Data mining and data brokers: the boundary between business strategy and cybersecurity risk

Learn where the legal and ethical boundaries lie, and discover how to safeguard your privacy.

Data has become the most valuable asset for any organization. When used effectively, it allows us to better understand our customers, personalize services, and anticipate market trends. However, this immense capacity for data collection and analysis is a double-edged sword.For financial institutions such as BBVA, where trust and information security are fundamental pillars, it is crucial to understand concepts such as Data Mining and the role of Data Brokers, as well as the cybersecurity and reputational risks they entail when ethical and legal boundaries are crossed.What is Data Mining and what role do Data Brokers play?To understand the current landscape, we must differentiate the technological process from the actors who commercialize it:

  • Data Mining: the set of statistical and computing techniques used to explore large volumes of data (Big Data) to discover hidden patterns, correlations, or anomalies.

  • Data Brokers: companies whose primary activity consists of collecting information on citizens from thousands of public and private sources (social networks, browsing histories, purchase records, etc.), cleaning it, analyzing it, and selling it to third parties without users, in many cases, even being aware of it.

Internal Value: Data Mining as a Business DriverInternally, and within the legal framework, data mining is an extraordinary tool. In the banking sector, it enables us to:

  • Optimize marketing strategies: design financial products tailored to the real needs of each customer profile.

  • Prevent fraud: detect unusual transaction patterns in real time to protect our users’ accounts.

  • Risk assessment: improve credit approval models with greater accuracy.

 

The Risks of Excessive Data Harvesting: The Cambridge Analytica Case (2018)
The real risk arises when Data Mining techniques are combined with lack of ethics and massive, unthinking extraction of data. A clear example of this is what happened with the Facebook and Cambridge Analytica scandal.

What happened?

A political consulting firm used a seemingly harmless personality-test application on Facebook. Not only did it collect data from the users who took the test, but, due to the social network’s privacy settings, it was also able to extract the personal profile data of all their “friends” without the users’ consent.

What did they obtain and how did they use it?

Cambridge Analytica obtained psychological and behavioral profiles of more than 87 million people. With this information:

  • They micro-segmented the population: they identified the most “undecided” or “persuadable” voters.

  • Electoral campaign design: they designed communication campaigns and personalized ads targeted at those profiles to try to influence the US presidential election and the 2016 Brexit referendum.

This case showed that data isn’t just used to sell products, but can also be used to try to manipulate behavior on a large scale.

Why is it a cybersecurity threat?

From the perspective of information security, the ecosystem of Data Brokers and uncontrolled Data Mining represents three main threats:

  • Advanced social engineering (targeted phishing): if a cybercriminal buys your detailed profile from a Data Broker (your preferences, the university you attended, your recent purchases), they can design a fake email impersonating your favorite store or your bank, so perfect that it would be almost impossible to detect.

  • Data leaks and security breaches: Data Brokers store massive databases of personal information. If one of these companies suffers a cyberattack, the private data of millions of individuals (many of whom may be our customers or employees) can be exposed and end up on the Dark Web.

  • Regulatory and reputational risk: for BBVA, the safeguarding of data is fundamental. The use of data of questionable origin or the excessive storage of information without a legitimate purpose not only violates strict regulations such as the GDPR and Organic Law on Data Protection and Guarantee of Digital Rights, but could also undermine the trust that customers place in us. 

Cybersecurity is a shared responsibility. To protect your digital footprint against these threats, we recommend two quick actions:

  • Review your app permissions: revoke access to your location or contacts in applications that do not need them to function.

  • Be suspicious of messages tailored specifically to you: if you receive an email or SMS that seems “too perfect” with an urgent link, do not click on it. Always access through the official app or website.