Privacy and Security: What’s the Difference? | Impact Makers

Privacy and Security: What’s the Difference?

Article Summary:

Data Deja Vu

There is without a doubt a close link between privacy and security and the two words are frequently used synonymously. While there is often a common parallel goal between the two, the business perspective of privacy and security are very different.

When thinking about the collection of sensitive information and personal data, data security can be defined as the method of safeguarding personally identifiable information against unwanted or unauthorized access. An organization’s ultimate challenge when dealing with security is to keep the data available to the business while maintaining confidentiality, integrity, and availability. Data privacy is how that same private data is used and to ensure that it is appropriately handled. Ideally, organizations should only collect data that they need and only for specific purposes.

The relationship between the two is often explained with the adage: “you can’t have privacy without security, but you can have security without privacy.” This is best illustrated by thinking about the two together – security controls are put in place to control who can access the information and privacy controls for when and what they can access.

Recent History of Data Collection Controversies

It seems like everything we use today in our daily routine collects some amount of personal data. Although most of this data may seem harmless and most of it is given willingly by the user, the same data used to program your smart home could also be collected and tracked to provide a very intimate personal picture of an individual’s routines – how often you are home or away, purchases, health habits, and obviously where you live and who you live with.

As data collection has increased so have the scandals, leaks, and breaches. The world was introduced first hand to one of the largest data collection programs, on a scale previously thought to be unimaginable, in 2013 when Edward Snowden blew the whistle on the National Security Agency’s massive surveillance program. Collecting phone records, emails and texts from hundreds of millions of people (domestic and foreign) the NSA laid the framework of how widespread adoption of technology could be leveraged for the collection of data.

While companies and individuals began changing their practices to protect their data, through increased encryption, the issue of data security and privacy has been brought more and more to the forefront. One of the more recent events, and maybe one of the most memorable to date given the recent presidential election, Facebook has been accused of lax security around privacy of its users’ data. Although Facebook’s officially stated it was not a data breach, the security and privacy measures around user data led to an alleged illegal data mining of personal information of as many 87 million users. This data was then acquired by Cambridge Analytica, political affiliates of the Trump campaign that were hired during the 2017 presidential election campaign.

All of this comes on the heels of the European Union’s (EU) new privacy law, called the General Data Protection Regulation (GDPR), which goes into effect May 25th, 2018. The new regulation will seek to strengthen and unify data protection for individuals within the EU by prohibiting companies from forcing consumers to give up their data as a term and condition of using their service.

As Facebook continues its effort to comply with GDPR partly by asking users to agree to being shown targeted ads, the debate remains on what companies really need to know (i.e., your recently visited websites) and what constitutes consent.

Debates such as these will only continue once GDPR goes into effect as advocacy groups will be able to issue collective complaints, such as class action lawsuits to regulators and national courts.