Comparing data security and data privacy
More often than not, risk practitioners consider data privacy and data security to be the same concepts; however, they are not. As discussed in the previous section, data privacy refers to the protection of personal information, ensuring that individuals have control over who can access their data, how it is used, and who it is shared with. On the other hand, data security refers to the measures taken to protect data from unauthorized access, use, disclosure, destruction, or modification.
Measures to ensure data privacy could involve obtaining explicit consent from individuals prior to collecting and using their personal data, implementing policies for retaining data, deleting that data when not required, and enabling individuals to access and manage their data. Measures to ensure data security could involve the use of access control, implementing strong password requirements, encrypting data in transit and at rest, implementing firewalls...