Skip to content
Artwork for She Said Privacy/He Said Security
BusinessManagementEntrepreneurshipExplicit

She Said Privacy/He Said Security

Jodi and Justin Daniels

This is the She Said Privacy / He Said Security podcast with Jodi and Justin Daniels. Like any good marriage, Jodi and Justin will debate, evaluate, and sometimes quarrel about how privacy and security impact business in the 21st century.

Play
  • 20 episodes
  • fortnightly
  • Avg 31 min
  • English
  • August 27 · 30 min

    Maintaining Human Intelligence in an AI World

    Elise Houlik is the Chief Privacy Officer at Intuit, where she leads the company's global privacy and responsible data innovation and protection strategy, ensuring data is used to safely power innovation across Intuit's ecosystem of financial technology products. Her team is deeply engaged with the business on all matters related to product development, data innovation and governance, and information security. In this episode… Legal and privacy professionals are using AI more often to save time and accomplish more in their day-to-day work. While these tools offer clear advantages, they also generate convincing outputs that are incomplete, generic, or factually wrong. Using AI responsibly requires professionals to apply human judgment and review the output closely to ensure it is accurate and supported before relying on it. As AI becomes more embedded in legal and privacy work, critical thinking skills remain just as important as knowing how to use the technology. Professionals get the most value from AI when they view it as a collaborator, rather than an authority. As privacy and legal teams use AI to kickstart analysis, pull facts together, and hunt for nuances across fragmented laws, they need to compare its answers against actual laws and reputable sources and challenge the tool when an output misses the mark instead of accepting it at face value. Being mindful about the personal information they put into public models is equally important. Professionals should also be comfortable using a variety of different tools and learning which ones fit different purposes. And as companies hire the next generation of tech-savvy professionals, they need to ensure they don't become overly reliant on AI and provide them with hands-on experience and exposure to real conversations that strengthen analytical skills. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Elise Houlik, Chief Privacy Officer at Intuit, about the importance of maintaining human intelligence in the age of AI. Elise shares how AI is changing the skills employers value in legal and privacy professionals and explains why human judgment, curiosity, and a willingness to challenge AI-generated answers are essential as these tools become a standard part of workflows. She highlights why junior professionals still need practical experience and peer-to-peer learning opportunities and shares her perspective on keeping human intelligence at the center of how professionals use AI. Elise also offers tips for building AI skills and experimenting with different tools.

  • August 13 · 32 min

    Navigating the New Era of Data Broker Laws

    For 30 years, Ben Isaacson has been a leading privacy professional and trusted counsel. During the "Internet 1.0" era, he was instrumental in launching the first self-regulatory guidelines for email marketing, addressable TV, and mobile marketing. Ben was one of the first privacy professionals to get certified as a CIPP/US with the IAPP in 2005. In this episode… Data broker laws are pulling a once-hidden industry into the light. For years, consumers generally had no idea which companies were compiling and selling their personal information, what those companies were doing with it, or how to opt out. States are responding with data broker laws that require brokers to register and disclose information about their businesses and data-selling practices. Seven states now have these laws on the books, with some providing consumers with a centralized mechanism to request deletion of their data or to opt out of its sale. So, how can companies that purchase or license data from brokers manage the downstream risks that come with using it? Companies buying or licensing data from data brokers need to know where that data comes from, how it's used, and what their third-party contracts permit. Legal and privacy teams should work with marketing and sales to identify which adtech vendors they buy or license data from and scrutinize their licensing relationships. They also need to map how purchased data flows through the business and ensure their privacy notices disclose its use. California's Delete Act makes this downstream visibility especially important because it requires data brokers to apply deletion requests before that data is used. Companies also need to consider whether their activities qualify them as data brokers, particularly because New Jersey's data broker law extends registration requirements to data collectors, potentially affecting businesses that fall outside the traditional data broker definition. Companies should seek a legal opinion to determine where they stand based on the nature of their business and its commercial terms. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Ben Isaacson, Principal at In-House Privacy, about the rise of data broker laws and what they mean for companies that buy, license, or sell personal information. Ben discusses the evolution of these laws and how data broker definitions and legal requirements vary across states. He highlights what companies can do to mitigate risk when using data purchased from brokers and provides tips on how companies can determine whether they are considered data brokers under these laws. Ben also shares his perspective on how California's Delete Act could influence future state and federal regulation.

  • July 30 · 36 min

    The People-First Approach to Building Effective Privacy Programs

    Chris Tarbell is a leading privacy, cyber, and data strategy executive. He currently serves as the Chief Privacy Officer for VERSANT Media LLC. Prior to his current role, Chris was an associate general counsel for Fanatics and the Walt Disney Company, where he advised global businesses on compliance with domestic and international privacy, data security, and related consumer protection laws. Most recently, Chris served as Senior Counsel at the leading law firm of Kelley Drye and Warren, where he also supported clients in numerous regulatory investigations related to marketing and advertising. In this episode… Building strong privacy programs relies on human connection and a deep understanding of organizational dynamics and business goals. To be successful, privacy professionals must participate in the business rather than just focusing on meeting legal requirements. This approach enables leaders to advocate for the tools, budget, headcount, and other resources to move the program forward. Because privacy impacts many business functions, it is very much a people business, requiring strong relationships, cross-functional collaboration, and the ability to build trust with stakeholders and internal teams. So, what steps can companies take to achieve this? Putting this into practice starts with assembling a people-first privacy team and hiring individuals with the soft skills to step into unfamiliar situations, assess what is needed, and work across departments to move the program forward. By bringing curiosity and enjoyment to privacy work, they create an environment where other departments are more willing to involve privacy early and often. This approach is especially important in the media industry, where privacy pros may need to work with news colleagues to balance the right to be forgotten with First Amendment considerations or partner with intellectual property teams to protect personal information during piracy investigations. And while collaboration is essential, teams must also determine what can realistically be achieved with the time and resources available without allowing perfection to stall progress. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Chris Tarbell, Chief Privacy Officer at VERSANT Media, about building effective privacy programs through relationships and collaboration. Chris explains how his experience as both in-house and outside counsel shaped his ability to understand business objectives, advocate for resources, and communicate the value of privacy. He shares insights on the cross-disciplinary nature of privacy work in the media industry, lessons from building a program during a major corporate spinoff, and the importance of creating a people-first privacy team capable of handling unfamiliar business challenges. Chris also explains why bringing some fun to privacy work can make a program more effective.

  • July 16 · 36 min

    AI Governance Built to Scale

    Andrew Burt is a lawyer, entrepreneur, and former national security official widely recognized as one of the world's leading experts in the intersection of law and artificial intelligence. Over the last decade, he has built companies, law firms, and software systems that have revolutionized how AI is managed for legal risks, and his work has impacted hundreds of millions of people around the world. As a pioneer in the field of legal engineering, he founded and led the world's first legal engineering team focused on automating data governance in 2016. In 2019, he co-founded and later sold the first-ever law firm run by lawyers and data scientists solely focused on artificial intelligence. He is co-founder and CEO of Luminos.AI, the first AI governance company focused on legal risk, where he currently serves as CEO. In this episode… Companies are adopting AI faster than they can set guardrails around it. Privacy and legal teams can review an AI model or approve a vendor contract, but AI governance doesn't stop there. Risk varies by use case, including whether the system is internal or customer-facing and the level of human oversight involved. As organizations connect new AI tools, chatbots, and agents to more business processes and systems, AI governance has to move from policy to a scalable structure. One of the biggest challenges companies face is making governance work at the same speed as AI adoption. Andrew Burt knows this well as a co-author of the NIST AI Risk Management Framework, where he helped shape how companies identify, document, and manage AI risk. Turning frameworks into action is where organizations often get stuck. Implementing AI guardrails requires involvement from legal, privacy, security, compliance, engineering, and other business teams. Yet when too many people share responsibility without a lead decision-maker, it can create what Andrew calls "governance debt." Effective governance starts with accountable leadership and a working connection between the teams writing the rules and the teams building the AI systems. This means moving beyond policy-heavy approaches so governance can scale with the business and the technology. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Andrew Burt, Co-founder and CEO of Luminos.AI, about the challenges of scaling AI governance. Andrew explains why traditional governance models struggle to keep up with how quickly AI systems are built and deployed. He breaks down the differences between managing risk at the model level and at the use-case level, including why the same AI tool can carry different risks depending on its use. Andrew also shares his prediction for the future of AI regulation in the United States and offers practical steps companies can take to strengthen AI governance.

  • July 2 · 36 min

    Lessons Learned From a Decade of FTC Privacy Enforcement

    Aaron Alva is a Harvard Berkman Klein Center fellow and the Founder of Alva Strategy Center, advising organizations and enforcers on privacy, security, and AI governance. Previously, Aaron was a lead tech advisor at the FTC, where he was instrumental in driving the agency's approach to privacy and security enforcement. In this episode… Privacy risks often hide in how companies collect, use, and share personal information. Smart TVs, health-related websites, and location data have all drawn regulatory scrutiny when data is used in ways consumers did not reasonably expect. A decade of FTC privacy enforcement shows companies what regulators consider unfair or deceptive. So, what can companies learn from these cases to strengthen their privacy practices? Reducing privacy risk starts when companies understand the data they collect, where it goes, why it's being used, and whether that use is necessary in the first place. Companies should pay close attention to handling sensitive data with care, including health information, location data, children's and teens' data, and driver behavior data. Embedding stronger privacy practices often comes down to establishing clear purpose limitations, thoughtful data minimization measures, limited retention, and privacy-enhancing defaults. It also requires a regular and thorough review of AdTech tools, like pixels and tags. Getting these practices right can help companies reduce regulatory risk. Yet when companies fall short, the FTC and state privacy regulators can impose remedies that reach beyond fines, requiring companies to delete data, stop certain data uses, change platform default settings, or build a stronger privacy program. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Aaron Alva, Founder of Alva Strategy Center, about what companies can learn from a decade of FTC privacy enforcement. Aaron explains the role technologists play in helping enforcement agencies work through technically complex privacy issues during investigations. He delves into lessons from major enforcement actions involving smart TVs and social media platforms and shares insights on the FTC's privacy remedies. Aaron also explains how companies can strengthen their privacy practices by setting clear limits on data use, treating sensitive data with care, and aligning privacy controls with consumer expectations.

  • June 18 · 27 min

    How to Build and Implement AI Systems That Businesses Can Trust

    Myles McNamara is Tarkenton's lead technical architect and full-stack developer, specializing in building secure, scalable software solutions. He oversees infrastructure, code, and system design, serving as the team's in-house expert. Previously, he worked with Fortune 500 government contractors and ran his own software and hosting companies. In this episode… Integrating responsible AI tools and systems into business operations depends less on the model itself and more on the privacy and security controls a company embeds around it. "We need AI" is often where the conversation starts, but turning that need into a safe and controlled environment requires a clear understanding of where data lives, who can access it, and what the AI system is allowed to do. Those considerations shape whether AI can support the business without creating unnecessary risks. How can organizations design and implement AI in a way that is secure and grounded in real business needs? Before companies implement a new AI system, they need to set guardrails around how it will operate in practice. Governance needs to be built into the system from the beginning, not left in a policy or bolted on later. Establishing clear data boundaries, access controls, and system-level permissions defines what the AI tool can access and which actions it can perform. Logging and audit trails give companies visibility into how the system is functioning, so if something goes wrong, they can understand what happened and why. AI will continue to evolve, and companies also need to ensure that their privacy and security controls keep pace through regular monitoring and continued improvements. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Myles McNamara, Principal Software Engineer at Tarkenton, about designing and implementing AI tools and systems responsibly. Myles shares what it takes to build AI agents and systems in a secure, controlled way, including how companies should think about whether AI is needed and how much autonomy it should have. He emphasizes the importance of integrating governance into system design and offers advice for safeguarding data. Myles also shares how engineering teams can balance business expectations with privacy and security concerns and discusses why AI governance might get overlooked in practice.

  • June 4 · 45 min

    How a Georgia Lawmaker is Tackling Kids' Online Safety

    Sen. Sally Harrell was elected to the Georgia State Senate in 2018, representing DeKalb and Gwinnett counties. Prior to serving in the Senate, Sen. Harrell earned a Master of Social Work and worked as a non-profit executive. Recently, Sen. Harrell co-chaired a legislative study committee on Kids' Online Safety. She and her husband are proud parents of two young adult children. In this episode… Keeping kids safe online has moved beyond screen time limits and reminders about what not to click. From social media and gaming platforms to AI companion chatbots, lawmakers are focusing on features that can manipulate children or expose them to harmful interactions. Parents want stronger protections for their children, and lawmakers on both sides of the aisle agree more must be done. As lawmakers push to regulate harmful design and AI-driven risks, balancing child safety with innovation remains a challenge. Protecting kids online takes more than one policy or parental control setting. Georgia State Senator Sally Harrell knows this well. She introduced a resolution to create a bipartisan-led Senate Study Committee dedicated to keeping kids safe online. The committee's work helped advance the bell-to-bell cellphone ban for high school students, building on the K through eight ban previously signed into law in Georgia. Their efforts also led to bills addressing addictive social media and gaming design and AI companion chatbot safeguards. The legislative process revealed how lobbying pressure and buried bill language can weaken broadly supported protections. Yet call to action matters. Parents and constituents need to stay engaged, get involved, and speak up to ensure legislators are held accountable for protecting children online. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Georgia State Senator Sally Harrell about the realities of advancing kids' online safety legislation. Senator Harrell explains how the bipartisan-led Georgia Senate Study Committee on kids' online safety turned parent concerns into legislative action. She shares a behind-the-scenes look at what it takes to keep bills moving, including the constraints of short legislative sessions, Big Tech lobbying, and the role public advocacy plays. Senator Harrell also provides privacy and security tips for families navigating children's online activity.

  • May 21 · 31 min

    Navigating Opt-Out Challenges and Strategies for Getting It Right

    Max Anderson is a seasoned product executive with a proven track record of bringing successful technology products to market in the consumer privacy, data management, and marketing space. Prior to Ketch, Max was the Director of Product Management at Krux. After joining Salesforce as part of the Krux acquisition, Max ran data privacy and consumer identity products at Salesforce, including the rollout of their industry-leading GDPR solution set. Prior to Krux, Max was a Product Manager at IPG Mediabrands, where he was responsible for multiple successful advertising measurement products. In this episode… Getting consent and opt-out compliance right requires more than adding a cookie banner or standalone webform. It requires consent tools, consumer identifiers, and downstream third-party systems to work in concert. Regulators are looking closely at whether a consumer's choice follows them across devices, browsers, and the systems where their data is collected and used. When those pieces do not connect, an opt-out can be incomplete, putting companies at risk of regulatory enforcement. So, what does it take to build a complete and compliant consumer opt-out experience? Identity management is central to effective consent and opt-out compliance because consumer choices need to be honored at the person level, across devices and browsers. Privacy rights forms and consent tools also need to connect, so an opt-out request reaches the CMP controlling tag firing on the site. When data has moved to third-party advertising and marketing vendors, companies need to understand whether they can flow that opt-out downstream. Yet many third-party platforms do not provide privacy APIs or consent-related controls, and building integrations with them can be challenging. Companies should test the process by submitting an opt-out through the webform, returning to the website, and checking whether browser data collection events still happen that could facilitate cross-context behavioral advertising. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Max Anderson, Co-founder and Head of Product at Ketch, about navigating consent and opt-out compliance gaps. Max explains why identity management matters when honoring consumer choices across devices and browsers, and how disconnected privacy rights forms and consent tools can leave opt-outs incomplete. He also describes the challenges companies face when flowing opt-outs down to third-party advertising and marketing vendors and shares practical steps companies can take to assess vendor controls, cross-device exposure, and the areas that may create enforcement risk.

  • May 7 · 39 min

    From Gatekeeper To Architect: How General Counsel Are Shaping Innovation in the AI Era

    Smrithi Mohan is General Counsel at Awesome, the parent company of SmugMug and Flickr, where she oversees all legal, IP, privacy, and compliance matters for two of the world's most recognized photo-sharing platforms. She previously spent a decade at Dun & Bradstreet, where she built the company's first global IP and innovation practice. An elected Board of Education member and recognized Top Woman Leader, she speaks and writes on legal operations, IP strategy, leadership, and building legal functions from the ground up. In this episode… When a new AI feature ships or a new product is designed, general counsel may not be looped in until after key decisions are made. This creates risk because most product decisions have legal implications, especially around data use, user rights, and consent. That changes when legal teams are brought into the product development cycle at the outset, helping design outcomes that align with legal obligations and business goals. How can general counsel and legal teams move from being seen as gatekeepers to business drivers? Shifting how general counsel and legal teams are viewed starts with building strong relationships across business teams. When legal leaders understand how product, engineering, and other teams operate, they are more likely to be included as ideas take shape. Early involvement enables general counsel to explain regulatory requirements and legal frameworks across different jurisdictions, thereby improving products and making them more defensible. It also creates space to ask fundamental questions in AI development upfront, including what data is being used, whether the company has the right to use it, who owns the outputs, and whether user information is collected with proper consent flows. Vendor relationships require the same level of attention, as older contracts may not address AI and often need audits, addendums, and updated terms. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Smrithi Mohan, General Counsel at Awesome, about how legal teams can integrate into AI and product development. Smrithi explains why general counsel needs to act as business architects and not just legal advisors, and what it takes to make that shift. She outlines the core legal questions teams should address when developing AI tools and other products, how to manage third-party vendor contract risks, and the evolving legal gray areas surrounding AI-generated content and platform liability. Smrithi also offers practical advice on building genuine, collaborative relationships across teams.

  • April 23 · 21 min

    The Accountability Problem Behind AI Adoption

    Kristin Calve is the Editor & Publisher of Corporate Counsel Business Journal and the Co-founder of Law Business Media. She leads editorial strategy focused on AI governance, legal operations, and board-level risk, and convenes forward-leaning legal leaders through interviews, events, and industry analysis. In this episode… Controlled AI deployment is one of the most pressing challenges legal and business leaders face right now. New AI tools are often adopted quickly without the full understanding of how they're being used, where data goes, and who's accountable for the outcomes. Some teams explore AI without direction or intention. Others prescribe it with guardrails, defining who can use it and how. The gap between those two approaches is where risk lives. So, how can organizations deploy and use AI without losing control? Legal operations teams are often accountable for how AI is used in practice. They understand the regulatory landscape and manage contracts and deadlines. They're often involved in operations across finance, HR, sales, and other business functions, so they know how those processes work and why they were built that way. That institutional knowledge matters as AI is introduced into those systems. At the same time, prompt documentation, AI notetakers, and recordings are introducing new risks. Teams may not know what is being captured, where it is going, or how it could become discoverable. Supply chain exposure adds another layer of risk. Vendors might embed AI into the tools organizations already rely on, potentially affecting an organization's overall privacy and security posture. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Kristin Calve, Editor & Publisher of Corporate Counsel Business Journal and Co-founder of Law Business Media, about how organizations are navigating AI deployment and risk. Kristin explains how companies are deploying AI inconsistently and the challenge of controlling its use. She shares how regulatory requirements shape accountability and why legal operations teams often bear responsibility for what's permissible. Kristin also explains the risks of prompts and recordings becoming discoverable and discusses how AI increases speed and capacity, but does not replace the need for judgment.

  • April 9 · 31 min

    Advancing AI Fluency With Grit and Growth Mindset

    Gabrielle Kohlmeier is a lawyer, tech whisperer, and transformation executive in a lifelong love affair with growth mindset and sustainable innovation. From building a Fortune 30 legal and policy approach to antitrust, to navigating retail risk, to leading global legal AI adoption and outperforming teams. She helps organizations rightsize risk and turn disruption into strategic value. In this episode… Many companies are rushing to adopt AI tools and publish AI policies, yet far fewer are investing in AI fluency across their workforce. Knowing how to use an AI tool is not the same as understanding what it is doing, what data it collects and uses, and the privacy, security, and compliance obligations that come with using it. Without that level of understanding, organizations risk using AI without fully grasping its impact. So, what does true AI fluency look like in practice? Organizations spend time creating AI governance policies, and sometimes those policies are not operationalized. Governance then becomes "precious" when it is documented and published but not embedded into how teams actually work. That gap becomes more pronounced when teams lack the AI fluency needed to apply governance to their day-to-day use of AI tools. To be effective, governance needs to be lived, with clear accountability, ongoing feedback loops, and policies and processes regularly revisited as AI use cases evolve. It also requires establishing privacy and security guardrails that allow teams to experiment with AI responsibly, while right-sizing risks. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Gabrielle Kohlmeier, Legal and Innovation Executive, about building AI fluency and operationalizing responsible AI use. Gabrielle explains why AI fluency goes beyond simply using AI tools and requires a deeper understanding of the ethical and legal obligations that come with them. She shares how AI governance often breaks down in practice and what it takes to truly operationalize it, while enabling responsible AI experimentation with clear guardrails. Gabrielle also highlights numerous curated resources to help companies stay grounded as AI evolves and offers a practical privacy tip that applies to everyday internet and AI use.

  • March 26 · 26 min

    Why Every Company Needs a Trust Center

    Kelly Peterson is the Chief Privacy and Compliance Officer for Yobi AI, a company dedicated to building models based on consented data to democratize access to data in an ethical and privacy-respecting manner. As CPO, Kelly establishes the strategy for the company's compliance programs and advises on product development utilizing PbDD. She collaborates cross-functionally with key internal stakeholders and external partners to explain Yobi's unique approach to AI development. In this episode… Building trust around how companies collect and use consumer personal information has become a defining challenge. Companies need to be upfront with the types of personal information they collect from consumers, why they collect it, and how it is used. Making that information easy to access can help people better understand a company's privacy and security practices. And one way to do that is through a trust center. Trust centers do more than build credibility. They can also serve as an efficient sales and marketing tool that quickly answers questions about an organization's privacy and security practices. Building one often starts with an internal advocate. That advocate can work with sales and marketing teams to demonstrate how having privacy and security information in one place enables more effective responses to requests from organizations evaluating potential business partnerships. When building AI tools or other new products and features, companies should treat trust as a design choice and be transparent about how behavioral data is used and the benefits consumers receive from it. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Kelly Peterson, Chief Privacy and Compliance Officer at Yobi AI, about building trust-centered approaches to privacy and security practices. Kelly explains the role trust centers play in demonstrating transparency to consumers and business partners. She shares how businesses benefit from building new products, features, and AI tools with trust in mind, and why demonstrating the benefits of using consumer behavioral data helps build trust. Kelly also discusses the challenges companies face when navigating overlapping privacy laws, AI regulations, and other privacy-adjacent regulations.

  • March 12 · 38 min

    Behind the Curtain With Tom Kemp: New CCPA Rules, Enforcements, and What's Next

    Tom Kemp is the Executive Director of CalPrivacy. Previously, he was a Silicon Valley tech entrepreneur and CEO. He volunteered on the California Privacy Rights Act campaign and has advised on major tech policy legislation nationwide, including the Delete Act (SB 362) and AI Transparency Act (SB 942). He is the author of Containing Big Tech. In this episode… California's privacy law evolves once again as its new regulations push companies to move from policy to proof. Privacy risk assessments, cybersecurity audits, and automated decision-making technology requirements introduce new obligations for businesses that process personal information at certain thresholds. Alongside recent CCPA enforcement actions, these new rules reinforce the importance of establishing governance, ensuring technical compliance, and demonstrating accountability. So, what do businesses need to do to stay ahead? CCPA enforcement actions do not happen in a vacuum. Consumer complaints, website and data flow reviews, and media reports influence investigations that can trigger enforcement actions. Tom Kemp, Executive Director of CalPrivacy, knows this firsthand as he oversees these efforts, along with the rollout of the new CCPA rules. Companies are being evaluated based on real-world user experience. That's why they need to establish governance and strong operational processes that ensure compliance as regulations and consumer expectations evolve. Companies also need to walk a mile in a consumer's shoes and test their websites and mobile applications to ensure they are free of dark patterns and that access, deletion, and opt-out rights function without friction. And when it comes to AI use, companies need to keep in mind that existing CCPA obligations still apply whenever personal information is involved. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Tom Kemp, Executive Director of CalPrivacy, about the new CCPA regulations, enforcement, and what's next for businesses. Tom explains why the California Privacy Protection Agency transitioned to the CalPrivacy name and how the agency focuses on raising privacy awareness and making it easier for consumers to operationalize their privacy rights. He outlines key timelines and thresholds tied to risk assessments, cybersecurity audits, and automated decision-making obligations and discusses how businesses can leverage existing processes to meet the new requirements. Tom also shares how California's collaboration with other state attorneys general and international regulators is shaping enforcement coordination and privacy oversight.

  • February 26 · 32 min

    Governing AI and Privacy Without Becoming the Bottleneck

    Brittney Justice is the Global Head of Privacy at Valvoline Inc., leading the company's privacy strategy. She works at the intersection of data privacy, technology, and AI, advising on governance and risk at scale. Brittney also serves on the IAPP Privacy Law Advisory Board, shaping the future of privacy law. In this episode… Privacy and security leaders operate in an environment where innovation moves quickly, and risk evolves just as fast. That's why global companies need to maintain one consistent privacy program and layer in jurisdiction-specific requirements as privacy laws evolve. At the same time, organizations are adopting new AI tools while deepfakes and executive impersonation threats introduce new reputational challenges. How can companies enable innovation while staying ahead of emerging privacy and security risks? When privacy and security teams are pulled into projects early, relationships strengthen, and teams no longer hesitate to involve them in new initiatives. Instead of being seen as gatekeepers, they become part of the conversation, strengthening trust and collaboration across business teams and prompting proactive issue spotting. That same discipline applies when evaluating and managing AI tools, where privacy leaders need to coordinate with business teams to understand what the tool will accomplish and how it could affect the company. This requires asking: what problem is being solved, what data is involved, and what the real impact would be if something goes wrong, especially when third-party vendors and model training are involved. That same mindset is critical to educating employees about AI deepfakes and executive impersonation risks, as coordinated response planning can reduce impact. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Brittney Justice, Global Head of Privacy at Valvoline Inc., about building a globally consistent privacy program while supporting business growth and managing emerging AI risks. Brittney explains her approach to building and maintaining one strong global privacy program without creating separate versions for every applicable jurisdiction, and the importance of embedding privacy and security teams into projects early to identify risks. She also shares tips on evaluating new AI tools, managing third-party and AI model training risks, and using executive deepfake simulations to strengthen employee awareness and establish clear escalation paths.

  • February 12 · 20 min

    Optimizing Privacy, Cybersecurity, and AI Governance for Growth

    Amy Worley is a seasoned executive and thought leader in cybersecurity, privacy, and AI governance. She is the Managing Director at BRG and leads its Privacy Compliance Advisory Practice. With a unique blend of legal, technical, and strategic expertise, Amy brings a multidimensional perspective to digital risk management and value creation. In this episode… Digital trust has become a commercial imperative. As companies move quickly to adopt new AI tools and systems, privacy, security, and governance efforts often remain fragmented. Teams continue to operate in silos, without a shared framework for managing data and AI across the business. Without governance and core privacy and security controls in place, AI initiatives are more likely to fail or create risk. So how can organizations move forward with AI while building digital trust? The best path forward often starts with structure, not speed. Rather than jumping straight into new tools, organizations need to have clear processes in place before implementation. Developing a competitive advantage through the confidence by design framework means building evidence-based programs grounded in transparency, data minimization, and core privacy and security controls. Taking time upfront to anticipate where projects might fail can help teams scope governance work more effectively before moving forward. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Amy Worley, Managing Director and head of the Privacy Compliance Advisory Practice at BRG, about building digital trust by aligning privacy, security, and AI governance frameworks. She explores how organizations can integrate these disciplines into one unified approach rather than operating in silos. She shares insights from her book, The Confidence Advantage, and explains how evidence-based programs, metrics, and governance fit into the confidence by design approach. Amy also discusses why governance must precede companies' implementation of AI tools and offers practical ways to strengthen everyday privacy and security habits.

  • January 22 · 30 min

    How Safe Are Kids' GPS Trackers and Smartwatches?

    Steve Blair is the Senior Privacy and Security Test Program Leader at Consumer Reports, where he evaluates connected devices and digital products to uncover privacy and security risks. With a background spanning early internet technology, mobile hardware, and product security, he helps consumers better understand how their data is collected, used, and protected, especially in emerging technologies designed for families and children. In this episode… Connected devices designed for kids play a growing role in how families stay connected and informed. GPS trackers, smartwatches, and other apps and tools often promise safety and convenience, yet they also raise questions about how children's data is collected, used, stored, and protected. The challenge is not whether these tools function as intended, but how they handle personal information once they are in use. How can parents gain confidence in the technology their children use every day while avoiding privacy and security risks? A practical starting point is to read privacy notices and product descriptions, then examine how devices and apps behave in practice. Reviewing default settings, questioning app permissions, and noting how easy privacy controls are to find can help parents manage risk and better understand how a company collects and handles kids' data. These considerations become especially important when children are required to use certain apps or connected devices to participate in school activities or other events. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Steve Blair, Senior Privacy and Security Test Program Leader at Consumer Reports, about privacy and security risks in kids' GPS trackers, wearables, and apps. Steve explains what Consumer Reports found when testing GPS trackers and wearables designed for children, and how hands-on testing helps parents better understand device privacy controls. He shares practical ways parents can assess app privacy and security protections, even without deep technical expertise. And Steve also shares practical privacy and security tips parents can use every day, like keeping devices updated, removing apps when they are no longer needed, and requesting data deletion when app use ends.

  • January 8 · 27 min

    From Manual to Automated: Building Privacy Programs That Scale

    Ron De Jesus is the Field Chief Privacy Officer at Transcend, driving practical privacy governance and industry advocacy. He previously led privacy at Grindr, Tinder, and Match Group, built global programs at Tapestry and American Express, founded De Jesus Consulting, and remains an active community leader through the IAPP and LGBTQ Privacy & Tech Network. In this episode… Privacy professionals navigate a growing web of privacy regulations and emerging technologies, yet many still rely on manual processes to manage their programs. Teams might track global requirements in spreadsheets and manually triage privacy rights requests. To scale privacy programs effectively, teams need to move beyond manual approaches. So what should privacy teams consider as they adopt automated solutions? The key to scaling privacy programs efficiently lies in embracing automation and technology that aligns with an organization's broader goals. When privacy leaders secure early buy-in from stakeholders, technology decisions are more likely to support the business beyond basic compliance needs. Teams also need clarity on what they are trying to accomplish, a thorough understanding of where their data lives, and time to evaluate how new tech fits into their existing systems and workflows. Sometimes teams expect third-party privacy tools to work out of the box and solve their compliance needs. However, that is often not the case, and why companies must review and test vendor tech solutions to ensure they accurately meet company requirements. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Ron De Jesus, Field Chief Privacy Officer at Transcend, about transitioning privacy programs from manual processes to automation. Ron emphasizes the importance of internal alignment when adopting privacy technology, discusses the risks of treating privacy tools as plug-and-play compliance solutions, and highlights the need for companies to review vendor tech solutions against their specific requirements and legal obligations. He also explains how the privacy community helps shape his view of how teams operationalize privacy in practice and shares his prediction for what's in store for privacy professionals in 2026.

  • Dec 18, 2025 · 26 min

    Why Knowing Company Data is Every General Counsel's First Privacy Move

    Talar Herculian Coursey is the GC and VP HR for ComplyAuto, a SaaS company serving auto dealerships in the US. Talar was previously the GC for Vista Ford and a file clerk, associate, and partner at the national labor and employment law firm, Fisher Phillips LLP. Talar is licensed to practice law in California and Utah. She is also a CIPP, CIPM, certified yoga instructor, certified life coach, and a retired dog walker. In this episode… Knowing the types of data a company collects is essential for building strong privacy and security practices. Many organizations collect a wide range of sensitive information, including financial data, identity documents, and data created through connected technologies. Employees often rely on text messages and mobile apps to communicate, creating touchpoints where sensitive information is shared with third parties. So, how can general counsels and privacy pros safeguard sensitive information while accounting for the risks introduced by third-party vendors? Protecting sensitive information starts with establishing policies and processes that reflect how data flows through an organization and understanding how teams communicate with consumers. That's why it's important to provide employees with secure, encrypted channels when communicating with customers. Customized training is equally important, and using gamification and tailored phishing simulations helps engage employees, deepen their understanding of the sensitive information they handle, and improve their ability to recognize potential privacy and security risks. By pairing these tools with training that is specific to the work environment, general counsels and privacy pros can help employees stay vigilant and reduce the likelihood of privacy and security incidents. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Talar Herculian Coursey, General Counsel and Vice President of Human Resources at ComplyAuto, about managing privacy and security risk tied to data collection practices. Drawing on her experience in the automotive dealership industry, Talar explains why understanding the types of data companies collect is critical to building effective privacy and security programs. She explains how companies can strengthen their defenses through encrypted communication tools and customized employee training programs. Talar also outlines the significant risks posed by third-party vendors and offers practical tips for managing these risks.

  • Dec 11, 2025 · 22 min

    So You Got the Privacy Officer Title, Now What?

    Teresa "T" Troester-Falk has over 20 years of experience building privacy programs that work when resources are limited and timelines are real. She led initiatives at DoubleClick (Google), Epsilon, Nielsen, and Nymity (TrustArc) before founding BlueSky Privacy and BlueSky PrivacyStack. Today she creates practical tools and systems that help privacy professionals step into their role with confidence and give executives decisions they can act on. Through her writing and teaching, she brings clarity to complex requirements and shows how privacy can succeed in practice. In this episode… Privacy professionals step into their roles with foundational knowledge, yet often without the support needed to apply it in practice. They are sometimes expected to build and maintain privacy programs without a budget, authority, or a clear plan. This gap creates daily uncertainty, especially for newly certified privacy professionals who enter the field with little operational experience. So how can privacy professionals move through these challenges and build programs they can defend with confidence? Building a functioning privacy program requires making decisions in gray areas and moving forward without waiting for perfect information. Privacy pros can start by focusing on high-risk areas first and documenting their decision-making process using a three-pillar approach. This framework helps professionals explain the decision they made, maintain what was decided, and defend it with evidence. Clear ownership and accountability ensure processes hold over time. With the right operational structure in place, privacy pros can move privacy programs forward even when resources are tight. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Teresa Troester-Falk, Founder of BlueSky Privacy and BlueSky PrivacyStack, about building effective privacy programs with limited resources. Teresa explains how a simple decision-making framework can help new and seasoned privacy professionals work through ambiguity. She also shares strategies for prioritizing privacy work when budgets are tight and expectations are high, and explains why establishing ownership and operational processes are essential for sustaining long-term privacy success.

  • Dec 4, 2025 · 28 min

    Where Policymaking Meets Privacy and AI Innovation

    Monique Priestley is a Vermont State Representative focused on data privacy, AI, right to repair, and the future of work. Monique serves on the House Commerce & Economic Development Committee, Joint IT Oversight Committee, and multiple national tech policy task forces. She was named a 2024 EPIC Champion of Freedom. In this episode… State privacy laws are evolving faster than ever, yet the dynamics shaping them often remain out of view for most organizations. Technology shifts quickly, and the issues raised in proposed privacy and AI bills require far more research and preparation than the calendar allows. That's why lawmakers work year-round to understand these complex technologies and collaborate with their peers in other states to refine definitions and bill provisions, ensuring that appropriate privacy protections are in place. Many states entered 2025 with strong privacy bills on the table, yet progress slowed as industry counterproposals and competing drafts drew support away from stronger models, making it harder for legislators to keep consumer privacy protections intact. Vermont State Representative Monique Priestley has seen this firsthand and brings a unique lens to this dynamic, drawing on her discussions with the public and her collaborative work with lawmakers across the country. As public concerns about privacy and AI grow and privacy laws evolve, companies will need to be proactive about the steps they take to protect people's data and be clear about how those protections work. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Monique Priestley, Vermont State Representative, about the realities that shape state-level privacy and AI legislation. Monique discusses the behind-the-scenes work required to educate lawmakers and build strong, technology-informed privacy and AI bills, and what might change in the year ahead. She also shares insights into the public's rising concerns about how their data is used, highlighting the steps companies can take to build trust.

Showing 1–20 of 20 episodes