How Should Organizations Manage Privacy Risk?

313 views
•
August 28, 2013
by
RSAC Cybersecurity
YouTube video player
How Should Organizations Manage Privacy Risk?

TL;DR

Organizations should treat privacy as both a risk-management priority and a source of value in the information economy. Effective programs must account for government surveillance concerns, complex mobile data ecosystems, changing standards, and the behavioral effects of observation, while replacing impractical notices with intuitive, timely controls connected to specific data uses.

Transcript

Well, hello everyone, and thank you for this opportunity to chat with you about privacy. My name is Trevor Hughes, and I am the president and CEO of the International Association of Privacy Professionals, the IAPP. The IAPP is a not-for-profit professional association, and we represent all the people in the world who work in the burgeoning field of... Read More

Key Insights

  • Privacy is a responsibility shared by many professionals who handle data strategically, not only chief privacy officers and privacy lawyers. Its growing importance reflects its role in consumer protection, citizen protection, marketplace activity, organizational risk, and the development of information-based business models.
  • Privacy is difficult to describe through a single word because it spans business, technology, law, public policy, security, and individual freedom. The presentation uses art to make these challenging relationships more evocative and to illustrate tensions that conventional professional language may not communicate as effectively.
  • Government surveillance is a privacy issue because security-driven data collection can include information about individuals inside and outside the United States. Collection involving American citizens raises constitutional concerns and intensifies debate about where the boundary between state interests and individual rights should be drawn.
  • Observation changes behavior, which makes surveillance relevant to freedom and autonomy rather than merely data handling. When people know or believe they are being observed, they act differently, supporting the presentation's conclusion that information creates power and observation can function as control.
  • The security and privacy debate affects organizations through government data requests and customer concerns about information sharing. Companies may need to address subpoena requests from FISA courts while also explaining whether, when, and how customer data may be shared with governments around the world.
  • Mobile devices are central points in the data ecosystem because technology, information, and services converge within devices that accompany users continuously. Public policy organizations consequently view mobile platforms as important places to establish controls and develop privacy standards.
  • The mobile privacy ecosystem includes hardware providers, carriers, platform providers, and application providers, each potentially connected to significant data flows. A single device may contain dozens or hundreds of applications, creating a complicated network of actors within a technologically limited communication channel.
  • Long privacy notices are poorly suited to small mobile screens and may be ineffective for communicating current data practices. Better mobile privacy mechanisms should be intuitive, short-form, just in time, and directly related to the particular data function occurring when the information is requested or used.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why should organizations treat privacy as a strategic issue?

Organizations should treat privacy strategically because many employees and professionals deal with data in ways that affect consumers, citizens, and markets. Privacy is no longer limited to chief privacy officers or privacy lawyers. It also shapes organizational risk, customer concerns, information-based business models, technology development, and the ability to create value from the information economy while maintaining appropriate protections.

Q: How does government surveillance create privacy concerns?

Government surveillance creates privacy concerns when security programs gather large amounts of information about people inside and outside the United States. The collection may knowingly or unknowingly include data about American citizens, raising constitutional questions. It also forces society to decide where state security interests should end and individual privacy, autonomy, and freedom should begin.

Q: Why does observation change the privacy debate?

Observation matters because it changes how people behave. The presentation identifies this principle as fundamental to privacy and uses it to connect surveillance with power, control, freedom, and self-determination. If being watched causes individuals to act differently, data collection is not merely passive recordkeeping. It can influence choices and challenge whether people are acting autonomously or responding to external pressure.

Q: How can surveillance debates affect private organizations?

Surveillance debates can affect organizations through legal requests for information and through customer concern about government access to data. The presentation specifically identifies subpoena requests coming from FISA courts and questions about whether customer information may be shared with governments around the world. These pressures can influence privacy practices, risk management, customer communication, and organizational responses to changing public policy.

Q: Why are mobile devices a major privacy concern?

Mobile devices are a major privacy concern because they bring technology, data, and services together in a small device that travels with the user. This creates a central point in the user's data universe and attracts attention from public policy organizations. The device also connects many actors, making accountability and meaningful communication about information practices unusually complicated.

Q: Who can access or process data in a mobile ecosystem?

A mobile ecosystem can involve the hardware provider, the carrier, the platform provider, and many application providers. Hardware companies may connect to data flowing through the device, while carriers and platform providers can see enormous amounts of information. A user may also install dozens or hundreds of applications, and any of them may seek device data at a particular time.

Q: Why are traditional privacy notices ineffective on mobile phones?

Traditional privacy notices are ineffective on mobile phones because small screens provide a limited channel for communicating long and complex explanations. A lengthy notice is difficult to read on a mobile device, even for someone willing to read it. The mismatch between the amount of information disclosed and the available screen space makes conventional notice-based privacy approaches inefficient or ineffective.

Q: How should mobile privacy controls be designed?

Mobile privacy controls should be intuitive, concise, timely, and connected to the specific data activity taking place. The presentation points toward short-form and just-in-time mechanisms rather than lengthy general notices. A control or explanation should appear in relation to the data function being conducted at that moment, helping users understand the immediate request within the constraints of a small screen.

Summary & Key Takeaways

  • Privacy has expanded beyond the responsibilities of chief privacy officers and lawyers because many people now handle data strategically. Organizations must understand it as a consumer protection, citizen protection, and marketplace issue, then monitor changing laws, regulations, self-regulatory programs, technologies, and risks that influence emerging privacy standards.

  • Government surveillance highlights the difficult boundary between state security interests and individual privacy. The presentation argues that observation changes behavior, making information a form of power and observation a form of control. Surveillance therefore raises questions about autonomy, constitutional concerns, customer trust, government data access, and fundamental freedom.

  • Mobile devices concentrate technologies, services, and personal data within a small interface. Hardware companies, carriers, platform providers, and numerous application providers may participate in this ecosystem. Because lengthy privacy notices work poorly on small screens, emerging approaches emphasize intuitive, short-form, just-in-time controls tied directly to the current data function.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚