Artwork

Content provided by Debra J. Farber (Shifting Privacy Left). All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Debra J. Farber (Shifting Privacy Left) or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

S2E5 - What's New in Privacy-by-Design with R. Jason Cronk (IOPD)

58:32
 
Share
 

Manage episode 421035590 series 3407760
Content provided by Debra J. Farber (Shifting Privacy Left). All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Debra J. Farber (Shifting Privacy Left) or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

R. Jason Cronk is the Founder of the Institute of Operational Privacy Design (IOPD) and CEO of Enterprivacy Consulting Group, as well as the author of Strategic Privacy by Design. I recently caught up with Jason at the annual Privacy Law Salon event and had a conversation about the socio-technical challenges of privacy, different privacy-by-design frameworks that he’s worked on, and his thoughts on some hot topics in the web privacy space.
---------
Thank you to our sponsor, Privado, the developer-friendly privacy platform
---------

We start off discussing updates to Strategic Privacy by Design, now in it's 2nd edition. We chat about the brand new ISO 31700 Privacy by Design for Consumer Goods and Services standard and consensus process and compare it to the NIST Privacy Framework, IEEE 7002 Standard for Data Privacy, and Jason's work with the Institute of Operational Privacy Design (IOPD) and it's newly-published Design Process Standard v1.

Jason and I also explore risk tolerance through the lens of privacy using FAIR. There’s a lot of room for subjective interpretation, particularly of non-monetary harm, and Jason provides many thought-provoking examples of how this plays out in our society. We round out our conversation by talking about the challenges of Global Privacy Control (GPC) and what deceptive design strategies to look out for.

Topics Covered:

  • Why we should think of privacy beyond "digital privacy"
  • What readers can expect from Jason’s book, Strategic Privacy by Design, and what’s included in the 2nd edition
  • IOPD’s B2B third-party privacy audit
  • Why you should leverage the FAIR quantitative risk analysis model to define address effective privacy risk management programs
  • The NIST Privacy Framework and developments of its Privacy Workforce Working Group
  • Dark patterns & why just asking the wrong question can be a privacy harm (interrogation)
  • How there are 15 privacy harms & only 1 of them is about security

Resources Mentioned:

Guest Info:

Send us a Text Message.

Privado.ai
Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans.
Shifting Privacy Left Media
Where privacy engineers gather, share, & learn
Buzzsprout - Launch your podcast
Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.
Copyright © 2022 - 2024 Principled LLC. All rights reserved.

  continue reading

Chapters

1. S2E5 - What's New in Privacy-by-Design with R. Jason Cronk (IOPD) (00:00:00)

2. What are the "socio-technical challenges of privacy" and how can we overcome them? (00:02:37)

3. Why we should think of privacy beyond "digital privacy." (00:03:34)

4. Jason discusses his book, Strategic Privacy by Design and what's included in the updated 2nd edition (00:05:42)

5. ISO 31700 Privacy by Design Standard for Consumer Goods and Services (00:12:49)

6. Jason describes the Institute of Operational Privacy Design (IOPD) and it's newly-published Design Process Standard v1. (00:21:04)

7. IEEE 7002 Standard for Data Privacy Process (00:23:31)

8. Leveraging the FAIR quantitative risk analysis model to define the necessary building blocks for implementing effective privacy risk management programs (00:30:13)

9. Jason discusses The NIST Privacy Framework and The NIST Privacy Workforce Working Group developments (00:37:48)

10. Hot topics in web privacy: do not sell; global privacy control (GPC) (00:41:56)

11. Discussing dark patterns and why just asking the wrong question can be a privacy harm (interrogation) (00:47:39)

12. Discussing data minimization and "data devaluation" (00:54:03)

13. How there are 15 privacy harms, and only 1 of them is about security (00:55:58)

63 episodes

Artwork
iconShare
 
Manage episode 421035590 series 3407760
Content provided by Debra J. Farber (Shifting Privacy Left). All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Debra J. Farber (Shifting Privacy Left) or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

R. Jason Cronk is the Founder of the Institute of Operational Privacy Design (IOPD) and CEO of Enterprivacy Consulting Group, as well as the author of Strategic Privacy by Design. I recently caught up with Jason at the annual Privacy Law Salon event and had a conversation about the socio-technical challenges of privacy, different privacy-by-design frameworks that he’s worked on, and his thoughts on some hot topics in the web privacy space.
---------
Thank you to our sponsor, Privado, the developer-friendly privacy platform
---------

We start off discussing updates to Strategic Privacy by Design, now in it's 2nd edition. We chat about the brand new ISO 31700 Privacy by Design for Consumer Goods and Services standard and consensus process and compare it to the NIST Privacy Framework, IEEE 7002 Standard for Data Privacy, and Jason's work with the Institute of Operational Privacy Design (IOPD) and it's newly-published Design Process Standard v1.

Jason and I also explore risk tolerance through the lens of privacy using FAIR. There’s a lot of room for subjective interpretation, particularly of non-monetary harm, and Jason provides many thought-provoking examples of how this plays out in our society. We round out our conversation by talking about the challenges of Global Privacy Control (GPC) and what deceptive design strategies to look out for.

Topics Covered:

  • Why we should think of privacy beyond "digital privacy"
  • What readers can expect from Jason’s book, Strategic Privacy by Design, and what’s included in the 2nd edition
  • IOPD’s B2B third-party privacy audit
  • Why you should leverage the FAIR quantitative risk analysis model to define address effective privacy risk management programs
  • The NIST Privacy Framework and developments of its Privacy Workforce Working Group
  • Dark patterns & why just asking the wrong question can be a privacy harm (interrogation)
  • How there are 15 privacy harms & only 1 of them is about security

Resources Mentioned:

Guest Info:

Send us a Text Message.

Privado.ai
Privacy assurance at the speed of product development. Get instant visibility w/ privacy code scans.
Shifting Privacy Left Media
Where privacy engineers gather, share, & learn
Buzzsprout - Launch your podcast
Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.
Copyright © 2022 - 2024 Principled LLC. All rights reserved.

  continue reading

Chapters

1. S2E5 - What's New in Privacy-by-Design with R. Jason Cronk (IOPD) (00:00:00)

2. What are the "socio-technical challenges of privacy" and how can we overcome them? (00:02:37)

3. Why we should think of privacy beyond "digital privacy." (00:03:34)

4. Jason discusses his book, Strategic Privacy by Design and what's included in the updated 2nd edition (00:05:42)

5. ISO 31700 Privacy by Design Standard for Consumer Goods and Services (00:12:49)

6. Jason describes the Institute of Operational Privacy Design (IOPD) and it's newly-published Design Process Standard v1. (00:21:04)

7. IEEE 7002 Standard for Data Privacy Process (00:23:31)

8. Leveraging the FAIR quantitative risk analysis model to define the necessary building blocks for implementing effective privacy risk management programs (00:30:13)

9. Jason discusses The NIST Privacy Framework and The NIST Privacy Workforce Working Group developments (00:37:48)

10. Hot topics in web privacy: do not sell; global privacy control (GPC) (00:41:56)

11. Discussing dark patterns and why just asking the wrong question can be a privacy harm (interrogation) (00:47:39)

12. Discussing data minimization and "data devaluation" (00:54:03)

13. How there are 15 privacy harms, and only 1 of them is about security (00:55:58)

63 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide