{"id":5555,"date":"2023-09-29T16:30:47","date_gmt":"2023-09-29T21:30:47","guid":{"rendered":"https:\/\/blogs.luc.edu\/compliance\/?p=5555"},"modified":"2023-09-29T16:30:47","modified_gmt":"2023-09-29T21:30:47","slug":"the-future-of-privacy-in-tech-might-just-depend-on-trust","status":"publish","type":"post","link":"https:\/\/blogs.luc.edu\/compliance\/?p=5555","title":{"rendered":"The Future of Privacy in Tech Might Just Depend on Trust"},"content":{"rendered":"<p><span style=\"font-family: 'times new roman', times, serif\"><em>Sydney Mann<\/em><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><em>Associate Editor<\/em><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><em>Loyola University Chicago School of Law, JD 2025<\/em><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">It is fair to say that privacy is a priority for nearly all companies, but technology organizations in particular. Many have had to adopt and quickly develop robust compliance programs, documentation, reporting, and consumer request systems to comply with global privacy laws or face serious fines and consequences. In the United States alone, <a href=\"https:\/\/pro.bloomberglaw.com\/brief\/state-privacy-legislation-tracker\/#:~:text=Browse%20all%20privacy%20articles&amp;text=Currently%2C%20there%20are%20nine%20states,data%20privacy%20laws%20in%20place.\">nine states<\/a> (California, Virginia, Connecticut, Colorado, Utah, Iowa, Indiana, Tennessee, and Montana) have signed comprehensive privacy laws into effect with an additional 16 pending in local legislature. Beyond this, individual one-off laws such as the <a href=\"https:\/\/www.ilga.gov\/legislation\/ilcs\/ilcs3.asp?ActID=3004&amp;ChapterID=57\">Illinois Biometric Information Privacy Act<\/a>, signed into effect in 2008, make privacy even more important.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><!--more--><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Many organizations have responded to these regulatory challenges by engaging tools such as <a href=\"https:\/\/www.onetrust.com\/platform\/privacy-management\/\">OneTrust<\/a> or <a href=\"https:\/\/bigid.com\/\">BigID<\/a>. In turn, consumers are faced with rejecting and accepting privacy terms and conditions under the guise of taking control and ownership over their data. The issue becomes that compliance is no longer enough \u2013 consumers comply with pop-ups out of a need to access what they really want, all the while losing faith in the brand in which they are directly engaging. With only a future of more <a href=\"https:\/\/news.bloomberglaw.com\/in-house-counsel\/the-rise-in-state-online-consumer-data-privacy-laws-explained\">privacy laws and regulations on the rise<\/a>, compliance will no longer be enough, consumers are going to demand something more from technology businesses, and that is Trust.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><strong>What is trust?<\/strong><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">\u2018Trust\u2019 in the data economy can be considered a combination of privacy policy, communications, and marketing to increase consumer confidence that the organization that is collecting information on them is actually being a good steward of such lucrative details.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Although it sounds new, it\u2019s really not. In 2016, two law school professors, Niel Richards and Woodrow Hartzog, from Washington University in St. Louis School of Law and Boston University School of Law respectively, published the article <a href=\"https:\/\/law.stanford.edu\/wp-content\/uploads\/2017\/11\/Taking-Trust-Seriously-in-Privacy-Law.pdf\"><em>Taking Trust Seriously in Privacy Law<\/em><\/a> in the Stanford Technology Law Review. In an age in which the European Union\u2019s General Data Protection Regulation (<a href=\"https:\/\/www.consilium.europa.eu\/en\/policies\/data-protection\/data-protection-regulation\/#:~:text=The%20GDPR%20establishes%20the%20general,data%20processing%20operations%20they%20perform.\">GDPR<\/a>) had not yet gone into effect, the scholars discussed a consent gap in which every solution requires a focus on organizations developing genuine trust with consumers.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Nearly seven years after publication, organizations have internalized this message, expanding their privacy compliance programs beyond check-the-box consent forms to dedicated \u201ctrust centers\u201d offering a new level of transparency for consumers on their collected information.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><strong>How major industry players are building consumer trust<\/strong><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Apple, Microsoft, and Google are three industry-leaders that have developed such sites. Located under \u201cApple Values\u201d is where <a href=\"https:\/\/www.apple.com\/privacy\/\">Apple\u2019s Privacy center<\/a> can be found. Consumers are able to view Transparency Reports from around the world and a series of time spans. Coupled with the familiar data control features, the organization places an emphasis on providing transparency on the technology the consumer already has access to whether it be through their purchase of hardware or software, informing the consumer while also strengthening their trustworthiness brand power.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">More so, Microsoft too has a thorough <a href=\"https:\/\/www.microsoft.com\/en-us\/trust-center\/privacy\">trust center<\/a> aimed at informing their array of consumers about independent audit reports, when data is secured, and regional compliance guidance for their products. Unlike Apple\u2019s Privacy Center, the Microsoft Trust Center is focused on privacy issues that businesses have when purchasing their various software or hardware products. Given that an estimated <a href=\"https:\/\/www.investing.com\/academy\/statistics\/microsoft-facts\/#:~:text=More%20than%2095%25%20of%20Fortune,Microsoft%20team%20increased%20by%20894%25.\">four out of every five Fortune 500 companies use Microsoft Office 365<\/a>, this is not surprising. To that end, the Microsoft Trust Center contains <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/security\/fundamentals\/physical-security\">publicly available documentation<\/a> regarding how the organization protects cloud Azure cloud platform and infrastructure physical security.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Finally, Google has also developed a <a href=\"https:\/\/safety.google\/security-privacy\/\">Safety Center<\/a>, geared towards individual users of its products. The site defines what different privacy terms mean to Google and how they in turn promote safeguarding consumer data. Some of the responsible data practices defined include data minimization, privacy reviews, and data transparency. Through the Center, consumers also have access to the <a href=\"https:\/\/business.safety.google\/compliance\/\">Google Business Data Responsibility<\/a> page that outlines the organization\u2019s internal compliance program, which only further support\u2019s <a href=\"https:\/\/www.google.com\/publicpolicy\/transparency\/\">Google\u2019s commitment<\/a> to transparency for all who use their products.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Overall, these organizations, though sweeping in size and scale, are examples of trust privacy in a consumer-centric manner beyond typical compliance that can be replicated by businesses of any industry facing the next wave of privacy regulation. Furthermore, it is not necessarily presumptuous to say that privacy is never going away. As predicted by legal scholars <a href=\"https:\/\/law.wustl.edu\/faculty-staff-directory\/profile\/neil-richards\/\">Niel Richards<\/a> and <a href=\"https:\/\/www.bu.edu\/law\/profile\/woodrow-hartzog\/\">Woodrow Hartzog<\/a>, and shown through the increasing amount of upcoming legislation, privacy is here to stay. However, the approach organizations take towards staying compliant will need to change as consumer preferences crave greater transparency and develop continued distaste for check-the-box compliance. Such a shift can only be built on a foundation of genuine trust.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It is fair to say that privacy is a priority for nearly all companies, but technology organizations in particular. Many have had to adopt and quickly develop robust compliance programs, documentation, reporting, and consumer request systems to comply with global privacy laws or face serious fines and consequences. In the United States alone, nine states (California, Virginia, Connecticut, Colorado, Utah, Iowa, Indiana, Tennessee, and Montana) have signed comprehensive privacy laws into effect with an additional 16 pending in local legislature. Beyond this, individual one-off laws such as the Illinois Biometric Information Privacy Act, signed into effect in 2008, make privacy even more important.<\/p>\n","protected":false},"author":155,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[283,499,1624,1630,2018],"class_list":["post-5555","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-big-tech","tag-consumer-trust","tag-privacy-compliance","tag-privacy-program","tag-trust-center"],"_links":{"self":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/5555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/users\/155"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5555"}],"version-history":[{"count":0,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/5555\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}