Too many organizations either provide for no security and privacy training and awareness or take a completely inadequate or ineffective (bad) approach. Effective regular training and ongoing awareness can provide tremendous return on significantly better security and privacy practices.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
Apple’s new privacy labels that indicate what sort of personal data apps are accessing are a boon for consumer privacy, but the system might not be working as intended.
Healthcare professionals will have to re-think protections for health data privacy as rapid new advances in AI technology are already able to generate the identity of specific individuals using anonymous health data from different sources.
We should strive for a human-centric, value-driven, yet flexible and business friendly standards backed by laws and regulatory enforcement. Yet abandoning the old ways of relying on privacy notices and consent forms will remain contentious, controversial and, if it happens, still take a lot of time.
To many, a CPO plays an important role with regulations like GDPR in play, hear it from Brock Wanless, Groupon’s global privacy and regulatory managing counsel, on how the company enforces privacy without one.
Currently slated for a September release, iOS 15 will implement enhanced privacy controls for Siri's speech recognition and email privacy as well as a new "privacy report" feature.
A Palantir rant against "business as usual" in Silicon Valley criticized the valley's various tech giants as being out of touch with the needs of American people.
New report claims that Israeli police used the Pegasus spyware on the country's citizens, including opponents of then-president Benjamin Netanyahu and a number of other targets not under suspicion of a crime.
In the first part of a three part series of articles, Pauline C. Reich, Professor and Director of the Asia-Pacific Cyberlaw, Cybercrime and Internet Security Research Institute at Waseda University School of Law in Tokyo, Japan gives some context to the recent US v. Apple case.
Children’s privacy violations is a problem that is common to big tech companies in targeted advertising: screening out minors who are entitled to enhanced data protection rights.









