Debbie Reynolds | LinkedIn
Guest Notes
- Debbie has more than 20 years of experience in digital transformation and data privacy with a background in library science and information management, which shaped her view of data flows.
- Widely published and quoted in outlets such as Bloomberg Law, Law360, PBS, Wired, and The New York Times, Debbie translates complex privacy law into practical business guidance.
- She was appointed to the U.S. Department of Commerce’s Internet of Things (IoT) Advisory Board and has served in leadership roles with IEEE on cybersecurity and next generation connectivity systems.
- Host of the long running, award winning “The Data Diva Talks Privacy Podcast,” which reaches a global audience across 150+ countries.
Key Takeaways
1. To be successful and achieve desired results, AI innovation requires governance and best practices in data management and strategy. Duplication is a huge problem, and it makes training AI more expensive. Data curation is the foundation of AI, and many organizations are missing it. They should understand why data exists, what data should be kept, and how it should be used.
2. Data deletion and end-of-life data strategy are major weaknesses. Data systems are created to save data, not delete it. Organizations are full of data generators, and they need to empower data curators. Without clear retention and disposal practices, data lingers often in neglected systems, which increases exposure.
3. Companies need end-to-end data ownership. Organizations should maintain a bird’s-eye view of the full data lifecycle. Most privacy failures aren’t malicious. They’re operational. Many incidents stem from mistakes, oversight, or poor governance, not intentional misuse.
4. Purpose and context get lost—and that’s where privacy risk happens. A key risk is data collected for one purpose is later used for another (e.g., phone numbers collected for multifactor authentication later being used for marketing), which can trigger compliance issues.
5. Old, unused data is vulnerable to attackers. Even if stale data has little business value, it can be highly valuable to hackers, and forgotten infrastructure (“old server in the back room”) becomes an easy target.