allocation strategy? EY
196.1K views24 slides
Apache Hadoop Summit 2016: The Future of Apache Hadoop an Enterprise Architec... by
Apache Hadoop Summit 2016: The Future of Apache Hadoop an Enterprise Architec...Apache Hadoop Summit 2016: The Future of Apache Hadoop an Enterprise Architec...
Apache Hadoop Summit 2016: The Future of Apache Hadoop an Enterprise Architec...PwC
8K views18 slides
The Decade to Deliver: A Call to Business Action by
The Decade to Deliver: A Call to Business Action The Decade to Deliver: A Call to Business Action
The Decade to Deliver: A Call to Business Action accenture
57.1K views19 slides
EY Germany FinTech Landscape by
EY Germany FinTech LandscapeEY Germany FinTech Landscape
EY Germany FinTech LandscapeEY
9.1K views33 slides

More Related Content

What's hot

Whole Brain Leadership: New Rules of Engagement for the C-Suite| Accenture St... by
Whole Brain Leadership: New Rules of Engagement for the C-Suite| Accenture St...Whole Brain Leadership: New Rules of Engagement for the C-Suite| Accenture St...
Whole Brain Leadership: New Rules of Engagement for the C-Suite| Accenture St...accenture
18.8K views16 slides
Cracking the Code on Consumer Fraud | Accenture by
Cracking the Code on Consumer Fraud | AccentureCracking the Code on Consumer Fraud | Accenture
Cracking the Code on Consumer Fraud | Accentureaccenture
10.6K views10 slides
Tech Adoption and Strategy for Innovation & Growth by
Tech Adoption and Strategy for Innovation & GrowthTech Adoption and Strategy for Innovation & Growth
Tech Adoption and Strategy for Innovation & Growthaccenture
31.6K views15 slides
Pursuing Customer Inspired Growth by
Pursuing Customer Inspired GrowthPursuing Customer Inspired Growth
Pursuing Customer Inspired GrowthKearney
7.9K views20 slides
Lifting the Barriers to Retail Innovation in ASEAN | A.T. Kearney by
Lifting the Barriers to Retail Innovation in ASEAN | A.T. KearneyLifting the Barriers to Retail Innovation in ASEAN | A.T. Kearney
Lifting the Barriers to Retail Innovation in ASEAN | A.T. KearneyKearney
3.9K views14 slides
World Economic Forum: The power of analytics for better and faster decisions ... by
World Economic Forum: The power of analytics for better and faster decisions ...World Economic Forum: The power of analytics for better and faster decisions ...
World Economic Forum: The power of analytics for better and faster decisions ...PwC
206.4K views20 slides

What's hot(20)

Whole Brain Leadership: New Rules of Engagement for the C-Suite| Accenture St... by accenture
Whole Brain Leadership: New Rules of Engagement for the C-Suite| Accenture St...Whole Brain Leadership: New Rules of Engagement for the C-Suite| Accenture St...
Whole Brain Leadership: New Rules of Engagement for the C-Suite| Accenture St...
accenture18.8K views
Cracking the Code on Consumer Fraud | Accenture by accenture
Cracking the Code on Consumer Fraud | AccentureCracking the Code on Consumer Fraud | Accenture
Cracking the Code on Consumer Fraud | Accenture
accenture10.6K views
Tech Adoption and Strategy for Innovation & Growth by accenture
Tech Adoption and Strategy for Innovation & GrowthTech Adoption and Strategy for Innovation & Growth
Tech Adoption and Strategy for Innovation & Growth
accenture31.6K views
Pursuing Customer Inspired Growth by Kearney
Pursuing Customer Inspired GrowthPursuing Customer Inspired Growth
Pursuing Customer Inspired Growth
Kearney7.9K views
Lifting the Barriers to Retail Innovation in ASEAN | A.T. Kearney by Kearney
Lifting the Barriers to Retail Innovation in ASEAN | A.T. KearneyLifting the Barriers to Retail Innovation in ASEAN | A.T. Kearney
Lifting the Barriers to Retail Innovation in ASEAN | A.T. Kearney
Kearney3.9K views
World Economic Forum: The power of analytics for better and faster decisions ... by PwC
World Economic Forum: The power of analytics for better and faster decisions ...World Economic Forum: The power of analytics for better and faster decisions ...
World Economic Forum: The power of analytics for better and faster decisions ...
PwC 206.4K views
Strategy Study 2014 | A.T. Kearney by Kearney
Strategy Study 2014 | A.T. KearneyStrategy Study 2014 | A.T. Kearney
Strategy Study 2014 | A.T. Kearney
Kearney13.5K views
2016 Strategic Hospital Priorities Study by L.E.K. Consulting
2016 Strategic Hospital Priorities Study2016 Strategic Hospital Priorities Study
2016 Strategic Hospital Priorities Study
L.E.K. Consulting2.1K views
Intelligent Operations for Future-Ready Businesses | Accenture by accenture
Intelligent Operations for Future-Ready Businesses | AccentureIntelligent Operations for Future-Ready Businesses | Accenture
Intelligent Operations for Future-Ready Businesses | Accenture
accenture405.4K views
PwC's Global Technology IPO Review -- Q1 2015 by PwC
PwC's Global Technology IPO Review -- Q1 2015PwC's Global Technology IPO Review -- Q1 2015
PwC's Global Technology IPO Review -- Q1 2015
PwC 3.4K views
Federal Technology Vision 2021: Full U.S. Federal Survey Findings | Accenture by accenture
Federal Technology Vision 2021: Full U.S. Federal Survey Findings | AccentureFederal Technology Vision 2021: Full U.S. Federal Survey Findings | Accenture
Federal Technology Vision 2021: Full U.S. Federal Survey Findings | Accenture
accenture45.3K views
Australia: Taking Bigger Steps | A.T. Kearney by Kearney
Australia: Taking Bigger Steps | A.T. KearneyAustralia: Taking Bigger Steps | A.T. Kearney
Australia: Taking Bigger Steps | A.T. Kearney
Kearney4.6K views
Turning big data into big revenue by PwC
Turning big data into big revenueTurning big data into big revenue
Turning big data into big revenue
PwC 24.9K views
Accenture Consumer Behavior Research: The value shake-up by accenture
Accenture Consumer Behavior Research: The value shake-upAccenture Consumer Behavior Research: The value shake-up
Accenture Consumer Behavior Research: The value shake-up
accenture13.6K views
PwC’s new Golden Age Index – how well are countries harnessing the power of o... by PwC
PwC’s new Golden Age Index – how well are countries harnessing the power of o...PwC’s new Golden Age Index – how well are countries harnessing the power of o...
PwC’s new Golden Age Index – how well are countries harnessing the power of o...
PwC 3.6K views
Right Cloud Mindset: Survey Results Hospitality | Accenture by accenture
Right Cloud Mindset: Survey Results Hospitality | AccentureRight Cloud Mindset: Survey Results Hospitality | Accenture
Right Cloud Mindset: Survey Results Hospitality | Accenture
accenture10.7K views
Fueling the Energy Future by accenture
Fueling the Energy FutureFueling the Energy Future
Fueling the Energy Future
accenture29.6K views
The Accelerating Growth of Frictionless Commerce | A.T. Kearney by Kearney
The Accelerating Growth of Frictionless Commerce | A.T. KearneyThe Accelerating Growth of Frictionless Commerce | A.T. Kearney
The Accelerating Growth of Frictionless Commerce | A.T. Kearney
Kearney4.4K views
Global Capital Confidence Barometer 21st edition by EY
Global Capital Confidence Barometer 21st editionGlobal Capital Confidence Barometer 21st edition
Global Capital Confidence Barometer 21st edition
EY4.5K views

Similar to Consumer privacy in retail

U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ... by
U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...
U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...Ebiquity
201 views34 slides
Data Privacy and the GDPR by
Data Privacy and the GDPRData Privacy and the GDPR
Data Privacy and the GDPRDemandbase
595 views46 slides
Data opportunities mini whitepaper by
Data opportunities mini whitepaperData opportunities mini whitepaper
Data opportunities mini whitepaperRobert Bowstead
145 views11 slides
Internet security and privacy issues by
Internet security and privacy issuesInternet security and privacy issues
Internet security and privacy issuesJagdeepSingh394
89 views21 slides
How GDPR Guidelines Regulate Marketing Automation and Customer Engagement by
How GDPR Guidelines Regulate Marketing Automation and Customer EngagementHow GDPR Guidelines Regulate Marketing Automation and Customer Engagement
How GDPR Guidelines Regulate Marketing Automation and Customer EngagementRay Business Technologies
14 views3 slides
Driving change by
Driving changeDriving change
Driving changeReem Allos, MS JD
33 views4 slides

Similar to Consumer privacy in retail(20)

U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ... by Ebiquity
U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...
U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...
Ebiquity 201 views
Data Privacy and the GDPR by Demandbase
Data Privacy and the GDPRData Privacy and the GDPR
Data Privacy and the GDPR
Demandbase595 views
Data opportunities mini whitepaper by Robert Bowstead
Data opportunities mini whitepaperData opportunities mini whitepaper
Data opportunities mini whitepaper
Robert Bowstead145 views
Internet security and privacy issues by JagdeepSingh394
Internet security and privacy issuesInternet security and privacy issues
Internet security and privacy issues
JagdeepSingh39489 views
Joint ad trade letter to ag becerra re ccpa 1.31.2019 by Greg Sterling
Joint ad trade letter to ag becerra re ccpa 1.31.2019Joint ad trade letter to ag becerra re ccpa 1.31.2019
Joint ad trade letter to ag becerra re ccpa 1.31.2019
Greg Sterling1.5K views
Mitigating Data Security Risks at Broker Dealers by Broadridge
Mitigating Data Security Risks at Broker DealersMitigating Data Security Risks at Broker Dealers
Mitigating Data Security Risks at Broker Dealers
Broadridge387 views
CSR PII White Paper by Dmcenter
CSR PII White PaperCSR PII White Paper
CSR PII White Paper
Dmcenter279 views
Big_data_analytics_for_life_insurers_published by Shradha Verma
Big_data_analytics_for_life_insurers_publishedBig_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_published
Shradha Verma443 views
Big data analytics for life insurers by dipak sahoo
Big data analytics for life insurersBig data analytics for life insurers
Big data analytics for life insurers
dipak sahoo6K views
GDPR: Data Privacy in the New by accenture
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the New
accenture3.1K views
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf by CIOWomenMagazine
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdfData Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Life Sciences: Leveraging Customer Data for Commercial Success by Cognizant
Life Sciences: Leveraging Customer Data for Commercial SuccessLife Sciences: Leveraging Customer Data for Commercial Success
Life Sciences: Leveraging Customer Data for Commercial Success
Cognizant618 views
Life Sciences: Leveraging Customer Data for Commercial Success by Cognizant
Life Sciences: Leveraging Customer Data for Commercial SuccessLife Sciences: Leveraging Customer Data for Commercial Success
Life Sciences: Leveraging Customer Data for Commercial Success
Cognizant546 views
Managing Consumer Data Privacy by Gigya
Managing Consumer Data PrivacyManaging Consumer Data Privacy
Managing Consumer Data Privacy
Gigya954 views
When consumers control data whitepaper by Duy, Vo Hoang
When consumers control data whitepaperWhen consumers control data whitepaper
When consumers control data whitepaper
Duy, Vo Hoang7 views

More from Deloitte United States

Turning diligence insights into actionable integration steps by
Turning diligence insights into actionable integration stepsTurning diligence insights into actionable integration steps
Turning diligence insights into actionable integration stepsDeloitte United States
161 views8 slides
New SEC Cyber Rules to Push Publics and Their Third Parties to Strengthen Pro... by
New SEC Cyber Rules to Push Publics and Their Third Parties to Strengthen Pro...New SEC Cyber Rules to Push Publics and Their Third Parties to Strengthen Pro...
New SEC Cyber Rules to Push Publics and Their Third Parties to Strengthen Pro...Deloitte United States
203 views7 slides
Pivotal Moments All-in-One_FINAL.pdf by
Pivotal Moments All-in-One_FINAL.pdfPivotal Moments All-in-One_FINAL.pdf
Pivotal Moments All-in-One_FINAL.pdfDeloitte United States
93 views54 slides
Divestiture Trends: 2023 Could See More Sell-Offs, but Expect Lengthier and M... by
Divestiture Trends: 2023 Could See More Sell-Offs, but Expect Lengthier and M...Divestiture Trends: 2023 Could See More Sell-Offs, but Expect Lengthier and M...
Divestiture Trends: 2023 Could See More Sell-Offs, but Expect Lengthier and M...Deloitte United States
194 views8 slides
Cash and Liquidity Management Confidence Levels Declining Among Executives, a... by
Cash and Liquidity Management Confidence Levels Declining Among Executives, a...Cash and Liquidity Management Confidence Levels Declining Among Executives, a...
Cash and Liquidity Management Confidence Levels Declining Among Executives, a...Deloitte United States
211 views9 slides
Lead Through Disruption Guide PDF by
Lead Through Disruption Guide PDFLead Through Disruption Guide PDF
Lead Through Disruption Guide PDFDeloitte United States
65 views39 slides

More from Deloitte United States(20)

Turning diligence insights into actionable integration steps by Deloitte United States
Turning diligence insights into actionable integration stepsTurning diligence insights into actionable integration steps
Turning diligence insights into actionable integration steps
New SEC Cyber Rules to Push Publics and Their Third Parties to Strengthen Pro... by Deloitte United States
New SEC Cyber Rules to Push Publics and Their Third Parties to Strengthen Pro...New SEC Cyber Rules to Push Publics and Their Third Parties to Strengthen Pro...
New SEC Cyber Rules to Push Publics and Their Third Parties to Strengthen Pro...
Divestiture Trends: 2023 Could See More Sell-Offs, but Expect Lengthier and M... by Deloitte United States
Divestiture Trends: 2023 Could See More Sell-Offs, but Expect Lengthier and M...Divestiture Trends: 2023 Could See More Sell-Offs, but Expect Lengthier and M...
Divestiture Trends: 2023 Could See More Sell-Offs, but Expect Lengthier and M...
Cash and Liquidity Management Confidence Levels Declining Among Executives, a... by Deloitte United States
Cash and Liquidity Management Confidence Levels Declining Among Executives, a...Cash and Liquidity Management Confidence Levels Declining Among Executives, a...
Cash and Liquidity Management Confidence Levels Declining Among Executives, a...
Could M&A Activity be a Springboard for Controllership Transformation? by Deloitte United States
Could M&A Activity be a Springboard for Controllership Transformation?Could M&A Activity be a Springboard for Controllership Transformation?
Could M&A Activity be a Springboard for Controllership Transformation?
Many C-suite Executives Say Their Organizations Want to Build Trust in Year A... by Deloitte United States
Many C-suite Executives Say Their Organizations Want to Build Trust in Year A...Many C-suite Executives Say Their Organizations Want to Build Trust in Year A...
Many C-suite Executives Say Their Organizations Want to Build Trust in Year A...
SOX modernization: Optimizing compliance while extracting value by Deloitte United States
SOX modernization: Optimizing compliance while extracting valueSOX modernization: Optimizing compliance while extracting value
SOX modernization: Optimizing compliance while extracting value
Future of controls: risks, realities, and next-generation trends by Deloitte United States
Future of controls: risks, realities, and next-generation trendsFuture of controls: risks, realities, and next-generation trends
Future of controls: risks, realities, and next-generation trends
Driving growth and differential performance among Class I railroads by Deloitte United States
Driving growth and differential performance among Class I railroadsDriving growth and differential performance among Class I railroads
Driving growth and differential performance among Class I railroads
Working capital management a top priority for many executives in year ahead by Deloitte United States
Working capital management a top priority for many executives in year aheadWorking capital management a top priority for many executives in year ahead
Working capital management a top priority for many executives in year ahead

Recently uploaded

Supermarket Floral Ad Roundup- Week 47.pdf by
Supermarket Floral Ad Roundup- Week 47.pdfSupermarket Floral Ad Roundup- Week 47.pdf
Supermarket Floral Ad Roundup- Week 47.pdfKarliNelson4
55 views40 slides
Supermarket Floral Ad Roundup- Week 48.pdf by
Supermarket Floral Ad Roundup- Week 48.pdfSupermarket Floral Ad Roundup- Week 48.pdf
Supermarket Floral Ad Roundup- Week 48.pdfKarliNelson4
59 views40 slides
EXW_MOUSSY_VINTAGE_PRE-FALL_2024_MV_WOMENS.pdf by
EXW_MOUSSY_VINTAGE_PRE-FALL_2024_MV_WOMENS.pdfEXW_MOUSSY_VINTAGE_PRE-FALL_2024_MV_WOMENS.pdf
EXW_MOUSSY_VINTAGE_PRE-FALL_2024_MV_WOMENS.pdfparagon49
8 views7 slides
15 Minute Breakdown: Navigating the Evolution: Unraveling the Past Decade's S... by
15 Minute Breakdown: Navigating the Evolution: Unraveling the Past Decade's S...15 Minute Breakdown: Navigating the Evolution: Unraveling the Past Decade's S...
15 Minute Breakdown: Navigating the Evolution: Unraveling the Past Decade's S...Tinuiti
65 views17 slides
MoussyVintagePF24DDP.pdf by
MoussyVintagePF24DDP.pdfMoussyVintagePF24DDP.pdf
MoussyVintagePF24DDP.pdfparagon49
32 views7 slides
Your Source for RJ's Fabulicious & more at S4S confectionery wholesalers by
 Your Source for RJ's  Fabulicious & more at S4S confectionery wholesalers Your Source for RJ's  Fabulicious & more at S4S confectionery wholesalers
Your Source for RJ's Fabulicious & more at S4S confectionery wholesalersStock4 shops
6 views1 slide

Recently uploaded(6)

Supermarket Floral Ad Roundup- Week 47.pdf by KarliNelson4
Supermarket Floral Ad Roundup- Week 47.pdfSupermarket Floral Ad Roundup- Week 47.pdf
Supermarket Floral Ad Roundup- Week 47.pdf
KarliNelson455 views
Supermarket Floral Ad Roundup- Week 48.pdf by KarliNelson4
Supermarket Floral Ad Roundup- Week 48.pdfSupermarket Floral Ad Roundup- Week 48.pdf
Supermarket Floral Ad Roundup- Week 48.pdf
KarliNelson459 views
EXW_MOUSSY_VINTAGE_PRE-FALL_2024_MV_WOMENS.pdf by paragon49
EXW_MOUSSY_VINTAGE_PRE-FALL_2024_MV_WOMENS.pdfEXW_MOUSSY_VINTAGE_PRE-FALL_2024_MV_WOMENS.pdf
EXW_MOUSSY_VINTAGE_PRE-FALL_2024_MV_WOMENS.pdf
paragon498 views
15 Minute Breakdown: Navigating the Evolution: Unraveling the Past Decade's S... by Tinuiti
15 Minute Breakdown: Navigating the Evolution: Unraveling the Past Decade's S...15 Minute Breakdown: Navigating the Evolution: Unraveling the Past Decade's S...
15 Minute Breakdown: Navigating the Evolution: Unraveling the Past Decade's S...
Tinuiti65 views
MoussyVintagePF24DDP.pdf by paragon49
MoussyVintagePF24DDP.pdfMoussyVintagePF24DDP.pdf
MoussyVintagePF24DDP.pdf
paragon4932 views
Your Source for RJ's Fabulicious & more at S4S confectionery wholesalers by Stock4 shops
 Your Source for RJ's  Fabulicious & more at S4S confectionery wholesalers Your Source for RJ's  Fabulicious & more at S4S confectionery wholesalers
Your Source for RJ's Fabulicious & more at S4S confectionery wholesalers
Stock4 shops6 views

Consumer privacy in retail

  • 1. Consumer privacy in retail: The next regulatory and competitive frontier
  • 2. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 2 Retail is at an inflection point with consumer privacy. The industry, leaders included, should benefit by striving for a new standard
  • 3. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 3 Consumers are becoming more privacy aware Some consumers are concerned about data privacy and want more control over data as they are aware of more data breaches Retailers should become data-wise and privacy conscious Some retailers struggle to develop privacy policies that align to business strategies, keep up with data proliferation, and deal with system complexity States are enacting new privacy regulations New regulations are coming as nearly half of US states are developing data policy legislation Consumers are increasingly aware of threats to their privacy and personal data; meanwhile, several states are introducing and enacting new privacy legislation
  • 4. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 6 Individuals are attempting to manage significant “digital exhaust” that comes from all aspects of their lives Mostly user controlled Minimally user controlled Publicly- available information Information shared voluntarily Career Government issued IDs Politics Information from data breaches Online and social media activity Family details Basic internet profile Login credential Social security number Geo location data Credit score/ history General purchase history Device ownership Photos Friends/ colleagues Education history Personal identifiers Healthcare /insurance identifiers Financial history User account details Medical prescriptions Cross- site history System info Shopping preferences Payment processing data Legal records Customer service logs Third- party tracking Media preferences Home address Telephone call records Demo- graphic features
  • 5. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 8 3 states have enacted dedicated privacy laws covering 42.5M Americans (13%) 19 other states are debating new privacy laws potentially covering 134M Americans (41%) The remaining states have traditional breach notification and security laws New privacy regulation coverage by U.S. population (327 million) FL NM DE MD TX OK KS NE SD NDMT WY CO UT ID AZ NV WA CA OR KY ME NY PA MI VT NH MA RI CT VA WV OH INIL NC TN SC ALMS AR LA MO IA MN WI NJ GA DC AK HI Enacted law Bill introduced and/or passed by House or Senate (includes “In Committee”) No dedicated consumer or data privacy action currently Dedicated privacy legislation by state7 Source: 7. Deloitte analysis of legislations related to privacy passed or enacted in 50 US states. New privacy regulations, either enacted or under consideration, will potentially cover 54% of American consumers with new protections and expose retailers to penalties
  • 6. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 10 Consumer businesses may have historically had lower compliance costs than other major industries; however, privacy regulations will likely change that dynamic Financial services Healthcare Retail $30.9 million $19.0 million $11.5 million Average compliance cost by industry8 Regulatory compliance requirements most difficult to achieve9 90% 55% 50% 39% 33% 22% 18% 17% 11% General Data Protection Regulation Payment Card Industry Data Security Standard US state laws HIPAA/HiTech Sarbanes-Oxley Country-level regulations Federal cybersecurity directives New York State Department of Financial Services regulations Gramm-Leach-Bliley Act (GLBA) Source: 8 & 9. Ponemon Institute LLC – “The true cost of compliance with data protection regulations” (December 2017). Notes: HIPPA/HiTech refers to Health Insurance Portability and Accountability Act/Health Information Technology for Economic and Clinical Health Act. Consumer privacy laws, which are directly applicable to retail, are complex and challenging to implement 10
  • 7. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 12 Retailers are in a challenging position: They are not highly trusted AND consumers hold them accountable to ensure privacy Most to least trusted businesses10 Accountability for ensuring consumer privacy in the retail industry11 (% of shoppers) Retailers 63% Federal government 41% Technology partners 27% Consumers 27% State government 23% Financial partners 20% Source: 10 & 11. Deloitte – Data Privacy Survey for US Consumers (N=2,000) Rank Sector % of respondents 1 Banks 63% 2 Hospitals 37% 3 Tax prep & legal services 37% 4 Credit reporting agencies 33% 5 Government 28% 6 Insurance 24% 7 Schools and universities 15% 8 Technology companies 11% 9 Nonprofits 10% 10 Airlines 8% 11 Restaurants 7% 12 Retailers 5% 13 Automotive 4% 14 Hotels 3% 15 Manufacturers 3% 16 Social media 3% 17 Print or broadcast media 2%
  • 8. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 13 The disconnect between consumer perception and how retailers use the data fuels the trust deficit Source: Deloitte –Retail executive survey on US Consumer Data Privacy (N=201); Deloitte – Data Privacy Survey for US Consumers (N=2,000) believe data is being predominately used for targeted marketing, sharing with third parties or outright sold to third parties have an opportunity to engage consumers on how data is being used to improve in-store and online experiences, product selection, and efficiency of retail operations 27%28% 36% 41% 55% 68% 53%52% 49% 46% 27% 45% Increase efficiency of retail operations Improve product selection Improve in- store consumer services or experiences Improve online consumer services or experiences Share data with third-parties Target marketing Consumers Executives Data usage: Consumer and retailer perceptions Consumers Retailers
  • 9. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 17 Source: Deloitte Retail executive survey on US Consumer Data Privacy (N=201) Based on Deloitte’s survey of retail executives, there are four major areas of focus when comparing and contrasting retailers’ privacy culture and privacy capabilities Deloitte surveyed 201 retail executives on data privacy to understand how retailers differentiate across a series of privacy tenets Data management • Enterprise views on what data needs to address and who needs to access it • Approach to determining how data needs to be managed and maintained Security and infrastructure • Approach to manage security for consumer and employee data • Focus on the infrastructure and cyber needs to protect data and manage third- party access or use of data Strategic alignment • Corporate governance structure and integration between privacy and business strategies • Internal environment and culture supporting privacy, empowering employees, and driving data ethics Consumer- centricity • Measures to elevate the consumer to managing their data and preferences • Policies developed to engage consumers and provide visibility into corporate actions, data collected, and use of data
  • 10. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 18 Overall, performance of retailers varies notably across the four tenets and only a third of them (Leaders) manage to build capabilities and also nurture a culture of privacyPrivacycapabilities Developed a privacy culture Leaders’ privacy policy is well integrated into corporate strategy and privacy capabilities are optimized with focus on consumer-centricity Adopters (both Testers and Aspirers) are increasing their focus on privacy, however, have not yet fully embedded it across the organization Laggards have not elevated privacy and, as a result, it has not gained strategic or operational traction Methodology: Using retailer executive survey responses, we conducted cluster analysis to identify the key attributes differentiating retailers and were able to identify three distinct segments: ‘Leaders’, ‘Adopters’, and ‘Laggards.’ These groups exhibit statistically significant differences in their approach and performance around privacy related activities Source: Deloitte Retail executive survey on US Consumer Data Privacy (N=201)
  • 11. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 19 There is a significant difference in how these clusters approach and manage privacy within their organizations Implement privacy through contracts and notices, with minimum processes, or even without full documentation Drive continuous improvement across key privacy areas, looking to optimize, and customizes approaches. Privacy is imbedded within the functions, often seen as a compliance or legal activity Privacy involves the C-suite with direction set at the top levels Internal operations and product selection Consumer-focused services and experiences (stores and digital) Security measures in place to protect the data Consumer rights and nature of data collected Laggards Leaders Across key aspects of privacy performance, ‘Leaders’ are over 10x more likely to have optimized capabilities and culture than ‘Laggards’ Approach Organization structure Top data uses Consumer communication Source: Deloitte Retail executive survey on US Consumer Data Privacy (N=201)
  • 12. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 20 Purpose of consumer data collection optimally defined 7.6x Usage of consumer data collected optimally defined 39.0x Optimized privacy governance structure 5.6x Optimal integration of privacy with corporate or business unit strategy planning 10.5x Data retrieval made easy to get a holistic view of our customer 11.2x Data structured to limit access on a ‘need-only’ basis 3.5x Optimized data collection based on ‘data minimization’ 19.0x Optimized information security program to prevent violations 11.3x 5% 0% 7% 4% 5% 22% 2% 4% Leaders consistently outperform Laggards across crucial privacy areas; however, the industry should advance the standard 18% 15% 18% 20% 30% 38% 18% 21% 38% 39% 39% 42% 56% 77% 38% 45% Leaders trust-focused and consumer-centric Adopters testers and aspirers Laggards process-focused and tactical Leaders vs Laggards Strategic alignment Consumer- centricity Data management Security and infrastructure Source: Deloitte Retail executive survey on US Consumer Data Privacy (N=201)
  • 13. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 24 With increased scrutiny on consumer and data privacy, there is a call to action to define a new standard that works for consumers and retailers 24 03 02 01Lead with consumer-centricity and consumer experience Treat data as an asset, someone should own and champion it Embrace privacy by design03 02 01 Work with leading trade associations to set the privacy standard Be transparent with consumers and regulators on source and uses of data Actively engage with state and federal lawmakers Internal External
  • 14. Consumer privacy: The new regulatory frontierCopyright © 2019 Deloitte Development LLC. All rights reserved. 25 Retailers who focus on consumer privacy as a strategic growth driver are poised to create more meaningful data, enhance consumer engagement, and reduce risk exposure all while staying ahead of the evolution of privacy in consumer business
  • 15. About Deloitte Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (“DTTL”), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as “Deloitte Global”) does not provide services to clients. In the United States, Deloitte refers to one or more of the US member firms of DTTL, their related entities that operate using the “Deloitte” name in the United States, and their respective affiliates. Certain services may not be available to attest clients under the rules and regulations of public accounting. Please see www.deloitte.com/about to learn more about our global network of member firms. This publication contains general information only and Deloitte is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte shall not be responsible for any loss sustained by any person who relies on this publication. Copyright © 2019 Deloitte Development LLC. All rights reserved.