Blog By: Kenneth Juhan
Date: August 12, 2026
Kenny Juhan will explain Privacy risk considerations in the following blog.
Privacy Risk in SecurityX: Data Rights, Sovereignty, and Biometrics
Cybersecurity and privacy overlap, but they are not exactly the same thing.
Security focuses heavily on protecting systems and information, while privacy also asks questions such as why information is collected, how it is used, where it is stored, and what rights individuals have over it.
SecurityX candidates should understand privacy risk involving data subject rights, data sovereignty, and biometric information.
Data Subject Rights
A data subject is the person the information relates to.
Depending on applicable privacy laws, individuals may have rights involving their personal information.
These can include rights to:
- Access information
- Correct inaccurate information
- Request deletion
- Restrict certain processing
- Receive information about how data is used
Organizations therefore need processes for receiving, verifying, and responding to privacy requests.
Security is important here because the organization must verify that the person making the request is actually authorized to access the information.
Data Sovereignty
Cloud computing makes data sovereignty especially important.
Data sovereignty means information can be subject to the laws and requirements of the country or jurisdiction where it is stored or processed.
An organization may operate in one country, use a cloud provider headquartered in another, and store customer information in a third.
That creates questions about which laws apply and whether information can legally move between jurisdictions.
Think:
Data sovereignty = Location can determine legal requirements.
For SecurityX, always pay attention to scenarios involving multinational organizations, cloud regions, or cross-border information transfers.
Biometrics
Biometric information can include fingerprints, facial characteristics, iris patterns, voice characteristics, and other physical or behavioral identifiers.
Biometrics can strengthen authentication, but they create unique privacy risks.
A password can be changed after compromise.
Your fingerprint cannot easily be replaced.
That means organizations should carefully consider how biometric templates are collected, stored, transmitted, retained, and eventually destroyed.
The organization should also avoid collecting biometric information simply because the technology is available.
Data minimization can reduce risk by limiting collection to information that is actually necessary.
Privacy and Security Together
Strong cybersecurity does not automatically guarantee good privacy.
An organization could perfectly encrypt a database and still create privacy problems if it collected information without a legitimate purpose or kept it much longer than necessary.
Security asks:
How do we protect this information?
Privacy also asks:
Should we have it, why do we need it, and what are we allowed to do with it?
Why This Matters for SecurityX
SecurityX scenarios may involve a technically secure solution that creates privacy or legal problems.
Candidates should therefore think beyond encryption and access controls.
Remember:
Data subject rights = What individuals can request
Data sovereignty = Where information exists affects requirements
Biometrics = Powerful authentication but sensitive, difficult-to-replace information
The best SecurityX answer should often balance security, privacy, business requirements, and compliance.
Understanding these privacy concepts makes it easier to recognize when a scenario is not simply asking, “Is the data secure?” but rather, “Is the organization handling this information appropriately throughout its entire lifecycle?”
Leave a comment