---
title: "Experts Discuss: Where Data Security and Data Privacy Meet"
description: Where Data Security and Data Privacy Meet. How data-centric security approach and comforte’s data security platform enable data privacy.
image: https://insights.comforte.com/hubfs/QA%20comforte%20Forrester_1.1.jpg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![Data Security & Data Privacy comforte AG ](https://insights.comforte.com/hubfs/QA%20comforte%20Forrester_1.1.jpg)](https://insights.comforte.com/experts-discuss-where-data-security-and-data-privacy-meet)

[Felix Rosbach](https://insights.comforte.com/author/felix-rosbach) l Jun 2, 2020 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance)

# Experts Discuss: Where Data Security and Data Privacy Meet

A few weeks ago, comforte AG  hosted an online webinar featuring Forrester. The focus of that presentation was the intersection point between data privacy and data security. The overall goal was to emphasize the impact on businesses large and small and how to put data security into practice.

The webinar provided a double-click into a variety of supporting subtopics, including privacy and ethics, the NIST privacy framework, and the intersection between security and privacy. It also touched on compliance challenges and evolving digital services. We used the [Forrester](https://go.forrester.com/) data control model as a strategic guide for the discussion. Along the way, we pointed to [comforte’s data security platform](https://www.comforte.com/resources-detail/news/data-centric-protection-explained-weighing-the-different-protection-methods/) and how it enables data privacy.

A number of questions came out of that webinar that we captured and discussed. We wanted to provide the answers to those in a Q&A format. Here are those questions, in no particular order of importance.

## Compliance

**Q:  You mentioned that compliance is not security and qualified that with the statement that ‘compliance is the floor.’ Can you explain that thought further? And why can’t compliance directives specifically point to data-centric measures?**

A:  Compliance requirements cover some types of data but not all of the different types of sensitive data, such as your trade secrets or intellectual property, within your organization that you would want to protect. The actions that companies are required to take in order to meet compliance requirements are also the minimum requirements and expectation. It’s a floor, because you can do more. Take riding a bicycle as an example. In some places, it is mandatory and required by law to wear a helmet. This is the [compliance](https://www.comforte.com/resources/ensuring-compliance-with-data-centric-security-a-primer/)requirement. A helmet offers protection, but it is not the only measure that a cyclist would implement for safety and protection. They may also want to add a lights to their bicycle, wear closed-toe shoes, and take additional precautions.  

A challenge is that these regulatory requirements may not be prescriptive (e.g., you must implement encryption at rest) and instead worded as requiring you to implement “reasonable security” measures as a way of offering flexibility. It also extends the life of the requirement; as technologies and measures for protecting data evolve, we do not want a mandate use of a specific technology and have to keep updating legislation. This is why security strategy is important. It enables you to determine a [data-centric approach](https://insights.comforte.com/why-data-centric-security-should-be-a-part-of-your-gdpr-strategy?hsLang=en) to security, and identify the controls necessary for the data in your environment.

## Privacy and privacy rights

**Q:  You talked about the fact that data collection triggers the most fines. Where is the balance between data collection and over-collection of data? Are there any dangers in automating the fulfillment of the individual’s privacy rights?**

A:  Data collection, and by extension data governance, is cause for concern here. Organizations must get smarter about privacy, privacy rights, and the purpose of data collection and use. It’s not so much about finding the balance between collection and over-collection. It’s more about the **practice of data minimization**, **collecting only what you need** for a clearly defined purpose. There’s also the other end of the data lifecycle, where we must consider what data to delete when it’s no longer required for business, compliance, or contractual purposes to maintain.

Automation is great when you are automating the correct process. Otherwise you are making mistakes and doing so faster. Before automating fulfillment of individual’s privacy rights, you need to have a thorough understanding of the process in which you fulfill those rights, and measures for ensuring that it is in fact the individual who is requesting their own personal information and not someone else doing so.

## Adapt

**Q:  You used the term ‘adapt’ a few times. Is this the most important quality for success in your opinion, the ability to assess and adapt?**

A:  The most important quality is to build a strong foundation of controls and processes for your security program and your privacy practices. This enables you to adapt – whether this is adapting to meet changes in regulatory and compliance requirements, business partner requirements, and evolving threats. For example, the foundational privacy capabilities and practices like privacy by design, data flow mapping, third party risk management, controls for data protection, processes to fulfill data subject rights that organizations had to embrace for EU [GDPR](https://insights.comforte.com/gdpr-2-years-on?hsLang=en)are not one-time endeavors. They will also apply to actions that companies must take for [CCPA](https://insights.comforte.com/ccpa-is-here-but-is-your-business-ready?hsLang=en)and other country-specific privacy compliance requirements.

## Best practices

**Q:  How can you leverage a larger body of best practices outside of your own organization’s? How can you tap into the best practices that other organizations have gained through their experiences?**

A:  There are different ways you can approach this at varying price points and investment of time. From networking in informal and formal peer CISO groups, membership and access to resources as a part of an industry organization (e.g., ISC2, ISACA), resources like [SANS](https://www.sans.org/), research organizations like Forrester, to security consultancies. Building your strategy on recognized security standards and frameworks also helps here; often these are developed based on an understanding of what measures have and have not worked within organizations. For example, Forrester created its data security and control framework as a way of helping our clients frame and discuss a high level strategy with a non-technical business audience, to help build the business case and approach for investment in data security.

## Collaboration

**Q:  What is the best way to encourage and facilitate that alliance between data science and IT that you mentioned at the end of your portion?**

A:  With your interactions and discussions, assume positive intent (each team is just trying to do their job here) to avoid an adversarial relationship. Rally behind big picture shared business goals, such as improving customer experience, embracing innovation through data, or protecting the firm’s reputation and brand. Understand each other’s objectives. For IT, this means understanding the business context of data assets, what data science teams are trying to accomplish, what data they need, how they use data, where this data comes from, what data science teams need to successfully and efficiently do their job, and where existing IT or security processes or procedures cause them grief. For data science, this means understanding IT and security’s objectives, what their concerns are, what requirements they’re trying to meet (e.g., privacy rights, compliance, contractual business requirements, etc), what limitations may exist with technologies today, what risks they’re trying to manage to enable the business. 

## Conclusion

We certainly feel that the topic and these questions have relevance for every business and organization, especially in the current climate of growing regulatory scrutiny of corporate data security. For example, Brazil will be yet another country to roll out a comprehensive set of data privacy rules, known as [LGPD](https://insights.comforte.com/13-countries-with-gdpr-like-data-privacy-laws?hsLang=en), later this summer. We want to keep an eye on how this all evolves and will make sure to provide other learning opportunities in the near future.   
So stay tuned!

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/experts-discuss-where-data-security-and-data-privacy-meet&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/experts-discuss-where-data-security-and-data-privacy-meet&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/experts-discuss-where-data-security-and-data-privacy-meet&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/experts-discuss-where-data-security-and-data-privacy-meet&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/experts-discuss-where-data-security-and-data-privacy-meet&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Why Not Watch the Full Webinar?

Did you miss the live webinar or would like to watch bits and pieces of it again?   
Not to worry, we did record the whole webinar and you can watch it via the following link.  

[![Watch the webinar (59min)](https://no-cache.hubspot.com/cta/default/4026697/4924c217-5121-4fa0-af66-70841f6a56e6.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/4924c217-5121-4fa0-af66-70841f6a56e6)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>