In the Alphabet annual report for 2018, Google’s parent company provided additional guidance on how their privacy practices could impact the company’s overall business model, and hence, its ability to churn out billions of dollars of revenue each quarter.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
The spread of the Delta variant highlights how important it is to quickly respond to public health crises, and that...
Reasonable anonymous transactions have been proposed for the digital yuan, which is currently in testing in multiple regions of the country. PBOC officials have also promised to deliver the best privacy protection, though questions remain.
Privacy groups are raising alarms about some EU aid programs. Funds, equipment and training are reportedly going to repressive governments and being used explicitly for domestic surveillance.
Home security cameras upload data when motion is detected, creating a predictable pattern that increases privacy risks by allowing third parties to know when someone was present at home without the need to watch the footage.
U.S. doing an “adequate” job for Privacy Shield but could be doing more to protect the data transfer of EU users, including reform of the FISA regulations.
With companies no longer able to rely on Privacy Shield for protection, companies have two main options available to them: to localize data storage and/or to strengthen their SCCs.
Student data privacy outcomes depend as much on operational design as on policy. Over the past decade, SDPC adoption demonstrates that when privacy is supported through shared infrastructure rather than individual contract negotiation, protections become more consistent, auditable, and sustainable.
The ISACA report finds that though the desire to beef up departments is there, a major privacy skills gap remains as the labor market for privacy professionals is tight (as are budgets).
It’s time to consciously Shift Left. Privacy teams must be involved with product development from the earliest stages. It’s the difference-maker between reacting to a privacy misstep after the fact and preventing the misstep in the first place.










