The Shifting Privacy Left Podcast-logo

The Shifting Privacy Left Podcast

Technology Podcasts

Shifting Privacy Left features lively discussions on the need for organizations to embed privacy by design into the UX/UI, architecture, engineering / DevOps and the overall product development processes BEFORE code or products are ever shipped. Each Tuesday, we publish a new episode that features interviews with privacy engineers, technologists, researchers, ethicists, innovators, market makers, and industry thought leaders. We dive deeply into this subject and unpack the exciting elements of emerging technologies and tech stacks that are driving privacy innovation; strategies and tactics that win trust; privacy pitfalls to avoid; privacy tech issues ripped from the headlines; and other juicy topics of interest.

Location:

United States

Description:

Shifting Privacy Left features lively discussions on the need for organizations to embed privacy by design into the UX/UI, architecture, engineering / DevOps and the overall product development processes BEFORE code or products are ever shipped. Each Tuesday, we publish a new episode that features interviews with privacy engineers, technologists, researchers, ethicists, innovators, market makers, and industry thought leaders. We dive deeply into this subject and unpack the exciting elements of emerging technologies and tech stacks that are driving privacy innovation; strategies and tactics that win trust; privacy pitfalls to avoid; privacy tech issues ripped from the headlines; and other juicy topics of interest.

Language:

English


Episodes
Ask host to enable sharing for playback control

S3E11: 'Decision-Making Governance & Design: Combating Dark Patterns with Fair Patterns' with Marie Potel-Saville

4/30/2024
In this episode, Marie Potel-Saville joins me to shed light on the widespread issue of dark patterns in design. With her background in law, Marie founded the 'FairPatterns' project with her award-winning privacy and innovation studio, Amurabi, to detect and fix large-scale dark patterns. Throughout our conversation, we discuss the different types of dark patterns, why it is crucial for businesses to prevent them from being coded into their websites and apps, and how designers can ensure that they are designing fair patterns in their projects. Dark patterns are interfaces that deceive or manipulate users into unintended actions by exploiting cognitive biases inherent in decision-making processes. Marie explains how dark patterns are harmful to our economic and democratic models, their negative impact on individual agency, and the ways that FairPatterns provides countermeasures and safeguards against the exploitation of people's cognitive biases. She also shares tips for designers and developers for designing and architecting fair patterns. Topics Covered: Guest Info: Marie on LinkedInAmurabiFairPatterns.comResources Mentioned: 7 Stages of Action ModelDark Patterns 101Deceptive Design PatternsFighting Dark Patterns Podcast Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. TRU Staffing Partners Top privacy talent - when you need it, where you need it. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:54:12

Ask host to enable sharing for playback control

S3E10: 'How a Privacy Engineering Center of Excellence Shifts Privacy Left' with Aaron Weller (HP)

4/9/2024
In this episode, I sat down with Aaron Weller, the Leader of HP's Privacy Engineering Center of Excellence (CoE), focused on providing technical solutions for privacy engineering across HP's global operations. Throughout our conversation, we discuss: what motivated HP's leadership to stand up a CoE for Privacy Engineering; Aaron's approach to staffing the CoE; how a CoE's can shift privacy left in a large, matrixed organization like HP's; and, how to leverage the CoE to proactively manage privacy risk. Aaron emphasizes the importance of understanding an organization's strategy when creating a CoE and shares his methods for gathering data to inform the center's roadmap and team building. He also highlights the great impact that a Center of Excellence can offer and gives advice for implementing one in your organization. We touch on the main challenges in privacy engineering today and the value of designing user-friendly privacy experiences. In addition, Aaron provides his perspective on selecting the right combination of Privacy Enhancing Technologies (PETs) for anonymity, how to go about implementing PETs, and the role that AI governance plays in his work. Topics Covered: Guest Info: Aaron on LinkedInHP's Privacy Engineering Center of ExcellenceOWASP Machine Learning Security Top 10OWASP Top 10 for LLM Applications Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. TRU Staffing Partners Top privacy talent - when you need it, where you need it. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:40:13

Ask host to enable sharing for playback control

S3E9: 'Building a Culture of Privacy & Achieving Compliance without Sacrificing Innovation' with Amaka Ibeji (Cruise)

4/2/2024
Today, I’m joined by Amaka Ibeji, Privacy Engineer at Cruise where she designs and implements robust privacy programs and controls. In this episode, we discuss Amaka's passion for creating a culture of privacy and compliance within organizations and engineering teams. Amaka also hosts the PALS Parlor Podcast, where she speaks to business leaders and peers about privacy, AI governance, leadership, and security and explains technical concepts in a digestible way. The podcast aims to enable business leaders to do more with their data and provides a way for the community to share knowledge with one other. In our conversation, we touch on her career trajectory from security engineer to privacy engineer and the intersection of cybersecurity, privacy engineering, and AI governance. We highlight the importance of early engagement with various technical teams to enable innovation while still achieving privacy compliance. Amaka also shares the privacy-enhancing technologies (PETs) that she is most excited about, and she recommends resources for those who want to learn more about strategic privacy engineering. Amaka emphasizes that privacy is a systemic, 'wicked problem' and offers her tips for understanding and approaching it. Topics Covered: Guest Info & Resources: Amaka on LinkedInThe PALS Parlor PodcastPrivacy Design Strategies (The Little Blue Book)Strategic Privacy by Design, 2nd EditionThe LINDDUN Privacy Threat Modeling FrameworkThe Privacy Library of Threats for Artificial Intelligence (PLOT4.AI) Framework Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. TRU Staffing Partners Top privacy talent - when you need it, where you need it. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:43:24

Ask host to enable sharing for playback control

S3E8: 'Recent FTC Enforcement: What Privacy Engineers Need to Know' with Heidi Saas (H.T. Saas)

3/26/2024
In this week's episode, I am joined by Heidi Saas, a privacy lawyer with a reputation for advocating for products and services built with privacy by design and against the abuse of personal data. In our conversation, she dives into recent FTC enforcement actions, analyzing five FTC actions and some enforcement sweeps by Colorado & Connecticut. Heidi shares her insights on the effect of the FTC enforcement actions and what privacy engineers need to know, emphasizing the need for data management practices to be transparent, accountable, and based on affirmative consent. We cover the role of privacy engineers in ensuring compliance with data privacy laws; why 'browsing data' is 'sensitive data;' the challenges companies face regarding data deletion; and the need for clear consent mechanisms, especially with the collection and use of location data. We also discuss the need to audit the privacy posture of products and services - which includes a requirement to document who made certain decisions - and how to prioritize risk analysis to proactively address risks to privacy. Topics Covered: Guest Info: LinkedIn 'Means of Control: How the Hidden Alliance of Tech and Government is Creating a New American Surveillance State' Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. TRU Staffing Partners Top privacy talent - when you need it, where you need it. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:01:15:33

Ask host to enable sharing for playback control

S3E7: 'Personal CRM: Embracing Digital Minimalism & Privacy Empowerment' with Chris Zeunstrom (Yorba)

3/19/2024
This week's episode, I chat with Chris Zeunstrom, the Founder and CEO of Ruca and Yorba. Ruca is a global design cooperative and founder support network, while Yorba is a reverse CRM that aims to reduce your digital footprint and keep your personal information safe. Through his businesses, Chris focuses on solving common problems and creating innovative products. In our conversation, we talk about building a privacy-first company, the digital minimalist movement, and the future of decentralized identity and storage. Chris shares his journey as a privacy-focused entrepreneur and his mission to prioritize privacy and decentralization in managing personal data. He also explains the digital minimalist movement and why its teachings reach beyond the industry. Chris touches on Yorba's collaboration with Consumer Reports to implement Permission Slip and creating a Data Rights Protocol ecosystem that automates data deletion for consumers. Chris also emphasizes the benefits of decentralized identity and storage solutions in improving personal privacy and security. Finally, he gives you a sneak peek at what's next in store for Yorba. Topics Covered: Guest Info: Chris on LinkedInYorba's websiteResources Mentioned: TechCrunch's review of YorbaDigital Minimalism - Choosing a Focused Life In a Noisy WorldBullet JournalConsumer Reports' Permission Slip Protocol Matomo AnalyticsFathom Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. TRU Staffing Partners Top privacy talent - when you need it, where you need it. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:43:11

Ask host to enable sharing for playback control

S3E6: 'Keys to Good Privacy Implementation: Exploring Anonymization, Consent, & DSARs' with Jake Ottenwaelder (Integrative Privacy)

3/5/2024
In this week's episode, I sat down with Jake Ottenwaelder, Principal Privacy Engineer at Integrative Privacy LLC. Throughout our conversation, we discuss Jake’s holistic approach to privacy implementation that considers business, engineering, and personal objectives, as well as the role of anonymization, consent management, and DSAR processes for greater privacy. Jake believes privacy implementation must account for the interconnectedness of privacy technologies and human interactions. He highlights what a successful implementation looks like and the negative consequences when done poorly. We also dive into the challenges of implementing privacy in fast-paced, engineering-driven organizations. We talk about the complexities of anonymizing data (a very high bar) and he offers valuable suggestions and strategies for achieving anonymity while making the necessary resources more accessible. Plus, Jake shares his advice for organizational leaders to see themselves as servant-leaders, leaving a positive legacy in the field of privacy. Topics Covered: Guest Info: LinkedInIntegrative Privacy LLC Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. TRU Staffing Partners Top privacy talent - when you need it, where you need it. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:54:09

Ask host to enable sharing for playback control

S3E5: 'Nonconformist Innovation in Modern Digital Identity' with Steve Tout (Integrated Solutions Group)

2/27/2024
In this week's episode, I am joined by Steve Tout, Practice Lead at Integrated Solutions Group (ISG) and Host of The Nonconformist Innovation Podcast to discuss the intersection of privacy and identity. Steve has 18+ years of experience in global Identity & Access Management (IAM) and is currently completing his MBA from Santa Clara University. Throughout our conversation, Steve shares his journey as a reformed technologist and advocate for 'Nonconformist Innovation' & 'Tipping Point Leadership.' Steve's approach to identity involves breaking it down into 4 components: 1) philosophy, 2) politics, 3) economics & 4)technology, highlighting their interconnectedness. We also discuss his work with Washington State and its efforts to modernize Consumer Identity Access Management (IAM). We address concerns around AI, biometrics & mobile driver's licenses. Plus, Steve offers his perspective on tipping point leadership and the challenges organizations face in achieving privacy change at scale. Topics Covered: Guest Info: LinkedInThe Nonconformist Innovation Podcast Resources Mentioned: Interview with Tom KempOn Change Management Organizational BehaviorEthics in the Age of Disruptive Technologies: An Operational Roadmap Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. TRU Staffing Partners Top privacy talent - when you need it, where you need it. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:54:55

Ask host to enable sharing for playback control

S3E4: 'Supporting Developer Accountability for Privacy' with Jake Ward (Data Protocol)

2/13/2024
This week, I chat with Jake Ward, the Co-Founder and CEO of Data Protocol, to discuss how the Data Protocol platform supports developers' accountability for privacy by giving developers the relevant information in the way that they want it. Throughout the episode, we cover the Privacy Engineering course offerings and certification program; how to improve communication with developers; and trends that Jake sees across his customers after 2 years of offering these courses to engineers. In our conversation, we dive into the topics covered in the Privacy Engineering Certification Program course offering , led by instructor Nishant Bhajaria, and the impact that engineers can make in their organization after completing it. Jake shares why he's so passionate about empowering developers, enabling them to build safer products. We talk about the effects of privacy engineering on large tech companies and how to bridge the gap between developers and the support they need with collaboration and accountability. Plus, Jake reflects on his own career path as the Press Secretary for a U.S. Senator and the experiences that shaped his perspectives and brought him to where he is now. Topics Covered: Resources Mentioned: Data Protocol's coursesThe Privacy Engineering Certification ProgramS3E2: 'My Top 20 Privacy Engineering Resources for 2024' Guest Info: LinkedIn Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn TRU Staffing Partners Top privacy talent - when you need it, where you need it. Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:44:40

Ask host to enable sharing for playback control

S3E3: 'Shifting Left from Practicing Attorney to Privacy Engineer’ with Jay Averitt (Microsoft)

1/30/2024
My guest this week is Jay Averitt, Senior Privacy Product Manager and Privacy Engineer at Microsoft, where he transitioned his career from Technology Attorney to Privacy Counsel, and most recently to Privacy Engineer. In this episode, we hear from Jay about: his professional path from a degree in Management Information Systems to Privacy Engineer; how Twitter and Microsoft navigated a privacy setup, and how to determine privacy program maturity; multiple of his Privacy Engineering community projects; and tips on how to spread privacy awareness and stay active within the industry. Topics Covered: Resources Mentioned: 'Privacy Everywhere Conference 2024Data Privacy Day’24 FestivalUSENIX PEPR ‘24 Conference Guest Info: LinkedIn Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn TRU Staffing Partners Top privacy talent - when you need it, where you need it. Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:51:57

Ask host to enable sharing for playback control

S3E2: 'My Top 20 Privacy Engineering Resources for 2024' with Debra Farber (Shifting Privacy Left)

1/23/2024
In Honor of Data Privacy Week 2024, we're publishing a special episode. Instead of interviewing a guest, Debra shares her 'Top 20 Privacy Engineering Resources' and why. Check out her favorite free privacy engineering courses, books, podcasts, creative learning platforms, privacy threat modeling frameworks, conferences, government resources, and more. DEBRA's TOP 20 PRIVACY ENGINEERING RESOURCES (in no particular order) Read “Top 20 Privacy Engineering Resources” on Privado’s Blog. Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn TRU Staffing Partners Top privacy talent - when you need it, where you need it. Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:54:20

Ask host to enable sharing for playback control

S3E1: "Privacy-preserving Machine Learning and NLP" with Patricia Thaine (Private AI)

1/2/2024
My guest this week is Patricia Thaine, Co-founder and CEO of Private AI, where she leads a team of experts in developing cutting-edge solutions using AI to identify, reduce, and remove Personally Identifiable Information (PII) in 52 languages across text, audio, images, and documents. In this episode, we hear from Patricia about: her transition from starting a Ph.D. to co-founding an AI company; how Private AI set out to solve fundamental privacy problems to provide control and understanding of data collection; misunderstandings about how best to leverage AI regarding privacy-preserving machine learning; Private AI’s intention when designing their software, plus newly deployed features; and whether global AI regulations can help with current risks around privacy, rogue AI and copyright. Topics Covered: Resources Mentioned: "How Rogue AI's May Arise"Microsoft's Digital Defense Report 2023“Thoughts on AI Regulation” Guest Info: LinkedInPrivate AIPrivate Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn TRU Staffing Partners Top privacy talent - when you need it, where you need it. Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:37:00

Ask host to enable sharing for playback control

S2E39: 'Contextual Responsive Intelligence & Data Minimization for AI Training & Testing' with Kevin Killens (AHvos)

12/26/2023
My guest this week is Kevin Killens, CEO of AHvos, a technology service that provides AI solutions for data-heavy businesses using a proprietary technology called Contextually Responsive Intelligence (CRI), which can act upon a business's private data and produce results without storing that data. In this episode, we delve into this technology and learn more from Kevin about: his transition from serving in the Navy to founding an AI-focused company; AHvos’ architectural approach in support of data minimization and reduced attack surface; AHvos' CRI technology and its ability to provide accurate answers based on private data sets; and how AHvos’ Data Crucible product helps AI teams to identify and correct inaccurate dataset labels. Topics Covered: Guest Info: LinkedInAHvosTrinsic Technologies Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:43:26

Ask host to enable sharing for playback control

S2E38: "PrivacyGPT: Bringing an AI Privacy Startup to Market" with Nabanita De (Privacy License)

12/19/2023
My guest this week is Nabanita De, Software Engineer, Serial Entrepreneur, and Founder & CEO at Privacy License where she's on a mission to transform the AI landscape. In this episode, we discuss Nabanita's transition from Engineering Manager at Remitly to startup founder; what she's learned from her experience at Antler's accelerator program, her first product to market: PrivacyGPT and her work to educate Privacy Champions. Topics Covered: Resources Mentioned: Privacy LicensePrivacyGPTPrivacyGPT Chrome ExtensionData Privacy Week 2024 Guest Info: LinkedInNabanita's Moonshots NewsletterThe Nabinita De Foundation Covid Help for IndiaProject FiB Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:41:36

Ask host to enable sharing for playback control

S2E37: "Embedding Privacy Engineering into Real Estate" with Yusra Ahmad and Luke Beckley (The RED Foundation)

12/5/2023
My guests this week are Yusra Ahmad, CEO of Acuity Data, and Luke Beckley, Data Protection Officer and Privacy Governance Manager at Correla, who work with The RED (Real Estate Data) Foundation, a sector-wide alliance that enables the real estate sector to benefit from an increased use of data, while voiding some of the risks that this presents, and better serving society. We discuss the current drivers for change within the real estate industry and the complexities of the real estate industry utilizing incredible amounts of data. You’ll learn the types of data protection, privacy, and ethical challenges The RED Foundation seeks to solve, especially now with the advent of new technologies. Yusra and Luke discuss some ethical questions the real estate sector as it considers leveraging new technology. Yusra and Luke come to the conversation from the knowledgeable perspective as The RED Foundation’s Chair of the Data Ethics Steering Group and Chair of the Engagement and Awareness Group, respectively. Topics Covered: Resources Mentioned: The RED FoundationGuest Info: Yusra on LinkedInLuke on LinkedIn Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:01:04:47

Ask host to enable sharing for playback control

S2E36: "Privacy Engineering Contracting: State of the Market & 2024 Predictions" with Jared Coseglia (TRU Staffing)

11/21/2023
This week, I welcome Jared Coseglia, co-founder and CEO at TRU Staffing Partners, a contract staffing & executive placement search firm that represents talent across 3 core industry verticals: data privacy, eDiscovery, & cybersecurity. We discuss the current and future state of the contracting market for privacy engineering rols and the market drivers that affect hiring. You’ll learn about the hiring trends and the allure of 'part-time impact,' 'part-time perpetual,' and 'secondee' contract work. Jared illustrates the challenges that hiring managers face with a 'Do-it-Yourself' staffing process; and he shares his predictions about the job market for privacy engineers over the next 2 years. Jared comes to the conversation with a lot of data that supports his predictions and sage advice for privacy engineering hiring managers and job seekers. Topics Covered: Resources Mentioned: "State of the Privacy Job Market Q3 2023”TRU Insights Guest Info: LinkedInTRU Staffing PartnersTRU Staffing Data Privacy Staffing solutionsOpen Privacy Positions Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:57:47

Ask host to enable sharing for playback control

S2E35: "Embed Ethics into Your SDLC: From Reactive Firefighting to 'Responsible Firekeeping'" with Mathew Mytka & Alja Isaković (Tethix)

11/14/2023
This week’s guests are Mathew Mytka and Alja Isakovoić, Co-Founders of Tethix, a company that builds products that embed ethics into the fabric of your organization. We discuss Matt and Alja’s core mission to bring ethical tech to the world, and Tethix’s services that work with your Agile development processes. You’ll learn about Tethix’s solution to address 'The Intent to Action Gap,' and what Elemental Ethics can provide organizations beyond other ethics frameworks. We discuss ways to become a proactive Responsible Firekeeper, rather than remaining a reactive Firefighter, and how ETHOS, Tethix's suite of apps can help organizations embody and embed ethics into everyday practice. TOPICS COVERED: RESOURCES MENTIONED: "Day in the Life of a Responsible Firekeeper"ResponsibleTech.Work FrameworkPathfinders NewmoonsletterGUEST INFO: LinkedInLinkedInTethix’s Website Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:44:51

Ask host to enable sharing for playback control

S2E34: "Embedding Privacy by Design & Threat Modeling for AI" with Isabel Barberá (Rhite & PLOT4ai)

11/7/2023
This week’s guest is Isabel Barberá, Co-founder, AI Advisor, and Privacy Engineer at Rhite , a consulting firm specializing in responsible and trustworthy AI and privacy engineering, and creator of The Privacy Library Of Threats 4 Artificial Intelligence Framework and card game. In our conversation, we discuss: Isabel’s work with privacy-by-design, privacy engineering, privacy threat modeling, and building trustworthy AI; and info about Rhite’s forthcoming Self-Assessment Open-Source framework for AI maturity, SARAI®. As we wrap up the episode, Isabel shares details about PLOT4ai, her AI threat modeling framework and card game created based on a library of threats for artificial intelligence. Topics Covered: Resources Mentioned: Privacy Library Of Threats 4 Artificial Intelligence (PLOT4ai)PLOT4ai's Github Threat Repository"Threat Modeling Generative AI Systems with PLOT4ai”Self-Assessment for Responsible AI (SARAI®)LINDDUN Privacy Threat Model Framework"S2E19: Privacy Threat Modeling - Mitigating Privacy Threats in Software with Kim Wuyts (KU Leuven)”"Data Privacy: a runbook for engineers"Guest Info: Isabel's LinkedIn ProfileRhite’s Website Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:50:03

Ask host to enable sharing for playback control

S2E33: "Using Privacy Code Scans to Shift Left into DevOps" with Vaibhav Antil (Privado)

10/31/2023
This week, I sat down with Vaibhav Antil ('Vee'), Co-founder & CEO at Privado, a privacy tech platform that's leverages privacy code scanning & data mapping to bridge the privacy engineering gap. Vee shares his personal journey into privacy, where he started out in Product Management and saw need for privacy automation in DevOps. We discuss obstacles created by the rapid pace of engineering teams and a lack of a shared vocabulary with Legal / GRC. You'll learn how code scanning enables privacy teams to move swiftly and avoid blocking engineering. We then discuss the future of privacy engineering, its growth trends, and the need for cross-team collaboration. We highlight the importance of making privacy-by-design programmatic and discuss ways to scale up privacy reviews without stifling product innovation. Topics Covered: Privado Resources Mentioned: "Technical Privacy Masterclass" (led by Nishant Bhajaria)Introduction to Privacy Code ScanningCode Scanning Approach to Data MappingPrivado's Privacy Engineering CommunityPlay Store Data Safety Report BuilderGuest Info: LinkedInPrivado's website Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:56:06

Ask host to enable sharing for playback control

S2E32: "Privacy Red Teams, Protecting People & 23andme's Data Leak" with Rebecca Balebako (Balebako Privacy Engineer)

10/24/2023
This week’s guest is Rebecca Balebako, Founder and Principal Consultant at Balebako Privacy Engineer, where she enables data-driven organizations to build the privacy features that their customers love. In our conversation, we discuss all things privacy red teaming, including: how to disambiguate adversarial privacy tests from other software development tests; the importance of privacy-by-infrastructure; why privacy maturity influences the benefits received from investing in privacy red teaming; and why any database that identifies vulnerable populations should consider adversarial privacy as a form of protection. We also discuss the 23andMe security incident that took place in October 2023 and affected over 1 mil Ashkenazi Jews (a genealogical ethnic group). Rebecca brings to light how Privacy Red Teaming and privacy threat modeling may have prevented this incident. As we wrap up the episode, Rebecca gives her advice to Engineering Managers looking to set up a Privacy Red Team and shares key resources. Topics Covered: Resources Mentioned: "S1E7: Privacy Engineers: The Next Generation" with Lorrie Cranor (CMU)Red Teaming ResourcesGuest Info: LinkedInBalebako Privacy Engineer's website Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:48:08

Ask host to enable sharing for playback control

S2E31: "Leveraging a Privacy Ontology to Scale Privacy Processes" with Steve Hickman (Epistimis)

10/10/2023
This week’s guest is Steve Hickman, the founder of Epistimis, a privacy-first process design tooling startup that evaluate rules and enables the fixing of privacy issues before they ever take effect. In our conversation, we discuss: why the biggest impediment to protecting and respecting privacy within organizations is the lack of a common language; why we need a common Privacy Ontology in addition to a Privacy Taxonomy; Epistimis' ontological approach and how it leverages semantic modeling for privacy rules checking; and, examples of how Epistimis Privacy Design Process tooling complements privacy tech solutions on the market, not compete with them. Topics Covered: Resources Mentioned: Data is What Data Does: Regulating Based on Harm and Risk Instead of Sensitive DataGuest Info: LinkedInEmailEpistimis Privado.ai Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans. Shifting Privacy Left Media Where privacy engineers gather, share, & learn Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you. Copyright © 2022 - 2024 Principled LLC. All rights reserved.

Duration:00:51:35