Skip to content

Part 1: Is Data Privacy Dead? The Answer Must be No

  • by

Photo by Jonathan Richard.

Claire McKay Bowen and Aaron R. Williams


“Data privacy is dead.”

As data governance and privacy researchers and instructors in higher education, we often hear this. For one of us, it has come up repeatedly in just the last few weeks, from people across varied walks of life. A person at a conference made the comment after a panel discussion on government data in which one of spoke about privacy. The same reaction came from a triathlon coach, who after asking about that author’s work, responded the same way.

It’s a common refrain, and it’s easy to understand why. News of massive data breaches, like the health data breach of 3.4 million patient records, can make us feel that privacy is a lost cause.

Despite these troubling developments—and how easy it is to feel defeated—we should continue to care deeply about our data privacy. We are not helpless. While the ultimate responsibility for protecting large-scale public data rests with the government and other institutions (we discuss some specifics in Part 2), there are some meaningful steps each of us can take to manage our personal digital footprint and strengthen our own privacy.

It’s not just about you or me. It’s about all of us.

We are often tempted to think about data privacy in purely individual terms. For many, the idea of their own information being online—from social media posts to business promotions—isn’t a major concern. However, a single person’s information can be a small piece in a much larger, interconnected puzzle. This phenomenon is often called the mosaic effect, where seemingly innocuous pieces of data can be combined to reveal sensitive information.

Imagine a 1,000-piece puzzle with an unknown image. Now, imagine 70% of the pieces are already in place. Those pieces represent people who don’t mind their information being public and reflect publicly-available collections (e.g., street view imagery or commercial databases). They make it easier to piece together more information than was intended to be shared. Even if you don’t include certain details in a social media post, enough auxiliary information may be available to guess the full picture.

The social media example demonstrates this problem well…

You might not care if others know you like running, your child plays soccer, or you have pets, but posts and photos that you share online could inadvertently reveal sensitive details about your life or those around you. A street sign, unique roofline, and distinct natural feature in the background of a photo might expose the location of your home or a loved one’s, increasing the risk of scams. A post about your child’s soccer game at a specific park could allow someone to look up the team’s schedule, know when you aren’t home, or even stalk your child. A photo of that soccer team may reveal the location of your child’s teammate, who may be trying to stay under the radar to avoid an abusive relative.

Each of us should be careful about what we share online, even when the information seems innocent. We never know what other puzzle pieces a malicious actor might have.

When we have the option to choose, we need to weigh the trade-offs.

The issue isn’t that our data exists online, but how it’s used and misused. Sharing information is often necessary for the services we enjoy, but the key is making those decisions consciously and requiring that the holders of the data act responsibly (for more on that, read Part 2).

We all make trade-offs daily. Many of us allow Google Maps to track our location for real-time traffic data or let Spotify gather our listening habits to recommend new songs. We may share personal and location data for car insurance discounts, or provide our contact information for store discounts and prizes.

Anytime we are prompted to share information, we should pause and determine whether sharing our information is worth the risk.

Some general considerations include:

  • Understanding how and why you are opting in—or out—of sharing data with third parties when signing up for any service.
  • Not sharing photos of children, which can be used to track and violate their digital privacy before they reach adulthood.
  • Avoiding social media challenges (such as “what were your first five jobs?”) or intentionally giving incorrect answers, since these prompts can be used to answer security questions for sensitive accounts.
  • Limiting the sharing of location data unless it is truly necessary, as it can reveal your routine, including where you live, work, and when you’re away from home.

Our personal actions are important but may not be enough.

While individual choices matter, they are not sufficient on their own. There are many instances in which we are compelled to share data (e.g., when filing taxes) or when data is collected without our knowledge (e.g., through license plate reader and surveillance cameras).

Another example is some universities use smartphone apps to monitor student attendance, tracking when students are late, leaving early, or missing class. These apps can also record which campus facilities students use. On one hand, this data can help universities understand student behavior, guide resource investments, or support emergency alerts. On the other hand, such tracking could reveal students’ identities, FERPA-protected information like grades, or real-time location, all of which raise serious privacy and safety concerns.

In one of the author’s classes, students are asked to keep a data diary for a day, tracking how their personal information is collected. They then read the privacy policy of one company involved. One student was alarmed to discover that her home security system shared and sold detailed information to third parties—including how she labeled individual rooms inside her home.

When data are collected and used with few (or no) ways to opt out, or downstream uses are hidden in the “fine print,” the primary responsibility for protecting privacy rests with the entities that gather, store, and analyze that information.

In the university example above, students may have little or no real choice about their location information being collected. If they want to attend the institution, their data may be collected by compulsion rather than by meaningful consent.

Individuals, alone, cannot reasonably defend themselves against situations like this, which is why strong data governance is vital.

Proper data privacy, security, and ethics measures require institutional accountability.

As a society, we must treat data privacy as a collective responsibility. Each of us has a role to play by engaging with—and holding accountable—the governments, businesses, and other organizations that collect our information.

Together, we can decide what data should be collected, for what purposes, under what safeguards, and with what limits on sharing and reuse. This also means insisting that our government enact, enforce, and continually update laws and protections to keep pace with new technologies and emerging risks.

Strong data privacy, confidentiality, ethics, and security policies should address the entire data lifecycle, including but not limited to:

  • Minimizing data collection to only what is necessary.
  • Ensuring secure physical and digital storage and adherence to FAIR principles (Findable, Accessible, Interoperable, Reusable).
  • Handling data sharing with appropriate consent and non‑disclosure protections.
  • Using data only for intended purposes, with clear guidelines to prevent misuse.
  • Communicating insights in ways that are accessible and useful while minimizing disclosure risks.
  • Establishing and following data retention schedules, including secure data destruction.

Data privacy is not dead…yet.

Data privacy is not dead…but we are dangerously close to it being so. Preserving privacy requires individual awareness, community engagement, and strong institutional commitment.