Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

Data privacy good governance and controls

By Muhammad Tariq Ahmed Khan
data privacy

Designed by Freepik

March 5, 2021

There has been a misconception about privacy that confuses many people. People tend to share seemingly related or unrelated personal information online, such as birthdays, address, contact details, marriage, and holiday plans on social media. People are also inclined to share pictures of favorite foods, people, localities, and workplaces, in addition to providing opinions on sensitive issues (religious, national, political, etc.) throughout different social media platforms. On the other hand, new and exciting technologies are emerging almost on a daily basis, and people share their information in the guise of playing games online, attending virtual worlds, and doing shopping online. Similarly, organizations also collect and store relevant personal information for business purposes. Consequently, the privacy risk increases ubiquitously with every share. The shared data, individually or collectively, can be used for malicious activities.

Before moving ahead, let’s have a clear understating of “Privacy” and related terminologies:

 

What is Privacy?

Privacy is the ability of individuals or groups to seclude themselves, or information about themselves, and thereby express themselves selectively. (Source: Wikipedia)

In other words, Privacy is an individual’s fundamental right to have control over the collection, usage, and dissemination of personally identifiable information.

Personally Identifiable Information (PII) – The Information that directly or indirectly identifies an individual. For instance: name, address, date and place of birth, National Identity Number, biometrics (e.g., photo, fingerprint, iris etc.).

 

What is Data Privacy?

“Data Privacy”, also called “Information Privacy,” is the technical aspect of information security that deals with the ability of an organization to handle PII, or an individual’s right to determine what kind of data can be collected/ stored in a computer system, and can be shared with third parties.

 

Difference between Data Privacy and Data Security?

People and organizations are sometimes confused by the differences between Data Privacy and Data Security. Both of them pertain to PII, but are distinct concepts. Data Privacy is about the control (related to usage and governance) over PII, such as policies and procedures being established to ensure that PII is collected, stored, used, and shared appropriately. Whilst Data Security is about ensuring that technical controls (related to confidentiality, integrity, and availability) are implemented to protect PII from malicious cyber-attacks. In other words: Data Security is a technical aspect of PII, whereas Data Privacy is a legal aspect. In layman terms, privacy is the fundamental right to be left alone without any intervention.

 

Privacy Risks:

One of the biggest challenges faced by any organization is managing privacy risks. Since privacy awareness has increased over time, people are becoming more concerned with how organizations are handling their personal information.

Moreover, with the inception of privacy regulatory laws and associated penalties, it has become mandatory for organizations to take necessary steps in establishing and implementing a strong privacy risk management framework. Inadequate, or the lack of, a risk management framework may present numerous organizational risks, such as:

1. Possible damage to the organization’s public image and reputation

2. Potential financial or operational losses

3. Regulatory sanctions and penalties/ fines

4. Loss of customers’ trust and failure to attract customers

5. Damaged business relationships

 

Recommended Good Privacy Governance and Controls:

Digital records of PII demand unique forms of protection at each part of their lifecycle. It is paramount for an organization to implement effective privacy program that includes the following good privacy governance and controls in order to address above privacy risks:

 

Privacy Governance:

1. Have a formal corporate governing structure to determine the level of privacy risk appetite acceptable for senior management.

2. Have a privacy framework containing policies and procedures relating to privacy of personal information address data classification, record management, retention, and destruction.

3. A Privacy Risk Management Framework should be developed to identify, analyze & evaluate, and treat privacy risks.

4. Define the roles, responsibilities and accountability related to the privacy program during its life cycle.

 

Data Collection:

5. Document the business purposes for collecting personal information to ensure PII which are not required are not collected and retained.

6. Identify what kind of PII the organization is required to collect, who will collect, how will it be collected and who will define what is personal or private.

 

Permissions:

7. Be well aware about where all personal information is stored and who has access to them.

8. Implement a technical solution to set different permission levels for employees based on what PII they need to access such as Public, Private, and Restricted Access.

 

Data Confidentiality Assurance:

9. Ensure PII is encrypted at rest and in motion throughout the life cycle. PII should be encrypted at various levels — databases, networks, system platforms, application layers, and business process/functional levels.

10. Identify the disclosure rules of PII to relevant third parties and not disclosed to unauthorized entities (people and systems).

 

Data Governance & Education:

11. Define an awareness program to provide employees the privacy awareness training and have guidance on their specific responsibilities in handling privacy requirements, issues, and concerns. Employees who handle or have access to personal information must have undergone the required training.

12. Ensure that skilled resources are available to develop, implement, and maintain an effective privacy program.

 

Privacy Compliance Monitoring Framework:

13. Establish a compliance monitoring framework to periodically verify the compliance level to ensure that privacy policies and procedures are being followed and detailed enough to meet new or current requirements.

14. Perform an assessment of privacy laws and regulations currently applicable for the organization or will be applicable in the future.

 

Privacy Incident Response Plan:

15. Develop a privacy incident response plan in the event of a breach or attempted beaches of personal information and to report such breaches to authorized individuals or regulators or anyone who has been affected by a data breach. This includes breaches that occur on the part of third parties.

 

Data-Flow Map:

16. Establish a data-flow map that covers what kind of information is subject to transfer from one location to another, such as between departments, between individuals, to and from third parties, and through geographical borders.

 

Privacy Technical Solutions:

17. Any software or system or technology to be used for privacy should be fully evaluated and secured before deployment.

18. Consider deploying hyper automation to automatically redact PII from both static files and audio/ video recordings.

 

Key Benefits of Good Privacy Governance and Controls:

I will outline some key benefits of them:

  1. Protecting the organization’s image and reputation.
  2. Protecting valuable data of the organization and its customers, employees, and business partners.
  3. Achieving a competitive advantage in the marketplace.
  4. Complying with applicable privacy laws and regulations and avoiding regulatory penalties
  5. Enhancing an organization’s credibility and promoting confidence.

Protecting privacy cannot be separated from technological development, and these days, organizations are inclined to invest in security technology to reduce the risk of privacy exposure. However, there is no technology that will prevent and eliminate the risk of every data privacy breach. So, organizations should fully understand the nature of risk and take a layered approach to improve their security posture by taking the time to understand PII and re-evaluate how this privacy data can be managed and protected.

 

Caveat:

This article doesn’t cover the Data Privacy with respect to collection, usage, storage and dissemination of PII in physical form.

KEYWORDS: cyber security data privacy data security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Muhammad Tariq Ahmed Khan is Head of Cybersecurity Audit, Internal Audit Division, Arab National Bank, Riyadh. He is a “Subject Matter Expert” in Technology and Cybersecurity Audits. He has more than 21 years’ experience in the Banking industry, in areas such as IT, Cybersecurity, and IT Audit. He has a solid understanding and application of Risk-Based Audit methodology, ISMS (ISO 27001), ISO 22301, NIST and COBIT, IT & Information Security regulatory compliance. To his credit, Tariq also has sound technical knowledge (as evident by his pertinent professional certifications) in various IT platforms and IT project management – with experience in Disaster Recovery and Business Continuity Management.

He has published articles on different topics of cybersecurity and he has spoken at regional and international seminars and conferences.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Cybersecurity
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cyber Tactics Column
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Logical Security
    By: Charles Denyer
close

1 COMPLIMENTARY ARTICLE(S) LEFT

Loader

Already Registered? Sign in now.

Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Person working on laptop

Governance in the Age of Citizen Developers and AI

patient at healthcare reception desk

Almost Half of Healthcare Breaches Involved Microsoft 365

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Cyber 1

    Achieving Good Governance Over Cybersecurity

    See More
  • data

    Data security governance strategies can be a business differentiator

    See More
  • data-protection-freepik1170x658v504.jpg

    Data privacy is a challenge. Tech leaders have the solution

    See More

Events

View AllSubmit An Event
  • October 29, 2024

    Data-Driven Security: Turning Incidents into Strategic Assets

    ON DEMAND: Are you looking for tips on how to turn everyday data into a powerhouse for your security strategy? Join us for our webinar, "Data-Driven Security: Turning Incidents into Strategic Assets," and find out how to unlock the full potential of your incident data.
  • August 27, 2025

    Risk Mitigation as a Competitive Edge

    In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!