<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/rss+xml" href="https://feeds.transistor.fm/the-web-privacy-podcast" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>The Web Privacy Podcast</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/the-web-privacy-podcast</itunes:new-feed-url>
    <description>Most companies trust their website. They shouldn't. The leaders who know better are rebuilding what it means to govern a website, and every week we sit down with privacy executives, compliance teams, and digital risk pros at the world's largest enterprises. 

We dive into stories with the ones who caught a broken consent tool before the regulator did, traced a six-figure loss back to a failed tracking pixel, and rebuilt their entire data governance approach from scratch. The rules of digital trust are being rewritten right now. This show is where you hear it first. 

Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.

https://www.observepoint.com/</description>
    <copyright>© 2026 ObservePoint</copyright>
    <podcast:guid>6cbc8634-4a2b-54bd-ad7c-096bba4d829f</podcast:guid>
    <podcast:locked>yes</podcast:locked>
    <language>en</language>
    <pubDate>Sat, 19 Sep 2026 04:55:43 -0600</pubDate>
    <lastBuildDate>Sat, 19 Sep 2026 04:56:12 -0600</lastBuildDate>
    <link>https://www.observepoint.com/</link>
    <image>
      <url>https://img.transistorcdn.com/jBiiNg1YNbrNBsaOVaDLWf7aqqPEZFplTj2MdPAm2Uc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81MWZh/MzBiODVkMTA2OTE3/NmVlYWRlZDM1MWE1/MmUwZS5qcGc.jpg</url>
      <title>The Web Privacy Podcast</title>
      <link>https://www.observepoint.com/</link>
    </image>
    <itunes:category text="Business">
      <itunes:category text="Marketing"/>
    </itunes:category>
    <itunes:category text="Business">
      <itunes:category text="Management"/>
    </itunes:category>
    <itunes:type>episodic</itunes:type>
    <itunes:author>ObservePoint</itunes:author>
    <itunes:image href="https://img.transistorcdn.com/jBiiNg1YNbrNBsaOVaDLWf7aqqPEZFplTj2MdPAm2Uc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81MWZh/MzBiODVkMTA2OTE3/NmVlYWRlZDM1MWE1/MmUwZS5qcGc.jpg"/>
    <itunes:summary>Most companies trust their website. They shouldn't. The leaders who know better are rebuilding what it means to govern a website, and every week we sit down with privacy executives, compliance teams, and digital risk pros at the world's largest enterprises. 

We dive into stories with the ones who caught a broken consent tool before the regulator did, traced a six-figure loss back to a failed tracking pixel, and rebuilt their entire data governance approach from scratch. The rules of digital trust are being rewritten right now. This show is where you hear it first. 

Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.

https://www.observepoint.com/</itunes:summary>
    <itunes:subtitle>Most companies trust their website.</itunes:subtitle>
    <itunes:keywords>web privacy,consent management,tag governance,website governance,data privacy,privacy compliance,GDPR,CCPA,cookie consent,tracking pixels,chief privacy officer,digital risk,data governance,privacy regulations</itunes:keywords>
    <itunes:owner>
      <itunes:name>Tanner Green</itunes:name>
      <itunes:email>tanner@executivemedianetwork.com</itunes:email>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <item>
      <title>From compliance to strategy with Fenwick &amp; West</title>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:title>From compliance to strategy with Fenwick &amp; West</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ef8816e0-77a1-4055-88ec-fe669a7d0a77</guid>
      <link>https://share.transistor.fm/s/f7c36945</link>
      <description>
        <![CDATA[<p><strong>Summary</strong><br> What happens to a privacy program after it declares itself ready for GDPR? According to Marcus Morissette, a privacy lawyer at Fenwick &amp; West who was a CIPP before there were slashes, most of them stop evolving. Host Ethan Prete sits down with Marcus to unpack privacy 2.0, where compliance is table stakes and the real job is getting the business to its goals inside the company's risk appetite. Marcus explains why he told his eBay team never to say no and never to say yes, why the enforcement everyone feared turned out to be security's problem, and why the next generation of privacy lawyers has to understand the technology, from hashing versus encryption to the fact that no US law contains the word cookie. He also walks through Maslow's hierarchy of data, the four-layer pyramid he built with Aaron Weller at Concise Consulting, and why a company still worried about the CIA of its data isn't ready for AI governance. Along the way: the CIPA consent banner trap, an AI drone use case that sounds like science fiction, hiring for business acumen over law degrees, and how to make a company regulator-proof. Essential listening for privacy professionals, marketers, and anyone deciding where privacy should sit in the org.<br></p><p><strong>Chapters</strong><br> 00:00 Introduction<br> 02:35 Doing privacy before privacy existed<br> 05:45 Why marketers should own privacy<br> 08:10 How GDPR built programs that stalled<br> 10:45 Privacy 2.0 is business enablement<br> 12:30 The hashing versus encryption test<br> 13:15 No US law regulates cookies<br> 14:30 The CIPA consent banner trap<br> 19:50 Maslow's hierarchy of data<br> 24:15 What AI governance actually means<br> 28:15 Building and funding a privacy team<br> 34:15 Predictions for the next three years<br> 37:30 Making your program regulator-proof<br></p><p><strong>Takeaways</strong></p><p>-Compliance is table stakes, not the finish line. Privacy 2.0 is business enablement: getting the business to its outcome inside the company's chosen risk appetite.</p><p>-Privacy teams are guidance, not decision-makers. Never say no and never say yes; act as a risk Sherpa who presents the upside and downside so the business can decide.</p><p>-The renaissance privacy lawyer has to know the technology. If you can't explain hashing versus encryption or follow the ad tech spaghetti diagram, you can't advise your business through it.</p><p>-No US law regulates cookies by name; they are regulated as a sale because regulators didn't understand the tech, and consent banners deployed where they weren't required have become CIPA litigation bait.</p><p>-Maslow's hierarchy of data runs security, privacy, information governance, then AI governance. A company still worried about the confidentiality, integrity, and availability of its data is not ready for an AI governance conversation.<br></p><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/mmorissette/">https://www.linkedin.com/in/mmorissette/</a><br> Website: <a href="https://www.fenwick.com">https://www.fenwick.com</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Summary</strong><br> What happens to a privacy program after it declares itself ready for GDPR? According to Marcus Morissette, a privacy lawyer at Fenwick &amp; West who was a CIPP before there were slashes, most of them stop evolving. Host Ethan Prete sits down with Marcus to unpack privacy 2.0, where compliance is table stakes and the real job is getting the business to its goals inside the company's risk appetite. Marcus explains why he told his eBay team never to say no and never to say yes, why the enforcement everyone feared turned out to be security's problem, and why the next generation of privacy lawyers has to understand the technology, from hashing versus encryption to the fact that no US law contains the word cookie. He also walks through Maslow's hierarchy of data, the four-layer pyramid he built with Aaron Weller at Concise Consulting, and why a company still worried about the CIA of its data isn't ready for AI governance. Along the way: the CIPA consent banner trap, an AI drone use case that sounds like science fiction, hiring for business acumen over law degrees, and how to make a company regulator-proof. Essential listening for privacy professionals, marketers, and anyone deciding where privacy should sit in the org.<br></p><p><strong>Chapters</strong><br> 00:00 Introduction<br> 02:35 Doing privacy before privacy existed<br> 05:45 Why marketers should own privacy<br> 08:10 How GDPR built programs that stalled<br> 10:45 Privacy 2.0 is business enablement<br> 12:30 The hashing versus encryption test<br> 13:15 No US law regulates cookies<br> 14:30 The CIPA consent banner trap<br> 19:50 Maslow's hierarchy of data<br> 24:15 What AI governance actually means<br> 28:15 Building and funding a privacy team<br> 34:15 Predictions for the next three years<br> 37:30 Making your program regulator-proof<br></p><p><strong>Takeaways</strong></p><p>-Compliance is table stakes, not the finish line. Privacy 2.0 is business enablement: getting the business to its outcome inside the company's chosen risk appetite.</p><p>-Privacy teams are guidance, not decision-makers. Never say no and never say yes; act as a risk Sherpa who presents the upside and downside so the business can decide.</p><p>-The renaissance privacy lawyer has to know the technology. If you can't explain hashing versus encryption or follow the ad tech spaghetti diagram, you can't advise your business through it.</p><p>-No US law regulates cookies by name; they are regulated as a sale because regulators didn't understand the tech, and consent banners deployed where they weren't required have become CIPA litigation bait.</p><p>-Maslow's hierarchy of data runs security, privacy, information governance, then AI governance. A company still worried about the confidentiality, integrity, and availability of its data is not ready for an AI governance conversation.<br></p><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/mmorissette/">https://www.linkedin.com/in/mmorissette/</a><br> Website: <a href="https://www.fenwick.com">https://www.fenwick.com</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 15 Sep 2026 04:30:00 -0600</pubDate>
      <author>ObservePoint</author>
      <enclosure url="https://media.transistor.fm/f7c36945/6e9e9319.mp3" length="105061806" type="audio/mpeg"/>
      <itunes:author>ObservePoint</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ak_iJiaN_BoDGAYPaHBT-vsPO2EvwQzFxUdjXFtgNXQ/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kMTFl/OGI3N2IyNDcxM2I4/MTFhYTA1YjQxMWRl/MzE2OS5wbmc.jpg"/>
      <itunes:duration>2626</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>Summary</strong><br> What happens to a privacy program after it declares itself ready for GDPR? According to Marcus Morissette, a privacy lawyer at Fenwick &amp; West who was a CIPP before there were slashes, most of them stop evolving. Host Ethan Prete sits down with Marcus to unpack privacy 2.0, where compliance is table stakes and the real job is getting the business to its goals inside the company's risk appetite. Marcus explains why he told his eBay team never to say no and never to say yes, why the enforcement everyone feared turned out to be security's problem, and why the next generation of privacy lawyers has to understand the technology, from hashing versus encryption to the fact that no US law contains the word cookie. He also walks through Maslow's hierarchy of data, the four-layer pyramid he built with Aaron Weller at Concise Consulting, and why a company still worried about the CIA of its data isn't ready for AI governance. Along the way: the CIPA consent banner trap, an AI drone use case that sounds like science fiction, hiring for business acumen over law degrees, and how to make a company regulator-proof. Essential listening for privacy professionals, marketers, and anyone deciding where privacy should sit in the org.<br></p><p><strong>Chapters</strong><br> 00:00 Introduction<br> 02:35 Doing privacy before privacy existed<br> 05:45 Why marketers should own privacy<br> 08:10 How GDPR built programs that stalled<br> 10:45 Privacy 2.0 is business enablement<br> 12:30 The hashing versus encryption test<br> 13:15 No US law regulates cookies<br> 14:30 The CIPA consent banner trap<br> 19:50 Maslow's hierarchy of data<br> 24:15 What AI governance actually means<br> 28:15 Building and funding a privacy team<br> 34:15 Predictions for the next three years<br> 37:30 Making your program regulator-proof<br></p><p><strong>Takeaways</strong></p><p>-Compliance is table stakes, not the finish line. Privacy 2.0 is business enablement: getting the business to its outcome inside the company's chosen risk appetite.</p><p>-Privacy teams are guidance, not decision-makers. Never say no and never say yes; act as a risk Sherpa who presents the upside and downside so the business can decide.</p><p>-The renaissance privacy lawyer has to know the technology. If you can't explain hashing versus encryption or follow the ad tech spaghetti diagram, you can't advise your business through it.</p><p>-No US law regulates cookies by name; they are regulated as a sale because regulators didn't understand the tech, and consent banners deployed where they weren't required have become CIPA litigation bait.</p><p>-Maslow's hierarchy of data runs security, privacy, information governance, then AI governance. A company still worried about the confidentiality, integrity, and availability of its data is not ready for an AI governance conversation.<br></p><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/mmorissette/">https://www.linkedin.com/in/mmorissette/</a><br> Website: <a href="https://www.fenwick.com">https://www.fenwick.com</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </itunes:summary>
      <itunes:keywords>web privacy,privacy compliance,privacy program maturity,gdpr readiness,ccpa compliance,cookie consent banner,cipa lawsuits,privacy lawyer,privacy by design,risk based privacy,business enablement,information governance,AI governance,data governance framework,privacy tech,martech compliance,privacy strategy,state privacy laws,dsar automation,privacy leadership</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/f7c36945/transcript.txt" type="text/plain"/>
    </item>
    <item>
      <title>Privacy Is a Team Sport: Pari Sarnot, Privacy, Risk &amp; Governance Leader</title>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:title>Privacy Is a Team Sport: Pari Sarnot, Privacy, Risk &amp; Governance Leader</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bea33efa-8c35-4470-8d8c-f8b480eb59b2</guid>
      <link>https://share.transistor.fm/s/44627d03</link>
      <description>
        <![CDATA[<p><strong>Summary</strong><br>What do you do when privacy rights create a challenge your existing process was never designed to handle? Host Ethan Prete sits down with Pari Sarnot, a Privacy, Risk &amp; Governance Leader with experience across organizations including Meta, Grant Thornton, eBay, and Microsoft, as well as an IAPP instructor and mentor. Pari shares an example from her broader professional experience involving a growing volume of GDPR access requests for customer service call recordings, and the privacy, operational, employee, and governance considerations that followed. She walks through how a cross-functional team evaluated multiple options and ultimately aligned the retention period more closely with the underlying business needs. Pari also discusses her approach to structured decision-making, why privacy is a team sport, the importance of cross-functional relationships, using metrics to anticipate operational challenges, and considerations around AI transparency and governance.<br></p><p><strong>Chapters</strong></p><p>00:00 Introduction</p><p>02:15 A pragmatic, risk based approach to privacy</p><p>04:30 Falling into privacy at Microsoft</p><p>06:15 Navigating call recording access requests</p><p>09:45 Responding to growing request volumes</p><p>12:30 Five options on the table</p><p>14:45 Rethinking the retention period</p><p>17:15 Privacy is a team sport</p><p>22:15 Metrics that spot the crisis early</p><p>29:00 AI transparency and model drift</p><p>31:45 Outcomes and final advice<br></p><p><strong>Takeaways</strong></p><p>-Retaining data without a continuing business need can introduce additional privacy, security, operational, and governance risk; aligning retention with legitimate business needs can help reduce that burden.</p><p>-When navigating a complex privacy issue, start by understanding the underlying business objective, then evaluate potential approaches against factors such as risk, applicable requirements, resources, operational impact, and customer expectations.</p><p>-Privacy is a team sport, and strong cross-functional relationships require continuous investment, not only engagement when an issue arises.</p><p>-Track privacy metrics and request-volume trends to identify emerging capacity and operational challenges early.</p><p>-Document key decisions, including the options considered, associated risks, rationale, and relevant sign-offs, so the reasoning remains clear over time.</p><p><br></p><p><strong>Connect with the Guest</strong><br>LinkedIn: <a href="https://www.linkedin.com/in/pari-sarnot/">https://www.linkedin.com/in/pari-sarnot/</a></p><p><br><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Summary</strong><br>What do you do when privacy rights create a challenge your existing process was never designed to handle? Host Ethan Prete sits down with Pari Sarnot, a Privacy, Risk &amp; Governance Leader with experience across organizations including Meta, Grant Thornton, eBay, and Microsoft, as well as an IAPP instructor and mentor. Pari shares an example from her broader professional experience involving a growing volume of GDPR access requests for customer service call recordings, and the privacy, operational, employee, and governance considerations that followed. She walks through how a cross-functional team evaluated multiple options and ultimately aligned the retention period more closely with the underlying business needs. Pari also discusses her approach to structured decision-making, why privacy is a team sport, the importance of cross-functional relationships, using metrics to anticipate operational challenges, and considerations around AI transparency and governance.<br></p><p><strong>Chapters</strong></p><p>00:00 Introduction</p><p>02:15 A pragmatic, risk based approach to privacy</p><p>04:30 Falling into privacy at Microsoft</p><p>06:15 Navigating call recording access requests</p><p>09:45 Responding to growing request volumes</p><p>12:30 Five options on the table</p><p>14:45 Rethinking the retention period</p><p>17:15 Privacy is a team sport</p><p>22:15 Metrics that spot the crisis early</p><p>29:00 AI transparency and model drift</p><p>31:45 Outcomes and final advice<br></p><p><strong>Takeaways</strong></p><p>-Retaining data without a continuing business need can introduce additional privacy, security, operational, and governance risk; aligning retention with legitimate business needs can help reduce that burden.</p><p>-When navigating a complex privacy issue, start by understanding the underlying business objective, then evaluate potential approaches against factors such as risk, applicable requirements, resources, operational impact, and customer expectations.</p><p>-Privacy is a team sport, and strong cross-functional relationships require continuous investment, not only engagement when an issue arises.</p><p>-Track privacy metrics and request-volume trends to identify emerging capacity and operational challenges early.</p><p>-Document key decisions, including the options considered, associated risks, rationale, and relevant sign-offs, so the reasoning remains clear over time.</p><p><br></p><p><strong>Connect with the Guest</strong><br>LinkedIn: <a href="https://www.linkedin.com/in/pari-sarnot/">https://www.linkedin.com/in/pari-sarnot/</a></p><p><br><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 08 Sep 2026 05:37:00 -0600</pubDate>
      <author>ObservePoint</author>
      <enclosure url="https://media.transistor.fm/44627d03/425ce4cf.mp3" length="81319092" type="audio/mpeg"/>
      <itunes:author>ObservePoint</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/I4T1ye71bum4bv4cHeOnRE7kelnn6JCpSOLuARujuKA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81MDQ3/YmU4OWZkZWIwM2U5/NGVlNmNjOTdjOTY1/OWZlNC5wbmc.jpg"/>
      <itunes:duration>2032</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>Summary</strong><br>What do you do when privacy rights create a challenge your existing process was never designed to handle? Host Ethan Prete sits down with Pari Sarnot, a Privacy, Risk &amp; Governance Leader with experience across organizations including Meta, Grant Thornton, eBay, and Microsoft, as well as an IAPP instructor and mentor. Pari shares an example from her broader professional experience involving a growing volume of GDPR access requests for customer service call recordings, and the privacy, operational, employee, and governance considerations that followed. She walks through how a cross-functional team evaluated multiple options and ultimately aligned the retention period more closely with the underlying business needs. Pari also discusses her approach to structured decision-making, why privacy is a team sport, the importance of cross-functional relationships, using metrics to anticipate operational challenges, and considerations around AI transparency and governance.<br></p><p><strong>Chapters</strong></p><p>00:00 Introduction</p><p>02:15 A pragmatic, risk based approach to privacy</p><p>04:30 Falling into privacy at Microsoft</p><p>06:15 Navigating call recording access requests</p><p>09:45 Responding to growing request volumes</p><p>12:30 Five options on the table</p><p>14:45 Rethinking the retention period</p><p>17:15 Privacy is a team sport</p><p>22:15 Metrics that spot the crisis early</p><p>29:00 AI transparency and model drift</p><p>31:45 Outcomes and final advice<br></p><p><strong>Takeaways</strong></p><p>-Retaining data without a continuing business need can introduce additional privacy, security, operational, and governance risk; aligning retention with legitimate business needs can help reduce that burden.</p><p>-When navigating a complex privacy issue, start by understanding the underlying business objective, then evaluate potential approaches against factors such as risk, applicable requirements, resources, operational impact, and customer expectations.</p><p>-Privacy is a team sport, and strong cross-functional relationships require continuous investment, not only engagement when an issue arises.</p><p>-Track privacy metrics and request-volume trends to identify emerging capacity and operational challenges early.</p><p>-Document key decisions, including the options considered, associated risks, rationale, and relevant sign-offs, so the reasoning remains clear over time.</p><p><br></p><p><strong>Connect with the Guest</strong><br>LinkedIn: <a href="https://www.linkedin.com/in/pari-sarnot/">https://www.linkedin.com/in/pari-sarnot/</a></p><p><br><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </itunes:summary>
      <itunes:keywords>gdpr subject access request,dsar response,right of access,call recording privacy,data retention policy,data minimization,privacy risk management,privacy governance,cross functional collaboration,privacy metrics,kpis and kris,ccpa compliance,cpra,german works council,employee data privacy,web privacy,consent management,tag governance,AI governance,privacy program management</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/44627d03/transcript.txt" type="text/plain"/>
    </item>
    <item>
      <title>Customer Relationships That Last Decades: Will Clayton at Marriott Vacations</title>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:title>Customer Relationships That Last Decades: Will Clayton at Marriott Vacations</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f80368e5-7564-4d70-a60e-bd47a4744e91</guid>
      <link>https://share.transistor.fm/s/fb066025</link>
      <description>
        <![CDATA[<p><strong>Summary</strong><br> What does it take to run privacy for a brand where the customer relationship lasts decades? Host Ethan Prete sits down with Will Clayton, Data Privacy Director at Marriott Vacations Worldwide, whose privacy career stretches back to 2000 and the early days of ad tech. Will explains why day one of a new privacy law actually starts at day minus 200, what happens to consent architecture when a customer moves from an opt-out jurisdiction to an opt-in one, and why the smartest compliance strategy is a single ethical policy that satisfies every jurisdiction at once. Along the way: who belongs in the privacy war room, who should own the consent and preference center, the real cost of negative marketing events like bounces and complaints, CIPA demand letters, AI governance, and how to spot privacy laws being weaponized. Essential listening for privacy professionals, marketers, and anyone building the infrastructure that sits between the two.<br></p><p><strong>Chapters</strong></p><p>00:00 Introduction</p><p>02:45 From ad tech to privacy, a 26 year career</p><p>04:30 The line between caring and creepy</p><p>06:45 When customers move, preferences explode</p><p>09:00 Day one starts at day minus 200</p><p>11:00 Who sits in the privacy war room</p><p>13:45 One policy for every jurisdiction</p><p>20:45 Who owns the consent and preference center</p><p>23:00 Measuring the cost of negative events</p><p>28:45 AI governance and final predictions<br></p><p><strong>Takeaways</strong></p><p>-Day one of a new privacy law is a monitoring exercise, not a scramble: the program should be written, implemented, and tested 200 days before the effective date.</p><p>-When a customer moves from an opt-out jurisdiction to an opt-in one, a binary consent switch becomes a matrix of flags, so preference architecture must be designed for people who move.</p><p>-The strongest compliance strategy is finding the commonality: one ethical policy that satisfies every jurisdiction and extends rights even where no statute requires them.</p><p>-Privacy earns executive buy-in by accurately describing consequences, because a lack of respect for consumer privacy is an existential threat to the mission, not just a compliance gap.</p><p>-Marketers should measure negative events, including bounces, complaints, and opt-outs, with the same rigor as conversions, because creepy marketing is bad marketing.<br></p><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/willclayton/">https://www.linkedin.com/in/willclayton/</a><br> Website: <a href="https://www.marriottvacationsworldwide.com">https://www.marriottvacationsworldwide.com</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Summary</strong><br> What does it take to run privacy for a brand where the customer relationship lasts decades? Host Ethan Prete sits down with Will Clayton, Data Privacy Director at Marriott Vacations Worldwide, whose privacy career stretches back to 2000 and the early days of ad tech. Will explains why day one of a new privacy law actually starts at day minus 200, what happens to consent architecture when a customer moves from an opt-out jurisdiction to an opt-in one, and why the smartest compliance strategy is a single ethical policy that satisfies every jurisdiction at once. Along the way: who belongs in the privacy war room, who should own the consent and preference center, the real cost of negative marketing events like bounces and complaints, CIPA demand letters, AI governance, and how to spot privacy laws being weaponized. Essential listening for privacy professionals, marketers, and anyone building the infrastructure that sits between the two.<br></p><p><strong>Chapters</strong></p><p>00:00 Introduction</p><p>02:45 From ad tech to privacy, a 26 year career</p><p>04:30 The line between caring and creepy</p><p>06:45 When customers move, preferences explode</p><p>09:00 Day one starts at day minus 200</p><p>11:00 Who sits in the privacy war room</p><p>13:45 One policy for every jurisdiction</p><p>20:45 Who owns the consent and preference center</p><p>23:00 Measuring the cost of negative events</p><p>28:45 AI governance and final predictions<br></p><p><strong>Takeaways</strong></p><p>-Day one of a new privacy law is a monitoring exercise, not a scramble: the program should be written, implemented, and tested 200 days before the effective date.</p><p>-When a customer moves from an opt-out jurisdiction to an opt-in one, a binary consent switch becomes a matrix of flags, so preference architecture must be designed for people who move.</p><p>-The strongest compliance strategy is finding the commonality: one ethical policy that satisfies every jurisdiction and extends rights even where no statute requires them.</p><p>-Privacy earns executive buy-in by accurately describing consequences, because a lack of respect for consumer privacy is an existential threat to the mission, not just a compliance gap.</p><p>-Marketers should measure negative events, including bounces, complaints, and opt-outs, with the same rigor as conversions, because creepy marketing is bad marketing.<br></p><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/willclayton/">https://www.linkedin.com/in/willclayton/</a><br> Website: <a href="https://www.marriottvacationsworldwide.com">https://www.marriottvacationsworldwide.com</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 01 Sep 2026 04:38:00 -0600</pubDate>
      <author>ObservePoint</author>
      <enclosure url="https://media.transistor.fm/fb066025/11565988.mp3" length="32512585" type="audio/mpeg"/>
      <itunes:author>ObservePoint</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/tPZbqe78KYRVCQe5CXbgcPPmUAwshKS7hq5l6GkAnOs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iNzcz/ZWQ1YWI0MDk1MmY1/MTgzNmFkOTZkZjU2/ODAwMC5wbmc.jpg"/>
      <itunes:duration>2030</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>Summary</strong><br> What does it take to run privacy for a brand where the customer relationship lasts decades? Host Ethan Prete sits down with Will Clayton, Data Privacy Director at Marriott Vacations Worldwide, whose privacy career stretches back to 2000 and the early days of ad tech. Will explains why day one of a new privacy law actually starts at day minus 200, what happens to consent architecture when a customer moves from an opt-out jurisdiction to an opt-in one, and why the smartest compliance strategy is a single ethical policy that satisfies every jurisdiction at once. Along the way: who belongs in the privacy war room, who should own the consent and preference center, the real cost of negative marketing events like bounces and complaints, CIPA demand letters, AI governance, and how to spot privacy laws being weaponized. Essential listening for privacy professionals, marketers, and anyone building the infrastructure that sits between the two.<br></p><p><strong>Chapters</strong></p><p>00:00 Introduction</p><p>02:45 From ad tech to privacy, a 26 year career</p><p>04:30 The line between caring and creepy</p><p>06:45 When customers move, preferences explode</p><p>09:00 Day one starts at day minus 200</p><p>11:00 Who sits in the privacy war room</p><p>13:45 One policy for every jurisdiction</p><p>20:45 Who owns the consent and preference center</p><p>23:00 Measuring the cost of negative events</p><p>28:45 AI governance and final predictions<br></p><p><strong>Takeaways</strong></p><p>-Day one of a new privacy law is a monitoring exercise, not a scramble: the program should be written, implemented, and tested 200 days before the effective date.</p><p>-When a customer moves from an opt-out jurisdiction to an opt-in one, a binary consent switch becomes a matrix of flags, so preference architecture must be designed for people who move.</p><p>-The strongest compliance strategy is finding the commonality: one ethical policy that satisfies every jurisdiction and extends rights even where no statute requires them.</p><p>-Privacy earns executive buy-in by accurately describing consequences, because a lack of respect for consumer privacy is an existential threat to the mission, not just a compliance gap.</p><p>-Marketers should measure negative events, including bounces, complaints, and opt-outs, with the same rigor as conversions, because creepy marketing is bad marketing.<br></p><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/willclayton/">https://www.linkedin.com/in/willclayton/</a><br> Website: <a href="https://www.marriottvacationsworldwide.com">https://www.marriottvacationsworldwide.com</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </itunes:summary>
      <itunes:keywords>web privacy,privacy compliance,state privacy laws,ccpa compliance,gdpr compliance,consent management,preference center,data privacy strategy,privacy operations,ethical marketing,dsar workflow,privacy program management,data subject requests,cipa demand letters,privacy governance,AI governance,marketing compliance,opt in vs opt out,privacy architecture,consumer trust</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/fb066025/transcript.txt" type="text/plain"/>
    </item>
    <item>
      <title>Privacy Checks Are Trust Builders, Not Roadblocks with Uche Orji</title>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:title>Privacy Checks Are Trust Builders, Not Roadblocks with Uche Orji</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2c4a2d59-8c96-4553-8a8c-0ce9d81d0159</guid>
      <link>https://share.transistor.fm/s/0c826b32</link>
      <description>
        <![CDATA[<p><strong>Summary</strong><br> What can a single pre-checked checkbox teach an entire company about consent? In this episode of The Web Privacy Podcast, host Ethan Prete talks with Uche Orji, Lawyer and Compliance officer, about the marketing signup form she flagged during an internal audit, and why "customers can always unsubscribe" is the mindset that leads to GDPR fines. Uche explains what the law actually requires of consent, how she replaced a lucky catch with a routine privacy workflow, why privacy checks are trust builders rather than roadblocks, and how legal teams can operationalize the law with process documents, education, and internal audits. The conversation closes with her advice to CMOs: focus on quality leads, because only a consenting customer converts. For privacy professionals, marketers, and anyone who owns a web form.<br></p><p><strong>Chapters</strong></p><p>00:45 Introduction</p><p>01:58 How Uche got into privacy</p><p>04:02 Where privacy should sit in the organization</p><p>05:31 A checkbox that took consent</p><p>07:14 The fix: double opt in and a paper trail</p><p>09:37 Finding the problem before the fine</p><p>11:42 Trust builders, not roadblocks</p><p>14:42 Think like an internal auditor</p><p>17:44 Cookies, resource downloads, and DSARs</p><p>20:49 No universal consent framework</p><p>23:15 Quality leads over lead volume<br></p><p><strong>Takeaways</strong></p><p>Consent must be unambiguous, unbundled, and actively given: a pre-checked box means the company took consent the customer never gave</p><p>Privacy checks are trust builders, not roadblocks: every check passed is a signal to customers that their data is safe</p><p>Operationalize the law: replace institutional knowledge with step-by-step process documents sent to every stakeholder</p><p>Think like an internal auditor: schedule walkthroughs of each department's processes and make teams show you, not tell you</p><p>Focus on quality leads over lead volume: only a consenting subscriber converts into a paying customer<br></p><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/orjiuchechukwu/">https://www.linkedin.com/in/orjiuchechukwu/</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Summary</strong><br> What can a single pre-checked checkbox teach an entire company about consent? In this episode of The Web Privacy Podcast, host Ethan Prete talks with Uche Orji, Lawyer and Compliance officer, about the marketing signup form she flagged during an internal audit, and why "customers can always unsubscribe" is the mindset that leads to GDPR fines. Uche explains what the law actually requires of consent, how she replaced a lucky catch with a routine privacy workflow, why privacy checks are trust builders rather than roadblocks, and how legal teams can operationalize the law with process documents, education, and internal audits. The conversation closes with her advice to CMOs: focus on quality leads, because only a consenting customer converts. For privacy professionals, marketers, and anyone who owns a web form.<br></p><p><strong>Chapters</strong></p><p>00:45 Introduction</p><p>01:58 How Uche got into privacy</p><p>04:02 Where privacy should sit in the organization</p><p>05:31 A checkbox that took consent</p><p>07:14 The fix: double opt in and a paper trail</p><p>09:37 Finding the problem before the fine</p><p>11:42 Trust builders, not roadblocks</p><p>14:42 Think like an internal auditor</p><p>17:44 Cookies, resource downloads, and DSARs</p><p>20:49 No universal consent framework</p><p>23:15 Quality leads over lead volume<br></p><p><strong>Takeaways</strong></p><p>Consent must be unambiguous, unbundled, and actively given: a pre-checked box means the company took consent the customer never gave</p><p>Privacy checks are trust builders, not roadblocks: every check passed is a signal to customers that their data is safe</p><p>Operationalize the law: replace institutional knowledge with step-by-step process documents sent to every stakeholder</p><p>Think like an internal auditor: schedule walkthroughs of each department's processes and make teams show you, not tell you</p><p>Focus on quality leads over lead volume: only a consenting subscriber converts into a paying customer<br></p><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/orjiuchechukwu/">https://www.linkedin.com/in/orjiuchechukwu/</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 25 Aug 2026 04:39:00 -0600</pubDate>
      <author>ObservePoint</author>
      <enclosure url="https://media.transistor.fm/0c826b32/487c7782.mp3" length="25395695" type="audio/mpeg"/>
      <itunes:author>ObservePoint</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/F3QoCECBughVTVKLB_U22jmieWq6MOxOYxRltWdfMtA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82Zjg3/MTNkMTVhYjMxYmNm/MjEyMjNhNGQyZDY1/ZDE0NC5wbmc.jpg"/>
      <itunes:duration>1585</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>Summary</strong><br> What can a single pre-checked checkbox teach an entire company about consent? In this episode of The Web Privacy Podcast, host Ethan Prete talks with Uche Orji, Lawyer and Compliance officer, about the marketing signup form she flagged during an internal audit, and why "customers can always unsubscribe" is the mindset that leads to GDPR fines. Uche explains what the law actually requires of consent, how she replaced a lucky catch with a routine privacy workflow, why privacy checks are trust builders rather than roadblocks, and how legal teams can operationalize the law with process documents, education, and internal audits. The conversation closes with her advice to CMOs: focus on quality leads, because only a consenting customer converts. For privacy professionals, marketers, and anyone who owns a web form.<br></p><p><strong>Chapters</strong></p><p>00:45 Introduction</p><p>01:58 How Uche got into privacy</p><p>04:02 Where privacy should sit in the organization</p><p>05:31 A checkbox that took consent</p><p>07:14 The fix: double opt in and a paper trail</p><p>09:37 Finding the problem before the fine</p><p>11:42 Trust builders, not roadblocks</p><p>14:42 Think like an internal auditor</p><p>17:44 Cookies, resource downloads, and DSARs</p><p>20:49 No universal consent framework</p><p>23:15 Quality leads over lead volume<br></p><p><strong>Takeaways</strong></p><p>Consent must be unambiguous, unbundled, and actively given: a pre-checked box means the company took consent the customer never gave</p><p>Privacy checks are trust builders, not roadblocks: every check passed is a signal to customers that their data is safe</p><p>Operationalize the law: replace institutional knowledge with step-by-step process documents sent to every stakeholder</p><p>Think like an internal auditor: schedule walkthroughs of each department's processes and make teams show you, not tell you</p><p>Focus on quality leads over lead volume: only a consenting subscriber converts into a paying customer<br></p><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/orjiuchechukwu/">https://www.linkedin.com/in/orjiuchechukwu/</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </itunes:summary>
      <itunes:keywords>gdpr consent requirements,marketing compliance,pre checked checkbox,opt in vs opt out,email marketing consent,double opt in,privacy by design,cookie consent banner,dsar requests,privacy compliance audit,ccpa compliance,data protection officer,privacy in marketing,consent management,lead generation compliance,web privacy podcast,quality leads,privacy regulations,gdpr fines,data privacy audit</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/0c826b32/transcript.txt" type="text/plain"/>
    </item>
    <item>
      <title>Why Privacy Lawyers Are Becoming AI Lawyers: Mark Sanders at Tekion</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>Why Privacy Lawyers Are Becoming AI Lawyers: Mark Sanders at Tekion</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">40b79cb3-6e02-4dc3-9a2d-c3e25d35ca57</guid>
      <link>https://share.transistor.fm/s/d8ef3655</link>
      <description>
        <![CDATA[<p><strong>Summary</strong><br>What happens to privacy lawyers when AI takes over the spotlight? In this episode of The Web Privacy Podcast, host Ethan Prete sits down with Mark Sanders, Sr Product AI &amp; Data Privacy Counsel at Tekion, an AI native platform for car dealerships, and a 30 year veteran of in-house roles at Adobe, eBay, and Airbnb. Mark explains why the lawyers who mastered America's fragmented privacy patchwork are the best prepared to navigate AI regulation, what it looks like to work as embedded product counsel reviewing Figmas and data flows alongside engineers, and the three lens framework he uses to review every consumer facing AI agent: AI regulation, privacy, and channel specific consumer laws like TCPA and CAN-SPAM. This conversation is for privacy professionals, in-house counsel, and the analytics and marketing teams who work beside them.<br></p><p><strong>Chapters</strong></p><p>00:45 Meet Mark Sanders</p><p>01:45 From digital signatures to data privacy</p><p>04:45 The shift from privacy law to AI law</p><p>06:30 Inside Tekion and the DMS space</p><p>09:00 The end of review and approve legal</p><p>13:00 Bridging the lawyer engineer language gap</p><p>18:05 Privacy through a B2B lens</p><p>20:00 The FTC and the California CARS Act</p><p>22:55 AI agents as the new privacy frontier</p><p>27:05 What keeps Mark up at night<br></p><p><strong>Takeaways</strong></p><p>-Embedded product counsel reviews designs and data flows before anything ships, which is cheaper and faster than the review and approve model where legal is always running behind.</p><p>-Privacy lawyers who learned to navigate the fragmented US state patchwork are the best positioned professionals to handle AI regulation, which is developing the same way.</p><p>-AI and privacy are concentric circles with a constantly moving overlap: you cannot have AI without data, and personal data in AI always raises privacy questions.</p><p>-Every consumer facing AI agent needs a three lens review covering AI regulation, privacy, and channel laws like TCPA and CAN-SPAM that apply regardless of the technology.</p><p>-AI is only as good as the data it can reach, which makes database access for AI tools the most practical privacy risk companies face right now.<br></p><p><strong>Connect with the Guest</strong><br>LinkedIn: <a href="https://www.linkedin.com/in/msanderslaw/">https://www.linkedin.com/in/msanderslaw/</a><br>Website: <a href="https://tekion.com">https://tekion.com</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Summary</strong><br>What happens to privacy lawyers when AI takes over the spotlight? In this episode of The Web Privacy Podcast, host Ethan Prete sits down with Mark Sanders, Sr Product AI &amp; Data Privacy Counsel at Tekion, an AI native platform for car dealerships, and a 30 year veteran of in-house roles at Adobe, eBay, and Airbnb. Mark explains why the lawyers who mastered America's fragmented privacy patchwork are the best prepared to navigate AI regulation, what it looks like to work as embedded product counsel reviewing Figmas and data flows alongside engineers, and the three lens framework he uses to review every consumer facing AI agent: AI regulation, privacy, and channel specific consumer laws like TCPA and CAN-SPAM. This conversation is for privacy professionals, in-house counsel, and the analytics and marketing teams who work beside them.<br></p><p><strong>Chapters</strong></p><p>00:45 Meet Mark Sanders</p><p>01:45 From digital signatures to data privacy</p><p>04:45 The shift from privacy law to AI law</p><p>06:30 Inside Tekion and the DMS space</p><p>09:00 The end of review and approve legal</p><p>13:00 Bridging the lawyer engineer language gap</p><p>18:05 Privacy through a B2B lens</p><p>20:00 The FTC and the California CARS Act</p><p>22:55 AI agents as the new privacy frontier</p><p>27:05 What keeps Mark up at night<br></p><p><strong>Takeaways</strong></p><p>-Embedded product counsel reviews designs and data flows before anything ships, which is cheaper and faster than the review and approve model where legal is always running behind.</p><p>-Privacy lawyers who learned to navigate the fragmented US state patchwork are the best positioned professionals to handle AI regulation, which is developing the same way.</p><p>-AI and privacy are concentric circles with a constantly moving overlap: you cannot have AI without data, and personal data in AI always raises privacy questions.</p><p>-Every consumer facing AI agent needs a three lens review covering AI regulation, privacy, and channel laws like TCPA and CAN-SPAM that apply regardless of the technology.</p><p>-AI is only as good as the data it can reach, which makes database access for AI tools the most practical privacy risk companies face right now.<br></p><p><strong>Connect with the Guest</strong><br>LinkedIn: <a href="https://www.linkedin.com/in/msanderslaw/">https://www.linkedin.com/in/msanderslaw/</a><br>Website: <a href="https://tekion.com">https://tekion.com</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 18 Aug 2026 05:18:00 -0600</pubDate>
      <author>ObservePoint</author>
      <enclosure url="https://media.transistor.fm/d8ef3655/215f6bbb.mp3" length="30114791" type="audio/mpeg"/>
      <itunes:author>ObservePoint</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/0KnPBVaL58LHmIbBg-RDkTWEk4ZZoPTbI0yLSofviNc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84MTVh/ZmEzYTQ5ZWQ5N2I3/NzMzMWE5ZGQwZWYw/ZGM1Yy5wbmc.jpg"/>
      <itunes:duration>1880</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>Summary</strong><br>What happens to privacy lawyers when AI takes over the spotlight? In this episode of The Web Privacy Podcast, host Ethan Prete sits down with Mark Sanders, Sr Product AI &amp; Data Privacy Counsel at Tekion, an AI native platform for car dealerships, and a 30 year veteran of in-house roles at Adobe, eBay, and Airbnb. Mark explains why the lawyers who mastered America's fragmented privacy patchwork are the best prepared to navigate AI regulation, what it looks like to work as embedded product counsel reviewing Figmas and data flows alongside engineers, and the three lens framework he uses to review every consumer facing AI agent: AI regulation, privacy, and channel specific consumer laws like TCPA and CAN-SPAM. This conversation is for privacy professionals, in-house counsel, and the analytics and marketing teams who work beside them.<br></p><p><strong>Chapters</strong></p><p>00:45 Meet Mark Sanders</p><p>01:45 From digital signatures to data privacy</p><p>04:45 The shift from privacy law to AI law</p><p>06:30 Inside Tekion and the DMS space</p><p>09:00 The end of review and approve legal</p><p>13:00 Bridging the lawyer engineer language gap</p><p>18:05 Privacy through a B2B lens</p><p>20:00 The FTC and the California CARS Act</p><p>22:55 AI agents as the new privacy frontier</p><p>27:05 What keeps Mark up at night<br></p><p><strong>Takeaways</strong></p><p>-Embedded product counsel reviews designs and data flows before anything ships, which is cheaper and faster than the review and approve model where legal is always running behind.</p><p>-Privacy lawyers who learned to navigate the fragmented US state patchwork are the best positioned professionals to handle AI regulation, which is developing the same way.</p><p>-AI and privacy are concentric circles with a constantly moving overlap: you cannot have AI without data, and personal data in AI always raises privacy questions.</p><p>-Every consumer facing AI agent needs a three lens review covering AI regulation, privacy, and channel laws like TCPA and CAN-SPAM that apply regardless of the technology.</p><p>-AI is only as good as the data it can reach, which makes database access for AI tools the most practical privacy risk companies face right now.<br></p><p><strong>Connect with the Guest</strong><br>LinkedIn: <a href="https://www.linkedin.com/in/msanderslaw/">https://www.linkedin.com/in/msanderslaw/</a><br>Website: <a href="https://tekion.com">https://tekion.com</a></p><p><strong>Sponsor</strong><br>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </itunes:summary>
      <itunes:keywords>ai privacy law,privacy lawyer,ai governance,product counsel,ai compliance,data privacy,ai regulation,privacy counsel,ai agents,agent compliance,web privacy,tcpa,can-spam,ccpa,gdpr,embedded legal counsel,ai native platform,dealer management software,consumer data protection,legal tech</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/d8ef3655/transcript.txt" type="text/plain"/>
    </item>
    <item>
      <title>The M&amp;A Playbook from the Chief Privacy Officer at Synopsys Inc, Erin McCurdy</title>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>The M&amp;A Playbook from the Chief Privacy Officer at Synopsys Inc, Erin McCurdy</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0d11815e-e441-4839-9c1d-468cd92454b5</guid>
      <link>https://share.transistor.fm/s/1e79e30c</link>
      <description>
        <![CDATA[<p><strong>Summary</strong><br> What does it take to share personal data during a merger or acquisition without creating regulatory liability before the deal even closes? Host Ethan Prete sits down with Erin McCurdy, Chief Privacy Officer and Data Protection Officer at Synopsys, who has managed privacy through three to five acquisitions a year at Ansys and then lived the sell side of the $32 billion Synopsys acquisition of Ansys. Erin breaks down the three non negotiables that must be in place before a single row of personal data moves, why aggregated data satisfies most buyer requests at the NDA stage, the difference between due diligence and integration after signing, and why a Legitimate Interest Assessment is the lawful basis that gets you to Day One. A must listen for privacy professionals, in house counsel, and anyone whose company might one day be on either side of a deal sheet.<br></p><p><strong>Chapters</strong><br> 00:00 Introduction<br> 02:15 Erin's path to chief privacy officer<br> 05:30 Inside the Synopsys privacy team<br> 08:45 Why a privacy notice is not a blanket pass<br> 09:45 The three non negotiables before sharing data<br> 12:45 Personal data under the NDA<br> 14:45 The power of aggregated data<br> 19:00 Diligence versus integration after signing<br> 21:30 Day one readiness and the legitimate interest assessment<br> 24:45 Web privacy audits and marketing consent<br> 37:00 Preparing before the deal sheet hits<br> 41:15 Know where your data is<br></p><p><strong>Takeaways</strong></p><ul><li>Never share personal data at any deal stage without an executed data protection agreement in place</li><li>Keep due diligence and integration strictly separate, a signed agreement is not an all access pass</li><li>Default to aggregated or de identified data early, most buyer requests can be satisfied without individual records</li><li>Back every pre closing transfer with a documented legitimate interest assessment and a signed deletion clause in case the deal does not close</li><li>Know where your data is before the deal sheet arrives, data mapping and records of processing are the foundation of a defensible sale<p><br></p></li></ul><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/erin-e-mccurdy-11040017/">https://www.linkedin.com/in/erin-e-mccurdy-11040017/</a><br> Website: <a href="https://www.synopsys.com">https://www.synopsys.com</a></p><p><br><strong>Sponsor<br></strong>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Summary</strong><br> What does it take to share personal data during a merger or acquisition without creating regulatory liability before the deal even closes? Host Ethan Prete sits down with Erin McCurdy, Chief Privacy Officer and Data Protection Officer at Synopsys, who has managed privacy through three to five acquisitions a year at Ansys and then lived the sell side of the $32 billion Synopsys acquisition of Ansys. Erin breaks down the three non negotiables that must be in place before a single row of personal data moves, why aggregated data satisfies most buyer requests at the NDA stage, the difference between due diligence and integration after signing, and why a Legitimate Interest Assessment is the lawful basis that gets you to Day One. A must listen for privacy professionals, in house counsel, and anyone whose company might one day be on either side of a deal sheet.<br></p><p><strong>Chapters</strong><br> 00:00 Introduction<br> 02:15 Erin's path to chief privacy officer<br> 05:30 Inside the Synopsys privacy team<br> 08:45 Why a privacy notice is not a blanket pass<br> 09:45 The three non negotiables before sharing data<br> 12:45 Personal data under the NDA<br> 14:45 The power of aggregated data<br> 19:00 Diligence versus integration after signing<br> 21:30 Day one readiness and the legitimate interest assessment<br> 24:45 Web privacy audits and marketing consent<br> 37:00 Preparing before the deal sheet hits<br> 41:15 Know where your data is<br></p><p><strong>Takeaways</strong></p><ul><li>Never share personal data at any deal stage without an executed data protection agreement in place</li><li>Keep due diligence and integration strictly separate, a signed agreement is not an all access pass</li><li>Default to aggregated or de identified data early, most buyer requests can be satisfied without individual records</li><li>Back every pre closing transfer with a documented legitimate interest assessment and a signed deletion clause in case the deal does not close</li><li>Know where your data is before the deal sheet arrives, data mapping and records of processing are the foundation of a defensible sale<p><br></p></li></ul><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/erin-e-mccurdy-11040017/">https://www.linkedin.com/in/erin-e-mccurdy-11040017/</a><br> Website: <a href="https://www.synopsys.com">https://www.synopsys.com</a></p><p><br><strong>Sponsor<br></strong>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 06 Aug 2026 10:35:38 -0600</pubDate>
      <author>ObservePoint</author>
      <enclosure url="https://media.transistor.fm/1e79e30c/8fa45ee0.mp3" length="40805284" type="audio/mpeg"/>
      <itunes:author>ObservePoint</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/iXBXfzKwnOJg6D0PVZlfsEBADBCuOAYs-uots0r65i8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zNTJh/YTE0MmExMjIxMmQ3/MTlkMjk1NjAxNDQ0/YWE2My5wbmc.jpg"/>
      <itunes:duration>2548</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>Summary</strong><br> What does it take to share personal data during a merger or acquisition without creating regulatory liability before the deal even closes? Host Ethan Prete sits down with Erin McCurdy, Chief Privacy Officer and Data Protection Officer at Synopsys, who has managed privacy through three to five acquisitions a year at Ansys and then lived the sell side of the $32 billion Synopsys acquisition of Ansys. Erin breaks down the three non negotiables that must be in place before a single row of personal data moves, why aggregated data satisfies most buyer requests at the NDA stage, the difference between due diligence and integration after signing, and why a Legitimate Interest Assessment is the lawful basis that gets you to Day One. A must listen for privacy professionals, in house counsel, and anyone whose company might one day be on either side of a deal sheet.<br></p><p><strong>Chapters</strong><br> 00:00 Introduction<br> 02:15 Erin's path to chief privacy officer<br> 05:30 Inside the Synopsys privacy team<br> 08:45 Why a privacy notice is not a blanket pass<br> 09:45 The three non negotiables before sharing data<br> 12:45 Personal data under the NDA<br> 14:45 The power of aggregated data<br> 19:00 Diligence versus integration after signing<br> 21:30 Day one readiness and the legitimate interest assessment<br> 24:45 Web privacy audits and marketing consent<br> 37:00 Preparing before the deal sheet hits<br> 41:15 Know where your data is<br></p><p><strong>Takeaways</strong></p><ul><li>Never share personal data at any deal stage without an executed data protection agreement in place</li><li>Keep due diligence and integration strictly separate, a signed agreement is not an all access pass</li><li>Default to aggregated or de identified data early, most buyer requests can be satisfied without individual records</li><li>Back every pre closing transfer with a documented legitimate interest assessment and a signed deletion clause in case the deal does not close</li><li>Know where your data is before the deal sheet arrives, data mapping and records of processing are the foundation of a defensible sale<p><br></p></li></ul><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/erin-e-mccurdy-11040017/">https://www.linkedin.com/in/erin-e-mccurdy-11040017/</a><br> Website: <a href="https://www.synopsys.com">https://www.synopsys.com</a></p><p><br><strong>Sponsor<br></strong>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </itunes:summary>
      <itunes:keywords>m&amp;a data privacy,personal data in mergers and acquisitions,data protection agreement,m&amp;a due diligence,chief privacy officer,privacy in m&amp;a deals,gdpr m&amp;a compliance,legitimate interest assessment,day one readiness,data sharing in acquisitions,privacy due diligence checklist,marketing consent transfer,consent management platform,m&amp;a integration privacy,data mapping,records of processing activities,privacy notice m&amp;a clause,sell side data protection,aggregated data due diligence,web privacy compliance</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/1e79e30c/transcript.txt" type="text/plain"/>
    </item>
  </channel>
</rss>
