Why is data privacy important?
As we mark Data Privacy Week 2025, the growing complexity of data-driven technologies and the escalating risk of cyber threats underscore the need for businesses to rethink their privacy strategies.
Our online activity creates a treasure trove of data, from interests and hobbies to purchases and online behaviors. It can even include information about your physical self, such as health data—think about how an app on your phone might track your steps. This data can be invaluable to businesses looking to personalize interactions, but are they keeping it safe?
With insights from industry leaders, TI explores how businesses can navigate data privacy challenges while leveraging it as a competitive advantage.
Data privacy as a market differentiator
The financial and reputational repercussions of data breaches are escalating. According to IBM’s 2024 Cost of a Data Breach Report, the global average cost of a data breach has reached $4.88 million, marking a 10% increase from the previous year and the highest figure on record.
Meanwhile, a 2024 Cisco Consumer Privacy Survey found that 75% of consumers will not purchase from organizations they don’t trust with their data. These figures highlight that data privacy is no longer just a compliance requirement but critical to customer trust and business longevity.
Akhil Mittal, senior security consulting manager at Black Duck, emphasizes the increasing importance of data privacy, not just as a compliance requirement but as a fundamental part of building trust and market differentiation. He states, “High-profile breaches and stricter regulations like GDPR, CCPA, and emerging AI-related privacy laws are pushing companies to make data privacy a fundamental part of their operations.”
To mitigate risks, Mittal advocates adopting a “privacy by design” approach—integrating privacy measures from the start of development. He also highlights the role of privacy-enhancing technologies (PETs), such as data anonymization and AI-based data protection, which can reduce risks and strengthen customer trust.
Building security by design: the shift to zero trust and encryption
The rapid adoption of zero trust architecture (ZTA) is transforming how businesses approach security. Carlos Aguilar Melchor, chief scientist for cybersecurity at SandboxAQ, advocates for ZTA as a cornerstone of modern data privacy strategies. “Zero trust underscores the ‘never trust, always verify’ principle, enhancing resilience against cyber threats,” he explains.
Aguilar also emphasizes the importance of Post-Quantum Cryptography (PQC) to future-proof encryption against emerging quantum computing threats. He notes that companies must implement technologies like Static Application Security Testing (SAST) and Software Composition Analysis (SCA) throughout the Software Development Lifecycle (SDLC) to uncover vulnerabilities and ensure compliance.
AI in Data Privacy: threats and solutions
AI is reshaping data privacy risks and protective strategies. On one hand, AI-powered cyber threats—such as deepfake phishing scams and automated hacking tools—pose significant risks. On the other hand, AI-driven PETs, including data anonymization and federated learning, are helping businesses strengthen security.
As Paul Bischoff, consumer privacy advocate at Comparitech, notes, “AI programs scrape as much data as they can from public sources to train their algorithms. As a result, personal info can be included in an AI’s response to a prompt, either intentionally or unintentionally.” This heightened capability makes personal data more vulnerable to exploitation by criminals.
Sunil Agrawal, CISO at Glean, stresses the need for robust governance in AI systems. “Data privacy isn’t a box to check—it’s a day-zero imperative,” he states. Agrawal recommends integrating real-time detection and correction mechanisms to address access anomalies as they arise to ensure responsible AI practices.
Transparency as a competitive edge
Dr. Andrew Bolster, senior R&D manager at Black Duck, points out that open-source AI models, like DeepSeek, emphasize the value of transparency in advancing privacy and innovation. However, he warns against neglecting security measures when leveraging open-source platforms.
Open-source AI, known for its transparency and collective development, may offer advantages over closed-source options in terms of adaptability and trust. As organizations recognize these benefits, a significant shift towards open-source AI could drive a new era of technological advancement.
High-profile breaches: lessons learned
Recent data breaches underscore the urgent need for stronger data privacy measures. The MOVEit breach in 2023 impacted nearly 100 million individuals due to a vulnerability in a third-party provider. Similarly, incidents like the T-Mobile API leak exposed the data of 37 million customers, while the Samsung AI data leak showcased the risk of employees unintentionally sharing sensitive source code with AI tools.
Besnik Vrellaku, CEO and founder of Salesflow.io, highlights the challenges of ensuring data privacy in the age of third-party generative AI tools, noting the significant concerns regarding data leakage faced by larger corporations. To mitigate these risks, Vrellaku emphasizes the importance of due diligence and continuous updates to terms and conditions.
What’s coming next?
Governments worldwide are tightening data privacy regulations. Laws like the EU AI Act and various US regulations impose new transparency requirements for AI-driven data processing. Data localization laws in countries such as India and China are enforcing stricter data sovereignty rules, requiring businesses to store data within national borders.
Experts predict that the next five years will bring major shifts in data privacy, including robust AI governance and stricter regulations surrounding AI-driven data processing. Businesses must also adapt to incorporate post-quantum cryptography to safeguard sensitive data amidst growing consumer privacy concerns.
As Chris Linnell, associate director of data privacy at Bridewell, points out, it’s not just regulatory fines that matter. Losing consumer trust is a significant concern. “Transparency and compliance with privacy laws are key to maintaining customer relationships,” he states, reinforcing that demonstrating proactive compliance is essential.
“Data Privacy Week serves as a reminder that protecting consumer data isn’t just a regulatory requirement—it’s a moral duty and a business advantage,” concludes Mittal. Organizations prioritizing data security today will go a long way in building trust, reducing risks, and remaining ahead of regulatory scrutiny in the future.

