Music first thing to know is that i consider the privacy officer role and the the ciso role flip sides of a coin they complement each other and really yount have one without the other if youre gonna have good data protection good privacy and security practices. The cpo role or the privacy officer role. I really break out around policies and practices related to collection and the use and the sharing of personal information.
As well as a large sloth of what ill just blanketly call surveillance and ethical considerations. That are particularly important in higher education. The ciso role is really about protecting data and sometimes.
Its protecting it according to law protecting it according to the policies and practices that youd have the privacy officer. Write for you so you cant really do one without the other i can have all the great policies and practices in the world laid out before everybody. But if im not actually securing the data in the background.
If im not encrypting it im not using two factor. Im not using those tools. The data could all go away flip side is i could have all the greatest security tools and techniques and technologies implemented but if my practice is to give away data.
The minute somebody asks me to share it whether its with business partners. Law enforcement without other best practices to prevent such things. Then you really dont have privacy.
So they go hand in hand theres a lot that cisos do that could be extremely privacy invasive. We have a lot of tools and a lot of data that could tell the private goings on what does your email look like what are you writing who are you writing it to what websites youre surfing all those are in my power to review. If need be its why you need a privacy officer to check that and strike the right balance in the relationship.
So overall complimentary roles partnership and collaboration is everything betweenem and a healthy amount of tension isnt bad. But ultimately they have to work together upbeat music. Some of the issues are just getting people to recognize that privacys a value.

Its a value that particularly in higher. Ed underpins and supports values. Like academic freedom intellectual free expression.
Student. Growth and development. All those that privacy touches that are becoming more important.
As we move into an era of big data. Data. Science analytics and oh.
By the way officially. Theres privacy related laws. We all have to pay attention to whether thats ferpa or im a student data hipaa around health and medical data.
The common rule. Which talks about human subject research data they all have strong privacy touches. None of them are just there for privacy.
Maybe the common rules closest. But theres a whole compliance piece that we have to think about in the privacy world that said. When i think about privacy in the higher.
Ed context. It does go back to what i would call the higher level math. So its not just about meeting.

The spirit and letter of the law. If thats the only reason we were doing i was doing privacy in higher ed. I wouldnt have come back its about things like academic freedom freedom of expression freedom of association student growth and development.
All of those have strong privacy components and ethical data use components that if we dont pay attention to them it changes. What we do as higher education professionals. Upbeat music.
Im all for gdpr in. Theory and i think something that many in the us. In particular dont understand is sort of its genesis so the way weve approached privacy in the.
Us. Versus much of the rest of the world not just the. Eu but well stick with the eu.
Its fundamentally different. We see privacy as a set of laws based on data that are things we dont want shared health information might be i want to protect my educational records from my parents i dont want to share my loan information so its something called a sectoral approach privacy in the eu. Is fundamentally a human rights issue.
So think back to world war ii. Or even pre world war ii and. The number of fascist dictatorships in actually pre during and post world war ii whether thats the soviet union nazi.
Germany east germany and the stasi salazar in portugal franco in spain the way they stayed in power was to devalue individuality and to pry into peoples affairs and be able to hold that against them to get them to conform. Its a human subject or its a human rights value and that this is now being pushed as part of the conversation is really heartening to me what im aside from just it being difficult. To actually comply with gdpr in the us and the.

Eu frankly i worry that we treat it in the us. More like hipaa or for that its gonna be treated as a compliance thing as opposed to the real like in that higher subject stuff. This is about human rights and about valuing individuality as opposed to conformity upbeat music.
We have privacy as a value and as a concept not just in our laws. But in parts of our constitution. While the word privacy doesnt exist that we have concepts like no illegal search and seizure are we gonna throw that out we have the fifth amendment and that you have a right to not self incriminate yourself are we gonna throw that out those are privacy values.
So yeah in a world of pervasive data. Collection big data data. Science and value in it.
Its not just that its being done against us. Its being done for us. I hate to throw out the concept that has gotten us.
Its fundamental in the way this democracy. And many democracies have grown calm. Music big data is actually breaking long.
Held privacy. Practices so the us. In the wake of watergate and the wake of the mccarthy era set actually had a privacy commission that helped instantiate fair information practice principles those principles informed how the eu has approached privacy and big important values in those principles were transparency you tell people what youre gonna collect why youre gonna collect it use limitation you only use the data for the purpose you collected dont share.
It with people you dont need to share. It with in the big data world thats turned on its head. We dont know what we want to use the data for of course.

Were gonna use it for other purposes and we want to share the data because theres such value in sharing of the data whether thats to inform how government happens how higher education. Happens or even how we can take advantage of consumers in businesses. Calm music.
So the great part about being at michigan. Is we have a number of faculty. That are privacy not just privacy aware.
But this is their field of study. So probably the biggest thing. I can think of is we had a data privacy day.
So every year january. 28th is international date of privacy day. So clearly.
Its still a value out there and a faculty member and i partnered to put together a half days worth of program that brought in expertise from both the university as well as actually we added some international folks who videoed in and it was a event that surpassed our expectations. We had hundreds of people attend. We had a lot of follow up we actually sparked some interdisciplinary conversations and research opportunities that if that hadnt existed boy.
You know things that might have been lost so that actually grew out of another privacy related. Faculty collaborative effort that i co convened with some faculty members in our school of information and our college of engineering and other departments. Where we on a periodic basis put together conversations at the confluence of technology privacy security law and policy and so if you want to look it up dissonance at umich somewhere along those lines.
If you use those those two words in whatever your browser or search. Engine of choice. It should come up.
But we touch on a lot of the subjects. Whether thats the apple and fbi encryption debate to privacy in the big data. World or in an internet of things world calm music.

