Find partners
She Said Privacy/He Said Security

She Said Privacy/He Said Security

Hosted by Jodi and Justin Daniels

Episodes

266

Latest episode

Aug 2026

Language

EN

About the show

This is the She Said Privacy / He Said Security podcast with Jodi and Justin Daniels. Like any good marriage, Jodi and Justin will debate, evaluate, and sometimes quarrel about how privacy and security impact business in the 21st century.

Listen to episodes

60 recent
August 27, 202630 min

Maintaining Human Intelligence in an AI World

Elise Houlik is the Chief Privacy Officer at Intuit, where she leads the company's global privacy and responsible data innovation and protection strategy, ensuring data is used to safely power innovation across Intuit's ecosystem of financial technology products. Her team is deeply engaged with the business on all matters related to product development, data innovation and governance, and information security. In this episode… Legal and privacy professionals are using AI more often to save time and accomplish more in their day-to-day work. While these tools offer clear advantages, they also generate convincing outputs that are incomplete, generic, or factually wrong. Using AI responsibly requires professionals to apply human judgment and review the output closely to ensure it is accurate and supported before relying on it. As AI becomes more embedded in legal and privacy work, critical thinking skills remain just as important as knowing how to use the technology. Professionals get the most value from AI when they view it as a collaborator, rather than an authority. As privacy and legal teams use AI to kickstart analysis, pull facts together, and hunt for nuances across fragmented laws, they need to compare its answers against actual laws and reputable sources and challenge the tool when an output misses the mark instead of accepting it at face value. Being mindful about the personal information they put into public models is equally important. Professionals should also be comfortable using a variety of different tools and learning which ones fit different purposes. And as companies hire the next generation of tech-savvy professionals, they need to ensure they don't become overly reliant on AI and provide them with hands-on experience and exposure to real conversations that strengthen analytical skills. In this episode of She Said Privacy/He Said Security , Jodi and Justin Daniels speak with Elise Houlik, Chief Privacy Officer at Intuit, about the importance of maintaining human intelligence in the age of AI. Elise shares how AI is changing the skills employers value in legal and privacy professionals and explains why human judgment, curiosity, and a willingness to challenge AI-generated answers are essential as these tools become a standard part of workflows. She highlights why junior professionals still need practical experience and peer-to-peer learning opportunities and shares her perspective on keeping human intelligence at the center of how professionals use AI. Elise also offers tips for building AI skills and experimenting with different tools.

August 13, 202632 min

Navigating the New Era of Data Broker Laws

For 30 years, Ben Isaacson has been a leading privacy professional and trusted counsel. During the "Internet 1.0" era, he was instrumental in launching the first self-regulatory guidelines for email marketing, addressable TV, and mobile marketing. Ben was one of the first privacy professionals to get certified as a CIPP/US with the IAPP in 2005. In this episode… Data broker laws are pulling a once-hidden industry into the light. For years, consumers generally had no idea which companies were compiling and selling their personal information, what those companies were doing with it, or how to opt out. States are responding with data broker laws that require brokers to register and disclose information about their businesses and data-selling practices. Seven states now have these laws on the books, with some providing consumers with a centralized mechanism to request deletion of their data or to opt out of its sale. So, how can companies that purchase or license data from brokers manage the downstream risks that come with using it? Companies buying or licensing data from data brokers need to know where that data comes from, how it's used, and what their third-party contracts permit. Legal and privacy teams should work with marketing and sales to identify which adtech vendors they buy or license data from and scrutinize their licensing relationships. They also need to map how purchased data flows through the business and ensure their privacy notices disclose its use. California's Delete Act makes this downstream visibility especially important because it requires data brokers to apply deletion requests before that data is used. Companies also need to consider whether their activities qualify them as data brokers, particularly because New Jersey's data broker law extends registration requirements to data collectors, potentially affecting businesses that fall outside the traditional data broker definition. Companies should seek a legal opinion to determine where they stand based on the nature of their business and its commercial terms. In this episode of She Said Privacy/He Said Security , Jodi and Justin Daniels speak with Ben Isaacson, Principal at In-House Privacy, about the rise of data broker laws and what they mean for companies that buy, license, or sell personal information. Ben discusses the evolution of these laws and how data broker definitions and legal requirements vary across states. He highlights what companies can do to mitigate risk when using data purchased from brokers and provides tips on how companies can determine whether they are considered data brokers under these laws. Ben also shares his perspective on how California's Delete Act could influence future state and federal regulation.

July 30, 202636 min

The People-First Approach to Building Effective Privacy Programs

Chris Tarbell is a leading privacy, cyber, and data strategy executive. He currently serves as the Chief Privacy Officer for VERSANT Media LLC. Prior to his current role, Chris was an associate general counsel for Fanatics and the Walt Disney Company, where he advised global businesses on compliance with domestic and international privacy, data security, and related consumer protection laws. Most recently, Chris served as Senior Counsel at the leading law firm of Kelley Drye and Warren, where he also supported clients in numerous regulatory investigations related to marketing and advertising. In this episode… Building strong privacy programs relies on human connection and a deep understanding of organizational dynamics and business goals. To be successful, privacy professionals must participate in the business rather than just focusing on meeting legal requirements. This approach enables leaders to advocate for the tools, budget, headcount, and other resources to move the program forward. Because privacy impacts many business functions, it is very much a people business, requiring strong relationships, cross-functional collaboration, and the ability to build trust with stakeholders and internal teams. So, what steps can companies take to achieve this? Putting this into practice starts with assembling a people-first privacy team and hiring individuals with the soft skills to step into unfamiliar situations, assess what is needed, and work across departments to move the program forward. By bringing curiosity and enjoyment to privacy work, they create an environment where other departments are more willing to involve privacy early and often. This approach is especially important in the media industry, where privacy pros may need to work with news colleagues to balance the right to be forgotten with First Amendment considerations or partner with intellectual property teams to protect personal information during piracy investigations. And while collaboration is essential, teams must also determine what can realistically be achieved with the time and resources available without allowing perfection to stall progress. In this episode of She Said Privacy/He Said Security , Jodi and Justin Daniels speak with Chris Tarbell, Chief Privacy Officer at VERSANT Media, about building effective privacy programs through relationships and collaboration. Chris explains how his experience as both in-house and outside counsel shaped his ability to understand business objectives, advocate for resources, and communicate the value of privacy. He shares insights on the cross-disciplinary nature of privacy work in the media industry, lessons from building a program during a major corporate spinoff, and the importance of creating a people-first privacy team capable of handling unfamiliar business challenges. Chris also explains why bringing some fun to privacy work can make a program more effective.

July 16, 202636 min

AI Governance Built to Scale

Andrew Burt is a lawyer, entrepreneur, and former national security official widely recognized as one of the world's leading experts in the intersection of law and artificial intelligence. Over the last decade, he has built companies, law firms, and software systems that have revolutionized how AI is managed for legal risks, and his work has impacted hundreds of millions of people around the world. As a pioneer in the field of legal engineering, he founded and led the world's first legal engineering team focused on automating data governance in 2016. In 2019, he co-founded and later sold the first-ever law firm run by lawyers and data scientists solely focused on artificial intelligence. He is co-founder and CEO of Luminos.AI, the first AI governance company focused on legal risk, where he currently serves as CEO. In this episode… Companies are adopting AI faster than they can set guardrails around it. Privacy and legal teams can review an AI model or approve a vendor contract, but AI governance doesn't stop there. Risk varies by use case, including whether the system is internal or customer-facing and the level of human oversight involved. As organizations connect new AI tools, chatbots, and agents to more business processes and systems, AI governance has to move from policy to a scalable structure. One of the biggest challenges companies face is making governance work at the same speed as AI adoption. Andrew Burt knows this well as a co-author of the NIST AI Risk Management Framework, where he helped shape how companies identify, document, and manage AI risk. Turning frameworks into action is where organizations often get stuck. Implementing AI guardrails requires involvement from legal, privacy, security, compliance, engineering, and other business teams. Yet when too many people share responsibility without a lead decision-maker, it can create what Andrew calls "governance debt." Effective governance starts with accountable leadership and a working connection between the teams writing the rules and the teams building the AI systems. This means moving beyond policy-heavy approaches so governance can scale with the business and the technology. In this episode of She Said Privacy/He Said Security , Jodi and Justin Daniels talk with Andrew Burt, Co-founder and CEO of Luminos.AI , about the challenges of scaling AI governance. Andrew explains why traditional governance models struggle to keep up with how quickly AI systems are built and deployed. He breaks down the differences between managing risk at the model level and at the use-case level, including why the same AI tool can carry different risks depending on its use. Andrew also shares his prediction for the future of AI regulation in the United States and offers practical steps companies can take to strengthen AI governance.

July 2, 202636 min

Lessons Learned From a Decade of FTC Privacy Enforcement

Aaron Alva is a Harvard Berkman Klein Center fellow and the Founder of Alva Strategy Center, advising organizations and enforcers on privacy, security, and AI governance. Previously, Aaron was a lead tech advisor at the FTC, where he was instrumental in driving the agency's approach to privacy and security enforcement. In this episode… Privacy risks often hide in how companies collect, use, and share personal information. Smart TVs, health-related websites, and location data have all drawn regulatory scrutiny when data is used in ways consumers did not reasonably expect. A decade of FTC privacy enforcement shows companies what regulators consider unfair or deceptive. So, what can companies learn from these cases to strengthen their privacy practices? Reducing privacy risk starts when companies understand the data they collect, where it goes, why it's being used, and whether that use is necessary in the first place. Companies should pay close attention to handling sensitive data with care, including health information, location data, children's and teens' data, and driver behavior data. Embedding stronger privacy practices often comes down to establishing clear purpose limitations, thoughtful data minimization measures, limited retention, and privacy-enhancing defaults. It also requires a regular and thorough review of AdTech tools, like pixels and tags. Getting these practices right can help companies reduce regulatory risk. Yet when companies fall short, the FTC and state privacy regulators can impose remedies that reach beyond fines, requiring companies to delete data, stop certain data uses, change platform default settings, or build a stronger privacy program. In this episode of She Said Privacy/He Said Security , Jodi and Justin Daniels talk with Aaron Alva, Founder of Alva Strategy Center, about what companies can learn from a decade of FTC privacy enforcement. Aaron explains the role technologists play in helping enforcement agencies work through technically complex privacy issues during investigations. He delves into lessons from major enforcement actions involving smart TVs and social media platforms and shares insights on the FTC's privacy remedies. Aaron also explains how companies can strengthen their privacy practices by setting clear limits on data use, treating sensitive data with care, and aligning privacy controls with consumer expectations.

June 18, 202627 min

How to Build and Implement AI Systems That Businesses Can Trust

Myles McNamara is Tarkenton's lead technical architect and full-stack developer, specializing in building secure, scalable software solutions. He oversees infrastructure, code, and system design, serving as the team's in-house expert. Previously, he worked with Fortune 500 government contractors and ran his own software and hosting companies. In this episode… Integrating responsible AI tools and systems into business operations depends less on the model itself and more on the privacy and security controls a company embeds around it. "We need AI" is often where the conversation starts, but turning that need into a safe and controlled environment requires a clear understanding of where data lives, who can access it, and what the AI system is allowed to do. Those considerations shape whether AI can support the business without creating unnecessary risks. How can organizations design and implement AI in a way that is secure and grounded in real business needs? Before companies implement a new AI system, they need to set guardrails around how it will operate in practice. Governance needs to be built into the system from the beginning, not left in a policy or bolted on later. Establishing clear data boundaries, access controls, and system-level permissions defines what the AI tool can access and which actions it can perform. Logging and audit trails give companies visibility into how the system is functioning, so if something goes wrong, they can understand what happened and why. AI will continue to evolve, and companies also need to ensure that their privacy and security controls keep pace through regular monitoring and continued improvements. In this episode of She Said Privacy/He Said Security , Jodi and Justin Daniels talk with Myles McNamara, Principal Software Engineer at Tarkenton, about designing and implementing AI tools and systems responsibly. Myles shares what it takes to build AI agents and systems in a secure, controlled way, including how companies should think about whether AI is needed and how much autonomy it should have. He emphasizes the importance of integrating governance into system design and offers advice for safeguarding data. Myles also shares how engineering teams can balance business expectations with privacy and security concerns and discusses why AI governance might get overlooked in practice.

June 4, 202645 min

How a Georgia Lawmaker is Tackling Kids' Online Safety

Sen. Sally Harrell was elected to the Georgia State Senate in 2018, representing DeKalb and Gwinnett counties. Prior to serving in the Senate, Sen. Harrell earned a Master of Social Work and worked as a non-profit executive. Recently, Sen. Harrell co-chaired a legislative study committee on Kids' Online Safety. She and her husband are proud parents of two young adult children. In this episode… Keeping kids safe online has moved beyond screen time limits and reminders about what not to click. From social media and gaming platforms to AI companion chatbots, lawmakers are focusing on features that can manipulate children or expose them to harmful interactions. Parents want stronger protections for their children, and lawmakers on both sides of the aisle agree more must be done. As lawmakers push to regulate harmful design and AI-driven risks, balancing child safety with innovation remains a challenge. Protecting kids online takes more than one policy or parental control setting. Georgia State Senator Sally Harrell knows this well. She introduced a resolution to create a bipartisan-led Senate Study Committee dedicated to keeping kids safe online. The committee's work helped advance the bell-to-bell cellphone ban for high school students, building on the K through eight ban previously signed into law in Georgia. Their efforts also led to bills addressing addictive social media and gaming design and AI companion chatbot safeguards. The legislative process revealed how lobbying pressure and buried bill language can weaken broadly supported protections. Yet call to action matters. Parents and constituents need to stay engaged, get involved, and speak up to ensure legislators are held accountable for protecting children online. In this episode of She Said Privacy/He Said Security , Jodi and Justin Daniels speak with Georgia State Senator Sally Harrell about the realities of advancing kids' online safety legislation. Senator Harrell explains how the bipartisan-led Georgia Senate Study Committee on kids' online safety turned parent concerns into legislative action. She shares a behind-the-scenes look at what it takes to keep bills moving, including the constraints of short legislative sessions, Big Tech lobbying, and the role public advocacy plays. Senator Harrell also provides privacy and security tips for families navigating children's online activity.

May 21, 202631 min

Navigating Opt-Out Challenges and Strategies for Getting It Right

Max Anderson is a seasoned product executive with a proven track record of bringing successful technology products to market in the consumer privacy, data management, and marketing space. Prior to Ketch, Max was the Director of Product Management at Krux. After joining Salesforce as part of the Krux acquisition, Max ran data privacy and consumer identity products at Salesforce, including the rollout of their industry-leading GDPR solution set. Prior to Krux, Max was a Product Manager at IPG Mediabrands, where he was responsible for multiple successful advertising measurement products. In this episode… Getting consent and opt-out compliance right requires more than adding a cookie banner or standalone webform. It requires consent tools, consumer identifiers, and downstream third-party systems to work in concert. Regulators are looking closely at whether a consumer's choice follows them across devices, browsers, and the systems where their data is collected and used. When those pieces do not connect, an opt-out can be incomplete, putting companies at risk of regulatory enforcement. So, what does it take to build a complete and compliant consumer opt-out experience? Identity management is central to effective consent and opt-out compliance because consumer choices need to be honored at the person level, across devices and browsers. Privacy rights forms and consent tools also need to connect, so an opt-out request reaches the CMP controlling tag firing on the site. When data has moved to third-party advertising and marketing vendors, companies need to understand whether they can flow that opt-out downstream. Yet many third-party platforms do not provide privacy APIs or consent-related controls, and building integrations with them can be challenging. Companies should test the process by submitting an opt-out through the webform, returning to the website, and checking whether browser data collection events still happen that could facilitate cross-context behavioral advertising. In this episode of She Said Privacy/He Said Security , Jodi and Justin Daniels talk with Max Anderson, Co-founder and Head of Product at Ketch, about navigating consent and opt-out compliance gaps. Max explains why identity management matters when honoring consumer choices across devices and browsers, and how disconnected privacy rights forms and consent tools can leave opt-outs incomplete. He also describes the challenges companies face when flowing opt-outs down to third-party advertising and marketing vendors and shares practical steps companies can take to assess vendor controls, cross-device exposure, and the areas that may create enforcement risk.

May 7, 202639 min

From Gatekeeper To Architect: How General Counsel Are Shaping Innovation in the AI Era

Smrithi Mohan is General Counsel at Awesome, the parent company of SmugMug and Flickr, where she oversees all legal, IP, privacy, and compliance matters for two of the world's most recognized photo-sharing platforms. She previously spent a decade at Dun & Bradstreet, where she built the company's first global IP and innovation practice. An elected Board of Education member and recognized Top Woman Leader, she speaks and writes on legal operations, IP strategy, leadership, and building legal functions from the ground up. In this episode… When a new AI feature ships or a new product is designed, general counsel may not be looped in until after key decisions are made. This creates risk because most product decisions have legal implications, especially around data use, user rights, and consent. That changes when legal teams are brought into the product development cycle at the outset, helping design outcomes that align with legal obligations and business goals. How can general counsel and legal teams move from being seen as gatekeepers to business drivers? Shifting how general counsel and legal teams are viewed starts with building strong relationships across business teams. When legal leaders understand how product, engineering, and other teams operate, they are more likely to be included as ideas take shape. Early involvement enables general counsel to explain regulatory requirements and legal frameworks across different jurisdictions, thereby improving products and making them more defensible. It also creates space to ask fundamental questions in AI development upfront, including what data is being used, whether the company has the right to use it, who owns the outputs, and whether user information is collected with proper consent flows. Vendor relationships require the same level of attention, as older contracts may not address AI and often need audits, addendums, and updated terms. In this episode of She Said Privacy/He Said Security , Jodi and Justin Daniels talk with Smrithi Mohan, General Counsel at Awesome, about how legal teams can integrate into AI and product development. Smrithi explains why general counsel needs to act as business architects and not just legal advisors, and what it takes to make that shift. She outlines the core legal questions teams should address when developing AI tools and other products, how to manage third-party vendor contract risks, and the evolving legal gray areas surrounding AI-generated content and platform liability. Smrithi also offers practical advice on building genuine, collaborative relationships across teams.

April 23, 202621 min

The Accountability Problem Behind AI Adoption

Kristin Calve is the Editor & Publisher of Corporate Counsel Business Journal and the Co-founder of Law Business Media. She leads editorial strategy focused on AI governance, legal operations, and board-level risk, and convenes forward-leaning legal leaders through interviews, events, and industry analysis. In this episode… Controlled AI deployment is one of the most pressing challenges legal and business leaders face right now. New AI tools are often adopted quickly without the full understanding of how they're being used, where data goes, and who's accountable for the outcomes. Some teams explore AI without direction or intention. Others prescribe it with guardrails, defining who can use it and how. The gap between those two approaches is where risk lives. So, how can organizations deploy and use AI without losing control? Legal operations teams are often accountable for how AI is used in practice. They understand the regulatory landscape and manage contracts and deadlines. They're often involved in operations across finance, HR, sales, and other business functions, so they know how those processes work and why they were built that way. That institutional knowledge matters as AI is introduced into those systems. At the same time, prompt documentation, AI notetakers, and recordings are introducing new risks. Teams may not know what is being captured, where it is going, or how it could become discoverable. Supply chain exposure adds another layer of risk. Vendors might embed AI into the tools organizations already rely on, potentially affecting an organization's overall privacy and security posture. In this episode of She Said Privacy/He Said Security , Jodi and Justin Daniels talk with Kristin Calve, Editor & Publisher of Corporate Counsel Business Journal and Co-founder of Law Business Media, about how organizations are navigating AI deployment and risk. Kristin explains how companies are deploying AI inconsistently and the challenge of controlling its use. She shares how regulatory requirements shape accountability and why legal operations teams often bear responsibility for what's permissible. Kristin also explains the risks of prompts and recordings becoming discoverable and discusses how AI increases speed and capacity, but does not replace the need for judgment.

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Business podcasts