惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
aimingoo的专栏
aimingoo的专栏
P
Proofpoint News Feed
宝玉的分享
宝玉的分享
MyScale Blog
MyScale Blog
The GitHub Blog
The GitHub Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
月光博客
月光博客
量子位
博客园 - 司徒正美
V
V2EX
I
InfoQ
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Vercel News
Vercel News
H
Hackread – Cybersecurity News, Data Breaches, AI and More
美团技术团队
N
Netflix TechBlog - Medium
L
LangChain Blog
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Stack Overflow Blog
Stack Overflow Blog
A
About on SuperTechFans
Microsoft Azure Blog
Microsoft Azure Blog

Privacy Ref

Privacy Ref expands IAPP OTP to Bermuda and Caribbean Privacy Ref announces new partnership with Tenrec Welome to Privacy Ref Academy CIPP/US Training at The Florida Bar Annual Meeting Certificate in Data Privacy and Protection Univ. of Technology, Jamaica, and Privacy Ref launch Data Privacy Training Initiative The need to verify Policy Compliance Privacy Ref named one of the Best Data Privacy Service Providers in the U.S. Massachusetts bill follows latest Privacy Law standards Personal Privacy Tips Bring AI into the Privacy Program in 2025
Thoughts after the IAPP GPS
Bob Siegel · 2025-05-12 · via Privacy Ref

The 2025 IAPP Global Privacy Summit confirmed what many of us in the industry already recognize: privacy has evolved from a compliance function into a strategic business priority. As someone who had the privilege of teaching Privacy Program Management for the CIPM (Certified Information Privacy Manager) designation at Summit, I was struck by how many professionals are grappling with the same challenge: how to operationalize privacy in a way that is scalable, efficient, and aligned with business growth.

Artificial intelligence dominated the conversation at this year’s Summit. Trevor Hughes, president and CEO of the IAPP, emphasized that for privacy professionals this is the time of the “&”. Organizations are depending upon their privacy team to take on a myriad of governance challenges. For example, with the EU AI Act and a wave of state-level regulation emerging in the U.S., organizations are scrambling to govern AI systems in line with privacy principles. Falling on the shoulders of privacy professionals, this is giving us the charter of Privacy & AI governance. The challenge? Most of us lack the tools to assess AI risks like bias, opacity, and data provenance.

Privacy and AI are only two areas of data usage where some level of governance is required. Many larger organizations have Data Governance teams that take a holistic view of their information use including legal compliance. I suggest that the same talents that make privacy professionals attractive for governing organizations’ AI efforts may also be applied to data governance in general.

Think of data governance as a framework of rules, policies, standards, processes, and controls that dictate how an organization manages its data assets throughout their lifecycle. Key principles underpinning data governance include accountability, transparency, data quality, data security, stewardship, and business alignment. Data governance’s primary goals are to ensure data is accurate, consistent, secure, available, and usable for informed decision-making, operational efficiency, regulatory compliance, and risk management.

This may seem as a parallel to the focus to that of a privacy program, however the scope of a privacy program is limited to personal information where data governance looks at all information assets.

Just as with AI governance, expanding into general data governance will require privacy professionals to take broader view of information systems. It will also require privacy professionals to gain some new perspectives and insight into new practices.

Notwithstanding the above, the basic requirements of establishing or validating a privacy program remain a challenge for some organizations. Teaching the CIPM class this year gave me the opportunity to connect directly with professionals working hard to build programs that are both compliant and resilient. What I heard again and again is that organizations need help translating privacy principles into operational practice. Advisory services provided by third parties are no longer a “nice to have” they are an essential part of how privacy gets done. Addressing privacy obligations through a comprehensive program is a great first step to preparing your organization for a more encompassing data governance program.

In a world where data is power, privacy and data governance are foundational need and done right, it’s also a competitive advantage.