See how CPOs and other data privacy professionals are preparing to comply with potential new state rules – even as they also work to ensure compliance with various international and state-level data privacy laws.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
With the growing interest from consumers, tech companies, media, and politicians, there may finally be enough momentum to pass a national data privacy law. What are the benefits and challenges?
For decades, U.S.-controlled Crypto AG helped the CIA spy on governments around the world by inserting encryption backdoor in cryptographic equipment.
Crypto exchange Huobi has announced that it will delist seven privacy coins, citing new financial regulations. Some analysts believe the primary motivation for this move is a planned entry to the US market.
A little-known law from 1984, originally intended to discourage large cash transfers, has been repurposed as a crypto regulation and tucked into the massive US infrastructure bill.
Data that is properly anonymised does not fall under the GDPR but anonymization brings about challenges for data analysis. What are the approaches viable for use in a commercial setting?
Can companies achieve true data anonymization to avoid weaker pseudonymization techniques and lessen the constraints of data privacy laws like the GDPR?
A controversial SDK used for location tracking remains present in hundreds of Android apps, in spite of bans. Data broker X-Mode's tracking software was forbidden from use in the world's two major app stores in 2020.
Even if Meta were using a data clean room for marketing and advertising purposes, it would not be adequate for GDPR compliance. And without GDPR compliance, Meta can’t claim legitimate interest as a legal basis for lawful secondary data processing.
With collection of personal data getting harder under legislations like GDPR and CCPA, ensuring adequate data protection will be the driving factor of success for organizations of the future.









