#23 – Why is privacy software so crap?
In this episode I talk about why privacy software seems to miss the mark so badly, why we all seem to hate it so much and whose fault it is that us privacy folk are so unhappy with it. I give some advice for vendors and privacy folk on how to make things better and explain what people on the front line with budget to spend want to see.
Audio
Transcript
Hello and welcome to the GDPR Guy. I’m Carl Gottlieb, your host and resident privacy advisor.
In this episode I thought it’s finally time to address the elephant in the privacy room. You know it, I know it, everybody knows it. Privacy software is crap.
I’m talking about your data mapping software, your cookie banner software, your vendor management tool, your assessment software, your rights management software. All of it. It’s all crap. You hate using it, I hate using it, we all hate it. Because it is crap.
Or is it?
Privacy software is something us privacy folk work with every day and we have a mainly hate/hate relationship with it. And I find myself asking why quite a lot. And I’m hugely to blame because I influence so many of my clients’ purchases of this software, so a lot of failure should probably come back to me.
And I appreciate that using the term “Privacy Software” encompasses a hell of a lot, and is probably too wide a category to be so opinionated about, but here we are.
Putting aside the actual quality of the software for a moment, the biggest reason why we all struggle to love privacy software is us. You and me. The users. Privacy software is primarily there to take the pain away. We buy it in the hope that our crappy problem of managing cookies, or data flows or vendor due diligence will be taken away – magically automated and become nothing more than a painful memory of the old days of manual grunt work.
But no. We wade through the painful implementation period and then start using it, only to find that the painful work is still there, but somehow it’s now even more painful. And this is where we’re to blame and not the software.
What you’re buying with these tools is forced procedure. You’re often replacing a void of work, or maybe a chaos of work, with something highly structured, ordered, logical and procedure driven. Now that’s ideal in theory, but you’re often moving from a place of doing less work to doing more work. You’re now managing things you weren’t actively managing before. Your workload has gone up. And that work is, let’s face it, pretty boring work. A lot of the backend privacy management work is boring and now you’ve bought some software to lock yourself into doing much more of it. And like me, you probably won the budget for the software by agreeing to some KPIs and a return on investment for when using the software. So you can’t really back out of using it now.
So yes, it’s your fault why you don’t like the software.
In the main.
But the software itself shouldn’t be let off the hook too easily, because yes, a lot of it is just bad, inadequate, poorly thought out and doesn’t match the dream of what was sold.
Maybe the most salient of examples is data mapping software and you can lump in any of the data discovery tools into this as well which supposedly will fulfil an access request for you. The dream is that this software does one or both of these things, provide a manual inventory where you can record all of your data processing activities, and magically find, understand and catalogue all of those data processing activities for you.
Starting with the manual inventory thing, this is nothing more than a fancy spreadsheet. It’s a database with a few forms. And somehow they can’t get that right. Want to embed all that lovely content on your intranet for the rest of your company to see? Nope. Want to have that data synching with another tool easily through something like Zapier? Well, maybe, but it’ll mostly be through our poorly documented API and get ready to pay for the advanced integration licence because you want to do something vaguely fancy, or useful. Oh, you just want to customise how this all looks so it might in some way fit your organisation’s quirks – no chance whatsoever.
If the product positioning is that it’s basically a database with a front end but it works brilliantly then it needs to work brilliantly. And because they don’t I built my own which now most of my clients use instead.
And as for automation, you’ve got several challenges here. Data needs to be discovered accurately and completely. Both are equally as important. You can’t apply an 80/20 good enough approach to this because you can’t miss a piece of software. You can’t miss an important database. You can’t miss a risky data processing activity. The big dependency is this tool requires being told where to look. It needs you to tell it what you have to some degree, maybe by pointing it at some other inventory or authentication tool. But then the shadow IT problem comes in here and you’re now missing the huge amount of software and data flows that aren’t centrally controlled.
And on top of all of that information gathering, you need to actually understand that information. And that is usually an area where technology fails badly. People fail at this too so it’s no surprise technology struggles. It’s all well and good being told that a database or a data element has been discovered in AWS, but if technology can’t magically understand what it does, what it’s for and what processing activities use it, then you’ve now got a load of work finding someone who does. And that’s usually really difficult. Is it a Product Manager, an engineer, an IT person? And which one. How the hell do you know? And when you do eventually speak to the right people, how do you know what they’re telling you is complete and accurate? The tool was meant to solve this whole problem, but rarely does.
So at best, you’ve got an automation tool that has found 80% of the stuff within 80% of things you know about, which is maybe 80% of what’s out there. You don’t know what it’s missed, what it’s misunderstood and what gaps you’ve now got to complete manually. You’re in the realm of the unknown unknowns.
Now I’m not saying this is easy. Essentially we’ve got technology trying to solve a problem that has never been solved manually. But in my view the reason the software is so far off the mark is that the software is technology-driven rather than value-driven.
As an example, let’s imagine you’re a technical founder wanting to build a new product. You’ve heard the privacy market is a good sector and that data discovery is a major challenge. So you immediately start building tech that discovers and attempts to understand data. Maybe it scans your website, maybe it scans AWS, maybe it scans GitHub. Ultimately you’re building a scanning tool like a thousand other people have done before. And the more you double down on building the best scanning tool out there, the more you miss what customers actually want – and it’s not a scanning tool. They want their problem taken away, in the same way as a person just wants a picture hung on a wall. They don’t want a drill, a screw, a wall plug, a tradesman, the clean up, or an invoice. They just want an outcome and not all the crap that might help get them there. Vendors will often build technology and lose sight of the outcomes people actually want.
Let’s talk about OneTrust for a second. I get that their software or support can be challenging at times, but that’s likely no different to any other vendor. But what is super interesting about OneTrust is how it started out life. Before building any technology, the founder, Kabir, just sat down with potential buyers with a load of post-it notes of potential product features and a fictional budget and asked which features and products they would pay for and prioritise. He then took what he learned and built the most successful privacy vendor in history. He chose to precisely align what he built with what people genuinely wanted. Whether that approach continues to this day is another question, but this outcome focused mindset is what all vendors in privacy need to think about.
The reason Kabir took this approach is he is a very smart business man first and foremost. Listen to my podcast interview with him if you want to hear more. But for technology centric founders, the biggest barrier is that most are trying to solve problems that they themselves have never had to deal with.
It’s the mentality of, “I imagine handling access requests is hard so I’m going to build you a tool that handles it.” Empathy will only get you so far if you’ve never actually faced that pain on a daily basis. It’s like me trying to create a revolutionary baseball bat, despite me never having played the sport. The annoying reality is that the best tech will be built by those whose day-to-day problems it solves. It’s why I built my own data mapping and compliance management software that most of my clients use. I don’t sell it, but my clients prefer it and they inevitably rip out their expensive vendors and use that budget elsewhere.
For founders that haven’t worked in privacy, you need to act like Kabir and listen. And keep listening and never stop listening. It doesn’t matter if what a customer asks for is technically hard or wasn’t designed to do. If the customer values it and expects it from your product then you’d better build it, even if there’s no extra revenue coming from that feature. Product Managers will focus solely on revenue led feature development, but they’ll never see the renewals that never happened. They’ll never see the customer turnover that arose from customers like you and me that think, “Their product just isn’t all there. It doesn’t do what I need it to do. I don’t hate it but I won’t be renewing. I’ll go with a competitor or I’ll build it myself.”
One of the great jobs I get to do as a consultant is advise tech founders on what should go into their product. I’ve some colleagues that do this for legal tech too. It can feel like an unnecessary cost for vendors to take on at the very early stages, but it can be make or break for the company in the short term for finding product market fit, and it’s essential for retaining customers in the long run. And where runway is tight, it’s not uncommon for vendors to offer consultants advisory stock instead of consultancy fees. Whatever works – just get experts on your side that feel the user pain and can advise on what people really will buy.
Let’s talk about pricing for a second. Vendors – don’t be stupid here. Land and expand. Land and expand. All you need to do is get us using your product, make sure we love it and we will buy more and give you referrals. So that means making it super easy to buy from you.
I want to be able to use your product instantly for free. I don’t need a sales person getting me enrolled in a proof of concept. A 14 day free trial is fine.
I want to see pricing on your website.
I want to be able to buy now with a credit card.
I want to be able to scale up to add more features and users as we do more with your product.
On scaling, vendors – please please please scale down so I can scale up. I should be able to buy a 1 user licence for a small fee and then grow all that as our need grows. Extremely successful companies such as Airtable are built on this exact model so you can do the same.
Help us buy from you. We do have some money to spend so help us spend it.
Speaking of money, don’t forget that because all this software inevitably needs people, you’ve got to budget for people too, both for setup and for ongoing running. This might not be a real cost per se, in that you probably won’t end up hiring new people, but the return on investment for any business case to win the software budget in the first place should really factor all this in. And it also helps clarify the minds of everyone around, of what value the software will actually bring. It won’t solve all the problems but it should help a lot. It will add some new work but it will hopefully take a way a lot too.
Until privacy technology vendors see the light, we’re stuck with what we have so it’s incumbent on us to make this work. You’ve just got to get over the fact that most privacy work is really boring, and that this software will likely give you more boring work to do. That’s the job. Deal with it. Privacy is an overpaid industry, just like Legal or IT or Security. Boring work is your cross to bear.
So please keep remembering that every problem needs a combined solution of machine and human. And the more human involvement you put in, the better the machines will operate. But also don’t be afraid to question whether you really need this technology in the first place. Do you really need that automation? Would a spreadsheet and a diligent human actually be better? Or maybe you could build a tool better yourself. You’re not trapped by what the technology market tells you to do or to buy.
So is privacy software actually crap? Generally I’d still say a resounding yes, but I’m positive things will get better. There are a few great products out there, especially some in sectors adjacent to privacy such as legal and security and general IT that can be used over in privacy. Ask your peers for what they’re using, and if you want my unvarnished opinions then please get in touch.
Thanks for listening.
More Episodes of The GDPR Guy
