<?xml version="1.0" encoding="UTF-8" ?><!-- generator=Zoho Sites --><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><atom:link href="https://www.aheadcrm.co.nz/blogs/tag/GDPR/feed" rel="self" type="application/rss+xml"/><title>aheadCRM - Blog #GDPR</title><description>aheadCRM - Blog #GDPR</description><link>https://www.aheadcrm.co.nz/blogs/tag/GDPR</link><lastBuildDate>Tue, 22 Sep 2026 12:01:53 -0700</lastBuildDate><generator>http://zoho.com/sites/</generator><item><title><![CDATA[The vCon Reality Check: Moving Beyond Generative Hype to Actual Conversational Architecture]]></title><link>https://www.aheadcrm.co.nz/blogs/post/the-vcon-reality-check-moving-beyond-generative-hype-to-actual-conversational-architecture</link><description><![CDATA[Welcome to Reality. Leave Your &quot;AI Magic&quot; at the Door. The AI hype train is moving at terminal velocity, but the tracks are missing. We have ]]></description><content:encoded><![CDATA[<div class="zpcontent-container blogpost-container "><div data-element-id="elm_4oWh5ELkSHuImITSQAbv9g" data-element-type="section" class="zpsection "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_E7c7uftdQ1mPwAPE39d2Fw" data-element-type="row" class="zprow zprow-container zpalign-items- zpjustify-content- " data-equal-column=""><style type="text/css"></style><div data-element-id="elm_3za17I9STVWIrlFYDFsOeA" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- "><style type="text/css"></style><div data-element-id="elm_angOy0HvRuq5ELUwxs-N9g" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-center " data-editor="true"><div><h1 class="wp-block-heading">Welcome to Reality. Leave Your &quot;AI Magic&quot; at the Door.</h1><p>The AI hype train is moving at terminal velocity, but the tracks are missing. We have vendors pitching artificial general intelligence that will solve world peace, and executives panicking because they think a conversational wrapper around a large language model is a strategy. In the latest episode of CRMKonvos, <a href="https://www.linkedin.com/in/ralfkorb/">Ralf</a> sat down with <a href="https://www.linkedin.com/in/danmiller/">Dan Miller</a>, formerly of <a href="https://opusresearch.net/">Opus Research</a> to discuss something that actually matters: infrastructure. Specifically, we are talking about vCons, or Virtual Conversations. It is an <a href="https://datatracker.ietf.org/wg/vcon/about/">IETF standard</a> that threatens to finally bring architectural integrity to the chaotic mess we currently call conversational AI.</p><h1 class="wp-block-heading">TL;DR</h1><p>If you want to watch the full CRMKonvo, please go ahead <a href="https://youtube.com/live/xSDZ8dKvo7s">here</a> (optimized for smartphones) or <a href="https://youtube.com/live/L9Eqoch2ag8">here</a> (optimized for tablets/computers).</p><figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">https://youtube.com/live/L9Eqoch2ag8</div>
</figure><p>Else, be my guest and continue to read.</p><p>Or do both …</p><h1 class="wp-block-heading">The &quot;PDF Problem&quot;: Why Your Call Recordings Are Useless</h1><p>For decades, the contact center has relied on the clunky mechanics of Automatic Call Distributors, green screen terminals, and audio recordings. As Dan rightly points out, a traditional call recording is essentially the conversational equivalent of a PDF. You get a static document or an audio file that you cannot easily manipulate, query, or extract meaningful context from. It captures one part of the conversation at a specific point in time, freezes it, and historically required overnight batch processing just to transcribe it for basic analytics.</p><p>These days, we have swarms of AI agents acting on our behalf, yet the enterprise plumbing remains grossly neglected. You are trying to deliver a data stream simultaneously with historical information about that stream to build a customer profile, but the underlying data format is a relic.</p><h1 class="wp-block-heading">Enter the vCon: Plumbing Over Poetry</h1><p>The Internet Engineering Task Force (IETF) is currently finalizing the <a href="https://datatracker.ietf.org/wg/vcon/about/">vCon standard</a>. While the W3C handles how things look on the web, the IETF handles the engineering guts that actually make communications possible. Think of a vCon as a standardized, portable container for a conversation, regardless of whether it happened via voice, text, messaging, or a mix of multiple media over time.</p><p>This container defines the content (the literal words spoken or written) and the metadata associated with it. It makes the conversation seamlessly available to CRM and other enterprise systems, CDPs, AI analytics engines, and CCaaS platforms. It is the foundation of the &quot;conversational graph&quot;, a neural network-like web of nodes representing the people involved, their ideas, and the resources utilized. This is not sexy generative poetry; it is hardcore data plumbing.</p><p>And plumbing is what makes a house livable.</p><h1 class="wp-block-heading">Flipping the Script: From B2C to C2B and the Consent Mandate</h1><p>I have little interest in the standard B2C relationship where the business dictates the terms of engagement. Similar to <a href="https://myterms.info/">MyTerms</a>, the real power of the vCon lies in enabling a C2B (Customer-to-Business) model. The vCon container allows the customer to express preferences and attach explicit instructions regarding privacy and data usage.</p><p>Consider the right to be forgotten under the California Privacy Act or GDPR. If a customer wants their data scrubbed after a sensitive call with a pharmacy like Walgreens, the enterprise is obligated to comply. Traditional legacy systems cannot easily isolate what was said, identify the PII, and retroactively throw it out. A vCon makes it possible to pinpoint the exact container holding that interaction's content and instructions, providing an auditable trail for consent and compliance. As Dan noted, you can draw a hard line on what is permitted for AI training purposes based on the customer's explicitly captured preferences.</p><h1 class="wp-block-heading">Revenue Acceleration: The Dealership Reality</h1><p>Let us look at actual business cases instead of theory, or even science fiction. Dan highlights <a href="https://strolid.com/">Strolid</a> &nbsp;and its spin-off <a href="https://www.vconic.com/">Vconic</a>, a company providing back-office support for automobile dealerships. By capturing conversations across a customer's entire lifecycle within vCons, a sales manager does not just see a phone number; they see a persistent, historical record.</p><p>When a customer calls, the system knows they previously inquired about an SUV, understands their past service issues, and detects if they are getting closer to a purchase decision. This leads directly to what Dan calls &quot;revenue acceleration&quot;. It qualifies leads, moves deals forward, and stops the customer from feeling like an unknown entity every time they interact with your brand. If your system has had 500 phone calls with a customer and still does not know how they tick, your architecture has failed.</p><h1 class="wp-block-heading">The Reality Check for Buyers: Three Mandates for Enterprise AI</h1><p>If you are an enterprise buyer looking to invest in conversational AI for CX, stop looking at the shiny front-end and start inspecting the foundation. Here are your three mandates based on the vCon reality.</p><h2 class="wp-block-heading">Fix Your Plumbing Before Buying More AI</h2><p>Stop buying generative AI wrappers and start looking at your data infrastructure. You cannot train an intelligent system or a Retrieval-Augmented Generation (RAG) setup on dirty, siloed data. A standard like vCon provides the necessary container to make your conversational data portable, structured, and chronologically sound across all your systems. If your vendor's idea of data integration is dumping flat audio files into an AWS bucket, show them the door.</p><h2 class="wp-block-heading">Consent is Not a Feature; It is a Baseline Requirement</h2><p>With regulations like GDPR and the California Privacy Act, you must be able to audit, manage, and delete conversational data with surgical precision. Dan rightly identified &quot;consent metadata&quot; as the most critical non-optional field for enterprise CX. If your current vendor cannot pinpoint a specific multi-channel conversation and scrub the PII upon a customer's request, you are carrying massive, unnecessary compliance risk. Buy systems that respect the C2B dynamic.</p><h2 class="wp-block-heading">Co-working is the Unavoidable Reality</h2><p>We are not replacing human agents with autonomous swarms tomorrow, even though some are trying. The near future is about co-working. Agents and AI assistants must collaborate, and the AI needs accurate historical context to be useful. Do not fall victim to the &quot;deer in the headlights&quot; paralysis where you buy a disconnected AI tool just to appease the board. Define the playpen, establish the bumper cars, and ensure your human agents have standardized conversational memory (like vCons) to actually get the job done.</p></div></div>
</div></div></div></div></div></div> ]]></content:encoded><pubDate>Wed, 15 Apr 2026 23:36:10 -0400</pubDate></item><item><title><![CDATA[Beyond GDPR: Is MyTerms the New Standard for Enforceable Personal Data Agreements?]]></title><link>https://www.aheadcrm.co.nz/blogs/post/beyond-gdpr-is-myterms-the-new-standard-for-enforceable-personal-data-agreements</link><description><![CDATA[The news IEE just released standard 7012-2025 for machine readable personal privacy terms , nicknamed MyTerms. MyTerms covers interactions and agreement ]]></description><content:encoded><![CDATA[<div class="zpcontent-container blogpost-container "><div data-element-id="elm_gwlINdRbScqUozuqPile3g" data-element-type="section" class="zpsection "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_s1J--JW8QL2JOt85UhKALg" data-element-type="row" class="zprow zprow-container zpalign-items- zpjustify-content- " data-equal-column=""><style type="text/css"></style><div data-element-id="elm_IhSA3cPvQJCSy2_F5A7ntg" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- "><style type="text/css"></style><div data-element-id="elm_sDhfulk9SHi05CJ8-VE_nw" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-center " data-editor="true"><div><h1 class="wp-block-heading">The news</h1><p>IEE just released standard <a href="https://myterms.info/">7012-2025 for machine readable personal privacy terms</a>, nicknamed MyTerms. MyTerms covers interactions and agreements between individuals and service providers they interact with on a network. It defines a way for personal privacy requirements to be expressed as standard-form contractual agreements.&nbsp;</p><p>MyTerms is intended to replace today’s “notice and consent” pattern with a standardized, machine-readable contract handshake between an individual and a service provider. The standard considers individuals true first parties who can proffer privacy terms as contractual terms, typically through an automated agent acting on their behalf.</p><p>The system relies on a neutral, non-business entity that hosts a bounded set of standard-form privacy agreements. These agreements are designed to be understandable and usable in practice by humans and by machines. They must be available in plain-language human-readable form, maintain legally meaningful wording, and also exist in machine-readable structured formats with stable identifiers so software agents can select and process them reliably.</p><p>When an individual, or their agent, proposes one of these agreements to a service provider, this service provider has a deliberately constrained set of responses to allow model scalability. The service provider may accept the proposed agreement, offer one alternative agreement from the same bounded roster, or reject the proposed agreement. The standard does not expect open-ended negotiation beyond that single alternative choice.</p><p>If the service provider accepts, the agreement is recorded so that both sides retain matching, immutable copies, including contextual metadata such as time, date, and location, to support later retrieval, audits, and dispute resolution. In parallel, service providers are required to publicly disclose which of the standard agreements they are willing to accept, which allows agents and users to choose compatible terms upfront rather than repeating consent interactions on every visit.</p><h1 class="wp-block-heading">The bigger picture</h1><p>(Unwanted) tracking on the web is still the norm although a “consent notice” regime has been established since the EU GDPR became enforceable on May 25, 2028. MyTerms is a direct response to regime with its associated high operational cost for operators, high cognitive load for users, and weak enforcement of user intent (preference signals can be ignored).&nbsp;</p><p>On top of this, many website operators and service providers still manage to keep their tracking-based advertising business running, by ignoring GDPR, by hiding behind “legitimate interests” or by simply making it very hard for people to not agree to tracking and sharing personal data.</p><p>Similarly, “Do Not Track” or Global Pricacy Control largely depend on website operators not ignoring the request headers sent by browsers to them. As a result, in spite of all these good intents, the consumer is still at an a very weak position. Privacy is granted as a grace and not as a requirement. The European Union’s Digital Market Act is aimed at large providers and does not address individuals’ right to have their privacy respected by these players.&nbsp;</p><h1 class="wp-block-heading">My analysis and point of view</h1><p>MyTerms argues for restoring equity by letting people participate as real contracting parties online.</p><p>It addresses some of the problems mentioned above by defining a framework that provides individuals with a means to proffer their own terms in a networked world. These terms, if agreed upon by a service provider, become an enforceable contract.</p><p>In my book, this is a very good idea. It is a serious attempt to move privacy from the current one-sided, unenforceable “notice and consent” regime towards a two-party, auditable agreements that machines can execute at scale. It essentially shall make sure that negotiations about customer data are held eye to eye.&nbsp;</p><p>For customers, it can reduce friction and restore agency. For businesses, it can reduce compliance chaos, lower dispute risk, and enable higher-quality value exchange (especially around buying intent), but only if implementation is made cheap, the agreement roster is tightly governed, and adoption is driven with real incentives rather than moral arguments.</p><p>From a CX perspective, there are a number of clear positives for customers. The more than annoying banner/toggle circus that we see these days gets replaced by a cleaner privacy contract handshake, which means less consent fatigue and less friction overall. As terms are to be legible, there is a trust impact. The risk of a mismatch between what customers think they have agreed to and what they actually have agreed to, gets reduced. Lastly, there is accountability, an enforceable contract; it changes the game from blind trust to trust but verify. Talking about trust, this is an important conversion lever for businesses. Not all businesses have understood it yet, but trust is a very valuable currency. As <a href="https://www.linkedin.com/in/nitinbadjatia/">Nitin Bajatia</a> said in a recent <a href="https://youtube.com/live/nupJJPXpNK0">CRMKonvo</a>, the free customer is more valuable than the captive one. Yet again, too many businesses have not yet got this memo.</p><p>Having said all this, there are some adoption risks, the biggest one being too many businesses simply not being interested in giving away their power. Nitin maintained that a good number of businesses do not collect personal data, anyways, but then these are not the ones that need to get governed via a standard like MyTerms. It is the other ones. These need an incentive, or the risk of punishment. And then, there is the whole gamut of MarTech and AdTech companies, many of which will consider MyTerms as an attack to their business model. Another important risk is the infamous chicken-and-egg problem. It needs early influential adopters and an ecosystem. It, therefore, is of crucial importance to win landmark enterprise software vendors as well as some big e-commerce sites as lighthouses. From a an enterprise software point of view, Microsoft, Salesforce, SAP, Zoho are probably good candidates – with MyTerms actually being right down Zoho’s alley. Wordpress and other major CMS, as well as e-commerce platforms need to support the standard, and ideally fast. Lastly, implementation must be simple for both sides and implementation fragmentation must be kept at bay.</p><p>All in all, MyTerms is a great initiative by IEEE that deserves full support. It will be interesting to see how it evolves, whether the rather influential voices that support it, including Doc Searls, are strong enough to make it lift off. I certainly wish so.</p></div></div>
</div></div></div></div></div></div> ]]></content:encoded><pubDate>Tue, 27 Jan 2026 19:33:30 -0500</pubDate></item><item><title><![CDATA[Why privacy is not an option]]></title><link>https://www.aheadcrm.co.nz/blogs/post/why-privacy-is-not-an-option</link><description><![CDATA[Data breaches, ransomware, stolen identities, collecting of data for no benefit of the customer, are only some of the things that we do see every day. ]]></description><content:encoded><![CDATA[<div class="zpcontent-container blogpost-container "><div data-element-id="elm_O3TJEXDIToW5mMYD6vxBqA" data-element-type="section" class="zpsection "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_9ZFR0-xaRZekXhUnxA4ICA" data-element-type="row" class="zprow zprow-container zpalign-items- zpjustify-content- " data-equal-column=""><style type="text/css"></style><div data-element-id="elm_PR2YK0-bQUyFXW_QJeNM7w" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- "><style type="text/css"></style><div data-element-id="elm__kzIUPhtSdSqmgv3IsGgKA" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-center " data-editor="true"><div><p>Data breaches, ransomware, stolen identities, collecting of data for no benefit of the customer, are only some of the things that we do see every day. There does not seem to be any privacy anymore. This makes privacy and data protection hot topics not only for customers, but also for software vendors - or at least should make it hot topics.</p><p>Apple put in some privacy controls and got chided for it by Facebook and the rest of the adtech industry. Google, with FLOC, tried to establish a technology that aimed at being able to track users in a post cookie world.</p><p>To adapt a quote of the Asterix books: The whole world tracks users and customers. The whole world? No, there is one brave company that doesn't.</p><p>All this is reason enough to have a #CRMKonvo with one of the most accomplished and outspoken protagonists of privacy in the enterprise software arena and we were very excited about the opportunity to have an intense and interactive discussion with Raju Vegesna of Zoho</p><figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">https://youtu.be/YsD0yxXYeZ4</div>
</figure></div></div></div></div></div></div></div></div> ]]></content:encoded><pubDate>Tue, 06 Jul 2021 14:44:37 -0400</pubDate></item></channel></rss>