Data Privacy in the Cloud – Whose Data is it Anyway? – Cloud Technology Partners

Last year was another banner year for security breaches, sad but true. At times it felt like a week did not go by without the announcement of another large corporate security breach (that usually happened sometime in the past) and the personal information of millions of people was potentially at risk. One breach in particular stands out to me. The Equifax breach that occurred last September. Approximately 145 million individuals’ personal information had potentially been acquired by the hackers.
The reason this one stands out is not due to the size, or that is was a company that sells services to protect your personal information (though that is ironic). What makes it stands out was the testimony of the interim CEO, Paulino do Rego Barros. Barros testified that ‘consumers do not have a say in opting in or out of the company’s data collection’.
Several senators responded incredulously to that assertion. There was much discussion about the need for more legislation requiring companies to better protect consumer data. This incident and discussion is a great example of the challenges facing us in our new world of constant technology disruption. New uses, devices and the data that is being collected are appearing at breakneck speeds. Sometimes before we even understand the implications and tradeoffs involved.
The European Union is working very hard to get ahead of the curve on the privacy challenges. The rules, called the General Data Protection Regulation (GDPR), is scheduled to go into effect this March. It is considered one of the toughest privacy laws to be implemented to date. At the core, the law will allow Europeans “…to tell companies to stop profiling them, they’ll have much greater control over what happens to their data, and they’ll find it easier to launch complaints about the misuse of their information”. The explosive growth and volume of personal data being collected is going to present challenges for everyone.
A while back, I attended a session at a Gartner Symposium entitled ‘Privacy vs the World’ presented by Heidi Wachs, a research director at Gartner. She presented many examples of data privacy concerns. She raised the point that ‘the lines between social culture, corporate culture and regulation are blurred when it comes to privacy’. She asked the attendees ‘How can organizations truly define privacy so that it is appropriately preserved?’ The discussion revolved around the constant struggle and balancing of the business needs, convenience, and addressing privacy and security concerns of the users of the system
As technologists, we have a responsibility to help the business understand the tradeoffs and risks involved in this rapidly changing environment. We as humans, by nature, love to hoard things, and data is no different.


