Module-4
Data Privacy and its importance: Introduction to data privacy, why is data privacy
important,key concepts in data privacy, key principles of data privacy, personal data,
sensitive personal data,controllers and processors, Individual rights, processing personal
data, ten steps to an effective data privacy programme, Data Privacy ecosystem : global
context in data privacy, Challenges : 1. Balancing of data privacy and digital economy
growth- context, the case of smart cities, 2. Navigating the complexity of the international
legislative landscape - issues and challenges of international data protection: Coverage of
data protection laws, Emergence of new technologies, cross-border data transfers,
strengthening of data protection sanctions and enforcement by trade partners, determining
jurisdiction linked to a data rotection law contravention, key considerations for future
policy
By:Gaurav Prasad
Data Privacy
• Data privacy, also known as information privacy, refers to the
practice of handling and protecting personal data to ensure that
individuals' information is not misused, accessed, or disclosed
without their consent.
• Why is it important?
Personal Security: Protecting personal data helps prevent identity
theft, fraud, and other forms of cybercrime.
Autonomy and Control: Individuals have the right to control their
own personal information.
• Trust: Organizations that handle data responsibly build trust with
their customers, employees, and partners
• Reputation Management: Data breaches and misuse can
damage an organization’s reputation.
• Prevention of Misuse: Data privacy helps protect against the
misuse of personal data for purposes such as unauthorized
surveillance, discrimination, or targeted manipulation.
• Social Responsibility: Ensuring data privacy reflects a
commitment to ethical behavior and respect for individuals'
rights.
Key Concepts of Data Privacy
• Personal Data: Information that can identify an individual, either
on its own or when combined with other data.
• Consent: The principle that individuals should have control over
their personal data and must give informed consent before their
data is collected, used, or shared.
• Data Minimization: The practice of collecting only the data that is
necessary for a specific purpose
• Data Security: Measures and practices to protect data from
unauthorized access, breaches, or other forms of misuse.
• Data Subject Rights: Rights granted to individuals regarding their
personal data, such as the right to access, correct, delete, or
restrict the processing of their data.
• Transparency: The obligation to provide clear and accessible
information about data collection practices, data usage, and the
rights of individuals regarding their data.
• Data Breach: An incident where personal data is accessed,
disclosed, or acquired without authorization.
Key principles of Data privacy
• Lawfulness: Personal data must be processed legally and in
accordance with applicable laws and regulations.
• Transparency: Data subjects should be clearly informed about
how their data will be used, collected, stored, and shared.
Transparency fosters trust between organizations and individuals.
• Purpose Limitation: Personal data should only be collected for
specific, explicit, and legitimate purposes. It must not be further
processed in a manner that is incompatible with these purposes
unless consent is given by the data subject or it is legally justified.
• Data Minimization: Only data that is necessary and relevant for
the purpose should be collected. Organizations should avoid
collecting excessive or irrelevant information.
• Accuracy: Personal data must be accurate, up to date, and
maintained properly. Inaccuracies should be corrected or erased
promptly when discovered or reported.
• Accountability: Data controllers and processors are responsible
for ensuring compliance with data protection regulations. They
must be able to demonstrate that they have adhered to these
principles.
Key importance of Sensitive Personal Data
• Protection of Individual Rights and Freedoms
Personal Security: Sensitive personal data, such as biometric
data, health records, and genetic information, can be used to
uniquely identify individuals.
Right to Privacy: Protecting sensitive personal data upholds an
individual's right to privacy, shielding them from undue intrusion
into their private lives, beliefs, and personal choices.
• Legal Compliance and Avoidance of Penalties
Explicit Consent: Sensitive data typically requires explicit and
informed consent before it can be processed.
• Risk Mitigation
Higher Stakes for Breaches: Sensitive personal data is highly
valuable and a prime target for cybercriminals.
• Ethical Responsibility
Moral Obligation to Protect: Organizations have an ethical
responsibility to handle sensitive personal data with care.
Respect for Individuals: Ensuring the privacy of sensitive data
demonstrates respect for the individual’s personal values, beliefs,
and choices.
Ten steps to an effective data privacy
program
• Understand Legal and Regulatory Requirements
Identify Applicable Laws
Compliance Obligations
• Appoint a Data Privacy Officer (DPO)
Assign Accountability
DPO's Responsibilities
• Conduct Data Mapping and Inventory
Identify Data Types
Data Flow Analysis
• Develop Clear Privacy Policies and Notices
Transparency
User Rights
• Implement Data Minimization and Retention Policies
Limit Data Collection
Retention and Deletion
• Ensure Security Measures
Data Protection by Design
Incident Response
• Conduct Privacy Impact Assessments
Risk Assessment
Identify Risks
• Provide Employee Training and Awareness
Education
Ongoing Programs
• Manage Third-Party Risk
Vendor Assessments
Data Processing Agreements
• Regular Monitoring and Auditing
Continuous Improvement
Adapt to Changes
Challenges in Data Privacy Ecosystem
• Data privacy exposures, commonly referred to as data security
incidents, are critical business concerns. Data incidents can
result in consumer identity theft, profiling, censorship,
surveillance, harassment, discrimination, exploitation and fraud.
• There are two types of data incidents: data breaches and data
leaks. A data breach is a security incident concerning
unauthorized data access. A data leak is an internal privacy
incident concerning accidental or intentional unauthorized
disclosure, dissemination or sharing of protected data.
Balancing Data Privacy and Growth in the
Digital Economy
• Businesses across the globe collect data through many sources,
such as through transactions, communications, customer
behavior, supply chains, risk assessments, or social media.
• With the digitalization of most sectors of economic and social life,
as well as the emergence of the Internet of Things (IoT), the
quantity and quality of data available for collection and analysis is
unprecedented.
[Link]
and-growth-in-the-digital-economy/
Navigating the complexity of the
International Legislative landscapes
• Treaties, conventions, and agreements establish norms for
diplomacy, trade, and cooperation.
• However, enforcing international law can prove challenging due to
the lack of a global enforcement body.
• The cooperation of sovereign states is crucial for upholding these
agreements.
[Link]
landscape-of-law-and-regulations/
Coverages of Data Protection laws
• Personal Data Definition: Laws typically define what constitutes personal
data, often including any information that can identify an individual.
• Data Subject Rights: These laws grant individuals rights regarding their
personal data, such as:
1. Right to access
2. Right to rectification
3. Right to erasure (the "right to be forgotten")
4. Right to restrict processing
5. Right to data portability
6. Right to object to processing
• [Link]
• Data Controller and Processor Obligations: Organizations that
collect or process personal data have specific responsibilities,
including:
1. Ensuring data is collected and processed lawfully.
2. Implementing security measures to protect data.
3. Notifying authorities and individuals in case of a data breach.
• Consent: Many laws require that personal data be processed only with
explicit consent from individuals, especially for sensitive data.
• Enforcement and Penalties: Laws usually establish enforcement
mechanisms and penalties for non-compliance, which can include
fines and legal action.
Emergence of new technologies
• Encryption Advances: Stronger encryption algorithms and
methods, such as homomorphic encryption, allow data to be
processed while still encrypted, reducing the risk of exposure
during computation.
• Zero-Knowledge Proofs: This cryptographic method enables one
party to prove to another that a statement is true without revealing
any additional information. It's useful in authentication and
privacy-preserving transactions.
• Differential Privacy: This technique adds noise to datasets to
protect individual privacy while still allowing for useful statistical
analysis. It’s widely used by tech companies for data analysis
while safeguarding user identities.
• Decentralized Identity Solutions: Blockchain technology and
decentralized identifiers (DIDs) allow users to manage their own
identities without relying on a central authority, giving them more
control over their personal data.
• Privacy-Enhancing Computation: Technologies such as secure
multi-party computation (MPC) enable parties to jointly compute
a function while keeping their inputs private. This is valuable in
collaborative data analysis.
• Artificial Intelligence for Privacy: AI can help identify and
mitigate privacy risks, automate compliance with data protection
regulations, and improve data anonymization techniques.
Cross border data transfers
• The security of personal data transferred across national borders
has been one of the drivers for international consensus on the
fundamental principles for the protection of personal data.
• However, due to uncertainty regarding data protection standards
in foreign countries, many countries limit extraterritorial transfer
of personal data.
• [Link]
laws
Determining jurisdiction linked to data
protection law
• Location of Data Subjects
Residence: Data protection laws, like the GDPR, often apply based
on the location of the individuals whose data is being processed.
• Location of Data Processing
Physical Location: The jurisdiction may be influenced by where the
data is physically processed or stored. If a company operates
servers in a specific country, that country’s laws may apply.
• Establishment of the Organization
Main Establishment: Organizations with a physical presence (e.g.,
offices, branches) in a jurisdiction typically fall under that jurisdiction’s
data protection laws, even if they process data elsewhere.
• Applicable International Agreements
Treaties and Frameworks: Bilateral or multilateral agreements can
influence jurisdictional aspects, particularly for cross-border data
transfers, and might provide frameworks for mutual recognition of data
protection standards.
• Emerging Trends
As data privacy regulations evolve globally, emerging laws may introduce
new criteria for determining jurisdiction, emphasizing the need for
organizations to stay informed and agile in their compliance strategies.
Future Policy
• User Empowerment and Consent
• Data Minimization
• Technological Advancements
• Public Awareness and Education
• Regulatory Innovation
A Scenario : Alice Buys
a Wearable Device:
An e-commerce transaction followed
by sharing data with a friend or
service provider.
In this scenario, Alice searches the
Web (e.g., Google) for information
on wearable health and fitness
devices and purchases it (e.g., Fitbit)
via an e-commerce website (e.g.,
Amazon). Alice wears her health
and fitness tracker and shares her
data with Bob, her primary care
physician.
A Scenario : Alice Buys a Wearable Device:
Alice does the following:
1. Web Search
2. Purchase
3. Using Fitbit
4. Sharing Data with Bob