Trends in Data Protection

Explore top LinkedIn content from expert professionals.

  • View profile for Dr. Barry Scannell
    Dr. Barry Scannell Dr. Barry Scannell is an Influencer

    AI Law & Policy | Partner in Leading Irish Law Firm William Fry | Appointed to Irish AI Advisory Council | Member of the Board of Irish Museum of Modern Art | PhD in AI & Copyright

    61,755 followers

    HUGE AI LEGAL NEWS! The European Data Protection Board (EDPB) has published its much anticipated Opinion on AI and data protection. The opinion looks at 1) when and how AI models can be considered anonymous, 2) whether and how legitimate interest can be used as a legal basis for developing or using AI models, and 3) what happens if an AI model is developed using personal data that was processed unlawfully. It also considers the use of first and third-party data. The opinion also addresses the consequences of developing AI models with unlawfully processed personal data, an area of particular concern for both developers and users. The EDPB clarifies that supervisory authorities are empowered to impose corrective measures, including the deletion of unlawfully processed data, retraining of the model, or even requiring its destruction in severe cases. On the issue of anonymity, the opinion grapples with the question of whether AI models trained on personal data can ever fully transcend their origins to be considered anonymous. The EDPB highlights that merely asserting that an AI model does not process personal data is insufficient. Supervisory authorities (SAs) must assess claims of anonymity rigorously, considering whether personal data has been effectively anonymised in the model and whether risks such as re-identification or membership inference attacks have been mitigated. For AI developers, this means that claims of anonymity should be substantiated with evidence, including the implementation of technical and organisational measures to prevent re-identification. On legitimate interest as a legal basis for AI, the opinion offers detailed guidance for both development and deployment phases. Legitimate interest under Article 6(1)(f) GDPR requires meeting three cumulative conditions: pursuing a legitimate interest, demonstrating that processing is necessary to achieve that interest, and ensuring the processing does not override the fundamental rights and freedoms of data subjects. For third-party data, the opinion emphasises that the absence of a direct relationship with the data subjects necessitates stronger safeguards, including enhanced transparency, opt-out mechanisms, and robust risk assessments. The opinion’s findings stress that the balancing test under legitimate interest must consider the unique risks posed by AI. These include discriminatory outcomes, regurgitation of personal data by generative AI models, and the broader societal risks of misuse, such as through deepfakes or misinformation campaigns. The opinion also provides examples of mitigating measures that could tip the balance in favour of controllers, such as pseudonymisation, output filters, and voluntary transparency initiatives like model cards and annual reports. The implications for developers are significant: compliance failures in the development phase can render an entire AI system non-compliant, leading to legal and operational challenges.

  • View profile for Marie-Doha Besancenot

    Senior advisor for Strategic Communications, Cabinet of 🇫🇷 Foreign Minister; #IHEDN, 78e PolDef

    42,205 followers

    🗞️ Needed report By CyberArk on a burning issue : identity security. A decisive element that will determine our ability to restore digital trust. 🔹 « Identity is now the primary attack surface. » Defenders must secure every identity — human and machine 🔹 with dynamic privilege controls, automation, and AI-enhanced monitoring 🔹and prepare now for LLM abuse and quantum disruption. Machine identities are the fastest-growing attack surface 🔹Growth outpaces human identities 45:1. 🔹Nearly half of machine identities access sensitive data, yet 2/3of organizations don’t treat them as privileged. Quantum readiness is urgent 🔹Quantum computing will break today’s cryptography (RSA, TLS, identity tokens). 🔹Transition planning to quantum-safe algorithms must start now, even before standards are finalized. Large Language Models include prompt injection, data leakage, and misuse of AI agents. So organizations must treat them as a new class of machine identity requiring monitoring, access controls, and secrets management. 🧰 What can we do? ⚒️ 1/ Implement Zero Standing Privileges (ZSP) • Remove always-on entitlements; grant access dynamically and just-in-time. • Minimize lateral movement by revoking privileges once tasks are complete 👥2/ Secure the full spectrum of identities • Differentiate controls for workforce, IT, developers, and machines. • Prioritize machine identities: vault credentials, rotate secrets, and eliminate hard-coded keys. 🛡️ 3/ Embed intelligent privilege controls • Apply session protection, isolation, and monitoring to high-risk access. • Enforce least privilege on endpoints; block or sandbox unknown apps. • Deploy Identity Threat Detection & Response (ITDR) for continuous monitoring. ♻️ 4/ Automate identity lifecycle management • Use orchestration to onboard, provision, rotate, and deprovision identities at scale. • Relieve staff from manual tasks, counter skill shortages, and improve compliance readiness. 5/ Align security with business and regulatory drivers • Build an “identity fabric” across IAM, PAM, cloud, SaaS, and compliance. • Tie metrics (KPIs, ROI, cyber insurance conditions) to board-level priorities. 6/ Prepare for next-generation threats • Establish AI/LLM security policies: control access, monitor usage, audit logs. • Begin phased adoption of post-quantum cryptography to protect long-lived sensitive data. Enjoy the read

  • View profile for Pradeep Rao
    Pradeep Rao Pradeep Rao is an Influencer

    Director @ Kyndryl || Peer Community Ambassador @ Gartner || Ambassador @ AWS || Certified Independent Director - Indian Institute of Corporate Affairs (IICA)

    28,136 followers

    🔐 𝐎𝐧𝐞 𝐏𝐚𝐬𝐬𝐰𝐨𝐫𝐝 𝐭𝐨 𝐑𝐮𝐥𝐞 𝐓𝐡𝐞𝐦 𝐀𝐥𝐥? 𝐍𝐨𝐭 𝐀𝐧𝐲𝐦𝐨𝐫𝐞. A recent study found that 1 𝐢𝐧 5 𝐈𝐧𝐝𝐢𝐚𝐧𝐬 𝐬𝐭𝐢𝐥𝐥 𝐫𝐞𝐮𝐬𝐞 𝐭𝐡𝐞 𝐬𝐚𝐦𝐞 𝐩𝐚𝐬𝐬𝐰𝐨𝐫𝐝 𝐚𝐜𝐫𝐨𝐬𝐬 𝐚𝐥𝐥 𝐩𝐞𝐫𝐬𝐨𝐧𝐚𝐥 𝐚𝐜𝐜𝐨𝐮𝐧𝐭𝐬. That’s not just a statistic — it’s a red flag. While passwords remain the dominant gatekeeper, they're rapidly becoming the weakest link. The future of identity is shifting from “what you know” to who you are — with biometrics, behavioral analytics, and passwordless technologies paving the way. But adoption still lags behind intent. As digital adoption surges, so does our attack surface. As a cybersecurity leader,  I believe 𝐰𝐞 𝐦𝐮𝐬𝐭 𝐫𝐞𝐭𝐡𝐢𝐧𝐤 𝐭𝐡𝐞 𝐛𝐚𝐥𝐚𝐧𝐜𝐞 𝐛𝐞𝐭𝐰𝐞𝐞𝐧 𝐜𝐨𝐧𝐯𝐞𝐧𝐢𝐞𝐧𝐜𝐞 𝐚𝐧𝐝 𝐜𝐨𝐧𝐭𝐫𝐨𝐥. The next frontier demands 𝐟𝐫𝐢𝐜𝐭𝐢𝐨𝐧-𝐬𝐦𝐚𝐫𝐭 𝐢𝐝𝐞𝐧𝐭𝐢𝐭𝐲 𝐬𝐲𝐬𝐭𝐞𝐦𝐬 that inspire trust, not fatigue. 💬 𝐇𝐞𝐫𝐞'𝐬 𝐚 𝐪𝐮𝐞𝐬𝐭𝐢𝐨𝐧 𝐰𝐨𝐫𝐭𝐡 𝐝𝐞𝐛𝐚𝐭𝐢𝐧𝐠: 𝐈𝐧 𝐚 𝐡𝐲𝐩𝐞𝐫-𝐜𝐨𝐧𝐧𝐞𝐜𝐭𝐞𝐝 𝐰𝐨𝐫𝐥𝐝, 𝐬𝐡𝐨𝐮𝐥𝐝 𝐠𝐨𝐯𝐞𝐫𝐧𝐦𝐞𝐧𝐭𝐬/𝐫𝐞𝐠𝐮𝐥𝐚𝐭𝐨𝐫𝐬 𝐬𝐭𝐚𝐫𝐭 𝐦𝐚𝐧𝐝𝐚𝐭𝐢𝐧𝐠 𝐩𝐚𝐬𝐬𝐰𝐨𝐫𝐝𝐥𝐞𝐬𝐬 𝐚𝐮𝐭𝐡𝐞𝐧𝐭𝐢𝐜𝐚𝐭𝐢𝐨𝐧 𝐟𝐨𝐫 𝐜𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐚𝐩𝐩𝐬 — 𝐨𝐫 𝐢𝐬 𝐭𝐡𝐚𝐭 𝐚 𝐝𝐚𝐧𝐠𝐞𝐫𝐨𝐮𝐬 𝐨𝐯𝐞𝐫𝐫𝐞𝐚𝐜𝐡? I’m listening 👇 #Cybersecurity #DigitalIdentity #PasswordlessFuture #CISOInsights #IndiaTech #ZeroTrust #DigitalTrust

  • View profile for Dr. Kartik Nagendraa

    CMO, LinkedIn Top Voice, Coach (ICF Certified), Author

    10,922 followers

    The trust economy is replacing the attention economy.✅ Marketers have long treated data as their superpower- the more you collect, the sharper your targeting. But as privacy laws evolve, that mindset is hitting a wall. New regulations are redrawing the boundaries of what’s fair, ethical, and legal in data use. Hyper-personalisation still matters. It drives relevance, loyalty, and conversion. Yet creating these experiences while respecting privacy has become the new balancing act. The line between helpful and invasive is thinner than ever. The smartest brands are already adapting. They’re moving from surveillance to service - collecting less, but using it better. They’re making consent experiences simple, data use transparent, and value exchange visible. Instead of chasing clicks, they’re building credibility. Here’s what that looks like in practice: 👉🏻 Audit every data point you collect. If it doesn’t add clear value to the customer, drop it. 👉🏻 Be upfront about how and why you use data. Transparency builds confidence. 👉🏻 Trade access for value - early previews, useful insights, or improved recommendations. Privacy is no longer just about compliance. It’s the foundation of modern marketing trust. The brands that will thrive aren’t those who know the most about their customers but those whose customers choose to share more with them. #futureofmarketing

  • View profile for Vishal Chopra

    Data Analytics & Excel Reports | Leveraging Insights to Drive Business Growth | ☕Coffee Aficionado | TEDx Speaker | ⚽Arsenal FC Member | 🌍World Economic Forum Member | Enabling Smarter Decisions

    19,144 followers

    As businesses integrate AI into their operations, the landscape of data governance and privacy laws is evolving rapidly. Governments worldwide are strengthening regulations, with frameworks like GDPR, CCPA, and India’s DPDP Act setting higher compliance standards. But as AI becomes more embedded in decision-making, new challenges arise: 🔍 Key Trends in Data Governance & Privacy Compliance ✔ Stricter AI Regulations: The EU AI Act mandates greater transparency, accountability, and ethical AI deployment. Businesses must document AI decision-making processes to ensure fairness. ✔ Beyond GDPR: Laws like China’s PIPL and Brazil’s LGPD signal a global shift toward tougher data protection measures. ✔ AI and Automated Decisions Scrutiny: Regulations are focusing on AI-driven decisions in areas like hiring, finance, and healthcare, demanding explainability and fairness. ✔ Consumer Control Over Data: The push for data sovereignty and stricter consent mechanisms means businesses must rethink their data collection strategies. 💡 How Businesses Must Adapt To remain compliant and build trust, companies must: 🔹 Implement Ethical AI Practices: Use privacy-enhancing techniques like differential privacy and federated learning to minimize risks. 🔹 Strengthen Data Governance: Establish clear data access controls, retention policies, and audit mechanisms to meet compliance standards. 🔹 Adopt Proactive Compliance Measures: Rather than reacting to regulations, businesses should embed privacy-by-design principles into their AI and data strategies. In this new era of ethical AI and data accountability, businesses that prioritize compliance, transparency, and responsible AI deployment will gain a competitive advantage. 𝑰𝒔 𝒚𝒐𝒖𝒓 𝒃𝒖𝒔𝒊𝒏𝒆𝒔𝒔 𝒓𝒆𝒂𝒅𝒚 𝒇𝒐𝒓 𝒕𝒉𝒆 𝒏𝒆𝒙𝒕 𝒘𝒂𝒗𝒆 𝒐𝒇 𝑨𝑰 𝒂𝒏𝒅 𝒑𝒓𝒊𝒗𝒂𝒄𝒚 𝒓𝒆𝒈𝒖𝒍𝒂𝒕𝒊𝒐𝒏𝒔? 𝑾𝒉𝒂𝒕 𝒔𝒕𝒆𝒑𝒔 𝒂𝒓𝒆 𝒚𝒐𝒖 𝒕𝒂𝒌𝒊𝒏𝒈 𝒕𝒐 𝒔𝒕𝒂𝒚 𝒂𝒉𝒆𝒂𝒅? #DataPrivacy #EthicalAI #datadrivendecisionmaking #dataanalytics

  • View profile for Martyn Redstone

    Head of Responsible AI & Industry Engagement @ Warden AI | AI Governance for HR, Recruitment, Staffing & HR Technology

    22,255 followers

    Forget employees experimenting with ChatGPT on their lunch breaks. That is yesterday's shadow AI problem. The more systemic risk facing HR and People teams right now is institutional shadow AI, and it is built directly into your standard software supply chain. For years, procurement teams have treated the standard Data Processing Agreement (DPA) as a definitive legal shield. If a vendor signed on the dotted line, the compliance box was checked. DataGrail’s 2026 Privacy and AI Trends Report (attached) suggests this compliance model is fractured. Out of 2,400 business software providers surveyed, 63.6% of vendors marketing AI capabilities failed to disclose their third-party AI subprocessors in their legal documentation. This means the talent acquisition platform or resume-screening tool you recently onboarded is likely routing sensitive applicant data into backend foundational models that your data protection team has never reviewed, vetted, or approved. From a Governance, Risk and Compliance perspective, this creates three distinct friction points: 1️⃣ First, it creates an auditability blind spot. Roughly 20.7% of these undisclosed systems power Automated Decision-Making (ADM). If a backend model quietly filters out a candidate pool, you cannot audit it for systemic bias. If a regulator investigates your hiring practices, pointing to an incomplete vendor DPA will not shift the liability away from your organization. 2️⃣ Second, the regulatory landscape is shifting toward personal accountability. Under updated compliance frameworks (like the CCPA’s risk assessment rule) executives are increasingly required to personally sign off on AI data safety. If your HR platform is quietly exposing PII to unvetted models, that structural risk rests on executive shoulders. 3️⃣ Finally, there is an operational logjam. The "Jobs & Professional Development" sector currently faces the highest volume of data deletion requests nationwide (US only), averaging 365 per month. Trying to manually track down and purge candidate records across an unmapped web of hidden software pipelines is driving up compliance costs, with mid-market companies spending an estimated $1.5 million annually just to manage the operational mess. The assumption that your HR tech vendors are inherently protecting your data is no longer a viable risk strategy. If you are navigating AI integration right now, the play is to shift from passive contract reviews to active technical verification. Do not stop reviewing DPAs, but ensure they require a technically verifiable map of every backend model and subprocessor your vendors actually use. The organizations that navigate the next wave of regulatory enforcement successfully won't be those with the thickest policy binders. They will be the ones that ensure their legal contracts match their engineering realities.

  • View profile for Winnie Ngige., FIP (CIPM, CIPP/E)

    Global Data Protection Officer leading compliance in (EU, UK, Africa, APAC) | AI Governance |CIPP/E | CIPM| FIP I help build defensible and scalable privacy and AI Governance programs across multiple jurisdictions.

    6,651 followers

    From a data protection perspective, the question of digital IDs and what constitutes a successful implementation remains a crucial topic of discussion. Despite the Data Protection Act (DPA) 2019 outlining clear requirements on protection of personal data, we have observed a troubling trend where the government has repeatedly flouted these mandates with minimal consequences. The recent rebranding of the project from Huduma Namba to Maisha Namba, despite ongoing privacy concerns and the recent court injunction halting its rollout, raises serious questions. Is compliance with and enforcement of the Act solely the burden of the private sector, while the government remains largely unaccountable? The recent injunction reflects broader issues, including privacy concerns and the lack of inclusivity for undocumented citizens, who face significant barriers due to bureaucratic processes and stringent vetting requirements. These challenges underscore the need for a robust framework that ensures both privacy and inclusivity in the implementation of digital IDs. This toolkit by Africa Digital Rights' Hub offers guidelines for both government and businesses involved in implementing digital IDs. It proposes the following: 📌Organizational Accountability: The implementing organization must establish clearly defined structures, including robust privacy management frameworks. A responsible individual, such as a Data Protection Officer (DPO) or Privacy Risk Manager, should be designated to oversee privacy issues and advocate for the privacy rights of individuals affected by the digital ID system. Additionally, privacy by design and default must be integral to the development of these systems. 📌Consultation with Supervisory Authorities: It is imperative that relevant supervisory authorities are consulted before the rollout of digital ID systems. These consultations should cover a range of issues, including guidance on conducting Privacy Impact Assessments (PIAs) or Data Protection Impact Assessments (DPIAs). 📌Third-Party Management: Given that many digital ID systems and platforms are developed or managed by third parties, including those outside the country, it is crucial for the government or implementing institution to conduct thorough due diligence on these third parties to ensure compliance with privacy standards. 📌Measuring, Monitoring, Auditing, and Improvement: Privacy risks must be identified, and appropriate controls should be put in place to mitigate these risks. These controls must be regularly reviewed and updated to ensure ongoing compliance and improvement. Additionally, for a digital ID to be successful, it is essential to implement fundamental privacy principles, such as data minimization, purpose limitation, and transparency. These principles are key to building public trust and ensuring that digital IDs are inclusive, secure, and respectful of individuals' privacy rights. #dataprotection #digitalrights #compliance

  • View profile for Martin Zwick

    Lawyer | AIGP | CIPP/E | CIPT | FIP | GDDcert.EU | DHL Express Germany | IAPP Advisory Board Member

    22,199 followers

    GDPR enforcement: Mark 2 April 2027 in your calendar The final text of the procedural rules for cross-border GDPR enforcement are now published as Regulation (EU) 2025/2518 in the Official Journal. The Regulation will enter into force in 20 days and will apply from 2 April 2027. What changes: 1) Uniform complaint admissibility across the EU for cross‑border cases. 2) Procedural rights clarified: complainants and investigated organisations have the right to be heard at key stages and to comment on preliminary findings before a final decision. 3) Access to procedural information: complainants gain access to relevant information and files. 4) Binding timelines to reduce delays: investigations to be completed within 15 months (extendable by 12 months for complex cases); 12 months for simpler cases resolved via cooperation. 5) Simplified cooperation & early resolution: streamlined handling for straightforward cases and early closure where the infringement has been remedied and the complainant does not object. 6) Early sharing by the LSA: the lead supervisory authority will share early summaries to help build consensus across DPAs. What organisations should do now: 1) Map cross‑border complaint touchpoints and align intake criteria and templates. 2) Prepare to respond to preliminary findings quickly and substantively; organise evidence files for timely submissions. 3) Adjust internal case‑management timelines to reflect DPA deadlines and likely earlier, structured information requests. 4) Enable early‑resolution workflows (e.g., rapid remediation + complainant communication) where appropriate. 5) Brief senior stakeholders that these are procedural changes and material GDPR obligations remain unchanged, but pace and transparency will increase.

  • View profile for Matthew Ball

    Chief Analyst at Omdia | Cybersecurity channel strategy and competitive intelligence | Keynote speaker and webinar host

    5,890 followers

    The Canalys (part of Omdia) Cybersecurity Titans Index rose 14.6% in Q2, below last quarter’s 15.4% but above the high-end forecast of 14.3%. This pushed combined revenue to a record $13.47 billion, with 13 of 18 vendors surpassing their high-end revenue guidance, highlighting the sector's strength amid economic headwinds. The 18 Titans (who's core business is security and publish a security revenue number each quarter) include: • Akamai TechnologiesCheck Point SoftwareCiscoCloudflareCrowdStrikeCyberArkElasticF5FortinetOktaPalo Alto NetworksQualysRapid7SentinelOneTenableTrend MicroVaronisZscaler Platform consolidation remained the Titans’ core strategic priority to drive larger deals and capture more customer spend. This approach has fueled robust ARR momentum, with several vendors hitting significant milestones: CrowdStrike reached $4.7B ARR (targeting $10B by FY2031), Palo Alto Networks' NGS ARR hit $5.6B (targeting $15B by FY2030), Zscaler surpassed $3B, and SentinelOne crossed $1B. Flexible purchasing programs have become increasingly important, with multi-year frameworks streamlining procurement of additional modules. CrowdStrike's Falcon Flex has attracted over 1,000 customers, while Zscaler's Z-Flex generated more than $100M in TCV bookings. SentinelOne and Qualys launched their versions this quarter. Other key trends is the ongoing industry shift from reactive to proactive security, with exposure management gaining significant traction. Simultaneously, AI has become a dual focus area—both enhancing security capabilities and requiring protection itself. Strategic partnerships with NVIDIA and targeted acquisitions like SentinelOne's purchase of Prompt Security underscore this trend. Identity security has emerged as the next platform frontier, evidenced by Palo Alto Networks' $25B acquisition of CyberArk. This segment is undergoing rapid consolidation as specialists integrate various functions (SSO, MFA, PAM, IGA) into unified platforms, while broader platform players incorporate identity security capabilities into their offerings. Throughout these transitions, partner ecosystems remain critical, with investment in expansion and enablement strategic priorities. Partner-led sales for the Titans continued to outpace direct sales. Looking ahead, the Titans Index is projected to grow between 11.8% and 14.0% in Q3, with full-year 2025 growth expected at 13.7%, compared to 13.5% for 2024. Eight vendors have already raised their full-year guidance, reflecting improved pipeline visibility despite continued market caution.

  • View profile for Mihaela Curca

    Cybersecurity Project Manager | Researcher | Political analyst | Human

    21,924 followers

    The Cybersecurity Forecast 2025 report highlights key trends and predictions in the global #cybersecurity landscape for the coming year and underscores the dual-edged role of #AI, highlighting its potential to both enhance cybersecurity defenses and empower sophisticated attackers. Key Trends: 1. Artificial Intelligence (AI): • Attackers increasingly use AI for advanced phishing, #deepfake-based fraud, and vulnerability discovery. • Defensive AI tools are evolving to automate threat detection and reduce workload for cybersecurity teams. 2. Major Threat Actors: • Russia: Continued focus on #cyberespionage and critical infrastructure attacks, especially around the Ukraine conflict. • China: Aggressive espionage using custom #malware and targeting elections globally. • Iran: Persistent regional cyber threats and espionage tied to #geopolitical conflicts. • North Korea: Focus on #cryptocurrency theft and supply chain compromises. 3. Global Cybercrime: • #Ransomware remains a top threat, with multifaceted extortion tactics causing disruptions in critical sectors like healthcare. • The rise of infostealer malware makes data breaches easier for attackers using stolen credentials. 4. Emerging Technologies: • Growing interest in #cloud security as organizations shift operations to the cloud. • Accelerated adoption of post-quantum cryptography to address potential #quantum computing threats. • Increased targeting of #Web3 and cryptocurrency platforms for financial gain. 5. Regulatory Changes: • Stricter regulations like the #NIS2 directive in Europe push for improved cybersecurity in essential and critical services. Recommendations for Organizations: • Adopt proactive cybersecurity strategies, including cloud-native security tools and robust identity management. • Prepare for new #encryption standards to counter quantum threats. • Invest in continuous monitoring and threat intelligence to stay ahead of evolving threats.

Explore categories