Confidentiality vs. privacy
IMPORTANT: Confidentiality protects information designated as confidential by agreement — it could be trade secrets, pricing, or contract terms. Privacy deals specifically with personal information and the rights of the individuals it describes. All personal information should be kept confidential, but not all confidential information is personal.
Core privacy principles
- Notice — tell people what you collect and why
- Choice and consent — allow individuals to agree or opt out
- Collection limitation — collect only what's needed for the stated purpose
- Use, retention, and disposal — use only for disclosed purposes; keep only as long as needed
- Access — individuals can view and correct their data
- Disclosure to third parties — only with consent or legal basis
- Security, quality, and monitoring and enforcement
Notable regulations
| Regulation | Scope |
|---|---|
| GDPR (EU) | Broad personal data rights: access, rectification, erasure ("right to be forgotten"), portability; large potential fines; applies extraterritorially to entities serving EU residents |
| HIPAA (US) | Protected health information; privacy and security rules; breach notification |
| GLBA (US) | Financial institutions' handling of customer information; safeguards rule |
| PCI DSS | Contractual, not a law — payment card data security standard |
| State privacy laws (e.g., CCPA/CPRA) | Consumer rights to know, delete, and opt out of sale of personal information |
Control frameworks
- COSO Internal Control — Integrated Framework — the general internal control model (five components)
- COSO ERM — enterprise-wide risk management
- COBIT — governance and management of enterprise IT
- NIST Cybersecurity Framework — Identify, Protect, Detect, Respond, Recover (plus Govern in the updated version)
- ISO/IEC 27001 — certifiable information security management system standard
EXAM TIP: Frameworks are not interchangeable. COSO is about internal control broadly; COBIT is specifically about IT governance; NIST CSF is about cybersecurity risk; ISO 27001 is a certifiable management system.