By Carsten Casper, Research Vice President at Gartner

The management and disclosure of personal data carries considerable privacy and security risks. To avoid the financial and reputational damage of privacy violations, IT leaders need to incorporate "privacy by design" principles into their infrastructure. While the legal mandate to follow the principles of privacy by design will not be enforced until at least 2015, Carsten Casper, research vice president at Gartner, explains how privacy by design can help organizations save costs and reduce the total cost of ownership of IT.

What Is Privacy by Design?

Carsten: Privacy by design is an emerging principle of privacy legislation in many countries, and states that privacy should be a fundamental consideration of any new IT architecture. IT leaders need to seriously consider it and alert their organization's leaders to the potential costs and damaging implications of noncompliance.

Privacy by design suggests several basic principles that organizations should adhere to, in order to comply with upcoming legislation:

  • Be proactive, not reactive
  • Enforce privacy as a default setting
  • Embed privacy into design
  • Enable full functionality
  • Require end-to-end security
  • Provide full visibility and transparency
  • Employ deep respect for user privacy
  • Highlight the business value of privacy

Why Is It Important?

Carsten: Managing privacy well is an increasingly complex task as organizations, their business relationships and their online infrastructures become more geographically distributed. Organizations that fail to manage privacy policy issues across national and international boundaries will increasingly find themselves exposed to levels of legal and reputational risk, which may damage their ability to operate in a given jurisdiction, and  ultimately threaten their viability.

If IT leaders correctly adhere to the several principles of privacy by design listed above, this can help their business avoid privacy risks while simultaneously reducing their IT total cost of ownership (TCO) and improving the user experience, security and scalability of their IT projects at a large operational level. It's also important to recognize that the principles of privacy by design are not stagnant; privacy programs must evolve to meet the inevitably changing requirements. Organizations that implement IT projects with privacy in mind will need to challenge and evolve their IT architectures during the next five years, as issues related to data residency requirements, the risks of reidentification and other technical complexities, such as in-memory processing, develop.

How Can It Help the Bottom Line of My Business?

Carsten: When IT leaders adopt privacy by design, privacy and security work in harmony with each other to transform compliance into a business advantage. It can provide an organization with a scalable, secure ecosystem and a deeper trust of personal, and web-enabled information, while simultaneously lowering operational costs without comprising on data privacy.

Mr. Casper will provide additional analysis on privacy and security at Gartner Symposium/ITxpo, November 10-14 in Barcelona.

About Gartner Symposium/ITxpo

Gartner Symposium/ITxpo is the world's most important gathering of CIOs and senior IT executives. This event delivers independent and objective content with the authority and weight of the world's leading IT research and advisory organization, and provides access to the latest solutions from key technology providers. Gartner's annual Symposium/ITxpo events are key components of attendees' annual planning efforts. IT executives rely on Gartner Symposium/ITxpo to gain insight into how their organizations can use IT to address business challenges and improve operational efficiency.

Additional information about Gartner Symposium/ITxpo in Barcelona is available at www.gartner.com/eu/symposium. Video replays of keynotes and sessions are available on Gartner Events on Demand at www.gartnerondemand.com. Follow news, photos and video coming from Gartner Symposium/ITxpo on Facebook at http://www.facebook.com/GartnerSymposium, and on Twitter at http://twitter.com/Gartner_inc and using #GartnerSym.

Contacts
  • Rob van der Meulen
  • Gartner
  • rob.vandermeulen@gartner.com
distributed by