[
    {
        "Example": [
            "New digital technologies process personal information often violate individuals' reasonable expectations of privacy."
        ],
        "url": "https://www.ohchr.org/en/press-releases/2022/10/privacy-and-data-protection-increasingly-precious-asset-digital-era-says-un",
        "summary": "[[Summary: \nOn October 19, 2022, UN Special Rapporteur on the right to privacy, Ana Brian Nougr\u00e8res, presented a report to the General Assembly highlighting the increasing challenges to privacy in the digital era. Nougr\u00e8res emphasized that new digital technologies that process personal information often violate individuals' reasonable expectations of privacy. She stated that while technology has been beneficial for development, it poses significant risks regarding privacy.\n\nThe report outlined that privacy is a fundamental human right that enables personal development and the exercise of rights in accordance with human dignity. Nougr\u00e8res urged states to adopt the principles laid out in her report as essential components of national legal systems governing the processing of personal data. These principles include legality, consent, transparency, purpose, loyalty, proportionality, minimization, quality, responsibility, and security. \n\nShe called for international cooperation and regulatory harmonization to address the challenges of personal data processing and to safeguard privacy rights globally. Nougr\u00e8res noted that commonalities in international normative documents could help achieve a global consensus on privacy protection.\n\nFurthermore, she acknowledged the need for civilization to evolve alongside technological advancements while respecting human dignity and freedom. Nougr\u00e8res was appointed as Special Rapporteur on the right to privacy in July 2021, and she is a law professor and practicing attorney specializing in data protection and privacy.\n\nFor more information, media inquiries can be directed to Sonia Cronin at the UN Human Rights Office. The UN encourages individuals to advocate for human rights through initiatives like #Standup4humanrights.\n]]",
        "access_time": "2024-10-26T14:32:44.103420"
    },
    {
        "Example": [
            "Boeing data breach incident",
            "Morrisons data breach incident",
            "Equifax data breach incident",
            "FDIC data breach incident"
        ],
        "url": "https://link.springer.com/chapter/10.1007/978-981-16-2126-0_17",
        "summary": "[[Summary: \n\n**Title:** Data Privacy and Security Issues in HR Analytics: Challenges and the Road Ahead  \n**Author:** Shweta Jha  \n**Publication Date:** First Online: 16 July 2021  \n**Book Series:** Lecture Notes in Networks and Systems, Volume 209  \n**Pages:** 199\u2013206  \n**Accesses:** 1277  \n**Citations:** 2  \n**Altmetric:** 1  \n\n**Abstract:**  \nThe paper discusses the increasing adoption of HR analytics by large companies and the associated privacy concerns regarding the use of sensitive employee data. It reviews existing literature on data privacy and pilferage issues in the context of HR analytics and evaluates the responses from governments and corporations. The paper also proposes a roadmap for addressing privacy concerns related to employee data used in HR analytics.\n\n**Keywords:** HR analytics, Data, Data breach, Privacy, GDPR  \n\n**1. Introduction:**  \n- Privacy and security are fundamental human rights recognized by the United Nations (UNO) since 1948.\n- Employers have greater access to personal information about employees compared to other entities, increasing the risk of data breaches.\n- HR departments are responsible for safeguarding employee data, which is increasingly utilized in HR analytics, raising privacy concerns.\n\n**2. Related Work:**  \n- HR analytics data is critical for organizations, necessitating careful data management.\n- GDPR, enacted in 2018, aims to protect data privacy and has influenced global data protection laws.\n- Various countries, including Singapore and Canada, have established laws for data protection, like the Personal Data Protection Act and the Personal Information Protection and Electronics Documents Act, respectively.\n\n**3. Findings and Discussion:**  \n- Data breaches can lead to severe consequences for individuals, including identity theft and financial loss.\n- Internal and external threats to data privacy are prevalent, with 55% of enterprises experiencing data breaches in the past year.\n- Organizations must implement robust data governance practices, including employee training, data encryption, and strict access controls.\n- Examples of significant data breaches include incidents at Boeing, Morrisons, Equifax, and the FDIC, highlighting the need for improved data protection measures.\n\n**4. Conclusion:**  \n- Employees often unknowingly risk their privacy when sharing personal information with employers.\n- Organizations are responsible for protecting employee data and must comply with relevant privacy laws.\n- A comprehensive policy and system for data protection are essential, including privacy notices and annual data protection impact assessments.\n\n**Legislation and Regulatory Frameworks:**  \n- GDPR imposes heavy fines for data breaches, applicable to European companies globally.\n- India has enacted the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to prevent data breaches.\n\n**Key Recommendations:**  \n- Organizations should establish data governance processes focused on employee consent and data usage monitoring.\n- Regular training for HR teams on data management and privacy issues is crucial.\n- Continuous impact assessments and audits are necessary to ensure compliance with data protection laws.\n\n**References:**  \nThe document cites various sources, including articles, laws, and studies related to data privacy and HR analytics, underscoring the importance of robust data protection mechanisms in organizations.]]",
        "access_time": "2024-10-26T14:32:51.034365"
    },
    {
        "Examples": [
            "Case Study - Octopus Cards Limited Incident (2010): Company sold customer data without proper consent, leading to public outcry and changes in privacy expectations."
        ],
        "url": "https://www.isaca.org/resources/isaca-journal/issues/2016/volume-6/an-ethical-approach-to-data-privacy-protection",
        "summary": "[[Summary: \n\n**Title:** An Ethical Approach to Data Privacy Protection  \n**Authors:** Wanbil W. Lee, DBA, FBCS, FHKCS, FHKIE, FIMA; Wolfgang Zankl, Ph.D.; Henry Chang, CISM, CIPT, CISSP, DBA, FBCS  \n**Date Published:** 24 December 2016  \n\n**Main Topics:**\n1. **Interrelation of Privacy, Trust, and Security:**\n   - Privacy, trust, and security are interconnected.\n   - Privacy violations threaten security and erode trust.\n   - Law resolves issues when ethics cannot, but ethics contextualizes law.\n\n2. **Data Privacy Definition:**\n   - Concerns unauthorized access, inappropriate use, accuracy, and legal rights to data.\n   - Implications of data breaches include hard costs (financial penalties) and soft costs (reputational damage).\n\n3. **Urgency of Data Privacy Protection:**\n   - Driven by a technology-driven environment presenting socio-techno risks (e.g., identity theft, phishing).\n   - Necessitates effective data privacy policies and compliance strategies.\n\n4. **Complexity of Data Privacy Protection:**\n   - Involves technical, ethical, and social considerations.\n   - Risks include unauthorized access through negligence (e.g., taking USB home).\n\n5. **Methods for Data Privacy Protection:**\n   - **International Data Privacy Principles (IDPPs):** Establish policies and guidelines for data privacy.\n   - **Hong Kong\u2019s Data Protection Principles (DPPs):** Reinforce data privacy standards.\n   - **Hexa-dimension Metric Framework:** Operationalizes policies through a structured approach.\n\n**Key Components of Data Privacy Protection:**\n- Technical solutions: Safeguarding data from unauthorized access.\n- Social solutions: Transparency and awareness among data subjects.\n- Compliance with laws: Addressing the lag of legal regulations behind technology.\n\n**IDPPs for Organizations:**\n1. Comply with national laws regarding data privacy.\n2. Protect personal data from unauthorized access.\n3. Maintain a clear privacy policy.\n4. Train employees on privacy compliance.\n5. Limit data collection to necessary information.\n6. Use data fairly and for specified purposes.\n7. Avoid outsourcing data without compliance assurance.\n8. Announce data breaches.\n9. Retain data only as necessary.\n10. Inform customers of inadequate data protection standards.\n11. Provide access to stored data upon request.\n12. Obtain explicit consent for sensitive data use.\n13. Delete outdated data upon request unless legally required to retain.\n\n**Hong Kong Personal Data Privacy Ordinance (PDPO):**\n- Based on OECD Privacy Guidelines, emphasizing lawful data collection, accuracy, purpose limitation, security safeguards, openness, and individual participation.\n\n**Case Study - Octopus Cards Limited Incident (2010):**\n- Company sold customer data without proper consent, leading to public outcry and changes in privacy expectations.\n\n**Hexa-dimension Code of Conduct:**\n- A framework to guide stakeholders on ethical behavior regarding data privacy.\n- Measures legal validity, social desirability, ecological sustainability, ethical acceptability, technical effectiveness, and financial viability.\n\n**Conclusion:**\n- Information security professionals need effective guidance for data privacy standards due to the complexity and urgency of privacy concerns.\n- Ethical perspectives on privacy enhance organizational accountability and compliance. \n\n**Authors' Backgrounds:**\n- Wanbil W. Lee: Expertise in information systems and security management.\n- Wolfgang Zankl: Professor of law and founder of the European Center for E-commerce and Internet Law.\n- Henry Chang: Expert in privacy technologies and adjunct professor at the University of Hong Kong.]]",
        "access_time": "2024-10-26T14:32:50.513937"
    }
]