Annual Privacy Governance Report from IAPP and EY focuses on the ongoing COVID-19 pandemic and its impact on privacy professions, along with the Schrems II decision and the resulting complications it has created for data transfers.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
New iOS 13 will limit VoIP apps from running in the background and thus close a loophole that allows third-party apps to exploit background access to collect data on users.
New privacy labels that Apple requires are revealing some major differences between competing messaging apps, best illustrated by setting Signal next to the voracious Facebook Messenger.
Privacy pros with the necessary technical skills are in-demand and hard to find even for well-funded enterprises, according to a new report from IT governance association ISACA.
About half of all organizations are struggling to fill both technical and legal & compliance roles that require privacy skills, with about 3/4 anticipating a need to add both in 2022.
In a blow to personal privacy, New Jersey's highest court has ruled that people do not have a Fifth Amendment right to refuse to give phone passcodes to police.
The unique device identifier that Apple uses for personalized ad tracking, the IDFA, has been in the news lately. You may soon be hearing just as much about Google's equivalent for Android, the AAID.
As of 2019, Big Tech companies were not particularly popular as a new poll shows that negative views have increased since then, with only 34% of Americans now expressing any level of positive opinion.
People are increasingly aware of consumer privacy issues, but also overwhelmingly feel that they do not have the tools to protect themselves and look to government to intervene.
The Apple privacy complaint is significant as France Digitale is a major lobbying organization, representing over 2,000 companies that include most of the country's venture capital firms and entrepreneurs.









