How to Align Data Privacy and Security Practices

187 views
•
February 16, 2017
by
RSAC Cybersecurity
YouTube video player
How to Align Data Privacy and Security Practices

TL;DR

Treat privacy as a strategic business issue by identifying how personal data is collected, used, shared, safeguarded, and disposed of, then translating those requirements into precise security controls. Strong privacy practices can protect brand trust, support digital transformation, and improve board oversight, especially as valuable data becomes more pervasive, porous, and widely shared.

Transcript

Good morning, everyone, and thanks for joining me. So today we're going to take a little tour, and I'm going to share with you my top tips for protecting privacy and keeping pirates away from your treasure. So we're going to start with a question. What's the difference between privacy and piracy? Anybody? It's just two letters switched around. I wa... Read More

Key Insights

  • Privacy is a strategic business issue because data is more valuable, more widely shared, and central to digital transformation. Organizations must manage not only security controls but also how information is collected, profiled, used, disclosed, retained, and ultimately disposed of.
  • Privacy is broader than security because it concerns the purposes and rules governing personal information. It includes accuracy, appropriate safeguards, limited access, individual choices, permitted sharing, and disposal, while security supplies the practical methods used to enforce those requirements.
  • Consumer trust is influenced by both brand reputation and visible technology. The cited longitudinal study associated one third of consumer trust with either confidence in a company’s brand or trust in observed protections such as biometrics, fingerprint detection, and transparency about data sharing.
  • Privacy is increasingly relevant to purchasing decisions. According to the study presented, 54% of consumers said privacy affected a purchase decision in 2011, while 82% said the same in 2015, indicating a substantial increase in consumer attention to organizational data practices.
  • Privacy policies are rarely read even though they may disclose extensive data sharing. The presentation reports that only 3% of consumers read these policies, creating a gap between formal notice and meaningful awareness of how organizations may handle or distribute personal information.
  • Data breaches are board-level concerns because accountability extends beyond technical security leaders. The presentation states that boards and chief executives receive blame after breaches, while the CISO ranks fourth, making frequent privacy and security reporting important for organizational oversight.
  • Strong governance includes frequent engagement with leadership. According to the presenter’s client experience, organizations performing well discuss privacy and security with the board or an appropriate committee once a month, rather than limiting those conversations to quarterly or semiannual updates.
  • Effective collaboration requires privacy and security professionals to translate between legal language and technical logic. Privacy rules can be dense, nuanced, and open to interpretation, while technology teams need crisp if-then decision points that can be converted into workable controls.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is the difference between data privacy and data security?

Data privacy defines why personal information is handled and what rules should govern that handling. It covers accuracy, safeguards, appropriate access limitations, individual choices, sharing, use, and disposal. Data security is the how: it provides controls that implement those privacy requirements. Privacy therefore reaches beyond protection against unauthorized access and addresses the complete way an organization manages information.

Q: Why should companies treat privacy as a strategic business issue?

Companies should treat privacy strategically because data has become more valuable, more pervasive, more porous, and more widely shared. It also sits at the center of digital transformation. Poor handling can harm customer trust and brand reputation, while responsible practices can support market success. Privacy and security therefore represent investments in the business, rather than merely compliance obligations.

Q: How does privacy affect consumer purchasing decisions?

Privacy can directly influence whether consumers trust and buy from a company. The presentation cites a five-year longitudinal study in which 54% of consumers said privacy affected a purchase decision in 2011, rising to 82% in 2015. The findings suggest that consumers became substantially more mindful of organizational reputation, visible safeguards, and transparency about personal data sharing.

Q: Why do consumers trust companies with personal information?

Consumers may trust companies because of brand reputation, confidence in visible technology, or resignation that no organization is perfect. The study discussed in the presentation attributes one third of the relevant trust responses to brand or observed technology. Examples of observable protection include fingerprint detection, biometrics, other security controls, and transparency about the information being shared.

Q: Why is reading a privacy notice important?

Reading a privacy notice can reveal how extensively an organization collects and shares personal information. The presentation reports that only 3% of consumers read such policies, even though the disclosed level of data sharing may be surprising. A notice is the outward-facing expression of privacy, so examining it helps a person understand stated practices before accepting them.

Q: How can privacy and security teams work together effectively?

Privacy and security teams can collaborate by learning each other’s terminology and preferred ways of expressing requirements. Security professionals should understand concepts such as data subject, data processor, and data controller. Privacy professionals should translate nuanced legal interpretations into clear decision points, such as whether a particular email must be encrypted, so technology teams can implement consistent controls.

Q: What should boards know about privacy and data breaches?

Boards should recognize that privacy and security failures create leadership and brand risks, not merely technical problems. The presentation says that the board and chief executive receive blame after a breach, while the CISO is fourth on the list. The presenter’s stronger-performing clients discuss these matters with a board or committee monthly, rather than quarterly or semiannually.

Q: How should organizations turn privacy rules into security controls?

Organizations should interpret privacy requirements and convert them into specific, testable decisions. Legal and regulatory language can be lengthy, dense, gray, and open to interpretation, whereas technology teams typically need black-and-white logic. A practical control can use an if-then structure, such as determining whether email is being sent and, if so, whether encryption is required.

Summary & Key Takeaways

  • Privacy has become a strategic concern because personal data is increasingly valuable, widely distributed, and central to digital transformation. Organizations must understand how information is collected, profiled, used, shared, protected, and disposed of. A breach can damage customer relationships, brand reputation, and confidence in the organization’s ability to manage sensitive information.

  • Consumer trust depends partly on an organization’s privacy reputation and the security technologies people can observe. The cited study found that privacy influenced purchasing decisions for 54% of consumers in 2011 and 82% in 2015. Yet only 3% reportedly read privacy policies, despite potentially extensive disclosures about data sharing practices.

  • Privacy and security teams must learn each other’s language to collaborate effectively. Privacy professionals often interpret dense legal requirements and concepts such as data subjects, controllers, and processors. Technology professionals need those interpretations converted into clear decision points and controls. Privacy defines why and what should happen, while security determines how protections are implemented.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚