Caveat 4.3.25
Ep 256 | 4.3.25

A make-or-break moment for businesses.

Transcript

Daniel Barber: I mean, I think consumers ultimately do expect control and transparency from the businesses that they interact with. There have been many studies that indicate, you know, if a consumer doesn't feel like they can trust a business, it's very unlikely that they'll continue working with that company.

Dave Bittner: Hello, everyone, and welcome to "Caveat", N2K CyberWire's privacy surveillance law and policy podcast. I'm Dave Bittner, and joining me is my co-host, Ben Yelin, from the University of Maryland Center for Health and Homeland Security. Hey there, Ben.

Ben Yelin: Hello, Dave.

Dave Bittner: On today's show, Ben has the story of a California lawmaker's proposal to regulate kids' use of AI companions. I've got the story of a reporter's 300-mile trek through rural Virginia in search of license plate readers. And later in the show, my conversation with Daniel Barber, CEO and co-founder of DataGrail, talking about why companies need to focus on privacy and compliance. While this show covers legal topics and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. [ Music ] All right, Ben, we've got some good stuff to cover this week. You want to start things off for us?

Ben Yelin: Yeah, mine's kind of a sad story. It comes from the technology section of the Washington Post. I've read a lot about these so-called AI companions. They're very popular among kids. Kids can talk to them about anything, but we've read high-profile incidents of kids talking to these AI companions, and the conversation turns to things like encouraging self-harm, suicide, et cetera. Things that are very, very dangerous. So one California lawmaker, State Senator Steve Padilla, is looking to put guardrails around the use of these AI companion bots. He and a couple of other California lawmakers have kind of knocked around proposals on how to regulate this. There are a lot of free speech concerns that come with it. If you set up the type of age verification that we have for pornographic websites, it might become too cumbersome for people to access these chatbots. And there are potential good uses, I think, for kids interacting with these chatbots. But ultimately, these chatbots, while they might seem like real human companions, are not human beings. They are not your parents. They are not a licensed therapist. And they aren't actually equipped to give teens, who obviously are far more impressionable than adults, they're not equipped to give them proper advice. So what this proposal would do -- it's California Senate Bill 243. It would require the makers of AI companion bots to limit addictive design features, put in place protocols for handling any discussion of suicide or self-harm, and undergo regular compliance audits. And then I think perhaps most importantly, and this is what will raise the hair on the arms of big tech companies in California, it would give users the right to sue if they suffer harm as a result of a companion bot maker's failure to comply with the bill. So what the state senator has said here is this is a common sense, pragmatic solution. I think the companies might play ball if it was limited to just putting guardrails around addictive design features, having those protocols in place to prevent suicide and self-harm. The audits are fine. But giving the private right of action, I think, is very concerning because you could get these scenarios where maybe a chatbot companion is 1% at fault for a teenager's tragic decision to inflict self-harm. That could still potentially be the cause of a lawsuit. So it could lead to a lot of litigation. But this bill is coming up as we're recording this, in a week, there's going to be a hearing on this in the California State Senate. So I'm just very curious to hear how lawmakers react to trying to put guardrails on this really novel tool here that I just I don't think we've really scratched the surface of.

Dave Bittner: Can we talk through the differences between the different ways of putting limits on access to something like this? I mean, I'm thinking about, you know, old school pornography, right? A Playboy magazine, you know. So before you had the Internet, a young man who's underage decides he wants to get his hands on a Playboy magazine. He would go to the newsstand and the person manning the cash register would say, hey, you know, you're too young to buy this. Beat it. Right? And that was the that was the gatekeeping. And of course, a lot of that's changed because things are available online. So my question is, like, about the proper placement of where the gatekeeping occurs. In the pornography case, I don't think people are saying we should not make a Playboy magazine like because they're legitimate, you know, adult uses and needs and enjoyments and all those kinds of things. But we understand that putting restrictions on it for underage folks is appropriate. I'm just curious, like in the modern age, your view on where can we place those pinch points to limit access?

Ben Yelin: Yeah. So there are a couple of options to do that. There's actually a really interesting piece of legislation that just passed in the state of Utah where the onus is on the app stores to require age verification. So it had previously been on the adult-oriented apps and websites. They were responsible for their own age verification to keep minors out, including things like social media platforms, Facebook, Meta, et cetera. But those types of laws, because they might inadvertently limit access by adult users, have been the subject of a lot of First Amendment lawsuits. We've talked about some of them on this podcast. Usually the plaintiff is NetChoice, which is a trade group representing a bunch of these companies. By putting it in the app store, that is kind of an end-around that might protect against some of these First Amendment challenges. The companies would be more supportive because they wouldn't be responsible for age verification. Just before a user downloaded any application, they'd have to submit to age verification measures, which I'm sure is making the Apples and Googles of the world not happy because they have to add a layer of compliance, at least in the state of Utah for now.

Dave Bittner: Huh.

Ben Yelin: I kind of have mixed feelings on it. I think there could still be instances where, especially if it's like a desktop application, or if we get to a situation where people can purchase apps outside of app stores, that there might be scenarios where that method of age verification doesn't work. But that's just one of the ideas that's floating around out there about how we can properly do age verification. I think kind of everyone agrees that we need age verification in some mode or method, but I just think there's disagreement on the best way of getting there.

Dave Bittner: Huh. It's interesting. I mean, a couple of things. On Apple's App Store, for example, I know with my own children, we had settings in place with sort of a family account for accessing things on the App Store where, for example, my teenage son wanted to install a new app. That request would come to both my wife and I, and one of us would have to approve it before the app could be downloaded.

Ben Yelin: Yeah, that's how we've kind of managed it with our kids as well.

Dave Bittner: Yeah. Now, my son recently turned 18.

Ben Yelin: You've lost that power now.

Dave Bittner: Well, yeah. My wife was like, well, I guess it's time to turn this off, right?

Ben Yelin: Yeah.

Dave Bittner: I was like, yeah, yeah, it is.

Ben Yelin: Yeah, I mean, we have the same thing set up for our kids for Facebook Messenger. We have to approve any new users. Our daughter has a smartwatch that is on school mode during the day, meaning she can only look at the time and do nothing else.

Dave Bittner: Oh, she's suffering.

Ben Yelin: These poor kids.

Dave Bittner: Right.

Ben Yelin: But we have to approve every contact she has because you can make calls even with these kids' smartphones. So parental approval is good. I always think about situations where, for one reason or another, a kid might need to access an application. There aren't parents around to approve it for them. Or you have irresponsible parents who are just approving things willy-nilly. The positive aspect of having age verification in an app store, at least potentially, is that it's a content-neutral restriction. So you're not focusing on specifically the adult nature of the app that somebody is trying to access. You're focusing on just having a gate that's kind of put in front of all apps altogether so that if anybody wants to access material that's designed for adults, no matter what that material is, whether it's pornographic, whether it's politically disfavored speech, if it's designed for adults, then there has to be some type of age verification process there. So that's the promising aspect of the approach that Utah is taking.

Dave Bittner: I also wonder how useful something like this will be because I know people, I have work colleagues who regularly interact with just the standard off-the-shelf ChatGPT as if it's a companion, and they just have conversations with it. I've talked to folks who say, I'll be in my car and I'll just start talking to it, and I find it interesting and comforting and thought-provoking and all those kinds of things, and that's not a version that's designed specifically for companionship. So if you have the power of that system capable of doing that --

Ben Yelin: Yeah, and then you mimic emotional connection.

Dave Bittner: Right.

Ben Yelin: I mean, that's the thing that the advanced companion chat bots are able to replicate that I think is dangerous, knowing to use those words that will evoke an emotional response.

Dave Bittner: So they're sort of pre-tuned to have an emotional attachment, and I guess use the history of your conversation for that sort of thing.

Ben Yelin: Yeah, and that's what makes it more addictive, is if you had any -- in the real world, a psychiatrist or a therapist who connected with you emotionally and understood and validated your concerns, you'd be more likely to want to keep talking to them. And chat bots are trying to replicate that.

Dave Bittner: Yeah.

Ben Yelin: But when you're talking about a licensed human-in-the-flesh therapist, they are bound by laws, rules, and regulations. I know that if anybody mentions self-harm or harm to another person, a licensed therapist is legally obligated to report that. You just don't have those guardrails around AI companions. And maybe it's one year from now, maybe it's five years from now, but I do think we're going to get to the point where at least some counseling is done through AI companions, even counseling that's recommended by medical professionals, just because the technological tools are getting so good and so advanced. We've seen great success at some schools that have experimented with AI tutors. And tutoring is a skill that's not just teaching kids about the actual content that they're learning, but also how to learn, how to write, how to do arithmetic. So they're relatively complicated tools, and they're working very well. So this is a problem that's certainly going to emerge in a more rapid way. And if we're going to leverage these tools, I think it's only proper that we have a mechanism for regulating them.

Dave Bittner: So real quick, refresh my memory on the challenges with restricting pornography online, the argument that age verification is a problem with free speech, and why that is.

Ben Yelin: It depends on the method of age verification, but sometimes you're required to upload sensitive documents like driver's license or other forms of identification. You wouldn't be able to access the content of the website without doing that. So it kind of puts people in an impossible position where they either have to give a platform personal identifying information, or they're blocked from accessing that site's content. And that ends up being an inhibition on free speech rights.

Dave Bittner: I see. As opposed to like what we were talking about earlier, you're buying the Playboy magazine at a newsstand where if they ask for your ID, that is a passing thing. They're not scanning it or copying it, or they're just looking at verifying it, but not filing it away.

Ben Yelin: Right, exactly. And as far as I know, there wasn't any data broker industry that existed around the driver's licenses that were being collected when you went to buy your Playboy magazine.

Dave Bittner: That's right.

Ben Yelin: So that's the big difference. It's part of a much larger ecosystem of data, data potentially being sold on the dark web, that kind of thing. And it could have a chilling effect. It would make people not want to go to these websites. Now, for pornography, maybe we're not that sympathetic, but you start to label other websites as things requiring age verification, you can see how it could get a little tricky. Like maybe there are some religious websites that somebody, some policymaker decides that's adult content and that needs to be regulated with age verification. And then somebody is unable to access that unless they provide their social security number or state-issued driver's license, that sort of thing. That's when it gets to be a slippery slope. And that's at least what NetChoice is arguing.

Dave Bittner: Yeah.

Ben Yelin: I mean, the states will say things like, this only applies to pornography. We will never extend these requirements to other industries. It's just, that's just not always the case.

Dave Bittner: Yeah. Do you suppose that this bill has a good chance of getting traction?

Ben Yelin: Yeah, in my experience with state legislation, sometimes it takes like two or three years. You have a first bite of the apple, but you have kind of an unperfected solution. And I think this is just kind of going to be a feeling out period. How resistant is the industry going to be? Is there a groundswell of popular support? I think in the medium term, there's a very good chance that we're going to, specifically California, is going to be able to set up guardrails around this, which I think is a good thing. Whether that will happen with this particular piece of legislation, I don't know.

Dave Bittner: All right. Well, we will have a link to that story. It's from the Washington Post, and we will include that in our show notes. My story this week is kind of an interesting and fun one. It's about a journalist named Jeff Schwainer, who decided to explore the extent to which he was being surveilled by license plate readers in rural Virginia. So Jeff got in his car, went on a 300-mile drive all over rural Virginia. He had some intentionality about where he would go, and he wanted to see how much police surveillance would track his movements. So after he went on this 300-mile drive, he asked 15 different law enforcement agencies in the areas that he went through for any footage or records they had of his car. You with me?

Ben Yelin: I'm with you. Yeah.

Dave Bittner: Okay. So basically he submitted FOIA requests for any information that they had. Nine of the agencies responded, and a few shared license plate reader hits from systems like Flock Safety. And we've talked about Flock Safety. That's sort of a third-party company who makes license plate readers, but also has lots of services that go along with that. And sure enough, from the records that were sent to him by the agencies that complied with the FOIA requests, he was indeed tracked multiple times. There was one time when he was tracked near a Dunkin' Donuts, which was kind of a fun police cliche.

Ben Yelin: Right. Police and donuts.

Dave Bittner: Right.

Ben Yelin: Always a good combination.

Dave Bittner: Yeah, but the tracking did confirm his route, but he also found there were all kinds of inconsistencies in data retention and the types of information that the cameras recorded. So what he came away with was really kind of a patchwork surveillance system. It wasn't at all consistent based on his, you know, not in-depth, purely scientific research. This is largely anecdotal. But the other thing was there's very little public oversight. You know, these are being collected by police forces. And also, interestingly, you know, some of the law enforcement agencies just said, no, we're not giving it to you.

Ben Yelin: Though that was only a couple of the agencies, right? The majority of them were like, sure, yeah, we'll oblige.

Dave Bittner: Yeah, yeah, absolutely.

Ben Yelin: What's really interesting about this piece is the last line of it, which is about how the police could have tracked him if they wanted to without asking for any kind of warrant or court order. So all of this is beyond the scope of the Fourth Amendment. It's all extremely publicly available data that's easily accessible, not just for the agencies themselves, but for anybody that has the time and energy to submit a FOIA request. Now, it's not going to be a perfect catalog of somebody's whereabouts. They go into some of the issues here, snowbanks that are blocking the view of a license plate or things like that. But it's a pretty comprehensive view. And this kind of brings up Carpenter concerns to me. I know I'm a broken record on this, but if the Supreme Court has a problem with long-term tracking of a person's location through historical cell site information, is the same concern not present when we're talking about this type of license plate recognition? There are differences. I think driving around is more of a voluntary action than turning on your phone. I think that can have an impact. And then there's a lot of things that you do when you're not driving. Now, granted, he was in rural Virginia, so I don't think there's public transportation that he could have used to get around. And I don't think much of these towns are -- I'm sure some of them are, but many of them aren't walkable. So it's de facto 24-7 surveillance. But it's also really interesting that this person took it on his own initiative to do this experiment. I kind of wish I had the time to do this, because I would love to drive around for hours in rural Virginia as part of an experiment.

Dave Bittner: Right. What are you up to? Research. I'm doing research.

Ben Yelin: Just a research project.

Dave Bittner: Right, right.

Ben Yelin: So if anybody wants to provide some seed funding, I'd be happy to --

Dave Bittner: Some grant money?

Ben Yelin: Yeah, some grant money. Exactly.

Dave Bittner: Sure. I wonder, so in terms of the FOIA request, he requested information about himself. Does that matter? Suppose he'd asked for information about your license plate, or my license plate, or his neighbor's license plate. Would law enforcement have been more likely to say no? Would they have been allowed to say no? What goes into a FOIA request?

Ben Yelin: No, it's about the information that you're requesting, like the actual content of the information. There are some things that are protected, at least at the federal level, by national security concerns. But by and large, it's like document by document what's eligible for FOIA. So I don't think, like if somebody is able to obtain data on themselves, at least as it comes to FOIA, I don't think it would make any difference if they were looking to obtain data on others.

Dave Bittner: Interesting. Right. So if you're a private investigator, this could be a powerful tool.

Ben Yelin: Absolutely. This could be a very powerful tool. It could be a very powerful tool for public investigators, i.e. local police departments. It's not as easy to do because this person is cataloging exactly where they're driving. And he's saying, like, I've been in X number of counties. I was in this town on this date. I hate to say it, but normal criminal suspects don't give you that type of helpful information. So you're going to have to do some investigatory work and obtain that license plate in the first place.

Dave Bittner: Yeah.

Ben Yelin: But I do think it's doable. I don't think anything -- I'm not an expert in Virginia FOIA law, but my impression is I don't think that there's anything preventing FOIA requests about data that is publicly accessible.

Dave Bittner: Well, getting back to the Carpenter decision, at what point do you suppose we cross that line? In other words, a single capture of a license plate is different than the stringing together of multiple captures of a license plate over time. And do we at some point cross the threshold of requiring a warrant?

Ben Yelin: We've gone seven years since Carpenter, and litigation has taken place all over the country about where we draw the line. The Supreme Court was not very clear about it, frankly. In that case, it concerned seven days of historical cell site location information, so we know that that applies in those circumstances. They talked about the breadth, the depth, and the involuntary nature of the collection. Those aren't clear-cut lines, and I think every good defense attorney and prosecutor is going to argue whether my client's case was similar to the circumstances in Carpenter or similar enough. But frustratingly, and we've seen this play out in the courts, it's really hard to know where that line is drawn. So sometimes it has to be at least those seven days to put it over that Carpenter threshold. Sometimes it has to do with the all-encompassing nature of the surveillance. The Fourth Circuit here on the East Coast of the United States held that the Baltimore city aerial surveillance, where there was a spy plane that flew over downtown Baltimore taking real-time pictures during daytime hours, that that was similar enough to Carpenter that it invoked Fourth Amendment concerns. And while that program was discontinued, it was held to be unconstitutional for those reasons. But to give you a short, unsatisfying answer, we don't really know where to draw that line. It's kind of just the topic of very heated arguments in legal proceedings.

Dave Bittner: And does it make a big difference that there's this whole notion that driving is a privilege, not a right? So your license plate information is sort of in a different category than your actual being?

Ben Yelin: Yeah, I don't know if it's about privilege versus right. I think it's about exposing -- not exposing yourself, that sounds dirty. It's the fact that you're out in public. So you forfeited a reasonable expectation of privacy by driving on public thoroughfares. And that's been a long-held constitutional principle. But does that change when we're talking about extensive long-term monitoring? At least some Supreme Court justices seem to think so. There was a case where, back in 2012, where law enforcement affixed a GPS device on somebody's car. And the case was decided on separate grounds, that that was actually a physical trespass, putting a GPS tracking device on a car. But there were a lot of justices who were talking about how concerned they were about long-term surveillance, when it's not just law enforcement tracking a license plate in limited circumstances around the time that a crime took place, something like that. But long-term monitoring of a whole of a person's movements. Supreme Court justices, ranging from the most conservative to the most liberal, have expressed problems with that type of long-term monitoring. So I think it's less about rights versus privileges and more about, are we going to allow this public view principle, that if you put something in public view, you forfeited your reasonable expectation of privacy. How far does that extend when we're talking about long-term monitoring?

Dave Bittner: So this is just going to play out over time, that eventually enough cases will come through that we'll have more clarity?

Ben Yelin: I would hope so. And we have had more clarity about certain things under Carpenter, but it has been seven years, and there are still a lot of questions that I'm unable to answer. And even law professors who are far smarter than me have been unable to answer. So yeah, I do think it's kind of frustrating. It's not like the Supreme Court had an obligation to engage in line drawing. Sometimes those lines can be rather arbitrary, especially when we're talking about a constitutional amendment. But that's the way they've done it here. So it leaves a lot of room for clever litigation in lower courts.

Dave Bittner: Okay. All right, well, we will have a link to that story in the show notes. Also, I've included a link. When I was researching this story, I came across another website that's sort of in response to all of these Flock license plate readers. The website is deflock.me. So Deflockme. It is a crowdsourced map of where the Flock license plate readers are located. So if you're curious, if there are any near you, you can go to this map, and it'll show you at least ones that have been reported.

Ben Yelin: Technology fighting technology.

Dave Bittner: Yeah.

Ben Yelin: It's like when my Google Maps asked me if I can confirm that there's a police officer at the next intersection.

Dave Bittner: Right, exactly. Police reported ahead. Yeah, yeah.

Ben Yelin: Just hearing those words makes me aggravated. Stop telling me that.

Dave Bittner: All right. Well, of course, if there's something you'd like us to discuss on the show, we'd love to hear from you. Our email address is caveat@n2k.com. [ Music ] Ben, I recently had the pleasure of speaking with Daniel Barber. He is CEO and co-founder of an organization called DataGrail, and we're talking about why companies need to focus on privacy and compliance. Here's my conversation with Daniel Barber.

Daniel Barber: The market has evolved a lot, right? I think there was a watershed moment that some of us may remember with Cambridge Analytica and the challenges related to privacy between Cambridge Analytica and Facebook. Things evolved, right? GDPR went into practice in 2018. California moved forward with their regulation in 2020. Now we find ourselves in a position where there are 19 U.S. states with different regulatory requirements. And, you know, I'd say at the highest level, data privacy has been a bipartisan issue in the U.S. So there's a lot of support for data privacy, but the requirements are challenging. And with the ever-changing technology environment, it's actually quite difficult for businesses to, one, keep up, and two, ensure they're delivering on their commitment to privacy and the promise of privacy to the consumers and users like us.

Dave Bittner: Well, as you mentioned, there's this patchwork of state privacy laws all over the nation. How are folks going about navigating that?

Daniel Barber: Yeah, it's really hard. I mean, we saw five new regulations going into effect this year. There have been discussions of a federal privacy bill for quite some time, although, you know, based on the current administration's position on federal regulation, it's unlikely that we see this, see that move forward in 2025 and probably not in 2026 either. Businesses struggle here, to be honest, Dave. It's very, very difficult, even in what would perceivably be the simpler end, you know, honoring your rights when you visit a website. So, you know, we're probably all familiar with cookie banners when you sort of think about Europe and that experience. In the U.S., we have laws, for example, the CCPA that protects users' consent, specifically giving, you know, us the ability to opt out for data processing. And when we looked at 5,000 companies last year, we found 75% of them, even when you clicked opt out, unfortunately, tracking continued. And so it's a challenging time for businesses to try to figure this out. And many don't have the internal resources they need, whether that's personnel or technology alike.

Dave Bittner: What are consumer attitudes like right now? I mean, it seems to me like on the one hand, there's a sense of resignation when it comes to our relationship with the big social media platforms. Like, you know, they're going to do what they do, and there's not a whole lot we can do about the type of tracking that goes on there. Does that extend to the companies that we're doing business with day by day, or do people have different expectations there?

Daniel Barber: Yeah, also a great question. I mean, I think consumers ultimately do expect control and transparency from the businesses that they interact with. There have been many studies that indicate, you know, if a consumer doesn't feel like they can trust a business, it's very unlikely that they'll continue working with that company. Our internal data suggests that, you know, people, consumers, users alike, are requesting their information and trying to understand how businesses are using that information more than ever. So we've done an annual study called the Privacy Trends Report, and last year's results suggested there was a 246% increase in the number of requests that people were making to businesses, a.k.a. asking, hey, you know, what type of data do you collect about me? Or, hey, I'd like to delete the information that you have about me. What was probably more interesting was actually the number of people asking, what type of data do you as a business collect about me? That's called an access request. And that volume increased 7x over a two-year period. We actually have our report for 2025 coming out shortly, and I expect that trend to continue. And so overall, there's, you know, at least in the U.S., very strong bipartisan support for privacy, and the expectations of consumers and users are high. But, you know, I do agree with you. I think that some consumers probably are accepting that perhaps, you know, their interactions with social media sites do collect data, and how they control that information now becomes more important than ever.

Dave Bittner: Can you describe to me the perils that companies face here? I mean, we talk about with consumers, I suspect it's largely reputational, but they have to deal with regulators as well.

Daniel Barber: Yeah, that's right. There's kind of two vectors of challenge there. One, you've got the regulatory requirements, which you mentioned. So when you've got, you know, a business that's a global business, and most businesses are these days, if you're operating a website, anyone in the world can visit your website. And so inherently, you're going to collect personal information on those businesses, whether you, you know, maybe intend to or not. And so, you know, global businesses by default, therefore, are exposed to a significant amount of regulatory risk as they operate. But on the technology side, the other vector, there's an underlying challenge that hasn't been solved over the last, really, two decades, and that's related to shadow IT. And so if you sort of think about the average business today, the stat that I usually share for folks, if, and especially CISOs listening will appreciate this one, you know, Okta is a single sign-on solution. They're actually an investor in DataGrail and a customer, too, and their data suggests that the average business, when they've been working with Okta for about four years, has about 200 systems that they've connected to Okta to allow employees to log into. Now, that's a lot, right? Any of those systems could collect and process Dave or Daniel's information. The challenge, though, is that that's not actually the true number. So if you look at Netscope's data, now Netscope looks at outgoing and incoming traffic going to a business, and when you look at their information, businesses between 500 and 2,000 employees typically use about 1,500 distinct applications. So there's clearly a huge delta between 1,500 and 200, and that just indicates the challenge that businesses have in that they can't control what they're not aware of, right? So if the CISO or the general counsel is not in control of the infrastructure or the technology used within a business, it makes it incredibly challenging to really deliver on the promise of privacy if you don't know where someone's information lives.

Dave Bittner: It seems to me like a few years back, there was this notion that the more data you could collect, there was value there, that you never know when you're going to want to go back and look at the things you've accumulated, and so storage is cheap, so let's hang on to everything.

Daniel Barber: Yeah.

Dave Bittner: And then over time, it seems like there was a shift in the attitude, like perhaps this data is actually radioactive, you know, like we have too much of it in one place, bad things can happen.

Daniel Barber: Yeah.

Dave Bittner: What is the current attitude of organizations who find themselves in the course of day-to-day business having to collect data here? Is there an active effort to minimize what they have?

Daniel Barber: Yeah, this is an area of conflict within business, right? I think, you know, if you've ever talked to a marketer, and I certainly have, and I'm sure you have, I don't meet too many marketers that say, you know what, let's not collect that information. Marketing teams and generally revenue-orientated teams, whether that's in a B2B capacity, so businesses selling to businesses or, you know, consumer-orientated businesses, usually are looking to collect as much information as they can because they use that information to then, you know, provide more relevant campaigns or, you know, personalization in their product or services. And so businesses generally are trying to collect as much information as they can. The problem is that, of course, is at odds to everything I just said in terms of, you know, trying to provide privacy and uphold consumer trust. And so, you know, there are certainly data minimization efforts that we see businesses going through. However, I would say that because of that conflict within an organization, we don't see that trend really picking up steam much, largely because, you know, AI only makes that data even more valuable, right? So businesses that have collected data on users and consumers now can perform, you know, different services, perhaps using Gen AI. And that is, you know, potentially valuable for the consumer and a good thing, but the privacy risk and associated security risk is non-trivial also.

Dave Bittner: Yeah. Well, as someone who is on the inside with this, you know, who's dealing with people's challenges when it comes to managing their data and data privacy day-to-day, what are your recommendations then for organizations to come at this issue?

Daniel Barber: Yeah, I mean, I think first step, right, understanding the type of data that you're collecting. This is commonly known as a data mapping exercise. So, you know, undertaking a comprehensive data mapping exercise to really get hold of that shadow IT and shadow AI that exists in the organization is kind of step one. Step two is making sure that, you know, you're providing consumer choice and, you know, upholding the rights that people have when they visit your website. So this is commonly known as sort of consent and making sure that that is working because we see most businesses, in fact, you know, it's not working. That's 75% stat that I mentioned earlier. And then lastly, as people go to request their information and really understand how information is being used and what type of information is being collected, that's an inflection point where someone may be agitated, maybe just trying to understand. But either of those scenarios, making sure that that process runs smoothly and provides consumers confidence in how it happens. And, of course, that the accuracy of information meets the expectation of the consumer because, you know, the wrong information into someone's hands, you know, that's the opposite goal of what you're probably looking to achieve, which is the promise of privacy.

Dave Bittner: So, Ben, I mean, it's really top of mind for a lot of companies, I think, this year, you know, more than ever, particularly this compliance side of things, that this is not something they could sweep under the rug or, you know, kick that can down the road.

Ben Yelin: No, and we've seen circumstances where businesses and organizations have tried to do that, try and skirt around compliance requirements, and they get fines levied at them. And it's just incumbent upon these organizations to make sure they have some folks on staff or folks they're willing to contract with who can help them understand how they can be in compliance with federal and state laws.

Dave Bittner: Yeah, absolutely. All right. Well, again, our thanks to Daniel Barber from DataGrail for joining us. We do appreciate him taking the time. [ Music ] And that's "Caveat", brought to you by N2K CyberWire. We want to thank all of you for listening. Our executive producer is Jennifer Eiben. The show is edited by Trey Hester. Our executive editor is Peter Kilpe. I'm Dave Bittner.

Ben Yelin: And I'm Ben Yelin.

Dave Bittner: Thanks for listening