E298 - Laura Pleskatcheva, Data Privacy and AI Governance Operations

The Data Diva E298 - Laura Pleskatcheva and Debbie Reynolds (33 minutes)
Debbie Reynolds

[00:00] Debbie Reynolds: The personal views expressed by our podcast guests are their own and are not legal advice or official statements by their organizations.

[00:11] Hello, my name is Debbie Reynolds. They call me the Data Diva. This is the Data Diva Talks Privacy podcast where we discuss data privacy issues with industry leaders around the world with information that businesses need to know.

[00:25] I have a very special guest on the show, a fellow Chicagoan, Laura Pleskatcheva.

[00:30] She is a data privacy and AI governance operations expert. Welcome.

[00:38] Laura Pleskatcheva: Thank you. Debbie, thank you so much for having me here. It's truly a pleasure and I'm very excited to continue our conversation that we started at the Master's conference, Masters of AI in Chicago.

[00:50] And I really enjoyed both the event and your presentation on data privacy and AI issues.

[00:56] So it'll be really nice to continue that conversation here.

[01:00] Debbie Reynolds: Oh, thank you. These are to me, these are fun because you meet the person in person and you talk and then it's a chance to have like a more detailed conversation.

[01:10] But yeah, I thought the conference was really great.

[01:13] I thought it turned out really great. Well, your career fascinates me. I like the fact that you work in privacy and operations and then I also like the fact that you transition from finance to privacy.

[01:27] And so I love, love to hear that story and your background and why this area interests you.

[01:33] Laura Pleskatcheva: Sure. I'm really happy to share my background because my path into data privacy wasn't exactly traditional.

[01:40] So as you mentioned, I came from finance to the data privacy world.

[01:45] So I started in the corporate finance and with years in finance, I realized that's not something that I want to do until I retire.

[01:53] And, and I started to look for Corelia Switch and around the same time my good friend went from compliance to data privacy world. So we would talk about what is her work entails and what I realized that data privacy entails.

[02:10] You know, business operations, the legal background, the technology,

[02:14] that it's like a fast moving, cross functional field. And I got really excited about it and that's where I was like, this is where I would like to go.

[02:23] And then the opportunity presented itself. I made the transition without questioning and I'm very happy that I did. I still enjoy and I want to continue in the data privacy.

[02:33] It fits me.

[02:34] Debbie Reynolds: Yeah, I want to talk a little bit about the difference between compliance and what people do operationally and privacy because I feel like people who are on the outside,

[02:48] they really think about privacy as compliance, which it really,

[02:53] compliance can be part of it, but that's not the whole picture of it. But what are your thoughts?

[03:00] Laura Pleskatcheva: For sure. So Data privacy, we are very niche. It's not very common to meet data privacy professionals. But also it's good to see that the field is growing and it's getting more and more attention, especially now with AI.

[03:16] So while we are not truly the whole compliance, but we play a very important role for people personally. And I think that's what it's.

[03:24] A lot of times it's missing because we deal with personal data and it affects everybody we meet.

[03:29] So when I talk about what is the data privacy and why it's important, I always want to bring it to the personal level and to say, like, I'm not just to protect the company, I'm really to protect you and your rights.

[03:43] And that's what the data privacy is about.

[03:47] And it really started to resonate with people more and more and I'm happy to see that switch. And again, because more news come out,

[03:55] more states have privacy laws and I think it's a really good shift into people having a more understanding what privacy means.

[04:04] Debbie Reynolds: I don't think that's true. So are you seeing more just ordinary people either talking about it or thinking about privacy more? Your thoughts?

[04:14] Laura Pleskatcheva: Yes, to some extent. So just last weekend someone asked me what I do and I said data privacy. And they kind of give me a foggy look a little bit and I said AI governance.

[04:24] And it's all of a sudden clicked like, oh, AI, okay, what is the governance entail? What does it look like? What about the personal data when we talk about AI?

[04:33] So I feel like when the topics are being brought to the broader audience and it's more widely discussed and people can make those connections.

[04:42] So now AI is such a hot topic, everybody knows about it. So it's a lot easier to transition to talk about AI and then to talk about the data privacy because 99% of people now interact with OpenAI tools and they provide the personal data in whatever format that is ensures viva AI tools.

[05:02] And it's a good moment to educate people about the risks and benefits of AI tool and personal use.

[05:09] Debbie Reynolds: Well, what do you think about operationalizing privacy?

[05:14] So I think sometimes when people think about privacy again from like an outsider looking in, they think of it like, oh,

[05:22] there's a law or there's a regulation that we need to comply with, but they don't may not know what it is or how it applies to them or how to actually execute on that.

[05:33] But talk a little bit about that attorney.

[05:36] Laura Pleskatcheva: So I looked. So one of the keys, a couple of key skills that helped me to transition to,

[05:44] from Finance to data privacy world was project management and relationship building and influence.

[05:51] So when we talk about the law and an implementation, it's like a mini project every time,

[05:57] right? So we take the requirements and we build it into the execution. And that's something that the data privacy operations is responsible.

[06:06] And I don't think people realize how much of the project management and how much cross functional work we need to do.

[06:12] Because in the legal function, you know, the legal looks at the requirement, what is required and really focus on the what.

[06:19] And the data privacy focuses on the how.

[06:22] So anything that you see externally, like you visit the site and you interact with a cookie banner or you go on the web form and you provide your information,

[06:32] data privacy operations will ensure that that meets the requirements.

[06:36] So then that's how I tend to explain privacy operations, because a lot of people think it's just a legal function,

[06:43] but really we translate from what to how. And we're ensuring that when we serve our customers or patients,

[06:52] we do it in a compliant way. So it's really the how for me when it comes to data privacy operations.

[06:58] Debbie Reynolds: I agree with that.

[07:00] So for me, someone who's successful in this role,

[07:03] it really is about building relationships and so that people within the organization understand not only your role, but why you're there to help them as opposed to someone who's just going to say no to them every time.

[07:18] But what are your thoughts?

[07:21] Laura Pleskatcheva: That's a very good topic and it's very relevant to anyone who works in the privacy operations. We've been, we all been into this uphill battle of explaining why it's needed and maybe some teams having a resistance to that.

[07:35] But I will say from the data privacy operations and data privacy in general, it's a team sport.

[07:42] So we look at not only the cross functional. So I worked with it, I worked with marketing, I worked with hr. So really the scope is broad,

[07:51] but it's also about our internal relationship between the legal and the privacy operations that we need to be really holding hands when it comes to executing on compliance.

[08:02] But most important,

[08:03] I feel it's a company culture and that comes from the senior leadership. And I know that you do executive briefings and I think that's amazing work that you do to help us all to do the compliance and data privacy.

[08:18] Because if the senior leadership understands the risk,

[08:22] if the senior leadership pays attention, what it means to build the integrity and the trust,

[08:27] then it makes our jobs a lot easier.

[08:31] Because when you don't work cross functionally and you go to other teams, they are More accepting of the requirements and the requests because it comes from the senior leadership and that's the culture within the company.

[08:43] So it's really in my mind as a team sport, it's not just cross functionally, it's internally.

[08:49] And then also it comes back to the culture of a company and that helps us to, to do our jobs a lot more efficiently.

[08:58] Debbie Reynolds: I think that's true. So what's happening just in the world in general, in privacy, that's concerning you, whether it be for companies or personal?

[09:08] Laura Pleskatcheva: There are a couple of things.

[09:09] One is the speed of technology that is coming out. People in general and companies talk a lot about it. How do we keep up with all the technological changes even when it comes to AI?

[09:21] The speed, the nuances,

[09:23] the new things. I feel like technology is really ahead of the regulatory bodies and you know, regulation is a bit behind and technology is evolving very fast. So that concerns me not just from the company perspective,

[09:40] but also from the personal use to understand the risks that come with a technology. I think that's one of the things.

[09:49] Another what I'm noticing across multiple companies and fields that a lot of focus now is on AI,

[09:56] but data privacy as a field didn't go away.

[10:00] It still exists. Right. And it's still important and for companies to have kind of the equal attention to it. Right? Because we see the regulatory bodies are still active and companies get fined.

[10:13] So data privacy and state laws didn't necessarily go away.

[10:18] So now we just have extra thing to on top of data privacy is to ensure that AI is being done compliantly as well.

[10:26] Debbie Reynolds: I think so. I've heard a lot of companies say, well,

[10:30] we could do whatever we want with AI because there are no regulations. And it's like, but AI uses data and data is regulated,

[10:39] right? In some ways. And then even when there are gaps, like when like the US doesn't have a federal data privacy regulation. But what I'm seeing, and I want your thoughts, I'm seeing a lot of companies push down requirements to their third parties,

[10:59] saying I have to align with GDPR in Europe, then I want you to align with them because that's part of our business practice.

[11:08] So basically what I'm seeing is a lot more pressure, business to business,

[11:11] on making sure that companies are handling data correctly because that can,

[11:18] not only that,

[11:19] could they have regulatory implication, but then also business implications.

[11:24] What do you think?

[11:26] Laura Pleskatcheva: Oh, for sure. So vendor management and the third party risk management is a big topic.

[11:32] And how do you ensure that your vendors or people that you work with right outside of your company and outside of direct influence treat the data the same way you do, right?

[11:45] So a lot of companies spend time to draft really meaningful agreements,

[11:50] right? When it comes to data practices. But from data privacy operations it's like how do you audit and how do you really understand that whatever wasn't put in place for data agreement audit a production agreement that actually happens in the real time and in the real world.

[12:10] And I think we need to spend more time working on those relationship and building that trust between our company to company and not only company to customer.

[12:20] Debbie Reynolds: So we just talked about third party risk.

[12:23] What are some of the challenges that come in with third party relationships? So in my view I can just give you my perspective.

[12:33] And this has just been evolving over time and it's so funny to me because before a lot of data privacy regulations or requirements were coming down,

[12:44] a lot of times a third party would say, well it's not my responsibility to do X with data because the parent company does whatever. And it's like, well no, you have a shared responsibility.

[12:57] You don't have the same responsibility as maybe the parent company, but as a third party you do have responsibility. So you can't just say well they take care of it and then we can do whatever.

[13:09] But what do you think?

[13:10] Laura Pleskatcheva: I really agree, like the third party needs to be held accountable because they're extension of our company when it comes to processing and touching the data.

[13:21] So we spend, and I've seen companies spend a lot of time negotiating the contracts to really put the right protection in place. So you're protecting your company when it comes to outsourcing of a data for a better lack of a description.

[13:37] And also it's your responsibility to protect your customers data to ensure that the parties that you engage to and the vendors that they're really going to take care of that data.

[13:48] Debbie Reynolds: I'm glad that I'm seeing more of evolution and more less pushback from third parties around that data handling and them having a better understanding of what their part is to play.

[14:02] But I think it's so funny because when I hear like a lot of conferences that I go to or things that I read, they talk a lot about how difficult the third party risk issue is.

[14:14] And it is a difficult issue.

[14:16] But companies have third parties. So it's not like you're gonna ever go away from third party risk is always going to be there. What do you think?

[14:25] Laura Pleskatcheva: That's true. And I feel, you know, now when we are more and more connected in terms of our systems and our technology,

[14:34] we don't build systems just by ourselves. We buy systems. Right. And we adapt to our needs. So just by default that means we have a system that is somewhat shared.

[14:47] Right. So building our internal controls,

[14:50] what data can be accessed by the vendor,

[14:54] as well as understanding what vendor does with the data. Right. So that comes with meetings and vetting the vendors. Right. We spend a lot of time vetting the vendors and understanding the practices.

[15:06] And it really just put in the time of how vendors process our data.

[15:11] I think that's one thing important and another one is the regulatory activity also helps. I feel that companies can take it more seriously that they play the role as well, that it's not just like one company responsibility that that becomes a shared responsibility.

[15:29] So regulatory bodies and what we see in enforcement also helps.

[15:35] Debbie Reynolds: I want your thoughts about AI governance. So I think AI governance has changed a lot of the way that we think of governance in a way because now we have applications that,

[15:50] let's say before,

[15:52] before people went crazy about AI.

[15:55] Let's say a company bought a tool and you want to implement it, you evaluate it, you figure out what the privacy risk are and then you implement it and they kind of go forward.

[16:05] Right? You just make sure that people are doing what they need to do with the data.

[16:09] I think AI is different because with these tools the tool that you bought is changing.

[16:19] So it's like, okay, the thing that it did when you on day one, it can do different things now. But how do you think about that in terms of governance?

[16:29] Laura Pleskatcheva: Right. So our, so when it comes to that governance, our step one is to understand what data the model gets to. Right? And we work to limit what data that model can work with.

[16:42] So I think like limiting the feeds and limiting what model can ingest,

[16:48] that's a step one in the governance because if you have a limited data,

[16:52] then it limits the risk and then the requirement is to have a human in the loop and also evaluate the models and evaluate the technology.

[17:02] Putting in AI terms into the third party vendor agreements,

[17:08] that's a big effort as well because then we have a contractual agreement of how those models should be functioning and what data and what can be done with the data that the models gather from our pools.

[17:21] But I think the step one is to truly limiting the data that can go into the model because then it limits the risk,

[17:30] even if the model drifts.

[17:33] Debbie Reynolds: I agree with that and I'm glad that you brought that up because I feel like some people think, oh, AI is this thing where you just throw everything in and then something magical comes out at the end.

[17:45] But really it is about that curation step, figuring out what, first of all what you want as an end result,

[17:53] what is the right data to put in there before you throw it into a model. And so drift is an issue also the personal data part is an issue as well.

[18:04] But then you know, you're, you're basically poisoning or messing up your tool if you just throw too much junk in it. Right. So being having that curation step,

[18:16] that's something that we hadn't thought about before. Like in the big data days, we were like, let's just take everything and throw everything in and then something magical is going to come out.

[18:24] And it's like AI just doesn't work that way.

[18:28] Laura Pleskatcheva: All right. Then we also have to be very careful of what vendor of the AI will do with that data.

[18:35] So that's where I feel like another guidelines and guide rails come in to really understand if your data will be used for training the own model,

[18:45] how the outcomes will be communicated. Did our inputs help the outputs in the future for the company?

[18:53] These are all the questions that we need to ask the vendors to really ensure that our data that feds through AI is going to be held accountable.

[19:07] And I think that's very important also.

[19:09] But again the first step is to limit what the model can digest and then it goes back to relationship and as a team.

[19:20] And that's where I like that theme for privacy. Because to understand the business outcome is so important.

[19:26] So our the core doesn't change of a tool.

[19:30] So if you collect the data with AI and you process of the AI, what is the outcome, what you're looking for?

[19:37] Data limitation.

[19:38] Do you really need like all these 10 points of data to get to your outcome or only 2 points of data will give you the same outcome? So these are conversations that data privacy needs to have.

[19:50] Every business that support to really understand what is absolutely needed and take out anything that's extra because AI shouldn't be having that in my view really remains a core when it comes to AI.

[20:06] Debbie Reynolds: I agree with that wholeheartedly. I guess this is the secret sauce,

[20:12] the thing that I feel that differentiates people who are successful in this field. But how do you go about building relationships across the business and then also like having champions of privacy in different teams that you work with across business?

[20:30] Laura Pleskatcheva: That's such a good question,

[20:32] Debbie.

[20:33] When we talk about the influence of our authority and there are good days or there are bad days,

[20:39] I'm going to admit but it all goes back to, to some of it is personality.

[20:45] But it's also for business to have trust in you by that if you spend the time to understand the business needs and to understand the outcomes and then you go from that mutual understanding of going towards the same goal just in a compliant way.

[21:04] And that's how you build the trust with people. And every time you come with them with a new request requirement or increased requirement,

[21:12] then they listen to you because they respect you in the sense that you're not going to just have your own agenda, but you're going to be doing, working together to support the business need.

[21:23] So I always look at the data privacy and AI now as we are still a support function,

[21:31] right?

[21:32] And our job is to ensure that company process the data with integrity and that it's a shared effort.

[21:42] But you also have to think about like what business needs. And once you have that mutual understanding,

[21:49] then the building the cross functional relationship becomes a lot easier.

[21:55] And for the privacy coordinators,

[21:57] I feel like the key is to get the right group of people that they really work with a personal data that they interested in the privacy field.

[22:09] And a lot of it comes to education and the training for privacy coordinators. So then can be, they can be extension to you across the teams when you're not present.

[22:20] And that's something that requires continuous work and continuous training and then that helps to become like a tighter group and

[22:29] Debbie Reynolds: you can't wait until you have like an emergency for that.

[22:33] Laura Pleskatcheva: It needs to be built up front because if you show up and a lot of it in relationship comes to building it up front because when you come to something happens and it needs to be fixed, it's a bit too late.

[22:46] And people might view it as it's not my job to do.

[22:50] Your emergency is not my problem.

[22:53] That's true.

[22:54] Debbie Reynolds: One thing that you had talked about I think is really interesting. I just want your feeling about it. So a lot of times I see people when they want to do things in AI,

[23:07] they don't automatically see how it connects to privacy.

[23:11] You know,

[23:12] so like maybe company initiatives, they want to, okay, we want this tool.

[23:17] And they may not exactly understand that they need to loop in the privacy person. But I mean how are you seeing this play out in companies? Are you seeing them like forge ahead of AI and then figure out, oh wow,

[23:30] well we made this misstep and then now we have to talk to this privacy person? Or are they understanding at the beginning that as they're moving into these AI tools that they need to bring in or loop in the privacy folks?

[23:44] Laura Pleskatcheva: Well, let's take another great question because it touches on the privacy by design.

[23:49] And for me that's another core concept that it's not new just because AI is new.

[23:56] Similarly to data minimization and limitation, that privacy by design,

[24:02] that's something that needs to be built into the programs when AI governance comes, because not all of the AI tools deal with personal data.

[24:13] But you need to incorporate the right questions and work with a business that you know is in front of the AI implementation.

[24:21] And you come in with your correct set of questions that might trigger the privacy review. And that's when we can talk about what data can be ingested, how it's going to be used and, you know, everything else follows.

[24:35] But embedding the privacy by design process early on,

[24:40] I think that's the key that helps you to avoid any going back and misunderstanding later on.

[24:47] And another thing with the AI models, I think these are, you know, they are expensive and time consuming to build in.

[24:55] So going back and fixing it is going to be a lot more effort than asking the right question at the beginning of a process.

[25:03] So it goes back to the relationship and to a team sport as a theme of today's right. So you need to know who is your business AI person,

[25:12] who takes in the cases, who look at the cases, and you need to work with them together to embed that privacy by design to ask the right questions at the right time.

[25:22] And that's how the privacy becomes an equal partner when it comes to AI governance.

[25:28] Debbie Reynolds: I have seen a company,

[25:31] actually a pretty big company,

[25:33] who shall remain nameless, but their process was they would build these tools and then before it got released, they do like a privacy review.

[25:46] And then a lot of times because they did it so late,

[25:50] they had to either not release the thing or they have to go back. And to me it just seems like, like why waste all the time and money when you could do that up front?

[26:00] What do you think?

[26:02] Laura Pleskatcheva: No 200%.

[26:04] Because that's the core concept of a privacy by design. It's even outside of AI.

[26:09] If you look at just our day to day technology and systems that we use,

[26:15] if you talk to it before the project begin into existence,

[26:21] you can build so many guardrails to build a system or AI tool in a compliant way and it's going to cost you a fraction of what it will cost to go back and do the change management and change the system.

[26:36] Then you have to go to vendors, it becomes a whole thing.

[26:40] So it's always the best thing is to look the privacy early and that's like my messaging. When I work with different groups and the privacy coordinators, I have my little chart of what personal data means and I show it every.

[26:54] In a lot of conversations that I have, I'm like, this is what the personal data, if you touch any of that,

[27:01] let me know. Let's evaluate it in the beginning of your project,

[27:06] not at the end because it might be, you know, a lot more time and effort consuming and then everybody ends up unhappy. So let's keep everybody happy and look at the privacy before the projects go live.

[27:19] For sure.

[27:20] Debbie Reynolds: When you're trying to talk with groups and trying to get them to champion privacy, do you find at all that sometimes it is helpful to give personal examples,

[27:31] like how data is handled in their own personal life? Does that help at all?

[27:37] Laura Pleskatcheva: For sure. So I introduced a new topic for me. It's a Privacy in the News and we talk about it,

[27:45] what it means to you personally. Do they feel like these laws to you as a person? Do they make a difference?

[27:52] So the latest one, and as a great example was for Maryland and regulation of dynamic pricing where you cannot charge people less or more for the same carton of X just because you have the data and people agree that it's a good regulation.

[28:11] So it's not like legal sometimes is viewed as a bit of an enemy and we stop some activities.

[28:19] But when you go down to the personal level and you look from the consumer or patient side,

[28:25] would you want your data to be processed and used with integrity and ethics?

[28:32] And then I feel like then people really switch the thinking of importance of the topic because we are not just looking at the company, we look at the person and that makes a difference.

[28:45] Debbie Reynolds: I think it's a fascinating time to be in technology because it's just so many things happening and the rapid pace of things happening. I'm glad that I was happy to see all the evolution in AI because to me it became more of an opportunity to understand or talk about why privacy was important and why that data is important.

[29:09] And even your example about the price changes based on people's personal data, that does really hit home people,

[29:18] right?

[29:18] Laura Pleskatcheva: And again, the ki is new and exciting and everybody wants to be a part of it. We are still in a learning environment of how we can use it outside of a prompting.

[29:31] Right now we talk about building agents and there's a lot of buzz and excitement about the topic.

[29:37] But the core principles for me, they remain the same,

[29:42] right? It's a technology,

[29:44] but our job is to make sure that data is being used responsibly what data goes into the models?

[29:51] Privacy by design.

[29:53] So it's really,

[29:54] you know, it's a Newton clock technology. But the core principles of data privacy remain outside of excitement around AI.

[30:03] Debbie Reynolds: So, Laura, if it were the world according to you, and we did everything you said,

[30:07] what would be your wish for privacy anywhere in the world, whether that be human behavior,

[30:13] technology,

[30:14] or regulation?

[30:16] Laura Pleskatcheva: I will say, from listening to your podcast, and I see that I hear the responses, a lot of falls into regulation and human behavior. And I'm on the same page.

[30:27] I think where regulatory can do more is not about just passing the limitations on the company or more requirements,

[30:35] but really educating the public of what that means.

[30:39] So if someone accepts all the cookies, if someone clicks on that ad and submits the web form,

[30:46] they should be educated of what that means,

[30:49] what data are they input and what can happen to that data. And I think regulatory bodies can do more to educate the people, to drive the human behavior, and then the companies will follow and technology will follow.

[31:04] So it's really where I want to see. It's more education for people to have better understanding what the rights are.

[31:13] Debbie Reynolds: I think that's true because I feel like once people know,

[31:16] then they can make a decision.

[31:19] They can make the best decision for themselves about what technologies they want to use or how much data they want to share. Because I think a lot of times when people are using tools or different things,

[31:31] they're not imagining that their data could possibly be used for anything other than what they said it is being used for. So just like the pricing example you gave in Maryland, like, most people don't think they're like, why would someone be using my data in that way?

[31:46] Right. And so I think a lot of it, when I tell companies, whenever you're doing something that gets away from the benefit of the person,

[31:54] you're like entering like hot water.

[31:59] Hot water territory, you know, because it's not just regulatory, it's also consumer trust as well.

[32:05] Laura Pleskatcheva: Right. And so that's something that we talk about in privacy. That privacy is really about building trust between the company and the consumer and educating consumer of what that trust should look like.

[32:17] I think it's a big component of what regulatory can do.

[32:21] Debbie Reynolds: Excellent, Excellent. Well, thank you so much. This is fantastic. It's been great having you on the show talking about this. I think this will definitely resonate with people who are definitely shifting in careers, then also understanding how to build that muscle within organizations to be like a champion and a person that can be successful in the privacy role.

[32:45] Laura Pleskatcheva: Thank you. For having me. Having me here. It was. It's a real pleasure to talk to you.

[32:49] Debbie Reynolds: Yeah. Excellent. Well, thank you so much. And we'll talk soon.

[32:53] Laura Pleskatcheva: All right. Okay, Bye.

[32:55] Debbie Reynolds: Okay, Bye. Bye.

Next
Next

E297 - Patrick Zeller, General Counsel, Jetstream Security