Trending
Data privacy vs. data security | TeamMate
The strategic impact of data privacy vs. data security
The lines between data privacy and security are blurring, and today’s business environment isn’t making it any easier. Cloud migrations. Rapid digital transformation. The sudden integration of artificial intelligence (AI). Companies are collecting more data than ever before, and it is very hard to keep track of it all. To put this in perspective, Statista and IDC did research that showed the world created and consumed 181 zettabytes of data in 2025.
When a breach occurs, the strategic impact hits hard. Failure in data security leads to ransomware attacks, intellectual property theft, and operations grinding to a halt. On the flip side, failure in data privacy results in massive regulatory fines and a profound loss of customer trust. In the financial services sector, where consumer confidence is the currency that matters most, a privacy misstep can be just as fatal as a breached firewall.
Let’s look at this from the boardroom perspective. Ten years ago, the audit committee might have been satisfied with a simple check-the-box exercise stating that the firewalls were active and antivirus software was up to date. Today? The conversation has entirely changed. Board members are asking pointed questions about data lineage, third-party handlers, and the financial exposure associated with a potential privacy breach. They recognize that a fractured approach to data privacy vs. data security is a massive, unmitigated risk. In the financial services sector, where consumer confidence is the currency that matters most, a privacy misstep can be just as fatal as a breached firewall. Rebuilding a server takes days; rebuilding customer trust takes decades.
Stakeholders view data privacy vs. security not as back-office IT problems but as non-negotiable pillars of organizational health. In fact, The Institute of Internal Auditors’ (The IIA) Risk in Focus Report 2026 found that cybersecurity continues to hold the number one spot in global risk rankings and internal audit priorities. By evaluating the strategic impact of these elements, internal audit can step out of the reactive compliance checker role and become a proactive advisor on risk management.
Data privacy vs. data security: Definitions, differences, and audit implications
You can’t audit what you don’t understand. To effectively evaluate these domains, auditors need clear definitions. They are connected, but they need different controls, frameworks, and ways to evaluate them.
What is data privacy?
Data privacy dictates the rights, usage, and consent governing how data is collected, processed, shared, and destroyed. But for an internal audit, assessing privacy goes far beyond reviewing policy documents to see if the business says it respects consumer rights. As highlighted in ISACA’s 2025 Privacy in Practice analysis, consumer protection should not be based solely on jurisdiction; the ethical burden of privacy belongs to enterprises, not end users. A comprehensive audit requires testing the actual mechanisms enforcing those rights.
Privacy asks the challenging audit questions: Are the automated deletion scripts effectively purging data at the end of its retention lifecycle, or is the organization unnecessarily hoarding data simply because it can? Is sensitive information properly masked or tokenized when used in non-production testing environments? Are we tracking the flow of data through complicated API integrations to make sure that third-party vendors aren’t breaking our consent agreements? To do a full data privacy audit, we need to get our hands dirty and check the architectural level of data minimization and consent management workflows.
What is data security?
Data security is about the technical, physical, and administrative measures that are taken to keep data safe from being accessed or changed (without permission) or destroyed or stolen. Privacy sets the rules for how people can interact, while security puts up the walls.
For seasoned IT auditors, assessing security means moving past basic compliance checklists. Because of insider threats—whether malicious employees or well-meaning staff accidentally emailing unencrypted client data— account for a massive percentage of security incidents, modern audits must heavily scrutinize Zero Trust architectures.
The audit implications here involve deep technical control testing. Rather than just verifying that encryption exists, auditors need to evaluate cryptographic key management lifecycles. They should test the efficacy of Data Loss Prevention (DLP) rules in stopping unauthorized data egress, review Identify and Access Management (IAM) privilege creep, and challenge the rigor of the vulnerability management program. Are we merely running automated network scans, or are we actively testing incident response playbooks and the configurations of our Endpoint Detection and Response (EDR) tools?
How data privacy and data security intersect—and why both matter for internal audit
Privacy and security are distinct, but you can’t have one without the other. It is impossible to guarantee privacy without the security infrastructure to protect the data. Conversely, you can have airtight security, including firewalls and zero-trust architecture, and still completely violate privacy laws if you sell a consumer’s data without their explicit consent.
Evaluating this intersection is crucial. A siloed audit approach leaves glaring blind spots. Auditors must assess the extent to which security controls facilitate compliance with privacy regulations, ensuring that data privacy and data security operate in concert to manage information ethically and protect it rigorously.
Key audit considerations for data privacy and security programs
As regulatory pressures mount, internal audit teams must look critically at whether managements’ data governance strategies actually work in practice, not just on paper.
Assessing risk across privacy and security domains
Everything starts with the risk assessment. When looking at data privacy and security, an internal audit must assess the specific threat landscape.
What types of Personally Identifiable Information (PII) does the organization hold? Where does it live? Who has access to it? Internal audit adds immense value by helping organizations establish formal data governance practices, and it’s important to provide a roadmap for scoping these assessments effectively.
Internal Audit also needs to consider organizational changes that suddenly shift the risk profile. Mergers and acquisitions are a great example. When two companies combine, they aren’t just merging bank accounts and office spaces; they are merging entirely different data ecosystems, often with conflicting security postures and privacy standards. Identifying these friction points early is where internal audit can earn its keep.
Can data privacy be achieved without data security?
This is a question that frequently surfaces in the boardroom, and the answer is a definitive no. Can data privacy be achieved without data security? It is impossible. If you lack the security architecture to keep unauthorized users out of your database, any privacy promises you made to your customers are worthless. Security is the foundational infrastructure upon which privacy is built.
Once you identify the risks, you must test the design and operating effectiveness of the controls.
For privacy controls, internal audit needs to evaluate the data retention policies, right-to-be-forgotten procedures, and vendor data agreements. Third parties often handle your most sensitive data. If you aren’t watching them, you are exposed. The role of internal audit in vendor and third-party risk management is critical to preventing downstream privacy violations.
For security controls, test the access management and incident response plans. Are security patches applied on time, or are they sitting in a backlog? Is data encrypted in transit and at rest?
Trending
Jordan Brand Basketball Enters a New Era of Design and Innovation With the Air Jordan 41 — NIKE, Inc.
Welcome to a new chapter of Jordan greatness.
Jordan Brand is introducing the Air Jordan 41: a game shoe inspired by Michael Jordan’s legendary versatility and style, built with a future-forward philosophy that pushes the boundaries of technology and expression.
The silhouette’s introduction marks an evolution of Jordan Brand heritage design, blazing a new path to greatness that prioritizes performance innovation and modern style — redefining what it means to be a leader in basketball footwear and challenging opponents to keep pace.
“The Air Jordan 41 is a statement about where Jordan Brand is headed. It carries forward a legacy built on greatness, but it was created for the athletes, whose culture and style of play are defining the future of the game,” says Sarah Mensah, President, Jordan Brand. “This silhouette reflects our commitment to pushing performance innovation with purpose — delivering bold design, elite function and a point of view that only Jordan Brand can bring. It is more than the next Air Jordan. It is a signal of the next chapter of Jordan performance.”
The 41 is a testament to innovation, dominance and driving the future of the game — engineered for end-to-end dominance on the court, just like MJ himself.
Feedback from athletes at every level of the game, including MJ, Jordan Brand’s professional and collegiate roster, and players from Nike’s Elite Youth Basketball League, informed the design of a lighter and more responsive Air Jordan silhouette.
At the foundation of the Air Jordan 41 is the new-to-Jordan nano print mesh upper, engineered to deliver the lightweight containment and breathability demanded by today’s game.
The advanced woven construction helps reduce weight while creating targeted structure throughout the shoe, allowing athletes to move with confidence, precision and speed. By balancing airflow with support, the nano print mesh upper provides a secure, adaptive fit that helps players stay locked in through every cut, drive and defensive possession, reinforcing the Air Jordan 41’s focus on modern performance without compromising comfort.
“With the 41, we wanted to create an upper that could move with the athlete and feel lighter without sacrificing the containment and confidence they need to play at their best,” says Leo Chang, Senior Creative Director, Basketball & Sport, Jordan Brand.
“The nano-printed mesh allows us to engineer that balance, creating a material that feels light on the foot while providing targeted structure and support where players need it most. It’s a solution that reflects our ongoing pursuit of performance innovation, helping athletes move freely, react instinctively and stay locked into the game from tip-off to the final possession.”
The upper material also responds to a variety of graphic and color treatments. The cross-hatch print, with its two contrasting directions of lines, can each receive a color independently or cohesively. This allows for a number of different looks for the 41, both through graphic approaches and when in motion.
The 41 also features a full-length Zoom Strobel for underfoot responsiveness; a ZoomX midsole for industry-leading lightness and speed; and, in an evolution from the 40, adds an Air Zoom heel unit for enhanced impact protection. The addition of the Zoom air bag in the heel was inspired by Michael Jordan’s insights on the importance of defense and staying on your toes, and its cushioning ensures players can stay prepared to rock forward.
“The Air Jordan 41 prepares me for every movement; it gives me confidence in every cut, read and possession,” says Jordan Brand athlete Napheesa Collier. “When you trust your shoes like that, it makes all the difference.”
A carbon fiber and TPU shank provides stability, working in tandem with a full-length HART rubber herringbone traction pattern to enable rapid changes in direction. These features collectively modernize the shoe’s construction and ensure optimal comfort and performance for all hoopers.
The design evolution from the Air Jordan 40 to the 41 takes shape through both material choices and technological advancements. The new silhouette eschews the leather traditional to the Air Jordan lineage, opting for nanoprinting and thin textiles that create a lighter, nimbler feel. Details like a TPU window that exposes the shoe’s internal technology are reminiscent of a high-performance car, and while the shoe’s tech is sleek and understated on the surface, its sophistication is revealed upon closer inspection.
Each design element, from the asymmetrical collar to the metallic Jumpman hardware, signals Jordan Brand’s commitment to advancing the legacy of the Air Jordan lineage, setting the stage for the next generation.
“What I love about 41 is that it lets me play my game without thinking about what’s on my feet. It’s light and responsive, and it gives me the confidence to move how I want,” says Jordan Brand athlete Paolo Banchero. “When you’re competing at the highest level, those details matter, and the 41 delivers.”
This move beyond nostalgia and heritage is brought to life through colorways that follow a gemstone theme, each reflecting MJ’s mentality and personal symbolism, such as the Ruby launch colorway that calls to mind his legendary three-peats in Chicago. Upcoming colorways include an Amethyst style modeled on MJ’s birthstone, and Opal, which nods to his alma mater.
This seasonal color approach coupled with the performance-driven design positions the Air Jordan 41 as a true evolution for Jordan Brand, setting a new standard for basketball footwear.
“The 41 matches the way I like to compete. It’s built for players who impact the game on both ends,” says Jordan Brand athlete Stephon Castle. “I trust it every possession because it keeps me feeling quick, connected and ready to react. When you’re playing with confidence, you can focus on being aggressive and letting your game take over.”
The Air Jordan 41 debuts with a limited release in China on August 28, with a global release to follow.
Trending
Peters-Berger pleads guilty in homicide of Lily Peters, sentenced to life in prison
CHIPPEWA FALLS, Wis. (WEAU) – A major development in the criminal case against the man accused of killing 10-year-old Lily Peters is taking place in Chippewa County Court.
“I think this tragedy opened up a lot of eyes to just how fragile things are for all of us,” Dana Whitcome, a stepmother of two of Lily’s siblings, said.
18-year-old Carson Peters-Berger appeared in person for the first time when he pleaded guilty to the charge of first-degree intentional homicide in the death of Lily Peters. Chippewa County Judge Steven Gibbs accepted the plea and convicted Peters-Berger of the crime. The other two charges of sexual assault were dismissed but read in. Judge Gibbs then sentenced Peters-Berger to life in prison with the possibility of extended supervision after 25 years.
“I believe in giving people a second chance after you paid your debt to society,” Judge Gibbs said. “While you were a minor when you committed it, it is still a very serious offense, and it shook this community.”
While going through the proceedings, Judge Gibbs asked Peters-Berger if he understood that by pleading guilty to first-degree intentional homicide, he would be admitting to killing Lily Peters and planning to do so. Peters-Berger said he did understand.
“I don’t think you get closure in the criminal justice system. It’s not set up for that sort of thing,” Chippewa County District Attorney Wade Newell said. “It’s one point in time that is now over with, but it doesn’t give you closure regarding what occurred because nothing that’s done here will erase what happened to the poor young girl.”
Family members of Lily Peters spoke in the hearing. They discussed the impact the loss had on their families in the community and shared how much they missed her.
“She was my light,” Kiara Stevens, a friend of Lily Peters, said. “There were times where I just didn’t want to do it anymore, but Lily was that kind of person that made you want to keep going.”
Those connected to the family also shared concerns about the possibility of Peters-Berger being eligible for release and the worries that another crime may be committed.
Peters-Berger did not wish to speak in the hearing
Lily Peters disappeared the evening of April 24, 2022, after leaving her aunt’s home in Chippewa Falls. Her family reported her missing that night. The following morning, volunteers searching the area found the 10-year-old’s body in a wooded area near a walking trail.
Peters-Berger previously pleaded not guilty in December 2024 to adult charges of first-degree intentional homicide, first-degree sexual assault causing great bodily harm and first-degree child sexual assault. A jury trial was initially scheduled for this November, but because of that hearing, that will no longer take place.
Newell was asked why the case was no longer going to trial. He said trials always present some risk as you don’t know how a jury will respond. He also said trials can be very traumatic for the family. Those close to Lily said they are relieved this chapter is over and are ready to continue healing
“We just look forward to moving forward in healing and sharing that spirit of kindness with everyone in Lily’s memory,” Whitcome said.
“Lily was an amazing person and what I hung onto the most was the happy memories instead of that last bad one I had of her,” Stevens said. “I just want to say it does get better. We do heal.”
Copyright 2026 WEAU. All rights reserved.
Trending
Anthony’s Soul Café brings Southern comfort cooking to Santa Fe | Business
-
Trending2 weeks agoThe 9 Senate seats most likely to flip in 2026
-
News3 weeks agoSpaceX Junk Hits the Moon. Not a Good Sign
-
Entertainment3 weeks agoQVC host reacts to viral on-air blooper
-
News2 weeks agoAncient Maltese Seafarers Likely Navigated By The Stars
-
News3 weeks ago
The U.S. Is Burning Through Weapons in Iran. Russia and China Are Taking Note.
-
Trending3 weeks agoBoeing 737 Max operators told to check fuselages for cracks | Boeing
-
Entertainment3 weeks ago‘The Simpsons’ actress Nancy Cartwright predicts when hit show will end
-
Trending3 weeks ago🔴 EN VIVO: Alianza Valledupar vs. Bucaramanga
