TechKnowSurge
NIST 800-53 PT-2 NIST 800-53 PT-4 ISC2 CISSP 2.4 CompTIA SecurityX 1.4
VideoSecurityFree

Privacy

Privacy fundamentals cover the core rights and regulations that govern how personal data is collected, used, and protected in today's connected world. Key concepts include data sovereignty, ownership, the right to access, the right to be forgotten, and consent requirements across different jurisdictions.

Complete this video to capture a CTF flag worth 1 point.

About this video

Privacy is the right to be free from unwanted observation or intrusion, whether that means keeping a phone call confidential, protecting a text exchange from interception, or simply not receiving unsolicited communications. While privacy as a concept has roots in foundational legal documents like the U.S. Constitution, the rapid expansion of connected technology — from landlines to mobile devices — made explicit privacy legislation necessary. Germany introduced the first formal privacy laws in the 1970s, followed shortly by the United States, setting off a global trend of consumer data protection regulation that continues to evolve today. Organizations responsible for managing IT infrastructure must understand and comply with these frameworks not just as a legal obligation, but because they exist to protect the individuals whose data is being handled. Several key terms define how privacy law operates in practice. Data sovereignty establishes that the laws governing collected data are determined by where that data originates, not just where a business is physically located, meaning a company can simultaneously be subject to multiple international regulatory frameworks. Ownership under most privacy regulations belongs to the data subject — the individual the data describes — rather than the entity that collects or generates it. From this principle flow specific consumer rights, including the right to access collected data, the right to be forgotten through deletion requests, data portability to transfer records between providers, protection against discriminatory use of data, and the right to be notified in the event of a breach. Many jurisdictions also require either an opt-out mechanism, allowing individuals to restrict how their data is used or shared, or a stricter consent standard, requiring explicit permission before any collection, communication, or sale of data can take place. Navigating these overlapping and sometimes conflicting requirements demands significant time and legal diligence, but compliance is essential to both organizational integrity and the protection of end users.

What you'll learn

What's covered

Privacy

Aligned to

NIST 800-53
PT-2 Authority to Process Personally Identifiable Information
PT-4 Consent
ISC2 CISSP
2.4 Manage data lifecycle
CompTIA SecurityX
1.4 Explain how privacy and data sensitivity impact security and business requirements

Key terms

Data Privacy
The principle and practice of ensuring that personal information is collected, stored, and used in accordance with applicable laws and individual rights.
Data Sovereignty
The concept that data is subject to the laws and regulations of the geographic region in which it originates or is collected.
Data Ownership
The principle that the data subject — the individual whose information is collected — retains rights over that data, not the organization that collected it.
Right to Access
A consumer right that allows individuals to request and view the personal data an organization has collected about them.
Right to Be Forgotten
A regulatory right that allows data subjects to request the deletion of their personal data from an organization's records.
Data Portability
A consumer right that allows individuals to have their personal data transferred from one service provider to another.
Consent
A privacy principle requiring that organizations obtain explicit permission from individuals before collecting, using, or sharing their personal data.
Data Breach
An incident in which protected or sensitive data is accessed, stolen, or disclosed without authorization, typically triggering legal notification requirements.

Topics

Data Privacy Data Sovereignty Consumer Rights Gdpr Compliance Regulatory Compliance Cybersecurity

Transcript

A lot of the laws and regulations that we have out there, or even our customers' demands, are really a lot around privacy. The meaning of privacy just means that we are free from being observed or disturbed.

Some examples of this might be: if I am making a phone call, I don't want somebody listening in on that phone call. Or let's say I am texting somebody — I don't want somebody to be able to view that text that is being transferred back and forth. Or perhaps I don't want somebody to call me or be able to text me if I am not wanting them to call or text me, or email me if I have never requested an email from a specific person. Think about how a lot of junk mail will fall under this. So privacy is just being free from being observed — people viewing us and our actions, and what we are saying and what we are doing — and disturbed, that is, unwanted phone calls or unwanted email or unwanted approaches.

Privacy is not a new concept

The idea of privacy is not a new concept. In fact, we have some stuff written into the US Constitution that essentially, even though it doesn't necessarily address privacy specifically, helps enforce our privacy rules and laws. So privacy is not necessarily a new thing, but back then there weren't a lot of phones and not a lot of need to call out privacy specifically.

What has happened over time is that we started having phones inside our house, and so now people could call us and reach us any time that we were at home. Then we started carrying phones on us, so now they could call and reach out to us at any time that we are carrying our phone, which for a lot of us is all the time. And so it became a lot more of a heated topic as we have got more and more connected.

What we have seen is that in the '70s, Germany came out with the first laws specifically addressing privacy, and then shortly after that the US came out with a couple of laws as well, also reinforcing privacy for the general consumer.

Why we implement privacy

The question is, why are these laws coming out, and why do our businesses that we manage, the infrastructures that we put in place, why do we need to be so concerned about privacy? Well, it is the demand of the consumers. You and I are consumers. We go and purchase other products, we have different technology that is on us, and so we don't want to be disturbed all the time, and we want to extend that to everyone. We want to extend that ability to be free from being observed or disturbed. So really it is all about us, and the reason why we are implementing it is for us and people just like us.

When it comes to privacy there are some things that we need to be familiar with: things like what the term sovereignty means, ownership, and a bunch of different rights that the end consumer has, things like the right to access or the right to be forgotten. So let's talk about some of those rights and some of those terms.

The scope of these terms

When it comes to privacy, the first thing we should understand is the scope of what I am going to talk about. That is, I am going to talk about certain terms and certain aspects of this which are not going to apply across the board. There are a lot of different laws and regulations that are out there, so what has to be followed in the US is different than what has to be followed in Australia, which is different than what has to be followed in the European Union. They all have different sets of laws and regulations, they have different definitions for the same terms, and they have different meanings for them, so you really have to look at the laws and regulations. But what we are going to cover is kind of the overall scope of what some of these terms mean and what privacy looks like.

Data sovereignty

The first term we should be familiar with is something called data sovereignty. Data sovereignty is the idea that we may fall under laws and regulations of other countries based off of what data we are collecting.

Let me give you an example of this. Let's say I start a company in — well, maybe it is in Australia right here. Because I started in Australia, I am bound by the laws and regulations that Australia has. But let's say I have some customers actually in Asia. Now, because I have customers in Asia and I am collecting data from those customers, that data has a different set of laws and regulations that are applied to it, and I have to follow the laws and regulations when it comes to that data from wherever it is collected from.

This is really important, because I am no longer bound geographically from where I am located at, but also where I am doing business at and where I am collecting the data from. So it is an important term when it comes to these laws and regulations and following compliance.

Ownership

There is this important aspect of ownership. As a business that is collecting data, we are the data collector, so it might seem like we own that data. Let's say you visit my website. I am recording things like your IP address and some information about your browsing history, and I am recording that information. The idea of ownership is that just because I have collected it — maybe I have even generated some of that data — doesn't mean I own that data. In the case of privacy, most of the time it is the data subject, the person that I am collecting that information about, that actually owns that data. So just because I generated that data and created that data and I have collected that data, that doesn't give me the rights to that data.

Rights of the data subject

This is important because of rights like the right to access. A right to access is that the data subject can actually see what data I have collected on them, so they can request and say, what data do you have on me, and then I have to show them what that data looks like.

There is also this term right to be forgotten. That user or data subject could say, I don't want you to collect that data from me, and so you have to delete that data, because they have the right to request that you forget about them and that you don't know who they are. The flip side is that there could be certain data retention requirements, that is, you are required to keep certain data for a certain period of time and you can't just go and delete it. So there are times when we have to keep data.

There is also a concept of data portability. This is the idea that this data needs to be able to switch to a different service provider. An example of this is maybe the data subject doesn't want to go with your company anymore, or a single company, whoever is collecting this data, and that information then can be transferred or moved to other companies.

Many of these laws and regulations also address non-discrimination, that is, you can't use this data to discriminate against somebody.

Another thing that is common is a data breach, that is, a company or data collector gets broken into and that information gets stolen. Laws and regulations now are protecting the data subject, saying that if this information is stolen they have a right to be notified, and you have to notify your customers that the data actually has been stolen.

Opt out and consent

A lot of laws and regulations have implemented some sort of opt out clause, that is, the data subject can opt out of whatever you are doing with their data. Let's say we have a data collector here and they have information on this user. Maybe they are selling that information — well, the data subject can opt out of that and say, I don't want you to sell my information. Or maybe they are calling this data subject, or maybe they are sending them emails. This user has a right to say, I don't want you to send me emails, I don't want you to give me phone calls, I don't want you to send me text messages. They can opt out of that communication.

Other laws and regulations have taken it a step further, to consent: that you can't ever collect that data to begin with unless you have consent from the data subject, or you can never call them or email them or text message them unless you have received consent first, or you can never sell their data unless you have received consent, that you have received permission from that user to be able to do whatever with that data. And you have to receive that permission before you can do it.

What this means for IT

Quite honestly, from an IT perspective, from implementing change within our infrastructure, dealing with these different privacy laws and regulations is actually really time consuming. It takes a lot of time and effort to make sure that you are doing it right, pouring over a lot of legal documents, and so it is not something that everybody really just gravitates towards. However, it is really critical that we do it — not just for the company and keeping the company safe, but because these laws and regulations are put into place for a reason: to help protect the consumer.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →