How should we control access to user data?

strategy (33), eng-strategy-book (22)