Hi-Mark To Boost Data Privacy W/ Encryption Solution
<B>Hi-Mark To Boost Data Privacy W/ Encryption Solution</B>
By Jay Campbell
Attempting to tackle data privacy and confidentiality concerns brought about by both European Union regulations and the controversy over Continental Airlines' Corporate Insight program (BTN, Feb. 26), Hi-Mark Software within 30 days will finish developing high-end data encryption for its DataMan consolidation solution that will allow users to hide the contents of specific data fields.
Upon completion of development and after satisfying legal guidelines, the encryption service will be available for every back-office system with which DataMan works. It will allow users to check off which lines of data they want encrypted, going beyond the encryption commonly used to secure all the data in a given file transfer.
"With all the privacy issues, we're deploying a solution to allow each corporation to work in conjunction with its travel agency and determine the data elements they would like encrypted," said Hi-Mark president Kevin Austin. "We'll specify an encryption key that only the customer holds, so that at the source of the data the handoff is all encrypted and can't be decrypted by Hi-Mark, an airline or anyone else."
Users then could, for example, encrypt such private information as names and credit cards to meet EU standards, or supplier names to appease the concerns on contractual confidentiality brought about by the Continental hubbub.
Austin thinks Hi-Mark is uniquely positioned to solve data privacy concerns. "We're at the source, and under the EU law, there's no liability for receiving it, but there is for sending it," he said. "You're going to see more countries adopting stricter privacy data laws."
Now, Austin said, in order to keep up with privacy guidelines, large travel agencies are attempting to shift legal obligations for privacy protection to other parties, and either are not sending or "masking the data, which is a nice word for destroying the data."
Christopher Brittin, executive vice president of McLean, Va.-based TRX Data Services, said his company has encountered some refusal by European travel agencies to send data outside of the EU for fear of breaking EU rules. "The directive states that you cannot send information outside the EU that can be used to identify an individual. There are negotiations going on between the United States and the EU to try and get the United States qualified as a 'safe harbor.' "
In the meantime, TRX handles those situations by having either the agency send data directly to the corporation or having it consolidated at a satellite office within the EU. Though some said enforcement by the EU has been scant, Brittin said enforcement "has become more visible day to day."
I:FAO North America CEO Roger Hunt has not experienced the same difficulties with agency data sources, but he agreed that "masking does very effectively ruin the data."
Michael Whitesage, president of Albuquerque, N.M.-based The Prism Group, which works with Continental on its controversial program, also said data is being damaged by the concern about confidentiality. But, he said, "Privacy is not a concern when a company is receiving its own data or is working with its designated consolidator. We want the data intact, and we don't encrypt it when it goes to the airline, we eliminate it."
Whitesage called Hi-Mark's plan "a good improvement," though he added that, "This needs to be seen in a larger context, because micro-managing the issue doesn't provide solutions to the whole problem. Where we have concern is about the transfer of personal information, which can be masked at the source.
"The other issue is not privacy, it's confidentiality of data that one party may consider proprietary," continued Whitesage. "So now we have carriers claiming their data are confidential and that data cannot be supplied to any third party. What needs to be established is a protocol that safeguards the privacy of the individual and the confidentiality of the company, and that has been done. Prism developed the protocol, and when we pass data to the third party, the data are masked to meet that protocol."
Hi-Mark's plan is to eliminate the need for a protocol, which Austin doubted hundreds of companies could follow. "There's no way all these groups will coordinate to provide a consistent encryption format," he said. "The issue is the carriers having access to detailed information. I don't think Continental is asking for detailed data, but for a lot of people this is a matter of confidence.