Retail News CRM

Tag: privacy

  • Google was fined for $57 million under the GDPR

    Google was fined for $57 million under the GDPR

    The CNIL, the French data protection watchdog, has issued its first GDPR fine of $57 million (€50 million). The regulatory body claims that Google has failed to comply with the General Data Protection Regulation (GDPR) when new Android users set up a new phone and follow Android’s onboarding process. Two nonprofit organizations called ‘None Of Your Business’ (noyb) and La Quadrature du Net had originally filed a complaint back in May 2018 — noyb originally filed a complaint against Google and Facebook, so let’s see what happens to Facebook next. Under the GDPR, complaints are transferred to local data protection watchdogs.

    While Google’s European HQ is in Dublin, the CNIL first concluded that the team in Dublin doesn’t have the final say when it comes to data processing for new Android users — that decision probably happens in Mountain View. That’s why the investigation continued in Paris.

    The CNIL then concluded that Google fails to comply with the GDPR when it comes to transparency and consent.

    Let’s start with the alleged lack of transparency. “Essential information, such as the data processing purposes, the data storage periods or the categories of personal data used for the ads personalization, are excessively disseminated across several documents, with buttons and links on which it is required to click to access complementary information,” the regulator writes.

    For instance, if a user wants to know how their data is processed to personalize ads, it takes 5 or 6 taps. The CNIL also says that it’s often too hard to understand how your data is being used — Google’s wording is broad and obscure on purpose.

    Second, Google’s consent flow doesn’t comply with the GDPR according to the CNIL. By default, Google really pushes you to sign in or sign up to a Google account. The company tells you that your experience will be worse if you don’t have a Google account. According to the CNIL, Google should separate the action of creating an account from the action of setting up a device — consent bundling is illegal under the GDPR.

    If you choose to sign up to an account, when the company asks you to tick or untick some settings, Google doesn’t explain what it means. For instance, when Google asks you if you want personalized ads, the company doesn’t tell you that it is talking about many different services, from YouTube to Google Maps and Google Photos — this isn’t just about your Android phone.

    In addition to that, Google doesn’t ask for specific and unambiguous consent when you create an account — the option to opt out of personalized ads is hidden behind a “More options” link. That option is pre-ticked by default (it shouldn’t).

    Finally, by default, Google ticks a box that says “I agree to the processing of my information as described above and further explained in the Privacy Policy” when you create your account. Broad consent like this is also forbidden under the GDPR.

    The CNIL also reminds Google that nothing has changed since its investigation in September 2018.

  • Experts blame high licensing fees for piracy in Vietnam

    Experts blame high licensing fees for piracy in Vietnam

    Speaking at a conference held in Hanoi on Wednesday, Lee Dogoo, head of business at South Korean firm SBS Contents Hub, said while infringements occur in all countries, they are rife in Vietnam because of high licensing fees.

    As these fees continue to go up, the pirate broadcast market also continues to grow, he said.

    Vu Thi Huong Lan, head of the Hanoi Law University’s international law faculty, voiced agreement saying high fees charged by copyright holders are deterring viewers from watching licit content.

    Referring to the recent Asian Games (Asiad), she said the owner of the event’s broadcasting rights had demanded such a huge price for broadcasting rights in Vietnam that no Vietnamese broadcaster was able to afford it.

    This in turn forced Vietnamese fans to seek out previously unknown pirate sites that illegally broadcast the event live, she said.

    “While I do not support this, I believe the copyright holders clearly should reconsider [the price].”

    Nguyen Quang Dong of the Institute for Policy Research and Communication Development said the rising trend of watching sports on the Internet in Vietnam contributes to the increase in copyright infringements.

    According to data released by Global Web Index, the percentage of people watching sports on the Internet globally was 15 percent in 2016 and 19 percent now. But in Vietnam it was 27 percent in 2016 and 32 percent now.

    Citing data about the five largest illegal sports broadcasting websites, Dong said they only had 11.1 million views last March but this number jumped to 25.4 million in June during the 2018 FIFA World Cup.

    This trend also explains why Facebook recently acquired the rights to broadcast the English Premier League in several Asian countries including Vietnam, he pointed out.

    Nguyen Thanh Van, head of Vietnam Television’s (VTV) Intellectual Property Unit, said the national broadcaster is also suffering badly from copyright infringements.

    Many units have been found broadcasting VTV programs or making DVDs of them for sale without permission, including programs for which it had to pay large amounts of money to produce or obtain broadcasting rights.

    “For instance, in just the first month of us broadcasting the TV shows ‘Nguoi phan xu’ [The Arbitrator] and ‘Song chung voi me chong’ [Living with Mother-in-Law], over 400 Facebook pages and YouTube channels violated our copyrights. As for the 2018 World Cup, in just the first two days there were 700 [pirate] accounts.”

    A representative of pay TV firm K+, lamenting that copyright infringements are occurring every hour in the digital environment, said there is still no effective tool to combat them on all platforms.

    K+ has tried requesting violators to remove pirated content many times, but this has not worked, and his company was bleeding financially, he said.

    K+, which has the Vietnam broadcasting rights to many major sports events such as the English Premier League, the UEFA Champions League and Europa League and tennis’ ATP World Tour, has also been investing in upgrading its systems and training employees to monitor, detect, prevent, and handle copyright violations.

    But these efforts would not be enough to combat piracy without cooperation from consumers and assistance from the authorities, the representative said.

    However, the most important reason for pirates dominating Vietnam’s broad market is a lack of effective law enforcement. According to local authorities, websites found violating copyright laws would be punished and banned. However, many illegal websites have opened and operated without interference from the authorities.

    National broadcaster VTV said it had found more than 700 sites and Facebook pages that broadcast World Cup matches without permission within just three days after the event started and dealt with nearly half of them.

    According to experts, many of the sites are registered overseas, so it is difficult for Vietnamese authorities to find and penalize the culprits. It can be seen from the case of xoilac.tv, a site registered in the U.S., which had been illegally broadcasting live matches from the Asiad with Vietnamese commentary last month.

    The Institute for Policy Research and Communication Development proposed that Vietnam should allow Internet Service Providers (ISPs) to block pirate websites, remove content that violate copyright and prevent violators from receiving money from advertisers.

    It also suggested that broadcasters associations could publicize the list of pirate websites and circulate it among advertisers.

  • Facebook, Google okay with Vietnam’s cybersecurity law

    Facebook, Google okay with Vietnam’s cybersecurity law

    Representatives of tech giants raised no objections and said they would modify their strategies according to the new law, claims senior official.

    Facebook and Google found Vietnam’s cybersecurity law “appropriate” and did not object to it, a senior Public Security Ministry official said Friday.

    Vietnam’s cybersecurity law, which was approved by a majority vote in the National Assembly on Tuesday, requires foreign businesses like Facebook and Google to store Vietnamese users’ data within the nation’s territory and provide it authorities upon receipt of written requests.

    As the law was being drafted, lawmakers had reached out to Google and Facebook to discuss its provisions, said Lieutenant-general Hoang Phuoc Thuan, director of the ministry’s Cybersecurity Department.

    “They said that this law was appropriate and that they will research to modify their companies’ strategies accordingly,” Thuan told.

    Authorities will only ask businesses to provide users’ data when there are signs of violations of the law, Thuan said.

    “Providing customers’ data to security authorities is not a violation of privacy,” he added.

    Facebook Vietnam and Google were not immediately available for comment.

    The cybersecurity law, which has been discussed by Vietnamese legislators since October last year, had raised concerns of MPs and experts that the country would end up violating its international commitments.

    Thuan dismissed these concerns. “I have met with and listened to diplomats and they all affirmed that there are exceptions in every country.”

    He affirmed that the law doesn’t affect freedom of speech; it actually protects the rightful benefits of individuals and organizations on networks.

    The new cybersecurity law, which will take effect in 2019, bans internet users from organizing, encouraging or training other people for anti-state purposes.

    They are not allowed to distort history, negate the nation’s revolutionary achievements, undermine national solidarity, offend religions and discriminate on the basis of gender and race.

    The law also prohibits the spreading of incorrect information which causes confusion among people, hurts socio-economic activity, creates difficulties for authorities and those performing their duty, and violates the legal rights and benefits of other organizations and individuals.

  • How updating Privacy Settings will affect Businesses

    How updating Privacy Settings will affect Businesses

    You may have suddenly started receiving privacy updates from all the internet sites, apps and services you use. That’s because the European Union’s General Data Protection Regulation becomes law on May 25, 2018. It’s the clearest statement yet from any regulator on what consequences companies could face in dealing with their customers’ personal data.

    The regulation has been introduced to counter the power and prevalence of data collection and online surveillance techniques. It contains strict new rules of data protection, and severe penalties for breaches.

    The regulations apply to the data processing activities of any business that is a data processor (like US-based Amazon Web Services or India-based Habiledata) or data controller (like Ebay and Facebook) with an establishment in the EU.

    It also applies to any processor or controller, wherever they are located, that is processing the personal data of EU residents. This is regardless of where that data is processed and is irrespective of whether payment is required.

    By forcing non-EU companies to comply, the EU is ensuring that EU and non-EU businesses compete on the same terms.

    How it will affect businesses

    Australian businesses will not be forced to comply with or fall foul of the new data regulation merely because they maintain websites accessible in the EU. However, those with an office in the EU, or whose website is aimed at or tracks the data of EU residents, will be affected.

    These include businesses with an EU footprint, for example retailer Harvey Norman operates in Ireland, Croatia and Slovenia. It also covers data processors in Australia whose business includes EU or EU based clients, and startups which trade globally.

    Australian businesses may benefit from the fact that the new rules are consistent with the Australian Privacy Principles. Both promote transparency and accountability in information handling and require businesses to notify of any privacy breaches.

    By contrast, businesses in countries where data handling requirements are less comprehensive (notably the US) will have to make changes to become compliant.

    Nevertheless, the new EU law will impose new burdens on Australian businesses. For example, the EU laws specify encryption and pseudonymisation – where personally identifiable information is replaced by one or more pseudonyms – to ensure data is not identifiable.

    The new EU law will also change the standard practices of online businesses by outlawing pre-ticked boxes, required consent and bundled consent. Businesses must now seek (in clear and plain language), and individuals must give, active, specific, free and informed consent to each purpose for which their data is collected.

    The data law also require all businesses to demonstrate that they have procedures for notifying regulators and customers of data compromises: within 72 hours in the case of high risk breaches and without undue delay in all cases.

    How it will affect consumers

    The EU law includes new or enhanced rights for individuals. Many have no equivalents in other jurisdictions, including Australia.

    People have a right to demand that businesses erase and cease disseminating personal information, and to halt its processing. However, this “right to be forgotten” is balanced against the public interest in the information remaining available.

    The right to data portability in the legislation enables individuals to obtain personal information they have given by consent to one controller in a “structured, commonly used, machine-readable format” and transfer it to another. This will make it easier for customers to switch between businesses.

    However these rights impose regulatory burdens on businesses. It may be technically and organisationally difficult without sophisticated and expensive data handling processes.

    For businesses that rely on things like cloud backup and third party customer support, deleting or making copies of transferable data will be difficult.

    The commercial value of data is such that some companies may simply try to avoid the consequences of the new EU laws by processing information outside the EU, and applying different standards of data protection to customers depending on their location. Facebook has done this.

    On the other hand, given how complex double standards can be to apply in practice, they may simply make the EU rules the new normal of global privacy. In that case businesses should be using it as an opportunity to build more sustainable business models in the emerging era of respect for privacy.

  • True Move told to consider compensation over data leak

    True Move told to consider compensation over data leak

    Thai telecoms regulator NBTC has instructed mobile operator True Move H to assess the impact of its recent personal data leak and offer compensation to any affected customers.

    The regulator also plans to conduct a formal investigation into the incident and consider imposing punishments, and issue a letter demanding that mobile operators take appropriate steps to prevent similar breaches in the future.

    A security researcher recently revealed that the identity documents of up to 45,736 customers of True subsidiary iTrueMart had been exposed by being stored in a publicly-accessible Amazon S3 data bucket. The company also took more than a month to finally make the cache of files private.

    Researcher Niall Merrigan discovered the cache by scanning certificate transparency logs created when someone creates a new security certificate.

    Yet True Move H and parent True Corp are continuing to characterize the action as a data breach. A True Corp executive told that the company is considering taking legal action for hacking the data from the system, stating that he used “special tools to access data which he has no right to get into.”

    But a cloud expert noted that because the default setting for the AWS S3 service is private, True had to have intentionally set the data to public.

  • Uber CEO says company failed to disclose massive breach in 2016

    Uber CEO says company failed to disclose massive breach in 2016

    Uber Technologies Inc failed to disclose a massive breach last year that exposed the data of some 57 million users of the ride-sharing service, the company’s new chief executive officer said on Tuesday.

    Discovery of the company’s handling of the incident led to the departure of two employees who led Uber’s response to the incident, said Dara Khosrowshahi, who was named CEO in August following the departure of founder Travis Kalanick.

    Khosrowshahi said he had only recently learned of the matter himself.

    The company’s admission that it failed to disclose the breach comes as Uber seeks to recover from a series of crises that culminated in the Kalanick’s ouster in June.

    “None of this should have happened, and I will not make excuses for it,” Khosrowshahi said in a blog post.

    According to the company’s account, two individuals downloaded data from a web-based server at another company that provided Uber with cloud-computing services.

    The data contained names, email addresses and mobile phone numbers of some 57 million Uber users around the world. The hackers also downloaded names and driver’s license numbers of some 600,000 of the company’s U.S. drivers, Khosrowshahi said in a blog post.

    Bloomberg News reported that Uber’s chief security officer Joe Sullivan and a deputy had been ousted from the company this week because of their role in the handling of the incident. The company paid hackers $100,000 to delete the stolen data, according to Bloomberg.

    Though such payoffs are rarely discussed in public, U.S. Federal Bureau of Investigation officials and private security companies have told Reuters in the past year that an increasing number of companies have made payments to criminal hackers who have turned to extortion.

    None have previously come to light that aimed to suppress breaches that would have required public disclosure, such as those involving protected personal information.

    Sullivan did not immediately return messages seeking comment.

    Sullivan, formerly the top security official at Facebook Inc , is a former federal prosecutor and one of the most admired security executives in Silicon Valley.

    Kalanick learned of the breach a month after it took place, in November 2016, as the company was in negotiations with the U.S. Federal Trade Commission over the handling of consumer data, according to Bloomberg.

    Uber representatives did not respond when asked to comment on the Bloomberg report.

    Khosrowshahi said he had hired Matt Olsen, former general counsel of the U.S. National Security Agency, to help him figure out how to best guide and structure the company’s security teams and processes.

    “While I can’t erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes,” he said. “We are changing the way we do business, putting integrity at the core of every decision we make and working hard to earn the trust of our customers.”

  • Uber to end post-trip tracking of riders as part of privacy push

    Uber to end post-trip tracking of riders as part of privacy push

    The change, which restores users’ ability to share location data only while using the app, is expected to be announced on Tuesday and rolled out to Apple Inc iPhone users starting this week.

    Uber Technologies Inc is pulling a heavily criticized feature from its app that allowed it to track riders for up to five minutes after a trip, its security chief told, as the ride-services company tries to fix its poor reputation for customer privacy.

    The change, which restores users’ ability to share location data only while using the app, is expected to be announced on Tuesday and rolled out to Apple Inc iPhone users starting this week. It comes as Uber tries to recover from a series of crises culminating in the ouster of Chief Executive Travis Kalanick and other top executives.

    Dara Khosrowshahi, the CEO of travel-booking company Expedia Inc is set to become Uber’s new chief executive.

    The location-tracking update is unrelated to executive changes, said Joe Sullivan, Uber’s chief security officer, in an interview with Reuters. Sullivan and his team of about 500 have been working to beef up customer privacy at Uber since he joined in 2015.

    “We’ve been building through the turmoil and challenges because we already had our mandate,” said Sullivan, who is a member of the executive leadership team that has been co-running Uber since Kalanick left in June.

    An update to the app made last November eliminated the option for users to limit data gathering to only when the app is in use, instead forcing them to choose between letting Uber always collect location data or never collect it.

    Uber said it needed permission to always gather data in order to track riders for five minutes after a trip was completed, which the company believed could help in ensuring customers’ physical safety. The option to never track required riders to manually enter pickup and drop-off addresses.

    But the changes were met with swift criticism by some users and privacy advocates who called them a breach of user trust by a company already under fire for how it collects and uses customers’ data. Uber said it never actually began post-trip tracking for iPhone users and suspended it for Android users.

    Sullivan said Uber made a mistake by asking for more information from users without making clear what value Uber would offer in return. If Uber decides that tracking a rider’s location for five minutes is valuable in the future, it will seek to explain what the value is and allow customers to opt in to the setting, he said.

    Sullivan said Uber was committed to privacy but had previously suffered “a lack of expertise” in the area.

    The change comes two weeks after Uber settled a U.S. Federal Trade Commission complaint that the company failed to protect the personal information of drivers and passengers and was deceptive about its efforts to prevent snooping by its employees.

    Uber agreed to conduct an audit every two years for the next 20 years to ensure compliance with FTC requirements.

    The location-tracking changes will initially only be available to iPhone users, but Uber intends to bring parity to Android devices, Sullivan said.

    The changes are part of a series of updates expected in the coming year to improve privacy, security and transparency at Uber, Sullivan said.

  • Aussie mobile customers’ private data up for sale

    Aussie mobile customers’ private data up for sale

    Private information on Australian mobile subscribers are being sold off by unscrupulous members of offshore call centers, according to an investigative report.

    The private details of customers from the market’s three operators – Optus, Telstra and Vodafone – are being offered for sale by a call center business named AI Solutions, run by Indian businesman Imran Khan.

    Information including home addresses, dates of birth, alternative numbers, billing statements and call history are being offered for between A$350 ($260) and A$1,000, the report states. Prices are higher for VIPs , politicians, police and celebrities.

    Security industry sources spoken to for the report say the practice of call center workers selling off Australian customer details has been long-standing, and potentially involves more than one company.

    In a press statement, a Vodafone Hutchison Australia spokesperson said the company is “aware there are individuals who do attempt to illegally access data through various channels from companies and organisations which hold customer information,” and has “invested millions of dollars over recent years in security systems and processes, and have a number of safeguards in place to prevent unlawful access of customer information.”

    For offshore call centers, security safeguards include paperless offices, a no mobile phone policy, no access to third party websites, email monitoring, role based systems access, continuous agent training and disciplinary process.

    An Optus spokesperson said the company has referred the matter to federal police, and Telstra said the company does everything it can to protect customer data.

  • Privacy is paramount to online consumers

    Privacy is paramount to online consumers

    More than half (55%) of consumers globally have decided against buying something online due to privacy concerns, a recent KPMG International survey indicates.

    The survey also revealed that less than 10% of consumers feel they have control over the way organizations handle and use their personal data. Respondents in most countries say privacy controls are more important than the potential convenience gained from sharing personal data.

    “An executive would be at risk of being fired if half their customer base disappeared after they made a crucial business decision,” said Mark Thompson, Global Privacy Lead at KPMG.

    “Failure to embed privacy into the DNA of their business strategy could ultimately lead to the extinction of a business given how closely consumers and regulators alike are paying attention to how organizations collect, store and use personal data.”

    The survey further revealed that 82% are not comfortable with the sale of their data to third-parties in exchange for the speed, convenience, product range, home delivery and price comparison that online shopping offers.

    Over two-thirds of people are not comfortable with smartphone and tablet apps using their personal data. In all markets but one, at least 75% of respondents said they were uneasy with their online shopping data being sold to third-parties.

    About 55% said a free fitness tracking device that monitors the well-being of users and produces a monthly report for them and their employer is also crossing the line.

  • HK privacy commissioner weighs in on e-wallets

    HK privacy commissioner weighs in on e-wallets

    Privacy commissioner for personal data Stephen Kai-yi Wong has urged Hong Kong residents to vigilantly keep control of their personal data in wake of the Hong Kong Monetary Authority’s (HKMA) decision to grant Stored Value Facilities (SVF) licensesto five mobile e-wallet providers.

    Wong also called on e-wallet operators to win customers’ trust by respecting their privacy rights and safeguarding their personal data.

    While he acknowledged that e-wallet operators may need to collect significant amounts of personal data as part of their operations, he said providers should give consumers control over the types of data e-wallet apps are allowed to access, and the ability to revoke these permissions at any time.

    To keep their personal data safe, Wong recommended that users of e-wallet services find out how e-wallet operators will handle and process personal data collected, understand the apps’ privacy settings and permissions and avoid operating e-wallet apps over public or insecure Wi-Fi connections.

    Users should also use complex, unique passwords, make sure devices with the app installed have appropriate anti-theft features switched on and regulatory monitor transaction records for unauthorized payments.

    Wong said e-wallet operators are required under the new Stored Value Facilities Ordinance to clearly explain to users what personal data is collected and the reasons why.

    Operators planning to use collected data for purposes not directly related to payment should obtain the user’s explicit and voluntary consent, and are legally required to ensure the accuracy and security of personal data collected. Customers are also entitled to access this data and request corrections.

  • Mobile apps collecting alarming amounts of data

    Mobile apps collecting alarming amounts of data

    More than half of mobile applications are collecting “alarming” quantities of data, a new study indicates.

    Hewlett Packard Enterprise’s HPE mobile application security report 2016 analyzes scans of more than 36,000 iOS and Android mobile apps, and reveals the impact of increasing data collection.

    As mobile applications become more prevalent in the work environment, it’s essential that organizations understand the security vulnerabilities of mobile applications and implement mobile security best practices and policies required to protect today’s digital enterprise. Adversaries are shifting their focus to mobile platforms, with more than 10,000 new Android threats discovered per day in 2015, and an iOS malware growth rate of more than 230%.

    “Modern mobile applications are collecting, transmitting and storing a wide range of data that often is not necessary to the application’s function, and can cause significant financial and reputational damage if a vulnerability is exploited,” said Jason Schmitt, vice president and general manager, HPE Security Fortify at Hewlett Packard Enterprise.

    “With attackers’ growing interest in mobile, it’s critical that developers build security into applications from the onset, and organizations take a proactive approach to data security to better protect both personal and corporate data.”

    Not all apps need to track your location

    A majority mobile applications track your location, but not all of them need to. More than 50% of the scanned applications accessed geolocation data. This can create serious privacy implications in the event of an attack, as an attacker can gain access to the physical location of otherwise anonymous, unsuspecting users.

    While it makes sense for a traffic application to track location, the study found that more than 70% of education applications on iOS did as well. This is disturbing as education applications are often marketed towards children.

    The report also found that calendar data was accessed by more than 40% of the iOS games and more than 50% of the iOS weather apps scanned. Calendar data can be particularly sensitive, detailing not just when business meetings take place, but also the topics and invitees.

    Ad and analytics frameworks are commonplace in application development, with more than 60% of applications scanned using these frameworks. A framework that is misconfigured – or insecure to begin with – could be storing or transmitting a significant amount of highly specific and potentially sensitive data about users.

  • Online data disrupts how consumers buy cosmetics in Singapore

    Online data disrupts how consumers buy cosmetics in Singapore

    The global market research firm TSN just released the results of a study—The Connected Life—that found nearly nine out of every ten shoppers (88%) in Singapore research products before making a purchasing decision.

    “It’s unsurprising that Singaporeans are exceptionally good at shopping,” says retail expert Fabio Trabucchi of TNS Singapore, in his recent commentary piece for the Singapore Business Review. “With more high-end malls per capita than anywhere else in Asia, shopping is now a well-entrenched national past-time.”

    Pre-shopping

    A preponderance of personal care items consumers in Singapore investigates products and prices before actually shopping to buy.

    “Ever keen for a bargain, almost eight in ten (78%) shoppers say they do pre-purchase research for personal care products such as skin care, perfume, and cosmetics, and 66% for hygiene items such as deodorant and shower gel,” explains Trabucchi, referring to data from The Connected Life study.

    This marks a shift in consumer behavior that could inform brand strategy to good effect, aligning packaging, branded content and ingredient information with new consumer preferences.

    “Previously these categories used to be a prime area for impulse buying, but thanks to the ease of the internet, Singaporean shoppers are getting savvier about the products they chose and the rationale behind it,” remarks Trabucchi.

    Information age

    Getting informative content in front of consumers is the key to capturing shoppers’ attention and dollars today.

    Multinational companies are ahead of the game, producing beauty content that resonates with consumers. L’Oréal recently opened an in-house branded content studio in Canada , where employees can create dynamic messaging to reach consumers with information that matters.

    “As consumers in Singapore adopt a more considered approach to their purchases, brand owners and retailers can provide the information – and incentives – they need to make up their minds,” confirms Trabucchi in his post for the Singapore Business Review.

    “Whether online or offline, businesses need to understand researching behaviours and ensure they are providing shoppers with relevant content that informs their purchase decisions,” he believes.

    Concluding, “this means they must stop thinking in terms of advertisements and start becoming content providers that offer relevant information and offers at every stage of the shopper journey.”