Delivering Digital Privacy and Digital Resilience
The escalating urgency of digital privacy, GDPR compliance through data subject rights and organizational responsibilities, privacy oversight and lawful processing, embedding privacy through Privacy by Design, the economics of digital resilience and business continuity planning, and building resilience through testing, crisis communication, and lesson learning.
Topics in this chapter
- Privacy: An Urgent Priority — GDPR Rights and Responsibilities, Increased Penalties, Privacy Authorities
- Privacy Compliance: Oversight, Processing Data, Subject Access Requests
- Getting It Right: Ethics and Policy, Cultural Dilemmas, Other Required Processes
- Employers' Vicarious Liability, Embedding Privacy and Minimising Risk
- Digital Resilience: Definitions, Foundations, Situational Awareness, Outcome-Driven Planning, Devolved Coordination, Avoid Over-Dependence
- Resilience Challenges: Testing and Rehearsal, Managing Stress, Crisis Communication, Lesson Learning
Digital Privacy Priorities and GDPR
The digital economy thrives on data, but pervasive datafication has generated profound externalities: individuals lose control over their digital selves, face opaque profiling, and are increasingly vulnerable to data breaches, identity theft, and manipulative practices. The urgency of digital privacy is fundamentally a market failure problem, necessitating robust regulatory intervention to realign private incentives with social welfare.
GDPR: New Rights and Responsibilities
The GDPR constitutes a paradigm shift through a comprehensive catalogue of data subject rights, transforming individuals from passive data sources into active participants in the information ecosystem. These include the right of access (Art. 15), right to rectification (Art. 16) and right to erasure or "right to be forgotten" (Art. 17), right to restriction of processing (Art. 18), right to data portability (Art. 20), and right to object and rights regarding automated individual decision-making including profiling (Art. 21–22).
Organizational responsibilities embed the accountability principle. Data Protection by Design and by Default (Art. 25) requires privacy be integrated into the design of processing operations from inception. Data Protection Impact Assessments (Art. 35) must be conducted where processing is likely to result in high risk. A Data Protection Officer must be appointed (Art. 37–39). Records of processing activities must be maintained (Art. 30), and data breaches must be notified without undue delay and, where feasible, within 72 hours (Art. 33–34).
Increased Penalties
GDPR fines scale with global turnover: up to €20 million or 4% of worldwide annual turnover. The firm's compliance decision follows , where is compliance cost, is detection probability, is the fine, and is reputational damage. The revenue-proportional fines raise substantially for global technology firms, creating strong financial incentives even with moderate detection probabilities. Reputational damage represents the present value of lost customer trust, reduced user engagement, and adverse market reactions — often highly non-linear and escalating dramatically for severe cases.
Privacy Authorities
Each EU member state must establish independent Data Protection Authorities (DPAs) vested with investigative, corrective, and advisory powers. They cooperate through the European Data Protection Board (EDPB) to ensure consistent application of the regulation. The global trend points toward dedicated, multi-sector privacy regulators because digital data flows transcend traditional industry boundaries.
Privacy Compliance and Getting It Right
Privacy Oversight
Privacy oversight resolves a principal-agent problem. The governing body minimizes , where is monitoring investment and is training investment. Effective oversight materializes through appointment of a Data Protection Officer (DPO) with direct reporting lines to the governing body, establishment of a privacy governance committee with cross-functional representation, and deployment of continuous assurance processes including DPIAs, internal audits, and key risk indicator dashboards.
Processing Data
Organizations must identify a lawful basis for processing — consent, contractual necessity, legal obligation, vital interests, public task, or legitimate interests. Three substantive principles structure lawful processing: purpose limitation (data collected for specified purposes not further processed incompatibly), data minimization (processing adequate, relevant, and limited to what is necessary), and storage limitation (data retained only as long as necessary). These principles operationalize Privacy by Design, embedding protection into the architecture of systems rather than bolting it on as an afterthought.
Privacy: A Trade-off Between Principle and Pragmatism
The optimal compliance effort equates marginal benefit to marginal cost: . Organizations allocate resources to processes and data assets where the marginal benefit of protection is largest. The governing body must set a floor for that reflects societal expectations, not just economic optimization.
Subject Access Requests (SARs)
SAR fulfillment is a stochastic service system. Using an M/M/c queue model, the expected waiting time is , where is the per-handler service rate and is the Erlang-C probability of queueing. The regulatory constraint is a hard deadline — typically one month — and the organization must staff such that . Three procedural safeguards are essential: identity verification sufficient to prevent disclosure to impostors, scope clarification for manifestly unfounded or excessive requests, and redaction protocols for third-party personal data and legally privileged material.
Digital Resilience
Questions of Ethics and Policy
Three ethical traditions inform digital governance. A deontological approach treats privacy as an inviolable right that cannot be traded for efficiency gains. Utilitarian reasoning evaluates policies solely by aggregate net benefits. Rights-based contractualism seeks principles that could be accepted by all free and equal persons. The Privacy-Resilience Frontier — the societal transformation function — requires choosing an optimal point based on the chosen normative framework.
Cultural Dilemmas, Limitations and Exclusions
Privacy is culturally contingent. The heterogeneous utility function captures how in individualistic cultures (), personal privacy dominates, while in collectivistic cultures (), individuals internalize positive externalities of data sharing on communal well-being. A rigid, uniform global privacy standard creates deadweight loss for societies preferring communal data pooling.
Systemic exclusions manifest along axes of disability, income, literacy, language, gender, and geography. A Rawlsian maximin social welfare function would prioritize the worst-off, yielding optimal conditions that differ from utilitarian allocations. Supplementary governance processes — polycentric governance, data trusts, and algorithmic impact assessments — are required to correct these failures.