Other meanings of Data privacy
INFORMATION GOVERNANCE
Data privacy is the protection and proper handling of personal and sensitive information. It concerns what information is collected, why it is collected, how it is used and shared, how long it is retained, and what rights people have over it. Privacy is distinct from cybersecurity: cybersecurity protects information and systems from unauthorized access, while privacy governs appropriate collection and use even when access is technically authorized.1
Data privacy governs the lifecycle of information that can identify, describe, locate, or be linked to a person. Personal data may include names, identification numbers, device identifiers, location records, photographs, health information, financial details, and inferred characteristics. Some laws apply additional safeguards to sensitive categories such as medical, biometric, genetic, racial, or political information.2
Privacy decisions begin before collection. An organization should establish a specific purpose, collect only what is necessary, explain its practices clearly, and avoid using information in ways that conflict with the original purpose. Good governance also covers accuracy, retention limits, deletion, access controls, contracts with service providers, and procedures for responding to incidents and individual requests.
Modern privacy laws increasingly give individuals enforceable rights over information about them. The European Union's General Data Protection Regulation provides rights including access, rectification, erasure in defined circumstances, restriction of processing, data portability, and objection to certain processing.3 These rights are balanced against legal duties, freedom of expression, public interest, and the rights of others.
Legal models differ across jurisdictions. The United States uses a mixture of sector-specific federal laws, state statutes, and regulatory enforcement; the Health Insurance Portability and Accountability Act addresses protected health information in specified healthcare contexts, while the Children's Online Privacy Protection Act imposes requirements on services directed to children under 13.4 Consent is one lawful basis for processing, but it is not the only one and is not meaningful when obtained through deception or coercion.
Effective privacy depends on organizational governance as well as technical security. A privacy program commonly assigns responsibility, inventories data flows, classifies sensitive information, evaluates vendors, documents purposes and retention periods, and conducts privacy impact assessments for higher-risk projects. Privacy by design places these considerations into product development rather than treating them as an afterthought.5
Technical measures include data minimization, pseudonymization, encryption, access logging, role-based permissions, deletion automation, and separation of identifying information from analytical datasets. These controls reduce exposure but do not make data anonymous by themselves: seemingly harmless fields can be combined to re-identify people. A breach therefore represents both a security failure and a possible privacy violation, while lawful access can still become harmful through excessive collection or unexpected secondary use.
Privacy risks often arise from inference rather than from the direct disclosure of a name. Purchase histories, mobility traces, search behavior, and device signals can reveal health conditions, relationships, or political interests; aggregated data may also become identifying when combined with outside datasets. Automated decisions create a related concern because a person may be profiled without seeing the underlying data or understanding how an inference was made.
Children, patients, workers, migrants, and people using public services can face unequal consequences when refusing data collection is impractical. De-identification is therefore a risk-reduction technique, not a universal guarantee. International data transfers add another layer: organizations must assess legal protections, onward disclosures, and the ability of individuals to exercise rights across borders.3 Strong privacy practice ultimately combines restraint, transparency, accountability, and meaningful remedies.
Legal obligations vary by jurisdiction, sector, data type, and the role of the organization handling the information.
Help improve the encyclopedia. Reports go straight to the site manager.