This episode reflects on a recent in-person workshop focused on data protection impact assessments and privacy risk management, featuring conversations among privacy and legal practitioners. A recurring theme was the challenge of translating compliance obligations into language that resonates with business stakeholders — moving away from statutory jargon and toward shared objectives. Participants noted that framing privacy work in terms of business value and strategic alignment, rather than mere legal obligation, significantly increases organizational buy-in and cross-functional cooperation. The DPIA discussion examined four foundational questions: where assessments are required, when they must be completed, what they should describe, and who is permitted to read them. Colorado was highlighted as a state with explicit DPIA mandates, covering activities such as targeted advertising, sensitive data processing, profiling, and automated decision-making with significant consumer impact. A practical approach was recommended: rather than creating separate assessments for every vendor or activity, organizations can draft umbrella DPIAs covering materially similar practices and include callout sections for variations — a more efficient use of resources as programs scale. The FTC's expectation of privacy-by-design was also noted as a de facto risk assessment standard even absent explicit state requirements. With July 1 state enforcement dates approaching, the episode offered predictions on regulatory priorities: enforcement letters targeting digital advertising opt-out failures, increased scrutiny of health information practices, and interest in DPIA programs — particularly from Colorado regulators. The conversation also addressed attorney-client privilege considerations for DPIAs, noting that most of a DPIA's content is factual and likely not privileged. Practitioners were advised to deliberately isolate legally privileged analysis within DPIAs, limit access to those portions, and not rely on regulatory assurances that producing DPIAs constitutes a privilege waiver.
DPIA workshop preview for targeted advertising
- State Privacy LawsPrivacy RegulationsFTC Enforcement
- Episode 17
- June 29, 2023
Stream this episode on
Summary
Transcript
**Jonathan:** Hey, Lisa and Wyatt. Good morning. **Alysa:** Hey. Good morning. **Jonathan:** Hey. I loved our workshop last week. **Alysa:** Oh, that's so fun. That was — first of all, it's so great to get off the screen. I mean, we like being on the screen, but really good to be in person and interact with folks on these questions. **Jonathan:** Yeah. It was interesting. I didn't realize it was gonna be part therapy session. Like, hey. We need to collaborate as lawyers across the company, and how do we do that? And how do we get budget? And we hear a lot from business about some of the translation issues, right? Like between, hey, you're kind of talking to me about risk mitigation, but I don't quite know what to do with that. And it's always been a little one-sided for me, but actually lawyers are like, hey. It works the other way too. **Alysa:** It absolutely does. And I mean, the therapy session — this is a challenging time. And so I think empathy is really important, and you need to convince other people that everybody should be rowing in the same direction and how do you motivate. And I think having empathy and really thinking about one of the things we heard really is like how do you motivate the business? And if you come at it with just saying, this is compliance. You have to do this, the law says, as opposed to really speaking in a business way on how does this support the business and how does — what are all of our combined objectives and how do we get there and which are the points that the lawyers do, the compliance people do versus the business people do. And I think almost like chess, like strategizing that, you really increase the odds of moving forward in a lot more of an efficient, successful way. **Jonathan:** I love how Aaron Bernstein facilitated that session and just so clearly laid out all the pieces for DPIAs as an example. And just supported with David Leduc at the NAI. I thought it was such a great session. One of the quotes that really stood out for me is when Aaron said, when you walk up to people in the business and you say, hey, do you process personal data? Like, what? You want me to say no, right? So yeah, there's an understanding of what they're doing in the business and how they're using data and this idea that just about compliance, but it's like, let me help you do what you're trying to do. **Alysa:** I think that that's right. Really, language is so important. I think as lawyers, we get comfortable with these defined statutory defined terms, but your audience — this is not — they're doing something very different. And if you're using terms and they have no idea what you mean, then you're losing time and you're absolutely speaking past each other. And so that's a pretty important thing to consider before you even approach those discussions. **Jonathan:** Yeah. No. For sure. So we talked risk assessments and how to build a DPIA, things to think about, and we'll talk about that today. We talked about clean rooms. We talked about AI. I think we've talked about that a ton. So a couple of things. I want to roll through just a little summary of the DPA section with you and get your thoughts on that, Alysa. And then also in the comments, we're doing another one of these somewhere else in the country. Maybe it's different topics and people can kind of weigh in with, actually, I'd like to hear you talk about this or that. On DPIAs, what I loved is Aaron's framework, which was, okay, where are they required? When do they need to be done? What should they describe? Who gets to read them? And so as you kind of work through that — where and when are they required? Like, in terms of states and activities. **Alysa:** Yeah. I thought it was really an interesting point he made that, yes, some states specifically require them, you know, Colorado being an example. California is still working on their regulations, but I would get super practical. You're not doing it just for one state. At the end of the day, the FTC, for example, expects privacy by design, which is a risk assessment. And Colorado, I think, helpfully lays out particular topics that you need to do a DPIA for, and targeted advertising is at the top of the list. If you're using sensitive personal information, right, that is going to be something you need to do a meaningful risk assessment on. If you are doing automated decision making — so, you know, generative AI is in the news — or making decisions that really impact people's lives in a legal way or other type of significant way, housing, education, then yeah, you're gonna need to do a risk assessment. And so I think just, it's not everything. I mean, you have to do some risk kind of basic scanning when you're processing personal information for business reasons, but it's what's that at the top of that list in terms of organizing. And I thought he made the really good point being strategic on — well, what's it? So let's say targeted advertising, how do you — is it targeted advertising for every vendor? Is it targeted advertising for cookies versus something else? And I think what we saw and what the discussion in the room was, maybe you have a version one, which is different than the version two a year from now or nine months from now when you've already gotten a whole bunch of these done if you're just starting and really thinking about is there a common category, right, where the facts don't materially vary. And so that might be a better way to bucket it and just better use of resources if there's not such key distinctions between the practices. **Jonathan:** I love that question. This idea of, okay, can you have one DPIA that covers similar activities or is it multiple narrow ones? And so you're saying, Alysa, yeah, you could have one that covers several materially similar activities, and when it changes, you update it. Right. **Alysa:** Maybe it's eighty percent the same, but you have twenty percent where one vendor is slightly different. Well, why not still have an overall DPIA and you have your callouts and your distinct kind of here's the additional part to that smaller piece? To me, that just seems like an easier way to manage as opposed to doing separate ones for each partner. **Jonathan:** Gotcha. And then so targeted advertising, seller data, profiling, sensitive data processing, but then any heightened risk of harm to consumers. How do you — is there a test for that or is there a guidance for what that means? **Alysa:** So the states exempt things like HIPAA and FCRA, right? So credit, HIPAA based decisions that impact insurance, for example, or medical care. But I put the lens on the FTC and what we've seen the FTC do. And at the end of the day, if you are using sensitive personal data, that's one way of going at it that you would need to do a DPIA. But the other is just really thinking about where, what the business is doing is going to meaningfully impact consumers, either taking away options or giving them options. So I don't see that, for example, as like price variation for, you know, kind of common retail stuff. I do think that on the risk spectrum, as you're doing things that do personalization in ways that might get into, that might raise discrimination issues. I think that there is a whole area with this unfairness category on really thinking broadly on what discrimination means and negative impacting certain population groups. I think to me, that's where I think that's more likely to come up, thinking really practically. **Jonathan:** Gotcha. Gotcha. Thanks, Alysa. Related to that, this idea of who will read the DPIA, and when will they read it? Just specifically, what happens to attorney client privilege in that scenario where regulators are asking for DPIAs on a regular basis and they can read those. I thought that was a fascinating conversation. Can you shed some light on it for us? **Alysa:** Yeah, so I think, look, there's always this age old question of the privacy function and is that in the legal department or is it out of the legal department? And we see companies do that in a lot of different ways. Attorney client privilege is when, you know, you are providing protected — either you're the attorney working on your work doctrine, right, your work product, or you're advising the clients providing legal advice to the client. And that is different, think, a, it's from facts. It's different from facts. And b, it's different from a lot of business functions that end up being compliance, operationalized compliance. And so the DPIAs to be meaningful, you should have a component of that that really is the result of attorney client privileged advice, but the output — kind of a lot of that output — is gonna be factually based compliance. And so the way that I think about it is one, can you have an executive summary that really goes through all the core factual things? And that's like the smaller piece, which just is more efficient anyway to have a quick way to look through all your DPIAs. But then two, for the more in-depth ones, eighty percent, seventy percent of that probably is not privileged. Can you do a — make yourself have an easier time by having the part that you want to have privileged communication isolate that part and not only isolate where it appears, but who has access to that part. I mean, that's part of the journey to get to your final DPIA product. But the whole thing, I think the ability to keep a whole DPIA privileged if challenged is probably not very high. And we've already heard from many of the offices, like, they're going to expect that you produce it. They don't expect — they've made comments that, you're not waiving attorney client privilege, but I would not rely on those kinds of representations. I take the — put that control in your hands on what you intend to treat as privilege and have really good reasons for doing that. **Jonathan:** Gotcha. Awesome. That's what I loved about this session because, you know, frankly, I was worried about doing a session on risk assessments because I thought people do some things all the time. Like, they know this stuff intimately, but there's so much nuance to it and different states and there was so much benefit in people just talking about what they're doing and sharing kind of how they think about things. Of course, the perspective from Kelly Dry, which was amazing. All right. So July first coming along pretty fast here. What can we expect from regulators or what's in your crystal ball? **Alysa:** So July first, as we know, that is the key date where the regulators get to enforce these new laws in many of these states. And we had already heard months ago from California, for example, saying expect some letters going out on July second. We don't think that the other states that have new laws are gonna sit idly and quietly by. So my expectation is that we are gonna see a whole lot of press releases and they — these are not supposed to be laws just on the books. They are going to enforce. My sense — if California at least was an example in where we've seen some of the states, just based on their commentary and their emphasis in the regulations — I think digital advertising opt outs is still gonna be a priority area. We have, for example, from CCPA, we went to sale or share, and companies are still dealing with that in creative ways. So I expect we're gonna see more letters in that space. I think there's been a lot of focus on health information, and I can imagine that's a sensitive type of sensitive personal information that we're gonna see regulators also focus in on that topic. And then finally, I do think we're gonna see DPIA curiosity by some of the regulators, particularly Colorado. I can imagine asking businesses about that. I don't think that the first round of these kinds of investigations are regulators going out to sue companies. Don't think that, but I do think that these letters and asking what you are doing to comply, how you are addressing — I do think that there's going to be a decent amount of dialogue. I'm watching for any published business guidance that might go up, interviews with different representatives from the state AG offices. And then, of course, seeing what the California Privacy Protection Agency — they've got rulemaking, they've got these monthly meetings, are they hiring the auditors? Is there going to be that audit function where companies need to turn over, right, their risk assessments? And what does that process look like? How do we keep that — forget the privilege part of it — confidential? There's like pretty sensitive business proprietary information in those risk assessments and just really thinking through once CPPA starts that audit function, how that is all going to work and how businesses are gonna maintain the confidentiality of their materials. **Jonathan:** I thought I'd say this, but it's, like, actually pretty exciting. **Alysa:** I am biased, but I think it's just really interesting. I mean, look. At the end of the day, this is it's about data, and data supports business. It supports strategy. It supports intention. It supports trust. And it's really important to do it right. So we have gravitated to this field for a reason, but I think it's just gotten — it's in prime time. **Jonathan:** Awesome. Well, looking forward to staying tight on it over the coming weeks. Thanks, Alysa. I appreciate your time.
Next step
See permissioning infrastructure in action
Walk through the platform with a Ketch architect, or launch the free CMP today.
Get started in less than 5 min