The Problem With Privacy

Brand … Trust … Digital risk … Values … Ethics …?The right to be let alone …?The “creepy” factor …?Notice and choice …?Fundamental human right …

?These and other terms inevitably come up in just about any conversation about data privacy. For companies, though, these terms are often challenging. It isn’t that they are unimportant, but rather that their importance isn’t always put in the?proper?context so that companies can?actually understand and take appropriate action?with respect to data.

?From a business perspective, there are two key problems with privacy. First, it is “underinclusive.” As a concept?rooted in?individual rights (usually enforced by data subjects and data protection regulators), privacy fails to contemplate, let alone address, the broader point that data (both personal and nonpersonal) is what fuels the predominant line of communication in our world today.

?The second problem with privacy is the widely held perception that it isn’t directly relevant to the primary purpose of a corporation. Most corporate executive see privacy as offering a branding, marketing, and/or ESG benefit, not as something that, in and of itself, returns value to shareholders.

?To address these problems, and the growing centrality of data to our global economy, we need a new concept for describing how companies should govern their data practices. That concept is “data sustainability.”

?Whereas the vast majority of companies today focus on compliance with privacy laws, data sustainability also addresses the other three pillars of corporate governance—business strategy, operational viability, and financial performance. In particular, data sustainability would help to prevent, mitigate, and eliminate “unsustainable” data practices that could threaten the company’s resilience and continuity.

?Unsustainable data practices could include any number of issues that may not be illegal, but could nevertheless disrupt a company’s access to critical data. An example might be “creepy” data collection that, while lawful, may not be well received by data subjects, regulators,?policymakers,?the media, or other key stakeholders, and might include non-legal consequences to the company or its executives (e.g., reputational damage, congressional hearings, or other crises that compel the company to stop the practice in question, even before being legally compelled to do so). Another instance might be legally compliant cybersecurity practices that nonetheless result in data breaches, wherein essential data becomes unavailable to a company due to third party activity.

?To be clear, data sustainability is not about ignoring the legal ramifications of processing personal information. It is, in fact, quite the opposite. One need only look at some of the consequences of regulatory enforcement actions to?appreciate that the legal risks in many cases are actually operational resiliency risks.

In the U.S., for example, the Federal Trade Commission cannot obtain civil penalties for fist-time violations and instead relies on consent decrees that can compel companies to delete data, restrict conduct, and in some cases disgorge proprietary algorithms. In the EU, moreover, while GDPR-related fines are always a potential risk, the most pressing issue today is the potential suspension of cross-border data transfers and a possible “data blackout.” All of?these consequences have greater operational resiliency impacts than legal ones.

?Future articles will help to define data sustainability further, but the chief takeaway here is that the concept is meant to encompass more than the legal consequences of using personal data—specifically, the operational risks and benefits of such data use. Data sustainability certainly includes the concept of privacy, but it doesn’t stop there.?In?short, it acknowledges the reality that companies in every industry now face. Having?a road on which nothing can move due to a lack of fuel is effectively the same as having no road at all.

Rebecca Davis

Privacy and Technology Lawyer

2 å¹´

Thank you for such a thoughtful article. I’d like to suggest that perhaps the concept of sustainability is much broader than what you present here. You state that data sustainability enables companies to manage data in support of company strategy, operational viability, and financial performance in order to drive company resilience and continuity. However, resilience applies to a single entity and sustainability is other-directed. ?A resilient company engages in practices that enable it to survive. ?A company that engages in sustainable practices supports the survival, even flourishing, of society and the planet, as well as of itself. Therefore, a company that engages in sustainable data practices does not stop at mitigating its own reputational, compliance, and operational risks. It also works to mitigate harms to individuals (and society as a whole) resulting from loss or exploitation of privacy, including loss of freedom of expression and autonomy, discrimination, and the commodification of individuals into data sources. And it works to mitigate harms to the planet that result from the massive energy consumption, exploitation of rare earth minerals, and generation of hazardous waste that accompany data processing [comment 1/2]

Michael H. Cox, CIPP/US

SMB Data Mapping, Governance, Privacy and Security Consulting Experts - Assessments, Policies, Retainer - HIPAA Privacy/Security, ISO 27001-02:2022, CIS Controls v8 - Mentoring, Coaching

2 å¹´

Love the "sustainable data" concept which fits within a defensible and sustainable privacy and security program!

The problem with privacy is that regulations and contract clauses are ineffective if software does not implement the practices! When does it cross the line to fraud when companies publish privacy policies that they nknow they can’t/don’t VCs.

Christine Axsmith

Cyberstalking, Privacy, AI Policy Writer, with a little Royal Gossip

2 å¹´

With increasingly severe weather events, it is conceivable that small and medium-sized business could fail because of a lack of data sustainability. Have you read Resilience: A New Tool in the Risk Governance Toolbox for Emerging Technologiesby Gary E. Marchant & Yvonne A. Stevens?

要查看或添加评论,请登录

Andrew Serwin的更多文章

  • Cybersecurity and the Hybrid World

    Cybersecurity and the Hybrid World

    Having just examined privacy and data and shown that how we look at “privacy” isn’t perhaps the best way, I will not…

    1 条评论
  • Value and Data

    Value and Data

    Picking up on the last post regarding value, risk and data, it is helpful to again return to the types of data that…

  • Defining Value and Risk in Corporate Governance, and the Limits on Privacy

    Defining Value and Risk in Corporate Governance, and the Limits on Privacy

    As we continue to explore new strategies for governance around data and cyber, it is helpful to return to our corporate…

    1 条评论
  • Data Sustainability

    Data Sustainability

    Having taken what seems like a detour down the path of “primary purpose” after having identified the problems with…

    1 条评论
  • Mission Statements, Strategy, Values and Ethics--How They Relate to Governance, Data and Connectivity.

    Mission Statements, Strategy, Values and Ethics--How They Relate to Governance, Data and Connectivity.

    Corporations and other entities frequently create mission statements, values, or other similar statements regarding the…

    2 条评论
  • Boards and Risk

    Boards and Risk

    Lawyers love writing about talking to the Board about privacy and cyber, and I could add yet another article to that…

    6 条评论
  • The Hybrid World

    The Hybrid World

    “born from the ashes of a world at war…..

    6 条评论
  • Applying Corporate Governance

    Applying Corporate Governance

    In my last article, I covered corporate governance and defined what it was, and most importantly what it was “keyed”…

    3 条评论
  • Corporate Governance

    Corporate Governance

    The first step in our journey was to define governance, which is summarized by the process below, where a direction for…

    2 条评论
  • Defining Governance

    Defining Governance

    Governance is perhaps one of the most often used, but misunderstood, concepts by business people and compliance…

    5 条评论

社区洞察

其他会员也浏览了