Industry executives and experts share their predictions for 2022. Read them in this 14th annual VMblog.com series exclusive.
Data privacy concerns will continue to affect IT initiatives in 2022
By Rajesh Ganesan, Vice President of Products, ManageEngine
Next year will bring more privacy regulation across the globe. The E.U.’s GDPR has been in effect for three years now, but China just passed their Personal Information Protection Law (PIPL) last month, and India has a Personal Data Protection Bill (PDPB) coming down the pike.
In the United States, three states (Virginia, California, and Colorado) already have data privacy laws in place, and lawmakers on the Hill are currently pushing for a federal data privacy law. Although it remains to be seen if and when that law will come to fruition, organizations need to adapt to the changing legislative tide across the globe.
So, how will this focus on customer data privacy affect IT infrastructure initiatives in 2022?
1. Businesses will utilize their AI tools in ways that respect end users’ privacy.
AI regulation is an inevitability. This regulation will strive to ensure that algorithmic decision-making is fair, transparent, and unlikely to adapt or evolve in a way that discriminates against groups of people.
Organizations are becoming more cognizant about exactly how they train and deploy their AI models. These models must obfuscate all personally identifiable information (PII); put differently, all algorithmic training needs to be conducted on data that is completely devoid of PII. In those instances in which an algorithm needs to make a decision based on PII, explicit consent must be sought out and received.
2. AI models will become increasingly explainable.
In order to comply with forthcoming AI regulation, organizations will need to ensure that their models are explainable. The GDPR already addresses the need for AI explainability; according to GDPR, users have “‘the right…to obtain an explanation of the decision reached’ by algorithms.” That said, what qualifies as an explanation is still a bit of a gray area. At the very least, under GDPR, users definitely have to be informed whenever a decision that affects them is made by an AI model.
Much like GDPR, the California Privacy Rights Act (CPRA) also explicitly addresses AI explainability. Under CPRA, consumers have the right to access information about companies’ automated decision-making tools, and they also have the right to opt-out of such tools. Although the CPRA doesn’t take effect until January 1, 2023, organizations should, and will likely, recognize that mandatory explainable AI is on the horizon.
3. Tighter privacy regulations will continue to make on-premise applications quite popular.
As more countries pass data privacy laws, organizations will increasingly opt to deploy applications on-premises. On-premise software not only helps organizations to keep sensitive data within geographical boundaries, but it also provides companies with better control of business data. Highly regulated businesses, such as those required to comply with HIPAA, FERPA, and other federal laws, will continue to run many applications in an on-premises IT environment, as this limits the number of parties able to access sensitive data.
4. Blockchain technologies will continue to facilitate personal identity information storage and robust audit trails.
Users are increasingly wary about sharing their information with third parties for identity verification. Blockchain architecture minimizes the amount of data required for verification, and it provides a secure, decentralized approach to the validation of information requests.
Through blockchain architecture’s end-to-end traceability, every login is timestamped, providing users with the ability to track the provenance of their credentials. Additionally, blockchain technologies bolster audit trails and ensure that privileged users are unable to modify or delete any entries.
The traceability, decentralization, and immutability that blockchain provides will continue to make it a popular component in the realm of identity information storage.
5. Non-human identities are proliferating, making it an important focal point for identity management in 2022.
Networks will continue to be inundated by a plethora of non-human identities, including bots, IoT devices, APIs, and service accounts. It’s important to monitor these entities in order to prevent compliance-related risks, security breaches, and data leaks.
The proliferation of these non-human identities, combined with increased compliance concerns and the recent increase in remote work, has made identity management a challenge for many organizations.
To deal with synthetic identities, it is vital to use key-based authentication capable of supporting hundreds or thousands of authentication requests in a short period of time. Given the rapid influx of non-human identities, cryptographic authentication tools are going to be vital in the upcoming year.
In summation: the forthcoming focus on user data privacy will bring many side effects for IT personnel and business leaders alike. And as a quick aside, we also believe the need to take care of employees’ mental health will continue to be an important part of the discourse in 2022. The pandemic helped bring mental health into the global discourse-and rightfully so. Unfortunately, we are not out of the woods yet, so we can expect employee mental health, much like the protection of data privacy, to remain top of mind next year.
##
ABOUT THE AUTHOR
Rajesh Ganesan is the Vice President of Products at ManageEngine, a division of Zoho Corporation. Rajesh has been with Zoho Corp for over two decades, developing software products in various domains, including telecommunications, network management, and enterprise IT security. He has built many successful products at ManageEngine, currently focusing on delivering enterprise IT management solutions as SaaS.






