Search This Blog

Monday, September 04, 2006

Bush/Cheney Reinvent Big Brother III

Nixon, Although Sneaky, At Least Had His Capable Moments


Molly Ivins is one of my favorite columnists. She has a great political mind and an amazing ability to put the right words together that always seem to hit the point. She did this particularly well in her August 21, 2006, piece, “Big Brother Bush,” posted on AlterNet. It drew some comparisons between Richard Nixon and George W. Bush, with the latter not even finishing as a contender. “Testy Kid,” as she describes Bush, can’t even uphold the Constitution that put him in office.

Nixon Also Gave Us Dick Cheney and Donald Rumsfeld


Ivins cites as an example of Bush’s Big Brother, the Pentagon’s giant data-mining program called Total Information Awareness (TIA), designed to tie databases together world-wide, and use the data to spy on anyone they chose. After pressure from just about everybody, the TIA was shut down, or as Molly puts it: “As often happens with this administration, it turned out they just changed the name and made the program less visible.”

Working in the background during all this time were graduates of Nixon’s regular classes on Deceit: 101, Dick Cheney and Donald Rumsfeld, taking the reins on every available means to pry into the lives of innocent Americans.

TIA Sets Stage for NSA Spying


Then someone convinced the gung ho Bush that using the very secretive National Security Agency (NSA) to do this surveillance of U.S. citizens could keep it all under wraps and, once again, the Constitution be damned, full speed ahead. Fortunately, the New York Times exposed this attempt, and it ended up in Judge Anna Diggs Taylor’s court. Her decision was that the NSA’s warrant-less surveillance authorized by George W. Bush was unconstitutional.

This decision, of course is being appealed by the administration, and you will want to read in The Village Voice August 26, 2006, article, “George Bush: Recidivist,” by Nat Hentoff, on how the Justice department strong-armed Taylor to dismiss the case.

If You Can’t Beat ‘em, Discredit ‘em


Although Bush and his cronies once again used their hackneyed strategy, “if you’re agin us, you must be wrong,” a respected law professor, Laurence Tribe, recognized as one of the foremost constitutional law experts and Supreme Court practitioners in the U.S., considers her decision “splendid.”

But then, along came Republican Senator Arlen Specter to prop up the President and try to bail out the entire administration for violating the law, and the Constitution. Nat Hentoff strikes again on September 1, in “Arlen Specter’s Sellout,” his article on Specter’s attempt to pass legislation giving the administration a way to prevent going to the slammer. This, when Specter has stated before his belief that Bush did violate the Foreign Intelligence Surveillance Act (FISA), which requires a president to present programs of this nature to a special court for approval.

How Did We Get Here, and What Do We Do Now?


If you really don’t know how we got to this point where our privacy is in constant jeopardy—and I doubt many don’t—I will tell you much in the same way George Orwell told his readers in the classic novel, 1984: Big Brother is watching you. Although simple, it predicted a tyrannical state in the future that could usurp all our freedoms. I believe we are very close to realizing Orwell’s prediction. If we don’t wake up and take control of our privacy, Big Brother is imminent.

Wednesday, August 30, 2006

Bush/Cheney Reinvent Big Brother II

Playing Big Brother Becomes Illegal


In mid-August, Judge Anna Diggs Taylor decided to cut Bush’s NSA wiretapping program off at the knees: “Federal judge orders end to wiretap program.” I say, “at the knees,” because the administration appealed and asked for a stay of the ruling: “Judge Finds NSA Program Unconstitutional.”

Coincidence? I Think Not!


About one week later, Seattle-based Cray Inc. and the U.S. Energy Department announced an increase in their supercomputer, Jaguar, located at Tennessee’s Oak Ridge National Laboratory, to 54 teraflops: “U.S. supercomputer gets speedier.” To us humans, that means the ability to do 54 trillion mathematical calculations per second. Like I said in my two earlier posts, “Yes Virginia, Data Mining Can Catch Terrorists,” and “It’s Monday Morning. Do you Know Where Your Name Is?” the future in spying is data-mining…to anticipate and predicts your every move. No coincidence here. Just more Bush and company deceit to get what they want.

The Jeopardy Of Not Controlling Your Personal Data


In 2004, the General Accounting Office did a report, revealing that federal agencies had initiated 199 data-mining efforts, with 131 already operational: “Perspective: Government data-mining lives on.” Included was Homeland Security’s “Incident Data Mart,” comprised of state, local and federal police data. The FBI has its own data mart, built to catch illegal aliens. The Defense Intelligence Agency has four projects, mining from the intelligence community and the Internet to catch terrorists. All probably legitimate in purpose, but deadly to the privacy of the innocent, American public.

Big Brother Regroups and Always Strikes Again


The Bush administration, with Cheney’s hands clearly on the reins, and the rest of the stooges riding shotgun, will not give it up until they are stopped by U.S. consumers that realize the tyranny of the situation. We can start this November by voting out a Republican majority afraid to “rein-in” this president and his acrimonious accomplice.

Wednesday, August 23, 2006

Bush/Cheney Reinvent Big Brother

Big Brother Is Watching You


On her site Orwell Today.com, Jackie Jura describes an unseen, yet, all-seeing Big Brother with eyes that follow you wherever you go. The caption says, Big Brother Is Watching You, and in George Orwell’s dystopic novel, 1984, the Party knew everything there was to know about the citizens of Oceania. The Party’s three slogans were: War Is Peace; Freedom Is Slavery; and Ignorance Is Strength.

After some reflection, all three would mimic the absurd in any free society. Each assumes, of course, a government objective that has decided it knows what’s best for its citizens, and will not be told otherwise. When you consider the world body charged with protecting all nations against war, and promoting humanitarian causes, the United Nations, there is an eerie, self-serving realization that comes to mind

First, without war, the UN is out of business. Second, if freedom prevailed around the world, global humanitarianism would be in far-less demand; and, three, the “ignorance is strength” premise is not only UN driven, but a basic priority for any government that, while espousing democracy, practices tyranny.

Bush/Cheney Simply Redesign Orwell’s Despot


Anyone who thinks the Bush/Cheney administration has not evolved into a totalitarian regime, needs to explain to me the other meaning of Bush’s comment that “You’re either with us or against us,” proclaimed as a mandate to our former close allies. Followed by “Trust me to get it right,” a statement that this president apparently will never fulfill on any level. A mellower Big Brother, but, nevertheless, still its personification.

Another stupid statement like, “Bring it on,” which they did, and which gave the Bush/Cheney bunch the twisted logic of spying on innocent Americans to uncover the bad guys, because they don’t have the leadership skills to fight terror. You can read about this and other “national nightmares” of this administration, as described by the author, Mark Medish, in his 2004 OpenDemocracy.net article, “Four more years for Big Brother.”

He draws an excellent comparison with Orwell’s “War Is Peace,” in Medish’s own words, “…war is also profit.” He is referring, of course, to Halliburton’s no-bid, Iraqi contract, a company Dick Cheney ran before becoming vice president.

Opinion Writer Investigated for Sedition


In a bizarre case of “no one questions Big Brother,”—AKA George W. Bush—Laura Berg, a VA nurse from Albuquerque, wrote a letter in September of 2005 to Alibi.com, titled, “Wake Up, Get Real,” which lambasted the Bush administration for its Iraq War and Katrina incompetence, and suggested Bush, Cheney, Chertoff, Brown and Rice be tried for criminal negligence. The Alibi.com article, “Big Brother is Watching,” by Steven Robert Allen, reports that Berg was being investigated for sedition, apparently due to her criticism of the Bush administration.

Berg is being represented by ACLU lawyers, George Bach and Larry Kronen, for the charge that she was suspected of writing the letter on government time, property, and using government equipment. However, Mel Hooker, Chief of Human Resource Management Service at the VA, later said that no evidence was found implicating the use of Berg’s work computer, according to the ACLU. Pathetic.

Can you recall the last time when an American citizen was charged with sedition— a crime indicating insurrection or rebellion against the government—for writing an opinion piece criticizing their government?

Next post: some observations on “Big Brother Bush” from my favorite columnist, Molly Ivins.

Friday, August 18, 2006

Experian Denies My Right to Dispute Credit Report Problem

Why Is Experian So Elusive?


In my last post on August 9, “Level of Competence at Experian Credit Bureau Found to Be Low,” I was unable to get my credit report from Experian’s Credit Manager, where I have been a member for over twenty-five years, paying $90 annually for the service. After hours on the Internet and telephone with Credit Manager personnel who turned out to be completely useless—and being regularly “escalated” to the “right” people—I finally reached a supervisor who was known as…the Escalation Manager.

Mark sounded competent, acted like he wanted to help, and spent another hour covering the same material as the “useless” bunch. I was wrong. He couldn’t help me, even if he wanted to. Something was also blocking Mark—the Credit Manager Escalation Manager, no less—from accessing my credit report.

Impossible to File Dispute With Experian


When I requested that Mark fix the problem, the answer was that Experian wouldn’t let him. It made no difference that I made my membership payment to and received my credit reports from Credit Manager. I would have to contact Experian direct to file a dispute, which he “hoped” would solve everything.

After a brief out-of-town trip, I tried to file an online dispute with Experian, giving them every possible bit of personal ID necessary to identify me. The result was a message labeled, “Error.” “We are unable to allow access to our online dispute services at this time.” I thought, by law, they were required to take credit disputes, which I am researching.

Then, a call was made to Experian with a phone number supplied by Mark. I was denied access to my credit report again in an automated telephone call from the number he provided, with the words, “We are unable to process your order.” Then, amazingly, they instructed me to order a credit report by mail, giving me an address. Why? To receive a letter stating that they are unable to process my order by mail? There was absolutely no way to reach a human being from this telephone number, so I called the “useless” folks again.

“Useless” Staff Refuse Dispute Help


All I wanted was for someone to give me an address to file a dispute. As usual, I was “escalated” to the “right” people, but they all refused to give me the “dispute” address. Finally, the last guy noticed my prior activity with Mark, and once again “escalated” me to the Escalation Manager. After a five minute wait, “Mr. Useless” came back on and told me to call Mark in one hour. I did and left word on his voicemail, then had to call back the next day.

Mark, the Escalation Manager, returned my second call, had nothing new to offer, and basically told me there was no more that he could do, intimating that I was on my own. He refused to call his parent, Experian, about my problem, had absolutely no suggestion other than another phone number he was rummaging around in his desk to find, while cautioning me at the same time that he had no idea if it would work. I declined and hung up.

Why has the entire Experian Credit Manager staff been so deceptive in dealing with me in this matter, and why doesn’t Experian provide them with a direct line when everything else fails, as it has in this case? Mark replied to this question by stating that Experian does not want the telephone calls. In other words, just wear them down, as they have in my case, and maybe they will go away. I won’t.

Conspiracy Theory


But could I be wrong about the incompetency? The treatment by Experian’s Credit Manager staff sure seems like I am being jerked around in a concentrated effort to prevent me from seeing my credit records. And, that is my right so that I can protect my family against identity theft.

I’m beginning to smell a conspiracy, a veiled attempt at a warning from the junk mail industry, based on the fact that The Dunning Letter has repeatedly criticized data brokers like Experian—they maintain a database of over 215 million consumers nationwide, with a significant amount of private information other than your credit records—and I am advocating federal legislation to give consumers control over their names and personal data.

More on this later.

Wednesday, August 09, 2006

Level of Competence at Experian Credit Bureau Found to Be Low

Identity Theft Concern


I am a member of Credit Expert, Experian’s Credit Manager service that normally provides me instant online access to my credit report. I pay $90 annually for this membership, and have been a loyal customer for over twenty-five years. Until today. During a periodic checkup to insure against identity theft, I was unable to get to my data. That was July 12, four weeks ago.

After 14 e-mails, all of which resulted in no resolution from a staff so inadequate it is incomprehensible they hold their jobs, I finally received a telephone number to call. Apparently, I had gone through this boiler room full of dummies—God only knows where they were—and at least one had the inclination to hand me off to someone else. That was last Friday, July 28.

After another complete explanation to someone equally as inept by the name of Bemi, I was put on hold several times for durations up to three minutes. I’m guessing that wasn’t enough since he finally got back to me with the answer that my problem had been “escalated” to the proper party, and I would hear from them within 48 hours.

The “problem” is that I cannot check my credit report to make sure there is nothing going on that is fraudulent. It involves logging on to Credit Expert, then proceeding to look at “inquiries;” anyone that has accessed my credit report. At the same time you can scan all your credit history, and confirm that the data is correct. That is, if you can get to it. I couldn’t.

248 Names, Personal Data Breaches Since 2005


Since ChoicePoint started the parade in February of 2005, Privacy Rights Clearinghouse reports almost 250 breaches of sensitive data in everything from Social Security numbers to medical records. Just fewer than 90 million records of your private information was on the open market, at least temporarily, even if it was eventually recovered. And for what hasn’t been recovered, don’t feel any comfort in the fact that you, personally, haven’t experienced fraud. The new identity criminal is smart, and willing to wait until the heat is off to tear into your credit.

I didn’t see Experian on the list of breaches—TransUnion, another credit bureau, was—but if the frontal guard I dealt with is any indication of the rest of the company’s proficiency, they are due any day. I worked with this organization—as well as Equifax and TransUnion—during my 35 years selling names and personal data in the junk mail industry. It is this experience, among others, that led me into privacy activism, and the launch of this blog.

Nowhere to Turn for Credit Dispute


Returning to the Experian episode, there was no call or e-mail in over 72 hours, so another contact was made. This time, I started with a quick explanation of the situation, with a demand to speak to a supervisor. Anthony sounded somewhat competent, but with absolutely no authority to help me in any way; it took over an hour to learn this. He could only listen and “escalate” the problem elsewhere.

Anthony gave me a telephone number to request an immediate credit report, and file a dispute over my credit report that was inaccessible. Result, it was “automated response” only, and I must purchase a credit report for $10 before I can file the dispute, with no human being within miles. Upon recalling Anthony, he confirmed all this, at which time I almost went postal.

The outcome was that he was again “escalating” my problem to the right people, and he would have them call me within two hours. They didn’t, but I did hear from someone at Credit Expert later in the day. He was late responding because Anthony hadn’t given him proper contact information.

But, you’d never guess who called. The Escalation Manager. More on this later.

Wednesday, August 02, 2006

The Do-Not-Call Registry Works, Proving Consumers Should Control Their Names and Personal Data

Do-Not-Call Provides Control Over Telephone Number



If you are on the National Do-Not-Call Telephone Registry, you are one of more than 107 million individuals that decided you were fed up with unwanted telemarketers that were pushy, inconsiderate, and a general pain in the butt. They still are, and they remain out there, but they can’t call us anymore if we signed up. If they do, you can file a complaint with the FTC that will stop them once and for all. I know. I did it.

With just under one-half the adult population on the DNC list, I haven’t heard of mass-bankruptcy proceedings for the junk mail and non-junk mail companies using this method of selling. Meaning, I assume, that they have found other means to present their wares. In other words, this federal legislation did not put anyone but the telemarketing business in jeopardy, which is a work ethic they chose to make.

As a former broker of mailing lists—yes, I once sold telephone numbers, but refused to with my clients after experiencing the intrusion trauma of the telemarketer’s call—I can confirm that this was a major part of the advertising thrust of many junk mailers. Some in the industry even indicated that the DNC would put them out of business. Crying wolf again, similar to when the Direct Marketing Assn. (DMA) started the “Mail Preference Service” years ago that allows shoppers to opt-off mailing lists.

Consumers should Control Names and Personal Data



So why am I bringing all this up now? Congressional leaders virtually ignore the concept that consumers should have control over their names and personal data. There are two possible reasons for this. One) business lobbying does not want it, and, therefore, pays to keep it from being legislated; Two) Congress thinks the individual is not capable of handling the task. My gut feeling is that it is both. However, I like neither the fact that junk mailers and non-junk mailers are bankrolling the open door to my identity theft, nor am I fond of being considered stupid.

FirstMonday.org, an Internet journal from the University of Illinois, had an interesting article, “Economics of Personal Information Exchange,” that explores who owns our private data. Scrolling down to the heading, “Personal Information as a Property Right,” they confirm how our current system recognizes businesses that warehouse our personal data as its owners.

Government and Business Do Not Own Our Private Information



My argument against this premise is that numerous, distinctly different entities (ChoicePoint, Bank of America, Sharper Image, plus several more) store this sensitive data simultaneously. They all cannot be considered legal owners; therefore, this remains an issue for lawmakers to decide. You can read more about this in my July 19, post, “Junk Mail Industry Continues to Rob Customers.”

On the other hand, I do not believe that consumers should be given property rights over their names and private information. There are too many scam artists out there that will turn this into a money-making proposition that some individuals will not be able to refuse. Beth Givens, founder of Privacy Rights Clearinghouse, agrees with this position.

Contact Congress to Pass Federal Legislation



My answer is to pass federal legislation that gives consumers control over their names and personal data. While we’re at it, you should be paid any time it is sold. If you agree, write, E-mail or telephone your Congressional representatives and tell them. Contacting the House of Representatives. Contacting the Senate.

Wednesday, July 26, 2006

Congress Keeps Getting It Wrong...and So Do You

You are probably unaware of, and maybe even unconcerned with the fact that the House of Representatives is about to vote on a piece of identity theft legislation that is an insult to the citizens of this country. But why should you care? You’ve let it get this far without protest, so, like the saying goes, you reap what you sow.

HR 3997, The Financial Data Protection Act of 2005, will take away most of the rights you currently have, placing absolute control over your name and personal data in the hands of the same culprits who keep losing it. Like the 540,000 New Yorkers’ names, addresses, and Social Security numbers contained on a piece of computer hardware—didn’t say if it was a laptop—that is now missing since Monday of this week. Story on MSNBC.com.

But why should you care. It hasn’t affected you. Yet. The House leadership will most likely pass a bill that allows companies like ChoicePoint, Bank of America, Sharper Image, or just any junk mail or non-junk mail facility that holds your private information, to notify you only if they decide you are at risk. In other words, after the fact. If you are willing to take that, then, maybe the means justify the end.

Washington state Attorney General, Rob McKenna, said it best, when commenting in the NewStandardNews.net article, “’Protection’ Act Would Strip Consumers of Credit Safeguards.” He said: It’s like telling someone you can’t put a deadbolt on your front door until after you’ve been burglarized . The same article documents how the finance and credit industries have donated over $12 million to political campaigns, and spent nearly $30 million on lobbying.

Susanna Montezemolo, Policy Analyst with Consumers Union, and Ed Mierzwinski, Consumer Program Director for the U.S. Public Interest Research Group, both oppose the legislation. Montezemolo says, “Congress should be helping consumers prevent identity theft, not making things worse.” Paraphrased, Mierzwinski adds that what the states have given—like the California law that caught ChoicePoint—Congress wants to take away, “…with this industry-approved bill that won’t prevent data breaches…”

Montezemolo also makes a point I have been blogging about for over a year now. She states: “Consumers are the greatest protectors of their own personal information.” Therefore, why not pass federal legislation giving them control over their names and personal data, and, while we’re at it, pay them when it is sold? Read more of their article at: USNewswire.com.

What everyone should know is that HR 3997 will amend the Fair Credit Reporting Act. The Act’s coverage, of course, does not fully protect consumers, but it is all we have from lawmakers who are either afraid, or too inept to serve notice on government agencies and the business community that the public, also, has rights.

And this will never happen unless consumers stand up for these rights, and demand that Congress do the right thing when it comes to the identity crisis. Tell them you want control over your name and private information. Encourage friends and family to do the same.

Write, E-mail or telephone your Congressional representatives and tell them what you think of this concept of controlling your name and personal data, and, being paid when it is sold. Contacting the House of Representatives. Contacting the Senate.

Wednesday, July 19, 2006

Junk Mail Industry Continues to Rob Customers

Perhaps this headline is somewhat severe when you consider the connotation, but certainly well within reasonable boundaries, when you look at the damage. The junk mail list industry reaps around $4 billion each year from the sale of your name and personal data. You are lured into the conspiracy by supposed convenience and the sale of products you desire, with a feeble warning that your name “might” be “occasionally” shared with other junk mailers.

You receive your merchandise, but not one penny from the repeated sale—25 to 50 times annually—of your name and private information that follows each purchase. The irony of this is that 98 of each 100 mailings go in the trash. And they wonder why it is called junk mail.

This all comes from my experience selling mailing lists for 35 years. As a privacy activist now, my goal is to pass federal legislation that will give consumers control over their names and personal data. At the same time, you should share in at least half of that $4 billion windfall each year. The proceeds could be taken either in cash, or put away in an interest-bearing account for retirement.

On July 4, I posted the article, “Independence Is Control Over Your Name and Personal Data,” which lays out my plan, and shows how similar law in the United Kingdom has worked in favor of the consumer without halting related business interests. Just this week I received data from the Brits’ Information Commissioner’s Office that shows just how effective their Data Protection Act has been. A complete article on this later.

Identity theft is rampant. Gasoline prices could reach $3 dollars per gallon any day. What better reasons for this control and compensation?

On the other hand, we’re dealing with a current administration and an incompetent Congress in so many areas that ID theft, and Americans’ privacy in general, is slowly evaporating. Along with this, data brokers and junk mailers, as well as non-junk mail companies that gather and sell our private information, go on their merry way harvesting obscene profits.

Yet, the very culprits responsible for the conspiracy are whining over how to get even more results from your names and private information. In a recent article, “Marketers Feel Data-Challenged,” from Direct, a junk mail industry publication, a survey reveals a general unhappiness by companies of not realizing the highest return from your personal data. They want more and more of it, but don’t know how to use it. Pathetic.

In keeping with the inaccuracy of ChoicePoint and Acxiom data from another survey ( 73% and 67%, respectively), junk mail marketers seem to fare no better, with only 30% reporting their data as reliable. Have you ever known of an industry selling its product—mailing lists—for $4 billion a year with an average error rate of 70%? I think not.

I did a couple of posts earlier in this blog that explore how junk mailers feel about being the proprietor of your names and private information: “Junk Mail 101: Junk Mailers Believe They Own Your Name,” and “Junk Mail 101: Junk Mailers Believe They Own Your Name II.” Each has its points about a business greedy to take advantage of this by-product of your junk mail shopping, and II even quotes some prices of industry mailing lists.

It’s almost a “squatter’s rights” mentality used for real property, but legally that won’t even work. This approach requires “exclusive use,” and your name and personal data is in the hands of several hundred junk mailers and data brokers…simultaneously. And, I have yet to see a valid argument from anyone in the business that it is legal to take control of something as private as this data by any party other than the name-holder.

So, it’s time to take back what is rightfully yours. Write, E-mail or telephone your Congressional representatives and tell them what you think of this concept of controlling your name and personal data, and, being paid when it is sold. Contacting the House of Representatives. Contacting the Senate.

Wednesday, July 12, 2006

Winner of the Big Brother Awards

George Orwell could not have envisioned that his imaginary 1984 character, Big Brother, would manifest itself into the symbol of the loss of privacy for generations to come. Although it is speculated by some that he really meant that 1984 would occur sometime after 2000—1984 could have been the year he completed the novel, 1948, with the last two numbers reversed—once again, could he have visualized a George W. Bush, with his rag-tag bunch of incompetent flunkies attempting to create an imperial presidency?

Probably not, but 1984’s major legacy is a tyrant called Big Brother, and we attach it to anything that reminds us of being under surveillance by government or business. And that is exactly where we are, characterized by the feds’ unrelenting spying techniques on innocent Americans, and junk mail and non-junk mail companies’ obsessive accumulations of our names and personal data.

Privacy International, a non-profit based in London, with its affiliates, presents the “Big Brother Awards” each year to government and private sector organizations that have done the most to threaten personal privacy. The ceremony has been held in sixteen countries since 1998, but we will concern ourselves with just the U.S.

The first of any significance was in 2000, where DoubleClick, then engaged in online media, received the “Greatest Corporate Invader” award for monitoring the surfing of 50 million net users. In the prior year, DoubleClick had acquired Abacus, a company performing analytical services for junk mailers by using sensitive customer data from catalog purchases covering almost half the U.S. households.

DoubleClick wanted to marry this private information with the net surfing habits of its 5 billion record database. This strategy was quickly rethought when privacy advocates, even junk mail industry leaders, reacted with shock.

Also in 2000, the “Lifetime Menace” award was bestowed on TransUnion, one of the big-three credit reporting companies, for selling credit reports to marketers and keeping inaccurate reports for years. TransUnion was also a persistent litigator to sell personal data their way. They went through a ten-year court battle with the Federal Trade Commission over the selling of sensitive credit information. They lost. In the end, the Supreme Court refused the case.

It should come with no surprise that ChoicePoint won as the “Greatest Corporate Invader” in 2001, for massive selling of records, accurate and inaccurate, to cops, direct marketers, and election officials. Then, of course, the bomb dropped in February of 2005, starting a string of data breaches that it seems will never end.

In connection with the “inaccurate” records, Privacy Activism, another non-profit, did a study on errors found in ChoicePoint’s data, which included name, Social Security number, address, and phone number. The mistake rate was 73 percent. Still not surprised.

And the one to watch that could bring Big Brother to all our doorsteps is Acxiom, winner of the “Worst Corporate Invader” in 2005, for a tradition of data brokering. Has to have something to do with that Privacy Activism study, where Acxiom’s sensitive records had an error rate of 67 percent. The reason to keep an eye on them is partly due to the company’s aggressiveness in pursuing government contracts for clandestine programs like CAPPS II, where the feds could secretly share with them everything they know about you.

Oh, by the way, a mailing list company by the name of Response Unlimited shared the Acxiom award, because they tried to sell the list of donors to the Terri Schiavo cause…while she was still alive. I can hardly wait for the 2006 Big Brother Awards.

Tuesday, July 04, 2006

Independence Is Control Over Your Name and Personal Data

What better way to celebrate July 4th than having the right to control your name and personal data, and be paid each time it is used. It won’t happen this year, but it could by 2007. It all depends on your reaction to this concept, and being able to get a grass-roots movement going that would force Congress to pass federal legislation to give consumers this right.

It is not only a right, it is a necessity, if we are to curb the onslaught of the current identity crisis. And if you have read any of the carefully planted articles that claim the crisis is overblown, be aware of the statistics from Javelin Research, provided on the Privacy Rights Clearing House site, “How Many Identity Theft Victims Are There? What Is The Impact On Victims?” PRC is one of the largest and most respected privacy advocates in the U.S.

Javelin says that even with a decrease, the number of identity fraud victims was 9.3 million in 2005. Total fraud was $54.4 billion that same year. At the hands of ID thieves in 2005, each victim suffered $5,885 in financial loss, and it took them 28 hours to correct the problem. But it’s a problem you probably won’t worry about until it happens to you and…then it’s too late.

Freezing your credit will help, but unless you are notified at once and you react immediately, there is still the chance the crooks can hijack your private information. And, there is the hassle involved for you to unfreeze your account for legitimate reasons. Paul Wenske did a good article on this subject in the Kansas City Star, “’Freeze’ on credit meets a lukewarm reception.”

There is only one answer to protecting our names and personal data, and holding Big Brother at bay when it comes to business and government usurping individual privacy. Orwell’s 1984 predicted it, and we are very close to fulfilling his prophesy, but Americans are beginning to see the light and the need to protect their inner sanctum.

This can be accomplished by passing federal legislation that gives consumers (1 CONTROL over their names and private information, and while we’re at it, give them the (2 RIGHT TO BE PAID each time it is sold. Government and business reaction is that this would halt commerce in its tracks, but this hasn’t happened under the United Kingdom’s Data Protection Act of 1998. The Act requires the U.K.’s Information Commissioner’s Office to approve any use of personal data.

1) Taking the U.K.’s Act one step further in giving the individual approval, U.S. law would set up a system where consumers, business and federal agencies are assembled in a database that assigns each a unique ID, which would replace the Social Security number for identification. This ID, along with a Pin number chosen by each person, firm or agency involved, would be the key to using the system. Any business or government entity wishing to access consumer names and private information would sign in with their ID and Pin.

But first, the individual would opt-in, or opt-out of all junk mail use of their name. Opting-out would deny any commercial or government use of data, except for emergencies.

Whether one or a million records are required, an automatic signal would be sent to each name-holder by urgent e-mail or telephone message, repeated regularly until the recipient responds. The notification would alert the consumer as to what the nature of the data request is, and, if legitimate, could be authorized immediately. If not valid, the individual so indicates, and the transaction is stopped at that point, causing no harm, and with minimum effort by all concerned.

Arrangement would be made for medical or financial emergencies, as well as the needs of national security. All activity would be subject to oversight by a committee including private citizens, along with federal and industry representation.

(2 In the case of compensation in the sale of consumer names and personal data, this same system would calculate revenue by individual, and maintain an accounting of what is due. Based on the junk mail industry’s annual take of $4 billion for the selling of names and private information, I feel the name-holder should receive one-half. Ideally, it could be placed in an account bearing simple interest of 3 percent, and the person could eventually draw around $607 a month to supplement their retirement, or take the proceeds in cash.

Write, E-mail or telephone your Congressional representatives and tell them what you think of this concept. Contacting the House of Representatives. Contacting the Senate.

Wednesday, June 28, 2006

Identity Theft 101

Identity thieves are becoming much more sophisticated in their strategy. You could even say this is becoming a cottage industry since they have so many incompetent businesses and government agencies to work with. The kind that allow their employees to take laptops home with them crammed with personal data on just about every household in the U.S. Any person who would do this has to be working with a double-digit IQ in common sense.

In just the last couple of months, the following organizations have lost a laptop(s) containing combined sensitive information on almost 26.8 million individuals:

• Veterans Administration – 26.5 million
• Hotels.com – 250,000
• IRS – 291
• ING Financial Services – 13,000
• Equifax Credit Bureau – 2,500
• Federal Trade Commission – 110

In many cases the data included name, address, Social Security number, birth date, and credit card information. The perfect formula for ID fraud.

And then a computer server was stolen on March 31, from the Midwest office of insurance giant, AIG, containing 930,000 names, addresses, Social Security numbers and thousands of medical records. The data had been sent to AIG by 690 insurance brokers who were shopping their clients for medical coverage. A “server” seems like a strange thing to steal, unless you know what you’re getting. Read the story: “Stolen computer server sparks ID theft fears” on MSNBC.

That’s just the laptops and one server. There have been several others where hackers have broken into systems, but two are worth mentioning because of the unique methods used.

Somehow, 28,000 sailors and their families ended up on a civilian Web site. Included were names, birth dates, and Social Security numbers. Once again, just what the crooks need. In an MSNBC story, “Sailors’ personal data found on the Internet,” the Navy admits it has no idea how the information was stolen.

Then, one that could top the dunce responsible for the VA breach, a Humana insurance employee called up data on 17,000 Medicare beneficiaries through a hotel computer, and then failed to delete the file. In a Washington Post story by Kevin Freking, “Medicare Beneficiary Data Left in Hotel,” it was an auditor from the Department of Health Services, using the exact same hotel computer in Baltimore that caught the mistake.

If I recall correctly, in every incident, the statement was made: “There is no evidence that the information fell into the wrong hands and was misused.” This will probably end up being the quote of the century. Perhaps, one of the most famous disclaimers ever written, and it probably didn’t require a staff of legal experts.

And here’s why it’s so ludicrous. It’s what I call Identity Theft 101.

No, there is no evidence the thieves have used the private information yet, because they are smarter than the businesses and government agencies they lifted it from. When the inexperienced culprits who took it in the first place realize they can’t use the data, and because of the media attention—which, by the way, is justified—this petty thief will sell it to the next level of the more sophisticated identity swindler. This bunch will sit on it for a year and one day, when the credit monitoring has expired, and go for the gold. Yours, that is.

Eventually, the inexperienced, petty thief will graduate to Identity Theft 102, or higher, realizing that you can easily cut out the middle-person since data gatherers are focused squarely on profits, not consumer security. In this scenario, the students will excel in their field without ever graduating.

Wednesday, June 21, 2006

FEMA and ChoicePoint Deserve Each Other, but We Don't Deserve Either

According to the Government Accountability Office (GAO), poor information technology and lack of management controls is responsible for as much as $1.4 billion fraudulently paid out in hurricane relief funds by FEMA. Lack of management is FEMA’s specialty, but not securing the technology to access consumers’ personal data takes their incompetence to yet another level since every other governmental agency does it regularly. FBI, Homeland Security, Pentagon, NSA, Justice Department…the White House.

Michael Arnone writes in Federal Computer Week, that the GAO uncovered this figure through the same technology that FEMA should have used to catch the crooks: data mining and database matching techniques. His article, “FEMA pledges better disaster relief fund payouts,” quotes the GAO as saying that around 16 percent of the disaster assistance was questionable. Some of the millions of dollars even went to federal and state prison inmates.

So far nothing unexpected. However, then Arnone drops the bombshell. FEMA has hired data broker ChoicePoint to verify identities, using Social Security numbers for those applying for assistance. That’s the same ChoicePoint that led the charge in February of 2005, with 145,000 personal records stolen by ID thieves, an incident that was revealed only because of a new California law on identity theft.

Not satisfied with the original version, ChoicePoint goes for two sequels, one totaling 9,900 names and private information stolen September of 2005, another 17,000, November of the same year. That’s almost 172 thousand consumers who have had to run for cover, and sweat out the threat that their identities could be taken from them at any time. Maybe tomorrow, maybe next month, or even a year or two from now.

By the way, the Federal Trade commission reports that there have already been at least 800 cases of ID theft resulting from the ChoicePoint breaches.

According to an Information Week article by Thomas Claburn, titled “The Federal Information Tax,” the government has become one of ChoicePoint’s best customers. Based on the Privacy Act of 1974, there are major questions regarding what the feds can ask for from these data brokers, and also what private information they are allowed to maintain on American consumers.

This fact notwithstanding, the question is, after three data breaches by ChoicePoint, are they qualified to provide personal data on consumers for businesses or government? Privacy Activism, a non-profit organization reporting on privacy issues, isn’t sure. In an article, “Privacy Activism study finds new problems for ChoicePoint, Acxiom,”they found a majority of participants found errors in the most basic of biographical information: name, Social Security number, address, and telephone number.

But the shock of the day was that the background check reports (your private information) provided by ChoicePoint were inaccurate 73 percent of the time. By the way, the same Acxiom figure was 67 percent.

Are you ready to see the light and demand federal legislation to give you control over your name and personal data, and, pay you when it is sold? Let me hear from you.

Tuesday, June 13, 2006

British Consumers Aren't Stupid Either

No, consumers in the United Kingdom aren’t stupid; as we also agreed in my last post, neither are Americans. The big difference is that the Brits are doing something about it, and this country isn’t. By “country” I mean the Bush administration, congressional leaders on both sides of the aisle, and you, the consumer.

You can forget the Bush/Cheney duet when it comes to going to bat for the average individual. If neither business nor the moneyed elite profit in the transaction, there’s absolutely no interest on their part.

And then, while Washington flounders in a mass of mostly meaningless legislation on identity theft, the U.K. has had the Data Protection Act (DPA) since 1998, which seeks to strike a balance between the rights of individuals and the sometimes competing interests of business. Anyone processing personal information must notify the Information Commissioner’s Office (ICO) that they are doing so, unless their processing is exempt.

In my last post, “Is the American Consumer Stupid?,” I quoted from an article in junk mail industry publication, Direct, and an interview with Martin Abrams, executive director of the Center for Information Policy Leadership at Hunton & Williams in Washington. One of his points is that U.S. privacy laws are based on preventing harm, as compared to European law which is based on giving consumers control. Actually, Abrams was saying that American business has it easy, compared to the United Kingdom.

The Brits have taken control over consumers’ names and personal data with the requirement that business must inform the ICO of their use. Yes, there are exemptions, but this is the kind of balance we must strive for if we are to put a stop to the current identity crisis in the U.S. I would advocate that we take it one step further, and give the control to individual consumers, and pay them when their names and private information is sold.

But this won’t happen unless you speak up and tell your congressional representatives that you’re tired of this crap and won’t take it anymore. Contact your elected officials in the House of Representatives and in the Senate.Tell them you read about this in The Dunning Letter, and you want to know why we are eight years behind the United Kingdom.

On the other hand, the UK is having its own problems with compliance; naturally, in the business community. As late as November of 2005, that country’s Accountancy Age journal reported in the article, “Data protection disaster looms for thousands,” that less than half the profession’s companies had registered with the ICO, a requirement costing only £35, $64.48 U.S. Apparently the accountants aren’t the only non-compliers in Great Britain, but the ICO is threatening further action.

Which all goes to say that eight years after the enactment of the UK DPA, there are still problems that will probably take yet more time. But the U.S. Congress is currently muddling through several bills on the ID theft issue—most of which will not get the job done—which are really delay tactics to soothe us into believing they are working on our behalf. They aren’t.

If we don’t get serious about this today, tomorrow could pose an ID crisis for your family. Folks, there have been eighty-three data breaches since the beginning of 2006, and there were 8.9 million victims of identity fraud in 2005.

Take a look at the Chronology of Data Breaches, and the Javelin/BBB ID Theft Survey, both from Privacy Rights Clearinghouse, and if you can come away from that with indifference, and you are in the majority, we are on a fast track to George Orwell’s Big Brother.

Wednesday, June 07, 2006

Is the American Consumer Stupid?

I don’t think so, although government and business are steadfast in their efforts to convince us that we are not competent to manage our personal affairs. Like controlling our names and private information so that they don’t fall into the hands of ID thieves. Like government and business are better equipped to do this.

The latest major incident is the 26.5 million records lost by the Veterans Administration; some moron took it home with him where it was later stolen. The first occurrence was a theft from data broker, ChoicePoint, in February 2005, who revealed the loss only after being forced to by California law. There have been twelve more breaches since the VA abduction May 22, and you can see the whole sordid story at the Privacy Rights Clearinghouse site, “A Chronology of Data Breaches Since ChoicePoint.”

Total personal records lost or stolen as of this date: 84,797,096. It will probably increase even before I can post this article.

So back to my original question: Is the American consumer stupid? Since I’ll bet you agree with me that most of us aren’t, why are we being treated as if we are too dumb to regulate the use of our names and personal data? And why haven’t we, as an intelligent group, risen up and demanded to take command over this most valued possession? Actually, the second question answers the first.

Just as George Orwell’s citizens of Oceania were completely apathetic about the Party and Big Brother controlling their lives, today’s population is at an indifference level regarding their privacy that is alarming. With just over 9 million victims of identity fraud confirmed, and a huge media circus built around the data breach hullabaloo in 2005, an Experian/Gallup survey at the end of that year recorded an ID theft concern rate of a dismal 35 percent.

I don’t have to point to, nor even provide any specific quotes, as to how the government has contempt for our intellect. From Bush on down, we are being told that: 1)either things are not as bad as they seem; 2)that someone is looking into and analyzing the situation; or 3)that Congress is drafting legislation to solve the problem. Unfortunately, we’re batting zero on one, and two and three are very questionable.

From the standpoint of business, particularly junk mail and non-junk mail companies maintaining dossiers on every U.S. household, and including data brokers, I can speak with some authority. There is a high level of concern over potential privacy laws, but this bunch still chooses to stick their heads in the sand. Outwardly, they are exclaiming concern that consumers will get control over their names and private information, but inwardly, still convinced they own your data.
Kinda like 1984’s Doublethink.

A recent case in point is an article, “Bad Law Rising,” in a junk mail publication, Direct, by Ray Schultz, Editorial Director. Schultz is a good journalist and from past articles, has a high respect for consumer privacy. He talks with Martin Abrams, executive director, Center for Information Policy Leadership at Hunton & Williams in Washington. Also well respected in the industry.

The interview focuses on financial data, which is certainly one of the most important areas we want to protect. Abrams first statement is, “Privacy law in the United States is unstable.” For the most part, his remark refers to the effect on business, not the consumer, and he rightfully states that much of the fault lies in the advance of technology. What is downright frightening is that he feels any real change has to come from the top (not sure if this is government or business) and is three to seven years away.

By then, the identity crisis will have arisen to humongous proportions, a situation that could very well stop commerce in its tracks. At that point, it won’t matter who we are for the chaos will probably shut down both government and business.

More on this issue next time. How individual control over names and personal data works in the United Kingdom.

Thursday, June 01, 2006

It's Monday Morning. Do You Know Where Your Name Is?

When the junk mail industry—and that includes data brokers like ChoicePoint, Acxiom and LexisNexis—opens every Monday morning, there is already a flurry of data mining going on. Actually, the predictive modeling episodes have been in progress over the weekend, sort of a 24/7 event in this business. And your name and personal data? Always an integral part of the process.

During my tenure as a broker of mailing lists, I became interested, and eventually learned the technique of predictive modeling, primarily as a targeting means, to cut down on my clients’ “junk mail.” Most data mining/modeling companies work at the individual household level with their personalized data, something I refused to do. Working only with zip codes, it was possible for me to get acceptable results, while not encroaching on the privacy of individuals.

So what really happens when computer meets your private information in the process of data mining? First of all, there is a human being conducting the modeling procedure, who, by the way, is privy to all your personal data. Usually, there are assistants with the same access. The data arrives at the data mining company in a digital format. It is delivered by one of the services like UPS, who lost 3.9 million records of the Citigroup in mid-2005, including customers’ names, addresses, Social Security numbers, account number, etc.

Let’s say the data arrives securely, but then it must be logged in by a clerk in the tape library. In my 35 years experience in junk mail, this was where an alarming number of computer tapes housing your private information were lost. Just vanished. But in our hypothetical case it is accounted for and moves on to the people who analyze the data. Could be one or several, and each has entrée to all your private information.

Next, it reaches the human being doing the modeling, with advice from the analysts on how to crunch the data. Here’s where the fun part starts. Let’s say Sharper Image has a home humidifier/air purifier that sells for over $500, and they want to target households that both can afford the item, and have some underlying health issue need. This is where your personal data comes into play.

First, the modeler might determine if you own a home, moving next to your home value for verification, then to your income to substantiate your ability to buy the product. Other factors are marital status, children in household, whether you are a junk mail shopper, and your education level, the latter two confirming that you might carefully read the humidifier advertisement.

Our human being will want to know if there are any pets in the home, whether anyone is a smoker, who has what allergies or related ailments, and what medications are being taken, which further confirms these allergies. Other factors like your fitness level, what you buy from junk mail catalogs, and what you buy at the super market could be used.

All this data is fed into high technology software that will look at each item, determine its relevancy, evaluate its impact on the purchase of the humidifier, and spit out millions of qualified names and addresses. Sound simple? It is if you are experienced in data mining and have sophisticated programs at your disposal like neural networks (artificial intelligence).

So what’s the downside to this for the average consumer? Sharper Image determines who wants their humidifier, and you get a mailing you might just be glad to receive for a change. The answer is that nothing is wrong if you had control over your name and private information from the beginning. I am talking about my concept to pass federal legislation to give you this control, and pay you when it is sold.

This would have allowed you to say yes to the whole procedure, knowing your name and personal data was out there in junk mail limbo, able to target the breach immediately if it occurred. Believe me, the security level of your data would be significantly higher than it is now, if the junk mailers knew you had this control.

Folks, the alarming rate of stolen private information is only going to get worse. Your enlightenment is the sole purpose of this blog, and it is posts like this that point the need for individual control

There’s more to say about this in future posts. Encryption of data is one of the top levels of protection. Another possibility is anonymous separation of name and personal data. Something being used in the United Kingdom, and being explored in the U.S.

Thursday, May 25, 2006

Yes, Virginia, Data Mining Can Catch Terrorists

A recent article from Information Week, “Can Data Mining Catch Terrorists?,” asks a question I first thought was rhetorical…until I read further. The author, J. Nicholas Hoover, covers all the recent activity of the National Security Agency (NSA) spying issue, touching on USA Today’s article, “NSA has massive database of Americans’ phone calls,” by Leslie Cauley. They’re both worth reading.

Hoover is right about the technology for assembling humongous databases, not the least of which is Microsoft’s Access. Data, of course, is a necessary part of the equation, and the jury is still out on whether that has been given up. If the NSA does not have the algorithms that allow them to conduct the predictive modeling/data mining that identifies patterns of terrorism, it is simply a matter of incompetence. It is expensive—when has that ever bothered this administration?—but readily available.

But there is one part of the article that I take issue with, and it is where Hoover indicates the NSA could learn from retailers (junk mailers) who mine customer data “without invading customer privacy.” When CitiBank buys your name and financial data from TransUnion (one of the big three credit bureaus that uses data mining techniques for selection), to send you a credit card offer that could be intercepted by an ID thief, that is invading your privacy.

My other major concern is the attention given to the “accuracy of data” in the piece. Hoover indicates its integrity “is different” for each data broker. What isn’t mentioned is the fact that much of your private information is also incorrect. In the article, “Privacy Activism study finds new problems for ChoicePoint, Acxion,” two major data brokers, there are alarming facts that should make every American consumer rise up and insist on control over their names and personal data.

The error rates for private information by Acxiom and ChoicePoint were 67 percent and 73 percent, respectively. 100 percent of the eleven participants in the survey had mistakes in their background check reports. This included the most basic information of name and address, but also involved Social Security numbers and phone numbers. The latter, of course, the basis of NSA’s database.

ChoicePoint has 19 billion records, including information on most U.S. residents. Acxiom’s warehouse is similar and includes over two hundred demographic and lifestyle items the last time I checked. Each has sufficient data to insure that the NSA could easily determine your household’s daily habits.

In the Hoover piece, the Government Accountability Office found in a 2004 survey that federal agencies were already involved in or planning 199 data mining projects, including 122 involving personal data. That’s your private stuff, folks. And, many of these will use ChoicePoint and/or Acxiom data, because of the contract these companies already have with the government.

So yes, Virginia, data mining can catch terrorists. But only if it is done correctly and with accurate data. It must not in the process, however, randomly access the personal records of innocent U.S. citizens, who give up this data for purposes that have absolutely no relationship to terrorism.

In my next post, I’m going to reveal the technology and antics of the predictive modeler/data miner, so that readers can understand the process their names and private information go through to forecast their next move. It’s an event that occurs hundreds of times daily, creating an identity crisis for your household each time.

Tuesday, May 23, 2006

Veterans Discharged After Vietnam...Beware Stolen Data

It’s hot news today, and worth a quick post to get out the word. It also underscores my fight to give U.S. consumers the right to control their names and personal data. If we had that right, there would be no need for the millions of veterans to worry about their identity being stolen, after the recent data theft.

What happened was that the private information of 26.5 million veterans was lifted from the Veterans Administration in another bizarre example of loose security. Those affected are discharges after 1975, or those who submitted claims to the agency before 1975.

According to Consumers Union, information such as names, Social Security numbers, dates of birth—all that is necessary to steal your life—were stolen from the home of a long-term employee. The data was downloaded to his or her home computer, which was stolen in the burglary. No indication from the VA why this moron was “allowed” to capture such sensitive, private information, supposedly protected by security.

In an article, “U.S. Veterans Data Stolen, VA Shows Little Concern Over Data Theft,” by Dave Porter, the VA has yet to explain why they waited until now—the data was taken early May—to make the announcement. This is, in fact, required by law in several states—remember California’s law and ChoicePoint?—and just another example of government incompetence.

And, while on that subject, Porter tells us that George W. Bush just got around to establishing a task force on identity theft on May 10, giving his henchman AG, Alberto Gonzales, the go-ahead to exercise zero tolerance in the prosecution of data loss cases. Yeah, right. At the same time one of the biggest culprits, ChoicePoint, continues to enjoy lucrative government contracts.

So, what to do? There’s a VA telephone number to call but I heard the incompetence persists even there. It is (800) 333-4636. If you get a letter from the VA, and you live in a state that allows a security freeze on your credit files, you have to consider this in relation to the risk. I suggest a free credit report from each of the three credit reporting agencies, spread out over a period of time that, hopefully, will either allow recovery of the data, or the circumstances are too hot for the ID thieves to act.

Beth Givens, Director, Privacy Rights Clearinghouse (PRC), warns veterans and their families to monitor their financial picture “indefinitely.” What does that tell you about their future? If you go to the PRC web site, there is a Chronology of Data Breaches showing close to 82 million American consumers who have had their personal data compromised since February 2005.

Folks, it’s time to voice your support for my goal of passing federal legislation giving you control over your name and private information. And, pay you, when it is sold. Let your local print and broadcast media know what you think. Contact your representative in the House, and your Senator.

Dave Porter said it best. “The one way you'd get lawmakers to pass legislation that would control how data is managed would be to go to Visa or Mastercard and buy the personal information on them and start posting it online.” He goes on to say what I have been saying for months, that there is no meaningful identity theft legislation in the works. He also agrees that it is lobbying money that has put us in this position.

Wednesday, May 17, 2006

Junk Mail Ethics IV

So far we have covered marketing surveys, envelope “teaser” copy, and shipping and handling costs, in relation to the Direct Marketing Assn.’s (DMA) guidelines: “DMA Releases Latest Ethics Report; Refers Listing Service To FCC.” My intent was to pick the four most prominent issues and highlight their importance from my experience as a former junk mail list broker. Number four is by far the most significant.

“Where do they get my name?” is a question on the minds of most junk mail shoppers, and the number one priority for anyone who has suffered identity theft. My concept of passing federal legislation to give consumers control over their names and personal data would not dampen in the least the efforts of the junk mail industry in finding new sources to uncover your name and private information. Why? Because this is inherent in the never-ending process of bulding intimate dossiers on every American household.

It would, however, stop them from using this data without you having full control and knowledge of the fact.

The DMA guideline states: “Direct marketers should disclose the source from which they obtained information about consumers upon a consumer’s request. Marketers should tell consumers the source of their name on a specific list, or, if not possible, the kinds of sources used.” I would add one more point. The junk mailer should also be prepared to tell the consumer how much they paid for their name and personal data.

Any regular reader of The Dunning Letter knows of my grass-roots movement to pass the above legislation that also advocates that the consumer be paid whenever their name and private information is sold. In all of my 35 years of selling mailing lists, I cannot remember the DMA seriously addressing the issue of letting individuals control their names and personal data. The reason is the bottom line for their members; selling lists is a $4 billion annual business.

But after 100 significant data breaches in 2005, affecting nearly 56 million consumers, resulting in 9.3 million victims, and a per-victim cost of $5,885, you should want to know where they got your name.

A few years ago, after placing list orders for one of my clients, and after their advertisement was sent, they contacted me about a disgruntled recipient who wanted to know where the junk mailer had gotten their name. Since every name is key-coded by list, it was easy to identity the source. I contacted the junk mailer as a courtesy to let them know they might get a call re. this matter. They stonewalled me with a complete refusal to allow me to reveal their name.

Probably not true of all junk mailers, but this gives you an idea of the secrecy level over names and private information. It certainly does not conform to DMA guidelines, above.

So what to do? Like with the shipping and handling charges in my last post, call or e-mail the junk mailer from whom you receive the advertisement. Look on the order page for a telephone number or web site, or just Google the company. Click on either “Contact Us” or “Customer Service.”

You have a right to know who is selling your name and personal data, and you really should put out the above effort to keep the junk mailers on the ball. Hopefully, this will all change soon when the consumer is finally in complete control.

Monday, May 08, 2006

Junk Mail Ethics III

We’ve covered junk mail marketing surveys that sell your personal data, and envelope “teaser” copy that is meant to lure you inside for the kill. In both instances, the Direct Marketing Assn. (DMA), touts its ethics standards for these and other issues, as covered in their article, “DMA Releases latest Ethics Report; Refers Listing Service to FCC.”

Next, let’s turn to another DMA point of concern. Junk mailers charge you a shipping and handling charge for sending the products you ordered. After 35 years of selling mailing lists to these companies, I am still confused about just how they arrive at the S&H. It is supposed to be the total of postage, UPS, Fed EX, etc., and the labor necessary to prepare your package for shipping.

Here are the DMA ethical guidelines: “Shipping and handling costs should not be excessive. They should bear a reasonable relationship to actual costs incurred, according to DMA’s guidelines. Marketers should be able to substantiate their shipping and handling charges.” I went to the DMA site, “Guidance For Establishing And Substantiating Shipping And Handling Charges,” and found three pages of text that basically say junk mailers should charge a fair amount.

But it is this part that I don’t understand from the above statement: “They (S&H charge) should bear a reasonable relationship to actual costs incurred…” Does that mean junk mailers can mark up shipping and handling, as if it is an extension of the merchandise they are selling? I am here to tell you that it is done. In doing list work for one company a few years ago, the person in charge told me it was customary to tack on a few bucks to S&H.

However, it is the manner in which the shipping and handling is calculated that mystifies me most. The figure you pay is based on the dollar amount of the order. If you purchase items weighing five pounds that add up to $25.00, you pay the same amount as the customer who has the same dollar amount, but the order weighs ten pounds. When I go to UPS or USPS to ship something—companies many junk mailers use—the package is weighed and I am charged accordingly, supposedly including handling.

I decided to do an analysis of major catalogs to determine a range of shipping and handling costs, based on this industry-wide system. My fictional order would total $50.00 to make sure each catalog was measured equally. Out of twelve catalogs, the S&H cost extended from FREE to 24 cents per dollar ordered, with the average around 18 cents. That means you must add an average of 18 cents to each dollar purchase you make by junk mail, which is a bargain if you don’t have the time to go to the mall. Particularly, with current gas prices.

To name a few names, Lillian Vernon ships free for over $40.00 purchases. TravelSmith is the next cheapest at 14 cents per pound. Harry and David came in highest at a whopping 24 cents. Improvements was 22 cents; Plow & Hearth and Signals 20 cents; Sharper Image and Walter Drake 18 cents; Crate and Barrel 17 cents; and Maryland Square, Coldwater Creek and PetsMart at 16 cents. Go figure.

Here’s my advice. Call or send an e-mail to your favorite junk mail catalog and ask them just what they base their shipping and handling charges on, and how they are calculated. Look on the order page for a telephone number or web site, or just Google the company of your choice. Click on either “Contact Us” or “Customer Service.” You might be interested in what you find out and I would like to hear about your results.

The next and final ethics issue is the answer to everyone’s question: where did they get my name?

Wednesday, May 03, 2006

Junk Mail Ethics II

In my last post, I covered junk mail marketing surveys, which was listed in the Direct Marketing Assn.’s (DMA) article, “DMA Releases latest Ethics Report; Refers Listing Service to FCC,” as a priority in their ethics agenda. My blog pointed out just how much of your personal data is requested in these questionnaires, and how rich the junk mailers get from selling it.

Another DMA issue from the article was “teaser” copy; those alluring statements on the front of junk mail envelopes designed to get you inside. The DMA states that they, “…should not cross the line into deceiving a consumer about the nature of the promotion.”

One only needs to remember the sweepstakes mailing received by an individual not too long ago that indicated they were a winner. The person paid their own way to Florida, if I recall correctly, to redeem the prize, only to find out they had won nothing.

My wife just received a mailing from the AAA; we both are members. The envelope has two pieces of “teaser” copy. First, the “Club President” has authorized an upgrade in our membership, “free of charge.” Second, on an oval black and gold seal: “Courtesy Upgrade, FREE, To AAA Plus.” We are instructed to confirm by return mail.

Not until you get inside the envelope and carefully read all the literature, do you find out that it’s only free for one year. Then it costs you $58.00, and that’s in addition to the $73.00 we already pay. Although the letter mentions a $58 renewal after one year, you must go to the “Return Receipt” to find out your grand total is going to be $131 ($58+$73). There are additions to the coverage but the only thing we have used AAA for in the last year is maps, so I’m not sure of the value.

Junk mail auto insurance company, 21st Century, sent us a mailing recently soliciting our business. The envelope says: “Think you have the best auto insurance just because you’re with one of the biggest companies? You’re in for a surprise.” That got me inside, because I was curious just how they knew I was with one of the “biggest companies.” They didn’t.

That was just another ploy to tell me four things my “big company” insurance agent won’t tell me: 1) I can save $300 switching to 21st; 2) No other company offers the important policy features 21st does; 3)No other company is as accessible and easy to work with; 4) They are rated A+ by Fitch Ratings. As to one through three…questionable. And for number four, my “big company” is rated AA+ by Fitch.

Finally, probably the fastest known data acquisition known to man: when you buy or refinance your home. Your name, and a bunch of private information, is made available to a host of predators, not the least of which is the very company with whom you bought or refinanced. You told them at closing you didn’t want all the extra insurance, but apparently they didn’t believe you. Add to that a number of companies you’ve never heard of, and you begin to understand the true meaning of “junk mail.”

Envelope messages like: “Important Information concerning Your Mortgage!,” “Personal and Confidential,” “Protect Your Home.” Here’s my answer. I would like to protect my home from the inane junk mail I receive, or, give me a piece of the action and pay me every time my name and personal data is sold.

Next issue of concern: do junk mailers make a profit from your shipping and handling charges?

Wednesday, April 26, 2006

Junk Mail Ethics

Back in December of 2005, the Direct Marketing Assn. (DMA) published an article on its website that identifies current action against three companies for lack of cooperation in solving matters of ethics. Neither of the companies is a member of DMA, so therefore, they really don’t have to cooperate. They didn’t, and there’s really not much more the organization can do but refer the companies on to the appropriate law enforcement authority.

What the DMA did do in the article, “DMA Releases Latest Ethics Report; Refers Listing Service to FCC,” is compile a list of six issues of primary concern, based on 20 current cases. Based on my 35 years as a broker of mailing lists, I am impressed with the issues, but not moved in the least with what I know of junk mail compliance. Four are worth mentioning, however.

Number one: Customer information should not be readily available for access by other individuals; here they are primarily concerned with services that make this data available online. “Customers would not reasonably expect that information about what they purchased, or how they responded to a marketing survey, would result in their inclusion in an online look-up service.”

One of the most lucrative areas of selling your name and personal data comes from marketing surveys you complete to get free products. OK. We’re all frugal to a point, but if you knew how quick and widely distributed your private information was after filling out these detailed questionnaires, you’d think twice next time.

The giants of this gold mine are Equifax and Experian, both credit reporting firms. Their subsidiaries, Lifestyle Selector and Behaviorbank, maintain databases of your personal data and daily habits, numbering 56 million and 40 million households, respectively. Things like what you read, what you drink, what ailments you have and the medications you take, how you invest, if you smoke and what brand, whether you gamble…and much, much more.

And these aren’t the only companies who assemble and sell this data. Be assured that just about anytime you put your private information on paper, online, or give it up by telephone, it will be collected and sold to the highest bidder. There are billions of dollars to be made, and you won’t realize one penny in the deal. To add insult to injury, you might even suffer identity theft down the line.

Please tell me, what is worse? Making the survey data available to Web surfers online (as is the point of the article’s issue), or selling it to thousands of junk mailers that, as we have already experienced, can lose the data to potential ID thieves? The DMA’s focus is typical of an industry that covets the sale of your name and personal data, and is willing to protect this supposed right at any risk.

It’s already enough that Equifax and Experian turn over this data for the marketing strategies of those companies who provide you the free products. It’s equally troubling that they fail to make it clear to you that your private information will be sold over, and over, and over…ad infinitum.

If you, the consumer, had control over this personal data, there wouldn’t be a problem, and you would be enjoying the fruits of the sale of this data.

Next issue of concern, the “teaser” copy on junk mail envelopes that bribe you to open them.

Wednesday, April 19, 2006

Junk Mail Industry Rag Puts Down Consumers

Direct Magazine, a junk mail industry publication, obviously must back the business it receives its advertising revenue from, but when they belittle the very customers who support Direct’s advertisers, that sucks. It all comes from a recent article on DirectMag.com, “No, Consumers Shouldn’t Always Be in Control.”

Right out of the gate they’re wrong. Consumers should have complete control over their names and personal data.

The article comments on Phil Raymond’s concept that e-mail recipients should be paid when they receive e-mail they do not want. YES! Very similar to my theory that consumers should be paid each time their name and private information is sold. Raymond is CEO of Vanquish Labs, and plans to introduce software that will support his concept.

Direct calls the idea interesting, but then states it gets “wackier” and “wackier” when scrutinized. Continuing, they contend there would be a “chilling effect” by letting “unpredictable” and “hair-trigger consumers” make decisions like this.

The put-down progresses to Direct’s conclusion that, “…consumers simply don’t deserve money for accepting e-mail.” Their reasoning is you pay little to nothing for e-mail boxes. What they don’t mention is that junk mailers charge premium prices for the sale of your name with an e-mail address.

According to junk mail list manager/broker Worldata in their latest “List Price Index,” names with e-mail addresses sell for 50 percent more than the average junk mail shopper. Naturally, this segment of merchandising your names and private information is growing at a high rate of 38 percent annually.

Phil Raymond is backed by Boston University economics professor, Marshall Van Alstyne, who did research for the project. See “Boston U. professor to develop anti-spam program.” Reaction is mixed at BU. Most students didn’t think they would charge the spammers, and an engineering junior stated flatly there was no reason to charge for something some people could find “entertaining.” That’s a switch.

This is not just about e-mail lists, or anti-spam, or whether Raymond and the BU professor have a good idea. It is about an arrogant junk mail industry that continues to take the position that it owns your name and personal data, and you, the name-holder, have no rights whatsoever.

This, after over 100 significant data security breaches in 2005, affecting nearly 56 million consumers, while junk mailers and data brokers continue to reap over $4 billion each year from private information they are supposed to protect and don’t want to pay you for. It’s pathetic, and the issue worsens with each new loss of data, compounded by self-serving articles like the one above in Direct Magazine.

There is only one way to solve the identity crisis, and at the same time put some of the junk mail fortunes in your pocket. Pass federal legislation that will give consumers control over their names and personal data, and pay them when it is sold. Click on the following to contact your congressional representatives: House of Representatives; Senators. Folks, I cannot do this alone.

As usual, tell them I sent you.

Saturday, April 15, 2006

Hispanics and a New Independent Party

All of a sudden both sides of the aisle are interested in the Hispanic vote. That’s because they have finally begun to make themselves heard. In the 2000 presidential election, they registered 7.5 million voters out of a possible 13.1 million citizens. This increased to 9.3 million in 2004, out of 16 million, respectively. I bet the recent demonstrations upped this substantially.

We can all remember when the Democrats championed causes for minorities, but barely a peep has been heard from those party members either running for Congress in 2006, or the Presidency in 2008. Republicans do garner some support, but the individual usually comes from a wealthy background or has made it big in business. There is a tendency to forget the little guy, to whom we owe much of this country’s progress.

I won’t get into the legal aspects of the immigration movement since it is just that, a legal issue. However, I will say that federal legislation is desperately needed to determine the status of the 11 to 12 million Hispanics who are here illegally. And, it isn’t likely that Democrats or Republicans have the guts to do what is right. The opinion is based on both parties’ track record in recent privacy legislation, another concern dear to the average consumer.

Perhaps this potential voting block of over 16 million (citizens only) should consider an independent political party as the answer to their problems. It’s not too far-fetched to combine a civil rights movement with a privacy theme, especially since many of the privacy issues apply to minorities. And there are another 25 to 30 million sharing this status that would join the momentum.

Nearly 58 percent of Hispanics registered to vote in 2004, and 81.5 percent of that voted. However, of the 42 percent not registering, just under 38 percent gave the reason that they weren’t interested in the election or not involved in politics. This doesn’t differ much from the total population where 46.6 percent gave the same excuse. But you can take it to the bank that the recent demonstrations have changed at least the Hispanic thinking.

The next move is to integrate all this enthusiasm into one solid cause that stands for individual rights with no boundaries of race, or otherwise. Starting with the demand for personal privacy, every issue that impacts this mandate becomes part of the independent party platform. Immigration and human rights in general would top the list.

Timing is perfect. Every seat in the House of Representatives is up for grabs in November, along with 33 Senate seats. If you don’t have an independent you can vote for in your area, find a candidate who subscribes to the principles of individual rights and encourage them to run.

The latest LA Times/Bloomberg poll shows only 39 percent of Americans approve of Bush as President; 57 percent disapprove. And, these figures are confirmed in AP/Ipsos, and Washington Post/ABC surveys. Congress fares even worse with a 28 percent approval rating; 61 percent disapproval. You can read about this continued Republican slump in an MSNBC.com article, “Bush job-approval ratings remain low,” by Jeff Pruzan.

Many voters believe that it is impossible to elect an independent President or majority in Congress. Most of this rhetoric comes from the top echelons of the Democratic and Republican parties, as well as their elected officials. Well, Ross Perot’s almost 19 percent of the vote in 1992 established him as the most successful third-party candidate since Teddy Roosevelt’s 27.4 percent in 1912.

The TV show, Commander in Chief, on ABC, portrays Geena Davis, an Independent, as the President, ushered into office from the death of the former President. The question is…will she be re-elected? But I think we can all agree that in the best of Hollywood fashion, this has been predetermined. The show’s creator and Producer, Rod Lurie, had to have done extensive research into the possibility of the election of an Independent Party President, in order to maintain believability in characters and the storyline.

Does he know something we don’t? Stay tuned!

Tuesday, April 11, 2006

New Regulations Needed to Protect Credit Card Users

My wife made a purchase recently at a farmers market using her credit card to complete the transaction. This is one of those planned events held in shopping centers and strip malls across the country which frequently produces unique items you can’t find anywhere else, made by the very people from whom you are buying. It’s an experience thousands flock to regularly, but it could be a disaster in the making if some changes aren’t made.

In December of 2003, the Fair and Accurate Credit Transaction Act-FACTA was passed, which specifies that no more than the last five digits of your credit card number can be printed when you make a purchase. However, the law governs electronically printed receipts, and doesn’t apply to transactions where the number is either written or executed by an imprint. In other words, thousands of times daily, credit card numbers, maybe yours, are recorded on paper that may or may not be secure.

The merchant used the old-fashioned imprint machine to record my wife’s credit card information, which clearly states the full sixteen digit credit card number. From experience, I know he or she must deposit this receipt to a business account for credit, so, hopefully, it won’t be lost. What worries me is just who, and how many, other people see this number in the trip to the bank.

The “mom and pop” merchants in this country are the very backbone of our great system of commerce. They should be given considerations, but not at the expense of losing my identity to thieves that lurk at every corner…and farmers markets. Folks, they are everywhere, as evidenced by the outbreak of security breaches in 2005. Give them a grace period to comply, like Visa and MasterCard did all the other merchants, and make them stick by it.

You would think that one of the first things lawmakers would do after the recent rash of breaches would be to plug the loopholes of existing law to better protect the consumer. Just imagine that the person who took my wife’s credit card number goes to a bar for a drink on the way to the bank, and someone steals all the daily receipts. Then, multiply that possibility by thousands of transactions like this every day.

ChoicePoint, LexisNexis and other data brokers do pose a huge threat to the security of our identities. They can lose millions of personal records in one quick event—illustrated by CardSystems exposing 40 million credit cards in June of 2005—and need to be controlled to prevent this from happening. But alas, it is not likely, with either current law or the recent blitz of identity protection legislation.

Real security will be accomplished only by individual consumer control over their name and personal data.

The Pittsburgh Post-Gazette printed an article by Robin Sidel from the Wall Street Journal “Identity theft—unplugged,” that quotes some recent figures from Javelin Strategy & Research. Some 29 percent of victims in the survey said their private information was stolen when they lost their wallet, checkbook or credit card. The balance of 71 percent is attributed to someone from the outside initiating the theft.

Most privacy experts agree that a large number of ID thieves get their information from traditional, low-tech sources. Even a family member, friend…or small neighborhood merchant.

It is time to update FACTA and include all merchants, no matter who they are, and seal this big hole in the ID theft dike. In the meantime, if you must make one of these purchases, let the businessperson know that you realize your personal data could be in jeopardy.

Thursday, April 06, 2006

What's Your Name and Private (or Public) Information Worth?

As a junk mail shopper, your name could be worth around $65 to you personally on an annual basis. More or less, depending on how many times you buy. The total take each year on consumers’ names and personal data is $4 billion from junk mailers, a part of their business they would rather you know very little about. With each purchase, you have the option to check that you do not wish your name “shared” with other junk mail companies. They will never tell you that your name and private information is sold, over and over and over.

So you don’t think the $65 is enough to worry about? Then let’s put just half of that $4 billion every year in a simple interest-bearing account until you are age 65. Bingo! Retirees could supplement their retirement income with an average of $607 monthly; again, more or less, based on buying habits. Sound better? It could happen if Congress got off their duff and passed federal legislation giving you control over this data.

And that’s only the junk mailers. Your private and public information is being sold by thousands of data brokers other than ChoicePoint and LexisNexis. The SWIPE Toolkit knows this, and has come up with a great site that shows you just how much you are worth. Go to their calculator and you’ll be blown away by what you see. Click “Data Calculator” first, then, “Launch” on the left and you’re on your way.

Trying it myself, I selected address, date of birth, unpublished phone number, Social Security number, credit records, driver’s license info, and voter registration. Total: $40.25. And, that’s only one report out of thousands that are sold daily. I found the SWIPE Toolkit in a CNNMoney.com article by Jeanne Sahadi, “You want a piece of me? Pay me.” She is saying what I have been saying for the last several years, that the name-holder should have control over their name and personal data, and be compensated when it is sold.

Sahadi asked Chris Hoofnagle, “who owns this private information.” Hoofnagle, Director of the West Coast Office and Senior Counsel for Electronic Privacy Information Center, replied: “Whoever possesses it.” The EPIC has been fighting vigorously for years to protect your privacy, so you can understand the frustration in this statement.

And yet another new entry into the private information marketplace, reported by Washington Post columnist, Don Oldenburg, in his article, “Everything You Ever Knew About Yourself—for $79.95.” The company is MyPublicInfo Inc., founded in 2004 to provide personal data retrieval services for consumers. I went to mypublicinfo.com and clicked on “Sample” to see what they offer. Folks, it comes out to a list numbering fifteen pages of public and personal data items about your present-day status, as well as your past.

But, you have to give up your name, address, Social Security number, and birth date to get the report. This is the same stuff an ID thief needs to walk away with your identity. They also claim no one else can get your report—the $79.95 charged should be your best protection—and the safeguards look pretty secure. However, their database is out-sourced—there’s that word again—to a firm in California.

Oldenburg quotes Beth Givens, Founder and Director of Privacy Rights Clearinghouse as saying that access ought to be “free of charge, just like they can get their credit reports for free.” I agree, and the way to solve the whole problem is to pass federal legislation that will give consumers control over their names and private information and, at the same time, pay them when it is sold.

There, I said it again.