The only way to achieve data privacy is through implementing effective data security. A well-designed, privacy-first security program offers significant benefits to any organization while minimizing potential privacy impacts.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
Citizen Lab reports that QuaDream spyware is being used by governments in at least 10 countries to track activists, journalists and political opponents among other questionable uses.
In June 2016 the Korean government announced new guidelines on personal data de-identification measures which have contributed to a greater clarity around the use and transfer of personal data for purposes other than those consented to by the data subject. How will they positively impact the big data market?
FTC has just issued a record-setting $5 billion Facebook fine for privacy breaches from the Cambridge Analytica scandal. Is the U.S. government changing the way they regulate technology companies on user privacy and data?
New report claims that Israeli police used the Pegasus spyware on the country's citizens, including opponents of then-president Benjamin Netanyahu and a number of other targets not under suspicion of a crime.
Study finds RTB adtech systems share online behavior data 294 billion times per day in the U.S. and 197 billion times per day in Europe. Average internet user in the US is exposed 747 times each day; in Europe it is 376 times per day.
A Reuters report indicates that popular cryptocurrency exchange Binance was pressured into handing user data over to the Russian FSB, but the company denies that the story is accurate.
ProtonMail has built its reputation in no small part because of its pledge to not keep user IP logs except in "extreme criminal cases." A recent case indicates that the circumstances may not need to be all that extreme.
With consumer awareness of privacy at an all time high, there is not only regulatory risk, but also reputational and brand risk for those CMOs who drop the ball – an increasingly likely occurrence as the changes to the familiar status quo mount.
Popular department store chain Macy's is facing a privacy lawsuit over its alleged use of the controversial facial recognition software sold by Clearview AI.










