Serious Privacy
The PICCASO award winning Podcast, for those who are interested in the hottest field of human rights and laws on the digital frontier. Whether you are a professional who wants to learn more about privacy and privacy laws, data protection, GDPR or cyber law or someone who just finds this fascinating, we have topics for you from data management to cybersecurity, from social justice to data ethics and AI and digital identity protection. In-depth information on serious privacy topics including interviews with privacy leadership, privacy culture, serious discussions, and more.
This podcast, hosted by Dr. K Royal, Paul Breitbarth and Ralph O'Brien, features open, unscripted discussions with global privacy professionals (those kitchen table or back porch conversations) where you hear the opinions and thoughts of those who are on the front lines working on the newest issues in handling personal data. Real information on your schedule - because the world needs serious privacy.
Follow us on BlueSky (@seriousprivacy.eu) or LinkedIn
Serious Privacy
COVID-19 Part 2
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The world suddenly came to a standstill when the #Coronavirus took hold of our daily lives. Fighting the virus is the first priority, but that cannot be done at the expense of the rights to #privacy and #data protection. In this double episode of #SeriousPrivacy, K and Paul talk about the virus with a number of guests, discussing employee privacy, the collection of health data and the latest regulator guidance.
This is a two-part series, both at 40 minutes. Links are below for Spirion to follow up with Cameron and Gabe, along with links to their free offering for privacy / security and other resources we mention in the podcast.
Guests
- Gabe Gumbs - Chief Innovation Officer, Spirion
- Cameron Ivey - Senior Marketing/BDR, Spirion
- Lindsay Palmer - Research Specialist, TrustArc
- Prof. Ulrich Kelber - German Federal Commissioner for Data Protection and Freedom of Information
References
- TrustArc COVID-19 Blog
- Top 10 Tips for Companies with (new) Remote Workers
- Top 10 Tips for Enabling (new) Remote Workers
- COVID-19 German DPA Guidance (🇩🇪)
- Privacy Please Podcast
- Spirion COVID-19 Blog
- Spirion Data Discovery Agent
- Spirion SDM trial
- Future of Privacy Forum - COVID-19: Privacy & Data Protection Resources
Twitter
@Spirion
@GabrielGumbs
@PrivacyPlsPod
@UlrichKelber
@heartofprivacy
@EuroPaulB
If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us!
Subscribe today HERE
Back the Board Game!
https://www.kickstarter.com/projects/seriousprivacy/serious-privacy-the-data-game
Powered by TrustArc
From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.
Welcome back to Serious Privacy. This is part two of our special episode on the coronavirus or COVID-19. If you haven't listened to the first part yet, it is probably a good idea to start there. In this part of the episode, Kay and I will continue the conversations on employee privacy, regulator guidance, and the collection of health data in these times of crisis. Happy listening.
KThank you, Paul. To start off, we're going to go back to some more questions we had with Lindsay. From there, we'll move in to Cameron and Gabe, and that will conclude the second part of this two-part series on COVID. So Lindsay. Thank you, Lindsay. And we actually at TrustArc published two flyers on remote workers, what they can do for privacy and security at home, and then another flyer for top 10 tips for employers and knowing how to report a security breach and how to get hold of security. Because if your internet goes out and something happens and you don't have your contacts for security, you should have that somewhere other than just on your intranet or through your email. Another question is Lindsay. The other day we were speaking on a podcast with two women about sharing children's information online. In that podcast, we talked about the fact that Facebook has become a real asset in Europe because of their ability to help gather data and share important data for the epidemic. And we contrasted that with just recently, they were penalized by the authorities in Europe for their ability to collect data and share it. What do you think about that contradiction there?
SPEAKER_00I do think it's interesting. I myself am not a social network user at all. I have very little online presence. So I do think it's very interesting that juxtaposition where uh they're being fined in one instant, but then also being considered quite essential in times like this. I think the authorities will need to look at that and maybe use a bit of discretion in what is reasonable in this specific time frame where we're dealing with COVID. Again, I might not be the best person to answer this because of my kind of loathe for social networking tools, but I I can see that coming into play, some sort of discretion, maybe more of a like, hey, you I know you're trying to do a good thing here, but don't do it this way. I really can't answer beyond that without invoking personal opinions.
PaulLindsay, many people may expect that DPAs just give one statement or one guidance document, and that's that. But to me, that doesn't seem to be the case. We've seen already two statements from the European Data Protection Board, also from multiple national DPAs. We see government communication also on privacy and data protection issues. Even the Dutch King has said that he considers privacy also to be vital in these times of crisis. Kudos to him. But what are your observations here?
SPEAKER_00It feels like this is going in waves as far as guidance. So wave one seems to be generalized guidance from DPAs, regulatory authorities, financial regulators, where it's okay, we need to get something out there, people need to know just the basics. And then they're hungry. Yeah, and so that seems to have been wave one, and then wave two or two seems to be the legislature responding. So for instance, oh interesting, yeah. Yeah, so the the legislature responding, so not even the legislature, but for instance, in New Zealand, the OPC provided general guidance on COVID-19, and then the Ministry of Health provided basically this guidance saying that hospitality establishments have to keep a guest register. And so then I would say wave three would be the regulatory authorities responding to the legislature or the government's decrees. So what we've now seen the OPC New Zealand kind of go back and say, okay, in specific reference to what the Ministry of Health has said regarding these guest registers, this is how we want you to handle it from a data protection standpoint. So I kind of see it emerging in these waves. And so uh I think we're kind of in the middle of wave two entering into wave three as we see more legislatures start to address this. Denmark has also passed a decree saying that the Ministry of Health basically can promulgate regulations that that dictates what personal data can be collected during an emergency such as this. So it'll be interesting to see if then the Denmark DPA comes out with guidance specifically regarding what has taken place in the legislature.
PaulI think this is a good point. It's interesting.
KLindsay, I was reading a post by IAPP, the International Association of Privacy Professionals, about how the key word is proportionality. That resonated very strongly with me. What do you think about proportionality applying to what we're seeing right now when it comes to personal data, privacy, getting information when it's needed, anything along that line? Any thoughts on proportionality? Or would you suggest a different word?
SPEAKER_00No, I think proportionality is the buzzword of the COVID-19 epidemic as far as personal data is concerned. Every single guidance that we see, especially coming out of Europe, uh, is mentioning proportionality. So where a data protection authority can't specifically say you can collect X, Y, Z because they just don't want to get into too much specifics. They are relying heavily on the fact that employers still have to exercise proportionality under the GDPR or national law. And I think across the board that that is the key factor in all of this. If you're not getting the guidance you need from your specific regulator, then proportionality is the safest way to go.
KAnd then Lindsay, I'm gonna follow up a little bit on what you said earlier about how regulation and guidance is going in waves, because we're seeing that a little bit here in the US as well. A lot of states that were front runners in consumer privacy laws, their bills are no longer even alive. And in California, we're seeing an interesting one because we got a couple of different things going on at the same time. We're looking for enforcement from the Attorney General of California for CCPA to go into effect no later than July 1st. There was already concern over that because we're we're on the third round of draft regulations now, and companies may not have time to come into compliance. But now companies are in a position where they can't even try to work on compliance because of the current environment. And so there's a lot of chatter going around about delaying the regulations and a debate about whether the attorney general can choose to delay enforcement on July 1st based on current circumstances, or whether the legislature needs to make that official that they can push his date off uh to enforcement. I kind of think we can go either way.
SPEAKER_00So we're seeing it worldwide. I'm interested to see, especially in the United States, what happens with facial recognition services and technology bills. There have been some states that have banned it outright just until they can get a hold on what this means from like a privacy standpoint, security standpoint. So I am interested to see if any of this like wave two legislative response has any indication of how they will, maybe government will be using facial recognition services or technology. We've seen in a few jurisdictions where public authorities have attempted to either ask the question or use telecom data in order to track people where they are, locations, just to get an idea of where people are gathering and the the spread of the disease. So that's also something that's interesting. It's mostly out of the public sector right now, so it's not something we've been mostly concentrating on. We've been concentrating on the private sector, but I am interested to see if anything there will be any movement there.
KVery interesting.
PaulYeah, thank you, Lindsay. That was great. Thank you for joining us this time, and we hope to have you on again at a later point. I'm sure we're not done talking about the coronavirus anytime soon.
SPEAKER_00Thank you, Paul. Thank you, Kay. Anytime I'm here for you.
KLadies and gentlemen, that was Lindsay Palmer, and we seriously couldn't say thank you enough. So from here, we're gonna move back into Cameron and Gabe, and we're going to start with that list of top 10. We were running through it with them. We're gonna start with that and pick up from there.
PaulSo, Cameron, one of the other top 10s, uh top 10 tips in in our list is transparency and making sure that it is also clear that people are working from home, what kind of data is being collected also by the company, uh, but also that there might be additional risks involved. Is this something you and your team, your sales team, are also discussing? And and are you making clear to your customers, for example, yes, we are working from home at the moment?
SPEAKER_05Um not necessarily. I mean, anyone that we're prospecting, we're not like necessarily saying, hey, we're working from home. We are changing our our message and our our goals because I think it's it's important to come out of out of this and try to just be a helpful resource more than anything, especially around, you know, when you work for a privacy company, we're all about trying to help other companies protect their private data. And our approach to it is, you know, hey, we have uh these helpful articles, you know, tips from working from home, that kind of thing. I think it just comes without saying, I guess. But I don't think there's anything that we've said to be like, hey, we're working from home. I think it's just kind of goes without saying.
SPEAKER_02And do you have clients that are asking you for advice on what to do for their own systems? Because I know Spirion is very into the privacy and security. I love your philosophy about you know protecting data and limiting sensitive data. Do you have clients that are coming to you with specific issues and questions?
SPEAKER_05Like our current customers?
SPEAKER_02Uh, could be current customers, or do you have an influx of new clients? I'm hoping the answer is yes, that are saying, oops, we need to put something in place.
SPEAKER_05Um, I haven't seen much activity. Our customer success team has probably encountered some. I would say that, you know, as a company, we have uh released a free discovery product to deploy on uh as an agent for your virtual machine, and you can actually download that for free if you wanted to kind of kind of as a like, hey, we're trying to help. This isn't like a ploy to try to, you know, there's a catch here. It's literally a free discovery agent. And I'm sure Gabe can probably touch on that a little bit more, but it's nice to be able to offer that to our prospects because we we just want to try to help. And in these times, this is probably the best thing that we can do across the board.
SPEAKER_02So you know, I'm going to your LinkedIn because I think it was yesterday that y'all posted a free security thing for people during these times. I know that's a very technical phrase there, free security thing. Exactly. But I'm going to it right now.
SPEAKER_01That's exactly what Cam was referred, was alluding to. And so we have seen uh a lot of questions from both customers and non-customers about all right, how how can we help keep that information safe? What what can we do in particular? The tool that you're referring to, since one of the challenges is so many organizations in the rush to get people working remotely, means that a lot of information that may have otherwise stayed within certain controlled environments are now in people's homes. And that offer is for folks to go ahead and and help themselves understand what sensitive information that they are now working with in those environments and help them clean it up and and uh make sure they're not exposing themselves to yet another problem on on top of all the challenges that we're currently facing. So there's been there's been a lot of of interest and and chatter in in a number of different areas of what working from home for these organizations now means, the least of which is that information moving to these to these remote environments.
SPEAKER_02Absolutely. I'm I'm looking for that link. I'll make sure that I post that link down in the description of the podcast so people have that to come in. What about incident since we're on yeah, that's where we were both going since we're talking about security, incident notification and security concerns. Most employees are taught how to report potential security concerns. The security incidents are through the roof right now with the phishing and the scams and the fraud and the hacking. It's outrageous. What else do you recommend for employees working from home about incident notification and security concerns? It could be tips about how to avoid something, as well as it could be what are you seeing that employees need to know? Like one of the big things I picked up on is in case their in their internet goes out, they need to have the notification contact for security somewhere else, on their phone, on a post-it note, on their wall, something.
SPEAKER_01That's huge. That's uh that's very, very important. From an incident notification standpoint, I think that's probably one of those areas where organizations need to make sure that they are over-educating their employees, because containment of that incident is equally as important. And if unfortunately something were to happen, those channels may now be otherwise disrupted as well. And there's a lot of there's a lot of phishing attacks and all kinds of other malicious activity that's currently going on in uh in this environment. And incident notification is going to increase quite a bit. Part of the challenge these organizations are going to have is how they respond to these these incidents, how they triage them, how they they prioritize them, and how they they respond to them. So having multiple channels for those, for those are a very good start.
SPEAKER_02Have you seen a big uptick in security concerns, or is there something that specifically comes to mind that kind of surprised you that is occurring?
SPEAKER_01Not anything that's a surprise, but I might be an old cynical grizzly security vet. So but there's but there is an uptick. There is very much an uptick where there is chaos. Chaos breeds opportunities for for bad actors, and and there's a there's a significant uptick in every type of activity you can think of, from just the the random, malicious, um, you know, no good nick who wants to zoom bomb someone to folks who are who are f actively fishing um and trying to get access to to data as well. There's there's an uptick across all vectors. One of the things that bad guys are pretty adept at is adapting their uh capabilities rather quickly. They are they are certainly more agile in doing so than we are as defenders, just kind of the natural landscape of things. And so there is an uptick across all vectors of attacks right now.
SPEAKER_02Right. I think one of the first things that came out was a false website tracking COVID-19 activity and purporting to be a World Health Organization or a CDC, and it was it was not. It was a fraudulent site.
PaulYeah, we've seen dozens of apps, uh, especially in the Google Play Store. We've seen also lots of other oh, we've seen lots of text messages claiming to be from banks that bank cards need to be replaced by self-disinfected bank cards to fight corona. You you gotta give it to the criminals. They have become very creative in coming up with new ideas of things that we might like in the future, but that doesn't mean that we should fall for them now.
SPEAKER_01Yeah, they creativity is not one of their challenges as bad guys at all, not even a little bit.
SPEAKER_02Okay, so let's talk about some of the other things that um I I want to get to. So privacy laws in countries. So we know here in the US we have different privacy laws than the EU does, than South America does, than Australia does, than Canada does. Are you seeing any or do you think there's any additional controversy with US companies trying to manage privacy under these circumstances, but yet they fall under the laws of other nations as well? Maybe things such as taking temperatures, they come in the door.
SPEAKER_01That's yeah. I mean, I I don't even know if I I don't even like that for US companies, much less ones that fall under other countries' regulations. But I apologize, though.
SPEAKER_02So specifically, you're asking if what do you what do you see under the the current circumstances, the privacy issues that we're dealing with? And Gabe, if this is a stupid question, then we can just skip to the next one. Um but are you seeing any particular conflicts between how US companies are managing privacy right now, especially if they fall under laws of other nations as well? In other words, do they have a bifurcated approach of doing something different here in the US than they are in Europe?
SPEAKER_01Yeah, I think the biggest the biggest conflict you see is that US companies weren't used to to dealing with privacy at all. They weren't used to enforcing it even a little bit. And now they're they are being asked to do so under you know the California Consumer Protection Act. I think one of the things that we saw, Google themselves challenged the EU on whether or not they had to enforce someone's right to be forgotten in jurisdictions outside of the EU. And so what we're seeing is this natural resistance of businesses to uh remediate data that uh is their lifeblood. That's that's probably the biggest friction. I I see more friction in terms of uh businesses that thrive on data, which is most businesses these days, and there's the friction between that versus the friction between uh US laws and international laws. I think we can find ways to uh to synergize those two. And one of the just kind of best practices is typically, you know, you you you apply your controls at the the highest level, the most stringent level, and that then just ensures that you don't have to bifurcate your practices. But the friction really hits the rubber meets the road and friction there when uh when it's the business practice that starts being interrupted by the privacy laws, whether they're US or or international ones. Organizations are are reluctant and resistant to change, especially as it will change their bottom lines.
PaulSo do you think there is sufficient guidance available from uh governments, from governmental authorities, from independent supervisory authorities on what is allowed and what isn't allowed in these in these days?
SPEAKER_01There absolutely is not, and so much so that uh under CCP in particular, there's a lot of uh vague language in there. It was written very quickly, but there's a lot of interpretation that still needs to to to be borne out through GDPR as well. A lot of things will be challenged in the courts, and that will that will equally uh you know change uh the the guidance, if you would. Certainly guidance, not at all. It might be somewhat anecdotal, but we we too have a privacy lawyer on our staff, Scott Giordano. Um shout out Scott Giordano, love him a shout out. And the number of requests we get for his for his time to to be able to for folks to be able to get clarity and guidance around all these things, it's it's incredible. It's it's significant. Um, when we host webinars with him, the number of people that flock to those are are huge for the for exactly that reason. There's certainly not enough guidance, and folks are hungry for guidance. So, what what impact does that have on your immediate operations? Well, we you know, we have some scale issues there. Obviously, I've only got one Scott Giordano, unfortunately. I'd love to there is only one Scott. When folks are actually trying to implement our solutions for for their greatest security and privacy needs, it it it really means we have to spend a lot of time. Um helping them understand how best to uh to make sure that they don't fall afoul of those things. It's not a negative impact. It's uh it's more of a scale thing, just you know, making sure that we have that we spend enough time with each person and each customer so that they understand those things.
PaulYou hear some people say, well, uh why should we care at all about privacy in in these times? Let's fight the crisis first, then let's make sure that we recover the economy because the economy all around the world is taking a very big hit, probably more so than in 2007, 2008. So why care about privacy? It's only a it's only a stand in the way, it's only a hindrance at the moment.
SPEAKER_02It's a luxury, not a necessity.
SPEAKER_01Yeah, I I I think the only people that say that may be somewhat ignorant to uh to to the realities of what happens when when we lose control of our privacy, especially if we were to lose control of it to foreign adversaries. You will just be fighting one challenge after another. So you you can you can get out in front of it now and uh and and uh you know kind of suffer through some of the the pains of that, or you can r lose it forever. It's not it's not something that, all right, I'll ignore it now and I'll deal with it later and it'll still be there to deal with. Once you lose it, it is gone. You don't you don't regain that privacy, certainly the many aspects of it once it's uh once it's been uh compromised. So actually the real reason to pay attention to it now is uh it's a one-time event. It's a one-time event. You don't you don't get to unring that bell.
PaulYeah, that sounds fair to me. That's also one of the things that of course the uh the commissioner alleged to alluded to in in the conversation I had with him earlier today. Privacy is a fundamental right, and we should be careful because especially in times of crisis, these are things that are easily set aside but very hard to get back. That's right. That's exactly what it is.
SPEAKER_02It is. And in looking at some of the the questions that are going across, we did a webinar the other day on an update to US law, and during it, one of the attendees wrote me a question and said, Did we think? And now our law wasn't specific, our updates weren't specifically on COVID-19, but of course you can't give an update on US law right now without covering it. They asked that was there any guidance that whether or not you can ask employees for what is it when they come off an FMLA or a workers' comp, a um return to work or fit for duty? There you go. Could you ask employees for a fitness for duty report in order to come back to work after this COVID-19 episode passes?
SPEAKER_01I mean, do we ask cancer patients to do that? No. I I I don't know why this should be any different, quite frankly. I mean, it's uh, you know, if someone were to let's say this were not a pandemic, let's just say it was not a pandemic and they had come down with COVID-19. Um COVID-19 wasn't a pandemic, would we ask the same? Or is it that we're only asking because it's highly contagious? Because, you know, the there are lots of things that are highly contagious. But I don't think that's reasonable. That's I again that's for me as a as an individual, as a uh as someone who cares about you know privacy and in his own privacy kind of deeply to uh push back on that one. What what is so different about this scenario that one would need to prove their fitness for work any more than say, you know, you broke your hand. Can you can you still type? No one asked that question. I'm sure the the ADA would be all over this one. I don't see that one really uh getting a whole lot of airtime beyond kind of the the mental exercise of it. There's no way that one holds up in in any court of law in this country, I believe, anyway. But again, not a lawyer, but I love that.
SPEAKER_02Want to disclaim that. No legal advice here on the thing. Well, there are two websites that I am following that give very daily updates on guidance from regulators around the world, including on legislation, on COVID privacy on everything. Uh, the two websites, the two law firms, Fisher Phillips and Ballard Spar. So I'm looking at the Fisher Phillips one. We'll make sure to provide these links uh in the description. Well, you're gonna get all kinds of links in the descriptions for these podcasts. But this one was an updated question, and it was during a pandemic, may an ADA covered employer ask employees who do not have symptoms to disclose whether they have a medical condition that the CDC says could make them especially vulnerable to complications. And this one had to be updated based on new advice, and it was generally no. However, if it becomes severe or serious, according to any level of geographic health officials, they may have subject sufficient objective information to reasonably conclude that employees will face a direct threat if they contract it, and then they could make disability-related inquiries or require medical examinations of asymptomatic employees to determine which employees are at a higher risk of complications. Does that scare you?
SPEAKER_01It worries me. Yeah, I'm not comfortable with that, not at all. Yeah, I'd like to understand. Oh, right. Yeah, what's missing for me in that is like what's so what's the justification, right? Like, what exactly is the justification? More importantly, what what outcome are you trying to drive with that? That worries me.
PaulRight. Right. Under GDPR, all of this would not would just not be allowed. It it's it's fairly straightforward. Everything related to corona and COVID-19 and and and your medical conditions are special categories of personal data for which the processing is restricted. The employer cannot just force you to provide that information, not even in an indirect way. Feels so self-evident, doesn't it? It does.
SPEAKER_02Right. It does, but again, I I hate to keep saying US point of view. US point of view. When are we gonna wake up and join the real world when it comes to privacy? So, yeah, because we even had HHS, the Department of Health and Human Services, even came out with two advisories. One advisory was about how you can share HIPAA-related information, PHI. Now, Paul, for you, I don't know if you work a lot with HIPAA in the United States. Trust me, people who work with HIPAA don't necessarily understand all the nuances of it. But PHI, protected health information under HIPAA, is only protected health information if the company is subject to HIPAA. And companies are only subject to HIPAA if they file one of 11 types of electronic transactions, most of which are centered around health claims. So, with that foundation, that not all medical information is considered protected under HIPAA, there were these two advisories that came out. The first one was just explaining current status of HIPAA and where you can share information that first responders can share medical information about people. Doctors can share medical information about a patient to their loved ones, their friends, their family, even without the person's permission. All of that has already been part of HIPAA. HIPAA was never intended to get in the way of patient care. But the second advisory was about how they're going to suspend enforcement on HIPAA violations, not all of them, but they're going to suspend enforcement on a lot of violations, especially when it comes to telehealth. So being able to treat patients at a distance. And when it comes to whether or not there is the appropriate agreement in place between a vendor that you might be sharing this information to, but you had to get them on board quickly in order to manage the circumstances. How does that resonate with anyone in that some of the one of the only privacy laws we have?
PaulThe latter part I understand that you that you cannot immediately do an impact assessment or a risk assessment when you need to act quickly to resolve a major crisis. That is fully understandable. And again, with my European hat on and looking at the GDPR, there is even often a possibility to postpone certain obligations, especially in relation to individual rights, as long as the essence of the fundamental right is respected, which means that at some point later on, when everything has quieted down, you may still want to do that risk assessment or that privacy impact assessment and put the proper safeguards in place. And that will be after the fact. And it may be that there were some problems in between, but at the same time, then you resolve them later on and you acknowledge that during a time of crisis, you ignored those just to be able to solve the crisis first. And there I think that would be acceptable. But just not to not to enforce the law all out, that that seems too far. Going too far.
SPEAKER_01I don't know if I have anything intelligent to add on top of that, other than I I wholeheartedly agree. That just seems like it goes well too far for all the same reasons. I I certainly would not endorse that.
PaulAnd luckily, also the California advocate or advocate general, attorney general, the California attorney general has said that also he still intends to enforce CCPA as of July 1st, or when the regulations are finalized. So also in California, you see privacy laws will still be enforced, despite everything else that is going on. And I applaud him for that.
SPEAKER_02And despite the fact that the regulations haven't been passed yet.
PaulWell, that's a tiny detail, but okay.
SPEAKER_02We are at the top of the hour. So last question, and by the way, Cameron and Gabe, like I said earlier, this may very well wind up being two separate sessions. We've got about 20 minutes of some legal analysis or legal uh updates to come from one of our uh European researchers. So we have that to add in as well, which one of the words that resonated there was proportionality. So I this probably isn't the best question to close on, so it might not be the last one. Another one under discrimination uh issues. Do we have any discrimination, equal employment opportunity concerns related to COVID? The only thing they answered was employers cannot select employees for disparate treatment based on national origins. And the CDC recently warned do not show prejudice to people of Asian descent because of fear of this new virus. Do not assume that someone of Asian descent is more likely to have COVID-19. Now, I thought one, it's a shame we had to put that out there, because of course that's logical. But two, they didn't address any other issues. Older people are considered more vulnerable to COVID-19. People with pre-existing health conditions are considered more vulnerable, and the only discrimination they addressed were people of Asian descent.
SPEAKER_01That may be part and parcel to just the overall political landscape. That's that's possible. I'm just speculating here. It is it is a good question. Maybe it's one of those scenarios where folks are simply not anticipating that that will be a concern. And sometimes, not sometimes the way the way I've observed the our overall legislative process in in the US is we we we tend to cover just the you know as much as we need to. It's kind of a just in time law, if you will. Right.
SPEAKER_02The minimum necessary.
SPEAKER_01Minimum necessary. That that feels very just in time to me. It's like let's let's cover what we know is an open issue out there now, and let's not let's not speculate and try and and over-legislate the rest, which to be fair, I can kind of understand and agree with, right? I there there's always a balance with with legislation and and not going too far too fast. But it is it is interesting that that was neglected to be put in there. That does not seem like oversight. That feels somewhat intentional, right?
SPEAKER_02Hopefully it's it does, right?
SPEAKER_01Yeah.
SPEAKER_02Especially when you can see that there might be discrimination issues, which cross over with privacy issues when it comes to people that may have vulnerable populations at home, the older um people with pre-existing health conditions, children. I mean, can you see discrimination against women for having to take care of children? Because somehow that seems to be the default norm, as opposed to men who need to take the time to take care of children.
SPEAKER_01Yeah, I think you will almost guaranteed see that, unfortunately. That that is that is a thing. Yeah, that's a thing for sure.
SPEAKER_02Yeah, that's a shame.
SPEAKER_01Absolutely is a shame. And and if the work from home persists, you are almost guaranteed to see some favors being being uh being levied in one direction over the other. I I think it's it's upon all of us in positions where we can influence those things to ensure that they don't they don't occur, though.
SPEAKER_02Well, and I will say that funny enough, I think I've seen it happening. The discrimination, and I'm doing air quotes here that you can't see, is because, and I've I've actually read studies on this, men get the allowances to take care of children because it's not it's not their standard way of operating. Women should be able to do it without allowances because they do it all the time.
SPEAKER_01I agree.
SPEAKER_02And so men are given extra time or leeway in order to do it. Crazy. I don't know that this is across the board, just speculating here. This might be one of those controversial topics that people are all up in arm zone when they hear us talk about it. Paul, hit me with a really good closing question because Cameron and Gabe are are full of wonderful information, although I haven't heard as much from Cameron as I would like to. So, Cameron, you're gonna answer this question first that Paul's gonna give you hit with something brilliant.
SPEAKER_05Oh man, put me on the spot. She puts me on the spot as well.
PaulOkay. There you go. So, in in wrap-up, Cameron, if you can give one recommendation to everybody who is now forced to work from home from the privacy security perspective. Uh, and and we've already discussed the video sharing and keeping your documents secure and all of that. But if there is one other thing that you could tell them, what would that be?
SPEAKER_05I mean, I think one good thing to to kind of touch in, and I think Gabe was kind of talking about this a lot earlier. We I think we touched on it, was you know, be mindful of your your surroundings and try to try to plan out your day as if as if you're actually going to work. So I would say get up normally like you would when you were going to work, take a shower, get ready, you know, find a nice place in your house that's actually quiet and away from distractions. And and uh I think that allows for less um just more productivity, and you will have less privacy issues when it comes to someone running in and or like you know your wife coming behind you and being, you know, just displaying any kind of privacy that uh when it comes to physical privacy. But I don't know, I I think that that goes a long way because and and again, I think also using video with everybody in your in your company a lot more than you used to is key too, because a lot of people probably miss those relationships in the office. They miss that that connection. And I think when you're talking with people, if it's prospects, your company, what whatever it be, I think using video and uh that kind of communication is really really helpful and key. Absolutely. Gabe. Oh, and before Gabe jumps in, yeah, I'm just gonna I'm gonna steal, I'm gonna steal one thing that's technical that he can touch on even further, and I'll throw out a shameless plug, which is using something like Privacy Badger as as a a good little thing to throw on to your to your computer to to help with privacy.
SPEAKER_01Oh I appreciate that. And and and that uh that tells me we've been really we've we've been really on the same mind waves, Cam, because that actually is one of the things I was going to suggest, which is and privacy badge is just one of them. Take additional but uh reasonable precautions above and beyond what you would have normally done anyway, and things like installing privacy badger into your your browser, which uh helps protect your your privacy when browsing, amongst others. You've got you know, uBlock, you've got ad block plus, you've got ghostary, you've got https everywhere, you've got disconnect. I have all of those and then some installed in my browser. Those are great from both a professional and a personal perspective. Again, we talked about bad guys being very creative. And one of the ways that uh they're going to understand and try and track who they should be attacking is by placing, you know, uh relatively benign but malicious uh tracking capabilities throughout uh throughout different parts of the web, et cetera. So take take those additional precautions to protect yourself. Um and I think if as an individual you took those precautions to protect yourself, many of those will naturally equally help protect uh the things that you work on. Because the things that you work on ultimately affect other people just like you, the person across the street and up the block, et cetera. So be mindful, just like Cam said, be mindful. Think about those actions when when when you're interacting with information. Pretend that information were your own, pretend it were that of your significant others, your your mothers, your your uh your your neighbors. Be mindful.
PaulThank you very much. If people want to reach out to you to to learn more about all your expertise, where can they reach you?
SPEAKER_01Well, they can reach us, uh www.spirin.com. Uh they can find us online uh on social media on Twitter. You can find me at Gabriel Gums, you can find Spirit at Spirian. Cam.
SPEAKER_05You can find me at CamDivy, and you can find our podcast at privacy plod.
PaulGood. And for all the listeners, if you like our series, please do tell your friends and colleagues about us as well. Should you have any questions or suggestions, please reach out via serious privacy at truststark.com or via Twitter at podcastprivacy. You will find Kay on Twitter as Heart of Privacy and myself as Europol B. Thank you again for listening to Sirious Privacy. Until our next episode, goodbye.
SPEAKER_02Bye, y'all.