Hosted by VeraSafe
Listed under Business › Management, News › Tech News, Government
Privacy in Practice, brought to you by VeraSafe, is the podcast for actionable insights and real-world strategies for privacy and compliance teams.
21 episodes · publishes monthly · latest 2026-08-11 · ~44 min/episode
Rank
#45
Substance
78.6
/ 100
Breakdown
Scored 2026-09
Updated monthly
Across the index
#45 of 846
Substance
Top 5%
outscores 95% of the index
Privacy in Practice ranks #45 on The B2B Podcast Index with a substance score of 78.6 out of 100, scored across 5 recent episodes. It scores highest on guest caliber and insight density. Tom Kemp is exceptionally well-calibrated as a guest: he is the Executive Director of the California Privacy Protection Agency, bringing authentic regulatory authority combined with rare private-sector operating experience (built Centrify to 500+ employees and $100M+ revenue). He has lived compliance from both sides and authored substantive work on Big Tech regulation. This combination of practical execution experience and current enforcement power is uncommon and highly valuable for a B2B privacy audience.
Averaged across 5 recently scored episodes, with cited evidence.
The episode delivers substantial, actionable guidance on California privacy law compliance with multiple concrete scenarios and enforcement patterns. Tom Kemp provides specific details on opt-out mechanisms, testing requirements, GPC implementation, and risk assessment frameworks that practitioners can apply directly. However, the content is largely explanation of existing regulations rather than novel theoretical insights, and significant portions involve the hosts asking clarifying questions that slow information delivery.
“We repeatedly see in enforcement that businesses implement mechanisms especially for opt outs without verifying that they actually work in practice. And yes, some companies rely on purchased or licensed technology but don't test it end to end from the consumer's perspective, which leads to broken or incomplete implementations.”
“businesses must honor opt out preference signals such as the global Privacy control. We call that here in California the opt out preference signal or oops. And California has been quite clear actually from the initial Attorney General Sephora one of their first enforcement announcement or actually the first enforcement announcement that GPC needs to be honored.”
The episode covers well-established regulatory frameworks and enforcement approaches already documented in settlement agreements and guidance materials. While Kemp provides clarity on implementation details, the core ideas - testing consumer experiences, walking in consumer shoes, honoring preference signals - are now standard regulatory messaging. The DROP system represents genuine operational innovation, but most of the discussion recycles existing CCPA/CPRA principles.
“you really need to walk a mile in the shoes of the consumer. Take into account that they may access different web properties that you, that a business may have. They may use a mobile application, they may use a browser, they may use a browser on a phone.”
“the drop system stands for the delete, request and opt out platform. It's the nation's first statewide deletion platform and this is only available to Californians and gives Californians a simple scalable way to delete their data across multiple registered data brokers.”
Tom Kemp is exceptionally well-calibrated as a guest: he is the Executive Director of the California Privacy Protection Agency, bringing authentic regulatory authority combined with rare private-sector operating experience (built Centrify to 500+ employees and $100M+ revenue). He has lived compliance from both sides and authored substantive work on Big Tech regulation. This combination of practical execution experience and current enforcement power is uncommon and highly valuable for a B2B privacy audience.
“I was in the private sector and so this is my first government job and I've historically been an entrepreneur and my last company was a cybersecurity company called Centrify...we had to go through GDPR compliance. So probably what also makes me a little bit unique as a regulator is that I've actually had to go through the regulatory process myself.”
“After my company was acquired, I started doing policy work in the area of privacy and cybersecurity and AI, and that eventually led me to this position, which I'm so glad to be working with a great team here at Cal Privacy.”
The episode includes specific enforcement examples (General Motors, Sephora, Disney, Honda, Ford, Tractor Supply, Playon) and references concrete regulatory sections (Section 7157, Section 7154). However, the evidence for core claims is often illustrative rather than quantitative - few specific metrics, dollar figures, or timelines are provided beyond the April 1, 2028 deadline and 300,000 DROP signups. The guidance is sometimes deliberately vague ("Without knowing the particulars of the business...") to avoid creating bright-line rules.
“If you look at the General Motors settlement that we did with The Attorney General and four district attorneys. Clearly that was data minimization, purpose limitation that those were key themes as well.”
“over 575 data brokers are registered with the state. It's free. There was no taxpayer dollars involved in this...over 300,000 Californians have signed up for it.”
The hosts ask competent, clarifying questions and demonstrate understanding of the landscape (noting Disney's cross-device issue, referencing GDPR parallels). However, the conversation is largely a structured Q&A format where Kemp answers thoroughly but rarely gets challenged or pressed on tradeoffs. The hosts are deferential and collaborative rather than adversarial - they nod enthusiastically and affirm rather than probe contradictions or edge cases. There are few moments of genuine pushback or uncomfortable follow-ups that would deepen insight.
“Without knowing the particulars of the business, the branding, it's very hard for me to say that but I think the key thing is based on the user, the consent that's given.”
“we have such a great team here at Cal Privacy that in Silicon Valley, where I historically worked, that I think everyone felt that they're the smartest people in the room all the time.”
4 periods tracked.
6 scored on substance · 21 tracked in total.
Children’s Privacy and Age Assurance Across Borders
2026-08-11 · 46 min
Inside the Mind of Tom Kemp, California's Privacy Regulator
2026-07-14 · 51 min
Are Privacy Myths Shaping Your Business Decisions?
2026-06-16 · 40 min
Privacy in M&A: Getting Acquisition-Ready
2026-05-12 · 47 min
Empowering Teams to Exercise Judgement in Privacy Decisions
2026-04-14 · 35 min
California Is Watching: Unpacking Enforcement Trends with Daniel Goldberg
2026-03-17 · 1h 7m
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/privacy-in-practice" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/privacy-in-practice/badge.svg" alt="Ranked #2 on The B2B Podcast Index" width="360" height="136" />
</a>Track Privacy in Practice's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.