enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Colliers

Is your privacy worth protection?

Tamer Nagy, Global Director of GRC, Colliers

Imagine yourself building a home with no windows so you can protect what matters inside the house, or digging a tunnel from your home to your work and every destination you and your family might head, so no one in the neighborhood can recognize your faces and harm the family. Furthermore, to add an extra layer of protection to get unrecognized, you recommended your family wear a mask while in the tunnels. It is impossible and unpractical. You cannot live isolated. You need to get fresh air into the house and see the skies. You must get your face recognized, but at what cost?

We are living in an era when receiving, processing, and storing data are essential mandates in every aspect of our lives. It is essential to receive services like healthcare, banking, purchasing, etc. That means you will expose part of your personal data to the caregiver, whether it is a government agency or a private entity, so you can get the service you need. You must be identified and recognized.

The argument is not about whether sharing our personal data with others is the right thing to do or not! It is about who we should share this data with. Why should we share it? Are we sharing it willingly? For what purpose will it be processed? And how will it be protected?

Over the years, public organizations and governments have tried to find answers to those questions to provide the public with the assurance that their valuable data will remain private and protected. The first form of privacy emerged in 1789 with the introduction of the "Bill of Rights," which includes the fourth amendment: the right of the people to be secure in their persons, houses, papers, and effects against unreasonable searches and seizures." In the last 30 years, the Organization for Economic Co-Operation and Development (OECD) has played an important role in shaping the principles of privacy globally. The OECD guidelines govern the right to privacy and transborder data flows. Over the years, the guidelines became the basis for many privacy laws and regulations. In Canada, the OECD’s principles were incorporated into the Personal Information Protection and Electronic Documents Act. In the EU, the principles were the core of Directive 95/46/EC of the European Parliament and of the Council of October 24, 1995, on the protection of individuals with regard to the processing of personal data and on the free movement of such data, which was followed by the EU General Data Protection Regulation in 2018.

"Our personal data is part of who we are and is worth every effort we exhaust to protect it "

The OECD introduced eight privacy principles to govern the collection and processing of personal data and give data owners the right to control their own data. (1) collection limitation, (2) data quality, (3) purpose specification, (4) use limitation, (5) security safeguards, (6) openness, (7) individual participation, and (8) accountability

The OECD articulates that the purpose of collecting personal data must be clear and unambiguous, and the collection of data must be limited to and used only for that announced purpose. The collected data must be accurate and up-to-date. The collector must specify why the data is collected and how it will be used. Above all of that, the collector must ensure that the data is secured at all times and that the data owner has access to and control over it.

In the last few years, cyberattacks against identities have increased exponentially. In 2021, the Federal Trade Commission in the USA has received 2.8 million fraud reports from consumers. The FTC reported that "the reported fraud losses increased more than 70 percent over 2020 to more than $5.8 billion."

Our personal data is part of who we are and is worth every effort we exhaust to protect it. We must be careful about who we share our personal data with. If we must share it, we should read the collector's advertised privacy policy or notices to understand the purpose of the collection, what data will be collected, how it will be used, and how it will be protected.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief