Companies are implementing vaccine mandates or regular testing, with social distancing and mask wearing in the office, and more employers are requiring full vaccination as a criterion to being hired. Now many organizations are struggling to determine how they will collect and manage this information.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
India’s new CERT-In order applies to VPN providers, virtual private server (VPS) providers, data centers and cloud service providers. These services are required to hold and turn over a variety of customer data.
Change to India's cybersecurity laws has sent VPN providers running from the country ahead of the slated June 27 start date for the new terms.
With so much of our lives documented online and on social media, it can be hard to decipher what is and isn’t a security threat. Securing your digital footprint takes vigilance and persistence and in an increasingly digitally-reliant world, safeguarding the profiles of you and your loved ones has never been more imperative.
The decision in Privacy Commissioner v Telstra has important implications for metadata regulation in Australia, and for judicial oversight of the Australian Privacy Commissioner’s functions. This article examines the decision and discusses the key takeaways for businesses that are based in, or doing business with, Australia.
In recent years, plaintiff attorneys have filed lawsuits alleging that the use of session replay software on websites constitutes an illegal wiretap of plaintiff’s communications with that website and are in violation of state privacy laws.
The Five Eyes proposal for lawful access compromises on encryption, infringes upon our right to privacy, puts our personal data at risk, and utlimately undermines public trust in technology.
The fitness tracking app Strava may have inadvertently compromised not only classified locations, but the movement of personnel over extended periods of time. Surveillance campaign on Israel's military uncovered.
To help information security, privacy and compliance professionals architect and implement the best security and privacy practices for your organization, Rebecca Herold, lead developer and author of ISACA's Privacy Principles and Program Management Guide, provides an overview of the 14 principles and explain the importance for each business, in any country, to implement them within their own organizations.
The WeChat privacy questions stem from numerous users posting logins from unknown devices to their accounts, sometimes at very late and odd hours. Users are speculating about Chinese law enforcement inspecting accounts using some sort of a backdoor.









