Drawing on terms first proposed in a series of stalled-out data privacy bills that date back to at least 2018, the Government Surveillance Reform Act of 2023 (GSRA) narrows the focus specifically to warrantless government interception at all levels from federal to local.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
A new data sharing policy is universalizing personal information among Facebook products. WhatsApp informed users of this change in a privacy policy update, which did not provide any means of opting out.
Elon Musk followed the privacy policy update with a statement affirming that X's machine learning and AI models would not be trained with private and confidential information, such as direct messages.
This article is based on a presentation made during the Data Privacy Asia 2016 conference held on 9-11 November 2016. Author Karen Ngan is a commercial law partner at Simpson Grierson (New Zealand) . She co–heads the firm's information and communications technology group and its data protection and privacy group. In this article she discusses some of the challenges with dealing with 21st century privacy issues under a Privacy Act that is over 20 years old. She also covers some of the measures or practices that have been taken to address some of these challenges.
Privacy concerns may be getting lost in the stampede to find a 'better Twitter,' as researchers warn that Meta's new app collects much more sensitive personal information than comparable platforms.
Public Health England announced that personal identifiable information collected by NHS Test and Trace program to control COVID-19 will be kept for 20 years.
NIST face recognition study found that law enforcement systems have trouble accurately identifying faces of Native American, African American, women and people at extreme ends of the age spectrum.
Why is there always some information security or privacy pros who insist on proclaiming that user awareness and training is a waste of time and money?
Amidst a recent storm of controversy in which leaks have revealed that repressive governments and even criminal groups have wound up with access to its Pegasus spyware, NSO Group now finds itself unwelcome in the US.
NSO group is now facing a lawsuit from Apple after leaks revealed that the Pegasus spyware was exploiting a zero-day, zero-click vulnerability in Apple devices.










