Privacy workshop: DPIAs, clean rooms, generative AI

  • AI PrivacyPrivacy RegulationsAI Governance
  • Episode 16
  • June 15, 2023
 

Summary

This episode previews an upcoming in-person workshop in New York, convening privacy professionals, in-house counsel, data practitioners, and technologists for a day of practical, hands-on compliance work. The concept originated from conversations at IAPP, where attendees repeatedly expressed a desire for actionable guidance rather than theoretical discussion. With approximately forty participants registered, the session is framed as a safe, collaborative environment where peers can speak candidly about real challenges and share implementation experiences. The workshop is organized around three substantive tracks. The first is a live walkthrough of a data protection impact assessment for targeted advertising — filling out an actual DPIA together, discussing the relevant considerations, and walking away with a working document that participants can adapt for their own programs. The second track addresses clean rooms, a technology that remains widely misunderstood in the market. The goal is to demystify common use cases, clarify what actually happens to data inside these environments, map legal obligations to specific scenarios, and benchmark how major industry players have approached the relevant compliance questions. The third track focuses on generative AI and its growing privacy implications. The generative AI discussion is expected to cover the risks introduced by democratized access — where any employee, not just engineers, can now interact with powerful AI models and potentially expose sensitive data, as illustrated by high-profile incidents like the Samsung case. Privacy lawyers are also increasingly grappling with ethical questions raised by AI, including bias and fairness concerns. The workshop will draw on the DPIA framework from the morning session to structure thinking around how organizations can deploy generative AI both internally and in customer-facing applications in a compliant and risk-aware way.

Transcript

**Jonathan:** Hey, Alyssa. Good morning. **Alysa:** Hello. Good morning. **Jonathan:** Hey. Good to see you. **Alysa:** Always good to see you. So what are we talking about today? **Jonathan:** Oh, well, we've got this big workshop next week. We're gathering like minded folks and privacy professionals and data people and technology people to talk about real practical approaches to privacy. If you remember, this was your idea, but when we were at IAPP walking around the conference there, everybody said, I wish there was just real practical advice on what we need to do. The topics — so we convened a group. There's forty of us coming. There's room for more. But we're talking about three big issues that kind of rose to the top here. The first one is let's go through an actual DPIA for targeted advertising and fill it out together and talk through the issues and the considerations. And then secondly, well, clean rooms. They're still too confusing. There's multi dimensions to that, right? There's the use cases. Well, what are they? What are you trying to do in a clean room? Are you advertising? Are you just doing measurement? Or whatever the case may be. And then secondly, there's the legal issues. Why are combining data? Are you a service provider? Are you not? So we're to hit all that. And then lastly, of course, how do you not talk about AI? So we'll think through those issues as well. We've been thinking about it a lot at Ketch. But, yeah, let's get into it. What give people a little preview. Like, how would you think about the DPIA piece, for example? **Alysa:** Yeah well I mean I think going back to what's practical, we're in this early phase of these new requirements. We know about DPIAs from Europe but now we have US laws and US regulators looking at it and wanting something more, right? And we have a lot of in house counsel and privacy professionals who haven't had to do one. I mean, we've all done risk assessments but haven't had to really go through the process of filling that out. At the same time, digital advertising and analytics is — we know it's one of the regulators' real top concerns. And you also have a lot of privacy professionals who are just still getting up to speed on ad tech. And so even to know what the right questions are to ask. And then putting both of those together and thought from a practical standpoint, amongst friends, in a safe space to be able to walk through the exercise and benefit from insights. We've got somebody from NAI, you know, obviously with the background on digital advertising and trend lines there, and a lot of smart people in the room to just talk through and share their thoughts and then hopefully walk out with kind of a mock filled out DPIA that they can really use going forward. And we've heard, I'll just say, from the Colorado Attorney General's Office that they want companies to get their DPIAs in order. And if you think — if you got a letter from a regulator basically asking, have you done one? — sure would be helpful to have one that you feel a little bit more comfortable. You've gotten the benefit of insights from a lot of folks. **Jonathan:** Is it true that it's when a regulator calls, it's the first thing they ask for? **Alysa:** So it depends on the issue. I think we have heard the word on the legal street is that Colorado Attorney General's office in particular, that may be one of their priorities. And so when they do some reach outs, that is something they're likely to ask. Whether that's true, that's the gossip. But I will say more generally when the Federal Trade Commission or a state AG is investigating or has questions about your business practices involving data, whether you've done a risk assessment to identify and foresee vulnerabilities and how you've mitigated that — that is a fairly common question that I would anticipate. **Jonathan:** Thanks, Alysa. And then for clean rooms, you know, as we get into these, there'll be more theory. But for clean rooms, we need it. Right? There's just so much confusion out there in the market on what they do and so many legal issues. Right. **Alysa:** I think we wanted to demystify and just be plain language. What is happening? What are the different scenarios and common use cases we hear from business clients? They'll use just different words. It's anonymous. We're just doing this. We're doing matching here. And then this is the output. And I think we thought it would be helpful, again, to get folks in a room in a safe space and talk through some of those common use cases and how to think about it from a privacy compliance risk assessment perspective so you know how to treat it. But also thinking of benchmarking and how some of the big players, the stances they've taken so that you know which company, which camp, right? Your approach is really falling in and whether maybe the way you're looking at it might ultimately raise more risk. So we want to think through that. **Jonathan:** Gotcha. And on the demystifying, someone said this the other day, it's like a laundry. You just throw data in there. It makes it good. Comes out the other side. Super clean. You can do whatever you want. Not quite. **Alysa:** Not quite. AdExchanger had an article I think a week ago where they just went to town on all of the privacy safe advertising that all these different clean rooms and companies were using — to the whole kind of laundry. It's all clean, we can do anything within it — and really buyer beware. Don't just take the advertising claim that it's privacy safe. What is actually happening to the data in detail matters. It's tools. You can do a whole lot of things with tools. It doesn't mean that you don't have legal obligations. **Jonathan:** Thanks, Alysa. And if AI, this is really kind of taking shape as well. Like, for me at least, I understand why generative AI has been so disruptive. And I mean, you gave me this term, this idea of democratized access. If you're an engineer to get value out of generative AI, you can just be a normal person. So that means normal people, normal employees in your organization, if they have access to data, could throw it against AI models. Like we saw with the Samsung example, has a potential to really be pretty risky, pretty bad. But then also, privacy tech is evolving to snap to generative AI. Privacy lawyers are starting to think through ethical issues, right? Issues of bias that generative AI raises. I love the webinar we did at IAPP where we had your legal view and machine learning knowledge of the world. I think that's a perfect combination. We'll replicate some of that. **Alysa:** Yeah. So that's exactly it. And I think we'll have the benefit of, in our webinar, we had people having to put in the chat a few questions. We couldn't get to all of them. But I think in the workshop, we can just really talk through the common new ideas of how business clients want to use generative AI both internally and to roll out to customers. And so how do you think through some of those issues? And we'll have the benefit of having done the DPIA exercise at the beginning of the workshop to just really think through some of those same themes when it comes to generative AI. **Jonathan:** Awesome. I'm so looking forward to it. We've got some great brands in the room. Chatham House rules. Yeah. I think I'd like to say, this is Thursday. It's in New York. If you're local, you should try to come. We'll post the link down the bottom. And if there's room, of course, people are welcome. Alright. Looking forward to it. Thanks, Alysa. I'll see you next week.

Next step

See permissioning infrastructure in action

Walk through the platform with a Ketch architect, or launch the free CMP today.

Get Started Free

Get started in less than 5 min