The Data Diva Talks Privacy Podcast
Debbie Reynolds “The Data Diva” talks Data Privacy with industry leaders around the world about issues businesses need to know now.
Join me weekly for new episodes
““I want to tip my hat to you ...the leadership that you’ve shown, as well as the platform that you’ve created, is simply amazing.””
“If anybody knows where to go for the types of conversations that they need to have on Data Privacy, you are that person. You are a rock star in this space.” ”
#1 Data Privacy Podcast Worldwide (Privacy Plan)
5 Best Data Privacy and Data Protection Podcasts for 2025 (Velotix)
Best Data Privacy Podcasts 2026 (RadarFirst)
The 17 Best Privacy Podcasts To Listen 2025 (bCast)
Best Data Privacy Podcasts 2025 ( Player FM)
Best Data Privacy Podcasts 2026 (Goodpods)
Best Privacy Podcasts 2026 (Feedspot)
The 10 Best Data Privacy Podcasts In The Digital Space 2024 (bCast)
Best Data Privacy Podcasts 2024 (Player FM)
Best Data Privacy Podcasts Top Shows of 2024 (Goodpods)
Best Privacy and Data Protection Podcasts of 2024 (Termageddon)
Top 40 Data Security Podcasts You Must Follow 2024 (Feedspot)
Top 50 in Business and Management 2024 (Apple Podcasts)
Top 25% in weekly Downloads 2024 (The Podcast Host)
Top 2% of 3 million + globally ranked podcasts of 2024 (ListenNotes)
12 Best Privacy Podcasts for 2023 (RadarFirst)14 Best Privacy Podcasts To Listen To In This Digital Age (bCast) in 2023
Best Data Privacy Podcasts 2022 (Player FM)
10 Best Top 10 Data Privacy Podcasts by DataTechvibe in 2022
20 Best Data Rights Podcasts of 2021 (Threat Technology Magazine)
20 Best European Law Podcasts of 2021 (Welp Magazine)
20 Best Data Privacy Rights & Data Protection Podcast of 2021 (Welp Magazine)
20 Best Data Breach Podcasts of 2021 (Threat Technology Magazine)
Top 5 Best Privacy Podcasts 2021 (Podchaser)
"The Data Diva" Talks Privacy Podcast reaches listeners in over 157 countries with over 1 million+ downloads!
〰️
"The Data Diva" Talks Privacy Podcast reaches listeners in over 157 countries with over 1 million+ downloads! 〰️
💃🏾 Search All Data Diva Talks Privacy Podcast Full-Episode Transcripts
Type a topic, guest name, or keyword to find matching episodes. This tool searches all public transcript pages.
Powered by Google Programmable Search. No login required.
💬 ChatGPT Chatbot: Search The Data Diva Talks Privacy Podcast Transcripts
Use this AI-powered tool to search over 250 full-episode transcripts from Debbie Reynolds' podcast. Get links and summaries of the most relevant episodes.
Free to use. Requires a free ChatGPT account.
🔍 Start ChatGPT Search
Debbie Reynolds, The Data Diva, Talks with Tom Kemp of Cal Privacy on Privacy Advocacy
In this introduction from The Data Diva Talks Privacy Podcast, Debbie Reynolds, “The Data Diva,” speaks with Tom Kemp, Executive Director of Cal Privacy, the California Privacy Protection Agency (CPPA), about their professional relationship and shared work in privacy advocacy and public policy. Episode 277 was released February 24, 2026..
E298 - Laura Pleskatcheva, Data Privacy and AI Governance Operations
Laura Pleskatcheva, Data Privacy and AI Governance Operations
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, The Data Diva speaks with Laura Pleskatcheva, a Data Privacy and AI Governance Operations professional, about the critical role privacy operations plays in helping organizations translate regulatory requirements into practical business processes. Laura shares her career journey from corporate finance into privacy, explaining how her interests in business operations, technology, compliance, and cross-functional collaboration led her to a career in privacy and AI governance.
The conversation explores the common misconception that privacy is solely a legal or compliance function. Laura explains that while legal teams focus on understanding requirements and obligations, privacy operations is responsible for implementing those requirements in a way that works across the organization. Debbie and Laura discuss the distinction between the "what" and the "how," highlighting how privacy operations serves as the bridge between policy and execution.
The episode examines the practical work involved in operationalizing privacy programs, including project management, relationship building, stakeholder engagement, and cross-functional collaboration. Laura explains that privacy professionals frequently work across legal, marketing, HR, technology, security, and business teams to ensure that privacy requirements are effectively implemented. The discussion highlights why communication, influence, and collaboration are often just as important as technical or legal knowledge.
Debbie and Laura also explore the importance of organizational culture and leadership support in building successful privacy programs. Laura emphasizes that privacy is a team sport and that executive engagement is often the key factor that determines whether privacy initiatives succeed. When leadership understands privacy risks and values trust and integrity, organizations are better positioned to integrate privacy into everyday business practices.
The conversation also addresses the rapid pace of technological change and the growing attention organizations are placing on artificial intelligence. Laura explains that while AI has become a major focus for businesses, privacy requirements and obligations have not disappeared. Organizations must continue managing privacy compliance while simultaneously developing governance frameworks for AI technologies. The discussion highlights the need for organizations to understand how personal data is used within AI systems and to educate both employees and consumers about the risks and benefits associated with emerging technologies.
The episode concludes with a discussion of third-party risk management and vendor accountability. Debbie and Laura examine the challenges organizations face when working with vendors that process personal data and discuss the importance of contracts, audits, due diligence, trust, and ongoing oversight. As organizations become increasingly interconnected through technology platforms and outsourced services, strong vendor governance practices remain a critical component of privacy and AI governance programs.
E297 - Patrick Zeller, General Counsel, Jetstream Security
Patrick Zeller, General Counsel, Jetstream Security
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, The Data Diva speaks with Patrick Zeller, General Counsel of Jetstream Security, about artificial intelligence, cybersecurity, privacy, and the evolving risks organizations face as AI becomes embedded throughout their operations. Patrick shares his unique career journey from the Illinois Attorney General's Office into technology law, cybersecurity, and emerging technologies, explaining how his early interest in computers shaped a career that bridges both legal and technical disciplines.
The conversation explores how organizations are adopting AI at an unprecedented pace and why many leaders are struggling to understand the risks associated with these technologies. Patrick explains that AI entered many organizations through productivity tools and enterprise platforms before legal, privacy, and security teams had an opportunity to evaluate its implications. As a result, many companies are now working to gain visibility into how AI is being used, what information is being shared, and where risks may exist.
Debbie and Patrick discuss AI risk through three primary categories: input risks, output risks, and related organizational risks. They examine how employees may inadvertently expose sensitive information by entering confidential, financial, employee, legal, or proprietary information into AI systems. The discussion highlights real-world examples involving compensation information, trade secrets, attorney-client privileged communications, and sensitive corporate data that may be exposed through unauthorized use of AI tools.
The episode explores the growing challenge of shadow AI, where employees use public AI tools outside approved enterprise environments. Patrick explains how organizations must understand what AI tools are being used, who is using them, and what systems and data those tools can access. The conversation also covers SEC reporting obligations, cross-border data transfer concerns, unauthorized access incidents, insider threat risks, and the increasing need for organizations to monitor how AI interacts with sensitive business information.
Patrick and Debbie discuss how organizations must rethink traditional security models because AI is no longer operating outside the corporate perimeter. Instead, AI increasingly functions as an insider with potential access to valuable data and systems. The conversation explores how organizations can improve visibility, governance, and oversight while balancing innovation and business objectives.
The discussion concludes with a broader examination of how society is approaching AI adoption. Patrick introduces the concept of a "Galbraithian inversion," where organizations begin using powerful technologies before fully understanding how they work. Debbie and Patrick discuss why this creates both opportunities and challenges as companies race to deploy AI while simultaneously trying to understand its legal, security, privacy, and governance implications.
E296 - Michael Booden. Senior Technology Counsel
Michael Booden, Senior Technology Counsel
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, The Data Diva speaks with Michael Booden, Senior Technology Counsel, about the evolving relationship between contracts, privacy, cybersecurity, and artificial intelligence. Michael shares his professional journey from litigation and appellate court clerkships to becoming an in-house technology attorney and adjunct law professor teaching contract drafting and negotiation. He explains how his litigation background shaped his approach to drafting agreements, emphasizing the importance of clarity, precision, and anticipating how contractual language will be interpreted when disputes arise.
The conversation explores how privacy and security requirements increasingly appear in technology agreements and why organizations can no longer rely solely on vendor representations regarding data protection. Michael discusses how he developed cybersecurity addenda to establish objective standards and expectations for vendors, including security controls, indemnification provisions, and requirements aligned with recognized frameworks such as NIST and ISO standards. He explains how these contractual protections help organizations proactively manage risk rather than simply reacting to incidents after they occur.
Debbie and Michael examine the growing role of AI in organizations and the challenges associated with managing data privacy and security risks when using AI tools. Michael discusses the development of AI-specific contractual provisions designed to address issues such as data handling, retention, outputs, transparency, and vendor accountability. The discussion highlights how organizations are increasingly being asked by customers, regulators, and business partners to explain how AI is being used and what safeguards are in place to protect sensitive information. Michael shares how his organization developed client-facing AI disclosures to provide greater transparency and build trust around AI usage.
The episode also explores the importance of selecting enterprise-grade AI solutions rather than public consumer tools, particularly when organizations are handling confidential, proprietary, or personal information. Michael explains how privately licensed AI environments can provide stronger protections against data leakage and unauthorized use, while also enabling organizations to take advantage of AI's productivity benefits. Debbie and Michael discuss how AI is transforming work by helping employees automate lower-value tasks, improve efficiency, and access information more effectively, while emphasizing that organizations must establish clear policies, governance frameworks, and contractual protections to ensure AI is used responsibly.
The conversation highlights a broader trend occurring across industries: organizations are increasingly pushing privacy, security, and compliance requirements down through their vendor ecosystems. As privacy regulations continue to expand globally, companies are using contracts to establish expectations for third parties and create more consistent protections for personal data, confidential information, and AI-enabled workflows. Michael emphasizes that strong contracts remain one of the most effective tools organizations have for managing technology risk in a rapidly evolving environment.
E295 - Marcus Wells, vCISO, WellSecured IT (Identity Security)
Marcus Wells, vCSO, Wells Secure IT
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, "The Data Diva" speaks with Marcus Wells, vCSO at Wells Secure IT, about identity security, digital transformation, artificial intelligence, and why identity has become one of the most important foundations of modern technology environments. Marcus shares his career journey through cybersecurity and explains how he gradually realized that identity was at the center of nearly every security challenge he encountered. He discusses how identity extends far beyond traditional access management and why understanding identity requires a broader view of people, devices, systems, applications, and data.
The conversation explores how organizations increasingly rely on digital identities to support business operations, cloud services, connected devices, and emerging technologies. Marcus explains his framework for understanding identity, including the ability to access, store, and connect to data and networks. Debbie and Marcus discuss how identity applies not only to people but also to devices, applications, and non-human entities that participate in modern digital ecosystems. The discussion highlights the growing importance of context when making decisions about access, permissions, and trust.
They examine how artificial intelligence is creating new identity challenges, particularly as organizations begin deploying AI agents capable of performing tasks, accessing systems, and interacting with data. Debbie shares examples involving AI agents granted broad access to systems, including incidents in which agents reportedly deleted databases or were granted extensive permissions without appropriate controls. Marcus discusses the risks associated with treating AI agents like traditional software or human users and explains why organizations must carefully consider how identities are provisioned, managed, and monitored in AI-enabled environments.
The episode also explores the concept of trust in technology and why AI systems introduce new categories of uncertainty. Marcus argues that traditional software is generally predictable and produces repeatable outcomes, whereas large language models and AI systems often generate probabilistic results that cannot be guaranteed. This creates unique governance, security, and risk management challenges that organizations must address as they accelerate digital transformation initiatives. The conversation highlights why identity, context, trust, and governance will become increasingly important as AI systems gain greater access to organizational data and decision-making processes.
E294 - Nabanita De, Founder and CEO of PrivacyLicense.ai
Nabanita De, Founder and CEO, Privacy License AI
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, "The Data Diva" speaks with Nabanita De, Founder and CEO of Privacy License AI, about one of the most significant challenges facing the AI ecosystem today: how creators, organizations, and AI developers can establish clear, enforceable rules for the use of content in AI systems. Nabanita shares her background working at Microsoft Research, Uber, and in the fintech sector, where she gained firsthand experience with privacy, AI, and compliance challenges. She explains how those experiences ultimately led her to create Privacy License AI and develop what she describes as a privacy operating system for the AI era.
The conversation explores the growing tension between creators, content owners, and AI companies as large language models increasingly rely on content gathered from across the Internet. Nabanita discusses how traditional approaches, such as robots.txt and website terms of service, were designed for an earlier Internet and were never intended to address the scale and complexity of modern AI training systems. Debbie and Nabanita examine how AI systems consume content, how creators often receive little or no attribution or compensation, and why both creators and AI companies face uncertainty regarding rights, permissions, and compliance obligations.
They discuss the rise of AI copyright litigation, including lawsuits involving major publishers and AI providers, and the practical challenges organizations face in determining whether content can legally be used for training purposes. Nabanita explains why legal frameworks alone cannot solve these issues and argues that technical solutions are necessary to create scalable mechanisms for communicating rights and permissions across the AI ecosystem. The discussion highlights how machine-readable privacy and usage rules could allow creators to specify how their content may be used, under what conditions, and whether attribution, compensation, or other restrictions should apply.
The episode also explores the concept of metadata-driven governance, where information about ownership, jurisdiction, usage rights, purpose limitations, and permitted activities travels with content throughout its lifecycle. Debbie and Nabanita discuss how this approach could create greater legal certainty for AI developers while simultaneously providing stronger protections for creators. The conversation highlights the broader challenge of balancing innovation, intellectual property rights, privacy, and trust as organizations seek to build AI systems that are both effective and responsible.
E293 -Veronica Canton, Partner at Pierson Ferdinand LLP and Chief Vision Officer of Optimized Leverage
Veronica Canton, Partner, Pierson Ferdinand LLP and Chief Vision Officer, Optimized Leverage
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, "The Data Diva" speaks with Veronica Canton, Partner at Pierson Ferdinand LLP and Chief Vision Officer of Optimized Leverage, about careers in privacy, cybersecurity, and artificial intelligence, as well as the importance of visibility, mentorship, and continuous learning in a rapidly evolving profession. Veronica shares her journey from commercial litigation into privacy, cybersecurity, and AI, explaining how certifications, networking, and consistently sharing knowledge helped create new professional opportunities.
The conversation explores how professionals can successfully transition into privacy and cybersecurity from a wide variety of backgrounds. Veronica discusses the importance of building expertise through continuous learning, developing a public presence, and sharing knowledge with others. Debbie and Veronica emphasize that privacy, cybersecurity, and AI are multidisciplinary fields that require perspectives from legal, technical, operational, business, and governance professionals.
They discuss the growing need for talent across privacy, cybersecurity, and AI, including roles that do not require legal training. The conversation highlights opportunities in compliance, data subject rights management, incident response, governance, risk management, and technology implementation. Veronica explains how transferable skills from previous careers can provide a strong foundation for success in emerging technology fields and why diverse viewpoints improve decision-making and organizational resilience.
The episode also examines the relationship between privacy, cybersecurity, AI governance, and global regulatory trends. Debbie and Veronica discuss cultural differences between the United States and Europe, including how historical events have influenced privacy laws and attitudes toward personal data. They explore how organizations can build demonstrable compliance programs, prepare for regulatory scrutiny, and create governance structures that support innovation while managing risk.
E292 - Rowenna Fielding, Director, Miss IG Geek (United Kingdom)
Rowenna Fielding, Director, Miss IG Geek
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, "The Data Diva" speaks with Rowenna Fielding, Director of Miss IG Geek, about data ethics, privacy, governance, and the human impact of how organizations collect and use data. Rowenna shares her unconventional path into privacy, beginning in theater and information technology before eventually specializing in information governance, data protection, and data ethics. She explains how her work evolved as she became increasingly interested not only in legal compliance but also in the broader consequences of the way organizations make decisions about people using data.
The conversation explores the distinction between compliance and ethics, and why organizations often assume that following policies, regulations, or technical controls automatically leads to ethical outcomes. Rowenna argues that data is not neutral or objective but is instead the product of human choices, incentives, and assumptions. Debbie and Rowenna discuss how organizations frequently collect and use data without fully considering whether the data is appropriate, whether it should be collected at all, or whether its use could unintentionally cause harm.
They examine the challenge of defining harm in the context of privacy and data protection, particularly when the effects are psychological, social, reputational, or otherwise difficult to measure. The discussion includes comparisons to health and safety frameworks, highlighting how organizations can build systems, governance structures, incentives, education programs, and cultures that make responsible data use the default rather than the exception. Rowenna explains how GDPR's foundation in fundamental rights provides a useful framework for evaluating ethical questions and why organizations must think beyond legal compliance to consider the broader impact of their actions on individuals and society.
The episode also explores corporate social responsibility, ESG, organizational values, and how leaders can establish meaningful ethical boundaries in environments where technology is advancing faster than regulation or societal norms. Throughout the conversation, Debbie and Rowenna challenge organizations to think critically about what it means to use data responsibly and how privacy programs can move beyond box-checking exercises to become part of a broader commitment to reducing harm and protecting people.
E291 - Eric Null, Director, Privacy & Data Program, Center for Democracy & Technology
Eric Null, Director, Privacy & Data Program, Center for Democracy & Technology
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, "The Data Diva" speaks with Eric Null, Director, Privacy & Data Program at the Center for Democracy & Technology, about the current state of privacy in the United States and the ongoing effort to establish comprehensive federal privacy legislation. Eric shares his unique journey from studying classical clarinet performance to becoming a leading advocate for privacy and consumer rights, explaining how his work in technology policy, net neutrality, broadband privacy, and consumer protection shaped his perspective on privacy as an issue fundamentally connected to power and control.
The conversation explores how information functions as a source of power in the digital age and why the collection, processing, and use of personal data can create risks ranging from manipulation and profiling to broader concerns about autonomy and control. Eric discusses his early work involving children's privacy, broadband privacy, and consumer protection, including efforts to strengthen privacy protections through the Federal Communications Commission and the Federal Trade Commission. He explains how the growth of the "free" Internet business model has created an environment in which individuals often exchange large amounts of personal information in exchange for access to online services, incentivizing extensive data collection and monetization.
Debbie and Eric examine the current U.S. privacy landscape, including the sector-specific approach taken by laws such as HIPAA, the Gramm-Leach-Bliley Act, and COPPA. They discuss the Federal Trade Commission's role as the primary federal privacy regulator and how the agency's authority has historically relied on preventing deceptive and unfair practices rather than establishing broad data rights. The discussion explores the limitations of the notice-and-choice model, in which organizations disclose their practices through privacy policies that consumers rarely read or meaningfully negotiate, and how network effects can limit the practical choices available to individuals seeking to participate in modern digital platforms.
The episode also covers the repeated attempts to pass comprehensive federal privacy legislation, including the American Data Privacy and Protection Act (ADPPA), the American Privacy Rights Act (APRA), and more recent proposals. Eric shares insights into the legislative challenges that have prevented these efforts from becoming law and discusses the policy debates surrounding data minimization, consumer rights, enforcement, and the relationship between privacy and broader concerns about the power of large technology companies. The conversation highlights why privacy remains one of the most important policy issues facing organizations, regulators, and consumers, and why meaningful reform continues to be difficult despite widespread public concern.
E290 - Doug Austin, Editor, eDiscovery Today
Doug Austin, Editor of eDiscovery Today
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, The Data Diva speaks with Doug Austin, Editor of eDiscovery Today, about how eDiscovery, data governance, privacy, and artificial intelligence are increasingly interconnected in modern organizations. Doug explains how eDiscovery has evolved from a litigation-focused discipline into a broader framework that supports investigations, audits, incident response, and privacy-related workflows such as data subject access requests.
The conversation explores how AI is generating entirely new categories of data, including chatbot interactions, meeting transcripts, automated summaries, and AI-generated content, all of which may become evidence in legal and regulatory contexts. Debbie and Doug discuss how organizations are struggling to manage this expanding data landscape, particularly as employees adopt AI tools without fully understanding the implications for privacy, confidentiality, and data exposure.
They examine real-world scenarios involving AI note-taking tools and meeting recordings, including cases where sensitive information is captured and shared beyond its intended audience. The discussion also highlights risks associated with uploading confidential information into public AI systems and the lack of awareness around how these tools handle and retain data.
The episode further explores key legal developments, including litigation involving AI companies and disputes over data retention and production, as well as emerging questions around privilege and work product protections for AI-generated content. Debbie and Doug discuss how courts are beginning to address whether interactions with AI systems can be protected and the implications for both represented and self-represented individuals.
The conversation emphasizes that AI is fundamentally reshaping how data is created, stored, and used, and that organizations must adapt their governance, legal, and privacy strategies to manage these risks effectively while maintaining defensible and compliant data practices.
E289 - Ross Saunders, Ross G. Saunders Consulting
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, The Data Diva speaks with Ross Saunders, Head of Ross G. Saunders Consulting, about privacy engineering and the challenges organizations face when translating legal requirements into technical implementation. Ross shares his background in infrastructure, DevOps, and software architecture, explaining how his experience working with SaaS environments and data breaches led him to focus on bridging the gap between legal, security, and development teams.
The conversation explores how privacy is often treated as a legal or compliance exercise, while in practice it requires integration into system design and development workflows. Debbie and Ross discuss how developers frequently receive requirements that do not align with legal intent, leading to inconsistencies in implementation and increased risk for organizations.
They examine real-world challenges in applying privacy regulations, including age verification requirements and the classification of IP addresses, where technical realities may conflict with regulatory expectations. The discussion also addresses the limitations of focusing on specific technologies, such as cookies, rather than addressing broader issues related to data sharing and potential harm.
The episode highlights practical examples of risk, including loyalty applications that collect extensive financial transaction data and the potential consequences if that data is exposed or misused. Debbie and Ross emphasize the importance of shifting toward harm-based approaches to privacy and ensuring that organizations understand the real-world impact of their data practices.
The conversation also explores emerging risks associated with agentic AI and autonomous systems, including scenarios where systems are granted excessive access and cause unintended damage or data loss. Organizations must implement governance, oversight, and clear controls to ensure that innovation in AI does not introduce unnecessary risk.
E288 - Terri Lewis, Planet Connected Consulting (Smart Cities)
Terri Lewis, Founder of Planet Connected
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, The Data Diva speaks with Terri Lewis, Founder of Planet Connected, about privacy, data governance, and risk in smart cities and connected infrastructure. Terri shares her background in digital strategy and her work supporting collaboration between cities and technology providers, emphasizing the importance of building trust and transparency into smart city initiatives.
The conversation explores how everyday systems such as water utilities, parking applications, and license plate readers collect and process personal data, often without individuals fully understanding the scope of that data collection. Debbie and Terri discuss how data from smart meters, for example, can reveal occupancy patterns and behavioral insights, and how location-based services and parking systems can introduce privacy risks through the collection of personal and financial information.
They examine the role of third-party vendors and the challenges organizations face in managing data across multiple providers, including concerns about overcollection, lack of transparency, and unclear data ownership. Real-world examples highlight how individuals may be required to provide more data than expected for routine activities, raising questions about proportionality and necessity.
The episode also explores broader IoT risks, including long device lifecycles, evolving capabilities through updates, and the increasing use of cameras and image-based technologies. Debbie and Terri discuss how advances in image recognition and facial recognition can enable identification of individuals in public spaces, creating new risks that existing legal frameworks may not fully address.
The discussion emphasizes that organizations must take a proactive approach to data governance, anticipating potential misuse, addressing unintended consequences, and aligning technology deployment with public expectations and trust. As cities continue to adopt connected technologies, leaders must ensure that innovation is balanced with strong privacy, security, and accountability practices.
E287 - Vibeke Specht, Author and Co-Founder at Peak Privacy
Vibeke Specht, Co-founder of Peak Privacy and Author of “From GDPR Confusion to Privacy First Marketing”
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, The Data Diva speaks with Vibeke Specht, Co-founder of Peak Privacy and author of “From GDPR Confusion to Privacy First Marketing,” about privacy, data governance, and the broader societal impact of data-driven marketing practices. Vibeke shares her background in journalism, political science, and marketing, explaining how her work evolved into a focus on privacy as she recognized the deeper implications of data collection, tracking, and profiling.
The conversation explores how GDPR is grounded in European history and fundamental rights, including protections against surveillance and misuse of personal data, and how this approach differs from more commercially driven data models often seen in the United States. Debbie and Vibeke discuss how marketing teams were among the first to confront the operational impact of GDPR, particularly through cookie regulations, consent requirements, and shifting expectations around transparency and accountability.
They examine the evolution of the ad tech ecosystem, including third-party cookies, large-scale tracking, and the role of dominant platforms in shaping how data is collected, shared, and monetized. The discussion highlights how complex and opaque data flows make it difficult for both organizations and individuals to fully understand how personal data is used, creating risk for companies and limiting meaningful user control.
The episode also explores how data practices influence behavior at scale, including the potential impact on democratic systems, decision-making, and public trust. Vibeke emphasizes the importance of moving beyond surface-level compliance and addressing the underlying structures that drive data collection and use, while organizations must balance innovation, competition, and responsible data practices in an increasingly complex regulatory environment.
E286 - Bradon Rogers, Chief Customer Officer, Island
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, "The Data Diva," speaks with Bradon Rogers, Chief Customer Officer, Island, about how organizations are addressing complex enterprise challenges related to data governance, privacy, and control. Bradon explains how Island was designed to solve persistent issues that companies face, including limited visibility into user activity, fragmented tools, and the difficulty of managing sensitive data across cloud applications, remote work environments, and emerging technologies.
The conversation explores how organizations can move toward a more unified, practical approach to data management, where governance and privacy controls are embedded directly into how work is performed. Rather than relying on disconnected systems, Island enables companies to monitor and control how data is accessed and used in real time, helping to reduce risk while maintaining operational efficiency.
Debbie and Bradon also discuss how modern enterprises are rethinking data governance as a business-critical function, not just a compliance requirement. They highlight how privacy considerations are becoming more integrated into enterprise workflows, and how organizations can better align their security, privacy, and data strategies to support both protection and productivity in increasingly complex digital environments.
This episode is sponsored by Island. We thank them for their support and for sharing insight into how organizations can better manage data governance and privacy in today’s enterprise landscape.
E285 - Michael Simon, Law+Data, LLC (Privacy and AI)
In this episode, Debbie Reynolds, "The Data Diva", speaks with Michael Simon of Law+Data, LLC about the convergence of law, data, and artificial intelligence, and how this shift is transforming privacy practices and legal frameworks.
Michael shares his background in technology and law, including early experience with computing and its influence on his legal career. The conversation explores how traditional legal models, particularly notice and consent, are becoming less effective in modern data environments where data is continuously collected, processed, and reused.
Debbie and Michael discuss emerging regulatory approaches, including restrictions on certain types of data use, and the limitations of relying solely on compliance to address privacy risks. They examine how organizations must develop a deeper understanding of how data flows through systems and how AI technologies generate insights and inferences.
The discussion also covers the need for legal professionals to understand technical systems, including AI, data processing, and system architecture, as well as lessons from eDiscovery that remain relevant in modern data environments. The episode highlights the importance of moving toward integrated approaches that combine legal, technical, and operational perspectives to manage privacy risk effectively.
E284 - Michelle Finneran Dennedy, Chief Data Strategy Officer, Abaxx Technologies
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, "The Data Diva" speaks with Michelle Finneran Dennedy, Chief Data Strategy Officer at Abaxx Technologies, about the evolving role of data strategy in modern organizations and how companies can operationalize trust, accountability, and value from their data. Michelle shares insights from her extensive experience at the intersection of privacy, data governance, and business strategy, emphasizing that data is not just a compliance obligation but a core enterprise asset that must be actively managed and aligned to business outcomes.
The conversation explores how organizations can move beyond reactive compliance models toward proactive data strategy frameworks that integrate privacy, governance, and innovation. Debbie Reynolds, "The Data Diva" and Michelle discuss the importance of embedding data responsibility into organizational culture, the role of leadership in setting expectations for ethical data use, and how companies can build systems that support both regulatory requirements and long-term business value. They also examine how data governance must evolve to address increasingly complex ecosystems, including cross-border data flows, emerging technologies, and shifting regulatory expectations.
Michelle highlights the need for clear accountability structures, strong internal alignment across legal, technical, and business teams, and the development of practical frameworks that translate policy into action. The discussion also covers how organizations can better measure the value of data, manage risk in dynamic environments, and create scalable approaches that support growth without compromising trust. This episode provides practical guidance for leaders looking to strengthen their data strategy, improve governance, and position their organizations for long-term success in a data-driven world.
E283 - Merry Marwig, Vice President, Global Communications & Advocacy, Privacy4Cars
Merry Marwig, Vice President, Global Communications & Advocacy, Privacy4Cars
In this episode, Debbie Reynolds, "The Data Diva" speaks with Merry Marwig, Vice President, Global Communications & Advocacy at Privacy4Cars, about privacy risks in connected vehicles and the expanding automotive data ecosystem.
Merry explains how modern vehicles function as sophisticated data platforms that continuously collect and transmit information about drivers, passengers, and vehicle activity. The conversation explores the types of data collected, including location data, behavioral data, infotainment usage, diagnostic data, and other signals generated through connected systems, as well as how that data is shared across manufacturers, dealerships, service providers, insurers, and third-party technology providers.
Debbie and Merry discuss the complexity of data flows within the automotive ecosystem, including the roles of controllers, processors, and third parties, and how these relationships create challenges for transparency, accountability, and consent. The discussion highlights how individuals often lack visibility into how their data is used and shared across multiple entities.
The conversation also includes discussion of Debbie Reynolds’ work on the Internet of Things Advisory Board report with the U.S. Department of Commerce, and how that work highlighted many of the same issues now seen in connected vehicles, including data sharing across ecosystems, lack of transparency, and challenges with governance and accountability in multi-party environments.
Debbie and Merry examine consumer awareness gaps, including how most individuals do not fully understand the extent of data collection in vehicles or how their information is used. They also discuss what happens to personal data when a vehicle is sold, transferred, or serviced, and the importance of tools and processes that allow individuals to manage, delete, or control their data across the vehicle lifecycle.
The episode also covers regulatory developments impacting automotive privacy, the role of advocacy organizations in improving industry practices, and the importance of clear communication between companies and consumers. The discussion emphasizes the need for organizations to integrate privacy into product design and governance processes while balancing innovation and responsible data use.
E282 - Evan Benjamin, CEO of Tier 3 Inc. (AI Safety)
In this episode, Debbie Reynolds “The Data Diva” speaks with Evan Benjamin, President of Tier 3 Inc., about the growing challenges of privacy in AI systems, particularly in relation to inference, agent-based systems, and data lifecycle management.
Evan shares his transition from IT, e-discovery, and information security into privacy, highlighting how the rapid adoption of large language models has exposed gaps in how organizations approach privacy and data protection. The conversation explores the distinction between security and privacy, emphasizing that security focuses on protecting systems while privacy focuses on purpose, data use, and fundamental rights.
Debbie and Evan discuss the risks associated with AI-driven inference, including how systems generate insights about individuals based on context and historical data, often without user awareness or control. They also examine how AI memory and agent-based systems can extend data usage beyond original intent, raising concerns about purpose limitation and data minimization.
The discussion further addresses challenges with data retention, logging, and traceability, as well as the difficulty of deleting data from AI systems once it has been incorporated into model training. Evan highlights the technical limitations of data erasure in machine learning models and the implications for privacy rights such as the right to be forgotten.
Finally, the conversation explores issues related to data processing across multiple systems, including the complexity of managing controllers, processors, and sub-processors, as well as emerging risks related to liability when organizations deploy AI systems and autonomous agents.
E281 - Mojisola Abi Sowemimo, Data Privacy and AI Governance Expert
In this episode, Debbie Reynolds “The Data Diva” speaks with Mojisola Abi Sowemimo about the intersection of privacy, governance, and emerging technologies, with a focus on how organizations can better align data practices with regulatory expectations and ethical responsibilities.
The conversation explores how organizations approach privacy in practice, including gaps between policy and implementation, and the challenges of operationalizing privacy requirements across complex systems. Mojisola discusses the importance of embedding privacy considerations early in system design, as well as the need for organizations to move beyond surface-level compliance toward more accountable and transparent data practices.
Debbie and Mojisola also examine how global regulatory differences influence organizational behavior, the role of governance frameworks in managing data risk, and the importance of building internal awareness and accountability. The discussion highlights how organizations can strengthen their approach to privacy by aligning legal, technical, and operational perspectives while ensuring that data practices remain consistent with user expectations and regulatory requirements.
E280 - Federica Fornaciari, Full Professor and the Academic Program director for the MA in Strategic Communications at National University
Federica Fornaciari, Full Professor and Academic Program Director for the Master's in Strategic Communications, National University https://www.nu.edu
In this episode, Debbie Reynolds "The Data Diva" speaks with Federica Fornaciari, Full Professor and Academic Program Director for the Master's in Strategic Communications at National University, about how communication, media narratives, and cultural values shape societies' understanding of privacy, technology, and artificial intelligence.
Federica shares her background studying communication, journalism, and privacy research, including her work examining how media narratives in the United States and Europe have shaped public perceptions of privacy over time. The conversation explores how privacy is often framed as a fundamental human right in Europe, whereas in the United States, it is frequently treated as a consumer or transactional issue, shaping both regulatory approaches and public expectations.
Debbie and Federica discuss the role of AI literacy in privacy protection, emphasizing that people increasingly share highly personal information with generative AI systems without fully understanding how their data may be collected, stored, or used. They also explore the ethical responsibilities of organizations developing AI technologies, as well as the importance of transparency, accountability, and the embedding of ethical values in algorithm design.
The conversation also addresses emerging risks, including deepfakes, the erosion of public trust in digital information, and the challenges of identifying manipulated content. Debbie and Federica discuss the importance of media literacy and education in helping individuals recognize these risks while also acknowledging that technological detection tools often lag behind the creation of synthetic media.
Finally, the discussion explores the risks of algorithmic inference in areas such as healthcare and decision making, the importance of keeping humans in leadership roles when using AI systems, and the need for ethical frameworks that protect human rights, avoid bias, and prioritize transparency and accountability. Federica concludes by emphasizing the importance of combining technology design, human literacy, and regulatory frameworks to create a more responsible global approach to privacy and AI governance.
By popular demand, Debbie Reynolds Consulting is now offering executive briefings on emerging data privacy risks and how companies can avoid them. To learn more, visit the Executive briefings page on my website.
E279 - Bob Carver, CEO of Cybersecurity Boardroom
Debbie Reynolds “The Data Diva” talks to Bob Carver, CEO of Cybersecurity Boardroom, about the evolving cybersecurity and privacy risks created by emerging technologies, connected devices, and increasingly sophisticated threat actors.
Bob shares his path into cybersecurity, beginning with a career managing commercial real estate before transitioning into information systems and eventually helping build one of the early internal security programs at Verizon Wireless. He reflects on how cybersecurity has evolved from basic perimeter defenses such as firewalls and intrusion detection systems into a far more complex environment where organizations must secure interconnected systems, APIs, cloud services, and AI technologies.
The conversation explores several emerging risks associated with artificial intelligence systems, including model inversion attacks that allow attackers to extract sensitive or proprietary information from AI models, as well as the potential theft of entire AI models through repeated API queries. Debbie and Bob also discuss the security risks associated with agentic AI systems that have administrative permissions to interact with files, databases, or enterprise systems, highlighting the importance of strong guardrails and controlled access.
Privacy risks related to connected devices are also discussed, including smart televisions and other IoT technologies that continuously collect and transmit user data to manufacturers and data brokers. Debbie and Bob examine the broader implications of large-scale data collection and the challenges individuals face in maintaining visibility and control over their personal information.
The episode also covers common phishing attacks that mimic legitimate security alerts and the importance of verifying requests through official platforms. Finally, Bob discusses the potential future of cybersecurity, highlighting the role that zero-trust architectures and post-quantum encryption may play in strengthening long-term digital security.
The Data Diva Talks Privacy Team Credits
Host – Debbie Reynolds “The Data Diva,” Debbie Reynolds Consulting LLC
A Data Diva Media Production
Producer - Data Diva Media
Producer and Research – MK Holmes - Data Diva Media
Graphic Design - Data Diva Media