When Your Product’s Requests for Consent Frighten Your Users

Do your user consent procedures drive your users away?

When a product deals with personally identifiable information (PII), the product vendor is nornmally required to obtain one or more types of consent from their users: consent to process the data, consent to store the data, consent to use the data in algorithmic traijing, and possibly others.

When the consent notice appears on the user’s screen, they will react in one of two ways:

  1. They will provide the requested consent without hesitation.
  2. Something about the consent request frightens them so much that they uit the process right then and there.
By Tim Reckmann from Hamm, Deutschland – Einkaufswagen, CC BY 2.0, https://commons.wikimedia.org/w/index.php?curid=83154898.

It’s yet another example of the abandoned shopping cart problem, where people stop shopping (or in this case consenting) and the seller loses money from a lost sale.

How can you get the first group to 100% and the second group to 0%?

By avoiding these three mistakes.

Mistake 1: your consent request is too vague

What if you ask your users for consent to use their data, but don’t explain how you’re going to use it?

Now some people will sign the consent form anyway, thinking that your company would never do evil things…until they do,

But more discerning people will become immediately suspicious and start asking questions…or just not bother to ask questions and abandon your process.

Mistake 2: your consent request is too detailed

To protect themselves legally, compliance teams often insist on dense, intimidating language full of terms like immutable identifiers, third-party processors, and permanent data storage retention protocols.

Now some people will sign dense documentation even if the fine print requires them to hand over their first born. Others won’t.

If you’re required to talk about immutable identifiers due to some regulation or another, add a preface that explains what immutable identifiers are.

Mistake 3: your consent request doesn’t have a time limit

Some privacy regulations require that companies managing data only keep the data for a specified amount of time. Your consent request should comply with these regulations. If you don’t, you’re in trouble.

But even if your local regulations don’t mandate a time limit for storing data, impose one anyway.

Think about the practicality of it. Let’s say you’re requesting resumes for job applications, and I submit one. How useful is that resume going to be to you ten years in the future?

Conclusion

Don’t frighten your users. Ensure that your consent process is easily understandable, not overwhelming, and explains what the users need to know.

Double It To 200 Proof, Steve

Coincidence again? I discussed something from long ago and found myself dealing with it today. Sort of. Prove me wrong.

I recently had occasion to refer to a year-old post that warned about authenticating online customers with knowledge based authentication. There is no guarantee that the person on the other end of the line is actually your customer.

JOE’S ALCOHOL EMPORIUM: Evelyn, what types of alcohol do you prefer?

“EVELYN’S TEENAGE SON WHO KNOWS HER PASSWORD IS HIS BIRTHDATE: 200 proof, man! Let’s get wasted!”

His mom is gonna be so mad…

Meanwhile Steve Craig—formerly of PEAK IDV, now with Prove—is participating in the launch of a new podcast.

Its name?

100proof Powered by Prove.

Steve, should you double the proof to attract the drunken teenager crowd?

Google Gemini. Deepfake. This is not real.

I guess not, since these aren’t Prove’s hungry people…I mean thirsty people.

But if you are in Prove’s…um…target audience, you will be (as LinkedIn says) excited and thrilled to learn that 100proof’s first guest is Steve Craig’s coworker Frances Zelazny, who has joined Prove as its General Manager of New Market Initiatives. Zelazny offers immense expertise in the identity industry. In fact we were coworkers for a few months at Safran, but she was on the other side of the impenetrable wall between MorphoTrust and MorphoTrak.

Join Steve and Frances today at 2pm Pacific Time on LinkedIn.

Marketing a Biometric Product Without a Biometric Product Marketing Expert

Bob and Judy had left television production and started a biometric company. Bob handled sales, Judy engineering. As their company grew, they both realized they needed help.

Bob turned to Judy one day. “What we need is a product marketer, but not just any product marketer. We need a biometric product marketing expert. I know a guy-“

Judy cut him off. “Forget it. Any so-called expert is hampered by legacy. We need new thinking.”

As they used to say, you won’t believe what happened next!

All the features

Ron, their new hire, was a fast learner who listened to Judy for hours, soaking up everything she knew until Ron understood every feature perfectly.

Google Gemini.

Ron assembled his product marketing materials, clearly differentiating the superior technical advantages of his product. Bob then took the materials out on a sales call.

That afternoon Bob returned, dejected.

“The prospect threw the brochures in the trash.”

“Why?” Ron asked.

“They didn’t make sense and didn’t speak to their needs.”

None of the use cases

Ron belatedly realized that the materials didn’t address the benefits the prospect would realize from using Bob and Judy’s biometric solution. And the owners realized that Ron needed to understand the biometric market so that his materials resonated with customers.

Google Gemini.

So Ron studied the market carefully, spending a lot of time with cops and forensic experts before rewriting his brochures to infuse them with industry knowledge.

A well-prepared Bob flew out to meet his next prospect, a well-known sports team in Chicago.

And returned the next day, dejected again.

“They loved the first hour,” Bob reported, “although all the talk about investigative leads confused them. Then they asked about consent.”

Ron, fresh from police station booking rooms, was confused. “Who needs consent to take bionetrics?”

“Sports teams, banks, hotels, office buildings, hospitals, you name it,” Bob replied. “Especially in Illinois.”

Fumbling Towards Insolvency

Sarah McLachlan. “Found a Job” it’s NOT.

Maybe “insolvency” is harsh, but if a biometric firm doesn’t have the embedded knowledge to speak the language of its prospects and customers, the firm’s success will be limited. Immediate expertise is impossible.

“A Patient Hand.” Google Lyria. Public Domain.

Bob, Judy, and Ron may be fictional, but lack of biometric expertise happens in real life. I still remember the time I worked with a company that was bragging about its three-year old NIST FRTE facial recognition accuracy rankings. I gently explained that FRTE results change monthly, with better algorithms appearing all the time. Those old results were worthless.

And your product marketing will be worthless also, unless you understand the many products and many markets.

Bredemarket can help you speak the language of your biometric prospects. Talk to Bredemarket.

International Data Sharing With CARICOM

Local and state governments cooperate, and national and multinational agencies do also.

Anthony Kimery at Biometric Update:

“The Department of Homeland Security (DHS) and the Caribbean Community’s (CARICOM) regional security agency, Implementation Agency for Crime and Security (IMPACS), signed an agreement to create the first multilateral biometric information sharing arrangement established by DHS, extending U.S. immigration vetting and border security checks across participating Caribbean countries.”

Because once someone has data, there is no TECHNICAL reason why they can’t share it with anyone else.

Comfort in the Frame

No more trips to CVS for passport photos?

“Comfort in the Frame.” Google Lyria. Public Domain.

For fuller background information, see “Secretary of State Marco Rubio on Online Passport Applications, July 2, 2026.”

For more on what ICAO Document 9303 recommends regarding facial expression, see this post.

And this song.

“Neutral Expression.” Google Lyria. Public Domain.

Secretary of State Marco Rubio on Online Passport Applications, July 2, 2026

United States passport applications may soon become easier, allowing you to do nearly everything online. Even the passport photo, saving you a trip to a location where someone or some machine wilk take the passport photo for you.

From Secretary Rubio’s recorded remarks:

“Now, beyond that I would say that we are also looking at some technological changes, which we’ll be more fully able to announce over the coming months, where it’s going to be a lot easier to get a passport in terms of the dynamics of it.  You’ll actually be able to go online.  You’ll be able to do almost all of it entirely online.  One of the questions we had was most of the devices that people are using, be it a laptop or a standing computer or what have you, where you would fill out this application, they have cameras on them.  I know, it’s shocking.  But they have cameras.  They have videos that people use.

“You should be able to take that picture on that device as opposed to going somewhere.  Now, the CVS people, of course, hate this, and the Walgreens and all those other places.  (Laughter.)  But you’ll be able to take your picture from that device and be able to have it in real time, through our security system, verify the facial ID.  And it just saves you a lot of – you don’t have to go down somewhere now and get a head shot and get the little pictures that you have to cut and then submit three passport pictures.  You’ll be able to do that.  You’ll be able to do it online entirely, for the most part, with all the right numbers.  They’ll be able to verify it for you, and you should be able to get it much sooner. 

“So we’re going to make it a much more customer-friendly – we’re not ready to do that yet, but that’s really what we want to be able to do.  (Applause.)  And it should cut down on the long waits, the long lines, the appointments, the making – some people may still decide to do it that way, but this way will be available to people.  And we look forward to, like, really rolling that out in a few months when it’s ready.”

Secretary Rubio didn’t go into the technical details of how they will ensure ICAO compliance for smartphone photos. What about the lighting? What about the inter-eye distance? What if I smile?

After all, smartphone photos are by definition “unconstrained,” unlike the photos you get at your friendly neighborhood CVS Pharmacy.

Google Gemini.

I’m Not a Small Business, Monday Edition

The advertised telephone number for Bredemarket is a free service.

Which is just as well, because over 90% of the calls on that line are from companies that ask if they can speak to the owner, and then tell me how much business I’m losing because my Google Business listing isn’t active.

Never mind that the advertised address for Bredemarket is a small mailbox, but I digress.

Bredemarket.

They NEVER remove me from their calling lists, despite repeated requests. Scumbags.

But those are about the only calls that line receives. (My clients have my REAL number, but they usually contact me by email and Slack anyway.)

So the voice line is a necessary nuisance. Perhaps a small business could use it profitably, but Bredemarket is too small to be what vendors consider a “small business.”

This morning I actually received a LEGITIMATE call on this telephone line…

…from a company offering a paid telephone service. Their representative would be in my area, and they wanted to meet.

I respectfully declined the company’s offer. Among other reasons, neither of us would fit in my mailbox.

Google Gemini.

The MOSIP “Standard”

I’ve previously discussed the false impression that standards achieve recognition via a free, fair, universal consensus. In truth, standards are bullied through the process by one or more interested parties, who then shut out competitors that don’t comply with their…I mean, the industry’s standard.

Meanwhile, companies that don’t comply with the standard ridicule it and say how the standard stifles innovation and brings the whole industry down.

For example, in a few years smartphone manufacturers will complain that the EU’s adoption of USB-C as a universal common charger standard will cause the EU to lag behind when new charging technologies emerge.

Which brings us to MOSIP.

What is MOSIP?

So what does this acronym stand for, and what does it mean?

“The Modular Open Source Identity Platform was established in 2018 to support governments in providing its residents with an official form of the most important human asset – identity.

“As nations around the world proceed on their digital transformation journeys towards true digital economies, a robust and secure national ID system is the crucial first step. With a foundational national ID system in place, a government can build effective civil registries, and service delivery systems, serving the population in a myriad of ways. Among other benefits, robust systems like these enable faster disaster relief, climate resilience, ease of starting new businesses, and better access to financial inclusion, healthcare, and education.”

Established and incubated in Bangalore, India, MOSIP is aligned with the United Nations Sustainable Development Goals and supported by the Gates Foundation and others.

In case you didn’t get the drift, the MOSIP people aren’t regular visitors to Mar-a-Lago.

But their principles align with the goals of many biometric companies that have chosen to list their MOSIP-compliant products on the MOSIP Marketplace.

The marketplace categorizes MOSIP-compliant solutions into six categories:

  • Registration devices.
  • Authentication devices.
  • ABIS (Automated Biometric Identification Systems).
  • SDKs (Software Development Kits).
  • Print devices.
  • Labs.

I won’t list all the MOSIP-compliant solution providers, but there are many of them, including two of the “big three” biometric firms, NEC and Thales.

Any questions?

MOSIP but not MOSIP

I hear a question from the back row from a guy wearing a multicolored wig.

Falco in “Rock Me Amadeus.” From https://youtu.be/cVikZ8Oe_XA.

After all, the third of the “big three,” IDEMIA, has advertised that it provides MOSIP solutions.

“The Togolese Agency for Identification, ANID-TOGO, has partnered with IDEMIA and Atos to build a national biometric eID system based on the Modular Open Source Identity Platform (MOSIP). IDEMIA and Atos will design, build, test, and run a biometric national eID solution for Togo based on iris, face, and fingerprint recognition technology.”

Sounds impressive…until you scan the MOSIP Marketplace and find no listed solutions from IDEMIA or ATOS.

Because “based on” does not equal “compliant with.”

I can say that Bredemarket’s seven-question process is based upon some marketing standard or another, but that doesn’t mean that an independent third party has certified my compliance, or even stated its conformance.

So why doesn’t IDEMIA offer MOSIP-compliant solutions?

Honestly, I don’t know. I haven’t had regular official contact with IDEMIA in years, and the person that I know who just rejoined IDEMIA probably doesn’t know either.

So I have no authoritative answer, but Google Gemini provides this very unauthoritative answer as to IDEMIA’s MOSIP non-compliance:

“IDEMIA’s core business model historically relies on end-to-end, proprietary solutions. MOSIP, by contrast, is an open-source framework designed specifically to prevent vendor lock-in by letting governments mix-and-match components from different tech providers.”

Let’s assume for the moment that Gemini is right in this case. So while IDEMIA may be willing to speak about a solution in Togo “based on” MOSIP, when IDEMIA goes after a critically important opportunity in the FBI or the CIA or the BBC (you know the rest), it’s going to provide a solution based upon IDEMIA-authored components such as its own MorphoKit software development kit.

Knowing full well that the U.S. Federal Bureau of Investigation doesn’t give a hoot about MOSIP compliance.

Because it’s not critically important in that market.

Know Your Market

Some biometric vendors focus on the developing world, some adopt the developing world as a secondary opportunity, and others just don’t care because their real revenue comes from elsewhere.

Where should your company focus its attention?

Bredemarket can help your company with analysis, and provide focused content as the analysis progresses. (Analysis is never complete. Things change.)

If Bredemarket can help you decide if MOSIP compliance is worthwhile or worthless, schedule a free meeting.

Having Fun?

In a recent Justin Welsh newsletter, he described the many activities of Michael Kauffman.

“And over the last year, I’ve watched him ship ideas at a pace that puts most entrepreneurs to shame. The Monopoly game. The trout hat. Dinners where strangers get matched to become friends. Cookouts and mushroom foraging days. Entrepreneur meetups. Puzzles. Fly-fishing excursions. And the most surprising one, that physical newsletter that arrives in my mailbox once a quarter.”

Then Justin kinda sorta asked “why.”

“I remember getting my first copy and thinking, Who the hell does this?

The answer?

“Someone who thought it would be fun, that’s who.”

Catskill-opoly. From the Catskill Crew website.

In case you haven’t noticed, I’m having fun promoting Bredemarket. Between the videos and the songs and the music references, I’m enjoying myself.

And, as William H. Cosby Jr., Ed.D. (disgraced) once said:

“If you’re not careful, you may learn something before it’s done!”

Google Gemini.