E309 - Julian Gage, Founder, Engage Compliance

The Data Diva E309 - Julian Gage and Debbie Reynolds (31 minutes)
Debbie Reynolds

[00:00] Debbie Reynolds: The personal views expressed by our podcast guests are their own and are not legal advice or official statements by their organizations.

[00:11] Hello, my name is Debbie Reynolds. They call me the Data Diva. This is the Data Diva Talks Privacy podcast where we discuss data privacy issues with industry leaders around the world with information that businesses need to know.

[00:23] Now I have a very special guest from one of my favorite cities in the world, Amsterdam.

[00:28] This is Julian Gage. He is the founder of Engage Compliance. Welcome.

[00:34] Julian Gage: Hi Debbie, how's it going?

[00:36] Debbie Reynolds: Hey, happy to have you here. It's really great to talk with you.

[00:40] Well, we had connected over email and I'm very fascinated. I love to talk to people who are in Europe and who are really in the day to day flow of data protection and privacy in Europe and doing different things and from different cities.

[00:56] So I thought you'd be a really great person to talk to,

[01:01] especially because of your role like you do DPO work and a couple of other things that we can get into. But tell me a little bit about yourself, your interest in data protection and privacy and how you decide to start your own company.

[01:16] Julian Gage: Yeah, happy to. Thanks again for having me on. It's absolute pleasure from my side. I'm based in Amsterdam. I've been here around nine years.

[01:25] I did go back and forth between here and the us. I saw a family over there and I was born and raised between Chicago and Ohio actually. So yeah, it's been a good move over here.

[01:35] We'll see what happens going forward. But in terms of my general interests, first off, within the privacy space, I started my own company here five years ago. It's been really interesting to build this up from scratch.

[01:46] Doing some freelance work initially.

[01:48] I'm now moving into DPO services,

[01:52] Article 27, representative services,

[01:55] EU, AI act, especially over the last year work too.

[01:58] And yeah, it's been very interesting just to build this from the ground up. Especially in the last year we've grown quite a good amount and that's very exciting career wise.

[02:07] Going back. I started off within cybersecurity and internal and external audit scopes.

[02:13] Also got into financial audits, ethical audits, every sort of audit you might be able to think about.

[02:19] And it was super fun and it was very good I think to start out my career because it just made me able to quickly understand what the gaps are and different sort of functions and whatnot.

[02:31] And then eventually moving into privacy since 2016. That's where I've been since I work both on the privacy,

[02:37] legal side, privacy program,

[02:39] you name it and I'll. I'll Stop there, but happy to go into more details, of course.

[02:45] Debbie Reynolds: Oh, I didn't know you're a Chicago connection. So I'm in Chicago.

[02:48] Julian Gage: Oh, very cool.

[02:50] Debbie Reynolds: So it's really cool.

[02:52] I love Chicago.

[02:53] One of the things that you said is really interesting is about your work and your background in auditing. And so I think that helps a lot when you're talking to companies about the things that they need to know and the things that they need to document.

[03:07] But I think the word audit sounds scary, but how do you approach companies when you tell them that they need an audit of some sort of.

[03:16] Julian Gage: Yeah, I mean, that's a good point. It is definitely scary. And it's often combined with just being. Being policed, even from, like, an internal auditor, often, which I've been. So the way I approach it is just explaining that it's a way for them to know what they should know about at the end of the day.

[03:32] Right. It's a list of the risks that are actually still needing to be addressed. Whether they accept those and move forward, which is perfectly fine in many cases,

[03:41] or do something about it, at least they therefore can have the knowledge and it's really there for them to use as a tool. And that's really how I go into it first.

[03:52] Debbie Reynolds: You know, you work with US Clients, too. It's a very different mindset. Right. So a lot of times when we think about audit in the US we think about the IRS like we did something wrong.

[04:01] Our taxes and the IRS is coming.

[04:04] But how do you. Part of that process is actually gaining trust with the company and getting them to tell you things that maybe aren't written or getting them to admit things they had done and do it in a way where you say, okay, we just need to document where you actually are so that we can benchmark,

[04:23] as opposed to,

[04:25] you know, us trying to,

[04:27] like, slap your hand and tell you, okay, this is wrong.

[04:30] What do you think?

[04:31] Julian Gage: There's a few ways to do this, and it does differ from where you're coming from. If you're an internal individual,

[04:38] which may be more difficult than maybe being external, which.

[04:42] The reverse can also be true, too, in certain cases. But the few things that I like to do is, first off, just explain in clear terms what we're asking for.

[04:50] That can immediately reduce the amount of confusions back and forth, because whether they intend to, say, hide things or not, if they don't really know what you're asking for on the same level of what you're intending,

[05:02] things might get left out. Right. And so I think having clarity in terms of what you're asking for is the first step.

[05:08] Apart from that,

[05:09] it's also important to present things that you are there to help that you're not going to be a blocker of that. It just sort of to uncover things that could lead to risks and could lead to them being whoever the business owner or team that you're talking to.

[05:24] It could lead to issues for them down the line from not being able to do what they wanted to do. Not from a compliance perspective even, but it could be just from a business strategy side of things.

[05:32] So, you know, pointing those things out usually I think will, will help a lot.

[05:37] And let's see, I mean, to be honest, I haven't had this much issue from a privacy perspective in many years. Especially compared to a real external or internal audit. That's a very different story.

[05:49] But I think it's just. But now that I think about that,

[05:53] one last thing I'll mention is stakeholder, just stakeholder management.

[05:57] If you're able to successfully get say business management of the teams that you're auditing on your side, that it's a benefit and that they do want their teams to really be truthful and really deep in terms of what they provide to you,

[06:11] that's a huge win as well.

[06:13] Debbie Reynolds: Yeah. And then also I found, and I want your thoughts is that if people understand that you're fact finding and you're trying to figure out where the company is and that and where you need to go or where the spots that you need to improve,

[06:28] they don't feel so guarded about telling you what's happening because sometimes people feel like, oh, I'm getting in trouble because I was supposed to be doing this backup and I wasn't doing it or whatever.

[06:39] I'm telling them a lot of times and I want your thoughts. I'm like, these assessments and audits, they need to really reflect what you're actually doing should be operational, not aspirational.

[06:50] So you can't say you delete data every day and then you don't do it.

[06:55] So it's better to be truthful, find a cadence that you can deal with and you can do as a company and then document what that is and then if there are gaps, you can work towards improving.

[07:07] But what do you think?

[07:09] Julian Gage: I agree and that's really well said. One thing I'll add to there is that is really beneficial is presenting it in a way that can actually help the person that you were literally auditing who maybe didn't do anything at the end of the day, there's probably things that they missed that might show up as a gaps in an audit report,

[07:26] but that might be because they're too busy in other things. Maybe they need more support,

[07:30] which is going to help that person. It's going to have them have less things to do every day. Right. Some of these things, if you explain it that way, also can help out too.

[07:39] Debbie Reynolds: Yeah. And I want your thoughts about basically,

[07:42] like roles.

[07:43] So like, for example,

[07:45] let's say you're working with a company,

[07:49] some bigger companies,

[07:51] they may have such a big team where they have different people who do different jobs. And so when you're assessing how they're doing things and you're saying, okay, well, this person wears this hat or this person wears this hat,

[08:08] it may be easier in a bigger company where someone really owns those things. But like in a smaller company where people are wearing many different hats, a lot of times things can get lost.

[08:18] So let's say, for example, and I want your thoughts,

[08:22] let's say John was responsible for documenting what got deleted and John left the company,

[08:30] but nobody took over that role.

[08:33] Yeah.

[08:34] From John. So it's a gap within the organization. But how do you deal with that?

[08:40] Julian Gage: Yeah, I mean. And do you mean more about uncovering that or what we do once we uncover, become aware of that.

[08:46] Debbie Reynolds: Well, what. What do you do when you become aware of that?

[08:51] Julian Gage: Yeah, I mean,

[08:52] with these situations, that's about just.

[08:55] It's really good question. I mean, the overall goal is to fix whatever the issue is. Right. And so first off is to take a look at what is the immediate risk.

[09:06] So if there are certain systems that, say, shouldn't be accessed by certain people on that. Now, now it's an issue.

[09:12] Close that out first and then worry about the root cause after.

[09:16] Right. If it's something that has less immediate concern,

[09:19] then you just go ahead and work on the root cause and move on. Right. The root cause can be done by doing a sort of like a postmortem assessment, which we typically do on the breach side of things, applying the same principles to these situations,

[09:32] that enables you to again, fix the immediate stuff as well as just fix the root causes as well. And that's usually what I'll do in these situations.

[09:39] Debbie Reynolds: I think when you talk about audits and assessments, I feel like the Europeans are accustomed to this. So it's not.

[09:45] You don't get as much pushback or. That's my experience. I don't get as much pushback from people in the EU and different countries about that, except the U.S. right. So I think from a legal mindset, even before a lot of the data protection and data privacy laws came about,

[10:03] and I literally heard people say this,

[10:06] counsel to other companies, they're like, well, if you don't write it down,

[10:10] then you can't be held accountable for not doing something.

[10:14] So, but,

[10:15] but what's happening now with especially the data privacy legislation in the U.S.

[10:22] obviously, we're not the same as Europe, but we're seeing some states borrow liberally from some of the practices and the things that we're seeing happen in Europe. And so right now, for example, we have, like, a patchwork of states.

[10:37] They have laws around data privacy and data protection,

[10:40] and some of them are asking for, like, assessments and things. So some of these things are new to some of companies in other states where they never had to ever show or ever demonstrate what they're doing around data protection.

[10:57] How are you seeing that play out in your business?

[11:00] Julian Gage: Yeah, I mean, it's definitely applicable to a lot of the companies that we work with who don't only have to comply with, say, the gdpr, but also the CPRA and many other US State laws.

[11:12] So the impact is high from what they have to comply with perspective. But operationally it's not that high and it's not that much work in reality, the way that we sort of tend to propose things.

[11:23] And the reason for that is every time there's a new regulation, a new state, in my experience, most of the things are not actually inherently that different than what my clients already are having as part of their risk framework, where they've agreed to, that they're going to be doing internally across the board,

[11:38] which are baked in from different international and local regulations. Right. And so there are stipulations and differences, and that's when we will raise those things. And that's a big job in and of itself.

[11:49] Right. Tracking all that stuff and assessing what's going to apply to what company in terms of scope.

[11:55] So I would say the impact is certainly there.

[11:57] But I think as privacy professionals,

[11:59] I find that we tend to oftentimes, you know,

[12:03] perhaps get overwhelmed with all these changes.

[12:06] But I think if you just take a breath, take a step back and see what's actually changed, in my opinion, I don't think it's been that much of an impact to companies because they would have already had CPRA for many years,

[12:19] or they would have already had if they're a global company. And GDPR requirements that many of them probably applied across the board instead of taking A jurisdictional approach to controls and how they comply with different products and,

[12:32] Debbie Reynolds: and yeah, yeah, yeah, I think definitely. Right. The companies that have some business in the EU or other jurisdictions that have more of the,

[12:45] a tighter framework of laws and regulation,

[12:48] it tends to make that other stuff easier downstream. I think it's harder when companies were like, okay, let's just do what Louisiana says or let's just do what Connecticut says and then it just makes it harder.

[13:01] Right. Because you're so narrowly focused on that. You know, I'm thinking about this in terms of the big picture.

[13:08] Right.

[13:08] Julian Gage: That's a really good point. I mean, most of the companies that I come across don't have those issues because they tend to not be having that, just that mindset or just from where they're targeting commercially.

[13:20] But I can definitely imagine that being an issue for many, many, especially the smaller companies too,

[13:25] who just operate locally and then they decide to open up the doors.

[13:29] That's a really, really good point.

[13:32] Debbie Reynolds: Well, I've seen it all. I've seen it all, that's for sure.

[13:35] What's happening in the world of data or data protection that is concerning you most? Like something that you're seeing maybe on the horizon or you're seeing coming up in conversations with clients that are like, concerning you.

[13:51] Julian Gage: Number one is the EU AI act for sure.

[13:54] And whether they mention it by name or not, just utilizing AI, period, that's going to be the number one concern that I see over and over for the last even year plus time,

[14:03] for sure. Companies are just, you know, first off, it's good, good that they're raising this. To me, that means that, you know, they, you know that throughout the last, what, 10,

[14:13] almost 10 years now of GDPR that they are that, that muscle of knowing when to raise things, your compliance staff is working.

[14:22] But yeah, definitely the AI side, there's a lot of concerns on, on just when they're inputting business data and employee data through different tools or not having awareness of what they should and shouldn't do, they read these articles that talk about leaks from AI tools being used inappropriately.

[14:40] This is definitely the number one area that I've seen be most of concern.

[14:46] Debbie Reynolds: Yeah.

[14:47] Are they now, the,

[14:49] I think the European approach is very different than the US approach. Obviously we don't have regulation in the same way that you all do in the eu, but I feel like in the US just in general, the thing is, like the way people approach things is like, let's just do it and then pay the consequences later,

[15:09] as opposed to be the more European approach, it's like, let's have a proactive way to think about this before we start doing things as opposed to let's just throw everything into AI and then just figure out what happens later.

[15:25] What do you think?

[15:26] Julian Gage: Yeah, I think so. You know,

[15:28] and it speaks to just the historical requirements. Right. I do think that this will change and hopefully, hopefully or not depends on who you are, but I think within a matter of years it shouldn't be that much different.

[15:39] I wouldn't be surprised if it is,

[15:42] but it really depends on the scope that we're talking about. You know, with globally scoped companies,

[15:49] they're well aware of this and it won't change much I think for them. But I think for mid sized,

[15:54] smaller tier companies who are operating in the U.S. certainly they're going to have less of a, they're just going to care less about this compared to, you know, localized companies in the EU where companies have understood for a long time the issue and the potential concerns by not sorting out what you need and as far as compliance with these things.

[16:11] Debbie Reynolds: Yeah, right, right. And then thinking.

[16:14] So our,

[16:15] a lot of times we, you hear people in the US talk about like shifting left,

[16:20] which meaning like looking at things before they like progr within the organization. Especially if you think about data as a life cycle. Right. So thinking about the data life cycle and being intentional at those early stages really help you reduce risks on the later stages.

[16:39] And that's true for data privacy and data protection as well. Right.

[16:43] But I think what some of these laws have done, thankfully is push more of that thought process more to the left or more to the start as opposed to let's just do whatever and then we'll try to try to remedy problems at the end.

[17:00] Julian Gage: Agreed, Agreed. Yeah. And with that said, one thing I'll add on there is I do find more often than ever that within my clients,

[17:09] even when they don't even need to, they'll be raising things just out of caution. Right. Shifting left earlier on in the product life cycle, whether it's a product for example, or a new commercial strategy coming out to our team sooner.

[17:20] So I think that it also mimics what you were just saying.

[17:24] Debbie Reynolds: Yeah. And then I think that, and I want your thoughts about this on the EU AI Act. So when the EU AI act passed, I saw people kind of panicking about it.

[17:35] They were so overwhelmed. Obviously the bigger companies didn't like it, but some of the smaller medium sized companies, they got very panicked about it. And for me it's like,

[17:47] do you Even do these things. It's like almost like, well, gdpr where people are very overwhelmed by it, but it's like you have to look at the law, the regulation,

[17:56] and apply it to what you're actually doing in your business. So not everything that you do in your business will apply or be applicable to this. So that's how I open this thing to people.

[18:10] And I think with the EU AI act is very similar. So, like if someone's writing,

[18:15] drafting an email, AI that's not considered like high risk unless you're doing something weird with someone's personal data or making decisions about them. But how do you broach those conversations with your clients?

[18:28] Julian Gage: Yeah, same way. In short, first off, explaining that most of the things that they're doing is unlikely to require almost anything that's not already required by the gdpr, which are things that they often already had in place.

[18:39] Or from even a US privacy perspective,

[18:41] for example,

[18:42] training your staff on appropriate data practices,

[18:46] that's one of the main requirements. You just need to make sure that those, that, that training extends to AI literacy, things like that. Right.

[18:53] And also ensuring that you're telling people what you're doing with their information. That was an already existing requirement.

[18:59] There's arguably one new one which is around making people aware that they are utilizing an AI or a chatbot or things like that. And plus some standard, maybe documentation requirements to have internally,

[19:11] depending on what you're doing with the AI systems.

[19:15] And so there's not really that much more than that for most companies because they don't typically get into what's considered a high enough risk as from the EU AIX perspective.

[19:25] So similar. Yeah, I've seen the same thing.

[19:27] Early fears,

[19:29] people reaching out.

[19:30] I think after, after a few conversations, you know, it's, it's calmed down a bit. But with that said, I think it's, it's. We're still going to continue to see the same exact thing over the next year or two,

[19:41] minimum,

[19:41] especially with the delay in the mandates now going into 2027.

[19:46] So there's been a change for those who don't know in terms of what you are going to have to comply with this year, mostly for the high risk stuff,

[19:55] as far as the EU act is concerned, that's been delayed till next year. And I think when we get closer to those dates, I think it's late next year, in 2027, we're probably going to see the same questions raised again.

[20:07] Debbie Reynolds: All right. Has the delay helped or hurt?

[20:11] Julian Gage: I'll definitely helped. I mean, from a business perspective, I think us as privacy professionals, we're going to get more and more in demand. And so it depends on what your role is as well.

[20:19] If you're internal, it might be more annoying because you're going to get more questions again twice,

[20:24] probably this year, again next year, and probably the year after then too. Right. So to be fair.

[20:29] But even with that said, I think it has helped because I do have some clients who definitely engage in high risk activities and that it has been a benefit from having extra time,

[20:38] legally speaking. From a regulation perspective. However,

[20:42] they still have, they still have customers who know that these requirements are in place even though they're not enforced yet.

[20:48] Their customers are still wanting and needing these requirements now today.

[20:52] So they have the ability to make the argument that, well, we're working on it, if they don't already have it in place, which is good for the commercials. But it's also doesn't really change that much if the customer says, and this has happened many times, that we want you to be compliant now,

[21:07] even with all the high risk obligations.

[21:09] Debbie Reynolds: Yeah, okay, that's a very interesting thing.

[21:13] I think that's true. Right. Where companies, that gives them more trust and more confidence in a company if they know that you're being proactive as opposed to waiting to the last minute to do things.

[21:25] So I think it could definitely be a business driver and it can definitely help bolster the reputation of the companies that are not waiting to the last minute to try to comply with things.

[21:38] Julian Gage: Yeah, totally agree.

[21:39] Debbie Reynolds: I have a question.

[21:40] This is a very unique question that I like to talk with people who do DPO services about.

[21:47] And this is about your role as an advisor to companies,

[21:53] not like a dictator.

[21:56] So some people early on, like I've, I used to read people on LinkedIn and they were like, oh,

[22:03] if the company doesn't do data protection the way that I wanted to do, then I,

[22:08] I quit or I do all this other type of stuff and I'm like, well,

[22:11] when you are an advisor, you advise and then the company is,

[22:16] you bring them the information and then they have to choose and decide how they want to,

[22:22] to move forward. Right. And you're there to enable them to move forward and do what they chose to.

[22:29] But what are your thoughts about that? Cause I feel like, I don't know when I hear people say that, I'm like, you must not do very much client work because that's just not the way things go.

[22:37] But what do you think?

[22:39] Julian Gage: Totally agree.

[22:41] Early in my career, you know, coming off of audit, which is not so much like an advisor, you're literally saying what the rules are and you're testing against them and whatnot, and what needs to be in place regardless.

[22:52] And there's an actual, you know, audit board that's requiring all those things to be done. Coming out of that, it was interesting and I had to sort of change my approach early on into becoming more of that advisor.

[23:01] That's also what I've seen with many of our peers within the privacy space.

[23:05] What it comes down to is from what I've seen is what your background is. I do tend to find that certain personalities and certain people coming out perhaps from a legal background or a GRC background or security might have different averages in terms of what I see.

[23:21] In terms of how they approach things,

[23:23] whether they come out and say the same thing, whether it's say, for example, I'm putting in a cookie banner. It can be very simple like that. They can phrase it.

[23:31] How you word it is important.

[23:34] And I think in order to be successful in this space for most companies, depending if you of course have a company or like myself or if you operate more internally,

[23:43] maybe certain companies might even need to be more strong armed because people need to be approached that way. For some cultures, I don't know, that's probably more rare. But yeah, long story short,

[23:53] I have seen both sides. I do see it moving more toward a advisor.

[23:59] The reason, I think is with more experience, I think people start to understand in this space that there's always exceptions. There's always exceptions.

[24:08] If you're going to say something without being an advisor,

[24:11] not only might be wrong, given the information you have, things might change.

[24:15] But further than that, it's important to just be also flexible with the business. What we spoke about earlier is how do you get people to be on your side and I guess sort of to continue to give you information that you do need for your job.

[24:27] Part of that is being a human being, I think, and saying this is what I think. These are my thoughts on a privacy improvement, if you will.

[24:36] And it's up to the business, not us,

[24:38] to implement things. Especially from a DPO perspective. You literally are not supposed to be doing any of that. All you're doing is advising, that's it.

[24:45] So you need to be able to stop and move on to the next thing, even if it's upsetting, if you will.

[24:51] Debbie Reynolds: I agree. I haven't heard people,

[24:54] I haven't dug into these differences because to me it's kind of semantics.

[24:59] I've heard people debate like the difference, like what's the difference in title DPO versus something else. I don't know if you heard this this before and I want your thoughts here.

[25:11] Like to me it's just kind of more semantic. Maybe I'm wrong. But what do you think?

[25:16] Julian Gage: Yeah, I mean people call data Privacy Officer, data Protection Officer at semantics. I mean, if you do have a formal GDPR definition as an example for what DPO means, you also have different requirements.

[25:27] I think it's in Korea,

[25:28] I think Singapore.

[25:30] Right. All around the world you have different designations for this.

[25:33] I think. Unless you're trying to meet a legal requirement that requires a certain role to be called something. Right. And then designate that person internally,

[25:42] whether it's like a one pager that they sign off on or a contract.

[25:44] Fine.

[25:45] Debbie Reynolds: I thought so too. Cause I've heard people like very strongly say, oh, this role means this and this role means that. And it's like, what are you talking about? I think it just the umbrella of what you're doing.

[25:56] Like you say certain laws and regulation dictate what falls under that role. But that role can be bigger, it can be different,

[26:06] it may add different things like we're seeing, just like you're seeing. And I want your thoughts on this.

[26:12] Before the EU AI act, you were mostly working kind of around GDPR and these other data protection regulations. But because you're so close to the data and the information, people naturally started looking at people in your role to help them figure out the EU AI act because it is a regulation in Europe,

[26:32] just like the GDPR was and it fits together like a puzzle piece. But I feel like that's like a natural thing that has happened. But what are your thoughts?

[26:41] Julian Gage: Yeah, definitely. I mean I could easily have said, I know I don't care about this, ask somebody else and moved on. And I probably would have been fine in most cases because it technically is not the gdpr.

[26:50] There is overlap.

[26:52] And I think the way it's because there is overlap. That's why I think it started,

[26:55] you know, typically,

[26:57] at least early on having to do DPIAs, for example,

[27:00] looking into data uses, secondary uses, training of data. They will oftentimes these included personal data, so.

[27:08] So they were going to go to the privacy groups anyway.

[27:10] I do think that. And the reason that is why I didn't just buy just shovel these requests off to the side is because I think it is. It's been a great last 10 years in privacy.

[27:19] I think it's going to continue to be very great. But I think you got to know the EU AI act and similar regulations. If you really want to be able to catapult your role, your success, your revenue to even you heights.

[27:34] Right. I think it's going to be very easy for us as privacy professionals to just learn a few extra things that you need even for the high risk stuff. It's not that complicated, I think, to be able to do more for our clients and companies.

[27:46] Those are my thoughts. But yeah, to go back to your question, initially it is different but so close that. Yeah, I mean, I don't see this going after the security teams to review themselves.

[27:55] I don't think it's appropriate there. Or grc,

[27:58] perhaps legal in some rights, can take on the role of the EU AI act and similar AI regulation reviews. But I think privacy is the best place for it.

[28:08] Debbie Reynolds: I agree, I agree with that wholeheartedly. So Julian, if it were the world according to you and we did everything you said, what would be your wish for privacy or data protection anywhere in the world?

[28:20] Whether that be human behavior,

[28:22] technology or regulation?

[28:26] Julian Gage: Okay, so from my opinion, I think things would be much more flexible but transparent.

[28:32] Then people will just be able to move on and not get so upset and stressed about what people are doing and just actually have companies who put things up front of what they're doing and why people can decide and move on.

[28:46] I think that will solve a lot of problems,

[28:48] a lot of stress,

[28:49] and I think it's just easier for both the companies and the individuals and data subjects themselves.

[28:55] I think that also applies to a tech perspective. I think many times companies are afraid to think of creative ways of data.

[29:01] So if you want to train on my data,

[29:03] I might not care about it. Give me the option about it and maybe give me some ways to get compensated.

[29:09] Many people would love this lineup. I'm sure ethically not everyone may agree with that, but just having those options up front I think could lead to a lot of innovation.

[29:17] Add one more thing if that's okay. Yeah, yeah. In terms of the regulation perspective, here in the EU it takes so long, like many other countries and regions around the world to pass regulations and they become very antiquated over time and they don't always serve people and companies in the best.

[29:33] Right. And they have people like ourselves in the privacy space, for example,

[29:36] doing a ton of reviews that are not worth it for anybody.

[29:40] I think having regulations, being able to better keep up with new technologies would be a huge benefit to everybody.

[29:48] Debbie Reynolds: Yeah, I think so too. I think so too. And you're right, they do.

[29:51] It does take a long time to pass.

[29:54] Although I very much commend the EU for passing these huge packages of regulation, where in the US it's just hard to do anything, so we can't agree on anything.

[30:07] So.

[30:08] So, yeah, and so we're happy, I'm happy that we can look to Europe for some of these frameworks because a lot of us are having to adopt them anyway, because they're just a good practice to do, you know, like the assessments and different things.

[30:22] So. Makes sense.

[30:23] Very cool. Very cool. Well, if anyone wants to reach out to you, to engage with you, literally,

[30:30] how would they do that?

[30:32] Julian Gage: They can reach us at www.engagecompliance.co.

[30:37] you can also reach out to my LinkedIn. Julian Gage is the name. You'll find it there. But best is the website for any DPO services or Article 27 representation support as well.

[30:48] Debbie Reynolds: Perfect. Perfect. Well, thank you so much. Thank you so much. Hopefully, next time I get to Amsterdam

[30:54] Julian Gage: and hang out, please let me know. Absolutely. That'd be great.

[30:59] Debbie Reynolds: All right. Thank you so much. Have a good day.

[31:02] Julian Gage: You, too. Thank you.

[31:03] Debbie Reynolds: Okay,

 

Next
Next

E308 - Monique Priestley, Vermont State Representative