TechKnowSurge
NIST NICE K0678 NIST NICE K0917 NIST 800-53 PT-7 NIST 800-53 PT-2 NIST NICE K1198 NIST CSF GV.OC-03 NIST 800-53 PM-18
VideoSecurityFree

Confidentiality - Privacy

Privacy laws and regulations govern how personal data must be protected, covering everything from browsing habits to health and financial records. IT professionals are responsible for understanding and enforcing compliance with these laws, which vary by jurisdiction and can apply across international borders.

Complete this video to capture a CTF flag worth 1 point.

About this video

Privacy, at its core, means freedom from unwanted observation or intrusion. While privacy protections in the United States date back to at least 1974, the rapid expansion of digital technology has made the issue far more complex, prompting a growing body of laws and regulations designed to keep pace with how personal data is now collected, stored, and shared. Today, countless organizations gather detailed information about individuals, including browsing preferences, purchase history, location data, and much more, making robust privacy protections both legally required and ethically essential. The categories of data covered by these laws are broad, encompassing personally identifiable information, protected health information, financial records, and educational records, among others. IT and cybersecurity professionals are not passive participants in this landscape. They carry an active responsibility to enforce privacy protections and ensure that the systems and processes they manage handle personal data in full compliance with applicable regulations. That compliance picture can be complicated by geography, since the relevant rules are not always determined by where an organization is headquartered. Frameworks such as the General Data Protection Regulation apply based on the citizenship or location of the individuals whose data is being processed, meaning a U.S.-based organization serving European clients must meet GDPR standards regardless of where operations are based. Professionals working in this field need to understand which regulations apply to their specific data, user base, and storage environments in order to remain compliant.

What you'll learn

What's covered

Privacy in Technology

Aligned to

NIST NICE
K0678 Knowledge of privacy laws and regulations
K0917 Knowledge of Personally Identifiable Information (PII) data security standards and best practices
K0678 Knowledge of privacy laws and regulations
K1198 Knowledge of privacy and data security regulators
NIST 800-53
PT-7 Specific Categories of Personally Identifiable Information
PT-2 Authority to Process Personally Identifiable Information
PM-18 Privacy Program Plan
NIST CSF
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.

Key terms

Personally Identifiable Information
PII
Personally Identifiable Information is any data that can be used alone or in combination to identify, contact, or locate an individual, requiring protection under privacy laws and organizational security policies.
Protected Health Information
PHI
Protected Health Information is individually identifiable health data covered under HIPAA that requires specific administrative, physical, and technical safeguards to protect its confidentiality, integrity, and availability.
General Data Protection Regulation
GDPR
A European Union regulation that establishes comprehensive data protection and privacy rights for individuals within the EU and EEA, and imposes obligations on organizations that process EU residents' personal data regardless of where the organization is located. GDPR introduced concepts such as data minimization, the right to erasure, and mandatory breach notification.
Data Privacy
The principle and practice of ensuring that personal information is collected, stored, and used in accordance with applicable laws and individual rights.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Compliance
The act of adhering to the laws, regulations, standards, and internal policies that govern how an organization handles data and security. Compliance programs use audits and controls to demonstrate that requirements are being met.

Topics

Data Privacy Gdpr Regulatory Compliance Personal Data Protection Cybersecurity Law Information Security

Transcript

There's a topic very closely related to data confidentiality, and that topic is privacy. Privacy is a big concern nowadays. Us as citizens in most countries have a right to privacy. In 1974, there was a law that was put into place here in the United States that enforced privacy, and that was before internet and really the boom of technology was a thing. Now with the boom of technology, there are more laws and regulations being put into place to protect our privacy.

At its basic definition, privacy just means free from being observed or disturbed. With the technology boom and everything that we're doing with technology, there's a lot of data that's collected about us. There are a lot of companies out there that are collecting what our browsing preferences are, where do we go, what do we buy, a lot of information, and that information needs to be protected.

So there are privacy laws in place to protect us and our data. These privacy laws help protect our personal identifiable information, our protected health information or PHI, our financial information, our education information, and much beyond that. It's important for us that other companies abide by these privacy laws. But us as technology experts and as professionals, we need to also protect other people's identity and personal health records, financial records, and educational records. We need to be the ones that are enforcing this and making sure that we're protecting this data.

There are a lot of different privacy laws out there. One of the newer ones is GDPR. Even though I'm in the United States, let's say the organization that I'm working for has clients over in Europe. Then I need to protect those clients and those clients' data just as if I were living in Europe; I still have to comply with the GDPR rules. So I might have to comply with a lot of different country rules depending on what data I'm storing, who the citizens are, what country they're a citizen of, and where that data is being stored.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →