Opens in a new tab
vmblog logo 2024 wht (updated)

Quest Software 2019 Predictions: For Data Privacy, Here Comes Washington

Share: 

David Marshall | Published: January 22, 2019

Industry executives and experts share their predictions for 2019.  Read them in this 11th annual VMblog.com series exclusive.

Contributed by Adrian Moir, Sr. Consultant, Product Management & Lead Technology Evangelist, Quest Software

For Data Privacy, Here Comes Washington

In 2019 we will see data privacy legislation pass Congress, signaling how elected officials are taking action in the wake of mounting criticism of tech companies.

Make no mistake about it, 2018 was a rough year for the technology industry in the eyes of the general public. It wasn’t that long ago– months really– when “tech darlings” were seen as the precursors to a more perfect society. Companies like Facebook and Google broke down barriers between people. They promoted democracy worldwide and brought people closer together. The world we saw, with them as our guide, was as rosy as the typical entry one would post on social media channels. In that world, everything seemed right and fair and decent.

But then all were forced to face the reality of how social media companies make money. When our tech company heroes hid behind the realities of their technology– e.g. we just connect people, we’re not responsible for what is posted– the backlash was intense. The New York Times recently detailed how Facebook executives attempted to navigate the PR crisis. The tone of the article is clear: Executives’ instincts led them to evade, rather than to address directly, their responsibility. Hopes were dashed. In corporate America, it would seem, business wins out over the ideal.

Meanwhile, across the pond in Europe, governments had already responded to the potential negative implications of personal data access ubiquity. GDPR went into effect in the middle of 2018, and it set strict guidelines regarding the use of personal information, required companies to set methods for deleting or destroying it, and threatened significant fines for non-compliance. GDPR came along at the perfect time, given criticism of Facebook and other tech giants, and the United States seemed instantly behind.

That will change next year. Legislation is already making its way through Congress. The Consumer Data Privacy Act, introduced by Oregon Sen. Ron Wyden, is one such example. As the criticism of tech’s handling of private information has not waned, such legislation will become law in 2019.

Of course, no one really knows if such legislation will have teeth. Companies are still waiting with bated breath for the first significant GDPR penalties. According to TechCrunch and other outlets, the recent Marriott data breach could lead to an early instance. Others are debating when they are required to disclose a supposed breach and how, with a recent Wired article outlining such a debate that took place at Facebook in the wake of a breach discovery there.

One thing GDPR has generated, besides browser pop-ups reminding us that every website has cookies, is a wide rash of breach disclosure announcements. Out-law.com notes more than eight thousand breaches have been disclosed between the time GDPR went into effect in late May and early December.

Setting aside the specifics of any U.S. privacy law, and whether or not penalties are levied for non-compliance, organizations have to take government action seriously. Small organizations that are online can do business in Europe, subjecting them to GDPR. Even if European business is not in the cards, all organizations must invest in software that will closely track how data is accessed and used, and software that backs-up data in the case of a security incident. Rather than rolling the dice that laws will not be enforced, the wiser course is to follow Europe’s lead. Be prepared for the rapidly rising flood of data breach notifications stateside once the law is on the books.

##

About the Author

Adrian Moir, Sr. Consultant, Product Management & Lead Technology Evangelist

Adrian is a seasoned data protection specialist with over 30 years of experience in IT, working for small and large companies, channel partners and vendors. Adrian’s background includes experience in electronic and electrical engineering, hardware platforms, networking, operating systems, virtual and cloud infrastructures. Adrian currently works within the Quest Product Management team for Quest Data Protection and advises and implements strategies for the entire Quest Data Protection portfolio.