Your job as a new CPO is to lay the foundation, merge any existing and new pieces into one privacy program and then lead the way on all things privacy. Where do you start? What are the priorities? How do you introduce privacy concepts to the company? You need a plan.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
Popular cloud-based word processor app WPS, one of the most widely used of its type in China, may be facilitating state censorship of user’s private documents. User complained million-word document was locked due to "sensitive content."
State DMV offices around U.S. have made tens of millions of dollars in profit since 2014 by selling personal data of drivers which surprisingly is not in violation of state law.
A temporary moratorium on the use of facial recognition technology in state schools is now a matter of law in New York, following the conclusion of a study that found that potential rights violations outweighed the safety benefit.
The aspect of SOTU that caught big tech's attention was a call for bipartisan support on antitrust enforcement and stronger protections for personal data. The president also called for targeted advertising to children to be banned.
The market for location data is staggering, surpassing $12 billion annually. Yet, it's riddled with privacy pitfalls. Precise location is particularly concerning among the trove of personal data brokers collect.
In part I of an ongoing series of articles Teresa Troester-Falk examined how the evolution of the concept of Accountability as a privacy and data protection principle. In this article, part II she looks at accountability in practice, and how to achieve accountability through structured privacy management.
Apps handling sensitive health data, including some that interface with labs and other entities covered by HIPAA privacy regulations, were found to be sharing health data with third party trackers that provide cues for targeted Facebook ads.
Privacy awareness is now more common than not, with 60% of consumers reporting that they are concerned. While consumers are very much aware of how companies track their online behavior at this point, 34% say that they feel "overwhelmed" in trying to manage it.
Meta is framing the lawsuit as an opening volley in a war against data scraping and invasive surveillance by law enforcement partners. The surveillance company has clearly gone farther than is usual given the creation of some 38,000 fake accounts.








