The Shifting Privacy Left Podcast

S3E8: 'Recent FTC Enforcement: What Privacy Engineers Need to Know' with Heidi Saas (H.T. Saas)


Listen Later

In this week's episode, I am joined by Heidi Saas, a privacy lawyer with a reputation for advocating for products and services built with privacy by design and against the abuse of personal data. In our conversation, she dives into recent FTC enforcement actions, analyzing five FTC actions and some enforcement sweeps by Colorado & Connecticut.

Heidi shares her insights on the effect of the FTC enforcement actions and what privacy engineers need to know, emphasizing the need for data management practices to be transparent, accountable, and based on affirmative consent. We cover the role of privacy engineers in ensuring compliance with data privacy laws; why 'browsing data' is 'sensitive data;' the challenges companies face regarding data deletion; and the need for clear consent mechanisms, especially with the collection and use of location data. We also discuss the need to audit the privacy posture of products and services - which includes a requirement to document who made certain decisions - and how to prioritize risk analysis to proactively address risks to privacy.

Topics Covered

  • Heidi’s journey into privacy law and advocacy for privacy by design and default
  • How the FTC brings enforcement actions, the effect of their settlements, and why privacy engineers should pay closer attention
  • Case 1: FTC v. InMarket Media - Heidi explains the implication of the decision: where data that are linked to a mobile advertising identifier (MAID) or an individual's home are not considered de-identified
  • Case 2: FTC v. X-Mode Social / OutLogic - Heidi explains the implication of the decision, focused on: affirmative express consent for location data collection; definition of a 'data product assessment' and audit programs; and data retention & deletion requirements
  • Case 3: FTC v. Avast - Heidi explains the implication of the decision: 'browsing data' is considered 'sensitive data'
  • Case 4: The People (CA) v. DoorDash - Heidi explains the implications of the decision, based on CalOPPA: where companies that share personal data with one another as part of a 'marketing cooperative' are, in fact, selling of data
  • Heidi discusses recent State Enforcement Sweeps for privacy, specifically in Colorado and Connecticut and clarity around breach reporting timelines
  • The need to prioritize independent third-party audits for privacy
  • Case 5: FTC v. Kroger - Heidi explains why the FTC's blocking of Kroger's merger with Albertson's was based on antitrust and privacy harms given the sheer amount of personal data that they process
  • Tools and resources for keeping up with FTC cases and connecting with your privacy community 

Guest Info

  • Follow Heidi on LinkedIn
  • Read (book):  'Means of Control: How the Hidden Alliance of Tech and Government is Creating a New American Surveillance State'

Send us a text



Privado.ai
Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans.

TRU Staffing Partners
Top privacy talent - when you need it, where you need it.

Shifting Privacy Left Media
Where privacy engineers gather, share, & learn

Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.

Copyright © 2022 - 2024 Principled LLC. All rights reserved.

...more
View all episodesView all episodes
Download on the App Store

The Shifting Privacy Left PodcastBy Debra J. Farber (Shifting Privacy Left)

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

17 ratings


More shows like The Shifting Privacy Left Podcast

View all
The Lawfare Podcast by The Lawfare Institute

The Lawfare Podcast

6,277 Listeners

The Digiday Podcast by Digiday

The Digiday Podcast

103 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,010 Listeners

DataFramed by DataCamp

DataFramed

270 Listeners

AHLA's Speaking of Health Law by American Health Law Association

AHLA's Speaking of Health Law

28 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

142 Listeners

Practical AI by Practical AI LLC

Practical AI

195 Listeners

Our Curious Amalgam by American Bar Association

Our Curious Amalgam

42 Listeners

Serious Privacy by Dr. K Royal, Paul Breitbarth & Ralph O'Brien

Serious Privacy

24 Listeners

POLITICO Tech by POLITICO

POLITICO Tech

391 Listeners

Privacy Please by Cameron Ivey

Privacy Please

28 Listeners

Surveillance Report by Techlore & The New Oil

Surveillance Report

89 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

120 Listeners

The Privacy Corner by Robert Bateman

The Privacy Corner

1 Listeners

The AI Fundamentalists by Dr. Andrew Clark & Sid Mangalik

The AI Fundamentalists

9 Listeners