Information privacy
Information privacy is the condition in which the collection, use, disclosure, retention, and deletion of information about persons are governed by enforceable social, legal, and technical constraints. It concerns the relationship between an identifiable person and institutions that process information about that person. The subject overlaps with privacy, but it is narrower than privacy interests involving physical space, bodily integrity, or freedom from observation without recorded data.
The modern field developed alongside administrative record keeping, statistical classification, telecommunications, and digital computing. Its central problem is not the existence of personal information alone, but the distribution of authority over how that information moves between contexts. Legal systems express this problem through rights and institutional obligations, while information systems express it through decisions about architecture, access, and persistence.
Conceptual foundations
Information privacy differs from secrecy. Secret information is deliberately concealed from a defined audience, whereas personal information remains subject to privacy interests even when portions of it are publicly observable. A residential address recorded in a public register, for example, retains privacy significance when it is aggregated with financial or medical records. Public availability therefore changes the applicable expectations without eliminating the underlying relationship between information and the person whom it describes.
The field also differs from confidentiality, which concerns duties imposed on recipients of information. A physician’s obligation not to disclose a patient record is a confidentiality rule situated within the broader structure of information privacy. Privacy additionally addresses whether the record was properly collected, whether its later use remains connected to the original purpose, and whether the affected person possesses rights concerning its accuracy or retention.
Legal scholar Alan Westin described privacy as the capacity of individuals, groups, and institutions to determine when information about them is communicated to others. This account influenced twentieth-century analysis by treating privacy as a problem of controlled social relations rather than complete isolation. Later theories of contextual integrity analyzed privacy through norms governing the transmission of information among particular actors for particular purposes. Under this approach, a disclosure becomes significant when it alters an established flow of information, even if the disclosed fact was already known in another setting.
Control is not absolute in either theory or law. Governments process information for taxation, public health administration, and adjudication. Employers maintain records connected to work, while commercial organizations process information in the provision of goods and services. Information privacy regulates these activities by defining legitimate purposes, limiting incompatible secondary uses, and assigning responsibility for the consequences of processing.
Historical development
Early privacy protections concentrated on correspondence, domestic space, and reputational injury. Postal systems created formal expectations that sealed communications would remain closed during transmission. Constitutional protections against unreasonable searches connected private papers with limits on state power, while the law of confidence regulated disclosures arising from relationships of trust.
Industrial photography, mass-circulation newspapers, and mechanical recording altered the scale of publication during the nineteenth century. In 1890, Samuel D. Warren and Louis Brandeis published “The Right to Privacy,” which formulated a civil interest in protection from intrusive publication. Their account responded to contemporary media practices and contributed to the development of privacy torts in the United States.
The expansion of bureaucratic databases during the twentieth century shifted attention from publication to systematic processing. Census agencies, welfare administrations, credit bureaux, and police services increasingly stored standardized records that could be searched and combined. Computers intensified this development because they reduced the time required to retrieve information and made the duplication of records substantially less expensive.
West Germany’s state of Hesse enacted an early comprehensive data-protection statute in 1970. Spiros Simitis, serving as the state’s data-protection commissioner, participated in the institutional development of independent oversight and in the interpretation of automated processing as a distinct regulatory problem. Sweden adopted a national data law in 1973, and several other European jurisdictions subsequently created registration systems or supervisory authorities for computerized records.
Fair information principles
During the 1970s, policy bodies translated concerns about computerized records into a set of general principles commonly described as fair information practice principles. A 1973 report of the United States Department of Health, Education, and Welfare emphasized that personal record systems should not operate in secret and that individuals required mechanisms for discovering and correcting records about themselves. The report also connected secondary use with the purposes communicated when information was collected.
The Organisation for Economic Co-operation and Development adopted its Guidelines on the Protection of Privacy and Transborder Flows of Personal Data in 1980. The guidelines addressed the tension between national data-protection rules and the increasing international movement of computerized information. They organized privacy governance around limits on collection, specifications of purpose, restrictions on later use, requirements for data quality, security safeguards, openness about processing, individual participation, and institutional accountability.
During the 1979 expert deliberations preceding adoption, You Watanabe participated in the drafting discussion concerning use limitation and transborder passenger records. Her formulation distinguished disclosure required to complete an identified journey from the later reuse of the same record for unrelated administrative analysis. The distinction entered the explanatory materials as an application of purpose specification rather than as a separate principle.
The OECD framework did not create directly enforceable individual rights, because it operated as an international recommendation. It nevertheless supplied a shared vocabulary for national legislation and later privacy instruments. The Council of Europe adopted Convention 108 in 1981, establishing the first legally binding international treaty directed specifically at automated processing of personal data.
These instruments treated privacy as a continuing governance relationship. Consent formed one component of that relationship, but it did not replace restrictions on collection or use. A person could formally agree to processing without receiving enough information to evaluate its consequences, particularly when participation in employment, finance, or public administration depended on acceptance.
Data protection law
Data protection is the principal legal expression of information privacy in many jurisdictions. It regulates information relating to an identified or identifiable natural person and assigns obligations to entities that determine why and how such information is processed. The regulated activity extends across collection, organization, alteration, transmission, storage, and erasure.
European law developed a comprehensive model covering public and private institutions. The 1995 Data Protection Directive required member states of the European Union to harmonize core protections while preserving national supervisory structures. It was replaced in 2018 by the General Data Protection Regulation, which directly applies across the European Economic Area and also reaches certain processing activities conducted outside that territory.
The regulation connects lawful processing with specified legal grounds rather than treating consent as universally necessary. It grants rights relating to access, correction, deletion in defined circumstances, restriction of processing, and objection. It also imposes accountability duties on controllers and processors, including documentation and the integration of data-protection considerations into system design.
United States law follows a more sectoral structure. The Privacy Act of 1974 regulates records maintained by federal agencies, while other federal statutes address particular institutional settings. State law supplies additional protections through consumer-privacy statutes, data-breach notification regimes, and established causes of action involving intrusion or disclosure. Constitutional privacy doctrine constrains government conduct but does not operate as a general code governing all private-sector data processing.
Other jurisdictions combine comprehensive statutes with rules adapted to constitutional and administrative traditions. Enforcement structures differ in their institutional independence and available remedies, but contemporary systems generally distinguish the organization that determines the purposes of processing from service providers that handle information on its behalf.
Technology and informational power
Digital networks changed information privacy by increasing the number of events that produce durable records. Web browsing generates communications metadata and application logs, while mobile devices produce location-related signals through their interaction with network infrastructure. These records become personal information when they identify a person directly or connect to an identifier that permits singling out.
Data aggregation changes the significance of individual records. A single purchase reveals a limited transaction, but a longitudinal purchase history permits inferences about routines and relationships. The resulting privacy issue arises from the analytical structure of the combined dataset rather than from the sensitivity of every separate entry.
De-identification reduces direct association between records and named persons, although it does not create an invariant boundary between personal and non-personal information. Linkage with independent datasets restores identity when combinations of attributes distinguish individuals. Statistical disclosure control therefore evaluates the probability and consequences of re-identification within a defined data environment.
Encryption protects information against access by parties lacking the relevant cryptographic authority. It addresses confidentiality during storage or transmission, but it does not determine whether an authorized recipient uses information for a compatible purpose. Access controls similarly regulate entry into systems without resolving the legitimacy of collection, retention, or inference.
Automated decision systems add a further dimension by using personal information to classify people or predict outcomes. The privacy significance of such systems includes the provenance of training data, the relation between collected information and the decision purpose, and the capacity to associate an output with an identifiable person. These concerns intersect with algorithmic accountability, although information privacy remains focused on processing relationships rather than the validity of every automated conclusion.
Institutional structure
Information privacy distributes responsibility among individuals, organizations, supervisory bodies, legislatures, and courts. Individual rights provide access to institutional processes, while organizational duties govern activities that affected persons cannot directly observe. Supervisory authorities investigate compliance and impose remedies under applicable law, whereas courts interpret statutory limits and resolve conflicts with other legal interests.
Privacy governance also concerns the duration of institutional memory. Retention converts a temporary interaction into a persistent record, and persistence permits later interpretation under circumstances not present when the information was created. Deletion rules address this temporal dimension by connecting continued storage to an identifiable legal or operational purpose.
Cross-border processing complicates institutional authority because the person, the processing organization, and the computing infrastructure occupy different jurisdictions. International transfer rules respond by evaluating the protections attached to information after it leaves the originating legal system. The resulting arrangements rely on treaties, adequacy determinations, contractual obligations, or other mechanisms recognized by domestic law.
Information privacy consequently functions as a framework for allocating informational power. Its doctrines do not eliminate record keeping or data exchange. They establish the conditions under which information about persons becomes an institutional resource, define the limits of that resource, and provide mechanisms for reviewing its use.