Dave: Hey everyone, Dave here with another episode of the Philly Tech Connect podcast. Today, I’m speaking with Jason Riser. We’re going to be talking a lot about data privacy because Jason is a tech leader and general counsel with over two decades of experience guiding software, biotech devices, and other tech companies about commercializing their products and bringing them to the market, and obviously dealing with the vast and murky world of data privacy. In 2023, he got a Masters of Science and Technology from Brown University and wrote a thesis about building a culture of privacy through innovation and how to integrate privacy by design into software development. So, a lot of good stuff here that’s going to be useful for the startup community that we have at Philly Tech entrepreneurs. Jason, how are you doing today?

Jason: I’m good, Dave. Thanks for having me on, I appreciate it.

Dave: My pleasure. We haven’t talked about these topics yet with any of our past guests, so I’m happy to dive into it. Let’s just talk a little bit about data privacy in general. You know, these are words that it’s almost like a buzzword. People who are not actively in the space know of it; they know it’s something that they’re supposed to be kind of paying attention to. But as a startup, maybe a CEO or a new founder, you’ve got a million things going on. So, how should we be thinking about data privacy? Where does it kind of fit into the conversation here?

Jason: Yeah, it’s a good question. And I think one thing to distinguish data privacy from is it’s not cybersecurity. Cybersecurity is a term we all understand; it’s been baked into operations for decades now. Cybersecurity is how you protect information. Privacy is really about what are you protecting and why. Think of cybersecurity as the lock on the gate, but once you’re past the gate, there are a lot of other issues that spring up. Privacy doesn’t always deal with data breaches; it doesn’t always deal with bad actors. Data privacy is sort of a way of how you manage all the data in your company. I and others like to say every company is a data company, whether you believe it or not. Exxon’s a data company, Dunkin Donuts is a data company, and obviously, things like Facebook are a data company. Everybody’s a data company; they’re all analyzing data from their users, from the markets. When you get into the area of data that can identify somebody, whether it’s their name and address and social security number, but also their biometrics like their fingerprint or their eyes—you hold your phone up and you look into it—it’s storing because it has to match a record of your biometrics. That’s data privacy. And on and on it goes. So that’s the context to look at it. It’s really the what are we, what are we using, why are we using, and how are we sharing it.

Dave: At the end of the day, when you talk about data privacy and you reference companies that maybe are not known as data companies, like Exxon, for example, and some of the other ones that you mentioned, I—it’s always associating this concept with very large companies, you know, the Fortune 500 or Fortune 100 companies that this is something that they need to be concerned about. But me, or someone else in the community, who’s got a new startup, working on a software product on the side, this is not a priority for them. Why—tell me why I’m wrong and sort of where data privacy, you know, when does this become a priority for someone working on their business?

Jason: Good question, and something I’ve been addressing very recently. One of our members, Gary Cohen, who’s an agile coach and software developer, and I have been working together recently to build a series of articles on this very topic. It’s really about the intersection of software development and data privacy. So, if you’re a founder and you’re trying to develop an app, a website, or a product, it’s most likely—you know, one of your goals probably is to get users. Now, you know, it could be a medical device, and that’s a different story, but if you’re building sort of your traditional tech app or product, it’s going to need users, right? Typically, users are the lifeblood; you need them either to pay or subscribe or to feed your engine so you can make the product better and get better market share. So, if you’re a small company, you think, well, listen, I really don’t have many active users, I’m still in the MVP stage, data privacy is something for later on. I’m selling my app on the iOS store, whatever, but by then, it’s probably going to be a little bit too late because a couple of things you got to think about: Who’s your keystone client going to be that you want to sort of latch on to and advertise like this is the first early stage company that’s using our app and you want to shout from the rooftops about that? Well, today companies are starting to ask about your privacy practices. So they’re going to ask you questions about your storage, your retention, your deletion, and your interaction with your customers, who have a variety of rights depending on what state they live in the United States. So if you’re starting to ask a question a year, two years into your development cycle, you’re now going to have to start answering these questions. And if you haven’t sort of thought them through and built them into your lifecycle, then you’re going to have to do it at that point, and that’s when things start to break and go wrong, and you get the vendors coming in and saying, “We’ll fix it for you,” and then you have all that time and energy spent trying to find a vendor who then has to come and integrate and figure it out, and then there’s money falling out the door. So my perspective is, yes, you don’t need to have a full-blown privacy suite day one with dashboards and everything else involved, but you do need to address it, whether from a data lineage point of view or from just the basics—privacy policy, data flows, use cases—you guys are thinking about it early on so that you’re not caught unprepared later.

Dave: And is that relevant for companies that maybe are not product heavy, you know, services industry? You have an agency; we have customers. I don’t necessarily think of them as users, but they’re certainly customers; they have data. Does the conversation change in any significant way when we’re talking about those types of companies that are not like product first?

Jason: It changes, but you’re probably going to be a vendor to somebody right who is a data company, and all the obligations that they have have to flow to you. So you have to say, “I’m going to treat the data that you give me to do this slice of the job that you need in a proper way.” You’re going to need some access to some sort of data, most likely. And you have to represent that you can treat the data the same way they treat the data, you know, as appropriate for what the service you’re providing. So that’s one angle, and that has become codified, at least in California and probably a couple of others. And so you have these agreements that get placed; they’re called data processing agreements that used to only exist in Europe, now filtering into the United States because of these state laws. And you, either as a processor or data owner, have to figure out your rights and responsibilities. So you’re still going to be exposed to requirements of data privacy if you want to build your business serving those sort of hardcore tech companies that have vast amounts of data.

Dave: You mentioned a couple of laws, one being California, and maybe some of the policies that are changing there. I’d like to talk a little bit about that for a minute. Years ago, let’s call it, I don’t know, maybe about six or seven or so to my recollection, there was a pretty famous law called GDPR that was coming out, and I’m not an expert on this—you are—but from what I remember, because I was running a software app at the time, it was more of a European-focused data privacy law that all the apps kind of had to make significant adjustments in the way they were handling their data to abide by this new law. It caused a lot of frenzy, a lot of people—the compliance rules were kind of murky; it wasn’t clear. A lot of ambiguous language was being used, a lot of companies weren’t sure how they were going to deal with it. And now, you know, looking back, I questioned whether there was a lot of teeth to that law, and I’m happy to stand corrected on this, but I do kind of wonder, you know, after all the commotion that it caused, is it still a large part of the dialogue in your day-to-day kind of software?

Jason: So, the European law, right, was about that timeframe, and it is truly a way of life now in Europe. You’re talking about corporate interactions, terms of contracts, terms of data flows. It’s been baked pretty well in. Now, you know, the teeth in those laws can be like 2% of your revenue; it’s like the greater of some huge millions of dollars or Euros or two percentage of revenue, obviously, that can be quite large for your big company. And then you have to sort of get these forced programs of compliance right, so it can greatly disrupt your business. Coming to the U.S., the laws are all a little bit different; some have private rights of action, so that means the civil attorney can step into the shoes of the attorney general and go after you; some reserve the rights to the Attorney General’s office like California, and they have to get the first bite of the apple. But I always say, forget the dollars, right? Because dollars—you know, you have insurance perhaps, or you have, you know, whatever—it’s about reputation and disruption. So, it’s like if you had an SEC audit tomorrow. People get, you know, ready for SEC audits by spending months with professionals and workflows and meetings, right? So now imagine that you have a privacy regulator saying, “We got this complaint that you’re not deleting data that you’re supposed to delete after a request by a client,” and they say, “Show us, show us your process, your flows, your retention schedules, who’s responsible for this,” you know, all this sort of stuff. And now you have to deal with the disruption, all the people that were building your product or helping you gain market share or whatever are now focused on these internal meetings to deal with the attorney general. And now it becomes a news story, and your competitor says, “Oh, look at them; they don’t do it right; we do.” So you can really stand to lose—you know, I say the regulators are bad, but you get lawyers, you can hopefully work out a deal, and it doesn’t cost too much; you get a remediation plan in place. But it’s the reputation and disruption to your business that’s truly the cost. And with so many different laws coming out, it’s gonna—the longer you wait, the more time you’re going to spend figuring out, “Do I have clients in Utah, do I have in Virginia, are they—you know, customers in California, where’s my business located, is it big enough to be subject to the act, or is it still too small?” You know, if you’re waiting two more years, there gonna be five, six more laws on the books. So the recommendation that we kind of talk about is a principles-based approach, so you’re not looking at every single law; you’re looking at what’s the best overall way to deal with data hygiene, data usage, data sharing, data depletion, and how to build a system called privacy by design from the get-go so you’re not catching up. So the short answer to your question is it’s very disruptive, can cost you a lot of money, but more likely will cost your reputation at the end of the day. Today, um, and there’s a lot of big companies now that are putting like Porsche has a whole big thing on the website about how they’re using privacy as a market differentiator. Um, and there’s other companies like Uber was the first company in the United States that actually got penalized by the Department of Justice and required to build a privacy by Design program into their way of doing work because they had so many problems under the old regime—uh, how they use personal information. So come from many different angles, but that’s kind of my long answer to your short question is it’s to more disruptive, you than you want to deal with.

Dave: Excuse me, Jason, I’m sorry, I just had an issue with my speaker not working. Are you still hearing me? You seem to still be hearing me quite well.

Jason: Yes, I can hear you fine.

Dave: Okay, let me see if I can make an adjustment on that; it’s mostly just the headset, I think. Give me a sec.

Dave: And are you on mute? Would you be able to go off, and I can hear okay?

Dave: Good, um, great. In any case, to follow up, when we talked about the law, and I mentioned GDPR, and you know, many businesses these days are serving customers not just in their specific state but nationally, globally even. Every country, continent, state, etc., they have potentially their own unique privacy laws. What is the realistic expectation here from a business perspective in terms of abiding by these, being on top of these? What is a standard approach?

Jason: Yeah, so this is really where you get to the principles-based approach of designing your systems. You can’t possibly keep track of every nuance of every law and on a minute-by-minute basis, right? It’s not realistic. So if you’re a more mature company that has been around for a while, you need to start somewhere, right? And that would start with assessing what you have, what you’re responsible for, and then looking at the data flows in your company. You know, a lot of companies have like bolt-on systems from old systems to new systems, and they have—you got Integrations coming in, you vendors, it gets very messy. And so you need something on a backbone, call a data lineage program, so you can—you know, software that can do that—you can scan and find out where your data is. It’s not easy; it takes time. But if you’re starting off, you’re in a much better spot because you can kind of build it the right way, the privacy by design way, which is using principles of—you minimize the amount of data you need, right? You restrict who you share it with; you delete when it’s no longer required; you have data flows and processes to respond to requests. Those kinds of things, that’s very simplistic, high level, but those kinds of things will start to shape a program that will fit any regime because they all ask about the same thing, right? Did you get consent? Did you use it consistent with the consent that you got, and did you get rid of it when you no longer needed it, and did you give it to anybody you said you weren’t going to give it to? Like those are some basic principles. You build systems around that, and because I tell you, like, here’s a quick and dirty use case that could go wrong. California law says you have a right to request of a company to understand what data of yours they have and then delete it. Now, there are exceptions; if you’re a current user of that platform, they have a right to keep your data that is required to provide the service to you. Okay, so let’s say they shut it down. “I’m only using a service; delete all my data.” Great. You get a certain timeframe to do that; you say it’s deleted. You say, “Jason, we deleted your data.” Two weeks later, you get a targeted ad from this very company, right? Because your digital marketing strategy is to do targeted ads, and you say, “Wait a minute, how do you have my information? You deleted all my data.” Call the Attorney General; they start an investigation like it start that easily because you didn’t—you obviously had data some—in some Marketing System, right, somewhere—that kept that data, and now you have to, like, again, start that whole process I talked about. So having good data hygiene practices, all those things will serve you well, um, and you know, it doesn’t so much matter the specific law; that program will set you up for success.

Dave: Let’s say you convinced me on the importance of data privacy and why I should probably be paying more attention to this in my business and others should as well. Who do we go to for services in this area? The fact that it’s data leads me to believe, you know, that there’s a developer, you know, architectural component to this, but the fact that it’s policy makes me think it’s legal, and like, you know, is unlikely that one person possesses complete expertise in both of those domains. So who is kind of doing the work of this?

Jason: Good question. If you don’t have internal resources, most people start with the lawyers, right, because they want to figure out what the laws are. They—I’m a lawyer, so I don’t—they probably lawyers, but lawyers are expensive, take a lot of time, and they don’t really have the necessarily all the knowledge of the underpinnings of how to actually do the fixes. They just say, “Here’s a solution; you figure it out and get there.” So that’s where your tech side has to come in; they have to be well-versed and understanding it. So, you know, Gary Cohen and I are working—he’s also a Philly PTE member—we created a little outfit called Privacy Forward Strategies; we’re putting out articles every week about privacy by design, and it’s really the intersection of software development and data privacy, how to practically build the right way your software stack. So Gary has years and years as an agile coach, as a software developer, five years of privacy U experience as well as working in-house at a large technology company building financial planning software. So you know, it’s nice to have that dual threat, so to speak. And really, it’s about—it’s called privacy by design—these principles are how do you build—you call, you shift left or code left—start earlier rather than later, and you build with those principles in mind. But I will tell you that it’s a challenge because when you’re talking to your CFO, right, or your board, and you say, “What are you spending money on?” Well, we’re spending this much money on product development, this much money on client acquisition, this much money on tech debt, um, and they—we spend this much money on a privacy by design program—they go, “What? What’s that?” And you explain to them, they say, “Well, we don’t—we’ve been fine without it so far, right?” So it can be a challenge. So it’s really a cultural issue, and that’s kind of what I wrote about my thesis and what I try to talk about is it’s really a cultural issue. So you have to get buy-in from the top by demonstrating from the bottom up the importance of it and how in the end result, it’s—it not only saves you time, energy, and money but it also is a differentiator for you as a company because you can then shout from the rooftops, “We are a privacy by design shop; we take your privacy seriously.” Some companies even put up customer-facing dashboards so they can actually self-serve a little bit how their data is used. Like, it can get really creative, and it does take time and energy in the beginning, but once you’ve done it, you’re set for success in the future. You know, like, you can just go on and just not worry about it because it’s self-sustaining; you have an educated workforce that works together with your privacy teams. You can get software scans; you can do all kinds of different things at the end. But once you have that cultural in place, it—it’s not a challenge as much anymore to—to get things right.

Dave: Yeah, it’s interesting you talk about privacy being a differentiator. Um, you know, from a marketing, acquisition standpoint, I didn’t think of this as a theme like five or more years ago, but now it feels like it’s coming up more often, and I could be wrong with this example if this represents kind of what you were saying or not, but like a company like DuckDuckGo, which is a search engine that I feel like has positioned themselves as, “Hey, we’re the Google that doesn’t track like everything about you,” and I believe they’re like a Philly-based company as well. Um, is somewhere where feel like privacy has been a differentiator for them. Would you agree?

Jason: Yes, I do. And I think the way to look at it is, you know, every app you have is a service and privacy policy which nobody reads. You scroll as fast as you can to press accept. Right? People value their time and productivity more than their privacy because we have all these data breaches that occur—Equifax, Wells Fargo, they all occur all the time, Target, and everybody’s just like, we’re so numb to it because we just assume all our data has already been exposed, and it’s a luck of the draw whether you are a victim of identity theft, right? But you know, that’s sort of like that’s just like throwing your hands up in the air and saying, “Well, I don’t care anymore.” But that’s why these laws have come into place, and I think as these laws do have more teeth, they get more exposure, and you start to see more high-profile examples, companies are going to realize that they don’t want to be the next one, right? They don’t want to be that next example because the costs are pretty significant when you get into these issues. So I think that Europe looks at privacy as a human right, as a fundamental right. The US has looked at privacy as a bargaining chip, a commodity that I can buy and sell, um, which makes it less valuable in the end. And we’re moving now more towards this European model where it’s a right that you have, um, you can’t just give away so easily and can’t be taken from you without your knowledge. So you know, it’s starting now to gain, it’s—it’s going to be, it’s starting to roll downhill; it’s getting a lot more momentum. Um, and I think over the next two or three years, you’re going to start to see more and more examples in the public of things that are done wrong. There’s only so much power, you know, time, and energy that every state has to investigate every—every company. They’ll find a few big ones, make examples of them, um, and scare them straight. I know Sephora, the makeup company, had a big one about a year ago. So they’re—they’re starting to trickle in.

Dave: Super interesting discussion, Jason. Um, it sounds like like you mentioned you’re putting out some content. I’d love for you to share that in the community, by the way. You know, we have a Slack channel dedicated for sharing content that is created by members. Um, for people that want to get in touch with you, you know, where should they go?

Jason: Yeah, you can reach out—for this kind of topic—Jason at PrivacyForgeStrategies.com. My colleague Gary, privacyforstrategies.com. I’ll post something in the Slack channel, um, if Gary hasn’t done it already. Um, and happy to have a discussion, um, even if it’s this high level, to still learn more. Um, but you know, again, I’m—I’ve been immersed in the world for a long time, so I get it; I’m kind of nerding about it. But um, rather than putting your head in the sand and saying it doesn’t apply to me, it’s gonna have a little bit of knowledge then make your decision, right? Then it’s an informed decision; at least you can say, “I looked into it, right?”

Dave: Awesome. Thank you so much for walking us through that today, Jason.

Jason: Hey, welcome. Pleasure to talk to you.