Sci & Tech

Cybersecurity and Consent: The Linkage

This blog raises a fundamental question: Who should control the information generated by our increasingly digital lives—the individual, the corporation or the state?
Data protection is often discussed in the language of technology, law and cybersecurity, but privacy is ultimately a question of individual rights, dignity and choice. Often, on our desktops/laptops and e-commerce sites, we reveal much of our personal data, as we are asked to give. Google nowadays gives an alert e-mail that we have shared our data with which entity. And this data reveals our preferences, behaviour, relationships, movements and vulnerabilities. And this data leads to cybercrimes, the root of which is not the data but our consent to give the data, which we give to tempting offers on the web. No such problem occurs with consent in physical purchases, retail or wholesale. In practice, however, consent is buried under lengthy privacy policies and Data Protection Acts of Nations. When you click “I agree,” do you understand what is being collected, why it is being collected, who will receive it, how long it will be retained, and where it will be retained? Should we really give consent ‘to accepting cookies’, ‘to understanding locations of our phones’, and to many more such requests? We must acknowledge noted Cybersecurity Expert Mr Rohit Srivastwa for placing the individual at the centre of the data economy through his book on Cybersecurity. And we do agree with him. Often, under threats like ‘Digital Arrest ’, we have consented to transfer money. What makes us give consent so easily? This is particularly significant at a time when businesses increasingly use artificial intelligence, big-data analytics and behavioural profiling to understand and predict consumer behaviour. Data can improve services and create enormous economic value, but the same technologies can also enable manipulation, discrimination and intrusive surveillance if appropriate safeguards are absent. Without safeguards, we just cannot build trust around data, and any web journey can become dangerous from the student to the office executive.
No discussion on Cybersecurity would be complete without a reference to the traditional trade-off between privacy and innovation, though actually, there is no trade-off. Well-designed privacy frameworks can actually encourage innovation by creating consumer confidence and predictable rules for businesses. Companies that demonstrate responsible data practices can build stronger and more durable relationships with customers. And Data-driven businesses have an obligation to move beyond compliance. Merely satisfying the minimum requirements of a law should not be the ultimate objective. Organisations need to adopt principles such as data minimisation, purpose limitation, security by design, transparency and accountability. Privacy should become part of Corporate Governance rather than remain the exclusive responsibility of the IT or the Legal department. Lastly, the ordinary Indian needs to understand their rights and responsibilities while sharing data. We should know what information we are sharing, why it is required and what choices we have regarding its use. Data may fuel the digital economy, but individuals must not lose control of their digital identity in the process. Ultimately, privacy is neither a luxury nor an obstacle to innovation. It is a foundation of trust.
And in the digital economy, trust is really the most valuable asset. What do you think?

Subscribe Our Newsletter

Loading