As the technologies for gathering, analysing, and acting on information become increasingly powerful, we find ourselves facing a tipping point as we consider the impact of data-driven processes on the ethics in information management and the challenges of managing data privacy.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
In the past few months the amount of talk, advice, debates, and claims about the EU GDPR which goes into effect May 25, has escalated to a fever pitch. And there is the rub. Most organizations do not know really know or understand what “personal data,” the GDPR term, is as it applies to their organization.
The congressional testimony was supposed to establish a national debate about data privacy and the right of users to protect their data from being sold, used, or analyzed in ways that were never intended. Instead, it has become very clear that regulating privacy is harder than anyone originally expected.
In the aftermath of the Cambridge Analytica scandal, many have suggested that Facebook be regulated, fined and perhaps even broken up. After all, if the FTC were to invoke its full power, it could theoretically levy hundreds of millions of dollars of fines, crippling Facebook. But is a big tech company too big to fail?
With high-profile scandals and the seemingly daily buzz of breaches, scams and exploits, it’s more and more obvious that the data points that make up your online profiles are a hot commodity. Time for the citizenry to take back their personal data and bring back responsibility into the ecosystem.
While the Facebook Cambridge Analytica scandal has created its share of problems for Facebook, it’s clear that the scale and scope of the scandal extends to every corner of Silicon Valley. After all, most tech giants are collecting staggering amounts of user data and comprehensive new privacy regulations seem imminent.
GDPR may have a huge impact on small businesses but may not stop government surveillance or cool the unfair advantage of tech giants over smaller industries and smaller players. Are there real improvements to consumer privacy?
Many companies may now be afraid of data monetization because of concerns over potential privacy violations. There is also a growing concern over being legally compliant but still making customers unhappy or uncomfortable. Is differential privacy the answer?
Despite Facebook pledging that it has figured out its problems, new revelations of data sharing with 60 different device makers has now come to light.
Proposed Secure Data Act wants to forbid government agencies from demanding for encryption backdoors. This is a positive move but will it resolve the security vs. privacy debate?









