The Web Privacy Podcast

ObservePoint

Most companies trust their website. They shouldn't. The leaders who know better are rebuilding what it means to govern a website, and every week we sit down with privacy executives, compliance teams, and digital risk pros at the world's largest enterprises. We dive into stories with the ones who caught a broken consent tool before the regulator did, traced a six-figure loss back to a failed tracking pixel, and rebuilt their entire data governance approach from scratch. The rules of digital trust are being rewritten right now. This show is where you hear it first. Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. https://www.observepoint.com/

Episodes

  1. 3d ago

    Privacy Checks Are Trust Builders, Not Roadblocks with Uche Orji

    Summary What can a single pre-checked checkbox teach an entire company about consent? In this episode of The Web Privacy Podcast, host Ethan Prete talks with Uche Orji, Lawyer and Compliance officer, about the marketing signup form she flagged during an internal audit, and why "customers can always unsubscribe" is the mindset that leads to GDPR fines. Uche explains what the law actually requires of consent, how she replaced a lucky catch with a routine privacy workflow, why privacy checks are trust builders rather than roadblocks, and how legal teams can operationalize the law with process documents, education, and internal audits. The conversation closes with her advice to CMOs: focus on quality leads, because only a consenting customer converts. For privacy professionals, marketers, and anyone who owns a web form. Chapters 00:45 Introduction 01:58 How Uche got into privacy 04:02 Where privacy should sit in the organization 05:31 A checkbox that took consent 07:14 The fix: double opt in and a paper trail 09:37 Finding the problem before the fine 11:42 Trust builders, not roadblocks 14:42 Think like an internal auditor 17:44 Cookies, resource downloads, and DSARs 20:49 No universal consent framework 23:15 Quality leads over lead volume Takeaways Consent must be unambiguous, unbundled, and actively given: a pre-checked box means the company took consent the customer never gave Privacy checks are trust builders, not roadblocks: every check passed is a signal to customers that their data is safe Operationalize the law: replace institutional knowledge with step-by-step process documents sent to every stakeholder Think like an internal auditor: schedule walkthroughs of each department's processes and make teams show you, not tell you Focus on quality leads over lead volume: only a consenting subscriber converts into a paying customer Connect with the Guest LinkedIn: https://www.linkedin.com/in/orjiuchechukwu/ SponsorBrought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. Learn more about your website here

    Privacy Checks Are Trust Builders, Not Roadblocks with Uche Orji
  2. Aug 18

    Why Privacy Lawyers Are Becoming AI Lawyers: Mark Sanders at Tekion

    SummaryWhat happens to privacy lawyers when AI takes over the spotlight? In this episode of The Web Privacy Podcast, host Ethan Prete sits down with Mark Sanders, Sr Product AI & Data Privacy Counsel at Tekion, an AI native platform for car dealerships, and a 30 year veteran of in-house roles at Adobe, eBay, and Airbnb. Mark explains why the lawyers who mastered America's fragmented privacy patchwork are the best prepared to navigate AI regulation, what it looks like to work as embedded product counsel reviewing Figmas and data flows alongside engineers, and the three lens framework he uses to review every consumer facing AI agent: AI regulation, privacy, and channel specific consumer laws like TCPA and CAN-SPAM. This conversation is for privacy professionals, in-house counsel, and the analytics and marketing teams who work beside them. Chapters 00:45 Meet Mark Sanders 01:45 From digital signatures to data privacy 04:45 The shift from privacy law to AI law 06:30 Inside Tekion and the DMS space 09:00 The end of review and approve legal 13:00 Bridging the lawyer engineer language gap 18:05 Privacy through a B2B lens 20:00 The FTC and the California CARS Act 22:55 AI agents as the new privacy frontier 27:05 What keeps Mark up at night Takeaways -Embedded product counsel reviews designs and data flows before anything ships, which is cheaper and faster than the review and approve model where legal is always running behind. -Privacy lawyers who learned to navigate the fragmented US state patchwork are the best positioned professionals to handle AI regulation, which is developing the same way. -AI and privacy are concentric circles with a constantly moving overlap: you cannot have AI without data, and personal data in AI always raises privacy questions. -Every consumer facing AI agent needs a three lens review covering AI regulation, privacy, and channel laws like TCPA and CAN-SPAM that apply regardless of the technology. -AI is only as good as the data it can reach, which makes database access for AI tools the most practical privacy risk companies face right now. Connect with the GuestLinkedIn: https://www.linkedin.com/in/msanderslaw/Website: https://tekion.com SponsorBrought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. Learn more about your website here

    Why Privacy Lawyers Are Becoming AI Lawyers: Mark Sanders at Tekion
  3. Aug 6

    The M&A Playbook from the Chief Privacy Officer at Synopsys Inc, Erin McCurdy

    Summary What does it take to share personal data during a merger or acquisition without creating regulatory liability before the deal even closes? Host Ethan Prete sits down with Erin McCurdy, Chief Privacy Officer and Data Protection Officer at Synopsys, who has managed privacy through three to five acquisitions a year at Ansys and then lived the sell side of the $32 billion Synopsys acquisition of Ansys. Erin breaks down the three non negotiables that must be in place before a single row of personal data moves, why aggregated data satisfies most buyer requests at the NDA stage, the difference between due diligence and integration after signing, and why a Legitimate Interest Assessment is the lawful basis that gets you to Day One. A must listen for privacy professionals, in house counsel, and anyone whose company might one day be on either side of a deal sheet. Chapters 00:00 Introduction 02:15 Erin's path to chief privacy officer 05:30 Inside the Synopsys privacy team 08:45 Why a privacy notice is not a blanket pass 09:45 The three non negotiables before sharing data 12:45 Personal data under the NDA 14:45 The power of aggregated data 19:00 Diligence versus integration after signing 21:30 Day one readiness and the legitimate interest assessment 24:45 Web privacy audits and marketing consent 37:00 Preparing before the deal sheet hits 41:15 Know where your data is Takeaways Never share personal data at any deal stage without an executed data protection agreement in placeKeep due diligence and integration strictly separate, a signed agreement is not an all access passDefault to aggregated or de identified data early, most buyer requests can be satisfied without individual recordsBack every pre closing transfer with a documented legitimate interest assessment and a signed deletion clause in case the deal does not closeKnow where your data is before the deal sheet arrives, data mapping and records of processing are the foundation of a defensible sale Connect with the Guest LinkedIn: https://www.linkedin.com/in/erin-e-mccurdy-11040017/ Website: https://www.synopsys.com SponsorBrought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. Learn more about your website here

    The M&A Playbook from the Chief Privacy Officer at Synopsys Inc, Erin McCurdy

About

Most companies trust their website. They shouldn't. The leaders who know better are rebuilding what it means to govern a website, and every week we sit down with privacy executives, compliance teams, and digital risk pros at the world's largest enterprises. We dive into stories with the ones who caught a broken consent tool before the regulator did, traced a six-figure loss back to a failed tracking pixel, and rebuilt their entire data governance approach from scratch. The rules of digital trust are being rewritten right now. This show is where you hear it first. Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. https://www.observepoint.com/