Privacy and Data Protection Principles
Security protects data; privacy governs whether you should have collected it at all. The exam tests the difference, and that encrypting data you should not hold does not fix a privacy problem.
What this makes you able to do
Evaluate whether personal data is collected, used and retained in line with privacy principles, distinct from how it is secured.
By the end you can
- Distinguish privacy from security.
- State the principle of data minimisation.
- Recognise that securing excess personal data does not satisfy privacy.
Transcript
Privacy and data protection principles. Most of Domain five is about security controls, but this lesson draws a line the exam insists on: privacy is not the same problem as security.
The scene. A privacy review finds the sign-up form collects date of birth, home address and marital status for a service that needs only an email. The team is unconcerned: it’s all encrypted, so privacy is covered. They have protected data they had no business collecting, and they think the lock on the drawer settles the question of what is in it.
So, two different questions. Security protects information: keeping it confidential, intact, and available, safe from unauthorised access. Privacy governs whether personal data is collected, used, shared and retained appropriately and lawfully. One protects the data; the other governs whether you should have it.
And that distinction matters because you can do one without the other. You can secure data you had no right to collect, and you can collect data lawfully but fail to protect it. Security is a means; privacy is a set of obligations about personal data specifically. When a question contrasts the two, security is about protecting data, and privacy is about the appropriate handling of personal information.
The core privacy idea is data minimisation: collect and retain only the personal data actually necessary for the stated purpose. The form’s date of birth and marital status fail this, they are not needed to deliver the service.
Privacy regimes differ in detail but share a common core the exam expects you to recognise. Let me name the main ones.
First, purpose limitation: personal data is collected for a specified purpose and not used for unrelated ones.
Second, data minimisation: collect and retain only what is necessary for that purpose.
And then retention limits, keep data only as long as the purpose requires; data-subject rights, individuals can access and correct their data; and accountability, the organisation can demonstrate compliance, echoing the continuous-compliance theme from Domain two.
Now the point the team missed. Encrypting the excess data is a security control; it protects that data from unauthorised access. It does nothing about the privacy failure, which is that the data should not have been collected or retained in the first place. Minimisation is breached the moment you hold personal data you do not need, however strong the encryption around it.
The right approach is privacy by design: building privacy in from the start rather than bolting it on, the same principle as designing controls in during development in Domain three. So the fix is not more security on the excess data; it is to stop collecting what is unnecessary and dispose of what should not be kept.
So carry this away. Security protects data; privacy governs whether collecting and using it is appropriate, and the two are assessed separately. Data you do not hold cannot be misused or breached, and holding it, encrypted or not, is the privacy failure.
1.What is the difference between privacy and security?
2.What does the principle of data minimisation require?
3.An organisation collects far more personal data than it needs but encrypts all of it strongly. Does this satisfy privacy requirements?
Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.
Stay ahead of cyber threats
Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.
No spam. Unsubscribe at any time.
