39:51No Privacy Without Security
Download resourcesAbout this session
Sabine Lainer, a governance, risk and compliance specialist at GoSecure, argues that privacy cannot exist without security. She surveys the wave of privacy laws that followed the GDPR (PIPEDA, CCPA, Brazil's LGPD and many others) and shows that every framework rests on the same fair information practice principles, one of which is a security safeguard. Privacy, she says, is that safeguard plus ethics, trust, transparency and a set of data-management goals such as minimisation, unlinkability and undetectability. Using layered diagrams, she explains how security controls form the outer defence and how privacy-enhancing techniques (anonymisation, de-identification, pseudonymisation, k-anonymity, differential privacy) protect data even after a breach, to prevent re-identification attacks. She then walks through translating legal frameworks into internal policies and measurable, practical controls, contrasting 'dark' and 'good' privacy patterns, and shows how much of a privacy programme can piggyback on an existing security programme, from data retention to training and access requests. She closes on ISO 27701 and the NIST Privacy Framework as ready-made bridges for security professionals.
We are collecting and generating data at an unprecedented rate and there is no end to
it. The volume, velocity and variety of data collected, transmitted, and stored is associated with numbers that hardly anyone fathoms. What is a quintillion? A lot of data! While a lot of companies still struggle with basic security, they now get run over by privacy. The GDPR in Europe has caused a landslide of privacy legislation left, right and center. A good example is the CCPA. In addition, a lot of existing privacy legislation is not well understood or even known. A lot
of what privacy is most concerned about can be met by good old-fashioned security controls. So let’s see what the marriage between security and privacy looks like in an day to day operational program.
Key takeaways
- Treat privacy and security as interdependent: the security safeguard principle is embedded in every privacy framework, so build the privacy program on existing security controls.
- Apply privacy-enhancing techniques (anonymisation, de-identification, pseudonymisation, k-anonymity, differential privacy) so data resists re-identification even if a breach exposes it.
- Translate legal frameworks into internal policies and then into controls that are meaningful, measurable and practical, not vague principles engineers cannot act on.
- Minimise and delete: collect only what the purpose requires, document a data taxonomy and purpose per element, and securely destroy data you no longer need.
- Adopt a ready-made bridge such as ISO 27701 (as a supplement to an ISO 27001 ISMS) or the NIST Privacy Framework to structure the program.
Speakers

Sabine Lainer is the Senior Advisor at GoSecure, bringing a wealth of knowledge and experience in security and privacy. She holds degrees from the University of Applied Science in Furtwangen, Germany; Brunel University in London, UK; the University… Read moreRead less
Sabine Lainer is the Senior Advisor at GoSecure, bringing a wealth of knowledge and experience in security and privacy. She holds degrees from the University of Applied Science in Furtwangen, Germany; Brunel University in London, UK; the University of South Australia; McGill University; Concordia University; and the University of Alberta. Sabine is passionate about security, privacy, learning, and teaching. She was awarded an innovative teaching prize in 1997 and was nominated for the Women in IT Award – Security Champion in the UK in 2016. Having lived and worked in nine countries, Sabine is now a proud permanent resident of Canada. Outside of her professional life, Sabine enjoys running, cycling, hiking, paddle boarding, and indulging in science fiction and fantasy stories through various media. A dedicated Star Trek fan, she takes great pride in living in the birthplace of William Shatner.
