A key concept of many privacy laws is the definition of “personal data”, “personal information” or “personally identifiable information”. If it’s not “personal data”, you are likely outside of the scope of data protection laws, however that is a line in the sand which is constantly moving – in this article David Fraser of McInnes Cooper in Canada examines what that constantly shifting line means for privacy, and the individual.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
Here's what businesses, organizations and governmental entities should be considering as they navigate privacy and cybersecurity challenges encountered in the transition to electric vehicles and the supporting infrastructure.
As Data Privacy Day approaches on January 28, it’s the perfect time for enterprises to reevaluate the way they safeguard data to ensure they’re maximizing its value while still mitigating risk to data subjects or brand safety.
While privacy by design is not a new concept, the GDPR makes it a legal requirement, and thus practical guidance is needed for putting policy into practice. What are the concepts and requirements in the context of recent guidance published by the EDPS and UK ICO?
More than one-third of organizations are concerned about privacy compliance budget spending to meet the requirements of evolving data privacy laws around the globe.
Sharing of financial data in the Google-Citi deal quickly attracted the attention of consumers, lawmakers and regulators concerned about the potential privacy implications.
Use of 'pandemic drones' to enforce social distancing has come under fire over concerns of possible privacy violations. The police surveillance drones would yell at people not observing the rules and also have sensors to detect health conditions.
China’s digital ID trial has stoked privacy concerns, and questions have also been raised about what may happen if a citizen's ID is revoked by the government.
Schrems has filed a case against Apple in the EU, alleging that the company's unique device tracking ID is in and of itself a breach of privacy law regardless of how it is used.
Secure messaging apps can provide a great means of communicating securely and privately, but there's a privacy dilemma as law enforcement and national security agencies face significant obstacles to the lawful access of communications.









