Verizon’s privacy counsel on risk assessments, children’s privacy, & leveraging AI

In the latest Privacy Huddle, Colleen Barry is joined by Aubrey Wesser, Managing Associate General Counsel for U.S. Privacy at Verizon, for a candid look at how a major US carrier operationalizes privacy assessments, children's privacy DPIAs, and consent UX that regulators—and customers—can live with.
stream this episode on

Summary

Building a privacy program inside a large, US-centric consumer business often starts under pressure: after California's CCPA landed, teams that had finished GDPR work still needed a different playbook for domestic consumer operations. Practitioners who moved into privacy without a prior specialty frequently learned the law alongside everyone else, then stayed to own ongoing compliance across products, marketing, network, sales, operations, fraud, and finance.

Assessment programs at scale typically blend several layers. Product reviews serve as privacy by design—documenting what data is collected, how it is used and shared, and what requirements apply. Formal PIAs and DPIAs address sensitive or novel data uses required by state privacy laws, while children's privacy statutes increasingly demand harm assessments for products used by kids. Vendor risk reviews, retention and governance documentation round out the stack. The operational challenge is making those reviews repeatable for business teams without turning every launch into a bottleneck.

Enforcement and litigation are also pushing companies beyond cosmetic notices. Recent cases and settlements emphasize frictionless choice and real backend control: if a banner looks compliant but data collection continues unchanged, regulators and plaintiffs will notice. At the same time, notice fatigue is a genuine customer-experience risk—especially for utilities like bill pay and support—so the strategic goal is seamless UX paired with infrastructure that can honor choices instantly. Companies should treat consent as a full-stack problem, not a front-end widget.

Transript

Colleen

Hi folks. Welcome to another episode of the Privacy Huddle. My name is Colleen Barry. I lead marketing at Ketch and we are absolutely thrilled to have you here today. If you're a first time listener, the Privacy Huddle is our weekly series on data privacy. We talk about data privacy news, trends, best practices, tips, you name it. And I am thrilled today to have a new guest on the show. We have Aubrey Wesser here, the Managing Associate General Counsel for Privacy at Verizon. Aubrey, it is such a pleasure to have you on the huddle. Thank you so much. It's such a pleasure to be here. Yeah. Absolutely. So Aubrey and I are just gonna chop it up today. So excited to dive in on a few different topics. And, of course, as you might notice, we are in the lovely Kallie Dre podcast studio. So a huge thanks to Kelly Dry for letting us use their space today. And it's nice and local for Aubrey who's based here.

Aubrey

Yes, yes, and based out of DC.

Colleen

It's I would love to just start with some background because as I've learned talking to many in house practitioners, most people didn't follow a super straight line into their privacy career. So tell me, how did you end up in privacy?

Aubrey

Yeah, so I came into Verizon right out of law school and I was on the antitrust team doing competition work, was my first love. And after several years, I started to want to expand into something else and try something new. And I thought that something in the consumer protection space was a good next step and it kind of bridged my experience in antitrust. So I let my leaders know I'm interested in something new and I always tell young lawyers a year passed before anything came of it so you can't get discouraged. And in that year, California passed CCPA. Now Verizon is a very US based business. Our entire consumer operation is in the United States. It's not international. And the team had just finished GDPR compliance. But none of that compliance was particularly helpful for our consumer business in the United States. So they needed help and they needed help fast. And so I was put into a privacy role for eighteen months helping them get compliant with CCPA. And at the end of the eighteen months, decided to stay. So I've been there for about eight or nine years. Wow, that's an amazing run.

Colleen

Cool. And what amazing timing with CCPA

Aubrey

It was a really perfect timing because I didn't have privacy background, but I was learning with everybody else. We were reading the same law for the first time and nobody had any extra like benefit for having worked in privacy. So it was a really great time to jump into the privacy world.

Colleen

I think that's one of the cool things about this industry. Just everybody kinda came up at once, like, reading the laws together. So, yes, everyone's on even footing, figuring it out together. I love that part of it. So tell me more about your role today at Verizon. I'm sure you've come a long way from your days of first eighteen months. What does your role cover now?

Aubrey

So my team now covers US privacy compliance across all of Verizon. So that looks like advising on products and services and projects that the business comes up with. And we're looking at it from the standpoint of does this meet privacy principles? Is this compliant with the law? Is it compliant with our own privacy practices, our own privacy policies, and our own disclosures? And so then we're advising the business on here are your legal requirements, here's what you need to do to be compliant, here's how this product should look, here's what we recommend. And then we're also making sure it's compliant with all of these new state privacy laws and making sure that we're updating our individual rights responses to include any new data that we might be collecting and overall keeping the business running. We support both the entire US operations, so that's all US products and services, as well as marketing, network, sales, operations, fraud, and finance.

Colleen

Wow. That's quite runs the gamut for sure.

Aubrey

Runs the gamut.

Colleen

I love it. Well, I want to dive into a couple topics. One, this one I think is interesting because we hear I attend a lot of conferences in the industry, and I think one of the hottest topics right now is how do I make privacy assessments easier. It just continues to be such a bane of existence for many privacy professionals out there from collaborating with business teams to just repetitive nature of to you name it. And so I would love to hear more about what the privacy assessment looks like at Verizon and how you're thinking about tackling it and just this challenges surrounding it. So tell me about how you at Verizon structure your assessment program right now around DPIAs, PIAs, you name it.

Aubrey

Yeah. So as I mentioned, we do a product review. So we think of that as our privacy by design. We're looking at how is the product functioning, what data is collecting, how is it being used and shared. And that's also getting documented in some form along with privacy requirements. We also do PIAs or DPIAs and those some of those are required by state privacy laws and they're going to analyze any uses of sensitive information or unique types of data that we might have and what we're doing with it and how we're protecting it. And then there's child privacy laws, which I know we'll talk about later, but some of those have requirements in them that companies create a DPIA to assess the harm to a child for using your products. So we have those as well. We also have vendor risk assessments. So anytime we onboard a new vendor, we're looking at that vendor to understand what their privacy practices are and making sure that it's a vendor that we would want to do business with from a privacy standpoint. And then on top of that, we have documents on our data governance, on our privacy controls, and on our data retention. So a lot of documentation throughout the company and through all of our processes.

Colleen

Yeah. That's a ton of documentation. How are you keeping tabs on all of that?

Aubrey

Yeah. There's a lot of opportunity for clients and business people to come into the privacy office to ask for guidance. And it can be at the beginning of a product launch. It could be in the middle as they're launching a new feature or as a product is being sunset or again as a vendor is being onboarded. And so you need a program and a and a documentation process that gives these business clients an opportunity to come to you in various ways and various forms. There's no single entry point to talk about privacy with our privacy office. But you also can't have so many different forms or processes that the business is overwhelmed. Know, a single client might need to do a vendor assessment and do a PIA and do a product review and they may feel like they're answering the same question multiple times. And so you have to balance both of those goals and figure out how to de duplicate your questions and your documentation as best that you can.

Colleen

Yeah. When you're dealing with the business in those situations, do you are there common pitfalls you see? Like, if you see some kind of interaction between the business and your team, you're like, oh, I have to fix that. Or what are the common things you see that could end up point to point something better needed?

Aubrey

I often find when there's that situation, it's a rigid somebody rigidly following a process that was stood up without being able to step back and say, oh, you did this questionnaire, you did this process, you answered these questions here, let me leverage that and pull that in for you so that you're not answering them again. And then you have clients getting frustrated because they're answering the same thing again, but we also need to make sure that we pull those into our documentation.

Colleen

Yeah, that's so interesting and I think sometimes whether it's this topic or others, when you see that kind of, like, rigidity in following a process from a team member, it often just means they just need more experience, right, to understand what to look for in the business.

Aubrey

Yep, exactly.

Colleen

On this topic of assessment, so when we think about the solution, this area is so ripe for AI, right? It's just such a repetitive task. It seems like obvious to say, let's AIify assessments. This should all be a lot easier. But maybe that's scary for teams. There's also tons of tools out there claiming to AI fire assessments, genetic assessments, all that stuff. So what are you thinking about in terms of

Aubrey

learning our teams are using AI every day. It results in a more robust analysis. For instance, I asked AI what are five arguments for and five arguments against this legal framework? And then it gave me the answers. Some were more convincing than others but that gave me a jumping point to start my legal research which ultimately resulted in legal research that combated those arguments and resulted in an overall more thorough analysis. We also have AI tools now where we can take prior guidance and prior memos and all these documentations that we're doing and give it to the AI and then ask questions to make sure that we're being consistent and thoughtful across our approach. And then of course we're thinking about it in terms of a privacy intake and this documentation issue. AI could take an intake form and help the person filling it out, the business client, fill it out in a more robust way. Help them craft a description of what they're trying to do that's a little bit more accurate or something that somebody can understand who's not immersed in what they're trying to build. And then on the other hand, when they're filling it out, if it says something like facial recognition, the AI can say, okay, here's a new set of questions that you need to answer because we understand, I understand, it understands that product involves sensitive personal information. And that means when it comes into our team, it's more robust, it's more accurate, it's something that we can actually rely on. But then the AI can also do things like help us issue Spot once it has that fully completed intake and then hopefully it can tie things together so it can take the intake, tie it to our guidance, tie that to a PIA so that we have a string of these documents all connected together without having to ask the same question again and again and again. Yeah. And some of this stuff has been around for a while and AI can do has been able to do that automation for a while. I think what's changing now is everybody's access to the tools and ability to leverage them.

Colleen

Absolutely. So how are you thinking about tackling adoption with your team? I mean, as you talk through that, is it still hypothetical for you and kind of biting off a little bit at a time or are you underway already? Like what are how are thinking about the road map?

Aubrey

We're sort of in the middle, I think. There's our company is has been extraordinary about doing AI training which has really helped with employee adoption. And our Chief Legal Officer Vandana Venkatesh has done specialized legal training to help us understand how it can apply, how we can apply AI in legal analysis or in legal thinking or in legal workflows. So that's been really helpful and it's really helped employee adoption. Where we are still trying to figure out how to get over the hurdle is moving as quickly as clients are moving. So I want to develop a legal intake, but the business isn't waiting for me to do it. They're gangbusters. And so we have to get in front of that and hurry up and build something that's going to work for everybody.

Colleen

Yeah, no doubt. I'm sure just about everyone listening has that issue as well. The business always wants to move so fast. So fast. Yeah, exactly. Well, amazing. I mean, what a journey, and I think every listener is on that journey as well. Let's move to another topic. I'd love to talk about children's privacy with you. We've been this has been a hot topic all year back from when we first met Aubrey at the Privacy State of the Union event here at Kelly Dry in D. C. Back in January but that was such a funny event because it was a single day event and we had sessions on, you know, just about every topic in data privacy. But I swear, even the topics that had nothing to do with children's privacy, children's privacy came up in every session. It's just such a top of mind thing for every business, even if a business isn't obviously marketing or selling to children. It's just such a pervasive issue. So from where you sit at Verizon, what do you have your eyes on as far as what's changed in children's privacy over the last six months? What's top of mind for you?

Aubrey

Yeah. There's definitely been quite a bit of change. And I think it's going to continue. It's definitely an area that's very hot. And we just found out, I think it was last month, the UK followed Australia and blocked kids from social media. In the US, you have a lot of school districts getting a lot of pressure to remove devices from class rooms. So there's just a really big focus on children's safety and online activity right now and I don't think that's going away. And so coming from that, we have just in the past couple of years a plethora of age appropriate design code laws coming into play. And each state is kind of putting their own little stamp on it. So they are very much a patchwork framework at this point. And then most recently, past six months, you have the App Store age verification laws coming out of Texas and California and a few other states. And those are really creating this interplay between all the child privacy laws because once you have age verification, you're then triggering these AADC laws as well as COPPA. And so you have to build an entire child framework when you might not have had to. And while a lot of the laws, COPPA and the AADC laws, were triggered by actual knowledge or by a service being directed to children, the App Store laws now give you actual knowledge. And so you're triggered even if you weren't triggered by some of these privacy laws before. You may now be in scope. Yeah. So and and like I said, it's a patchwork and so it's a very layered compliance approach that your products are going to need.

Colleen

Yeah. When you think about the state patchwork, is it are there enough commonalities that you're reassured or no, it's still just too

Aubrey

There's a lot of commonality but there's still a lot of individual requirements. South Carolina has some unique requirements including needing a third party audit. New York has some unique requirements and Maryland actually implemented a stricter standard. So you can't take a one size fits all. I saw this AADC law, know we're compliant with that so we're good. You really need to look at every single one of the AADC laws and make sure that you're meeting the letter of every law.

Colleen

Yeah, wow. And as we talk about this topic, for folks that are newer to it, there's so many terms thrown around with this from both the definitions of these concepts to the tech you hear like age verification, bins, gating, identity, like specifically when it comes to those concepts of age verification and then age assurance, how do you think about those differences for someone that's maybe newer to this area?

Aubrey

Yeah. So I think of age assurance as more like an age gate. Like somebody's coming in and they're saying, this is my age or you know this is a child or something like that and you're taking a reasonable approach. You're saying I have a reasonable it's a it's reasonable for me to believe that this is an adult. Whereas verification, you have something else like an ID verification where you're able to independently verify that that user is in fact an adult. Either way, you still have enough knowledge or constructive knowledge that you're triggering the laws regardless of which approach you decide to take.

Colleen

Yeah. Makes sense. So there's been a ton of legislation in this area, right? We've seen Texas social media upstream. When you think about the patchwork and then the national landscape as well, I mean, what's your prediction of where you think this is going? More complexity? Do you think you'll have more clarification on where you should bring your Verizon program? Like, how are you thinking about the future here?

Aubrey

Yeah. I think I think we will have more clarification. Right now, we have Texas, which is fighting its injunction and successfully fighting its injunction. So that'll be really interesting to see play out. And they text the plaintiff in that case just appealed to the Supreme Court, so we'll see what happens with that injunction and whether it sticks. Injunctions are always really interesting because the decisions have to decide the likelihood of success on the merits. And so in this case, the Fifth Circuit said, we think that the state of Texas is likely to succeed on the merits. So everybody should be thinking very carefully about how to get compliant with Texas's App Store age verification law today. And right after that decision, we immediately saw Apple and Google respond with additional guidance on how they're handling age verification and passing age to apps that want to be compliant. Even without Texas, we have California which takes effect in January. If you read the original decision from the lower court in Texas and you look at the California law, there are some significant differences. So I think California is less likely to be challenged or to and is more likely to withstand the challenge even if it is. So you have Texas now, you have California in January, and then we saw Louisiana amend their law in order to avoid a First Amendment challenge. So I think this is the way things are going and there's there's no turning back. We have to now deal with age assurance. And then it's gonna be up to each company to figure out how to actually comply and and what enforcement is gonna look like. And reminder that Texas has a private right of action. We'll see how that plays out. And companies that are just dipping their toe in need to first and foremost think about whether they're going to geofence their products and services. So are you only going to get age in the states that require it or are you going to get age for all of your users? The downside of getting it for all of your users is you may trigger AADC and COPPA, and you need to be prepared to do that as well as link your users across products or services that you might be selling. But if you do an age geofence rather, then you run the risk of the geofence not working or adding technical complexity to your solution or being inaccurate. So it's just a risk balance that every company is going to have to figure out for themselves.

Colleen

Yeah, that's great advice. It reminds me of the conversations when U. State laws were earlier and people were also still just getting used to GDPR and the conversations about do I just do GDPR everywhere or do I start parsing out these state laws and Exactly. Yeah. It's all about the risk tolerance, So interesting. Well, Aubrey, I'd love to touch on a few more things as we kind of close out here. There's always privacy headlines, always. Every week there's something new, I swear. Even when we were talking about having this conversation, there's been new updates to these headlines we were originally talking about. But let's touch on a couple that I think will be interesting to the audience. I'm sure we have privacy practitioners tracking these as well. I'd love to get your take on this VIPA case, right, the Video Privacy Protection Act. Of course, has been constantly in the headlines, these SIPA and VIPA demand letters and wiretapping claims and video pixel watching, and so now we have this very interesting case from Salazar who filed this case against Paramount, right, for supposedly sending his data to Meta. This is a case you've been watching, curious about how it's going to unfold. Can you, for the for the audience here, just kind of give your your recap on on what happened and and why it's interesting to you?

Aubrey

Yeah. So this was a case where Paramount, is considered a videotape services provider under Vipa, has a newsletter on a website that has nothing to do with that part of its business. And this individual subscribed to the newsletter and in operating their online site, Paramount has a Meta Pixel and the Pixel sends that user's information to Meta for purposes of targeted advertising. And when this individual realized that, they sued under Vipa. So the central question is going to be who is a consumer as defined by Vipa? Does it have to be somebody purchasing audio video material or could it be anybody buying anything from a company that happens to be a videotape services provider? So it's going be really interesting even if you are not in the videotape services provider space. I'm really interested to see what happens with this case in terms of digital advertising in the digital ad space with the pixels tags and cookies. And there was another case that was another Vipa case that the Supreme Court actually denied cert. So Supreme Court is hearing Salazar now. But this other case was asking the question, how do you define personally identifiable information under Vipa? And the Supreme Court denied cert. There's an equally circuit split going on on that issue, so it's really interesting to be able to see what they took up and why and what they didn't take up and see where the court focuses its attention. So that's why I'm really interested in that case.

Colleen

Yeah. And so with the Salazar one, is the implication that maybe depending how they rule, it could expand the definition of companies that need to be worried about these pixels on their site when it comes to video?

Aubrey

I think the companies that are videotape service providers will be the same. But the question is, is their risk going to go up? Are there other activities that they're viewing as out of scope today that may be in scope depending on how this Supreme Court decides.

Colleen

I got it. Okay, very interesting. Well, we'll keep an eye. Probably more headlines on it next week or so. And then the second case I'd love to kind of pick your brain on, Aubrey, is this Meta biometrics case, right? We've seen this group of plaintiffs in Illinois taking this case, again, against Meta. Give us your take on this one and why this one's interesting to you as I

Aubrey

just found this one interesting because the plaintiff alleged that they used some of Meta's voice to text features in Facebook and in Meta messages. And Meta also has a patent for voice prints and so or or technology that would create voice prints and so they are using those two facts together to allege that Meta created a voice print without providing notice and consent. A big portion of the plaintiff's claims were dismissed by the lower court. The the case is now in the Northern District of California, and Meta just filed a motion for summary judgment. The court denied the motion for summary judgment. They relied very heavily on expert testimony that plaintiff's counsel put forward that argued that the way Meta was processing the recording left a material issue of fact as to whether or not they in fact created a voiceprint. And so that case is going to go forward. I'm interested in seeing if Meta appeals or where that case ends up ends up going from here and if it ends up creating a roadmap for plaintiff's counsel.

Colleen

Yeah. Very interesting. I'm curious about that one as well. The biometrics topic is just so interesting. It feels niche but it affects so many companies.

Aubrey

So many companies.

Colleen

Yeah. Exactly. Well, Aubrey, it's been such a pleasure chatting with you. I'm so grateful that you joined us. Before we wrap up, I I have to ask you because there is so much on the privacy leader's plate today. One of the one of the number one things we talk about on this huddle is just just the overwhelm and prioritization and all these kind of things. And so I'm curious from your perspective if you think there is one issue that the community is underestimating or just just not talking about enough right now. Yeah. I would say

Aubrey

Cookies and Pixels global privacy control and the California **** cases that are that are out there affecting how cookie banners work. And I say that it it is getting some attention. It's not I don't wanna make it sound like people aren't talking about it. They're talking. But I think people may be underestimating the impact that it's going to have on the way our platforms work. And it's so important to companies that their website be seamless, provide the information consumers needed the the moment they need it. And banners can interfere with that and be a little bit difficult. You need to create a seamless experience and take the user's choice and build it into your back end all without losing the customer's attention or frustrating them. And I think that's the struggle that we should be talking about is how do we comply with these laws? How do we mitigate risk for a company, especially an online retailer, but do it in a way that creates a seamless UX and builds and can we build the back end infrastructure we need to do that and to instantaneously care for choice if we have to, but also give the customer the experience they want.

Colleen

Yeah. Such a great point. I mean, when I think about what the cookie banner, just to use whatever the term everybody uses, what what it needs to do. And I think about these recent cases, you know, Honda requesting frictionless and all these kind of things. Want it to be frictionless both from a UX perspective but then also from an actual data collection perspective if it's actually doing something on the back end and I think you see today a lot of environments where there's a disconnect between what the cookie banner looks like on the front end, but, like, you know, it's kinda like when the lights are on but nobody's home. Like Right. And that's gonna

Aubrey

get that's gonna get companies in trouble if there's nobody is home. Right? That's that's gonna be prime target for regulators. But also, I worry about notice fatigue Yes. And and customers getting frustrated seeing another banner and not being able to get to the site or do what they need to do or find customer care or pay their bill because they have to click through banners and notices. And so that's something that worries me in trying to figure out how to craft notices in a way that customers will read, that they will understand, and that meet their requirements of the law.

Colleen

Absolutely. Well, if US enforcement is any indication, I think we're gonna be seeing more settlements that talk about the need to have a good consumer experience. Yep. Well, Aubrey, this has been such a pleasure. Thank you so much for joining me. I'm so grateful. Thank you so much for

Aubrey

having me. This is wonderful.

Colleen

Absolutely. Folks, thanks for joining another episode of the Privacy Huddle. As always, if you'd like to hear about any topics or suggest any guests, please drop us a comment below. Thanks for watching. See you next time.

Subscribe
to the
Ketch Up newsletter

Trend watching, best practices, case studies, latest Privacy Huddles and more. Once a month, straight to your inbox:

Related episodes

view all episodes