Swiss banking secrecy laws began to see significant erosion in 2018, and are facing another substantial blow as the country's government is proposing to allow its spy agency to monitor financial transactions.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
Companies that monetize consumer data have a curious relationship with trust. In some cases however, corporate stewardship of that trust has taken a back seat to the larger imperatives of continuous growth and revenue generation. As a result, the trust relationship between consumers and companies that rely on their data is on very thin ice.
Real time bidding is facing a smattering of privacy complaints in the EU based on a lack of required consumer consent under the terms of the GDPR.
New privacy labels that Apple requires are revealing some major differences between competing messaging apps, best illustrated by setting Signal next to the voracious Facebook Messenger.
The concept of self-sovereign identity (SSI) is gaining interest as it allows users to selectively prove specific aspects of their digital identity using credentials stored in digital wallet.
Privacy-enhancing technologies, like homomorphic encryption, AI-generated synthetic data, and federated learning support privacy enhancing processes and can help meet data protection challenges.
If it were to become EU law, the proposal would require that all messaging services scan all of their messages (including encrypted messages) for potential CSAM materials, and includes use of an AI algorithm to evaluate the intent of conversations for signs of child grooming.
List of data privacy violations is still growing since the Cambridge Analytica scandal two years ago and will not stop unless the tech giants are forced to rewrite their business models.
Employee data collection is a longstanding practice. In light of the trends in privacy law, employers may want to reassess what they are collecting and how long the information should be retained.
The technology sector is facing new regulations and increased calls for further regulation, in particular with respect to data privacy and security. Emerging tech companies that plan to succeed should pay attention and be prepared for more questions about privacy and security from investors, strategic partners, consumers and, possibly, regulators.










