8.2 Countering Distortion, Exposure, Breach of Confidentiality, Blackmail, and Appropriation
Key Takeaways
Distortion is the dissemination of false or misleading information about a person; controls include provenance tracking, accuracy checks, dispute flags, and propagating corrections to every recipient (GDPR Article 19).
Exposure reveals intimate physical or emotional attributes, such as nudity, grief, or bodily functions; controls include default-private settings, redaction, and on-device hashing for intimate image takedowns.
Breach of confidentiality breaks a trust-based promise such as doctor-patient confidentiality, so the same disclosure is more harmful when made by a trusted holder.
Blackmail exploits stored compromising data, as in the 2020 Vastaamo psychotherapy breach in which patients were individually extorted; the best control is not keeping such data longer than needed.
Appropriation uses a person's identity or likeness for someone else's ends, including deepfakes and voice clones; controls include explicit likeness consent, content provenance (C2PA), and impersonation detection.
8.2 Countering Distortion, Exposure, Breach of Confidentiality, Blackmail, and Appropriation
Quick Summary: Once data leaves its original system, five dissemination harms from Solove's taxonomy become possible. The CIPT BoK names them explicitly and asks technologists to "leverage approaches and techniques that minimize the threat of" each. The pattern is the same for all five: identify the data that could cause the harm, keep less of it, control who receives it, and make it possible to correct or retract it quickly.
Section 8.1 covered general disclosure controls (egress filtering, API masking, tokenization, clean rooms). This section focuses on the specific harms those controls exist to prevent.
1. Distortion
Definition: disseminating false or misleading information about a person, which affects how others see and treat them. Distortion is not limited to lies; accurate data presented out of context (an old arrest with no mention of the dismissal) can also distort.
Examples: credit reports listing debts that belong to someone else; background-check reports confusing people with similar names; generative AI chatbots producing false statements about real people. In 2025, the privacy group noyb filed a complaint with Norway's data protection authority after a chatbot falsely described a Norwegian man as having murdered his children, arguing that the GDPR accuracy principle applies to model outputs.
Technical controls:
- Provenance and lineage so each attribute can be traced to its source and freshness date.
- Accuracy checks at ingestion (validation rules, matching thresholds for identity resolution so two people are not merged).
- Dispute and correction workflows that flag contested data while it is investigated. US consumer reporting agencies generally must reinvestigate disputes within 30 days under the Fair Credit Reporting Act.
- Correction propagation. GDPR Article 19 requires controllers to tell each recipient about rectification or erasure unless that is impossible or disproportionate; event-driven update buses make this automatic.
- Output filtering and grounding for AI systems that generate statements about people.
2. Exposure
Definition: revealing another person's nudity, grief, bodily functions, or other intimate physical or emotional details. Exposure harms dignity even when the information is true and even if it reveals nothing "useful."
Examples: leaked intimate images, medical photos shared in group chats, security body scanners that once displayed detailed body images, or a smart camera that streams the inside of a bathroom.
Technical controls:
- Classify intimate data (medical images, photos flagged as intimate, health notes) and apply the strictest access and retention rules.
- Privacy-preserving rendering: show generic outlines or blurred regions instead of raw images where a task allows it (for example, automated threat detection that displays only a body outline).
- Default-private sharing and warnings before posting sensitive media.
- Hash-based takedown: services such as StopNCII.org let people create a hash of an intimate image on their own device, so platforms can block matching uploads without anyone receiving the image.
- Access logging and alerts on sensitive records, so exposure by insiders is detectable.
3. Breach of Confidentiality
Definition: disclosing information in violation of a trust relationship, such as doctor and patient, lawyer and client, therapist and client, or bank and customer. The harm is the betrayal of trust, which is why the same disclosure is worse when the trusted party makes it.
Examples: a mental-health platform sharing clients' intake answers with advertisers (the FTC's 2023 BetterHelp order required $7.8 million in consumer refunds and banned sharing health data for advertising); a hospital employee posting patient details.
Technical controls:
- Confidentiality tiers in the data classification standard, mapped to access rules (need-to-know, break-glass with justification).
- Field-level or envelope encryption for confidential notes, with keys limited to the treating service.
- No third-party tags on confidential pages: block analytics pixels and session replay on intake forms, patient portals, and account pages.
- Contractual and technical limits on recipients (purpose-bound tokens, data use agreements, audits).
4. Blackmail
Definition: threatening to disclose information unless the person does something, such as paying money. Blackmail turns stored compromising data into leverage.
Examples: the Vastaamo breach in Finland, where an attacker stole psychotherapy records from a private clinic network and in October 2020 emailed thousands of patients individually demanding ransom to keep their therapy notes private; the 2015 Ashley Madison breach, after which users received extortion emails; and "sextortion" scams that threaten to release intimate images.
Technical controls:
- Do not keep compromising data longer than needed. The most effective control against blackmail is that the data no longer exists. Old therapy notes, deleted messages, and closed accounts should actually be purged.
- Encrypt sensitive records at the field level so a database dump does not yield readable notes.
- Separate identity from content (pseudonymize sensitive content stores) so stolen content cannot easily be tied to people.
- Detect exfiltration early and prepare rapid notification and victim-support plans, because extortion often follows a breach within days.
5. Appropriation
Definition: using a person's identity, name, likeness, or voice to serve someone else's purposes without permission. In US law this overlaps with the right of publicity; Tennessee's 2024 ELVIS Act extended that right to cover AI-generated voice imitation.
Examples: a person's photo used in an advertisement without consent; deepfake videos and cloned voices used in fraud ("Grandma, I've been arrested, send money"); a profile photo scraped to train a face-generation model.
Technical controls:
- Explicit consent for likeness use in marketing, with records and expiry dates.
- Content provenance: attach C2PA Content Credentials to media your organization creates, so altered or synthetic versions can be distinguished. The EU AI Act's Article 50 also requires providers to mark AI-generated content in a machine-readable way and deployers to disclose deepfakes.
- Limit high-quality samples: avoid publishing high-resolution face images and long clean voice recordings of employees and customers where not needed.
- Liveness detection and out-of-band verification for voice- or video-based authentication, which deepfakes can defeat.
- Impersonation monitoring and takedown processes for fake accounts and ads.
Mapping the Five Threats to Controls
| Threat | Data Most at Risk | Primary Technical Response |
|---|---|---|
| Distortion | Credit, criminal, identity-resolution, AI-generated data | Provenance, accuracy checks, correction propagation |
| Exposure | Intimate images, health and body data | Classification, default privacy, redaction, hash-based takedown |
| Breach of confidentiality | Health, legal, financial, therapy data | Need-to-know access, field encryption, no third-party tags |
| Blackmail | Compromising or stigmatizing records | Deletion, field encryption, pseudonymization, fast detection |
| Appropriation | Faces, voices, names, likeness | Consent, provenance, liveness checks, takedown |
A background-check company discovers that its identity-matching algorithm merged two people with the same name and birth year, and reports with the wrong person's eviction record were sent to three landlords. Which response best addresses the distortion harm?
Fix the merged profile, notify the three landlords, and tighten identity matching.
Delete the affected person's account and all of its records without informing the landlords who received reports.
Add a disclaimer to future reports stating that data may be inaccurate.
Encrypt the eviction database with a stronger cipher and rotate the keys every quarter.
An online therapy service stores session notes for all clients indefinitely in a single database table alongside client names. After learning of the Vastaamo extortion case, which control most directly reduces the blackmail threat?
Moving the database to a larger cloud instance with more storage
Purchasing cyber insurance that covers ransom payments and extortion response costs
Adding a banner to the client portal warning clients about phishing and extortion emails
Purging notes after retention ends and encrypting the rest separately from identities
Fraudsters use short clips of a company's CEO from public videos to clone her voice and call the finance team requesting urgent wire transfers. Which privacy harm does the voice cloning represent, and which control helps most?
Exposure, controlled by blurring the CEO's face in all future company videos and photos
Distortion, controlled by publishing a correction about the CEO's voice
Appropriation, controlled by out-of-band payment verification and fewer public voice samples
Breach of confidentiality, controlled by encrypting the finance team's email and call recordings
Sections you finish are checked off in the contents.