{"id":6257,"date":"2021-03-12T20:52:01","date_gmt":"2021-03-12T20:52:01","guid":{"rendered":"https:\/\/www.microsoft.com\/en-ca\/industry\/blog\/?p=6257"},"modified":"2021-03-12T20:52:01","modified_gmt":"2021-03-12T20:52:01","slug":"protecting-privacy-in-the-era-of-digital-innovation","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-ca\/industry\/blog\/government\/2021\/03\/12\/protecting-privacy-in-the-era-of-digital-innovation\/","title":{"rendered":"Protecting privacy in the era of digital innovation"},"content":{"rendered":"
<\/p>\n
The accelerated digital transformation in response to COVID-19 has moved the world online. People are working remotely, doing medical appointments virtually, socializing and participating in community life online \u2013 and the list goes on. The adoption of innovative technology has bridged the gap and enabled many critical services to remain open; it has also generated an unprecedented amount of data, which is being collected and processed by organizations with disparate privacy policies, and as a result, consumers, rightfully, have heightened concerns.<\/p>\n
Recently, I had the opportunity to participate in the Victoria Privacy & Security Conference<\/a> along with more than 1,000 security and privacy professionals from around the world. This event brought thought leaders together at a unique moment in time \u2013 the pandemic has demonstrated the indispensable value of data while also revealing the need for a more robust and permanent governance framework that facilitates data sharing and establishes public trust in how data is collected and used. In their keynote address, Julie Brill<\/a>, Chief Privacy Officer, Microsoft CVP, and Deputy General Counsel of Global Privacy and Regulatory Affairs, and Patricia Kosseim<\/a>, Information and Privacy Commissioner of Ontario, explored this topic and shared their perspectives on how individuals view the protection of their personal information, how organizations set their strategic priorities and the development of regional privacy laws and its impact globally.<\/p>\n Privacy Learnings from COVID-19 <\/strong><\/p>\n As Kosseim poignantly stated, COVID-19 has created a single, unifying urgency that has brought together the international community, \u201cIt\u2019s sparking collaborations across organizations, sectors and jurisdictions like never seen before to facilitate data sharing and deployment of new technologies to accelerate our understanding of how to prevent the spread of the virus and how to treat its debilitating impacts.\u201d<\/p>\n Data was instrumental in solving many of the problems that have arisen from the crisis, from contact tracing, to treating patients, to vaccine development.<\/p>\n \u201cAs one of many examples in this space, Microsoft is involved in helping other companies develop exposure notification systems for cellphones. We felt it was important to articulate the principles around the use of that data,\u201d said Brill. \u201cWe developed principles and we said that in the context of exposure notifications that very sensitive personal information should be collected with meaningful consent; it should only be used for public health purposes; it shouldn\u2019t be shared without consent unless it\u2019s being shared in the context of public health. These principles did help bolster the kind of trust that people need whenever their sensitive data is in use.\u201d<\/p>\n Even though these digital solutions were being developed in a time of urgent need, preserving privacy is critical and these solutions still need to meet the high standards of transparency and accountability that we demanded before the pandemic. In addition to being transparent about the reason for collecting data, what data is collected and how long it is kept, we must ensure appropriate safeguards are in place to secure the data. This includes de-identification, encryption, rotating and random identifiers, decentralized identities or similar measures to protect people\u2019s data from harmful exposure and hacking attempts.<\/p>\n The Prospects for Privacy Laws<\/strong><\/p>\n As Brill highlighted, the COVID-19 crisis required data to be unlocked in a responsible way, however, without a base-line privacy legislation, many companies did not know how to proceed because they didn\u2019t understand the guardrails around responsible data use and protection.<\/p>\n \u201cWhat we have yet to develop are appropriate governance frameworks to oversee the timely and flexible data sharing arrangements with the private sector \u2013 particularly for public good or data-for-good initiatives,\u201d said Kosseim. \u201cThese frameworks have to be more open to public scrutiny than they traditionally have been in the past and they have to ensure responsible treatment of data in accordance not only with privacy standards, but with broader societal concepts: fairness, accountability, transparency.\u201d<\/p>\n Policy legislation is one side of the coin, the other is public acceptance. Building trust with citizens will be equally important and it starts with ensuring AI systems are developed responsibly and in ways that warrant people\u2019s trust. At Microsoft, we\u2019ve established the Office of Responsible AI<\/a>, which sets company-wide rules for AI through the implementation of our governance and public policy work. As part of this, our senior leadership rely on the Aether Committee, and the local Responsible AI team I lead, to make recommendations on responsible AI issues, technologies, processes and best practices. The Aether committee\u2019s working groups also undertake research and development and provide advice on rising questions, challenges and opportunities. And this informs our work with customers; we provide resources for them to establish principles and a governance model that ensures they are building trust and collecting, storing and using data in a responsible way.<\/p>\n What\u2019s Next<\/strong><\/p>\n We are facing an exciting time for privacy reform in Canada. According to Brill, over the next 5 years, we can expect an evolving regulatory landscape that will involve more privacy laws and more in-depth laws that will be updated to meet the current environment. In Ontario, Kosseim\u2019s team will be focused on a set of strategic priorities that may include digital service delivery, transparency and open government, responsible use of data for good, access privacy and youth, next generation law enforcement and trust in virtual health.<\/p>\n \u201cIn five years, my hope is that we\u2019ll be sitting here discussing what we managed to accomplish in the strategic areas we will have selected,\u201d said Kosseim. \u201cThe Holy grail is if we can bring about the cultural change needed to build a sustainable trust and confidence in using and sharing data, in ways that can really help advance society\u2019s broader objectives \u2013 economic, health, social, etc.\u201d<\/p>\n For more information on how Microsoft\u2019s cloud services comply with Canadian policy, regulatory and legislative requirements, visit Compliance Resources for Canada<\/a>. And, visit CISO Central<\/a> for workshops, training and information on Zero Trust security and compliance.<\/p>\n