In this two-part series, we explore some of the issues around government surveillance and the search for that elusive balance between security and privacy. In this second part, we look at the search for that digital ‘safe place’ where privacy is assured and just why that place is becoming ever more elusive.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
Irish DPC is launching an investigation on potential GDPR violation of Google’s Ad Exchange online ad system which is active on 8.4 million websites worldwide.
After nearly two months of non-stop controversy and scandal over its improper use of Facebook data, Cambridge Analytica finally announced that it was ceasing operations, effective immediately. In doing so, Cambridge Analytica has become the new poster child to highlight the perils of data security breaches.
Newly published paper on twelve organizational accountability principles to help private and public organizations balance necessary data use with privacy concerns.
Facebook was served with a legal warrant and returned a set of messages in which mother and daughter discuss how to properly use abortion pills. The pair appear to have not enabled the optional message encryption.
Biometric technology is advancing rapidly and regulations need to keep up. What are some of the challenges and how they should be addressed to secure digital data?
While Apple does not appear to be backing down on any of its iOS 14 privacy features, it has relented somewhat in the face of pressure from some of the giants of the ad tracking industry.
With growing concerns about privacy practices at big Internet providers, FTC has issued orders to AT&T, AT&T Mobility, Comcast Cable, Google Fiber, T-Mobile USA, Verizon and Verizon Wireless to share how they collect, retain, use and disclose information about consumers and their devices.
Do we need to protect the privacy of the deceased? Let’s look at the two kingpins of privacy regulation mentioned earlier – HIPAA and GDPR. We then take a brief view at a few of the literally hundreds of other personal information protection laws with regard to if and how they relate to the protection of the deceased.
Most organisations are hungry for the insights and business value to be gleaned from their customer data but wary of falling foul of GDPR. It’s a privacy minefield that many businesses will have to navigate in 2019 and beyond.









