How to comply with new rules for privacy assessments, automated decisionmaking, & cybersecurity audits

Thank you!
Please check your email to view the guide.

Building a privacy engineering function

October 4, 2023
5
 mins read
Vaibhav Portrait
Vaibhav Antil
CEO & Co-Founder
Building a privacy engineering function

Building a Privacy Engineering Function goes beyond regulatory compliance—it's about fostering trust with customers. With businesses collecting more data than ever, how do we keep private details safe while still offering new and exciting products?

To help answer this, we've gathered thoughts from top industry voices: Nishant Bhajaria, Author of 'Data Privacy: A Runbook for Engineers'; Mira Olson from Uber; Pramod Raghavendran at Coinbase; Ellen Nadeau from Cruise; and Aaron Weller of HP. We've consolidated their insights into a singular narrative, offering a look inside building and scaling privacy engineering teams. Dive in.

What does privacy engineering mean to you? In terms of definitions or in terms of the function you serve in your company? What problem are you solving?

Privacy engineering is a multifaceted domain that primarily centers around the identification and mitigation of privacy risks, ensuring that businesses operate within the parameters of trust and legality. The term itself can vary in its interpretation across the spectrum. 

At one end, privacy engineering involves collaboration with engineering and product teams.

This facet primarily involves offering consultations, reviewing new features, processing data, and actively guiding the direction of privacy in products and services. It's about being at the forefront of change, understanding the evolving market, and ensuring that privacy standards are met.

On the other end of the spectrum, we see dedicated privacy engineers working diligently to design solutions that further the cause of privacy. 

This team consists of specialized engineers who focus on developing the tools and platforms necessary for the broader privacy objectives. Working in tandem with legal and advisory teams, this group has the autonomy to drive initiatives in data discovery, tagging, and policy enforcement.

However, all privacy engineers place a significant emphasis on anticipating future needs, ensuring that the tools and systems are adaptable and can accommodate changes in compliance and regulations. This forward-thinking approach aims to build a flexible engineering platform that can swiftly adapt to new privacy laws and challenges without undergoing exhaustive modifications, as seen in past instances like the GDPR.

What is your contribution as a privacy engineer? 

We work closely with both legal and engineering stakeholders, both internal and external. My role is to understand the legal risk compliance requirements and internal policies to ensure that these are aligned with the tools we're building. We identify privacy gaps as our engineers develop new features and products. Our collaboration with them is crucial in driving privacy forward, ensuring that privacy is engineered right into the design. We serve as the "connective tissue" between legal compliance and the technical implementation of that compliance.

Does the role of a privacy engineer vary based on the privacy posture of the company, the type of industry the company operates in or its lifecycle? 

Companies have different perspectives on privacy. First, some see it merely as a compliance checkbox. These businesses typically have teams focused on advisory roles, ensuring the necessary boxes are ticked, running DPIAs, generating RoPAs, and calling it a day. 

On the other hand, there are companies that view privacy as a means to gain customer trust or even as a unique selling point. This perspective encourages a more proactive approach: investing in tech, developing engineering solutions, and scaling privacy more holistically. 

The company's industry and maturity level also play a role. For example, if you're in the health or child product sectors, privacy is automatically a top priority. But for many businesses, the journey starts with a compliance-focused view, gradually evolving into a more holistic take on privacy as they mature.

How have you built techniques in communication methodologies and metrics in privacy engineering to make the case that what you're doing is actually working? And that results are actually showing up?

To effectively communicate the efficacy of privacy engineering, both quantitative and qualitative measures are crucial. One can actively collaborate with internal research teams to gather feedback on customer perceptions of privacy. Integrating privacy-focused questions into customer research can yield actionable insights into their preferences and concerns. Furthermore, the way the marketing team highlights privacy messages can provide valuable indicators of what customers prioritize, underscoring the point that beyond mere compliance, customers seek a robust trust relationship with the company's offerings.

By employing privacy-enhancing technologies, organizations can maximize the potential of data already in their possession without undermining its integrity. Another promising strategy he points out is the "seed funding" approach. Here, business segments encountering specific challenges contribute seed funding toward crafting a solution. The resulting platform or tool isn't just a remedy for that one segment but can be adapted and scaled to meet the needs of other teams. This collective investment means each team gains from the broader pool of solutions, benefiting the organization as a whole and reinforcing the value of privacy engineering initiatives.

How do you make an argument to invest in privacy in large enterprises? 

To highlight privacy's role in building trust, we use a customer-centric approach. We've developed a "reasonable customer" persona, representing an average individual who values data protection but has a basic understanding of privacy. This persona ensures that privacy remains at the forefront of product discussions, balancing it with revenue objectives. Another tactic we employ is considering potential negative press, especially from prominent sources like the Wall Street Journal, that a product launch might attract. This strategy heightens stakeholder awareness of privacy concerns, positioning it as a valuable investment rather than just an expense or obstacle. These methods effectively underscore the importance of privacy in our business decisions.

How do you fight the internal resistance when pushing to implement privacy initiatives?

To cultivate a privacy-centric culture, it's essential to lay the foundation through education, which includes securing buy-in from top management and establishing privacy principles. When encountering resistance to privacy discussions, it's crucial to pinpoint a clear risk owner to ensure accountability and a more critical viewpoint. 

Identifying the right stakeholders is key, underscoring that privacy is a shared responsibility and not just the domain of a specific team. Gaining the trust of business stakeholders requires diplomacy, understanding their objectives, and highlighting privacy's importance in achieving those goals. It's critical to be perceived as a partner rather than a barrier. 

How do you build a privacy engineering team — what skills do you look at, and what is a composition that works?

In privacy, three foundational skills are essential: privacy domain expertise, given the constantly changing global regulations; program management, to efficiently lead diverse teams towards common objectives; and technical knowledge about data processing and the wider tech ecosystem.

Differentiating between advisory and engineering roles, the former emphasizes domain expertise and program management, while the latter focuses on technical skills along with domain knowledge.

Beyond these hard skills, two crucial soft skills are navigating ambiguity and effective communication. Privacy professionals often face unclear situations, whether from evolving regulations or keeping pace with innovative product developments. The ability to clarify such scenarios is invaluable. Moreover, they must interact with various stakeholders, from engineers to legal teams, and must distill complex privacy concepts into clear, actionable insights.

In conclusion, while technical and domain expertise are foundational, it's the soft skills, particularly handling ambiguity and communicating effectively, that make a privacy professional stand out. This mix of skills ensures both compliance and a comprehensive, privacy-conscious approach.

How do you, as a privacy engineer, interact with legal? And how do you make the case for privacy engineering as a distinct function?

Engaging with the legal team in privacy engineering presents both alignment and challenges. Both the privacy engineering and legal teams strive to enable the business while ensuring adherence to privacy norms. Most legal professionals aim not just to restrict but to empower the business to achieve objectives. Similarly, privacy engineers work to facilitate this without violating privacy rules.

However, their approaches can differ. The legal team tends to be more cautious, focusing on risk and compliance, while privacy engineers, connected with product development, often seek innovative solutions, pushing the boundaries. This difference establishes a checks-and-balances system, crucial in privacy's gray areas of judgment and interpretation.

In building a relationship with the legal team, it's vital to recognize both the mutual goals and these inherent differences. Trust and a healthy tension between the teams are essential, ensuring a balance between innovation and compliance.

How do you prove that the investments in privacy are actually working?

Understanding our customers' perceptions of privacy is vital. The top priority is to continuously assess their views on our privacy policies and practices.

Collaboration with the research team is key. Their expertise ensures we gather accurate data. While we privacy engineers bring privacy-related questions, the research team uncovers deeper nuances about customer trust and its tangible measures in a privacy context.

We not only survey customers but also monitor their system interactions, especially regarding data requests. Ensuring easy channels for such requests and meeting our service level objectives (SLOs) boosts their trust. The efficiency in handling these requests indicates our alignment with customer privacy expectations.

Feedback, both direct from research and indirect from interactions, refines our privacy practices to be customer-focused.

Embedding promises, especially in advertising, sets trust benchmarks. By making clear commitments, we can assess our products and technologies against customer values. These promises, while adaptive to changing data landscapes and regulations, ensure deliberate alignment with customer perspectives and business goals.

Measuring trust is challenging. Using metrics, targeted surveys, and feedback, especially negative, offers insights into trust issues. Our customer service teams, through direct customer interactions, also highlight concerns. By utilizing this feedback, we address trust issues and adjust our strategies.

In summary, a mix of clear promises, continuous assessment, and understanding customer sentiment lays the foundation for building and sustaining trust.

What new technology fascinates you as a privacy engineer?

The integration of AI technology into modern services has heightened concerns about personal data privacy. AI systems rely on vast datasets, often comprising personal user information. This not only poses questions about data storage and processing but also its permanence. Despite any current efforts to delete or withhold information, previously shared data may persist in databases and be utilized by AI systems. The widespread nature of digital platforms suggests that all our online interactions form a lasting digital legacy.

Moreover, privacy regulations like GDPR introduce the "right to erasure," permitting individuals to request the deletion of their personal data. But AI models, once trained, make it nearly impossible to remove specific data points or gauge their influence, challenging the efficacy of this right.

The landscape of the "free" internet is also shifting, with increasing content behind paywalls. While not solely due to privacy concerns, they play a pivotal role. Business models are evolving, and traditional views of "free" services, where users "pay" with their data, are being reassessed as regulations tighten.

With automation taking on roles once occupied by humans, the nature of data exchange is transforming. Data might persist, serving secondary purposes beyond its initial intent, such as targeted advertising. This change underscores the importance of consent, transparency, and data minimization. Are users fully aware of how their data is being used in automated systems? There's a balance to strike between data-driven personalization and user privacy. As automation grows, ensuring that systems are not just efficient but also ethical becomes paramount.

Considering the data's lifespan collected by automated systems is crucial. Historically, humans could forget, rendering certain information transient. Should systems adopt a similar approach, deleting data after a set period?

In this evolving landscape, it's not enough to emulate human efficiency. We must also incorporate human empathy, values, and discretion as automation and AI redefine privacy norms.

How do you make a case for where privacy engineering lives within the company?

In an effective organizational model, the team's integration within the engineering organization's planning framework stands out as a strength. This integrated approach allows for continuous engagement with engineering teams on priorities, emphasizing the importance of proactive privacy work. Being embedded within the same unit ensures streamlined communication and alignment, leading to regular interactions throughout quarterly plans. The addition of a legal perspective to this structure further bolsters the comprehensive nature of their privacy initiatives.

Moreover, a reporting structure that connects to the chief data officer ensures alignment with broader data governance strategies. This structure, combined with a close relationship with a central privacy team, brings together professionals addressing similar challenges, albeit from different perspectives.

It is beneficial for such teams to maintain close ties with product and engineering, given that these roles often handle vast amounts of organizational data. Such positioning naturally fosters a privacy-centric culture within the entity. Another strategic alignment is with the security organization, tapping into synergies like tool utilization and combined advisory strategies. However, placing privacy in an isolated role might not be as effective.

Historically, technical privacy roles have often oscillated between legal and engineering alignments. Regardless of their organizational position, having a connection to the engineering security department has proven invaluable. With this link, the team benefits from the robust backing of security engineering. Given that privacy is still maturing compared to security in many organizations, such a connection ensures that the privacy team is recognized as a valuable partner rather than merely a compliance hurdle.

Conclusion

Privacy engineering plays a vital role in maintaining data integrity and trust. As technology evolves, the importance of effectively managing and protecting data becomes paramount. The insights shared here underscore the need for robust strategies and practices in this domain. The road ahead demands vigilance, adaptability, and a commitment to safeguarding user privacy.

Industry insights you won’t delete. Delivered to your inbox.

Get regular updates from Privado AI

Request free website audit

Request Privado AI demo

Vaibhav Antil
Vaibhav Antil
CEO & Co-Founder

Get regular updates from Privado AI

Request free website audit

Request Privado AI demo

Continue Reading