Click for Full Transcript

Intro 0:01

Welcome to the She Said Privacy/He Said Security podcast. Like any good marriage, we will debate, evaluate, and sometimes quarrel about how privacy and security impact business in the 21st century. Hi,

Jodi Daniels 0:21

Jodi Daniels here. I’m the founder and CEO of Red Clover Advisors, a certified women’s privacy consultancy. I’m a privacy consultant and certified informational privacy professional, providing practical privacy advice to overwhelmed companies.

Justin Daniels 0:36

Hello, I am Justin Daniels. I am a shareholder and corporate M&A, and Tech Transaction lawyer at the law firm Baker Donaldson, advising companies in the deployment and scaling of technology. Since data is critical to every transaction, I help clients make informed business decisions while managing data privacy and cybersecurity risk. And when needed, I lead the legal cyber data breach response brigade.

Jodi Daniels 1:00

And this episode is brought to you by ding Red Clover Advisors. We help companies to comply with data privacy laws and establish customer trust, so that they can grow and nurture integrity. We work with companies in a variety of fields, including technology, e-commerce, professional services, and digital media. In short, we use data privacy to transform the way companies do business. In short, we use data privacy. I I really want to say in short, we use data privacy to transform the way companies do business twice because I’m confused. So, anywho, to learn more about us and to check out our best-selling book, Data Reimagined: Building Trust One Byte at a Time, visit redcloveradvisors.com. I’m clearly very confused because I’m.

Justin Daniels 1:43

Did you take enough coffee?

Jodi Daniels 1:44

I did actually, but maybe I melted because I had coffee outside in the Atlanta humidity this morning. I wasn’t quite planning on the outside, but that’s okay. It was really good, and we’re recording during World Cup season and Justin, right before we hit record, you shared something cool.

Justin Daniels 2:05

Apparently, the World Cup teams are staying at the hotel, literally connected to our office. So I guess Argentina and and who are they playing today? England. They’re heading. They were heading down to the.

Jodi Daniels 2:18

You need to get this information earlier next time because we could have moved the recording and maybe seen cool World Cup people.

Justin Daniels 2:27

Didn’t know that you were so interested. Sports is not normally your forte,

Jodi Daniels 2:31

but the World Cup is the World Cup.

Justin Daniels 2:33

Yes, like you like the Olympics,

Jodi Daniels 2:35

and I have no interest in going with a couple 100,000 people to the fan fest. So instead, you know, at a distance in a hotel would be a lot easier. Okay, but I suppose we should talk about privacy because today we have a longtime privacy friend, Ben Isaacson, who for more than 25 years has been a leading privacy professional and trusted counsel. And during the Internet I Love 1.0 era, he. was instrumental in launching the first self-regulatory guidelines for email marketing, addressable TV, and mobile marketing. Ben has an incredibly long bio. If you are listening, please go to the show notes so you really hear all about how amazing he is. And fun fact, he was one of the first privacy professionals to get certified as a CIPP US with the IAPP in 2005. So Ben, we’re so excited that you are here with us today.

Ben Isaacson 3:32

Thank you. Great to be here.

Justin Daniels 3:34

So Ben, why don’t you tell us a little bit about your career journey?

Ben Isaacson 3:39

Yes. In fact, I need to change that bio because as of this week, it’s 30 years I’ve been in the same industry doing similar things. My my career journey started as an intern with a kind of fledgling startup trade association in Washington D.C. that was focused on interactive television, and then quickly morphed into becoming the association for Interactive Media and covering sort of the internet as well as interactive television, and I was the first, I think, the first registered lobbyist for the internet industry in 1997, and have been working at you know originally in public policy, and then you know I took over the trade association. It got acquired by the Direct Marketing Association, so I was really got my my deep learning in data brokers, which we’re going to talk about because that was the DMA, you know, for 100 years before they, you know, got acquired by the Association of National Advertisers, and then I joined Experian for 10 years and got really deep in the weeds on what is a data broker and all of the disparate data activities that around the world, because Experian really is a global conglomerate, not just early U.S. business. And then for the last 10 years, I’ve been in private practice doing, you know, my own law as well as you know AI and other kind of new innovative technologies that kind of intersect with data licensing and. Ad tech and marketing tech and kind of all the things that that we’re going to talk about today.

Jodi Daniels 5:04

And so, Hugh 10 talking about data brokers and Ben, you always like to help kind of set the stage for what is a data broker. And a lot of companies have that question, which is, are they a data broker? What is a data broker? And then, if you want, we could throw the monkey wrench of New Jersey’s new law that we may or may not need to be paying attention to. Depends on the day, where they have data collector as a new definition. So help us understand these definitions and maybe how this, how companies should be thinking about it.

Ben Isaacson 5:39

Yeah, I mean, with the exception of the New Jersey thing, which we’ll talk about, you know, I think the the common broad definition of data broker is entities that sell data that they didn’t collect themselves, that they don’t have a direct relationship. They’re hiding in the background. You don’t know who they are. They compile data from all different sources and then they sell it to you know whoever will buy it from them. There are really two categories of data brokers that I like to make sure everybody’s familiar with because there’s the category I think that most people think about is a consumer in their head, which is the the profiling individual search kind of you know the Spokios of the world that really provide you know tell me about that person, and that might be for background check. That might just be for you know rental verification. Anything that you know companies might use to say, or individuals even might use to say this person is has got this background or or some information about them that I need to know. And those are sort of the directory type services, right? But the the I don’t work with those companies. By the way, the companies that I work with are really in the second category, which are really large scale, more advertising, marketing, trying to you know reach you know broad basis of individuals or devices that again they don’t have a direct relationship with, but they just want to build information about, or you know, those individuals or predictions. Now, these the laws that are on the books now take a very different approach, combining these two into one common definition. You know, California is kind of being the benchmark for I think all of the definitions because they’ve come out with regulations and made it very clear what their their definition is that it you know a company that does not have a direct relationship and there’s really a subjective standard there now which is going to be interesting to see how it plays out in the next few months where did the individual know that they had a direct relationship with that entity even if the entity did collect the information from them, so so there’s kind of a two-step process to define what is a data broker. A, did you collect it? If you didn’t, you know, you’re automatically and you’re selling it. You’re automatically a data broker. But if you did collect it, and you either you know were still in the background somehow that the individual didn’t know you were collecting it, or that you’re enhancing that information with third-party data and then selling that information. California is going to consider you to be a data broker with with significant penalties, as we might talk about here. You know, if you don’t register and comply with their delete act, the other states are very different, and there’s a lot of different nuances between you know the the five other states that now are on the books with data broker related definitions and registrations. Some like Oregon really exempt business to business sort of professional you know B 2b targeting or B 2b data profiling. Others are more focused on is your business like Texas is your business really focused on data brokering or is it sort of an adjunct to you know everything else that you do? So there’s sort of a threshold to the primary purpose of of what you’re doing with that data licensing and sale. And and again, you know, and then obviously New Jersey is it’s whole other beast now that just came came to fruition around this combination of are you a data broker and a data collector that needs to register because you you know you’re just selling data to data brokers. So so that’s again I’ll pause there because there’s there’s a lot to unpack, but it it is getting more complex across the states, you know, seemingly every every few weeks now.

Jodi Daniels 9:26

That is true.

Justin Daniels 9:29

So when you compare the laws in these different states-California, Connecticut, Vermont, Texas, New Jersey-how many states are there with data?

Ben Isaacson 9:40

Well, there’s 6 states now.

Jodi Daniels 9:41

New Jersey’s the newest one to join the party.

Justin Daniels 9:43

I see. Yeah. What kind of themes are emerging? Because I guess what I would ask both of you is, and I’ve asked this about other laws, is how much are these going to deter people? Because these data brokers, it’s so lucrative. Where do they get the resources to prosecute people and ask them? Actually, make them pay big enough fines that they’re going to care.

Ben Isaacson 10:04

Well, I mean, I think California is the trendsetter. I mean, historically on privacy, and I think with data brokers, you know, it’s been an interesting evolution watching it go from, you know, simple transparency of hey, we just want to to bring these hidden companies into the light, and I think that’s the number one theme all these states are really following. Is that for you know generations now it seems like data brokers have been in the background selling data that consumers had no idea how how you opt out, who they are, what they’re doing, and that the number one objective of all of the states is to say, hey, we want we want consumers to know who these companies are. So California started that ball rolling. Actually, Vermont started the ball rolling on that, and then California quickly followed and enhanced it. And then you know to say, okay, this is the name of the company. This is an email address. This is a website. This is how you know you potentially can learn more and and opt out if you want to go opt out, and again, not necessarily requiring that opt out, but you know, but at least making the the privacy policy available. In in California, obviously, evolved with the Delete Act significantly to say we want to empower our consumers to opt out or delete really their their information. You know, it can function in a two step process from deletion to opt out. But we don’t have to get into the mechanics. The important thing is that that is the trend now, and Connecticut just followed suit a few you know a few months ago, saying we are going to you know create the same sort of deletion mechanism that California is implementing in two weeks to allow our consumers to get out of being sold, essentially, and and again, you know, the the pragmatic way of going about that, which New Jersey is not exactly following, is to say, you know, we’re going to allow consumers to register with California. We’re going to require them to verify their residency, and then we’ll create this really technical mechanism to synchronize with all of these data brokers to provide that that accountability and authentication needed to say, okay, we will actually delete your information and suppress it moving forward. So that that’s sort of this this trend line. New Jersey again took a very different path for very interesting reasons, as I’ve come to learn. But again, I think the the California and Connecticut you know combination is now a model for for other states to follow to at least empower their consumers to to to not be sold. I guess is the the simplest way to say it.

Jodi Daniels 12:41

So Ben, tell us a little bit more about New Jersey and its unique diversion from these other states. What what do people need to know about Jersey?

Ben Isaacson 12:52

Yeah, I’ve learned a lot in the last week or so. I’m you know I’ve never really followed New Jersey politics. I think what’s what’s fascinating about what’s been going on is New Jersey has a fiscal requirement to balance their budget every year, which I think is a great thing for states to to consider. But when when they get into the the sausage making and at the end of that you know deadline they’re not balanced, they need to figure out a way to increase revenue, and so my understanding, and again, Bloomberg Law reported on this as well. So it’s not just you know me saying it. Is that this this law that came that was introduced in both both houses, you know, the Senate and the Assembly passed out of committee, passed out of you know passed out of both floor votes, and was signed by the governor within four days, which is unspeakably crazy in any kind of lawmaking, unless there’s again an emergency. But there was obviously no emergency here. The emergency was the fiscal gap, and so they created this mechanism to you know, potentially raise $50 million. I think that’s the number they’re they’re trying to gap fill by creating a tiered structure for data brokers to register with the state based on the processing of New Jersey data. And so theoretically, this you know again conceptually whiteboarding that kind of idea makes some sense on a on a whiteboard, right? You know, how do we get $50 million from an industry that no one really loves and doesn’t understand, and what the implications are doesn’t really matter. We’re just going to put it on the books, and and then the governor can sign it, and we can say, “Yep, we balanced our budget. So that’s that’s my understanding of of the genesis for the law, they didn’t really think about you know little things like the U.S. Constitution and how it might you know not allow for these kinds of you know fee specific registries that are based on you know sort of volumes of data that no one can possibly correlate to. New Jersey residents, or you know, free speech grounds, or any of the kind of other challenges that that might come up. The main thing here is that you know this this was done so quickly that they really didn’t consider all the implications of the definitions that they put into place because it’s not just data broker as we defined it; it’s data collector, which they are defining really as any companies that sell data to data brokers. Which, when you look at like the list of you know California registered data brokers, which is you know public information, you can see a whole lot of companies on there that are the mechanics of the ad tech industry, for example, that just supply sort of the exchange of real time information for for bidding on on you know ads. So any kind of company that’s an ad supported company, for example, you know publishers, you know of websites that that are ad supported, likely work with one of these data brokers. So all of a sudden, like every ad supported publisher is now a data collector, and will have to comply with this New Jersey law. So you know, $50 million might be you know again if it’s possibly enforceable, is is is not even close. It’s probably $5 trillion. You know, it’s like the whole economy of the ad-supported industry plus all of the sort of interesting new companies and the like retail media networks that are, you know, Best Buy, for example, you know, that that has now ads that are built into its like listings of you know products on the shelf. Those kind of companies that that are going to work with these real time, you know, ad exchanges and whatnot. So you you have you know all sorts of industries now that I think again New Jersey just couldn’t have really thought through in you know two days are impacted by this law, and just again the the the fact of trying to comply with it without knowledge of who is a New Jersey resident is technically impossible. So I think you know we’ll see some change to this law before it goes into effect.

Ben Isaacson 17:04

At least on the data broker and collector side, there’s another part of this law that was really interesting that got sort of pushed through at the same time, which was the ban on sensitive personal information sale. And so you know they’re not the first state to do that. Maryland was the first state, but but what’s really interesting again, like they just passed a comprehensive data law, privacy law, a year or so ago. That law just came on the books. Companies are just starting to enforce it. It included an opt out for sensitive personal information. Now it’s just banned as of today. Like it was banned as of july 2. It’s not. They just went into effect. So again, not a lot of thought in terms of how that implication of immediate enforcement is in effect. But again, we’ll see if that stands up, you know, after you know the the next legislative session or however it might get amended before before too long. I guess.

Jodi Daniels 18:01

You hinted that this is an industry not everyone loves, and maybe this is an area of opportunity. So I’m curious, from your point of view, in general, we have six of these data broker laws. What do you think is driving the increased focus on data brokers? And if you if you had a crystal ball, what what’s your what’s your prediction? I don’t know. Pick your time horizon of the next year. What we might see for data brokers?

Ben Isaacson 18:34

I I think there’s there’s a few things in play here. I mean, and and one, you know, I have to kind of start with having been in this industry for so long, that you know again, it’s kind of sad to see that the direct marketing association really went away, right? And the and the association of national advertisers that acquired you know the the the former entity of the DMA really hasn’t focused on data as a coalition-building effort around public policy, and and so there’s really no industry that represents these companies anymore, no, or industry organization, I want to say, or coalitions that really represent these companies in a way that can help educate legislators that data is important to the you know commerce of of of the United States, and so you know, and there’s and again differentiating some of the harms that might come from data broker activities. Again, some of those background check type services that may not have you know full FCRA compliance or other laws that might intersect with them should be again focused on where there could be fraud or other other identity theft things that are happening in those industries, versus kind of the ad tech marketing tech you know industries where it’s harder to pinpoint any sort of harm that other than the sensitive data piece maybe that that really needs the same type of regulation. So I think a there’s really no friction. I think simple you put. You know, in the public policy space, B, it is relatively bipartisan. Like this isn’t a Democrat Republican thing. Like the you know they there are very few issues right now where the two parties could come together and say, yeah, this this this makes some sense from a privacy or consumer protection perspective, and and you know we’re really not looking at it from from a particular harm perspective, but you know, hey, let’s let’s raise a few bucks. You know, as New Jersey is trying to do here, and again, California I think came at it from a different, really more fundamental privacy perspective. You know, Tom Kemp, who is now the executive director of the California Privacy Protection Agency, was actually a co-author. I mean, behind the scenes of the Delete Act. He has been a long time consumer privacy advocate, and and really wants to align U.S. law with like European law and the fundamental right to privacy. So there’s again there’s a there’s a perspective that I think that Tom and other California advocates have taken over the years to really kind of philosophically align privacy with with the world, whereas others are like New Jersey are maybe coming at it from a very different angle. But again, there’s not much friction. There’s no lobbying dollar. Not a lot of lobbying dollars coming at it. And you know, unfortunately, that that’s really what’s needed here to to create more balance in some of these laws from from being enacted.

Justin Daniels 21:23

Speaking of California, how does the California Delete Act fit into the broader trend of state data broker regulation, and do you expect other states to follow a similar model?

Ben Isaacson 21:34

Yeah, I think it. As I think I hinted at, like it feels like the Delete Act is now the blueprint for the country, and there’s obviously been talk on the federal level as well since the California Duily Act came into effect. Is hey, you know, back when you know kind of the Telephone Consumer Protection Act was was being enforced, you know, the FTC came up with you know the the Do Not Call registry, and you know it’s been enacted for 20 plus years now, and it works very well. Why can’t we do the same thing for data brokers and and and the whole country and preempt these these state laws? Now that I think that’s going to come to a head. You know, obviously this this legislator, you know, this this session of Congress and this body of Congress is is not that motivated to get anything done. It seems like, but but again, like we’re seeing this blueprint with California and Connecticut now. There are many other states in New York. You know, I’ve heard Nebraska. Other states are now closely looking at a similar blueprint. So I suspect we’ll see you know a dozen of these delete acts get passed in the next you know year or two before Congress really gets their act together to really look at a federal solution. But ultimately, I think there kind of has to be some sort of federal solution here to preempt this because operationally, just you know, it’s going to get unwieldy for for companies to to really be in that space, especially if that data collector definition gets added on. You know, so New Jersey really is able to maintain that data collector definition, and that other states see that that’s enforceable. And and again, the revenue side of that could be significant, especially with enforcement penalties. That that that blueprint could extend very quickly to other states that are just looking for, again, easy revenue from companies that aren’t able to really defend against these kinds of you know overburdensome regulations.

Jodi Daniels 23:33

With multiple different data broker laws right now and slightly different definitions, what do you recommend companies do to start and figure out, are they a data broker?

Ben Isaacson 23:45

I don’t. I don’t want to sound crass, but but get a legal opinion. I think is is the simple answer here because it really varies significantly depending on the nature of your business. The and really the the most important thing is the nature of your commercial terms, in terms of what, how you’re licensing data from and to different companies, and you know even California has very rigid guardrails on who can be deemed a service provider, and you know again, if you’re in the ad tech industry, you know like you can’t be a service provider pretty much under under most California you know scenarios. But again, you might be able to split California from other states and like terms of your contracts. So it really requires close scrutiny of commercial agreements for all types of data use, and then the monetization of that data. If there’s if there is a sale taking place or a license taking place, you know what those licenses are. You know, and it’s not easy to geo fence California or New Jersey or these other states just by like IP address or things like that because. You know those are those are you know possible attempts to comply, but they’re not solutions legally. So you know you have to kind of look at that risk and say, okay, well we’re we’re trying to comply just by geo fencing in California or one of these other states, but doesn’t necessarily mean you’re actually in compliance. So it it requires a lot of legal scrutiny. Unfortunately, it’s getting more complex, and that’s the simplest answer.

Jodi Daniels 25:25

I appreciate you sharing. It is complicated.

Justin Daniels 25:29

So, what should companies who just buy data from data brokers be thinking or doing? Is there an impact to them?

Ben Isaacson 25:36

Yeah, this is this is an an increasingly novel issue around down, like what I’ll call downstream liability for licensors, licensees of licenser data that now needs an enhanced like layer of compliance, and so this delete act in particular is really new because again, it’s only coming into effect really august 1, and in you know 15 days, where if you’re licensing data from a California data broker, they must apply that drop you know deletion data in advance of you really you know using that data, and especially you know again if you’re if you’re reselling as well, which I’ll get into a sec, but like the the the most important thing is that you know that that like typical thing that you have in your contract that says you must comply with the law. Very simple, everybody has it. But in this world now, where there’s accountability, and there will be audits on that accountability as well, you know, you don’t want to have that data in your database if, again, that consumer has expressly said, “I I don’t want to be sold, and and again, the liabilities doesn’t necessarily mean that California is going to come after the licensee because the license swear didn’t apply it, but there might be uses by that licensee that get implicated that that could create liability under CCPA and other other laws as well that you know may may require you know may investigation by the CPPA or other other attorney general or others. So the answer is you know really button up your commercial terms with all of your data licensors, and very very closely scrutinize the licensing relationships you might have with with any sort of ad tech companies that you might be working with, because this sort of you know push pull on on just data licensing in general is going to be you know highly scrutinized, and the penalties. I just have to state very very clearly the penalties for non enforcement in California are bankruptcy level statutory level statutory penalties that are bankruptcy level penalties because it’s $200 per day per violation, so if you have you know again there are 300,000 individuals now on this drop you know deletion list, so if you combine you know $300 300 with $200, that’s you know a significant amount of money just for one violation, and you compound that over days and weeks or months, and you can you can do the math. You’re not really in a position to pay those fines, unless you’re Google or some you know some mega mega company. So any of the data brokers or data licensing you know companies in the ad tech space really are are in a bad position where if they if they don’t like really button things up, they could face statutory penalties that put them out of business.

Jodi Daniels 28:43

And I want to add to anyone listening. So this, I think, is an opportunity for privacy and legal team. So anyone listening who’s familiar with the California Delete Act, to talk to your sales teams and your marketing teams and whomever is purchasing that data, they might not be aware. And when what I think is going to happen is over time, on day one, it’s not going to be a massive drop all at once. You might not experience all 300,000, but that pool of data is going to continue to increase. And in terms of the number of people who want to opt out, which means you will start to feel the impact. Those teams will see a decrease, and they might appreciate the partnership to be able to say, “Here’s what’s happening in the industry, and here’s how this might affect the business. To give the business some time of how they might need to adjust if they can’t always rely on all the data that they’re licensing and purchasing.

Justin Daniels 29:35

Yeah.

Jodi Daniels 29:36

And with that being said, we always like to ask each guest, knowing what you know around privacy and security, what is your best personal tip?

Ben Isaacson 29:49

I mean, if you’re like to say it, if you’re a California resident, go register with the drop. I think it’s just go increase my numbers. I mean, I don’t. Look. Again, from a personal privacy perspective, this is the most powerful mechanism that’s been introduced in this country. With, I mean, again, do not call was helpful, but again, there’s sort of loopholes around that, around like consent, for example, and so you can still get telemarketing calls. And again, the enforcement, even in a private right of action, hasn’t been wonderful. So you still get calls, right? You still get texts. You still, you know, that sort of thing still happens. With this deletion mechanism for California, there’s no consent override. Like once you’re on that list, you’re on it forever. You’re not. I mean, at least unless they verify your residency again. But you know, as long as you’re a California resident, there’s nothing these data brokers can do to put you back on that list. So it is a very powerful way to protect your privacy, and and you’d be surprised again, knowing what I know, like just how many companies this really implicates. And you know, again, from a from a personal perspective, you know, there’s one thing that I think people the misnomer I think, is that you shouldn’t unsubscribe from commercial email. But in all of my years of working with emailers and understanding email service writers and how they the mechanics of it, it really works well. So you know, don’t let it just go to the spam folder. Just unsubscribe. Don’t let it clog up your promotions box. Just unsubscribe. That that that’s really the simple approach that I’ve you know always advocated to people.

Jodi Daniels 31:26

Those are two great tips. I wish I lived in California, but I have no rights here in Georgia.

Justin Daniels 31:32

So Ben, what do you like to do for fun when you’re not so engrossed in all this privacy advocacy that you do?

Ben Isaacson 31:40

It’s hard to say one thing, but I guess you know I’m a I’m a I guess I’ll say like I’m a big Grateful Dead Head and Jam Band fan, always have been since I was like a teenager. So I’m like seeing you know Grateful Dead cover bands and every sort of version of you know band that’s come with them. I just saw Fish for two nights last week, so it’s you know that’s that’s my that’s my favorite enjoyment,

Jodi Daniels 32:01

and and then people like to connect with you or learn more or follow along on all things data brokers and other fun privacy topics. Where can they find you?

Ben Isaacson 32:11

Yeah, I’m pretty active on LinkedIn. I try and post any thoughts and feelings and ideas and anything that comes to mind that I think are relevant here as much as possible. So that’s definitely the best place. You know, our website is inhouseprivacy.com. We do post a lot of blogs and things on there as well.

Jodi Daniels 32:28

Well, we are so grateful that you came today to share with us. So thank you again.

Ben Isaacson 32:33

Yeah, thank you for having me. It’s been great.

Outro 32:39

Thanks for listening to the She Said Privacy/He Said Security podcast. If you haven’t already, be sure to click subscribe to get future episodes and check us out on LinkedIn. See you next time.

Privacy doesn’t have to be complicated.