Digital privacy is a person's ability to control the information that exists about them online: what is collected, by whom, for what purpose, and for how long. That is the short definition. The longer one involves everything from the cookies on this page to facial recognition in a shopping mall, so let us take it apart calmly.
A working definition
Digital privacy is control over personal information in digital environments. Personal information means anything that identifies a person directly (name, email) or indirectly (IP address, cookie identifier, purchase history, location trail). Privacy does not mean secrecy: it means the person, not the organization, decides what happens with that information. That is why modern privacy laws are built on consent rather than on prohibition.
The main types of privacy
- Information privacy: control over personal data collected by sites, apps and organizations. The domain of cookie consent, privacy policies and laws like Law 25 and GDPR.
- Communication privacy: the confidentiality of emails, messages and calls, protected mainly by encryption.
- Behavioral privacy: freedom from having your browsing, purchases and movements profiled, the target of advertising trackers.
- Bodily and biometric privacy: control over fingerprints, face geometry and health data, subject to reinforced rules almost everywhere.
- Territorial privacy: freedom from surveillance in physical spaces, from cameras to Wi-Fi tracking in stores.
Concrete examples of privacy violations
- A site loads Google Analytics and the Meta Pixel before the visitor answers the cookie banner: tracking without consent.
- An app sells location history to data brokers without meaningful disclosure.
- A retailer builds a facial recognition database of shoppers without notice or consent.
- A breach exposes health records because the data sat unencrypted longer than it was needed.
- An employer reads employees' private messages on a personal account.
The first example is the most common by far, and the one most businesses commit without realizing it. Our cookie banner examples article shows what compliant consent actually looks like.
What the laws protect
Most modern regimes converge on the same core: collect only what you need, say what you collect and why, obtain valid consent for what is not essential, secure what you hold, delete what you no longer need, and honor people's rights of access, correction and erasure. Europe's GDPR set the template; Quebec's Law 25 is North America's strictest version of it, with penalties up to $25 million or 4 percent of worldwide revenue.
For website owners
Your visitors' digital privacy starts with your trackers. A consent banner that actually blocks them until consent, and a record proving each choice, cover the web side of these laws.