Do Not Track

Privacy by Design Awards 2024

Retrieved on: 
вторник, мая 28, 2024

Published 3 May 2024

Key Points: 


Published 3 May 2024
Read the keynote address prepared for delivery by Privacy Commissioner Carly Kind for the CyberCX and Tech Council of Australia Privacy by Design Awards on Thursday 2 May 2024.

Introduction

  • It was so clear to me that he has a real, personal connection to this issue, which I also am a passionate advocate for.
  • And I’m so honoured to have the opportunity to address you on the occasion of the Privacy by Design Awards.
  • That even as we, as individuals and communities, are shaped by technology, we also have the power to shape technology.
  • I’d then like to share a few brief thoughts on what’s next when it comes to privacy and power.

The lifecycle of privacy by design


True privacy by design isn’t about a single feature or gimmick. In the words of the European Data Protection Supervisor, privacy by design has ‘a visionary and ethical dimension’.
It’s about ensuring privacy is at the forefront of the entire design lifecycle. It is not a piecemeal approach but one that encompasses legal, governance and societal responsibilities.
So, what does this look like in practice?

Privacy by design begins with leadership

  • As with everything in business, privacy by design begins with leadership.
  • Organisations should be making the case for privacy from the get-go, and they should be doing that in the C-suite.
  • As our Australian Community Attitudes to Privacy Survey has shown, consumers place a high value on privacy when choosing a product or service, with it ranking only after quality and price.

Think about privacy from the start

  • You need to think about privacy right from the start, right from your first meeting.
  • Think about whether the community would consider what you’re intending to do as fair and reasonable.
  • Don’t be the guys who are just preoccupied with whether you
    can, think first about whether you should.
  • This is a fundamental shift in approach, and provides confidence that, like a safety standard, privacy is built into products and services from start.

Build consideration of privacy into research and design

  • As we move through the product lifecycle, organisations should be building in consideration of privacy into their user research, and throughout the research and design phase.
  • We know that when individuals have the chance to exercise agency around their privacy, they often will.
  • Proposed changes to the Privacy Act will seek to address the clarity of collection notices and consent requests, to improve consumer comprehension.

Carry privacy into deployment

  • Privacy should then be carried right through from research and design, to deployment.
  • Encryption, at rest and in transit, is one part of the puzzle when it comes to reasonable steps to protect the privacy and security of personal information.
  • Services and products that involve the collection of personal identity information can create serious privacy risks and harms.
  • The OAIC will be the independent privacy regulator for the scheme and will enforce its privacy safeguards.

Continuous improvement and monitoring is essential

  • Finally, then, what does privacy by design mean once your product has gone to market?
  • If you have done all of the above, then you can be congratulated for engaging in best practice privacy.
  • But continuous improvement and monitoring is essential.

Conclusion

Brace for Pressure: DataGrail Reports Worldwide Surge in Data Privacy Requests

Retrieved on: 
среда, мая 1, 2024

SAN FRANCISCO, May 1, 2024 /PRNewswire/ -- Ahead of the RSA conference, DataGrail (Booth #243), a leader in data privacy, released its 2024 Data Privacy Trends Report, which illustrates consumers' growing desire to take control over their data and helps businesses understand what to expect amid the rising demands. The findings reveal that Data Subject Requests (DSRs) — formal requests made to a company by a person to access, delete or request not to sell/share the personal data that the company holds on them — increased by 32% from 2022 to 2023. Data deletion requests were the most common type of DSR, on average accounting for more than 40% of requests across businesses.

Key Points: 
  • Data deletion requests were the most common type of DSR, on average accounting for more than 40% of requests across businesses.
  • 2023 saw a 246% increase in the total volume of data privacy requests compared to 2021.
  • While privacy laws have emerged in some states and regions, data privacy requests come from virtually everywhere.
  • DataGrail's research suggests that 75% of websites ignore GPC requests, which means most businesses are not respecting people's privacy requests.

GuidePoint Security Helps Organizations Address Data Privacy Requirements with Portfolio of Services

Retrieved on: 
четверг, марта 21, 2024

GuidePoint Security , a cybersecurity solutions leader enabling organizations to make smarter decisions and minimize risk, today announced the availability of its Data Privacy services, which are designed to help customers take control of their privacy operations.

Key Points: 
  • GuidePoint Security , a cybersecurity solutions leader enabling organizations to make smarter decisions and minimize risk, today announced the availability of its Data Privacy services, which are designed to help customers take control of their privacy operations.
  • These new data privacy laws will require companies to be accountable and to evaluate and ensure data protection addendums in their processes.
  • GuidePoint’s Data Privacy Services are tailored to meet an organization and its data privacy program at its current maturity level.
  • “We have developed a broad portfolio of data privacy services to meet a customer at their current maturity level,” said Scott Griswold, Practice Director - Governance Services, GuidePoint Security.

Colorado’s Approval of Global Privacy Control: Implications for Advertisers and Publishers

Retrieved on: 
среда, февраля 14, 2024

The privacy laws of both Colorado and California require organizations to recognize Universal Opt-Out Mechanisms (UOOMs), a tool through which a person can invoke their opt out rights broadly across all the websites they visit. While California has required responding to certain UOOMs since July 2021, the Colorado Attorney General has only recently approved their [?]

Key Points: 


The privacy laws of both Colorado and California require organizations to recognize Universal Opt-Out Mechanisms (UOOMs), a tool through which a person can invoke their opt out rights broadly across all the websites they visit. While California has required responding to certain UOOMs since July 2021, the Colorado Attorney General has only recently approved their [?]

OPTOUTCODE, PRIVACY4CARS' NEW UNIVERSAL OPT OUT MECHANISM, SHORTLISTED BY COLORADO AS A LEGALLY BINDING WAY FOR CONSUMERS TO OPT OUT OF DATA SALE AND TARGETING IN MONUMENTAL CONCEPT REVEAL

Retrieved on: 
вторник, декабря 12, 2023

ATLANTA, Dec. 12, 2023 /PRNewswire/ -- Privacy4Cars, a privacy-tech company focused on solving privacy challenges posed by vehicles, recently made the Colorado Department of Law shortlist with OptOutCode, a new Universal Opt-Out Mechanism. The radical concept, which simply relies on a consumer renaming their devices (e.g. smartphones, tablets, laptops, and routers) by adding "0$S" as the first three characters in their name had already garnered the official support of Electronic Frontier Foundation and Surveillance Technology Oversight Project. It has now been added to the Colorado Attorney General's Universal Opt-Out Shortlist. If accepted after a final review of public comments, OptOutCode would have to be recognized as an opt-out mechanism by data collectors, data brokers, and the AdTech industry, giving Colorado consumers the easiest and broadest way to not be targeted and minimize their data footprint. Companies failing to detect and treat the signal as a valid request would be in violation of the Colorado Privacy Act starting July 2024. Approval by Colorado may lead to OptOutCode becoming legally binding in California, as well (where opt-out regulation is already in effect), along with other states currently pending similar legislation for 2025 including Connecticut, Texas and Montana, and many more states in the future.

Key Points: 
  • It has now been added to the Colorado Attorney General's Universal Opt-Out Shortlist.
  • Companies failing to detect and treat the signal as a valid request would be in violation of the Colorado Privacy Act starting July 2024.
  • We're elated that the Colorado Department of Law has shortlisted OptOutCode for its public list, and hope more states will recognize OptOutCode.
  • For more information, or to learn more about the concept and its supporting organizations, please visit: https://optoutcode.com .

Peter Swire, Global Data Privacy Pioneer, Joins Privya's Advisory Board

Retrieved on: 
среда, ноября 30, 2022

TEL AVIV, Israel, Nov. 30, 2022 /PRNewswire/ -- Privya, which enables companies to build data protection and compliance into the lifecycle of their products, has announced that Professor Peter Swire, a world-renowned leader in privacy and cyberlaw since the 1990s, has joined its executive advisory board.

Key Points: 
  • Privya's AI-based technology identifies and maps data protection issues and potential violations early in the development process, ensuring that improper data handling practices are fixed before digital products are deployed.
  • The platform suggests actionable measures to remedy new and existing issues in order to avoid violating data privacy regulations, such as GDPR, HIPAA, CCPA and CPRA.
  • "Peter is one of the world's top leaders in the fields of health and data privacy regulations.
  • Privya bridges the gap between privacy professionals and engineers, and provides a centralized hub to manage and control privacy across cloud-native environments.

2022 Outlook on Privacy & Data Security from Bloomberg Law Delivers Guidance on Global and Domestic Regulatory Developments

Retrieved on: 
среда, февраля 2, 2022

ARLINGTON, Va., Feb. 2, 2022 /PRNewswire/ --Bloomberg Law announced today the publication of its2022 Outlook on Privacy & Data Security, which provides a detailed review of key activity in recent months and anticipated developments for the global and domestic regulatory landscape.

Key Points: 
  • ARLINGTON, Va., Feb. 2, 2022 /PRNewswire/ --Bloomberg Law announced today the publication of its2022 Outlook on Privacy & Data Security, which provides a detailed review of key activity in recent months and anticipated developments for the global and domestic regulatory landscape.
  • The 2022 Outlook on Privacy & Data Security includes:
    A collection of articlesfrom Bloomberg Law's news desk on the outcome of new state privacy legislation, the latest on ransomware attacks, the challenge for social media platforms in verifying age without violating privacy, the growing popularity of Global Privacy Control (GPC), Congress's debate over a national privacy law, and regulatory activity around facial recognition systems.
  • "Privacy and data security issues continue to play a central role in the global and domestic legal landscape," said Joe Breda, President, Bloomberg Law.
  • "Bloomberg Law provides distinct resources to privacy and data security practitioners to navigate complex regulatory and compliance initiatives as part of our integrated platform."

Startpage's Privacy Protection Browser Extension Gives Consumers Control Over Online Data Collection and Tracking

Retrieved on: 
вторник, января 18, 2022

LOS ANGELES, Jan. 18, 2022 /PRNewswire/ -- Startpage , a search engine that lets anyone search online without personal data collection, tracking, or targeting, today unveiled the Startpage Privacy Protection browser extension.

Key Points: 
  • LOS ANGELES, Jan. 18, 2022 /PRNewswire/ -- Startpage , a search engine that lets anyone search online without personal data collection, tracking, or targeting, today unveiled the Startpage Privacy Protection browser extension.
  • The Startpage Privacy Protection browser extension blocks these trackers and shields users from invasive targeted advertising with easy-to-use features that provide anyone with more control over their online privacy, including:
    Sends "Global Privacy Control" Signals: The extension sends Global Privacy Control (Do-Not-Track) signals to visited sites with your privacy preferences.
  • Blocks "Data Collection": The extension prohibits third-party sites from using special scripts to collect information about you.
  • "True Score" Privacy Ranking: The extension evaluates and displays a 1-5 privacy rating based on each site's privacy practices.

DeleteMe Releases Privacy Predictions for 2022

Retrieved on: 
пятница, января 7, 2022

Tech platforms made significant changes to how they (at least superficially) address consumer privacy concerns, and the government explored new approaches for privacy regulation of big tech, driving rapid growth in legislation at the state level and internationally.

Key Points: 
  • Tech platforms made significant changes to how they (at least superficially) address consumer privacy concerns, and the government explored new approaches for privacy regulation of big tech, driving rapid growth in legislation at the state level and internationally.
  • With all these different issues still in play, DeleteMe offers the following privacy predictions for 2022:
    PII Exploitation Will Continue to Get More Sophisticated.
  • DeleteMe is the leading online privacy personal information removal service.
  • In business for over 10 years, DeleteMe's privacy advisors have successfully completed over 25 million opt-outs from data brokers, ensuring consumers and businesses' online privacy.