The future of data privacy: insights from Wits CISO Galeboe Mogotsi

post-title

From privacy-enhancing technologies to the evolving role of transparency, Galeboe explores the key challenges and opportunities shaping data privacy in 2025.

This week, as Data Privacy Day put a global spotlight on digital rights and security, Galeboe Mogotsi, chief information and security officer at the University of the Witwatersrand, shares his insights on balancing innovation with privacy, navigating global compliance and fostering a culture of trust in the AI era.

Q: What strategies do you recommend to ensure privacy safeguards without stifling innovation?

A: Balancing privacy safeguards and innovation requires a proactive and collaborative approach. Globally, the starting point is embedding privacy by design into AI systems. Privacy-enhancing technologies (PETs) such as differential privacy and federated learning are game-changers. These tools allow organisations to derive valuable insights from data without exposing sensitive personal information. 

Global regulations also play a pivotal role. Frameworks like the EU’s GDPR have set the standard for balancing innovation with accountability. The key now is to harmonise such frameworks across regions, enabling innovation to flourish, while ensuring privacy is respected. 

Transparency is also critical. Organisations need to clearly communicate how they use data, offering users greater control and earning trust. 

Strengthening cybersecurity frameworks and investing in global collaboration around ethical AI practices is essential. The future of innovation lies in leveraging AI responsibly, protecting personal information, and ensuring equitable access to these technologies.

Q: How do you ensure your organisation stays compliant across multiple jurisdictions while maintaining operational efficiency?

A: Staying compliant across multiple jurisdictions while maintaining operational efficiency requires a structured and proactive approach. Adopting a global compliance framework that aligns with major regulatory standards is crucial, such as the GDPR in Europe, CCPA in the US, and POPIA in South Africa. This unified approach ensures that policies and processes meet the highest benchmarks, allowing for consistency and scalability.

Organisations also rely heavily on technology-driven compliance management systems to monitor changes in regulations across regions. Automated tools help them track updates in real time, assess their impact and implement necessary adjustments efficiently.

Another critical strategy is engaging local experts and legal advisors in key jurisdictions. These partnerships ensure organisations understand the nuances of regional regulations and can navigate complex requirements without disrupting operations.

Education and awareness are equally important. Teams undergo regular compliance training tailored to different regions, ensuring they understand and adhere to local requirements in their daily operations, and organisations foster a culture of privacy and compliance by design. 

Q: What innovative approaches has your organisation implemented to foster privacy awareness in 2025?

A: In 2025, as data privacy concerns become increasingly prominent alongside advancements in generative AI and analytics, organisations are finding innovative ways to educate employees and customers about privacy. A robust privacy framework is no longer about compliance alone –  it’s about fostering trust, transparency and a shared responsibility for data protection.

AI-driven personalisation has also become a cornerstone of privacy awareness strategies. By leveraging artificial intelligence, organisations tailor privacy training to employees’ roles or customers’ behaviours. For instance, marketing teams are trained on data consent laws, while IT professionals learn about advanced encryption techniques. 

In today’s fast-paced digital landscape, fostering privacy awareness requires creativity and continuous engagement. By adopting these innovative approaches, organisations can go beyond mere compliance to create a culture of trust and accountability, ensuring that privacy remains a priority for both employees and customers. 

Q: How do you strike that balance in your organisation, especially when introducing new security measures or technologies?

A: Balancing data security and user privacy is one of the defining challenges of modern digital governance. As threats evolve, so too must our safeguards – but not at the expense of the trust that binds users to technology. Striking this balance demands a mindset shift: privacy cannot be an afterthought to security, nor security a casualty of privacy. They must co-evolve.  

Transparency is the bedrock of trust. When introducing new security measures. Whether AI-driven behavioral analytics, biometric authentication, or advanced encryption – organisations must clearly articulate what data is collected, how it's protected, and why it’s necessary. Privacy by design is non-negotiable. Security tools should collect only the minimum data required to achieve their purpose. Techniques like anonymisation, federated learning and on-device processing reduce centralised data exposure. 

In the end, this balance hinges on recognising that data protection is a human right, not just a technical requirement. Security measures that undermine privacy will ultimately erode trust, and without trust, no system is truly secure.  

Q: If you could have one superpower to instantly solve a major data privacy challenge in 2025, what would it be, and why?

A: It would be the ability to create universal, ethical data ecosystems – environments where security and privacy coexist seamlessly, and every individual’s data rights are respected by default. This superpower would address the root issue of fragmented global standards and inconsistent ethical practices that currently undermine trust in the digital economy.

This superpower wouldn’t just benefit organisations. It would empower individuals, putting them back in control of their data. In a user-centric privacy landscape, you wouldn’t need to wade through pages of legalese or accept opaque terms and conditions. Instead, data ecosystems would allow you to set granular permissions, view real-time data usage, and withdraw consent with a single command. Such a world wouldn’t just protect people, it would restore the trust that today feels increasingly fragile.

Q: If you had to create a meme that perfectly captures the state of data privacy in 2025, what would it say or show?

A: Picture: a split-screen image of a person frantically clicking “I Agree” on endless cookie consent pop-ups (left) vs. the same person buried under a mountain of ‘Terms & Conditions’ paperwork labeled ‘AI Training Data, Biometric Scans, and Third-Party Sharing’ (right). 

Caption: “2025 Mood: When ‘I Agree’ becomes ‘I Have No Idea What I Just Signed.’”

Related articles

2026 Executive Day: Diagnosing and fixing corporate friction

During a breakaway session on tackling workplace tension, Zeda CIO Pulana Ngwasheng unpacked her five types of corporate friction. She was joined by Auditor-General CTO Phila Ndarana and AB InBev VP of people Inette Swart.

Top