What 80 chief privacy officers are worried about right now

In this week's Privacy Huddle, Host and Head of Marketing Colleen Barry sits down with Co-founder & Head of Product, Maxwell Anderson, and Alysa Hutnik, Partner at Kelley Drye to unpack the watercooler conversations from the Consero Chief Privacy Officer Forum.
stream this episode on

Summary

Privacy Huddle Ep. 99 — What 80 Chief Privacy Officers Are Worried About Right Now, hosted by Colleen Barry with guests Alysa Hutnik and Max Anderson, recaps the water-cooler conversations from the Consero Chief Privacy Officer Forum in Chicago, where roughly 80 CPOs and heads of privacy from B2B, B2C, and mid-to-enterprise companies gathered.

The biggest recurring topic was data mapping fatigue. The traditional approach — 40-page questionnaires or expensive data-cataloging software — often fails to answer the real question: what do you actually do with the information once you have it? Alysa and Max advocate for a more flexible, risk-triage approach instead, using artifacts you already have (DPAs, privacy policies, vendor documentation, website tag and pixel traffic) as low-cost signals to surface your highest-risk data flows, rather than chasing a perfect, exhaustive map. Max even floats feeding your list of licensed marketing tools into an LLM to get a fast, directional read on likely risk areas — a useful starting point, though not a durable substitute for real diligence.

Legacy vendor exhaustion came up constantly as well. Companies are increasingly shifting from three-year contracts to one-year renewals, but many still wait too long to start evaluating alternatives — often only four months out from renewal instead of starting the search early.

A third major theme was the industry's unhelpful fixation on the word "cookie." Max pushes back hard on the idea that a cookie banner alone satisfies do-not-sell or do-not-share obligations. In practice, most companies route opt-out requests through a separate web form that isn't integrated with their consent management platform, so tracking and data sharing continue even after someone submits a request — a gap that recent California settlements have specifically called out. Fixing this requires connecting the rights-request system and the consent system so a single action actually halts data flows across both.

The conversation also covers the identity and cross-device problem: many privacy teams assume they don't do identity resolution, when in fact they likely do simply by using common marketing and advertising tools (Facebook being the clearest example) that have identity matching built in. Aliya's advice is to presume you're doing it and verify with your marketing team or by reviewing vendor documentation and product marketing language for identity-related capabilities.

The episode closes on a broader point: settlements reflect regulator expectations from a year or two prior, not necessarily today's standard, and it's a mistake to assume enforcement only targets large enterprises. State attorneys general coordinate closely with one another, and companies of many sizes have faced action — meaning the underlying obligations likely apply more broadly than most privacy teams assume.

Transript

Colleen

Hi, folks. Welcome to another episode of the Privacy Huddle. I'm your host, Colleen Barry, and I lead marketing at Ketch. The Privacy Huddle is our weekly show where we talk about privacy, data privacy, headlines, tips, tricks, best practices and the like. Today, I am joined by two of my favorite guests, Alysa Hutnik and Maxwell Anderson. Say hello. Introduce yourself for the audience here. Alysa?

Alysa

Sure. Alysa Hutnik and I am delighted to be here and I am delighted that you are here in DC.

Colleen

Yes, I should say that. We are in the lovely Kelly Dry DC office and their wonderful podcast studio today. Max?

Max

Well, hello.

Colleen

So warm all.

Max

I know. Right? Excited to be on. I'm Max Anderson, one of the cofounders and head of product at Ketch. I'm also excited to be in DC with all this lovely lighting.

Colleen

And you too.

Alysa

It is.

Colleen

It's a more professional environment than we're used to on our typical Zooms, but we're — I think we're learning to love the spotlight.

Max

It's working for us. Yeah.

Colleen

So today's episode, I wanna talk about conference FOMO, really. Right? I mean, we all have it. There's way too many privacy events in this industry. We can't make it to all of them. But Max and I were lucky to attend one great kind of small format event last week in Chicago, the Consero Chief Privacy Officer Forum. And we thought it would be helpful for you all to spend an episode talking about just the water cooler topics at the conference. It was about eighty chief privacy officers or heads of privacy in their organizations, huge gamut of different types of privacy leaders, whether they're B to B, B to C, mid to enterprise sized companies. And so thought it would be helpful to just spend this episode talking about what seemed to be top of mind for folks at that conference and break these topics down. So I have a few I'm gonna run through. One I wanna start with that we heard a lot in Chicago was the topic of data map and data map investment. I think it's been top of mind for a lot of privacy leaders over the last several years as far as just — do I need it? Should I move from manual to tech? What's the importance of it? And that was a continuing trend at Consero last week. Just the question of do I need a data map and is it worth spending the time to do one correctly or real time? Alysa, I would love to start with you on this because I think the data map requirement has evolved considerably in the last ten years as far as we often try to go back to asking ourselves, what's the problem we're trying to solve here? And data map, I think the problem we're trying to solve has evolved. Can you talk about that from the legal perspective?

Alysa

Sure. So I'll start with a very practical premise that privacy teams are obviously inundated and there's a lot of what I would say luxury items, the things that they would like to have to make a, you know, robust top tier privacy program. I think most teams though in terms of budgeting had to do what — what do I have to do? What is must have versus what is nice to have and at least make some of those distinctions. And unlike, let's say go back a few years but unlike GDPR where you had a ROPA requirement, you don't really have that, you know, kind of historically in the US and so when we would think of data map, most lawyers think of a forty page questionnaire that they have to then go find the people, they have to get the people to fill out the questionnaires, the answers are inevitably people don't understand, right, they don't collect any data. You know, you get a lot of those things and the goal, I would say years ago, was you'd get the data map and you'd use that to compare with your privacy notice to make sure that the privacy representations were accurate. I would fast forward to the present where we now have a data map requirement. We've got it at least in California's regulations and we have it in a draft regulation for New Jersey and I think for many, they're thinking a data map and using technology. Well, first of all, what does that even mean? Right? Is it that whole enormous massive evaluation of our environment? Where are the people involved in this? And then is it gonna unearth so many things that I'm not prepared to solve for? So I think one — and I'd love, Max, to hear your perspective on this. Like, can a data map actually be flexible on what it's trying to solve for? Because that's — I think we get stuck at the massive picture as opposed to really triage and focus on where it could be enormously helpful.

Max

Yeah. That's the number one failure mode, I think. What, twenty nineteen, everyone would say, can't run a privacy program without a data map. And there were kinda two schools of implementation. One was the laborious survey you mentioned. And then there's kind of a security adjacent category of software, data cataloging, which kind of became data governance, whatever that means. But it was basically a connect to all of your systems and at high expense and very, very long implementation cycles. At the other end, you would get a long list of factoids that you've collected in your various systems. The thing that I always felt problematic about that pattern was, what do you do with it? Right? Like, great. I now know that there's this factoid in this system. What do people do with it? That question is still unanswered. And so one of the things that, at least, we've been trying to figure — implement are patterns where you can use factoids that are indicative of what you're doing that don't require the same expense. For example, your DPAs have really interesting, you know, factoids in them about what you're doing with data with regard to what vendor you're using. Or your privacy policy. I mean, of course, you're always trying to make sure it's in check, but it's a useful starting point. And a lot of people can make the mistake of spending two million dollars on the perfect kind of data discovery and classification product, but it in and of itself doesn't lend itself to managing privacy risk, right? Oh, do I have sensitive data that's being targeted in Facebook ads? You can know that by just looking at the website. You don't necessarily need to go connect directly to Facebook to figure that out. So I think a lot of people are struggling with the — oh, am I implementing data map, you know, juice worth the squeeze? I think it depends on the product that you're buying. That's a big part of it. And then the tactics that that product actually takes to solve this problem without necessarily burning two years and two million.

Colleen

But let's use that Facebook example. You say you can get an idea of what's happening in Facebook just by looking at the website. You don't necessarily need to connect to Facebook. I mean, that makes me think that you're talking about a different product than people would typically think of as their data mapping product. That's like website scanning or something outside. What is a data map? Right? I mean, that's maybe too existential of a question.

Max

But yeah, you can learn a lot about what your company is doing through inferences that are not dependent on connecting directly to the system. You can call it website scanning, but the fact that data leaves the browser and goes into Facebook on your website and I look at the data that's leaving the browser, I can tell you what's inside Facebook because I watch it leave. The other useful set of ingredients are just business terms. If you read Facebook's business terms or any of the service providers that you engage with, their service terms or, you know, policies will say a lot about the types of use cases that tool is meant to address. One tick further, the documentation of those tools. Go parse through documentation of any of these marketing tools you'll, you know, use and you'll read all the instructions for how to facilitate lookalike modeling. And you might not know what that is as a privacy pro, but it's important in the context of privacy. In none of those are we connecting directly to the system. And I think that's a — I think a tool or a tactic that's underutilized in the context of figuring out what am I, you know, what am I doing with data.

Alysa

The way that I would look at it is, I mean, data map is such a persistent terminology. That's what we recognize it as. But prioritized risk assessment in action. Right? Because if I can know the data flows that I think really present the biggest and the largest risk to the company and focus efficiently on in real time and in a dynamic way, what are those high risk situations so I can, you know, put my resources towards mitigating those risks as opposed to getting kind of looking for the needle in the huge haystack where ninety percent of those data flows are just not gonna be an issue.

Max

Exactly. Like, that's — that actually is a big needle mover.

Alysa

It is. And it's very available. Now, Claude, pick your LLM of choice, get through all the these relevant documents, and just ask the question. What are — what are my teams probably doing with data by virtue of knowing these are the systems that we've licensed? And you'd be astonished at how far you can get and at least, you know, prioritizing a list of risky things that are happening.

Colleen

That makes a lot of sense as you say then. Guess that's what — if I'm in the privacy practitioner in house seat, it makes me wonder how much I really need a tool or just what to decide to buy. Back to your point about what is a data map and all these different tools kind of accomplish some part of understanding risk across the business. So I think it's tricky from a buyer standpoint.

Alysa

It is. And I don't think that the roll your own clot approach is a durable long term solution. I think it's mostly just intended to be evocative and demonstrative of what's possible now without necessarily doing the traditional survey or connect all my data. Both those things are useful, and they actually have to work in concert. You need to take ingredients from, you know, this area, this area, and this area to get the perfect answer. But again, do you want to burn two years getting to the perfect answer? Or do you want to get to a better answer now with, you know, whatever risk that has inherent in it, at least you're doing something. And everyone stalls out with a two year project and a two million dollars price, you know, and they get nowhere. And then now you're going back to your executive leadership team saying, oh, sorry about that. I didn't know it was gonna be so hard. The engineers wouldn't do this or whatever happened. You wanna have something on the board that at least advances.

Max

Yep.

Colleen

I love it. There's so much conversation about data mapping. In addition to that, another one we simply couldn't get away from, just to state it bluntly, was lots of conversation about, "I'm exhausted with my legacy vendor." We just — this is the topic that just continues to live on in privacy conference after conference. And maybe, you know, being you and myself, Max being at Ketch, we maybe get a little bit more of the brunt of that. But just many conversations that start with, "I'm just I'm fed up with the legacy vendor. What else is out there? What else should I be doing?" Exhaustion from bad customer support to, don't know if I'm complying with the current laws, but just in a sense, it's frustrating that this continues to have so much cycle at a conference like this.

Max

Yeah. And it probably isn't gonna end. The one thing I thought was super interesting is all of these customers are moving to the one year renewal.

Alysa

Yeah.

Max

And the one — the one thing that so they're setting, you know, at in mass, companies are setting themselves up to make the move. They're not resigning three year agreements. The thing I think most people, when I ask them, okay. Great. So you've done the one year renewal. When are you gonna start looking? He's like, oh, I've got nine months. And I think that's the big trap. About fifty percent say, oh, you know, I'll start four months before I need to move.

Alysa

And then I'd say half of them would also say, I'm gonna — I'm looking now. By the time there's six months left, I should have signed, and then we're doing the migration.

Colleen

Absolutely. Yeah. And then as we talk about and heard those conversations about the legacy vendor exhaustion, that certainly led into just what are people looking for on the consent side and front end side of their privacy program. We hosted a breakout at the conference on just the intersection of privacy with a lot of this front end data collection and marketing teams and such. And, Max, I know you were getting so fed up with some of the terminology folks were using to describe their consent management solutions. And you have to let us in on what was driving you crazy in this roundtable.

Max

Cookie. The word cookie. I'm waging a holy war against that — the invocation of that term because it's really actually quite frustrating. So you see settlements that come out, you read the regs again, and people still say, if I can get my cookies under control, I'm good. And it just couldn't be further from the truth. And you would think after a session like that, everyone would come away saying, you know, perfect. I fully understand now. But really, it's only about twenty percent. And the rest, you know, they come out and say, great. I gotta — I need a cookie banner. And it's just — I'm certain I don't speak English well enough because that's the bottleneck, because I'm of the belief that the words coming out of my mouth would necessarily mean that we have a shared understanding that a cookie banner won't solve this problem. But you asked, I answered. It's a little frustrating.

Colleen

But, Alysa, you and I have talked about this on the podcast before. I can recall kind of an excited response from Alysa a couple episodes ago on stop calling it a cookie banner. So you have the same requests that come to you.

Alysa

I do — because you're spending so much time talking about cookies and burning money talking about this cookie banner and it doesn't solve your problem. Like, why spend all the energy if you don't at least diagnose what the problem is correctly and make sure your solution maps to the actual problem? And I think, I mean, unfortunately you have a lot of people asking the wrong questions and so they don't know if they're getting the right answer. And I mean, I see across a lot of vendors and so I think there's some high level talking points that if you don't know the right questions, it sounds like it's going to solve your problem — and we have, you know, we have a trio. Right? We've got the wire top demands. They look, you know, smell, walk, talk a little bit different than they did maybe a year or two ago and websites have gotten more modernized in terms of what the marketing team wants to do. But at the end of the day, that should not cause you to have more of a legal problem. And I just don't see folks really thinking about what are my state law compliance obligations, what are my litigation, risk mitigation questions, how can I harmonize those and not kind of amplify one over the other?

Colleen

So let's take a few minutes because this is I think an important topic for folks to understand and break down a few of these concepts. Max, I want to start with — when people think about a cookie banner on their website, they often think that they're solving for basically the number one enforced issue in privacy compliance, which is opt out of sale, right, do not sell requests. If a privacy practitioner implements a cookie banner, does that solve for the do not sell request as stated by regulators and in orders?

Max

I mean, I don't believe it does for a bunch of different reasons. And the first one is most people implement do not sell through a form, which I think is the right reason — I don't know if we have enough time to unpack all of those reasons. But if we look at the last two settlements, it seems pretty clear that if you start the do not sell process through a form, there's expectation that having submitted through the form, the sale and share is halted. And if you look back at the website after you invoke that right through the form, you'll see, you know, data being collected or things that are happening that would constitute a sale or a share. And the reason for that is the form implementation pattern doesn't talk to the CMP, the cookie banner, whatever you want to call it. That is the system that is responsible for controlling the data that is being collected on the website. And so those things necessarily need to talk to each other. If you just bought a cookie banner, there is no integration between those two things.

Alysa

Because your cookie banner probably didn't come with a web form.

Max

Exactly. And they're not integrated. And then lastly, could say, well, I'm gonna — I'm gonna — I'm gonna take the request and I'm gonna do all my do not sell through, you know, a switch on the cookie banner. But you've still got offline obligations. You've got data and use cases around data that is tethered to an email or an account ID or something like that where you can't get to that side of the house from just a cookie banner. It's kind of why you need to start with the form, but the form needs to necessarily talk to the CMP as well.

Colleen

So I think it's worth restating this because this was a point of contention in the discussion that we had last week in Chicago. Right? A consumer fills out a web form. They submit the do not sell or share request to the business, but nothing happens in the banner or on the website — tags or trackers that are firing. Those continue to fire regardless of the choice or request submitted in the form. You stated in the discussion in Chicago that it's possible to connect those things. Right? It's possible to have a consent system and a rights system that connect. And I saw a gentleman in the room raise his hand and ask you, "I don't think so, man. That's not possible. No one's doing that today."

Max

Yeah. Everyone's entitled to their opinion. And I'm happy to show anyone who wants to see it. Right. It is possible. Of course, it's possible. I don't think most vendors have done it, but it's possible.

Alysa

Right. Can I just repeat that point? Because what I see is most people, they have a banner. That banner may or may not present some problematic choices in language. Let's just say they've got the right language, it takes them to their CMP, right, where they can move the toggle because that's what they're thinking, they're thinking cookies, like cookie preference center and they can move the toggle — and sometimes they've updated the language in that form so it looks like it's opt out of sale share and they move the toggle and somewhere — messaging about — if you'd like to fully opt out of sale — Yeah, click this link and separately ask you to fill out the form and many people are not filling out the form. So I get your point, Max, like it should be the form and form should be holistic because you have to deal with all of these. That doesn't comply. I mean, that was emphasized in prior California settlements. They don't care that it's hard.

Max

Yeah. Right. They don't. They're looking at all the marketing practices. They're looking at the way you are connecting and following up with the consumer for a business purpose.

Alysa

You need to also do the compliance mapping to that. So you gotta both mitigate your SIPA risk and you gotta comply with state law. It's gotta be frictionless.

Colleen

Well, the frictionless — alright. You used a buzzword.

Alysa

I know. So I wanna unpack it. It — I will say, maybe zoom out of it. It's gotta be easy and they are counting how many steps in clicks. And when you add the form in addition to your cookie, that — they think that that is too many steps.

Max

Too many steps. Should be seamless if you know who I am.

Colleen

So should I excise the word frictionless from my lexicon?

Alysa

I don't know. So frictionless is used — I'm gonna totally nerd out for five seconds. It's used in the California regulations for when you don't have to do certain things, but I don't think it was a realistic carve out because nobody's doing only cookie based targeting. And it was frictionless like, essentially, if you're only doing cookie based targeting.

Colleen

I see. Interesting. Okay. And so back to the cookie banner tech. Right? You need to think about this from your website tags and website data collection as well as your internal and downstream system.

Max

So in the case of a cookie banner, no matter how perfectly your trackers and tags are categorized, if you're not connecting it to the web form, it's not gonna do the job. Right?

Alysa

Yeah. Necessarily. Yeah. It's not compliant.

Max

Exactly. It's not compliant. But I will also say that's not everybody. I mean, that's a huge problem and if we could solve that, that's enormous. I think most people when they, you know, in the room in Consero, like, they never had to learn ad tech. They don't know who the marketing — kind of all the different ways that tags are getting to the site. There was no kind of here is the centralized way in terms of where tags get approved and so in many ways it is your digital wild west and they're trying to figure out the facts of it as well as the legal side to it as well as the tech side to it.

Alysa

Right. And put those two together and, you know, they're looking for, I think, something that sounds like it's the right answer.

Colleen

Yeah. Exactly. It's funny you say that because it's a little bit back to our data map conversation. Because the privacy pro doesn't know — by virtue of using this vendor, whether it's Facebook or someone on the e commerce site, then one of their email sending tools, they don't know how these tools work and what they're actually doing with the information, so they don't know that they have compliance risk that they, of course, do based on recent settlements.

Max

The identity problem is the perfect example of that. You've got cross device obligations, what I'm sure we've all read about, but most customers will come to us and say, well, I don't do that. Like, but you do. You just don't know that you do. And when you've got Facebook in play, you're benefiting from cross device capabilities. They're just embedded in that product itself.

Colleen

So how should a privacy practitioner figure that out? Like, if you're saying you think your business doesn't do identity for advertising, monetization, whatever, but you probably do — how do they go about doing that?

Max

And you can buy software that'll tell you that answer. But if you wanted to roll, you know, roll your own, I would start with the policies of all of these tools that you use. Maybe somewhere in the DPAs we've seen in some cases that it talks about that and — or the documentation of tools. And I would just say, presume you are. Your marketing team is. I just don't find it believable that they're — it's just that is the reality of what it means to make yourself present today. So one, fight the bias and just say you are doing it. Talk to your marketing team. You'll get that answer pretty quickly.

Alysa

Or just ask, what are the top ten tools your marketing team is using? Go to the website and look at the way those products represent themselves and ask your machine. Here's a URL of a company's website. Tell me whether or not based on the way that they market that product, if they do identity management. And they say, oh, you know, single view of the customer and cross channel blah blah blah, that's identity.

The other point that you raised, which I think is a good one, folks said that's hard. Like, nobody really does that. Right? That's not really possible to make that so seamless in terms of a one step opt out of sale or share — and it is hard because most vendors don't offer that capability so you're either building yourself or you're using an option that does provide that capability. And I think you can make the mistake of saying, well, I'm seeing a lot of websites that don't offer this, so this can't be what is legally required. And I would just say having spent some quality time with the California agency's office, that is required. It is very clearly required. And it's required because most companies are benefiting from the same tools and techniques for, you know, the marketing angle.

Colleen

Is that essentially the crux of it?

Max

It's — we know who you are, right? You have established, you either have an account, right? I'm logging in, I know who you are, or you're not — I'm gonna say this, this wasn't in the settlements, but if I know who you are and you're browsing my site and I'm gonna send you a marketing email when you abandoned cart, that means for commercial reasons, I have linked identity. And because I know who that person is, I also have to keep my compliance obligations mapped to the same business reasons, right? If I have the business capability, I've got the legal capability. So understanding whether or not this is a triggered obligation is somewhat related to the knowledge of how your marketing tools operate.

Alysa

Correct. And I'm gonna go back to the presumption, most companies are doing this. I think it's safe, but it's better coming from you than me.

Colleen

As a marketer, I agree. We're all playing with these things. We're all using it.

Max

Yeah. Yeah.

Alysa

I just — I mean, I think we assess compliance based on settlements and settlements are a point in time in the past. Right? I mean, by the time a settlement becomes public, you're talking about two years, one year of facts before then. So the regulators' expectations continue to also get updated. And I think it's incredibly important to look at what is your marketing team doing? What are current practices today? What drives the most revenue? What are really important tools? And then think about how does my privacy side to this? You know, how do we map to it from a compliance standpoint?

I think the number one hope that I have for anyone watching this is, and what you just said, and this is something I hear all the time. Right? We'll talk about, you know, one of the two companies in the most recent settlements that say, oh, that's a big Fortune one hundred company problem. That's a — that's a this company problem. We don't have this, you know, we don't have this obligation. They are more complicated. They're more sophisticated. They built their own identity framework. We don't have any of those sophisticated things at play.

Colleen

It sounds like you're saying most companies do. They just don't know it, and they have the same problem that any of these companies recently settling in in the news had.

Alysa

So I'd say that's true. And I'd also look at the past settlements. They're not always with enterprise companies. I mean, if you look at who — I mean, California is a very good example. They have settled and CalPrivacy has settled with not necessarily all enterprise size. But I would also say the other state AGs, there are other states and they're also, you know, I would say have a diverse set of targets that they're focusing on. And I'll go back to a point we've said before — is those enforcers all talk to each other a lot.

Max

Yep. A lot.

Alysa

And they really are trying to harmonize how they interpret their laws as much as possible. And so I would just keep that in mind too when you take a different state by state approach.

Colleen

Great advice. Well, Alysa, Max, it's been a pleasure. Thank you as always for joining me on the huddle. And folks, we'll see you next time. Drop a comment below if there's any topics or things you'd like us to cover.

Subscribe
to the
Ketch Up newsletter

Trend watching, best practices, case studies, latest Privacy Huddles and more. Once a month, straight to your inbox:

Related episodes

view all episodes