Navigating the complexities of privacy with Jason Sarfati

Introduction

This week I’m joined by Jason Sarfati, the Chief Privacy Officer and VP of Legal at Gravy Analytics.

In our discussion, Jason outlines his perspective on how executives should navigate the complexities of privacy. He discusses the two guardrails that often govern data ethics and why it is so complicated to consider. Jason talks about the different privacy laws, their challenges at both a state and federal level and how social impact is starting to influence discussions.


Speaker Profiles

Jason Sarfati Twitter: https://twitter.com/JMSarfati

Jason Sarfati LinkedIn: https://www.linkedin.com/in/jasonsarfati/

Gravy Analytics: https://gravyanalytics.com


Audio File


#CIO #Leadership #Privacy #CPO #Data #Ethics #CxOitk


Podcast Transcript

Tim Crawford 0:04
Companies are looking for new ways to transform their business. Technology plays a critical role in this transformation. Speed and innovation in both technology and thinking are key to this shift. Hello, and welcome to the Cxo in the Know podcast, where I take a provocative but pragmatic look at the intersection of business and technology through the lens of leading CxO executives. I’m your host Tim Crawford, a CIO and strategic advisor at Avoa. This week, I’m joined by Jason Sarfati, the Chief Privacy Officer and VP of Legal at Gravey Analytics. In our discussion, Jason outlines his perspective on how executives should navigate the complexities of privacy. He discusses the two guardrails that often govern data ethics and why it is so complicated to consider. Jason talks about the different privacy laws, their challenges at both the state and federal level, and how social impact is starting to influence discussions. Jason, welcome to the program.

Jason Sarfati 1:03
Thank you very much for having me, Tim.

Tim Crawford 1:04
So, Jason Sarfaudi, you’re the Chief Privacy Officer and VP of Legal at Gravy Analytics. So, you know, to kind of get us started and to set the stage for our conversation today, why don’t you tell us a little about yourself and your role there as the chief privacy officer.

Jason Sarfati 1:22
Sure thing. So, well, for starters, the position of chief privacy officer didn’t really exist in most companies 510, years ago. It’s been a more of a recent trend, and it’s a response to the fact that there are laws that are being passed both in this country and in most of the major economies around the world that regulate how personal information needs to be handled, and yes, it’s a legal function, but it’s also a compliance function. It’s a marketing function. It’s a branding issue. So, chief privacy officer is where all those decisions are made and usually recommended to the rest of leadership. So, most of them tend to have a legal background. I went to law school, graduated in 2015, and even then, which was two to three years before the GDPR came out, which, for reference, is the European Privacy Law. the The indication was that privacy was going to become big, and privacy positions were opening up. So I knew even back in law school that one day, ideally, I would become a chief privacy officer, and so it’s it’s been a real pleasure watching the industry change and me growing within

Tim Crawford 2:25
it. You know, and even along those lines, I mean, if you look at regulatory compliance and privacy, I mean, it’s incredibly complicated, and it seems like every time you turn around, it’s just getting more complicated. When I think about this from an executive standpoint, though, how should I navigate through privacy in today’s world?

Jason Sarfati 2:46
It is incredibly complicated. I agree with you, Tim, and I also have some bad news to share with the audience. I foresee getting more complicated versus less complicated in the near future as well. The big problem, frankly, is the internet is has global reach, and therefore, legislatures across the planet can pass laws that impact the entire internet. Because again, everything is global. Back in the day when we had an economy that ran around widgets, things and supply chains were more regionalized. But today, the internet is global. So one of the main reasons why things have gotten so complicated as of late. Is you have in the United States, the 50 states are beginning to realize. Well, there’s no action happening on the federal level. You know, we’re going to start passing our own laws that regulate data privacy. And elsewhere, you have the European Union, but also Brazil, South Africa, the ANZAC countries are also stepping up to the plate and saying to themselves, you know, we have lost sovereignty over our internet, and most of the big tech companies exist in the United States where they are not regulated, or in the alternative, they are in China where they are absolutely not regulated, or you know, a byproduct of of a government arm. We need to pass our own laws to protect our citizens to preserve the sanctity of our business environment. So that’s why it’s so complicated.

Tim Crawford 4:07
Gotcha. Then

Jason Sarfati 4:08
you add on top of that all those data breaches, and it’s in the public eye. But I’m sure we’ll talk about that more.

Tim Crawford 4:13
Yeah, and I’d love to touch on that. You know, it seems like most of these efforts, at least of late, are focused around privacy law. Is that what you’re seeing, and what’s again coming back to that executive perspective? How do I start to think about that, and what should I be focused on?

Jason Sarfati 4:29
My again, what I tell my executives and the other executives I encounter is, you really do want to focus more on the legal obligations. That’s the ground floor requirements for these laws, you want to stay away from the prying arms of regulators, but that is not enough. That is, frankly, the bare minimum. But for many companies, the bare minimum is all that they can do. So, for those companies that have the budget and the bandwidth to have a little bit more of a forward-looking approach to it, I do agree that. Privacy ought to be incorporated as a branding issue. It’s you know we we we develop all of our products and the entire way our business model operates around the concept that people’s information is going to be both secure and also there’s going to be some thought into how we handle this information ahead of time before we start collecting it. That makes people feel more secure and comfortable with doing business, so I say to any any executive that’s wondering where does privacy fit into to this equation? It’s a revenue thing, but it absolutely also is an expense problem too. So you have to figure out where to draw your attention.

Tim Crawford 5:34
And you talk about the impact to brand. Can you help me understand kind of what you mean by that?

Jason Sarfati 5:41
Well, so I don’t want to call out any specific companies that have been in the news lately. Sure, audience knows who they are, but you know, I would turn the question to a CEO: Do you want your company to be in the news tomorrow for a data breach? Certainly not. That’s the type of branding problem that will last for several years. In some cases, I think forever. There’s some companies that might not be able to escape that shadow, and that’s a data security problem. As it relates to privacy, you know there are other companies that might not have a firm grasp on how the personal information that they collect from their customers is being used. I think a huge problem right now is loyalty programs. There is very little management around. You know someone bought you know a product three months ago now they’re getting advertisements or personalized coupons for that kind of thing and they’re getting offered promotions and that might you know distaste them. I bought a shirt I’ll tell you from a company that I rarely shop at a couple months ago and I still keep getting these advertisements from them and I actually bought it as a gift. I hate this company. We never wear their clothing, but I still I keep getting their their coupons, right? So I ask myself, okay, well, you know, as a customer, as a consumer, does this bother me? Does this make me less likely to go back into that store with my credit card and swipe and buy something? And I think the answer is yes for a lot of people out there,

Tim Crawford 7:01
but do you think that that consumers are picking products based on privacy, or do you think it’s something else? I mean, what from a company standpoint, what are the minimum requirements? Like, what should I be looking at and thinking about in that kind of continuum of first thing, second thing, third thing, and then where the customer kind of fits in.

Jason Sarfati 7:23
So certainly, if if you could figure out why consumers buy products, you would be a trillionaire, right? If you could figure out exactly what will motivate someone to purchase a product, I’m not here to tell your audience that privacy is number one. I think quality and price will probably always be one and two, but we are in a digital economy these days, and I do believe that, especially with certain transactions, privacy and security are going to be something that people put a premium on. So, I’m thinking things like mortgage or reinsurance or any any type of financial transaction, anything touching children or their love or individuals’ loved ones. You’re going to see privacy and security rise to the top of the the decision factors that people have. For basic things like you know retail, it might matter a little less, but at the end of the day, people do care about how their information is being used still. So, and as as the pendulum goes, I do believe that privacy will continue to to appreciate in importance over time.

Tim Crawford 8:26
Sure, and you know to some degree, if you use you as an example, your your shirt example, you had purchased a product, you might have purchased it as a gift for someone, thought it was a great idea, regardless of whether you were interested in buying it or not, but because of how the data was used, now you definitely are not interested in in engaging with that company.

Jason Sarfati 8:48
That’s true. I don’t like the clothing, but now I’m definitely not walking in there. And you know, and I have a lot of friends who sometimes approach me. They know what I do, and they say, “Oh, well, this you won’t believe this. I keep getting emails from this one company, and I know we do exist in a world where we get all these pop-ups and notices, and our internet experience hasn’t, in a way, kind of degraded. But at the end of the day, people still understand that a company is collecting information about them, and they they have a feeling when something’s wrong or something bothers them, and so they might not actually be able to articulate it, but they will go to your competitor even subconsciously. I think if the competitor is not as aggressive with collecting more personal information than is necessary.

Tim Crawford 9:32
Yeah, there’s one term that tends to be a trigger for folks in this space, and that is data ethics. And I know you have a strong opinion in the space. What’s your perspective on data ethics?

Jason Sarfati 9:45
Yeah, so the term data ethics is absolutely in vogue these days. The basic idea is companies are not going to do simply what’s required of them by the law. They’re going to do what’s ethical, what what ought to be done in a certain situation. The problem there. Of course, is when you’re trying to dictate, especially at the executive level, how personal information ought to be handled. The monetary considerations of how information can be again monetized is almost always going to trump. So I have been at the conference table at many organizations in my career where I’ve seen this conversation play out, and someone might say, “Well, it’s a little unethical for us to, you know, take information from subsidiary X and then provide it to subsidiary Y and try to monetize customers who do business through subsidiary X and move it over to subsidiary Y to increase sales on on the Y side, and you know the CEO or CMO or maybe a head of a business line will say, “Well, well, no, like this is the parent company, and we absolutely are entitled to bring that information over. And you know, someone who’s saying, “Yeah, well, that’s not ethical. They they don’t care about the new company. They they don’t even they might not even know that the new company has any relationship to the old company, and I just never see data ethics really getting implemented in a way that is concrete and that you know CEOs can actually understand what the action item is following that conversation. So,

Tim Crawford 11:14
when you’re talking about ethics or data ethics specifically, Jason, you’re talking about it as potentially a higher level or higher degree of privacy beyond just what the law requires, or you talking about it in a different in a different way?

Jason Sarfati 11:31
And that’s the problem: is it really even defined? So I kind of explored multiple definitions there. I think one definition certainly for it is a company wants to do more than what the legal requirement is, but the problem then is where do you go? It’s like you know they’re out to sea and they have zero point of reference. And what’s equally problematic is that there really aren’t any industry standards to maybe with the exception of go with financial services and education and healthcare, which tend to have more robust privacy regimes, but for retail or B 2b B 2g models, there really is nothing out there that says you know this is the ethical thing to do. So you know I go to conferences a lot, looking forward to once COVID ends to actually start going to them in person. And this this topic comes up. They try to develop industry standards or norms, and they just simply don’t exist. And you see that, you know, if anyone is in the legal industry and they’re dialing in, they’re they’re going to tell you that in contracting this is a huge problem because there’s no concrete idea of what’s normal and what’s not. So when you try to get it to a contract,

Tim Crawford 12:41
I mean, you know this from law school. There’s a reason why they call it practicing law, right? There’s an interpretation that comes with it. Is I, if I think of of what you’re talking about, I mean, it sounds like there’s an expectation that there might be some framework or some prescriptive method in which to handle privacy, which there isn’t, but how do I how do I kind of wrap my arms around this? Then I mean, I can’t just throw up my arms and say, okay, well, we can’t define it, so we can’t do it. What are some guidelines that you would offer to folks that are maybe trying to to understand the legal ramifications and requirements, but also also this ethical or potentially ethical aspect.

Jason Sarfati 13:26
I think there’s two guardrails. On the left is risk, and on the right is opportunity. So you absolutely, I think, always need to be looking to your left and keeping a very close eye on the compliance obligations that stem from these laws. And by the way, those obligations change almost month to month these days, so that absolutely needs to be where most of your budget, most of your workforce, and most of your attention is directed to. On the other side of the coin, though, there is a lot of opportunity around it. So I’m not going to mention specific companies that have branded themselves around privacy. I’m sure your audience can pick a couple off the top of their heads. But depending upon the business model, it absolutely is something that you would want to communicate to either one your consumers. Number two, if you’re in the B 2b space, tell your sales associates, “Hey, we put a premium on privacy. Yes, our product is better than the other competitor. Yes, our prices are competitive, but we will also protect privacy. I guarantee you that will help some of your sales cycles move along, even in the contracting phase. That’s been my personal experience at multiple companies. So it’s absolutely a tool that can be used to increase revenue and increase loyalty of your customers because they’ll feel comfortable doing business with your company.

Tim Crawford 14:44
When I think about who does this within a company, is that a single role, like a chief privacy officer, and maybe an organization that they have? Is it your risk or audit or legal existing legal teams, or is it a cult? That you have to build within the DNA that is your company and how you engage with customers.

Jason Sarfati 15:07
At the risk of sounding cute, I would say yes to all three of those options.

Tim Crawford 15:12
A little bit of each.

Jason Sarfati 15:14
Yeah, yeah, a little bit of each, right? So depends on the business.

Tim Crawford 15:18
I didn’t give you the option of all of the above, right?

Jason Sarfati 15:21
So, and I also understand. I know we’re joking, but it’s true that budgets are are constrained today, especially at the corporate level. So, if it makes sense, depending upon the business model, to have a chief privacy officer, I absolutely think it’s something that every company that can afford one ought to have centralize a lot of these decisions. But depending again on the business model, there ought to be what I’ll call a privacy ambassador or a privacy lead within each core function. So, marketing departments need to have one person in there that is responsible for data privacy. It could be the CMO or maybe someone else. The HR department for all internal data privacy issues, especially as we go back to the workplace with all of these overhangs from COVID residing over us, there needs to be someone in HR responsible for privacy, and then the business lines and sales, all of that. There needs to be someone in there that is the you know the standard bearer. If they have a CTO behind them at the at the top level, even better.

Tim Crawford 16:22
I think the pushback that I could see from that is great. Well, as an executive, if I’m the CEO of the company, now I need a chief privacy officer, and I need that expertise in every one of the departments. Well, I just heard the same thing about cybersecurity. Well, I just heard the same thing about the last thing before that, and the thing before that, and eventually, you start to feel like, well, wait a second here. We’re becoming incredibly top-heavy from an administrative standpoint, and aren’t able to truly focus on our customer and our product. I mean, you start to lose that efficiency aspect and start worrying about bureaucracy coming into play. Does that kind of weigh with with some of the conversations you’ve had?

Jason Sarfati 17:04
It does, but there are some solutions to it. So, to anyone who’s losing sleep over this, for starters, employee training, and there are different grades of privacy training that’s appropriate depending upon a person’s function and role. But I would say that people are smart; they will catch on and understand these concepts, and I think that some investment needs to be made into the pre-existing resources to also wear a privacy hat at the same time. And you know, as to the issue of whether or not they should have a chief privacy officer at the top of it, well, listen, if you’re doing more than 500 million a year in revenue. I’m just going to throw that number out there. You need to have as chief privacy officer because you are, by definition, collecting so much personal information that it’s not plausible for there not to be a full time role associated to that effort. So just start there. And legal can also hold on to a lot of the responsibilities as well. But again, training and decentralizing a lot of the responsibilities, I think, critically important too.

Tim Crawford 18:04
So let’s maybe shift gears a little bit and move from talking about what happens inside the organization to what happens outside of the organization. And I want to get your take on legislation and privacy law. You mentioned GDPR. There’s also the the California privacy law that’s in place. There are a number of them. Again, how do I start to kind of tease apart these pieces in terms of federal versus state, and where do we go from here?

Jason Sarfati 18:33
I think the first thing to focus on is there’s a cool term called data mapping, which I’m not the biggest fan of. But focus first on where does the personal information that flows through your organization come from. So, if you are an American company, you already know that you’re going to have to comply with the CCPA. It’s what an eighth of of the country demographically. So, look at all the rights and responsibilities that come out of that law and make sure your company is complying with them because there is absolutely going to be a robust enforcement regime that comes out of California for the CCPA, still maturing, but it’s getting there, and it will absolutely be there. But I think by the end of the year, and then abroad, yeah, there’s of course the the conflict that we might have between European privacy laws, American state laws, and even the potential of a U.S. privacy, federal privacy law, which I know we’ll get to. And you’re going to have to kind of create this what I call privacy jambalaya. But throw in all the responsibilities that you have and try to create something from that. So an internal privacy program that can address each of these issues simultaneously, it’s a pain and it’s it’s a very arduous task, but you have to do it.

Tim Crawford 19:46
So, in if we just look at the U.S. for just a minute, you know, not trying to boil the ocean of of the globe, which is which is complicated in its own right. But if we just look at the U.S. as one one example of this, we’ve got. CPA, the California privacy law that’s on the books, does it become the gold standard that then other states adopt, or potentially the federal government adopts, or is it potentially too centered around the the state’s requirements specifically?

Jason Sarfati 20:17
So a year ago, I might have told you that the CCPA was the gold standard because it was the only comprehensive privacy law on the books in the United States. There’s some sectoral laws like HIPAA and the GLBA that affect certain industries, COPPA for children, but there wasn’t a comprehensive privacy law with the exception of the CCPA. What we’re seeing this year, though, Washington State has a privacy law that is will know if it passes or fails by april 25 Virginia just passed its own privacy law that, in many ways, is actually stricter than California, especially as it relates to geolocation data. That’s something that impacts my company. There’s this patchwork of privacy laws that’s developing, and the answer is no. I don’t think any particular state privacy law is going to be the gold standard. So one of the big questions for Congress is this issue of preemption: Is the federal privacy law going to supersede all of these 50 state laws, or is it going to supplement them? Is it going to be sort of like the the gravy on top. Sort of use my company’s metaphor, right? So, I personally strongly advocate for a federal privacy law that preempts all the state laws. By the way, that’s why the GDPR came out because the 28 member states in Europe had different rules, and they needed to create what I’ll use, I’ll use the term a federal standard on that continent. We should learn from them and apply a federal standard here in this country.

Tim Crawford 21:48
But do you think that? Let me play devil’s advocate on that for a minute. Let’s say the federal government can’t get behind it, and states start building their own privacy laws individually, and maybe they maybe let me kind of wax philosophical a little bit here and just say, let’s say that there’s some collaboration that happens between states. Is that necessarily problematic? And the reason why I’m bringing this up is because quite often you have enterprises that are working across states, and so they have to navigate. Okay, I’ve got employees and customers in each of these states, and how do they differ? How do the requirements differ from state to state? Is there a problem with states kind of creating their own laws?

Jason Sarfati 22:30
I mean, interesting how you define the word problem. It’s certainly inefficient because again, the internet is is global. But okay, fine, the internet’s national, and it doesn’t make sense when we have an entity by way of Congress that is literally designed to regulate interstate commerce. That’s part of its main mission for the 50 states to be kind of stealing their lunch, so to speak, and and doing that work for them. So right now we only have two comprehensive privacy laws that have passed Virginia and California. I think by Christmas this year we could have five or six. And so, at what point do we reach Florida, Washington State, and New York, Oklahoma, Colorado? I’m not just pulling those names out of my pocket. Those are actual states that have privacy bills that are moving through their legislatures that have strong support both from the legislators and the public. So, at a certain point, federal Congress needs to step in. We cannot have this patchwork system, and it’ll it will be cost prohibitive to to.

Tim Crawford 23:38
So, I mean, there’s an inefficiency piece, and then there’s from the customer standpoint or the enterprise standpoint. I mean, that just gets to be just out of bounds in terms of trying to manage, especially if they conflict with one another or aspects that conflict with one another. You can do this in California, but not Washington. You can do this in New York, but not Texas. I can see how that that’s going to be really problematic. Do you see something coming down the pike from the federal government that might supersede or or provide some relief, for lack of a better word?

Jason Sarfati 24:12
There definitely are some federal privacy bills that have been introduced in Congress. Of particular note, there’s a congresswoman from Washington State, Delbini. I hope I’m pronouncing her her last name correctly. She introduced a bill that I personally read through that I thought to myself, you know, this is this hits all the high points, and I believe it preempts the the state laws, and also gets rid of a big issue, which is the private right of action. So some of these state privacy laws are including individuals, the right of individuals to sue in court, even under a class action setting, which would be very problematic. You could see the internet going the way of asbestos litigation and big tobacco of yesteryear. So, privacy bills like that do exist at the federal level. The problem is right now there just isn’t. Willingness on the part of Congress to pass a law, and it’s long overdue. My personal opinion on it is, it is a failure that is commensurate with the inability to pass gun reform in this law, immigration, what have you. But for some reason, we’ve talked about this, Tim. It didn’t get much play in the last presidential election. I don’t know why. It touches every piece of the daily experience. Our phones dictate to us how we spend our money, how we meet people, how we fall in love, all these other things. And for some reason, it’s not getting regulated. So there’s increasing demand by companies to have regulation at the federal level. We see that now in the hearings. CEOs are actually calling for it, I’ll call out one company. Facebook is actually publishing TV advertisements calling for federal what they’re calling internet law. That that’s the it’s a privacy law, and I think hopefully we’ll get more traction with time.

Tim Crawford 25:54
We’ll see how this goes. I I for 1am not going to hold my breath just because the wheels move so slowly for things like that. So as we kind of wrap on the episode, I want to get your take. Your two top pieces of advice for executives that are looking to navigate this space. You know, this as we’ve talked about, you know, this privacy space is complicated and going to get more complicated. And we’ve talked about the different guardrails you could consider to put in place, but what are your two top takeaways that you would offer to executives that are looking and thinking about privacy in their org?

Jason Sarfati 26:31
So, for starters, since we’re talking to the executives, unfortunately, you do need to throw money at this problem. So, allocate some budget to it, whether it’s outside legal counsel, outside consultants, or hiring internal resources, you-if you are hearing individuals in your organization say, “Hey, we need to make hires. Hey, we need to buy software, restructure some things, please listen to those folks. Like they are right, and allocate some budget to the problem. Number two, I will say that you know, I watch the news as much as anyone else, and I’ve noticed like two trends, especially watching CNBC, for example. Climate change in the last year has become a corporate responsibility. I’ve noticed that that individuals have been able to convince corporate America that it is their responsibility to solve the issue of climate change. I’ve also noticed that a lot of the social justice movements have also been adopted by corporate America as well, and I’m sure your executives have differing levels, but at least a baseline experience with those two movements. Privacy is also included in that bucket. It’s not necessarily a social issue; it’s more of an economic meets social meets personal issue, but it is absolutely a problem that’s going to need to also be resolved by our corporations. It’s not going to be solved at the ballot box exclusively. It’s not going to be solved, you know, on an interpersonal level. It is something that corporate America must resolve on its own.

Tim Crawford 27:56
Great pieces of advice there, Jason. Thank you so much for taking part in the episode today.

Jason Sarfati 28:01
Absolutely, it’s been a pleasure, Tim.

Tim Crawford 28:03
For more information on the Cxo in the Know podcast, visit us online@cxointheknow.com You can also find us on Apple Podcasts or wherever you listen to your podcasts. Please subscribe and thank you for listening.


Discover more from AVOA

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from AVOA

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from AVOA

Subscribe now to keep reading and get access to the full archive.

Continue reading