She Said Privacy/He Said Security Titelbild

She Said Privacy/He Said Security

She Said Privacy/He Said Security

Von: Jodi and Justin Daniels
Jetzt kostenlos hören, ohne Abo

This is the She Said Privacy / He Said Security podcast with Jodi and Justin Daniels. Like any good marriage, Jodi and Justin will debate, evaluate, and sometimes quarrel about how privacy and security impact business in the 21st century. Management & Leadership Ökonomie
  • How to Solve AI's Data Problem
    Sep 10 2026

    Cillian Kieran is the Founder and CEO of Ethyca, where he leads its product vision, engineering strategy, and growth. A serial entrepreneur and privacy engineer with two decades of experience, he launched Ethyca in 2018 to bring privacy-by-design infrastructure to developers. Earlier, he built the digital consultancy CKSK to 100-plus employees across four countries, serving clients like PepsiCo, Heineken, and PlayStation. He pairs deep technical grounding with a track record of scaling data-intensive businesses.

    In this episode…

    As companies expand their use of AI, they need guardrails around how the technology is used by employees and how those systems use enterprise data. Because models are trained on data, bias can be introduced through this information, while systems also continue to use this data to perform different tasks. This creates risk, and managing it requires evaluating what data a model or tool can access, its intent when it uses that data, and the economic, ethical, and regulatory implications of that intended use. So, what controls do companies need to manage AI and company data safely?

    Because AI wants to satisfy a user's request, it will keep trying to access data unless clear boundaries define what it can use. Using AI responsibly requires managing the data behind it alongside the technology itself. To do this effectively, companies need to know what data they have collected, where it came from, whether they have sufficient consent, and what legal basis applies to its use. Once companies understand those elements, they can give AI access to the information it needs for a specific purpose while limiting what falls outside that use, allowing them to leverage the value of their data while minimizing risk. Governance also needs to move from written policies into controls that can be enforced on a system in real time. And while AI can streamline processes like privacy risk assessments by gathering information and comparing it against policies, past assessments, and relevant requirements, human privacy experts still need to review the output for accuracy and challenge AI when it's wrong.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Cillian Kieran, Founder and CEO of Ethyca, about the importance of unifying AI governance and data governance. Cillian explains how bringing these two areas together helps companies stay in control of their data while allowing the technology to support the business. He discusses why companies are turning to open-source models for greater sovereignty and cautions that bringing a model in-house can still introduce risks. Cillian also addresses the tension between AI's need for data and privacy's data minimization principles, and he stresses why professionals need to think critically, question AI outputs, and avoid relying on AI as a crutch.

    Mehr anzeigen Weniger anzeigen
    36 Min.
  • Maintaining Human Intelligence in an AI World
    Aug 27 2026

    Elise Houlik is the Chief Privacy Officer at Intuit, where she leads the company's global privacy and responsible data innovation and protection strategy, ensuring data is used to safely power innovation across Intuit's ecosystem of financial technology products. Her team is deeply engaged with the business on all matters related to product development, data innovation and governance, and information security.

    In this episode…

    Legal and privacy professionals are using AI more often to save time and accomplish more in their day-to-day work. While these tools offer clear advantages, they also generate convincing outputs that are incomplete, generic, or factually wrong. Using AI responsibly requires professionals to apply human judgment and review the output closely to ensure it is accurate and supported before relying on it. As AI becomes more embedded in legal and privacy work, critical thinking skills remain just as important as knowing how to use the technology.

    Professionals get the most value from AI when they view it as a collaborator, rather than an authority. As privacy and legal teams use AI to kickstart analysis, pull facts together, and hunt for nuances across fragmented laws, they need to compare its answers against actual laws and reputable sources and challenge the tool when an output misses the mark instead of accepting it at face value. Being mindful about the personal information they put into public models is equally important. Professionals should also be comfortable using a variety of different tools and learning which ones fit different purposes. And as companies hire the next generation of tech-savvy professionals, they need to ensure they don't become overly reliant on AI and provide them with hands-on experience and exposure to real conversations that strengthen analytical skills.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Elise Houlik, Chief Privacy Officer at Intuit, about the importance of maintaining human intelligence in the age of AI. Elise shares how AI is changing the skills employers value in legal and privacy professionals and explains why human judgment, curiosity, and a willingness to challenge AI-generated answers are essential as these tools become a standard part of workflows. She highlights why junior professionals still need practical experience and peer-to-peer learning opportunities and shares her perspective on keeping human intelligence at the center of how professionals use AI. Elise also offers tips for building AI skills and experimenting with different tools.

    Mehr anzeigen Weniger anzeigen
    30 Min.
  • Navigating the New Era of Data Broker Laws
    Aug 13 2026

    For 30 years, Ben Isaacson has been a leading privacy professional and trusted counsel. During the "Internet 1.0" era, he was instrumental in launching the first self-regulatory guidelines for email marketing, addressable TV, and mobile marketing. Ben was one of the first privacy professionals to get certified as a CIPP/US with the IAPP in 2005.

    In this episode…

    Data broker laws are pulling a once-hidden industry into the light. For years, consumers generally had no idea which companies were compiling and selling their personal information, what those companies were doing with it, or how to opt out. States are responding with data broker laws that require brokers to register and disclose information about their businesses and data-selling practices. Seven states now have these laws on the books, with some providing consumers with a centralized mechanism to request deletion of their data or to opt out of its sale. So, how can companies that purchase or license data from brokers manage the downstream risks that come with using it?

    Companies buying or licensing data from data brokers need to know where that data comes from, how it's used, and what their third-party contracts permit. Legal and privacy teams should work with marketing and sales to identify which adtech vendors they buy or license data from and scrutinize their licensing relationships. They also need to map how purchased data flows through the business and ensure their privacy notices disclose its use. California's Delete Act makes this downstream visibility especially important because it requires data brokers to apply deletion requests before that data is used. Companies also need to consider whether their activities qualify them as data brokers, particularly because New Jersey's data broker law extends registration requirements to data collectors, potentially affecting businesses that fall outside the traditional data broker definition. Companies should seek a legal opinion to determine where they stand based on the nature of their business and its commercial terms.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Ben Isaacson, Principal at In-House Privacy, about the rise of data broker laws and what they mean for companies that buy, license, or sell personal information. Ben discusses the evolution of these laws and how data broker definitions and legal requirements vary across states. He highlights what companies can do to mitigate risk when using data purchased from brokers and provides tips on how companies can determine whether they are considered data brokers under these laws. Ben also shares his perspective on how California's Delete Act could influence future state and federal regulation.

    Mehr anzeigen Weniger anzeigen
    33 Min.
adbl_web_anon_alc_button_suppression_t1
Noch keine Rezensionen vorhanden