{"id":598,"date":"2023-07-14T20:21:20","date_gmt":"2023-07-14T20:21:20","guid":{"rendered":"https:\/\/solutionsreview.com\/expert\/?p=598"},"modified":"2024-02-02T14:40:31","modified_gmt":"2024-02-02T14:40:31","slug":"cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/","title":{"rendered":"Cloud Data Privacy and Security Challenges Part 4: Cloud Data Privacy and Security Challenges\u00a0"},"content":{"rendered":"<p style=\"text-align: justify;\"><span data-contrast=\"none\">A closer review of the comparison of the three laws reveals some inherent challenges associated with data protection and data privacy compliance, such as:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:200,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">Explosion of Data Privacy Laws<\/span><\/b><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"none\">Governments are taking data privacy rights seriously, leading to a proliferation of initiatives to define, approve, and enact data privacy laws. Each new initiative can benefit from the availability of the texts of existing laws (such as GDPR) that may influence how the jurisdiction\u2019s law is drafted. However, the sheer number of laws creates a challenge for compliance, especially when the business needs to keep track of the data, contexts, jurisdictions, locations, and scenarios in which data security and privacy need to be enforced according to each law. An example of this complication is differentiating between which consumers are covered and in which circumstances. In some cases, the residency status of the data subject is relevant. For example, a California consumer\u2019s data is subject to protection by the CCPA, but not by Virginia\u2019s data privacy law. In other cases, the types of data collected that are protected. For example, CCPA enumerates a variety of types of data that are protected, while the Virginia law specifies \u201cinformation that is linked or reasonably linkable to an identified or identifiable natural person.\u201d<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:200,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">Variation in Definitions<\/span><\/b><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"none\">These laws share intent to empower an individual with respect to protecting an individual\u2019s private information, but even slight variations in definition among the different laws can complicate efforts to categorize a data set\u2019s sensitivity classification as well as implementing data access controls. On example is the definitions of organizations that are subject to compliance. For example, CCPA defines \u201csale\u201d of data as \u201cselling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means a consumer&#8217;s personal information for monetary or other valuable consideration.\u201d VDCPA defines \u201csale\u201d of data as \u201cthe exchange of personal data for monetary consideration by the controller to a third party.\u201d In other words, the contexts for covered actions will differ based on the definitions. This means that the business may need to customize their governing policies according to the specific definitions provided in the different source laws. Consequently, it also means that organizations must configure their environments to operationally differentiate between compliance requirements depending on the characteristics of the transactions.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:200,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">Managing Exemptions<\/span><\/b><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"none\">All these laws describe scenarios in which the data protections are exempted or overruled such as for law enforcement or assurance against suppression of press freedom. At the same time, in most cases personal data can be used for the performance of a contract or compliance with a legal obligation, which both may come into play when a business provides customer support or honors a warranty for a purchased product. This means that literal interpretations of what is in the law (such as the \u201cright to be deleted\u201d) might not be adequate for correct implementation. The intent may be to allow the consumer to have personal data \u201cdeleted\u201d to prevent its use for targeted marketing. But supporting the exempted scenarios suggests that deletion be effected through some means (such as encryption) that is reversible under the appropriate circumstances.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:200,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">Managing Data Subject Preferences<\/span><\/b><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"none\">The organization must have a system\/means for logging and managing each data consumer\u2019s data protection preferences and ensuring that those preferences are observed. This implies managing an inventory of data subject preferences that can accommodate the specific rules for each source data privacy law along with the methods supporting each law\u2019s consumer preference notification mode (i.e., opt-in vs. opt-out).<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:200,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">Conveyance of Obligations<\/span><\/b><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"none\">Organizations that share data with third parties must convey the preferences of the data subjects whose data is being shared. In turn, data recipients would need to ensure that they acknowledge and will comply with all restrictions and consumer preferences. <\/span><span data-contrast=\"auto\">When one organization shares data with another, how does it communicate the consumer preferences associated with data privacy compliance?\u00a0 And how do you incorporate compliance with data obligations in a contract in an enforceable way?<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:200,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">Data Security is not the same as Data Protection<\/span><\/b><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Despite organizations\u2019 efforts at deploying perimeter security techniques to prevent data breaches, even the best firewalls can be breached by nefarious actors. Once that barrier has been crossed, though, any reachable data sets are subject to unauthorized access and use. This is complicated even more as companies migrate their data and applications to cloud data platforms.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:200,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A closer review of the comparison of the three laws reveals some inherent challenges associated with data protection and data privacy compliance, such as:\u00a0 Explosion of Data Privacy Laws Governments are taking data privacy rights seriously, leading to a proliferation of initiatives to define, approve, and enact data privacy laws. Each new initiative can benefit [&hellip;]<\/p>\n","protected":false},"author":441,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[11],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Six Key Cloud Data Privacy and Security Challenges\u00a0to Know<\/title>\n<meta name=\"description\" content=\"Knowledge Integrity, Inc. Principal David Loshin offers a look at some key cloud data privacy and security challenges.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Six Key Cloud Data Privacy and Security Challenges\u00a0to Know\" \/>\n<meta property=\"og:description\" content=\"Knowledge Integrity, Inc. Principal David Loshin offers a look at some key cloud data privacy and security challenges.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/\" \/>\n<meta property=\"og:site_name\" content=\"Solutions Review Thought Leaders\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-14T20:21:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-02-02T14:40:31+00:00\" \/>\n<meta name=\"author\" content=\"David Loshin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@davidloshin\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"David Loshin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/\",\"url\":\"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/\",\"name\":\"Six Key Cloud Data Privacy and Security Challenges\u00a0to Know\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#website\"},\"datePublished\":\"2023-07-14T20:21:20+00:00\",\"dateModified\":\"2024-02-02T14:40:31+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/a77d82d0f67b9e08808d48b31d9bc786\"},\"description\":\"Knowledge Integrity, Inc. Principal David Loshin offers a look at some key cloud data privacy and security challenges.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/thought-leaders\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cloud Data Privacy and Security Challenges Part 4: Cloud Data Privacy and Security Challenges\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#website\",\"url\":\"https:\/\/solutionsreview.com\/thought-leaders\/\",\"name\":\"Solutions Review Thought Leaders\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/thought-leaders\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/a77d82d0f67b9e08808d48b31d9bc786\",\"name\":\"David Loshin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4477fe35d87edece227287c8e83abb5f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4477fe35d87edece227287c8e83abb5f?s=96&d=mm&r=g\",\"caption\":\"David Loshin\"},\"description\":\"Recognized worldwide as an information management thought leader, David has popularized best practices for business intelligence, data governance, performance computing, master data management, predictive analytics, and data quality. David is a monthly columnist for TechTarget and frequently presents at The Data Warehousing Institute World Conferences, Enterprise Data World, the Data Governance and Information Quality conferences, and web-based seminars.\",\"sameAs\":[\"https:\/\/www.knowledge-integrity.com\/\",\"www.linkedin.com\/in\/david-loshin-4a961\/\",\"https:\/\/x.com\/davidloshin\"],\"url\":\"https:\/\/solutionsreview.com\/thought-leaders\/author\/david-loshin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Six Key Cloud Data Privacy and Security Challenges\u00a0to Know","description":"Knowledge Integrity, Inc. Principal David Loshin offers a look at some key cloud data privacy and security challenges.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Six Key Cloud Data Privacy and Security Challenges\u00a0to Know","og_description":"Knowledge Integrity, Inc. Principal David Loshin offers a look at some key cloud data privacy and security challenges.","og_url":"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/","og_site_name":"Solutions Review Thought Leaders","article_published_time":"2023-07-14T20:21:20+00:00","article_modified_time":"2024-02-02T14:40:31+00:00","author":"David Loshin","twitter_card":"summary_large_image","twitter_creator":"@davidloshin","twitter_misc":{"Written by":"David Loshin","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/","url":"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/","name":"Six Key Cloud Data Privacy and Security Challenges\u00a0to Know","isPartOf":{"@id":"https:\/\/solutionsreview.com\/thought-leaders\/#website"},"datePublished":"2023-07-14T20:21:20+00:00","dateModified":"2024-02-02T14:40:31+00:00","author":{"@id":"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/a77d82d0f67b9e08808d48b31d9bc786"},"description":"Knowledge Integrity, Inc. Principal David Loshin offers a look at some key cloud data privacy and security challenges.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/thought-leaders\/cloud-data-privacy-and-security-challenges-part-4-cloud-data-privacy-and-security-challenges\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/thought-leaders\/"},{"@type":"ListItem","position":2,"name":"Cloud Data Privacy and Security Challenges Part 4: Cloud Data Privacy and Security Challenges\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/thought-leaders\/#website","url":"https:\/\/solutionsreview.com\/thought-leaders\/","name":"Solutions Review Thought Leaders","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/thought-leaders\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/a77d82d0f67b9e08808d48b31d9bc786","name":"David Loshin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4477fe35d87edece227287c8e83abb5f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4477fe35d87edece227287c8e83abb5f?s=96&d=mm&r=g","caption":"David Loshin"},"description":"Recognized worldwide as an information management thought leader, David has popularized best practices for business intelligence, data governance, performance computing, master data management, predictive analytics, and data quality. David is a monthly columnist for TechTarget and frequently presents at The Data Warehousing Institute World Conferences, Enterprise Data World, the Data Governance and Information Quality conferences, and web-based seminars.","sameAs":["https:\/\/www.knowledge-integrity.com\/","www.linkedin.com\/in\/david-loshin-4a961\/","https:\/\/x.com\/davidloshin"],"url":"https:\/\/solutionsreview.com\/thought-leaders\/author\/david-loshin\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/posts\/598"}],"collection":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/users\/441"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/comments?post=598"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/posts\/598\/revisions"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/media?parent=598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/categories?post=598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/tags?post=598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}