Home / Companies / Duality / Blog / July 2026

July 2026 Summaries

6 posts from Duality

Filter
Month: Year:
Post Summaries Back to Blog
Duality Technologies has entered a new commercial growth phase by deploying its privacy-preserving data collaboration platform for national security and defence customers, supported by a strategic investment from the National Security Strategic Investment Fund (NSSIF). The company uses privacy-enhancing technologies including fully homomorphic encryption, confidential computing, and federated analytics to allow organisations to analyze and share sensitive data without losing control or exposing it during processing. NSSIF’s investment reflects its focus on dual-use technologies that support national security, resilience, and economic prosperity, while recognizing Duality’s progress in turning advanced cryptography into scalable commercial products. Both organisations describe the partnership as an effort to expand secure, trusted data collaboration across government, industry, sectors, and jurisdictions.
Jul 20, 2026 343 words in the original blog post.
The comparison between GDPR (General Data Protection Regulation) and CCPA (California Consumer Privacy Act) highlights the distinct legal frameworks and philosophical approaches that underpin these data protection laws. While GDPR mandates a lawful basis for processing personal data and defaults to restriction, CCPA operates on an open-permission model, allowing data processing by default and emphasizing consumer opt-out rights. This fundamental difference necessitates separate compliance strategies for organizations subject to both regulations, as a program designed for one often fails to meet the obligations of the other. Privacy-enhancing technologies offer a potential solution by ensuring data handling practices that avoid triggering the most stringent requirements of either law. The regulatory landscape continues to expand beyond GDPR and CCPA, with new laws emerging in various jurisdictions, underscoring the need for robust data infrastructure and privacy-preserving architectures to manage compliance efficiently across multiple regulations.
Jul 13, 2026 2,822 words in the original blog post.
Sensitive data discovery is the process of identifying, scanning, and classifying data that needs special handling under regulatory frameworks like GDPR, HIPAA, and CCPA, serving as the first step in a comprehensive data protection workflow. The discovery process is essential for organizations to maintain compliance, as it involves creating a detailed inventory of sensitive data across various environments, including structured and unstructured systems, cloud storage, and shadow IT. Effective data management requires ongoing discovery, classification, risk assessment, and remediation, rather than treating it as a one-time compliance task. Privacy-enhancing technologies such as federated learning, secure multi-party computation, and differential privacy help organizations utilize sensitive data securely after discovery by avoiding the risks associated with data centralization and movement. Continuous monitoring and integration with data catalogs and governance platforms are crucial to maintaining an up-to-date inventory, thus satisfying regulatory obligations and mitigating data breach risks.
Jul 13, 2026 2,959 words in the original blog post.
Understanding the distinction between pseudonymization and anonymization is crucial for organizations managing data, as choosing the wrong method can lead to significant compliance and security issues, especially under GDPR. Pseudonymization involves replacing personal identifiers with codes while retaining the ability to re-identify individuals, thus keeping it within the scope of GDPR. Anonymization, on the other hand, irreversibly removes identifying elements, making the data non-personal and outside GDPR's reach, although achieving true anonymization is challenging. Tokenization is a form of pseudonymization where sensitive data is replaced with tokens stored separately. In regulated industries, neither method fully protects data during active processing, which is where privacy-enhancing technologies like Fully Homomorphic Encryption and Federated Learning become essential. These technologies enable secure data collaboration without exposing raw data, addressing the "data in use" problem that traditional methods like pseudonymization and anonymization cannot solve. Duality Technologies offers solutions that integrate these advanced privacy technologies, allowing organizations to handle sensitive data safely across different environments and regulatory frameworks.
Jul 08, 2026 3,039 words in the original blog post.
HIPAA compliant AI systems require an architectural commitment that prevents the extraction, reconstruction, or exposure of protected health information (PHI) during any stage of the AI pipeline, transcending mere Business Associate Agreements (BAAs) and de-identification. De-identification alone is insufficient for AI training due to the risk of re-identification, and consumer AI tools like ChatGPT are not HIPAA compliant. Effective HIPAA compliant AI systems utilize federated learning and privacy-enhancing technologies, allowing model training on real patient data without centralizing or exposing PHI. These systems demand comprehensive governance infrastructures, including access controls, audit trails, and data lineage tracking, to ensure compliance. The EU AI Act introduces additional compliance layers for US health systems with European operations, requiring datasets to be relevant, representative, and free of errors. As the regulatory landscape tightens, organizations that integrate privacy into their architecture rather than relying solely on documentation and vendor contracts will be better positioned to comply with evolving regulations.
Jul 07, 2026 3,078 words in the original blog post.
Data governance for AI involves a comprehensive set of policies, processes, and technical controls that oversee the collection, preparation, use, and monitoring of data throughout the AI lifecycle. This discipline, often overlooked until an audit or breach occurs, differs from traditional data governance by addressing the unique challenges posed by machine learning models, which absorb training data into their weights, making it difficult to trace, audit, or reverse. The framework extends traditional data governance to include aspects like data lineage and provenance tracking, consent verification, and bias auditing, especially critical in regulated industries such as healthcare, finance, and government. These sectors operate under stringent regulations like HIPAA, SR 11-7, and data classification regimes, which demand rigorous documentation, consent management, and privacy-preserving technologies to ensure compliance. Furthermore, the EU AI Act imposes additional data governance requirements for high-risk AI systems, necessitating frameworks that can satisfy both EU and US regulatory standards. Privacy-enhancing technologies, such as fully homomorphic encryption and multi-party computation, provide robust solutions for training models on sensitive data without exposing it, offering technical guarantees that surpass traditional policy-and-audit methods.
Jul 02, 2026 3,203 words in the original blog post.