Privacy in 2022: A Look Back
Privacy is the right of an individual to be left alone, or the freedom from any interference. It is the right to have control over how an individual’s personal information is collected and used. Most people do not want everybody to know everything about them, hence privacy is helpful to reduce the social friction we encounter. As technology gets more sophisticated and people engage more with institutions/organizations/individuals, more data is being collected and exchanged. With this innovation, privacy is becoming more complex, and this leaves organizations with a complex risk matrix and with an obligation for ensuring that personal information is protected. As a result, protection of privacy has become of the utmost importance.
Change in thinking in privacy from legacy system to a mainstream, modern system
In the early days of computerization, the Chief Information Officer (CIO) had the responsibility of data policies, storage, privacy along with designing of architecture, its constituent servers, personal computers, software, networking, and security systems; this role was so limited since in the early days, computerization was typically based on on-premises computing and data centers.
In the late 1990s, with the advent of the federal, provincial, and sectoral laws such as EU GDPR’s predecessor, being EU Data Protection Directive; Children’s Online Privacy Protection Act, Gramm Leach Bliley Act for financial establishments, Health Insurance Portability and Accountability Act for healthcare establishments, etc.; safeguarding against external and internal threats became of utmost importance. Thus, the next decade, i.e., the early 2000s saw the evolution of cyber security with the advent of intrusion detection and prevention solutions such as antivirus, web-application security, database security, security system management, etc.
The late 2000s saw the rapid adoption of cloud computing services model such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS) coupled with revolution in Internet of Things (IoT) and Bring-Your-Own-Device (BYOD) models, causing a shift in the whole IT landscape impacting cyber security, compliances, and data privacy.
Thus, as discussed, the role of CIO was not limited anymore; the CIOs were now managing data encryption, anonymization, password management along with managing privacy aspects in the world of cloud, mobility and IoT, preventing data from hackers and insider threats, and managing more stringent guidelines related to data, especially sensitive data.
With the adoption of the General Data Protection Regulation (GDPR) in 2018, the legislation has become the baseline for new data protection laws across the globe. Many lawmakers around the world have sought parity with GDPR in hopes that such parity will allow a free data flow between their country and the European market. So, what is the status of privacy during the pandemic, post-pandemic and what does the future entail? Let us look at the same below.
Impact of pandemic on privacy
Digital transformation was already rising in the early 2000s and with the COVID-19, generation of data, its variety and volume has increased rapidly. This is due to the rising volume of attacks appearing from rapid adoption of cloud, IoT devices, IT penetration in automotive, wearables, telecoms, smart cities, utilities, and other verticals. Moreover, the rise of freelancing and remote/hybrid working has also added to the mass of attacks and vulnerabilities.
Many countries where work from home has been adopted, with video conferencing services, malware, ransomware, and the Dark Web; despite advances in cybersecurity measures, cyber-attacks have increased by three times. Some of the notable data breaches and data leakages were the Sunburst SolarWinds attack, the discovery of Facebook and MGM Resorts confidential data on the Dark Web, the resurgence of WannaCry and other ransomware attacks, along with the Mozi BotNet. Besides attacks on customers and critical infrastructures, there have been incidents across the digital supply chain, especially using vulnerabilities such as Log4j.
Aspects investigated by the companies in 2022
The key team of the organization such as the CISOs, legal, risk and governance teams have been working together to categorize the risks and assessments; and estimating cost of breaches and damages, implementing cyber security frameworks and technologies, and crystallizing policies. Technologies such as cybersecurity, artificial intelligence and blockchain mesh architecture are being harnessed by organizations to have a more automated, intelligent, and stringent adherence to regulations.
For multinational organizations, it is of paramount importance for CISOs and leaders to have an in-depth knowledge of country specific data privacy laws, especially those handling sensitive data and employee data. Irrespective of company size, it is critical to have a clear privacy policy explaining to users of data across the extended enterprise as to the type of data collected, its usage and purpose, shareability and security. This should also cover accepting, retention and disabling of cookies. The management teams are working together to balance risk, transparency, stakeholder satisfaction as well as compliance of the organizations. The policies must balance risk, prioritization, breach/damage, compensations, and operational and reporting costs. Some companies have appointed Chief Privacy Officers who are custodians and are responsible to overlook the functions mentioned above as well as to uphold privacy.
In recent years, data privacy has shifted from a mere topic of discussion to a regulatory requirement and a demand from many customers. Businesses can no longer wait for the legislation to align with the privacy regulations and protect consumer data. Instead, they must have a reasonable strategy for managing the privacy risks and complications. 2022 saw a series of shifts in the data privacy landscape, and the momentum of this change is not expected to slow down. So, what will be the new normal in the privacy landscape? Below are some trends.
Trends that have shaped the world of privacy in 2022
1. Intrusive home surveillance:
With the effects of the pandemic, a lot of organizations had to provide their employees with a flexibility of working remotely, also called Work-From-Home (WFH). To ensure that the employees are using their time in an efficient manner and are not abusing the relaxations provided to them, the organizations may have implemented surveillance software’s to ensure the same in this work arrangement. These surveillance and monitoring technologies can be considered intrusive and may breach data privacy requirements. To ensure the protection of the privacy of the employees and access relevant risks potentially faced by the organizations, the Data Protection Officers (DPOs) will need to check this software to ensure that the employees work ethics are aligned with their role while ensuring that employee personal data is not breached.
From the organizations’ perspective, the remote/hybrid working structure has financially benefited the organizations in a lot of ways; therefore, the DPOs along with the business management teams will have to be abreast with the developments in the privacy practices and review WFH policies to align with continued ways of remote/hybrid working.
2. Ongoing data and privacy breaches:
Digitalization, at an extremely fast pace, caused due to pandemic; created many risks and vulnerabilities leading to an increase in breaches. With governments opening borders and supplying more relaxations, pandemic-related tracing activities, such as verification and monitoring of vaccinated individuals, the implementation of vaccinated travel lanes; pose risks to organizations if data is not collected and processed appropriately. Privacy policies of organizations can provide the most insight into the purpose behind the collection and processing of the individual’s data; therefore, it is good practice to make it a habit to read the privacy policy before registering on a website, downloading an app, signing up for a membership, etc.
3. Increase in regulatory fines:
The world is undergoing one of the biggest transformations ever, which is shifting to digitization. But, with the rise of the digital world comes an increase in data privacy laws to protect the large volumes of personal and sensitive personal data and for improving data governance. The regulatory landscape is making it challenging for organizations to follow the specific requirements on time, therefore, 2022 has seen an increase in the frequency and severity of the regulatory fines.
Further, the newer privacy legislations are being implemented with significantly harsher noncompliance fines. The newly enacted Personal Information Protection Law (PIPL) in China penalizes the organizations up to 5% of its annual revenue (compared to the GDPR at 2-4% of annual global turnover) and includes potential criminal penalties. Also, as consumers are being aware of their rights in respect to their data and for protecting their privacy; we have seen an increase in the number of data subject requests and complaints in 2022.
Some notable fines of the 2022 are:
The French data protection authority (the CNIL) has fined Google Ireland with a large fine of €90 Million on 06th January 2022. This fine relates to the way Google’s European entity implements cookie consent procedures on YouTube.
Facebook’s second largest GDPR fine came from the CNIL on 06th January 2022. Meta, then Facebook, earned a €60 Million penalty owing to not obtaining proper cookie consent from its users.
On January 19th, 2022, the Italian data protection authority (the Garante) publicized its decision to fine Enel Energia €26.5 Million for a range of GDPR violations including not getting user consent or inform customers before using their personal data for telemarketing calls.
Garante, on 10th February 2022, fined Clearview AI with a fine of €20 Million it heard and decided after several issues in connection with Clearview’s facial recognition products.
On 15th March 2022, the Irish Data Protection Commission (DPC) fined Meta Platforms in Ireland, a €17 Million for issues which meant it could not readily prove the security measures that it implemented to protect EU users’ data. This was spotted in 2018 after twelve personal data breaches were reported to the DPC.
The Spanish data protection authority (AEPD) published on 18th May 2022, its decision in which it imposed a fine of €10 million on Google LLC for the violation of Articles 6 and 17 of the GDPR, following two complaints and later, investigation from the AEPD.
Conclusion
The digital transformation of business operations and individuals’ habits is escalating the amount of data collected and processed. To effectively follow the ever-evolving privacy landscape; the laws and regulations are very soon catching-up with the technology and the organizations should keep an eye on the latest enforcement actions, interpret the legislations and incorporate the privacy and security best practices.
There is an essential need to rethink the data-driven competitive advantages. The legislations, now, does not leave any room for ambiguity around “whether” data compliance trends will coincide with strict regulations or not. Rather, it is only a question of “when” it will intersect.
The trend of 2022 clarifies that the privacy programs can evolve beyond compliance and risk management to build trusted customer relationships worldwide. With this vision, privacy professionals should be striving to build privacy by default, support data lifecycle, inform individuals of their rights and be transparent of how to manage and govern data, to use automation in their favor.
