Kirsten Daru0:02
All right, so my name is Kirsten. The things I'm going to say here today are my own views, just like everyone else. But I am so honored to be here to talk to you about privacy and risk councils, which I think are so critical for any modern organization to really harness the value and the power of data and new technologies like AI, both responsibly and strategically.
So quick background on me. After law school, I was a litigator for about seven years before landing that coveted first in-house job. I was the first privacy counsel at Electronic Arts. That was in 2008. And in the years that followed, as we all know, privacy blew up. I got to build a program and an international team, and I was just fascinated to bear witness to this tectonic, historic shift in law, technology, and policy.
Then after 11 years at Electronic Arts, I landed my first General Counsel role. And as a General Counsel, I had to deal with a lot more stuff than privacy. I was dealing with contracts, financing deals, partnerships, antitrust, employment, IP prosecution, patent litigation, oh my gosh. And I had this revelation one day in my first General Counsel role that literally never occurred to me during the 11 years that I was the Chief Privacy Officer at Electronic Arts. And that was this: that privacy, and as we all know now AI too, they are the most challenging legal disciplines in existence, hands down. And it's because they're more about just the law. For most things, you take the facts and then you apply the law. And if the facts fit in the law, then you're good to go. But not so with these, because these have just as much to do with law as they do with ethics, integrity, morality, trust. As we've been talking about a lot, trust of any company's most important stakeholders: your employees, your customers, your investors, your shareholders, and your partners. And at the end of the day, privacy and AI really become about changing hearts and minds. You have to basically convince people to forgo opportunity and ideas and revenue-generating opportunities just because it's the right thing to do.
And what's even more challenging is making sure that everyone in your organization is making decisions that are consistent, because as we all know, it only takes one wrong move before it all comes crashing down. And the other thing that's very challenging for a privacy, a policy, a legal person, an IT person when you're dealing with these things is that unlocking the potential and the value of AI and data requires a lot of insight that no one privacy lawyer, IT pro expert, or a team of those people can do on their own. You need a lot of perspective. So you also have to have all this perspective to make sure that what you're doing actually makes sense for your company as the law, the technology, and consumer expectations continue to evolve on like a daily basis.
So it occurred to me that perhaps we should let other people into the fold here. And I came to this realization in two pivotal moments. I don't know if anyone here has had the same kind of experience, but when I started out, my team and I, we would write policies. They were so good. They were policies about privacy, personalization, monetization, oh my goodness, marketing, you name it. They were amazing. And once we got around the table and we perfected them, we posted them on the internet and we went forth and enforced them throughout the company. And it actually took me longer than you would think for someone to actually think to ask me the question: who makes these policies and who says I have to follow them? And I realized it wasn't a very compelling answer to say me and me.
And then second, you know, this just happened kind of organically. But in any organization, there are people that you just gravitate towards, you tend to like work with more than others, folks that tend to be a little bit more like-minded. I don't know, for me it was always CorpCom, our head of CorpCom and I were like attached to the hip, head of PR, the CISO, some engineering leaders, some leaders in marketing. And whenever I had those kinds of situations where I had this really hairy problem and I couldn't get this person to get to the right place no matter how hard I tried, I would just bring in my merry band of allies who had complimentary business and reputational insights to get them to the right place. And guess what? It worked every single time. So again, that's kind of how I came to realize like I've got to have more. I need it can't just be me being the arbiter of what's creepy, what's okay, what's not okay, what's too risky, what's not risky enough. And so I thought, okay, I need to have like some sort of a counsel. I need a privacy council.
But a bunch of people in a room together are not going to move the ball forward without governance. You're just going to end up with like a chaos council, and believe me, that is the last thing I needed in my life at that time. So I thought, okay, what do we need for a successful privacy council? And I think it's three things: you need a definition and a governance framework, you need the right people in the room, and you need them to have the right focus. Well, that sounds easy enough. All right, let's get started. This is my first definition of a privacy council. Here we go: a governance body charged with the development of privacy-related policies to ensure legal obligations are met and risk is minimized throughout the enterprise. Oh my God, that sounds so good. Lots of big words in there. And I thought, what would be better of a governance model than the one that I use and I geek out over all the time? It's like NIST. Let's use NIST. Let's have this group of people help me do my job, and it's going to make my job so much easier. My team's going to be so happy. We'll talk about data architectures and controls, and oh my God, I love it. But guess what? I got no takers for this council.
That's not to say that this isn't important. I mean, this is what we live and breathe by. This is what we live to do. This is how we measure the health and maturity of our programs. This is what we use to present to the board and our auditors and dazzle them with how much progress we've made. But for most normal people, apparently it is very, very boring. So what I needed was to harness the perspective and the points of view and the strength and the allyship of other stakeholders within the company, but I had to make it exciting. I had to make it engaging for them, and still fit it within a governance model, but without calling it governance. So I tried it again and I came up with this: how about an exclusive team of cross-functional leaders charged with making strategic decisions to unleash the power and value of data? And by the way, this works exactly the same for AI, and I've used it for both, so just data and AI, while maintaining trust and minimizing risk. Okay, I got some interest. Fine.
And then in terms of a governance model, what's worked for me is always a principles-first approach. I think Shannon nailed it, she mentioned it earlier actually. But what I'm talking about is one page with the definition and your mission of your council at the top, and then a list of bulleted principles that are inspiring and that get people excited. You know, we use data and we use AI to delight our customers, to give them the best possible experience, to optimize their experience with their product, to optimize our business operations, make our lives easier, always consistent with the reasonable expectations of our customers. You know, we're going to say what we do and we're going to do what we say. I mean, shout out to Jay-Z, thank you very much. Like, who doesn't want to be a part of a team that wants to do amazing things for your company while also doing something good for society?
So we've got this definition and we've got this kind of very concise, brief, exciting, principles-first framework. And then the question then becomes: who do you invite to be part of this? And you do need, and this is going to change based on the organization, but you need folks, leaders from throughout your organization who have a stake in this and that can apply those principles in a rational, reasonable way. So one team I always make sure I have in the room is customer support. A lot of times they get overlooked, but there is no team that has a better sense of the sentiment, the perspectives, and needs of your customer base than the people talking to them on the phone every single day. And then you need your CISO, your head of CorpCom and PR, because they have such good insight in terms of reputational risk. Marketing, because they're the ones that are going to be touting the competitive differentiation that you're able to accomplish, they're also a huge utilizer of data. You need your product teams, you need your engineering leaders, and you need some legal and compliance and policy folks.
And a lot of people say, well, my company is so big, I don't have... I mean, I'd have my room would be like this full. But you can have, I'd say, a dozen members of this team. That way, if you find a dozen leaders, great. And if your company is gigantic, then you can have multiple privacy councils, right? Depending on each of the business units, and they can all kind of feed into an uber council that kind of helps make all of the councils a little bit consistent. But then you've got all the stakeholders that you need to help solve problems and bring things to the table.
So then the question becomes, okay, what are these people you get in a room, what are they going to do? And again, for me, this is a place I can bring my policies, my really good policies that my team writes, I can take it to them and actually get feedback, you know, and actually take it and really synthesize it. Every single meeting I have a brainstorming session where people are able to raise ideas they have in terms of like AI or privacy initiatives, concerns, things they think might be problematic, so we can get those out on the table. The people get so invested and excited about being on this council that they actually become evangelists, and they're asking their teams beforehand what they think, so they're bringing these things to the table that otherwise wouldn't kind of bubble up to the surface. We vet new data processing proposals. Those guys with the hairy problems that I used to have to deal with by myself, I'd have them come to the council, pitch it there. We track progress of the top priority initiatives. And ultimately, at the end of the day, when you have a really high-functioning privacy council within your organization, it really elevates the role of privacy and AI within your organization.
And pretty key idea number one is that open forums drive alignment. You know, this privacy council, it's not about governance and NIST and ISOs. It's about bringing really smart, talented leaders together to openly share their thoughts and gain alignment according to a framework. If you have a philosophy that everybody kind of digests and understands and is the lens through which they view all new data processing initiatives and AI, then you've got the governance you need. And you're going to end up with a group of advocates and allies that are going to help you on your mission. And also, the cross-functional nature of this is going to get ideas to the table that otherwise wouldn't surface. It's going to identify potential risks and areas for improvement, and again, according to a simple framework. Because what I've seen also happen is when people get really excited about something like data or AI, it's kind of the hot thing right now, of course. If you spend a lot of time trying to put together a really complex governance model, the train's going to leave the station without you on it, and AI initiatives are going to happen without your oversight. It's going to be too late. So this helps you get ahead of the game, ahead of the curve, know what's going on in the company, and be able to kind of apply this framework.
And then I think this one is actually the most important, but also the most practically difficult, which is embracing dissent. Because by embracing dissent, you make sure that your program is actually serving the best interest of your company. As we mentioned, the law, technology, and consumer expectations continue to change. I remember back when I was at my desk writing all those policies, and someone would actually come to my desk and have the gall to complain to me about them. Like, I don't like this, I don't want to do this, this is not okay. And I'd get so annoyed. And then it occurred to me one day that, oh my gosh, these are the people that are reading my policies. These people care. They're engaged. They actually care enough to talk to me, to complain about them. Like, I want these people on my team, right? And when you embrace their feedback, you're like, yes. Because these programs are ever-changing, and unless you are listening to well-meaning and reasonable dissenting feedback, you're never going to be confident that your program is actually moving your company in the right direction.
So at the end of the day, you've got a good privacy council that's operating, and you end up with a complete mindset shift and an army of privacy evangelists within the company. I finally had allies and stakeholders who had ideas, perspectives, and experiences that I and my team lacked on our own. It elevated the privacy function within our organization. It helped ensure privacy was finally woven within its culture. It made my life easier. You know what the most profound thing was? Just organically, people started asking themselves, without me or anybody in the room from my team, well, I know we can do this, but should we? And when that started happening, I knew that this was a massively tectonic shift and exactly what I'd been working so hard to try to achieve for so long.
So in conclusion, clearly the landscape of governance these days requires more than just compliance. And yes, we cannot ignore NIST, we cannot ignore those frameworks. We take the fruits of these councils and we fit them within them. And we need to have a shift of mindset and a proactive approach to change. It lies in recognizing that change is really the only constant and that evolution is going to be inherent within it. And honestly, the biggest key to success is a simple framework that gives opportunities for leaders within your company to meaningfully contribute on their own terms, to contribute meaningfully to your strategic initiatives. Because at the end of the day, privacy and AI are very hard, and we don't have to do it by ourselves. Thank you very much.