Privacy risk includes inference, not just disclosure
Privacy harm does not require anybody to see your data. It can come from what is deduced about you.
A model that infers health status from shopping habits, or sexuality from browsing, has not disclosed anything you provided. It has produced new personal data about you, which carries the same obligations and frequently more sensitivity. Thinking of privacy purely as preventing leaks misses the entire category.
More on Privacy engineering
- Anonymisation is about re-identification riskThe name was the easy part
- Differential privacy limits one person's influenceOne person cannot move the needle
- Consent interfaces can undermine genuine choiceBoth answers, very different distances
- Purpose limitation prevents silent mission creepThe pipe was laid for one thing
- Privacy by design moves decisions earlierA line on the plan, or a hole in the wall
- A privacy notice does not create permissionTelling is not asking
