The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/She Said Privacy/He Said Security
She Said Privacy/He Said Security artwork

Lessons Learned From a Decade of FTC Privacy Enforcement

She Said Privacy/He Said Security · 2026-07-02 · 36 min

0:00--:--

Key moments - from our scoring

Substance score

51 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality8 / 20
Guest Caliber14 / 20
Specificity & Evidence12 / 20
Conversational Craft7 / 20

Aaron Alva, a former FTC technologist who spent a decade driving the agency's privacy and security enforcement strategy, sits down to dissect the real-world lessons from landmark cases like Facebook (Cambridge Analytica), Vizio, GoodRx, and Epic Games. The conversation illuminates how technologists are now embedded within the FTC and state attorneys general to help prosecutors understand complex data flows, tracking mechanisms, and harms - and crucially, how those cases establish a "common law of privacy" that competitors should follow. Alva emphasizes that despite billion-dollar fines, what actually deters conduct are bright-line remedies that prohibit specific practices rather than process-based orders: Facebook's mandated privacy program, GoodRx's ban on sharing health data for advertising, and Epic Games' default-off audio for children. The episode covers sensitive data categories (health pixels, location data via WiFi triangulation, browsing history, driver behavior data), the nuance of precise geolocation definitions across FTC orders (Market X Mode, Gravy Analytics, Mobwalla), and why data minimization and use-purpose limitations are now table-stakes compliance practices - made more urgent by state privacy laws and AI regulation.

Key takeaways

  • →FTC cases establish common law privacy precedent that competitors should follow, even though the agency can only bring enforcement actions against individual companies under 20-year legal orders.
  • →Bright-line remedies that prohibit specific conduct (like banning health data sharing for advertising) are more effective than monetary fines or process-based requirements at actually changing company incentives.
  • →Companies collecting sensitive data should audit what third-party pixels, ad tags, and advertising entities receive their data, starting with identifying where sensitive information is being collected on their websites.
  • →Data minimization and use purpose limitations - only using data for its intended service delivery - are increasingly critical across FTC cases and emerging state privacy legislation.
  • →Sensitive data categories extend beyond health and location to include browsing history, children/teen data, driver behavior data, and data used to train facial recognition models without proper consent.

Guests

Aaron Alva

Topics in this episode

FTC privacy enforcementVizio smart TV tracking caseFacebook Cambridge Analytica $5 billion settlementPixel tracking in health dataGoodRx Facebook pixel caseBetterHelp privacy violationsLocation data coarsening techniquesWi-Fi triangulationCOPPA children's privacy lawEpic Games $500 million settlement

Questions this episode answers

What was the $5 billion Facebook penalty from the Cambridge Analytica case actually about?

Facebook allowed third-party apps to access friends' data beyond what individual users expected, violating the FTC's understanding of fairness. The penalty came after the privacy settings that disclosed this practice failed to align with consumer expectations, triggering public and Congressional attention that led to the FTC case.

Why do companies keep repeating privacy violations like the Vizio smart TV tracking case?

The FTC can only bring enforcement against one company at a time, creating a 20-year legal order for that firm but leaving competitors without a technical legal requirement to follow the same rules. Without comprehensive federal privacy legislation, companies often ignore the "common law of privacy" established by cases unless they face their own enforcement action.

What is the most effective remedy the FTC has used - fines or something else?

Fines alone haven't deterred conduct; instead, bright-line remedies that explicitly prohibit specific practices (like GoodRx's ban on sharing health data for advertising, or Epic Games' default-off audio) are more effective because they cut at the incentives for data use and disclosure, not just impose costs.

What counts as location data under FTC orders beyond just GPS?

Location data includes WiFi triangulation (using unique router identifiers to triangulate a device's position), which can be more precise than GPS, as well as any precise data point about a consumer device. Four current FTC orders (Market X Mode, Gravy Analytics, Mobwalla, and others) define this differently but agree that precise location is the trigger, not just GPS.

What sensitive data categories has the FTC identified beyond health data?

The FTC has taken action on browsing history (Avast case), children's and teen data (COPPA and expanding), driver behavior data including speeding and hard braking (General Motors), and biometric data used for facial recognition training (OkCupid case with photos shared for AI training).

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

The episode delivers a genuine but uneven payload: specific FTC case mechanics (Vizio, GoodRx pixel tracking, Epic Games defaults remedy, GM driver behavior) are genuinely informative, but large stretches of the runtime are consumed by intro theatre, clothing banter, a kayak anecdote, and generic takeaways like 'limit data retention.' The substantive segments are real but not densely packed per minute.

Vizio, ah, had to delete all four years of TV viewing history so they couldn't benefit further from that conduct
your routers have a unique identifier. And there's a technique called WI fi triangulation where your phone can understand how far certain number of unique routers are from your device and that can be sometimes more precise than GPS data

Originality

8 / 20

The episode mostly recaps publicly known FTC enforcement actions rather than offering first-principles analysis or contrarian takes; frameworks like 'data minimization,' 'use purpose limitations,' and 'sensitive categories' are standard privacy-compliance vocabulary. The WiFi triangulation point and the observation that Texas AGs are re-litigating Vizio-era conduct a decade later are the only meaningfully fresh angles.

the theory from Dan Solov and Woody Herzog and others is that that creates a common law of privacy that informs other companies
those all require I think heightened care. Um, and the FTC has made that quite clear

Guest Caliber

14 / 20

Aaron Alva is a genuine practitioner - 10 years as a lead FTC technologist directly involved in landmark enforcement actions including the $5B Facebook matter - not a recycled thought-leader. He brings authentic insider perspective on how remedies are actually drafted and negotiated, which is rare for this topic.

I was the sole technologist on the Facebook privacy matter after Cambridge Analytica, that resulted in the $5 billion penalty
I spent a lot of time alongside case teams in the FTC's location data orders, precisely defining location data, what it means, what is included, what's not included

Specificity & Evidence

12 / 20

The episode names real cases with real figures (Vizio 2017, $5B Facebook penalty, $500M Epic Games, GoodRx, Avast, OkCupid, Market X Mode, Gravy Analytics, Mobwalla, GM) and includes a technically specific point on WiFi triangulation, which is above average for a podcast discussion. The 'lessons' and 'takeaways' segments, however, retreat into generic advice without anchoring to metrics, timelines, or outcomes.

Goodrx. For instance putting in your prescription that you want a coupon for and putting in the amount and the drug dosage and where you want the prescription served. But what Goodrx had was a Facebook pixel on their website
there are some subtle differences in the definition of location data even across the four current FTC orders, in Market X Mode, Gravy analytics and Mobwalla

Conversational Craft

7 / 20

The hosts ask broad, open-ended prompts ('what should companies take away?') that let the guest deliver prepared content rather than probing for depth; there is almost no follow-up, pushback, or productive disagreement. The kayak-and-police-boat tangent eats several minutes of runtime, and Justin's most pointed observation ('$5 billion is just the cost of doing business') is left undeveloped rather than pressed.

So, Aaron, what do you like to do for fun when you're not doing all of this technologist stuff?
But the fines don't matter. Uh, don't seem to deter anyone

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C64%
  • Speaker A23%
  • Speaker B13%

Most-used words

data58privacy43location19cases17health17case14sensitive13security12aaron10vizio10today9technologist9remedies9back9means8tech7

Episode notes

Aaron Alva is a Harvard Berkman Klein Center fellow and the Founder of Alva Strategy Center, advising organizations and enforcers on privacy, security, and AI governance. Previously, Aaron was a lead tech advisor at the FTC, where he was instrumental in driving the agency's approach to privacy and security enforcement. In this episode… Privacy risks often hide in how companies collect, use, and share personal information. Smart TVs, health-related websites, and location data have all drawn regulatory scrutiny when data is used in ways consumers did not reasonably expect. A decade of FTC privacy enforcement shows companies what regulators consider unfair or deceptive. So, what can companies learn from these cases to strengthen their privacy practices? Reducing privacy risk starts when companies understand the data they collect, where it goes, why it's being used, and whether that use is necessary in the first place. Companies should pay close attention to handling sensitive data with care, including health information, location data, children's and teens' data, and driver behavior data.

Full transcript

36 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to the she Said Privacy He Said Security podcast. Like any good marriage, we will debate, evaluate, and sometimes quarrel about how privacy and security impact business in the 21st century. Hi, Jodi Daniels here. I'm the founder and CEO of Red Clover Advisors, a, uh, certified women's privacy consultancy. I'm a privacy consultant and certified informational privacy professional providing practical privacy advice to overwhelmed companies.

Speaker B: Hi, I am Justin Daniels. I am a shareholder and corporate M and A and tech transaction lawyer at the law firm Baker Donaldson, advising companies in the deployment and scaling of technology. Since data is critical to every transaction, I help clients make informed business decisions while managing data privacy and cybersecurity risk. And when needed, I lead the legal cyber data breach response brigade.

Speaker A: And this episode is brought to you by. No one can hear the weird hand on the head. Red Clover Advisors. We help companies to comply with data privacy laws and establish customer trust so that they can grow and nurture integrity. We work with companies in a variety of fields, including technology, e commerce, professional services, and digital media. In short, we use data privacy to transform the way companies do business. Together, we're creating a future where there's greater trust between companies and consumers. To learn more and to check out our best selling book, Data Reimagine, Building Trust One Bite at a Time, VisitRed Clover advisors.com Too bad we're not doing pictures because we're matching and blending. Our pictures would be so nice. I'm in light blue. You're in dark navy. Got like a little blue in my jacket.

Speaker B: Uh, that's what I'm like. I walked upstairs, I'm like, what happened? You're like, all dressed up today.

Speaker A: Now I have a jacket on and everything.

Speaker B: I know. I was like, whoa, what happened here?

Speaker A: I know fancy things, um, are at play. And now we're going to go into fancy people because we have Aaron Alva, who is a Harvard Berkman Klein Center Fellow and founder of Alva Strategy center, advising organizations and enforcers on privacy, security and AI governance. Previously, Aaron was a lead tech advisor at ah, the ftc, where he was instrumental in driving the agency's approach to privacy and security enforcement. And Aaron, I can't wait to dive into all of this FTC Enforcement Fund today.

Speaker C: Happy to be here.

Speaker A: That's your turn.

Speaker B: What?

Speaker A: That's your turn.

Speaker B: Oh, I'm supposed to talk now?

Speaker A: Yeah, that's your turn. Um, I ran out of cue cards.

Speaker B: So, Aaron, why don't you tell us a little bit about your career journey?

Speaker C: Sure. Um, thanks again for having me. Um, my career Journey started uh, over 20 years ago. Um, I was working in cybersecurity research at a US national laboratory. Um, oftentimes what was a cybersecurity research issue had a technical response as how you fix things or how you make things more secure. Everything was technical in terms of how to fix or make things secure. And I was curious about well, what are the law and policy levers that you can pull in order to also make things more secure or more private? Um, and so I took that to um, doing a joint master's in information management and law degree at the University of Washington that was supported by the National Science Foundation. Uh, and then for 10 years I was at the FTC, um, as Jodi mentioned, um, uh, as a technologist and tech advisor working on some of the biggest, um, privacy and security as well as AI cases out of um, uh, the ftc. And now um, I'm recently uh, left and started my own venture. Um, and um, I'm excited to be out in the world to get to uh, share my expertise and knowledge, um, and help companies and enforcers really understand these um, really vexing and complex security, uh, and privacy and now AI challenges.

Speaker A: Uh, amazing. Well, let's dive in because you described yourself as a technologist and we've talked about privacy enforcement. Can you share more about what that actually means and how that shows up in work?

Speaker C: Yeah, um, so the term technologist is uh, is one that means a lot of things in different areas. So I would say at the ftc, um, a technologist in privacy enforcement meant that um, me and other technologists at the agency would get to sit alongside attorneys and describe these technically complex issues and then help at every stage of the uh, privacy, uh, investigation, um, at the ftc, from understanding at the outset what uh, potential uh, cases that the FTC would open, um, to helping write technically precise questions, uh, asking the company questions about what the privacy issues were, um, to describing um, to attorneys, what are potential harms, um, privacy harms and how this impacted consumers all the way to. And we can get to this further. Some of the remedies that I would help develop, uh, and write alongside and uh, negotiate alongside case teams.

Speaker A: And I think most people know, but I think what's also interesting is the idea of a technologist is popping up more and more in the state enforcement agencies like NCAL Privacy, they are very proud of their technologists that they have, uh, and other states I think are following suit. So something that I think is important for people to remember when they think, oh wait, do they actually know. Yes, they do.

Speaker C: Yes. Yeah. And that has been definitely a growth area, especially in the last six or seven years. Um, uh, for a while at the ftc I was the only technologist that would work on both antitrust competition and consumer protection issues. Um, and then in the later years of when I was there, uh, the number of technologists had grown up to 13 um, or so. And you're right, state ags and state uh, agencies are hiring in house technologists now which really um, gives attorneys the ability to kind of understand these complex issues um, much more efficiently and quickly now.

Speaker B: So speaking of technology, when you think back to the earlier days of your work, what still feels really relevant even today?

Speaker C: Yeah, that's a good question. Um, one thing that feels relevant today is a lot of the privacy enforcement from that earlier decade that I was at the ftc, the earlier time then, um, is still kind of popping up now. Um, one case I worked on, uh, back in the earlier days of my time there was Vizio, uh, where Vizio was taking pixels on your smart tv, uh, and had their own database that identified what you were watching. Um, and we're licensing that to um, advertising and analytics companies. Um, that is relevant still today. Like the Texas uh, attorneys general just brought a number of cases against smart TV manufacturers for um, the same conduct, the same uh, sort of tracking from what the FTC said in Visio in 2017 uh, was unfair. Um, and what came out of the Vizio was sort of an early days imagining of some remedies like Vizio, ah, had to delete all four years of TV viewing history so they couldn't benefit further from um, from that conduct that the FTC said was unfair at the time.

Speaker A: I'm curious as you think about the Vizio case and I was a Vizio consumer and remember that case vividly to what you just described now with what Texas is doing are companies forgetting these cases? Are the learnings just the technology's changing and they want to adopt the next technology? It feels like we're repeating in, I mean that's almost a ten year period.

Speaker C: Yeah, no, uh, uh, as a former enforcer, uh, uh, it's a hard thing to understand and grapple with and figure out is um, a lot of uh, you know, cases like Vizio and others like the FTC only has the authority to bring one case against one company and that that company is then under a typically 20 year legal order to just to you know, change their conduct. Um, and the, you know the theory from Dan Solov and Woody Herzog and others is that that creates a common law of privacy that um, informs other companies like Vizio's competitors that they should bring their practices to the level at which Vizio now has to do under FTC order. Um, but it's using 110-year-old law. It's limited. We don't have a comprehensive federal privacy, uh, legislation in the states. And so there's not a technically specific require legal requirement for the, for you know, the other companies, uh, you know, to have to follow the same uh, letter of the law.

Speaker A: That's interesting. I've always gone with, I guess that common law privacy concept and many peers have as well. You would always look to those cases here were the learnings don't do that.

Speaker C: Yes, yes, yes. And I, and I think that's, uh, I think that that's my view. I um, think also, uh, a lot of the privacy cases I worked on were bipartisan. Privacy and security are still bipartisan issues. This current FTC is still bringing security and privacy cases. Um, so I think that also bolsters the idea that what comes out of the FTC is something that companies should take note of.

Speaker B: So you were right in the middle of the Facebook case. Is there anything that really stuck with you from that experience?

Speaker C: Uh, other than it being a wild time in my life? Um, I was the sole technologist on the Facebook privacy matter after Cambridge Analytica, um, that resulted in the $5 billion penalty. Uh, and then Facebook, um, had certain 20 year order requirements to have to stand up a mandated privacy program and so forth. Um, one of the things that I think that stood out to me then, uh, that still continues to happen today is um, that the cost of not aligning uh, your privacy controls with consumers expectations is still high. That is still also from a legal perspective, what is partly what unfairness means. Um, and so back then Facebook had uh, you know, they had a privacy setting that said hey, yes, you can give away your friends data. But that went well beyond the expectations of what uh, each individual thought was happening and became a scandal that hit the public attention and Congress's attention, um, that led to that Facebook case. And so that sort of lack of clarity and not aligning your expectations with what people, consumers think is still, I think super relevant. Now.

Speaker A: Justin, I know you have lots of thoughts about this case.

Speaker B: Well, look in our notes, Aaron, repeat again. How much was the fine?

Speaker C: $5 billion.

Speaker B: $5 billion. What was today's theme? And then we had our pod, our episode the other day, Jodi. So why do you think most companies Are uh, like Vizio or some of these other companies ignore these FTC orders

Speaker A: because they want to keep making money because they're using the data.

Speaker B: Right. Because they're so rich. A $5 billion settlement to them is just merely the cost of doing business. Now if the FTC could haul some of these people and give them a little jail time, that would change things dramatically. So that's my point.

Speaker C: That's, I mean it's a, that's a totally a fair point. Uh, I think that you uh, know, especially the last five years of work I did at the FTC was a lot on developing remedies that create bright line rules that actually prohibit conduct. Right. And that uh, you know, versus a monetary fine or needing to stand up a privacy program that has, that's more process based on a violation good or X and better help. Being prohibited from sharing health data for app purposes I think is a clearer line sort of remedy that actually cuts at the heart of the incentives of data use and data disclosure and so forth.

Speaker B: I mean I guess Aaron, I know we're going to segue here into talking about remedies because honestly at the end of the day that's really what you do at the ftc. You identify problems and come up with remedies from your time there and what you do now. But I guess my question around that is when we talk about remedies it seems to me another remedy you could have is what if you had a rule that said the default privacy settings on all these different devices and apps had to be privacy enhancing as opposed to what we have. Whereas the default is you give everything away unless you want to go through about six different screens. So I'm just curious, you know, what do you think about things like that or what are some of the themes you've seen, you know, still seeing today around remedies that actually have impact? Because it's clear $5 billion is not having enough impact.

Speaker C: Yeah, um, I think, I think you're right about the switching the defaults. I think that is a powerful um, kind of piece where you know, it still gives people the choice to change back to what you know but it sets that baseline uh, at you know, a more privacy Preserving piece. 1 um, case where the FTC did this was in Epic games where, which was like a children, private children's privacy case um, where uh, kids who were, or children who were on Epic, you know on Epic Games platform were um, getting harassed, verbally harassed, uh, at times um, while going through their game. And so one of the remedies in Epic games, other than the $500 million penalty was to switch the default for kids to saying the audio during gameplay is off by default.

Speaker B: You know it's interesting you say that because I heard $500 million but I skipped right to switching the toggle differently because now when I think about what Aaron's talking about now go to OpenAI or some of this artificial intelligence and what are some of these impact on kids? So to your point Jodi, there's like this common law privacy idea around some of these rulings which kind of set guardrails. Obviously none of the AI companies are listening to any of those guardrails.

Speaker A: It's always been the challenge of uh, well it happened to them, maybe it won't happen to me. And is that really going to be what I have to worry about or is it just them?

Speaker C: Um, that is always going to be back and forth. Um, and I know there's a lot of AI laws that are out there that are being uh, enacted, you know in the states and there's the EU AI act um, as well. Like those are, those are some of the constraints that were that you know we're starting to see. But um, but from a existing laws on the books, uh, you know that the FTC and state ag saying this is deceptive or this is unfair is still, still applies to uh, you could say all of commerce in America. It still applies to AI, UM uses and situations.

Speaker A: We talked about smart TVs and data collection. We move in advertising. We had a big tech player advertising personal information. Health and pixel tracking was it seems like a multi year focus for the FTC and then even some states and some other areas. So can you talk a little bit about the health arena and if a company is listening right now and they're in the health space, what should they be thinking about?

Speaker C: Yeah, um, uh, so the health arena is one of those areas where if you think of um, even back to uh, an earlier I think 2011 privacy report from the FTC that identified here are certain sensitive or high risk categories of data. Health is quite prominent. It comes up, it's pretty apparent that your own health condition or inferences made about your health is really sensitive and personal. Um, and so a lot of the FTC cases in the health pixel tracking ah, arena involved uh, going to say goodrx or betterhelp and uh, say goodrx. For instance putting um, in your prescription that you want a coupon for um, and putting in the amount and the drug dosage and where you want the prescription served. But what Goodrx had was a Facebook pixel on their website that was sending this sensitive health information to Facebook, uh, for certain advertising purposes. And that is the piece that through all these FTC cases and other actions, um, it has been the reinforcing, um, this is an unexpected use of your personal sensitive health information, um, and for purposes that the consumers didn't often know about or consent to. Um, and that's conduct that is, uh, when we talk about remedies prohibited for these companies under order now.

Speaker A: And if you were to think about one or two steps for a company listening, who might be in that house, what should they take from this?

Speaker C: Ad tech is a very complex dynamic space. Um, so sitting down and auditing and understanding, uh, what data is being sent to other players, uh, to other entities, like advertising entities, I think is a really good step. Number one is sitting down and looking at your website, identifying, oh, do I have an area where I'm collecting or asking for sensitive info? And now what pixels do I have on this site? What's happening on this site? What ad tags do I have on this site? Um, getting an understanding of where your data is going or where your consumer's data is going is I think a critical first step. And then taking that next action and taking that action to say, I need to limit this, um, I need to change my practices here if it is sending sensitive info, um, and go through and then make it a repeatable part of your marketing process.

Speaker A: Those are good tips. Thank you for sharing. Someone needs to learn from these cases. I don't want my prescription information shared anywhere.

Speaker B: But the fines don't matter. Uh, don't seem to deter anyone.

Speaker A: Well, we're here doing our part.

Speaker B: I see.

Speaker C: And again, these pixel cases are not just fines. Go to is prohibited from sharing sensitive health info for advertising purposes.

Speaker A: Um, and then you have states that are looking at this. So now we have our state privacy laws and these are some of the issues that they're working in. And we are doing our part to remind people of these cases and remind them not to do it. So what's next? We have another goodie.

Speaker B: Location data.

Speaker A: Location data.

Speaker C: Oh.

Speaker B: So location data has been another big area. What should companies really understand about handling that can of worms?

Speaker C: Uh, yeah, um, very much like, uh, we talk about the sensitive or high risk health or data buckets. You think of health data, but you also think of location data and the potential harms that that can cause for somebody knowing where you are, where you've been, um, and what that means for you. And so, um, a lot, you know, for companies where location data is actually necessary to serve the service, uh, then the takeaway is data minimization and use purpose limitations is only use the location data for the delivering of the service, but not also. And don't use it also for other purposes that aren't, uh, expected or consented to by consumers. Um, that I think is a key part. And there's a number of technical ways to kind of deal with location data that manage the risk and lower the sensitivity, um, like coarsening the data, uh, so that it's not a precise data point. It's more of like, here's what happened in that mile or kilometer. Um, there are other techniques as well to kind of consider as part of managing location data use.

Speaker A: And location data is another really interesting one because the definition of precise geolocation seems to differ depending on who you're asking.

Speaker C: Uh, uh, yes, I spent a lot of time alongside case teams in the FTC's location data orders, precisely defining location data, what it means, what is included, what's not included. I think that was a key role for a technologist, is getting those technical definitions right. To be clear about what we're talking about, those technical definitions in legal orders or in descriptions really matter a lot. Um, there are some subtle differences in the definition of location data even across the four, um, current FTC orders, uh, in Market X Mode, Gravy analytics and Mobwalla. Um, but also it's pretty clear that, um, it's not just GPS data, um, that is considered location data. If it's precise about a consumer device, it is still location data. Um, uh, for instance, your routers have a unique identifier. And uh, there's a technique called WI fi triangulation where your phone can understand how far certain number of unique routers are from your device and that can be sometimes more precise than GPS data. Um, and so that, that. And so knowing that and including that as part of the definition of location data and working with those nuances is a lot of what I worked on, um, in terms of helping, um, case teams and providing clarity to, uh, companies about what's included.

Speaker A: Well, we've talked about health and location, which are definitely considered sensitive data types amongst a lot of people. But there's more. It's not just those. Erin, can you tell us what some of the other kinds of data that you are seeing that might also be considered sensitive data?

Speaker C: Yes. So based on, uh, FTC cases, um, the FTC has also taken action in, uh, Browsing data, um, as another kind of area where, where you go on the web and what you navigate to and what you're seeing and your Internet browsing history is considered uh, sensitive or high risk. Um, that came from the Avast case, uh, children's data. Obviously we have uh, a law in the books, coppa, um, children's data is inherently sensitive as it relates to kids. Um, and that definition is not just kids, it's increasingly from FTC orders expanding to teens, uh, in certain cases. Um, driver behavior data. Um, one of my last matters, uh, I worked on was the General Motors matter that deals with uh, the sensitivity of driver behavior data. Um, both location data coming from where you were driving your car and also how you were driving your car. Like were you speeding, were you hard braking or hard cornering, that sort of thing. Um, what you learned, what, what you were listening to on the radio in the car, that sort of thing. Um, uh, those are, those are the main buckets. And then there are, you know, there have been past actions from the FTC around AI related to M in high risk situations. Uh, like Rite Aid or, or the recent OkCupid case about um, sharing um, photos and demographic and uh, data for that ended up being used for training facial recognition models by another company.

Speaker A: Just. I know you have some thoughts that you want to talk about in AI.

Speaker B: I've been enjoying the remedy conversation with the ftc. Oh, um, okay.

Speaker A: I just wanted to make sure we, we covered all your fun.

Speaker B: No, no, we can take a day off from AI. I can't remember the last episode where we didn't discuss it. So, um, Aaron, after all the different topics we've covered, and we've covered a lot of ground here in the last 20 minutes. If we step back, what do you think some of the biggest lessons companies should take away from what we've talked about?

Speaker C: Yeah, um, the biggest lessons I think for, uh, take, you know, as takeaways and they apply both to, you know, privacy and as, as well as to security. Um, you know, these are not. Those are, those are both, uh, both applicable here. Um, one is, uh, how you know, limiting, you know, having use purpose. Limitations are increasingly critical today. Knowing as a company how you're using the data, being narrow and clear about what you're using the data for, and, and having that use purpose limitation that also is tied to um, how long you're retaining the data, making sure you're not using it for other uses. This is kind of a reoccurring theme. Um, in a lot of the cases from the FTC as well as some of the new legislation that's coming out. Uh, in terms of privacy, uh, you know, new state privacy laws and so forth. Um, another area is as I mentioned, data retention and minimization, um, and this is also particularly true for security is if you uh, you know limiting the, the um, ah, scope of a, of a potential breach, um means limiting the amount of data you have on hand that uh, that might be exposed. Right. Um, having those data retention and minimization kind of practices is a critical part um, I think of some of the takeaways, uh, sensitive data like all the categories we talked about. So health, location, uh, browsing, driver behavior, children, so forth. Um, those all require I think heightened care. Um, and the FTC has made that quite clear. And uh, and uh, both in previous administrations and now, um, that seems to be still quite relevant. Uh then I think finally technical details really matter. Um, it's really important, especially not to bring up AI again. Uh, it's important to have a clear scoped understanding of what it is we're talking about. What are the problems, where are the definitions. And I think that that translation and back and forth with attorneys and technologists about all getting on the same page of this is exactly what we're talking about or this is what health data means or location data means. That is I think critical to us having a clear way to move forward and have a dialogue and have clarity to the market about what it is. Um, you know, enforcers and companies need to take, take uh note of. So those are, those are my overalls.

Speaker A: Those are really good tips and themes and reminders. And given all you know about how technology works, especially in the privacy and security space, what best tip would you offer? I can only imagine the kinds of conversations you might have with, you know, with those around you.

Speaker C: Um, to me, uh, the best tip I have to offer um, is is changing up the emails that you

Speaker A: uh,

Speaker C: use to sign up for marketing or loyalty programs. Um, is I often like to take even say my Gmail address and do a plus sign and then have another name to it. That does kind of two things. One, uh, it throws the data brokers and ad tech ecosystem off, uh, because oftentimes email addresses are unique identifiers where all of your activity is associated with an email address or a hashed email address and then that all gets all put in one bucket, uh, and used to create inferences about you for ad targeting or whatnot. Um, so by changing up the email address, email still comes to you but it really makes it harder to piece all those, uh, information pieces together for that ecosystem. So that would be my personal tip.

Speaker A: Thank you for sharing. We have heard that one a couple of times. A lot of people who are. Who like that idea.

Speaker B: So, Aaron, what do you like to do for fun when you're not doing all of this technologist stuff?

Speaker C: That's a really hard question. No, um, I like to row. So I have the pleasure of living on an island. And so I get to go out, uh, in, uh, out on the harbor in a rowboat. Whether it's a quad or an eight or even, uh, yesterday I was out on a single, which was somewhat terrifying. Um, but it's a beautiful, good workout and practice. And, uh, it's one of the things that kind of gets me outside and is really pleasant.

Speaker A: That sounds so nice and so peaceful.

Speaker C: It is.

Speaker B: I don't think you appreciate how fast he might be rowing.

Speaker A: I. I didn't say it wasn't hard. I just said it might be nice. It might be peaceful. Because I bet you he might be rowing in. In his area without police boats coming at you like what you did to me when I was in the Washington.

Speaker B: Oh, I did nothing like that.

Speaker A: Yeah, it was great. Um, but let's get back to you, Erin, if people want.

Speaker C: I want to hear this story at some point.

Speaker A: It was lovely. We were in kayaks and, uh, in. I don't remember which busy harbor. And there's a police boat coming right at me in the direction that Justin has us going, and he's off in another one. And I'm just looking at this police boat right over here. And that was not fun.

Speaker B: See, you still seem traumatized.

Speaker A: I am still traumatized. I had one kid, you had another kid, and that was not nice. That is my story, everyone. But I do want to make sure that people here know how to connect with you. Erin.

Speaker C: Uh, yeah, so I am, um, on LinkedIn. Aaron Alva. Uh, um, as well as my own personal site is StrategyCenter Tech. Um, and all the rest of my contact, uh, details are on the site directly.

Speaker A: Amazing. Well, thank you so much for sharing an insider's view, uh, from all these different FTC cases. We really appreciate it.

Speaker C: My pleasure. Thanks for having me.

Speaker A: Thank you. Thanks for listening to the she Said Privacy, he said Security podcast. If you haven't already, be sure to click subscribe to get future episodes and check us out on LinkedIn. See you next time.

More from She Said Privacy/He Said Security

All episodes →
  • How to Build and Implement AI Systems That Businesses Can Trust
  • How a Georgia Lawmaker is Tackling Kids' Online Safety
  • Navigating Opt-Out Challenges and Strategies for Getting It Right
  • From Gatekeeper To Architect: How General Counsel Are Shaping Innovation in the AI Era
  • The Accountability Problem Behind AI Adoption
Explore the best B2B AI & Data podcasts →
All She Said Privacy/He Said Security episodes →