<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/rss+xml" href="https://feeds.transistor.fm/the-web-privacy-podcast" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>The Web Privacy Podcast</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/the-web-privacy-podcast</itunes:new-feed-url>
    <description>Most companies trust their website. They shouldn't. The leaders who know better are rebuilding what it means to govern a website, and every week we sit down with privacy executives, compliance teams, and digital risk pros at the world's largest enterprises. 

We dive into stories with the ones who caught a broken consent tool before the regulator did, traced a six-figure loss back to a failed tracking pixel, and rebuilt their entire data governance approach from scratch. The rules of digital trust are being rewritten right now. This show is where you hear it first. 

Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.

https://www.observepoint.com/</description>
    <copyright>© 2026 ObservePoint</copyright>
    <podcast:guid>6cbc8634-4a2b-54bd-ad7c-096bba4d829f</podcast:guid>
    <podcast:locked>yes</podcast:locked>
    <language>en</language>
    <pubDate>Thu, 06 Aug 2026 15:38:11 -0600</pubDate>
    <lastBuildDate>Thu, 06 Aug 2026 15:39:17 -0600</lastBuildDate>
    <link>https://www.observepoint.com/</link>
    <image>
      <url>https://img.transistorcdn.com/jBiiNg1YNbrNBsaOVaDLWf7aqqPEZFplTj2MdPAm2Uc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81MWZh/MzBiODVkMTA2OTE3/NmVlYWRlZDM1MWE1/MmUwZS5qcGc.jpg</url>
      <title>The Web Privacy Podcast</title>
      <link>https://www.observepoint.com/</link>
    </image>
    <itunes:category text="Business">
      <itunes:category text="Marketing"/>
    </itunes:category>
    <itunes:category text="Business">
      <itunes:category text="Management"/>
    </itunes:category>
    <itunes:type>episodic</itunes:type>
    <itunes:author>ObservePoint</itunes:author>
    <itunes:image href="https://img.transistorcdn.com/jBiiNg1YNbrNBsaOVaDLWf7aqqPEZFplTj2MdPAm2Uc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81MWZh/MzBiODVkMTA2OTE3/NmVlYWRlZDM1MWE1/MmUwZS5qcGc.jpg"/>
    <itunes:summary>Most companies trust their website. They shouldn't. The leaders who know better are rebuilding what it means to govern a website, and every week we sit down with privacy executives, compliance teams, and digital risk pros at the world's largest enterprises. 

We dive into stories with the ones who caught a broken consent tool before the regulator did, traced a six-figure loss back to a failed tracking pixel, and rebuilt their entire data governance approach from scratch. The rules of digital trust are being rewritten right now. This show is where you hear it first. 

Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.

https://www.observepoint.com/</itunes:summary>
    <itunes:subtitle>Most companies trust their website.</itunes:subtitle>
    <itunes:keywords>web privacy,consent management,tag governance,website governance,data privacy,privacy compliance,GDPR,CCPA,cookie consent,tracking pixels,chief privacy officer,digital risk,data governance,privacy regulations</itunes:keywords>
    <itunes:owner>
      <itunes:name>Tanner Green</itunes:name>
      <itunes:email>tanner@executivemedianetwork.com</itunes:email>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <item>
      <title>The M&amp;A Playbook from the Chief Privacy Officer at Synopsys Inc, Erin McCurdy</title>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>The M&amp;A Playbook from the Chief Privacy Officer at Synopsys Inc, Erin McCurdy</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0d11815e-e441-4839-9c1d-468cd92454b5</guid>
      <link>https://share.transistor.fm/s/1e79e30c</link>
      <description>
        <![CDATA[<p><strong>Summary</strong><br> What does it take to share personal data during a merger or acquisition without creating regulatory liability before the deal even closes? Host Ethan Prete sits down with Erin McCurdy, Chief Privacy Officer and Data Protection Officer at Synopsys, who has managed privacy through three to five acquisitions a year at Ansys and then lived the sell side of the $32 billion Synopsys acquisition of Ansys. Erin breaks down the three non negotiables that must be in place before a single row of personal data moves, why aggregated data satisfies most buyer requests at the NDA stage, the difference between due diligence and integration after signing, and why a Legitimate Interest Assessment is the lawful basis that gets you to Day One. A must listen for privacy professionals, in house counsel, and anyone whose company might one day be on either side of a deal sheet.<br></p><p><strong>Chapters</strong><br> 00:00 Introduction<br> 02:15 Erin's path to chief privacy officer<br> 05:30 Inside the Synopsys privacy team<br> 08:45 Why a privacy notice is not a blanket pass<br> 09:45 The three non negotiables before sharing data<br> 12:45 Personal data under the NDA<br> 14:45 The power of aggregated data<br> 19:00 Diligence versus integration after signing<br> 21:30 Day one readiness and the legitimate interest assessment<br> 24:45 Web privacy audits and marketing consent<br> 37:00 Preparing before the deal sheet hits<br> 41:15 Know where your data is<br></p><p><strong>Takeaways</strong></p><ul><li>Never share personal data at any deal stage without an executed data protection agreement in place</li><li>Keep due diligence and integration strictly separate, a signed agreement is not an all access pass</li><li>Default to aggregated or de identified data early, most buyer requests can be satisfied without individual records</li><li>Back every pre closing transfer with a documented legitimate interest assessment and a signed deletion clause in case the deal does not close</li><li>Know where your data is before the deal sheet arrives, data mapping and records of processing are the foundation of a defensible sale<p><br></p></li></ul><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/erin-e-mccurdy-11040017/">https://www.linkedin.com/in/erin-e-mccurdy-11040017/</a><br> Website: <a href="https://www.synopsys.com">https://www.synopsys.com</a></p><p><br><strong>Sponsor<br></strong>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Summary</strong><br> What does it take to share personal data during a merger or acquisition without creating regulatory liability before the deal even closes? Host Ethan Prete sits down with Erin McCurdy, Chief Privacy Officer and Data Protection Officer at Synopsys, who has managed privacy through three to five acquisitions a year at Ansys and then lived the sell side of the $32 billion Synopsys acquisition of Ansys. Erin breaks down the three non negotiables that must be in place before a single row of personal data moves, why aggregated data satisfies most buyer requests at the NDA stage, the difference between due diligence and integration after signing, and why a Legitimate Interest Assessment is the lawful basis that gets you to Day One. A must listen for privacy professionals, in house counsel, and anyone whose company might one day be on either side of a deal sheet.<br></p><p><strong>Chapters</strong><br> 00:00 Introduction<br> 02:15 Erin's path to chief privacy officer<br> 05:30 Inside the Synopsys privacy team<br> 08:45 Why a privacy notice is not a blanket pass<br> 09:45 The three non negotiables before sharing data<br> 12:45 Personal data under the NDA<br> 14:45 The power of aggregated data<br> 19:00 Diligence versus integration after signing<br> 21:30 Day one readiness and the legitimate interest assessment<br> 24:45 Web privacy audits and marketing consent<br> 37:00 Preparing before the deal sheet hits<br> 41:15 Know where your data is<br></p><p><strong>Takeaways</strong></p><ul><li>Never share personal data at any deal stage without an executed data protection agreement in place</li><li>Keep due diligence and integration strictly separate, a signed agreement is not an all access pass</li><li>Default to aggregated or de identified data early, most buyer requests can be satisfied without individual records</li><li>Back every pre closing transfer with a documented legitimate interest assessment and a signed deletion clause in case the deal does not close</li><li>Know where your data is before the deal sheet arrives, data mapping and records of processing are the foundation of a defensible sale<p><br></p></li></ul><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/erin-e-mccurdy-11040017/">https://www.linkedin.com/in/erin-e-mccurdy-11040017/</a><br> Website: <a href="https://www.synopsys.com">https://www.synopsys.com</a></p><p><br><strong>Sponsor<br></strong>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 06 Aug 2026 10:35:38 -0600</pubDate>
      <author>ObservePoint</author>
      <enclosure url="https://media.transistor.fm/1e79e30c/8fa45ee0.mp3" length="101949433" type="audio/mpeg"/>
      <itunes:author>ObservePoint</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/iXBXfzKwnOJg6D0PVZlfsEBADBCuOAYs-uots0r65i8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zNTJh/YTE0MmExMjIxMmQ3/MTlkMjk1NjAxNDQ0/YWE2My5wbmc.jpg"/>
      <itunes:duration>2548</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>Summary</strong><br> What does it take to share personal data during a merger or acquisition without creating regulatory liability before the deal even closes? Host Ethan Prete sits down with Erin McCurdy, Chief Privacy Officer and Data Protection Officer at Synopsys, who has managed privacy through three to five acquisitions a year at Ansys and then lived the sell side of the $32 billion Synopsys acquisition of Ansys. Erin breaks down the three non negotiables that must be in place before a single row of personal data moves, why aggregated data satisfies most buyer requests at the NDA stage, the difference between due diligence and integration after signing, and why a Legitimate Interest Assessment is the lawful basis that gets you to Day One. A must listen for privacy professionals, in house counsel, and anyone whose company might one day be on either side of a deal sheet.<br></p><p><strong>Chapters</strong><br> 00:00 Introduction<br> 02:15 Erin's path to chief privacy officer<br> 05:30 Inside the Synopsys privacy team<br> 08:45 Why a privacy notice is not a blanket pass<br> 09:45 The three non negotiables before sharing data<br> 12:45 Personal data under the NDA<br> 14:45 The power of aggregated data<br> 19:00 Diligence versus integration after signing<br> 21:30 Day one readiness and the legitimate interest assessment<br> 24:45 Web privacy audits and marketing consent<br> 37:00 Preparing before the deal sheet hits<br> 41:15 Know where your data is<br></p><p><strong>Takeaways</strong></p><ul><li>Never share personal data at any deal stage without an executed data protection agreement in place</li><li>Keep due diligence and integration strictly separate, a signed agreement is not an all access pass</li><li>Default to aggregated or de identified data early, most buyer requests can be satisfied without individual records</li><li>Back every pre closing transfer with a documented legitimate interest assessment and a signed deletion clause in case the deal does not close</li><li>Know where your data is before the deal sheet arrives, data mapping and records of processing are the foundation of a defensible sale<p><br></p></li></ul><p><strong>Connect with the Guest</strong><br> LinkedIn: <a href="https://www.linkedin.com/in/erin-e-mccurdy-11040017/">https://www.linkedin.com/in/erin-e-mccurdy-11040017/</a><br> Website: <a href="https://www.synopsys.com">https://www.synopsys.com</a></p><p><br><strong>Sponsor<br></strong>Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.</p><p><a href="https://www.observepoint.com/">Learn more about your website here</a></p>]]>
      </itunes:summary>
      <itunes:keywords>m&amp;a data privacy,personal data in mergers and acquisitions,data protection agreement,m&amp;a due diligence,chief privacy officer,privacy in m&amp;a deals,gdpr m&amp;a compliance,legitimate interest assessment,day one readiness,data sharing in acquisitions,privacy due diligence checklist,marketing consent transfer,consent management platform,m&amp;a integration privacy,data mapping,records of processing activities,privacy notice m&amp;a clause,sell side data protection,aggregated data due diligence,web privacy compliance</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/1e79e30c/transcript.txt" type="text/plain"/>
    </item>
  </channel>
</rss>
