Data privacy compliance is a growing priority for organizations worldwide, shaped by evolving laws and regulations that define how personal data must be collected, managed, and protected. This content covers core privacy concepts, data subject rights, key regulatory frameworks like GDPR, and the defined roles organizations must fulfill to remain compliant.
Data Privacy & Compliance
How companies manage data is a hot topic right now, and there are more and more laws and regulations that are either coming out or being altered to make sure that we're thinking about and managing our data correctly.
Privacy just means free from being observed or disturbed. Let me give you some examples of this. If you are at home, you don't necessarily want somebody knocking on your door all the time trying to sell you something, or calling you on the phone all the time trying to talk with you and sell you something. You don't want all of those disruptions, so you have a certain level of privacy. Same thing with online and with technology: you have a certain right to some privacy, and that's what laws and regulations help enforce.
Although laws and regulations are quite different depending on where you're from, there is some commonality amongst many of these. So we're going to talk about some common privacy concepts, about privacy and ownership and the different rights that these owners, or data subjects, have, and about the different data roles.
As I mentioned, depending on where you're from you could have different privacy laws that protect you. For instance, if you're in the European Union you have GDPR, and that's one of the newer privacy laws and regulations that are out there that protect its citizens.
This idea of data sovereignty means that you get protected against the laws and regulations of wherever you're located at. So for instance, if you're in the European Union, then you're protected by GDPR even if it's an American company that's collecting the data, or an Australian company that's collecting the data — they still have to comply with the laws and regulations that GDPR sets out.
One of the key factors in a lot of these privacy laws revolves around ownership. If there is a company out there that's collecting data — we call it the data collector — then they don't necessarily own that data that they are collecting, even if they are the ones that created that data. If they created that data based off of a data subject — that's you and I, the citizen, whoever they're collecting the information about — then the ownership relies on the data subject. So if they're collecting information about the data subject, then they don't necessarily have ownership over that data, and the data subject gets to make the call on how this company can use that data.
For instance, data subjects often have a right to access. That is, they can ask this company, this data collector, and say what information do you have on me, and then they have to provide that data to the data subject.
There's also a concept of right to be forgotten. That is, the data subject can say to the data collector, I don't want you to store information on me, and then they have to remove that information from their data stores. The reverse is true as well: there are data retention laws, which means that if you're holding data on somebody, you can't necessarily just delete that data without this data subject's permission. That doesn't always apply, but that is something that is out there — sometimes there are data retention requirements.
There's this idea also of data portability, where the data subject can take their data from a data collector and move it to another company. We see this in cases like medical records: you're not stuck going to the same medical facility. If they're doing a terrible job, you can tell them I want to switch to another company, I want to take my medical care to another place, and so you have the right for the data records at this health care facility to be moved to another health care facility.
Many of these laws address discrimination — that you can't utilize this data to discriminate against a data subject. A lot of times it also addresses data breach notification: that if this information were to ever be stolen, this data collector would have to notify the data subject that the information was stolen, that there was a data breach and the information was taken.
Many of these laws have an opt-out approach. That is, the data collector cannot contact or market to the data subject if the data subject says I don't want you to reach me, I'm opting out of you communicating with me, of you selling stuff to me, and you aren't allowed to use my data to market to me. That's an opt-out approach.
Other policies and laws have more of a consent approach. That means that they can't market to you even to begin with unless they get permission from the data subject — the data subject has to say yes, you can actually send me marketing material, and only then can the data collector do that.
Many of these laws and policies also define what data roles are. This is so we have a common set of language and understand our roles and responsibilities when it comes to our part and how we play into these policies. So let's take a look at some of the common data roles that you can see out there.
I can tell you from experience that a lot of these laws and regulations put quite a bit of strain on many different IT departments. There are quite a few things that we need to do to make sure we manage this data correctly. But after all, that is for the best, because essentially what we're doing is protecting our customers from the same thing that we want to be protected from, from companies who hold our data. So we need to be good stewards.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →