When Lawyers Sign Off but Systems Don’t Protect

▶ Watch (3:01)

A Canadian college campus found facial recognition built into its vending machines. The company’s response: the lawyer said it was fine. Biometrics qualify as sensitive personal data under GDPR. A legal sign-off doesn’t make a system privacy-respecting. Wuyts’s argument: you need to engineer privacy from the start, the same way you engineer security. Compliance is a bar, not a goal. Systems that process biometric data need privacy engineering before they need legal clearance.

Unlinkability: The Privacy Goal Confidentiality Can’t Cover

▶ Watch (5:10)

After Roe v. Wade was overturned, period-tracking apps became potential evidence of abortion. Wuyts explains why via the Guess Who board game: each question alone reveals nothing, but combining answers shrinks the anonymity set until one person is left. The same logic applies to menstruation data. Privacy’s central concept is not confidentiality but unlinkability. Apps responded by adding anonymous-use modes. The engineering answer is data minimization: collect less, link less.

Why Anonymization Is Harder Than It Looks

▶ Watch (9:26)

Strava released aggregate workout data labeled anonymous. Heat maps revealed the routes of military personnel at classified bases. On an individual level, Strava lets users hide their start and end locations, but researchers showed three overlapping runs still pinpoint a home address. The same flaw appears in location-based dating apps: three triangulation points expose a user’s position. Synthetic data, fed through AI to produce fake-but-plausible records, sounds better but clusters near originals, making the source locatable.

Purpose Limitation: Why Reusing Collected Data Breaks Privacy

▶ Watch (13:04)

In June, Meta updated its privacy policy to use all posted content, including images from minors and deceased users, for AI training. Opting out required finding a buried objection form. NOYB filed complaints with European data protection authorities, and Meta halted EU AI training. The lesson: having data doesn’t mean you can repurpose it. Original collection purpose governs reuse. “Ownership” isn’t a legal concept in privacy. Controllers determine purpose; data subjects hold rights.

Why GDPR Fines Reach Small Companies Too

▶ Watch (21:36)

Meta paid over 1 billion euros for transferring EU data to the US after courts invalidated Safe Harbor and then Standard Contractual Clauses. A separate 400 million euro fine covered personalized advertising. Belgian news publisher Media House received daily fines of 25,000 euros for cookie consent dark patterns: a bright-red “agree” button with the reject path buried two clicks deeper. GDPR maximums reach 20 million euros or 4% of annual global turnover. Large companies attract attention first; small ones are not exempt.

How Physical Environments Became Data Collection Surfaces

▶ Watch (28:44)

A Mozilla study of modern car privacy notices found manufacturers collecting marital status, medical data, genetic information, and sexual data. Tesla workers shared intimate images from car cameras among themselves. A patent application described using in-car microphones to serve targeted ads keyed to captured keywords. Microsoft’s Recall feature, which snapshots the screen every few seconds and stores results locally, creates a shared surveillance record on multi-user home PCs. One day after the announcement, a report concluded the local implementation was not secure.

Q&A

What can a consumer do when every company turns AI training on by default? In Europe, file a complaint with the data protection authority or use NOYB, which accepts individual complaints and pursues them collectively. ▶ Watch (44:09)

Does readability of privacy policies determine how well users are protected? Notices need to be understandable, but the burden shouldn’t fall on users to hunt for opt-out paths; applications must build privacy in by design. ▶ Watch (47:42)

If marketing departments want all the data, what is the argument against bulk collection? Studies show that specific, targeted training inputs produce better AI outputs than throwing everything in. ▶ Watch (49:11)

Notable Quotes

if you do nothing you agree Dr. Kim Wuyts · ▶ Watch (13:28)

if you don’t need it don’t store it Dr. Kim Wuyts · ▶ Watch (37:34)

privacy goes beyond confidentiality Dr. Kim Wuyts · ▶ Watch (42:39)

Key Takeaways

  • Privacy is distinct from confidentiality; unlinkability and data minimization are the core engineering goals.
  • GDPR fines reach 20 million euros or 4% of global turnover; dark patterns carry daily fines.
  • Anonymization techniques are still immature; store less data to minimize what can be linked or breached.

About the Speaker(s)

Dr. Kim Wuyts is a leading privacy engineering expert with over 15 years of experience in security and privacy. Before joining PwC Belgium as Manager Cyber & Privacy, she was a senior researcher at KU Leuven, where she created LINDDUN, a privacy threat modeling framework, and co-authored the Threat Modeling Manifesto.