Helios Salinger

  • About
    • About Salinger Privacy – now Helios Salinger
    • Meet our team
    • Work with us
    • Videos, Podcasts and Media Mentions
    • Privacy Awareness Week
  • Consulting
    • Overview – Our Consulting Services
    • Privacy Impact Assessment
    • Privacy Maturity Assessment
    • Privacy by Design advice
    • Privacy Compliance and Gap Analysis
    • Algorithmic Impact Assessment
    • Re-identification Risk Assessment
    • Data ethics
    • Privacy Helpdesk
  • Training
    • Overview – Our Training Services
    • Privacy Compliance Training
    • Privacy Professionals Training
    • All Online Modules
    • Training Calendar
    • Public Courses and Workshops
    • In-house Privacy Training and Workshops
    • Webinars
    • IAPP Certifications
    • Training Advisory Services
    • Login
  • Resources
    • Overview – Our Resources
    • THE PRIVACY PULSE
    • Privacy Act Reforms
    • Compliance Kits
    • Resources on key privacy topics
    • Free Handbook
    • Newsletter
    • Login
  • Case Study
  • Blog
  • Calendar
  • Contact
  • Compliance Kits
    • For Business & Non-profits
    • For Peak Bodies
    • For Australian Government
    • For NSW Public Sector
    • For VIC Public Sector
    • For QLD Public Sector
    • For WA Public Sector
    • Login

What technology designers need to know to understand privacy

July 10, 2017, Stephen Wilson

Privacy is contentious today.  Some say the information age has brought real changes to privacy norms.  With so much private data leaking through breaches, accidents and digital business practices, it’s often said that ‘the genie is out of the bottle’.  Many think privacy has become hopeless.  Yet in Europe and many jurisdictions, privacy rights have been strongly and freshly enforced, and for the very latest digital processes.

For technology designers and security pros coming to grips with privacy, the place to start is the concept of ‘personal information’ – also known as ‘personal data’ in the EU, or PII in the US.  The threshold for data counting as personal information is low: any data about a person whose identity is readily apparent constitutes personal information in most places, regardless of where it came from, or who might be said to ‘own’ it. This is not obvious to engineers without legal training, who may form a more casual understanding of what ‘private’ means.  So it seems paradoxical to them that the words ‘public’ and ‘private’ don’t even figure at all in laws like Australia’s Privacy Act!

There is a cynical myth that ‘Technology outpaces the Law’. In practice, it is the law that challenges technology, not the other way around!  The grandiose claim that the ‘law cannot keep up with technology’ is often a rhetorical device used to embolden developers and entrepreneurs.  New technologies can make it easier to break old laws, but the legal principles in most cases still stand.  If privacy is the fundamental right to be let alone, then there is nothing intrinsic to technology that supersedes that right.  It turns out that technology neutral privacy laws framed over 30 years ago are powerful against very modern trespasses, like wi-fi snooping by Google, over-zealous use of biometrics by Facebook, and intrusive search results extracted from our deep dark pasts by the all-seeing Google. So technology really only outpaces policing.

One of the leading efforts to inculcate privacy into engineering practice has been the ‘Privacy by Design’ movement (PbD), started in the 1990s by Ontario privacy commissioner Dr Ann Cavoukian.  PbD seeks to embed privacy ‘into the design specifications of technologies, business practices, and physical infrastructures’. As such it is basically the same good idea as building in security, or building in quality, because to retrofit these things too late leads to higher costs and disappointing outcomes.

In my view, the problem with the Privacy by Design manifesto is its idealism.  Privacy is actually full of contradictions and competing interests, and we need to be more mature about this.

Just look at the cornerstone privacy principles.  Collection Limitation for example can contradict the security instinct to retain as much data as possible, in case it proves useful one day.  Disclosure Limitation can conflict with usability, because it means PII may be siloed and less freely available to other applications.  And above all, Use Limitation can restrict revenue opportunities in all the raw material digital systems can gather.  Businesses today accumulate masses of personal information (sometimes inadvertently, sometimes by design) as a by-product of online transactions; real privacy means resisting the temptation to exploit it (as Apple promises to). Privacy at its heart is about restraint. Privacy is less about what you do with personal information than what you don’t do with it.

PbD naively asserts that privacy can be maximised along with security and other system objectives, as a “positive sum” game.  But it is better that engineers be aware of the trade-offs that privacy can entail, and that they be equipped to deal with real world compromises entailed by privacy just as they do with other design requirements.  Privacy can take its place in engineering along with all the other real world considerations that need to be carefully weighed, including cost, usability, efficiency, profitability, and security.

 

This is an edited extract from a chapter Stephen contributed to Darek Kloza and Dan Svantesson’s new book Trans-Atlantic Data Privacy Relations as a Challenge for Democracy?

Previously published on the Constellation Research blog.  Minor revisions made for a primarily Australian audience.

Photograph (c) Shutterstock

Filed Under: Uncategorized

If you enjoyed this blog, subscribe to our newsletter to receive more privacy insights and news every month.

Privacy Compliance Kits

Recent Posts

  • Tick and flick: what ’I agree’ really means to Australians in 2026
  • Inching towards individuation: OAIC decision on pixels broadens scope of the Privacy Act
  • How dark patterns can land you in hot water: new case offers lessons for all
  • How to sniff out the landmines that can ruin your AI project
  • Privacy reforms to impact over 100,000 small businesses
  • The view from the summit: trust and hope, caution and concern, and plenty of hard work
  • Is identifiability in the eye of the beholder?  EU case tests limits of pseudonymisation
  • Mind the gap: when legal permission is not enough to ensure compliance
  • Why “Don’t worry it’s de-identified” should (still) be a red flag when considering privacy risk
  • How to get ahead of the new ADM rules before they rule you

Archive

  • 2026
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015

Search

Helios Salinger can help you navigate the complexity of the regulatory environment, and ensure the trust of your customers.

CONTACT US

T: 02 9043 2632
Level 37, 180 George Street
Sydney NSW 2000
Email Enquiry

© Helios Salinger Pty Ltd
ACN 655 748 593
ABN 59 655 748 593

Our Privacy Policy

Terms of Engagement

Subscribe to our newsletter.

These details will be added to our mailing list to receive the Helios Salinger eNews and Product News newsletters. You can unsubscribe or adjust your preferences at any time, from the bottom of any newsletter.