Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

Veeamon Tour'26 - Data & AI Trust CONVERGE for the Agentic Era

View
Play Video
Contributors

Anas Baig

Product Marketing Manager at Securiti

Muhammad Faisal Sattar

Director of Product Legal & Global Data Compliance

FIP, CIPT, CIPM, CIPP/Asia

Published February 28, 2023 / Updated June 9, 2026

Listen to the content

Increasingly, individuals are asking about and learning the importance of their privacy rights across the globe. They are beginning to inquire about the privacy of their personal information, its integrity, how it is collected and being used, and, more importantly, its security.

Similarly, nations seem to be united on protecting the integrity and privacy of consumers’ personal information by regulating the data through privacy laws. Privacy was first noted as a fundamental right by the United Nations in 1948, the European Union wrote a convention in 1985, and since then, many laws have been enacted, including the EU’s General Data Protection Regulation (GDPR) that came into force in 2018 and California’s CCPA, which came into force in 2020.

Each law has differences around definitions of what is considered personal data (or in the USA, PII), the lawful basis for collection of personal data (consent, contract, vital interests, etc.), automated decision-making using that data, and processing, including whether, how, and when data can be transferred to third parties. These laws also provide rights to the individuals concerned so that they have the right of access, remediation, and deletion of data held.

New laws are coming into force on a regular basis - see our global map of privacy laws for the latest information on each country and state. Violations of these laws can result in bad publicity, millions of dollars in fines, class action lawsuits from individuals, and other penalties that may include imprisonment in some countries.

Take, for instance, the EU GDPR’s record-breaking fine of $865 Million on Amazon for violating the regulations associated with obtaining data subject consent.

Where does data privacy fit in all that? Why is it important for businesses in the GDPR or CCPA era? What is its role in regulatory compliance?

Data privacy is the resulting payoff of all those consumers’ concerns regarding the use of their personal information, the growth of data that keeps multiplying ceaselessly, and the increasing number of regulatory requirements.

This guide will discuss the definition of data privacy, its importance, role in compliance, challenges, and some best practices.

Definition of Data Privacy

In a broader sense, data privacy is the general right of every individual to be free from any prying or intervention. In plain terms, they have the right to be left to their affairs. In the internet-centric sense, data privacy is the principle of giving control of the flow of personal information (PI) to an individual. They have the right to know how their PI is collected, processed, and treated. They have the right to inquire about the third parties with whom the PI is shared. They also have the right to ensure that their data is being protected or kept private.

In the age of digitalization, there’s a seemingly never-ending growth in the collection and generation of data – It is reported to hit 175 zettabytes of data by 2025. Businesses are collecting users’ data at various touch points throughout their interactions. The same data is then broken down, refined, and analyzed to make critical decisions, improve users’ experience, and feed innovations.

In the United States, “Data Privacy” is the term used in policies, laws, and regulations. However, in the European Union and other countries, the term “Data Protection” is used in laws, regulations, and policies. The common understanding is that data protection is a wider term that includes all areas from theory, practice, and implementation, for example, includes references to the use of data (such as automated decision making), where privacy is more narrowly focused on the individual elements collected and used. Honestly, though, in many documents, the two terms are used interchangeably.

Types of Data Privacy

Since data privacy isn’t a hard and fast science, it is hard to describe it objectively. Similarly, it is just as hard to extract its various types. However, the most important and frequently mentioned categories include the following:

a. Financial

Financial information, such as credit card information, shared with an organization as part of a transaction or for any other purpose, is sensitive and needs to be appropriately protected.

b. Medical

A user’s medical history, such as details related to medical treatment in the past or the medications they’re on, is vital information. As such, this information must be protected and appropriately secured against any unconsented sharing of such data with third parties.

c. Biometric

Owing to technological advances, users now rely on biometric information as login credentials for everything ranging from their smartphones to their financial PIN codes. Hence, such data is highly valuable while being sensitive simultaneously, requiring appropriate measures to protect it at all times.

d. Political/Religious

This is information that websites, primarily social media sites, can discern about an individual based on their interactions with others and content on the platform. However, such discernment about a user’s political or religious beliefs does not free the organization from its obligations to maintain the privacy of such data by taking the appropriate measures.

The Importance of Data Privacy

Data is inarguably the ultimate driving component in various sectors. The internet giants have all built their empire atop the data that they have been collecting and processing for many years. The data economy keeps getting larger with the growing technological advances associated with the proliferation of data and its collection.

Customers are now considering data privacy as one measure of an organization that they consider before they do business with it. Organizations with a sound data privacy strategy and framework are able to reduce data breaches by a significant margin. A lower number of breaches gives organizations a better chance at upholding that trust. With a reduced number of breaches, organizations can prevent heavy fines, penalties, and civil lawsuits.

The Different Laws That Govern Data Privacy

As technologies around the collection of data have improved over the years, governments across the globe have started regulating how organizations treat personal information. There are now multiple global and regional laws that govern how organizations collect information, process it, and protect it. According to UN Trade and Development UNCTAD, as of 2024, privacy laws now cover the personal information of over 80% of the global population, with over 137 countries having enacted dedicated data protection legislation.

Let’s take a look at some of the most prominent data privacy laws:

Schedule Your
Personal Demo

Learn how you can leverage Securiti’s DataAI Command Platform to address data security, privacy, governance, and compliance.

See a demo
Schedule your demo today

a. Online Data Privacy

CCPA

The California Consumer Privacy Act (CCPA, soon to be CPRA) regulates how consumers’ personal information is collected and treated. The privacy law applies to businesses operating within or outside of California offering products and services to consumers living in California. The CCPA impacts over 40 million California residents and 0.5 million businesses in California. Amongst the many privacy rights that CCPA bestows on consumers, the right to opt-out ensures businesses do not sell consumers’ personal information. Businesses are required to set up a “Do Not Sell My Information” button on their website to comply with this right.

GDPR

The General Data Protection Regulation (GDPR) is by far the most comprehensive privacy and data protection law in the world, inspiring many other countries to follow up on the provisions provided under GDPR. The regulation is based on the EU Charter of Fundamental Rights, which considers the protection of an individual’s personal data as a basic human right. GDPR considers that in all cases the individual “owns” their data, and any time it is used by an organization, it is only on loan, and the individual can ask for data access, data update, data deletion, and that the data can only be used for the purpose it was initially collected.

The GDPR has set a broader definition of personal data and imposed strict regulations on data collection, storage, processing, access, security, and transfer. The GDPR applies to all organizations operating within or outside the EU regions dealing with the personal data of individuals living in the EU.

CPRA

The California Privacy Rights Act (CPRA) is an upgraded version of the CCPA, which went into effect on January 1, 2023. The new Privacy Act has amended data privacy rights by modifying and introducing additional consumer rights. Amongst the many other additions, the CPRA has also introduced a new category of personal information, i.e., sensitive personal information (SPI), mandating businesses to only use SPI for limited purposes, and at the same time, enabling consumers to restrict businesses from any other uses. The new law will be enforced by the California Privacy Protection Agency (CPPA).

LGPD

The Brazilian Lei Geral de Proteção de Dados Pessoais (LGPD) models most of its provisions after the EU GDPR. LGPD has defined 9 privacy rights for individual data subjects, 10 legal bases for lawful processing of personal data, and the obligation for businesses to provide a data protection impact assessment (DPIA) upon the request of the Brazilian Data Protection Authority (ANPD). LGPD further requires businesses to recruit a data protection officer (DPO) to oversee the implementation of the law and offer guidance to the senior management regarding compliance with LGPD.

b. Financial Data Privacy

PCI DSS

The Payment Card Industry Data Security Standard (PCI DSS) is an industry-centric data privacy and protection framework that governs only the collection, processing, and security of credit card data. The PCI DSS defines 12 security requirements grouped under 6 goals that every payment card processing service must comply with to ensure the secure collection and processing of cardholders’ data.PCI focuses more on specific security technologies, policies, and processes.

c. Healthcare Data Privacy

HIPAA

The United States Health Insurance Portability and Accountability Act (HIPAA) regulates how the personal health information of an individual should be treated. Under HIPAA, personal health information is covered for up to 50 years after an individual’s death. The violation of any act under HIPAA would result in a fine of $1,500,000.

Challenges Organizations Face with Data Privacy Protection

Although privacy laws provide a few hints, principles, and guidance on data privacy and protection, they don’t necessarily elaborate completely on how a sound data privacy framework should be implemented. Let’s take a look at some of the challenges that hinder organizations from ensuring the protection of data privacy and meeting compliance requirements.

a. Pervasive Sensitive Data

Most organizations have sensitive data across a number of different systems and environments. Especially, organizations that deal with petabyte-scale data often have sensitive data in their managed, on-prem systems, or cloud servers. The challenge of discovering sensitive data becomes more intimidating when it comes to finding it across legacy systems, where it tends to get lost. It is fairly challenging to monitor the flow of data in a dynamic environment and to track its lineage and residency.

b. Rapid Increase in Shadow IT

Data privacy becomes challenging with the proliferation of data assets, especially shadow IT. Shadow IT is the use of applications, systems, and resources that aren’t sanctioned by the IT team, and it may include BYOD. The growth in shadow IT can be measured by the fact that 80% of employees admit that they use cloud applications without the approval of the IT team. Other statistics report that 83% of IT teams believe that employees use unsanctioned cloud storage services to store business data. Keeping track of all those devices across the board can be challenging, which may lead to poor data privacy.

c. The Growing Number of Global Privacy Laws

As mentioned earlier, there are now more privacy laws across the globe than there were a decade ago. The challenge arises with varying regulations, provisions, and definitions associated with personal information, processing, and protection. Compliance becomes challenging for businesses that deal with data at a petabyte scale. Businesses find it difficult to track the level of data privacy they need to implement for varying datasets.

d. Ineffective Access Control

Most data privacy breaches are often the result of poor access control. Internal employees, malicious employees, or corporate spies might gain access to data that is not properly protected. With the growth in data systems and the data itself, it becomes difficult for organizations to keep track of sensitive resources and employees’ access levels.

Data Privacy vs. Data Security

With more and more data privacy laws coming into effect globally, it has become a tremendously important strategic and operational goal for most organizations. Each regulation that comes into effect places different requirements and obligations on organizations, resulting in it being more dynamic in nature.

On the other hand, data security is a staple industry name now. Whether it’s a multinational conglomerate or a startup, it is rare to find an organization that does not treat data security as a literal matter of life and death, since data integrity loss or corruption can have devastating consequences.

But what exactly sets them apart, and more importantly, are they really so different from one another?

In a nutshell, while data privacy and security are different aspects of an organization’s data processing obligations, they are highly dependent on one another. Most organizations collect personal data from their users in the form of email addresses, phone numbers, credit cards, login credentials, and so much more.

Owing to both their regulatory obligations and operational requirements, they must maintain the privacy of this collected data. That is only possible if the data in question is appropriately protected.

Data security is the protection of data from any form of theft, corruption, and unauthorized access that may jeopardize the storage, usage, sharing, archiving, and creation of data. It is not limited to virtual space, as any physical and policy changes designed to achieve the aforementioned purpose are also data security.

Standard methods used in data security involve encryption, data masking, and redaction of sensitive data.

Data privacy, on the other hand, aims to ensure that the data subject has appropriate control over how their data is used after the organization has collected it. Giving users a chance to unsubscribe from email marketing and newsletters is an introductory example of how organizations aim to provide users with appropriate data privacy.

Other common aspects of data privacy include only sharing/selling users’ collected data with third parties after getting the users’ informed consent, as well as only using the collected data for purposes that were specified during the initial permission to collect the data.

Data Privacy in the Age of AI

AI is transforming nearly everything it touches. As AI tools increasingly rely on massive volumes of data, data privacy has become one of the most prevalent challenges for modern-day enterprises.

Machine learning models routinely collect, process, and store large amounts of sensitive personal data. Primary risks include inadvertent data disclosure, "black-box" opaqueness, linkage attacks that re-identify anonymized data, and the possibility of hostile actors deploying deepfakes or spear-phishing.

Data privacy regulates an individual's right to control how their data is collected, used, stored, and shared, minimizing the risk of data exposure and regulatory penalties for noncompliance.

Data Privacy Best Practices

Compliance with privacy regulations is imperative for customer trust and loyalty, and to stay ahead of the competition. But to achieve that, it is also important that organizations must streamline their data privacy and protection practices. Best practices include:

  • Keep track of all the systems and resources containing personal information or sensitive personal information. Monitor the inclusion of new devices or unregistered devices regularly.
  • Discover all PI and sensitive PI across all the structured and unstructured systems to identify their lineage, residency, and privacy use cases.
  • Identify data owners to help define and establish a data governance framework.
  • Monitor employees’ access level to sensitive data and implement least privilege access to reduce insider threats.
  • Adopt and implement a Privacy by Design (PbD) approach to streamlining data privacy. To begin with, conduct routine assessments to minimize the risk impact on privacy. Create effective retention policies and ensure strict security measures, including encryption, MFA, SSO, etc.
  • Data privacy isn’t a done and delivered process, but iterative. Therefore, leaving the implementation of the process to traditional technologies and manual labor could result in delayed implementation, erroneous execution, and compliance failure. The best feasible option is to automate the process to reduce errors and increase efficiency.
  • The expansion of data is beyond the expectations of anyone. Organizations with international roots are dealing with data at a petabyte scale. Therefore, it is a must for organizations to adopt automated solutions that can help them scale their process with their growing inventory of data.
  • Data privacy and data protection need to be instilled in every employee of an organization or its culture. Routine training and awareness sessions should be conducted to educate employees about data security practices.

Frequently Asked Questions (FAQs)

It refers to protecting the confidentiality, integrity and accuracy of personal data from unauthorized access, use, and disclosure. It involves ensuring that individuals have control over their personal information.

It keeps personal information safe from misuse or theft. It helps people trust businesses, comply with laws, and protect rights. Good privacy practices also prevent fraud and security problems.

The four types include:

  • Physical Privacy: Protection from physical intrusion or surveillance.
  • Informational Privacy: Control over personal information disclosure.
  • Privacy of Thoughts and Feelings: Protection from psychological intrusion.
  • Privacy of Behavior: Control over one's actions and activities.

Examples include consent for data processing, encryption, secure data storage, anonymization, data access controls, multi-factor authorization, and data breach notifications.

It can be protected through measures like strong data security practices, clear privacy policies, user consent mechanisms, regular audits, employee training, and compliance with relevant data protection laws.

The two types are:

  • Data Security: Protecting data from unauthorized access, breaches, and theft.
  • Data Confidentiality: Ensuring that only authorized individuals can access and use the data.

Benefits include preserving individuals' rights, maintaining trust with customers, complying with legal requirements, avoiding data breaches, and fostering a positive reputation.

Principles include transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, accountability, and individual rights.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You

Take a
Product Tour

See how easy it is to manage privacy compliance with robotic automation.

Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Latest
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer View More
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer
Enterprises are deploying autonomous AI agents into production faster than they can secure them, and the best practices for securing this complex new landscape are still being...
DSPM in 2026: Why It Matters More Than Ever View More
DSPM in 2026: Why It Matters More Than Ever
In 2026, the convergence of cloud expansion, SaaS proliferation, and agentic AI adoption has fundamentally changed the data security challenge, making Data Security Posture...
Data Risk Management View More
What Is Data Risk Management?
Learn the ins and outs of data risk management, key reasons for data risk and best practices for managing data risks.
View More
An Overview of Bangladesh’s Personal Data Protection Act, 2026
Explore Bangladesh’s Personal Data Protection Act, 2026, including its key provisions, data subject rights, compliance requirements, and business impact.
EU AI Act: What Changes Now vs What Starts in 2026 View More
EU AI Act: What Changes Now vs What Starts in 2026
Understand the EU AI Act rollout—what obligations apply now, what phases in by 2026, and how providers and deployers should prepare for risk tiers,...
AI Governance Fails When Privacy Controls Stay Disconnected View More
AI Governance Fails When Privacy Controls Stay Disconnected
Access the whitepaper and learn how to operationalize core privacy controls across the AI lifecycle to ensure compliance, accountability, and defensible AI use.
You Can’t Protect What You Can’t See View More
You Can’t Protect What You Can’t See
Discover why disconnected security findings create hidden breach paths, why 57% of organizations can't prove data flows, and how to identify toxic risk combinations...
Agentic AI Security: OWASP Top 10 with Enterprise Controls View More
Agentic AI Security: OWASP Top 10 with Enterprise Controls
Map the OWASP Top 10 risks for agentic AI to enterprise-grade controls, identity, data security, guardrails, monitoring, and governance to stop autonomous AI abuse.
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New