In an era where data breaches dominate headlines and AI capabilities expand exponentially, the conversation around encryption has evolved far beyond technical specifications. It’s become a discussion about fundamental human rights, democratic resilience, and the ethical responsibilities organizations bear when handling sensitive information.
Paperclip recently hosted a compelling webinar featuring Heather Lowrie, an accomplished cybersecurity leader with extensive experience across government, public, and private sectors who was recognized as CISO of the Year 2024 at the SC Awards Europe. The conversation explored the intersection of encryption, privacy rights, and emerging technologies—revealing insights that every security and compliance leader should understand.
Encryption as a Fundamental Human Right
The webinar opened with a powerful reframing of encryption’s purpose. Drawing from Mallory Nodle’s article “Why Feminists Must Defend Encryption,” Lowrie emphasized that encryption protects far more than corporate data—it safeguards human dignity, equality, and democratic freedoms.
“Encryption protects survivors of gender-based violence and supports human dignity and equality,” Lowrie explained, connecting encryption to broader discussions on privacy rights and democratic resilience. This perspective aligns with legal frameworks like the EU Charter of Fundamental Rights and GDPR, which recognize privacy as a cornerstone of democratic societies.
The discussion underscored an essential truth: privacy isn’t just about feminist rights or specific demographics—it’s a fundamental human right that underpins free societies. When organizations implement robust encryption, they’re not simply checking compliance boxes; they’re protecting the fundamental freedoms that enable democratic participation, free expression, and human autonomy.
Breaking Down the False Privacy-Availability Dichotomy
One of the most persistent misconceptions in cybersecurity is that strong privacy measures inevitably compromise data availability and business operations. Lowrie directly challenged this assumption:
“There’s often a misconception within cybersecurity that data availability and data protection and privacy are opposing forces, but they’re complementary. When we think about availability and ensuring authorized users can reliably access data and services, it’s a core principle of InfoSec. Ensuring availability doesn’t mean exposing our data to everyone, it means authorized users can access what they need. And strong privacy measures don’t require sacrificing access or service. We really need to think about encryption, access control, secure authentication as ensuring data is both protected and available.”
This insight is particularly relevant for organizations evaluating encryption-in-use technology. Traditional encryption methods force organizations to choose between security and usability—data must be decrypted to be searched or analyzed, creating vulnerability windows. Paperclip SAFE’s encryption-in-use technology demonstrates that this trade-off is no longer necessary. Organizations can maintain complete data encryption while enabling authorized users to perform critical business operations in real-time.
The Shared Responsibility Model in Data Protection
The webinar addressed a critical question: who bears responsibility when data is compromised? Lowrie explained the shared responsibility model that governs data supply chains under European law.
In this framework, the primary data controller—such as an insurance carrier or healthcare provider—carries ultimate legal responsibility. Processors have contractual obligations, while individuals have limited but real responsibility for data hygiene. However, Lowrie introduced a concept that extends beyond traditional compliance frameworks: “humane by design.”
This principle recognizes that effective data protection must address broader societal vulnerabilities and fundamental rights within democratic systems. It requires breaking down organizational silos between legal, security, and technical teams, enabling holistic approaches to privacy that balance compliance obligations with ethical responsibilities.
The Evolution of Encryption: Protecting Data in Use
The conversation explored how new legislation and international privacy frameworks are driving encryption’s evolution—particularly the shift toward protecting data while it’s being actively used.
Historically, encryption focused on protecting data at rest (stored) and in transit (being transmitted). But as Lowrie noted, active data—the information being queried, analyzed, and processed—represents organizations’ most valuable and vulnerable asset. Encryption-in-use technology addresses this critical gap.
The webinar highlighted searchable encryption as a particularly promising development. This technology enables organizations to search and analyze fully encrypted data without exposing sensitive information—even when hosted on untrusted platforms like public clouds. For organizations navigating compliance frameworks like DORA (Digital Operational Resilience Act), which explicitly mandates encryption of data in use, this capability is no longer optional.
Navigating the Tension Between Privacy and Lawful Access
Perhaps no topic generates more debate in cybersecurity policy than the balance between privacy rights and law enforcement’s need to investigate criminal activity. Lowrie emphasized the need for targeted technical solutions that avoid introducing systemic vulnerabilities.
The key challenge: any encryption “backdoor” created for lawful access becomes a potential entry point for malicious actors. As discussed in the webinar, Paperclip’s approach to this challenge centers on data sovereignty and client accountability. Organizations using SAFE maintain control over their encryption keys and can provide legal access through their admin portals when required by law—without compromising the security of the broader system.
This approach enables compliance with legitimate law enforcement requests while preserving the encryption that protects 99% of users who aren’t under investigation. It’s a nuanced solution to a complex problem, reflecting the careful balance required in modern data protection strategies.
Preparing for Quantum Computing’s Impact on Encryption
The webinar addressed a question that’s increasingly urgent for security leaders: how should organizations prepare for quantum computing’s potential to break current encryption standards?
Lowrie stressed the importance of understanding current encryption technologies and developing clear roadmaps for future transitions. Organizations can’t simply wait for quantum computers to arrive—they need quantum-ready strategies today. This includes:
- Understanding crypto-agility: The ability to swap encryption algorithms quickly when threats emerge
- Implementing quantum-resistant encryption: Solutions like Paperclip SAFE are already designed with post-quantum cryptography in mind
- Planning migration strategies: Transitioning encryption without disrupting business operations requires careful planning and testing
The good news: organizations that prioritize continuous improvement in security practices position themselves to adapt to quantum threats as they emerge.
AI vs. Quantum Computing: Which Poses the Greater Privacy Threat?
The webinar concluded with a thought-provoking debate about whether AI or quantum computing represents the bigger immediate threat to privacy. While quantum computing’s potential to break encryption generates headlines, the consensus leaned toward AI as the more urgent concern.
AI’s rapid development and current deployment across industries creates immediate privacy risks. AI systems can:
- Aggregate and analyze personal information at unprecedented scale
- Identify patterns and make inferences that individuals never intended to share
- Perpetuate biases in ways that affect fundamental rights and opportunities
- Operate with limited transparency, making accountability difficult
These challenges are happening now, not in some distant quantum future. Organizations deploying AI systems—particularly for processing sensitive data—must implement privacy-preserving technologies that protect individuals’ information while enabling useful analysis. Searchable encryption technology offers one path forward, allowing AI systems to work with encrypted data without exposure.
Key Takeaways for Security and Compliance Leaders
The webinar provided several actionable insights for organizations navigating today’s complex privacy landscape:
- Reframe encryption as a human rights issue: Understanding encryption’s role in protecting fundamental freedoms helps organizations articulate its importance beyond compliance requirements.
- Challenge the privacy-availability trade-off: Modern encryption technologies eliminate the false choice between security and usability. Organizations should evaluate solutions that provide both.
- Adopt a holistic approach to data protection: Break down silos between legal, security, and technical teams. Effective privacy protection requires collaboration across disciplines.
- Prepare for encryption’s evolution: Whether addressing quantum computing or meeting new compliance mandates like DORA, organizations need strategies for adapting their encryption approaches as threats and requirements evolve.
- Prioritize encryption-in-use: Active data represents organizations’ most valuable and vulnerable asset. Traditional encryption methods that protect data at rest and in transit leave this critical gap unaddressed.
Moving Forward: Technology for the Greater Good
As Lowrie’s insights made clear, encryption isn’t simply a technical control—it’s a tool for protecting human dignity, enabling democratic participation, and safeguarding fundamental rights. Organizations that embrace this broader perspective position themselves not only for compliance success but also for ethical leadership in an increasingly data-driven world.
The conversation between privacy and security, between availability and protection, between innovation and accountability, will continue to evolve. But the fundamental principle remains constant: technology should serve the greater good, protecting individuals while enabling the beneficial use of data that drives progress.
Watch the Full Webinar: Explore the complete discussion on encryption and privacy rights at our webinar resource page.
Not Sure Which Option Is Right For You? Get Pricing Details Choose The SAFE Deployment Model That Fits Your Security Requirements.
Ready to Transform Your Data Security Strategy? Learn how Paperclip SAFE’s always-encrypted technology protects your most sensitive data while enabling the real-time access your business demands. Contact our security experts to schedule a consultation and discover how encryption-in-use can strengthen your privacy posture and prepare your organization for tomorrow’s compliance requirements.
