Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Carnegie Mellon's Data Privacy Head Urges Development of New Privacy Technologies | Main | HIPAA Violation in Divorce Proceeding? »

Privacy: Are You Sure You *REALLY* Have Nothing To Hide?

During the past few years it has become more common to have phone records, purchase records, and other logged activities datamined and reviewed by various organizations, government agencies and law enforcement groups. One highly publicized example was when AT&T provided access to their customers' phone records and Internet communications to the U.S. National Security Agency (NSA).

Many organizations, along with millions of individual folks, were outraged that their private information was being sifted through and judged. However, many groups and millions of other folks simply shrugged their shoulders, saying, "I've done nothing wrong, so I have nothing to hide! Let them look!"

Over the years I've heard this said many times by a large number of technology professionals, as well as other folks in completely different professions, "I've got nothing to hide. They can look at whatever they want!"

However, privacy is not about having nothing to hide. It is about the right to keep non-public communications and activities private.

A new paper by Daniel J. Solove was recently published , ""I've Got Nothing to Hide" and Other Misunderstandings of Privacy"

This truly provides a wonderful discussion for this important issue of privacy. It would definitely be a good article for those folks to read who think they have nothing to hide. Or, perhaps you could discuss the issues from the article with those folks.

The point the article makes very well, in a number of ways, is that it is a matter of personal privacy. As one passage puts it,

"“If you have nothing to hide, then that quite literally means you are willing to let me photograph you naked? And I get full rights to that photograph - so I can show it to your neighbors?”28 Canadian privacy expert David Flaherty expresses a similar idea when he argues: There is no sentient being in the Western world who has little or no regard for his or her personal privacy; those who would attempt such claims cannot withstand even a few minutes’ questioning about intimate aspects of their lives without capitulating to the intrusiveness of certain subject matters.29"

Indeed.

This is a very interesting read, with quite a bit of information from Solove's own blog, including others' comments in response to his postings, in addition to the expected, but very readable and understandable, legal discussion.

There is also a great privacy taxonomy Solove had previously proposed included in the paper. It helps to make the concept of privacy something more than just a vague, subjective term. It is something organizations could use to help build privacy and security into their procedures, operations, networks and IT applications.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/458

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.