The Role of Privacy Technologists in the Organisation
- Privacy roles and responsibilities: data governance with DPO, data owner, data steward and data custodian, legal compliance, cybersecurity
- Translating legal and regulatory requirements into technical and organisational solutions; implementing internal and external privacy notices, policies and procedures
- Technical tasks: supporting privacy reviews and audits including third parties, assisting with data breaches and other incidents, risk concepts such as threat, vulnerability, attack and exploit
- Risk models and frameworks: Contextual Integrity by Nissenbaum, Harms Dimensions by Calo, FAIR, NIST/NICE, FIPPs, OECD principles; threat modelling with LINDDUN and MITRE PANOPTIC
- Data ethics and privacy: distinguishing between lawful and ethical processing, societal and ethical questions, minimising bias and discrimination in automated decisions
Collection, Use, Disclosure and Deletion of Data
- Collection: data subject control and consent through clear privacy notices, settings, dashboards and consent management; automatic collection; data from publicly available sources
- Implementing appropriate retention and destruction of personal data
- Use: data minimisation, separation of processing activities, risks of aggregation, privacy-enhancing techniques such as anonymisation, pseudonymisation and differential privacy, secondary use and profiling
- Disclosure: mitigating risks from exposure and accessibility, protection against data falsification, data exposure, breach of confidentiality, extortion and appropriation; defence in depth with identity and access management and authentication
Privacy Risk Management
- Intrusion and decisional interference: mitigating risks from behavioural advertising, profiling, cyberbullying and social engineering, avoiding dark patterns
- Software security: identifying and fixing privacy vulnerabilities, intrusion detection and prevention, risks in change management for patches and upgrades, identifying vendor breaches
- Tracking and surveillance: e-commerce with cookies, chatbots and payments, audio and video surveillance, wearables and IoT, biometrics, location tracking, internet monitoring and web tracking
- Technologies in the workplace: artificial intelligence, machine learning and deep learning; communication technologies such as video conferencing, messaging, mobile devices, social media and gaming platforms
- Monitoring and managing risks: privacy audits and IT control reviews, key risk indicators and key performance indicators, data protection impact assessments
Privacy by Design
- Applying the seven foundational principles of Privacy by Design, defining privacy objectives and communicating them within the organisation
- Aligning high-level specifications and detailed specifications with the principles of Privacy by Design
- Assessing privacy risks in the user experience: the influence of UX decisions on user behaviour, usability testing for privacy features, value sensitive design
Privacy Engineering and Privacy Governance
- Applying the NIST Privacy Engineering Objectives: predictability, manageability and disassociability
- Considering enterprise architecture, data flow diagrams and data lineage tools, and cross-border data transfers
- Managing privacy risks throughout the development lifecycle
- Cataloguing data assets, building a data inventory and record of processing activities, reviewing code for privacy gaps, monitoring runtime behaviour