Tag: privacy

  • Private Data

    I think that as we evolve into a more digital world, we really need to modify and enhance the various legal systems around the world to cope with the challenges of digital information. The world changes when vast troves of information can be gathered, indexed, easily maintained, queried, and copied without anyone being aware, or few people understanding how any particular data is used. Data fundamentally is different in the digital world precisely because the costs and barriers to its movement are so low.

    I’ve been concerned with this for a few reasons. One is that I like my personal privacy and would like to ensure that data collected about me and my family is something I have some say in. Or at least some understanding. However as a data professional, I also have concerns about the responsibilities and potentials liabilities of managing data in the future. There’s also the not-so-little concern about employers pressuring employees to deal with data in a way that might conflict with their personal ethics, or even the local laws.

    I’m glad someone at Microsoft is taking a stance, asking the US and EU to recognize the privacy of digital data as a right we have as individuals and corporations. The request asks that governments treat digital data like they treat analog data, serving subpoenas and warrants to the owners of the data, not the custodians. While this isn’t what always happens in the real world, we certainly should have more protections for digital data than we have now.

    I’d like to see governments amend their laws to also exclude IT workers from liability in working with data that they are custodians of. We often don’t make the decisions about what data to gather or how it should be managed and moved. We just implement the decisions, often under coercion from our employers. Liability should rest with those employers, not those the employers have hired.

    I don’t have hope that things will change anytime soon, but I hold out hope they will at some point.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 2.4MB) podcast or subscribe to the feed at iTunes and LibSyn.

  • Data Freedom and Regulation

    HIPAA creates a floor, not a ceiling.
    HIPAA creates a floor, not a ceiling.

    The HIPAA laws passed in the US to provide for better privacy an security of medical information seem to be a joke in many of the situations in which I’ve dealt with medical providers. It almost seems like signing a HIPAA acknowledgment form is a formality and as patients, we should understand that HIPAA provides for standard requirements and protections for our data. However I’m not sure that’s the case.

    This article talks about the HIPAA laws being a floor, not a ceiling, and a patchwork of laws in various states superceed what HIPAA requires. However in doing so, they create inconsistent regulations and rules that people struggle to understand, and with which technology cannot keep up. I’d take issue with the comment that “Digital systems to move information need simplicity”. It’s not true. Our digital systems are very adept at handling exceptions and variable routing and security when they are programmed to do so. The problem is ensuring the people writing the code understand all of the rules for the exceptions.

    The article talks about the approach Hawaii has taken, in scrapping older laws and simplifying them to comply and expand the HIPAA requirements so that providers and patients can understand how to handle data. I suspect that few governments will take this approach, but it’s precisely what’s needed, in all fields, for those of us working with data to build systems that can not only comply with the laws, but also protect data in a secure manner.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.

  • Privacy

    Privacy icons
    We may be classifying all our data like this at some point.

    If you gamble online, you might be gambling in more than one way. It’s not surprising to me, but many online gambling businesses are located in places where the legal protections are more relaxed than in other places. However it’s not just the laws around the games themselves, but also the laws around data protections.

    Whether or not you have any sympathy here, or you think that companies engaged this this activity are worse than others, consider the fact that more and more companies in general are ignoring, flaunting, or just failing to keep up with data protection laws in other countries. What’s even worse, in my opinion, is that many of our laws are ill suited to dealing with the digital world and often don’t provide any protections for data that is more accessible, and greater in scale, than that which has ever been available.

    I have rarely known about data law changes, and have found myself ignorant of the laws in other countries at times. Not because I am looking to avoid any compliance, but because I’m too busy to keep up. I suspect many data professionals are in the same situation. We are unaware of problems in our data handling until there’s a complaint or someone notices.

    Privacy is important to many people in the world, despite the fact that all too often people aren’t sure how they would define the rules of privacy for their data. It’s a complex subject, and I understand the problems of passing or updating laws when various companies, advocacy groups, and even friends of lawmakers have opinions. I don’t know how things may evolve over time, but I do suspect that privacy and data handling will become more of a part of data professionals’ jobs in the future.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.