UC, Privacy, and Presence

Opinion
Jan 11, 20103 mins

UC

Last week, we discussed some of the issues unified communications raises with respect to litigatin, including e-discovery challenges. This week, I’d like to raise awareness of privacy concerns related to UC adoption.

Presence, one of the foundations of unified comunications, is pregnant with possibilities for changing how teams work together and how organizations work with their clients or customers. From simple “In/Out” boards for co-workers to “Here’s where I am, here’s how to reach me” data empowering a just-in-time-fetch-the-expert strategy, presence drives much of the transformation UC can bring.

But, in the course of empowering all that, IT creates for itself and the organization some new privacy issues to worry about. The phenomenon of cyberstalking has been with us almost as long as the Internet itself. Whether pursued by ex-spouses, abusers, or just plain crazies, or persecuted for religious or political affiliations or sexual orientation, some people have been forced to recognize the need to keep a low profile.

Yet, as we discussed earlier, companies are increasingly incorporating presence awareness—including physical location—as part of their UC roadmaps. That introduce risks. For example, let’s say a client’s realtime whereabouts become part of a UC-based project management system. What if that system is hacked, and the client is subject to stalking? The company could be legally liable.

Or imagine an employee in treatment for alcohol addition, whose employment is contingent upon the employee staying sober. If a find-me-follow-me communication determines the employee went into a bar—is it legitimate to report this information to human resources, and potentially terminate the employee’s employment?

These and other questions arise with presence, but they aren’t new, and there are ways to address them. In higher education, for example, pretty much every system is built to allow for “FERPA exceptions” — people who had opted under FERPA (the Family Educational Rights and Privacy Act) to have their names withheld from any and all publicly visible directories. Enterprise UC systems could, similarly, be built with the possibility of obscuring presence information from all but a person’s direct co-workers, similar to the people actually in a class with an “opt-out” student. Certainly they should be built to ensure that no presence information flows out of the organization’s own systems into public systems without the express permission of the employee. Likewise, an organization should ensure that no presence information is visible to non-employees through its own systems without the express permission of the employees. Staff need to be trained to hold presence information private where needed, and to resist social-engineering efforts to circumvent privacy safeguards.

Bottom line: When deploying presence, keep in mind a reasonable respect for privacy. Otherwise, presence-based UC is simply a tragedy (or at least a lawsuit) waiting to happen.