The Web Privacy Podcast

ObservePoint

Most companies trust their website. They shouldn't. The leaders who know better are rebuilding what it means to govern a website, and every week we sit down with privacy executives, compliance teams, and digital risk pros at the world's largest enterprises. We dive into stories with the ones who caught a broken consent tool before the regulator did, traced a six-figure loss back to a failed tracking pixel, and rebuilt their entire data governance approach from scratch. The rules of digital trust are being rewritten right now. This show is where you hear it first. Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. https://www.observepoint.com/

Episodes

  1. 6d ago

    From compliance to strategy with Fenwick & West

    SummaryWhat happens to a privacy program after it declares itself ready for GDPR? According to Marcus Morissette, a privacy lawyer at Fenwick & West who was a CIPP before there were slashes, most of them stop evolving. Host Ethan Prete sits down with Marcus to unpack privacy 2.0, where compliance is table stakes and the real job is getting the business to its goals inside the company's risk appetite. Marcus explains why he told his eBay team never to say no and never to say yes, why the enforcement everyone feared turned out to be security's problem, and why the next generation of privacy lawyers has to understand the technology, from hashing versus encryption to the fact that no US law contains the word cookie. He also walks through Maslow's hierarchy of data, the four-layer pyramid he built with Aaron Weller at Concise Consulting, and why a company still worried about the CIA of its data isn't ready for AI governance. Along the way: the CIPA consent banner trap, an AI drone use case that sounds like science fiction, hiring for business acumen over law degrees, and how to make a company regulator-proof. Essential listening for privacy professionals, marketers, and anyone deciding where privacy should sit in the org. Chapters00:00 Introduction02:35 Doing privacy before privacy existed05:45 Why marketers should own privacy08:10 How GDPR built programs that stalled10:45 Privacy 2.0 is business enablement12:30 The hashing versus encryption test13:15 No US law regulates cookies14:30 The CIPA consent banner trap19:50 Maslow's hierarchy of data24:15 What AI governance actually means28:15 Building and funding a privacy team34:15 Predictions for the next three years37:30 Making your program regulator-proof Takeaways- Compliance is table stakes, not the finish line. Privacy 2.0 is business enablement: getting the business to its outcome inside the company's chosen risk appetite.- Privacy teams are guidance, not decision-makers. Never say no and never say yes; act as a risk Sherpa who presents the upside and downside so the business can decide.- The renaissance privacy lawyer has to know the technology. If you can't explain hashing versus encryption or follow the ad tech spaghetti diagram, you can't advise your business through it.- No US law regulates cookies by name; they are regulated as a sale because regulators didn't understand the tech, and consent banners deployed where they weren't required have become CIPA litigation bait.- Maslow's hierarchy of data runs security, privacy, information governance, then AI governance. A company still worried about the confidentiality, integrity, and availability of its data is not ready for an AI governance conversation. Connect with the GuestLinkedIn: https://www.linkedin.com/in/mmorissette/Website: https://www.fenwick.com SponsorBrought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. Learn more about your website here

    From compliance to strategy with Fenwick & West
  2. Sep 8

    Privacy Is a Team Sport: Pari Sarnot, Privacy, Risk & Governance Leader

    SummaryWhat do you do when privacy rights create a challenge your existing process was never designed to handle? Host Ethan Prete sits down with Pari Sarnot, a Privacy, Risk & Governance Leader with experience across organizations including Meta, Grant Thornton, eBay, and Microsoft, as well as an IAPP instructor and mentor. Pari shares an example from her broader professional experience involving a growing volume of GDPR access requests for customer service call recordings, and the privacy, operational, employee, and governance considerations that followed. She walks through how a cross-functional team evaluated multiple options and ultimately aligned the retention period more closely with the underlying business needs. Pari also discusses her approach to structured decision-making, why privacy is a team sport, the importance of cross-functional relationships, using metrics to anticipate operational challenges, and considerations around AI transparency and governance. Chapters00:00 Introduction02:15 A pragmatic, risk based approach to privacy04:30 Falling into privacy at Microsoft06:15 Navigating call recording access requests09:45 Responding to growing request volumes12:30 Five options on the table14:45 Rethinking the retention period17:15 Privacy is a team sport22:15 Metrics that spot the crisis early29:00 AI transparency and model drift31:45 Outcomes and final advice Takeaways- Retaining data without a continuing business need can introduce additional privacy, security, operational, and governance risk; aligning retention with legitimate business needs can help reduce that burden.- When navigating a complex privacy issue, start by understanding the underlying business objective, then evaluate potential approaches against factors such as risk, applicable requirements, resources, operational impact, and customer expectations.- Privacy is a team sport, and strong cross-functional relationships require continuous investment, not only engagement when an issue arises.- Track privacy metrics and request-volume trends to identify emerging capacity and operational challenges early.- Document key decisions, including the options considered, associated risks, rationale, and relevant sign-offs, so the reasoning remains clear over time. Connect with the GuestLinkedIn: https://www.linkedin.com/in/pari-sarnot/ SponsorBrought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. Learn more about your website here

    Privacy Is a Team Sport: Pari Sarnot, Privacy, Risk & Governance Leader
  3. Sep 1

    Customer Relationships That Last Decades: Will Clayton at Marriott Vacations

    SummaryWhat does it take to run privacy for a brand where the customer relationship lasts decades? Host Ethan Prete sits down with Will Clayton, Data Privacy Director at Marriott Vacations Worldwide, whose privacy career stretches back to 2000 and the early days of ad tech. Will explains why day one of a new privacy law actually starts at day minus 200, what happens to consent architecture when a customer moves from an opt-out jurisdiction to an opt-in one, and why the smartest compliance strategy is a single ethical policy that satisfies every jurisdiction at once. Along the way: who belongs in the privacy war room, who should own the consent and preference center, the real cost of negative marketing events like bounces and complaints, CIPA demand letters, AI governance, and how to spot privacy laws being weaponized. Essential listening for privacy professionals, marketers, and anyone building the infrastructure that sits between the two. Chapters00:00 Introduction02:45 From ad tech to privacy, a 26 year career04:30 The line between caring and creepy06:45 When customers move, preferences explode09:00 Day one starts at day minus 20011:00 Who sits in the privacy war room13:45 One policy for every jurisdiction20:45 Who owns the consent and preference center23:00 Measuring the cost of negative events28:45 AI governance and final predictions Takeaways- Day one of a new privacy law is a monitoring exercise, not a scramble: the program should be written, implemented, and tested 200 days before the effective date.- When a customer moves from an opt-out jurisdiction to an opt-in one, a binary consent switch becomes a matrix of flags, so preference architecture must be designed for people who move.- The strongest compliance strategy is finding the commonality: one ethical policy that satisfies every jurisdiction and extends rights even where no statute requires them.- Privacy earns executive buy-in by accurately describing consequences, because a lack of respect for consumer privacy is an existential threat to the mission, not just a compliance gap.- Marketers should measure negative events, including bounces, complaints, and opt-outs, with the same rigor as conversions, because creepy marketing is bad marketing. Connect with the GuestLinkedIn: https://www.linkedin.com/in/willclayton/Website: https://www.marriottvacationsworldwide.com SponsorBrought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. Learn more about your website here

    Customer Relationships That Last Decades: Will Clayton at Marriott Vacations
  4. Aug 25

    Privacy Checks Are Trust Builders, Not Roadblocks with Uche Orji

    SummaryWhat can a single pre-checked checkbox teach an entire company about consent? In this episode of The Web Privacy Podcast, host Ethan Prete talks with Uche Orji, Lawyer and Compliance officer, about the marketing signup form she flagged during an internal audit, and why "customers can always unsubscribe" is the mindset that leads to GDPR fines. Uche explains what the law actually requires of consent, how she replaced a lucky catch with a routine privacy workflow, why privacy checks are trust builders rather than roadblocks, and how legal teams can operationalize the law with process documents, education, and internal audits. The conversation closes with her advice to CMOs: focus on quality leads, because only a consenting customer converts. For privacy professionals, marketers, and anyone who owns a web form. Chapters00:45 Introduction01:58 How Uche got into privacy04:02 Where privacy should sit in the organization05:31 A checkbox that took consent07:14 The fix: double opt in and a paper trail09:37 Finding the problem before the fine11:42 Trust builders, not roadblocks14:42 Think like an internal auditor17:44 Cookies, resource downloads, and DSARs20:49 No universal consent framework23:15 Quality leads over lead volume Takeaways- Consent must be unambiguous, unbundled, and actively given: a pre-checked box means the company took consent the customer never gave- Privacy checks are trust builders, not roadblocks: every check passed is a signal to customers that their data is safe- Operationalize the law: replace institutional knowledge with step-by-step process documents sent to every stakeholder- Think like an internal auditor: schedule walkthroughs of each department's processes and make teams show you, not tell you- Focus on quality leads over lead volume: only a consenting subscriber converts into a paying customer Connect with the GuestLinkedIn: https://www.linkedin.com/in/orjiuchechukwu/ SponsorBrought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. Learn more about your website here

    Privacy Checks Are Trust Builders, Not Roadblocks with Uche Orji
  5. Aug 18

    Why Privacy Lawyers Are Becoming AI Lawyers: Mark Sanders at Tekion

    SummaryWhat happens to privacy lawyers when AI takes over the spotlight? In this episode of The Web Privacy Podcast, host Ethan Prete sits down with Mark Sanders, Sr Product AI & Data Privacy Counsel at Tekion, an AI native platform for car dealerships, and a 30 year veteran of in-house roles at Adobe, eBay, and Airbnb. Mark explains why the lawyers who mastered America's fragmented privacy patchwork are the best prepared to navigate AI regulation, what it looks like to work as embedded product counsel reviewing Figmas and data flows alongside engineers, and the three lens framework he uses to review every consumer facing AI agent: AI regulation, privacy, and channel specific consumer laws like TCPA and CAN-SPAM. This conversation is for privacy professionals, in-house counsel, and the analytics and marketing teams who work beside them. Chapters00:45 Meet Mark Sanders01:45 From digital signatures to data privacy04:45 The shift from privacy law to AI law06:30 Inside Tekion and the DMS space09:00 The end of review and approve legal13:00 Bridging the lawyer engineer language gap18:05 Privacy through a B2B lens20:00 The FTC and the California CARS Act22:55 AI agents as the new privacy frontier27:05 What keeps Mark up at night Takeaways- Embedded product counsel reviews designs and data flows before anything ships, which is cheaper and faster than the review and approve model where legal is always running behind.- Privacy lawyers who learned to navigate the fragmented US state patchwork are the best positioned professionals to handle AI regulation, which is developing the same way.- AI and privacy are concentric circles with a constantly moving overlap: you cannot have AI without data, and personal data in AI always raises privacy questions.- Every consumer facing AI agent needs a three lens review covering AI regulation, privacy, and channel laws like TCPA and CAN-SPAM that apply regardless of the technology.- AI is only as good as the data it can reach, which makes database access for AI tools the most practical privacy risk companies face right now. Connect with the GuestLinkedIn: https://www.linkedin.com/in/msanderslaw/Website: https://tekion.com SponsorBrought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. Learn more about your website here

    Why Privacy Lawyers Are Becoming AI Lawyers: Mark Sanders at Tekion
  6. Aug 6

    The M&A Playbook from the Chief Privacy Officer at Synopsys Inc, Erin McCurdy

    SummaryWhat does it take to share personal data during a merger or acquisition without creating regulatory liability before the deal even closes? Host Ethan Prete sits down with Erin McCurdy, Chief Privacy Officer and Data Protection Officer at Synopsys, who has managed privacy through three to five acquisitions a year at Ansys and then lived the sell side of the $32 billion Synopsys acquisition of Ansys. Erin breaks down the three non negotiables that must be in place before a single row of personal data moves, why aggregated data satisfies most buyer requests at the NDA stage, the difference between due diligence and integration after signing, and why a Legitimate Interest Assessment is the lawful basis that gets you to Day One. A must listen for privacy professionals, in house counsel, and anyone whose company might one day be on either side of a deal sheet. Chapters00:00 Introduction02:15 Erin's path to chief privacy officer05:30 Inside the Synopsys privacy team08:45 Why a privacy notice is not a blanket pass09:45 The three non negotiables before sharing data12:45 Personal data under the NDA14:45 The power of aggregated data19:00 Diligence versus integration after signing21:30 Day one readiness and the legitimate interest assessment24:45 Web privacy audits and marketing consent37:00 Preparing before the deal sheet hits41:15 Know where your data is Takeaways- Never share personal data at any deal stage without an executed data protection agreement in place- Keep due diligence and integration strictly separate, a signed agreement is not an all access pass- Default to aggregated or de identified data early, most buyer requests can be satisfied without individual records- Back every pre closing transfer with a documented legitimate interest assessment and a signed deletion clause in case the deal does not close- Know where your data is before the deal sheet arrives, data mapping and records of processing are the foundation of a defensible sale Connect with the GuestLinkedIn: https://www.linkedin.com/in/erin-e-mccurdy-11040017/Website: https://www.synopsys.com SponsorBrought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. Learn more about your website here

    The M&A Playbook from the Chief Privacy Officer at Synopsys Inc, Erin McCurdy

Ratings & Reviews

5
out of 5
3 Ratings

About

Most companies trust their website. They shouldn't. The leaders who know better are rebuilding what it means to govern a website, and every week we sit down with privacy executives, compliance teams, and digital risk pros at the world's largest enterprises. We dive into stories with the ones who caught a broken consent tool before the regulator did, traced a six-figure loss back to a failed tracking pixel, and rebuilt their entire data governance approach from scratch. The rules of digital trust are being rewritten right now. This show is where you hear it first. Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it. https://www.observepoint.com/