Privacy Lawls with Donata

How to perform vendor privacy due diligence (Guest: Richy Glassberg, CEO at SafeGuard Privacy)

What is vendor due diligence? Why is it important? What do most people get wrong? What are best practices? What do you do if a vendor refuses?

We had on Richy Glassberg, CEO at SafeGuard Privacy to answer these questions and more. Plus, he shares some of the biggest red flags he’s ever seen in his career when it comes to vendor due diligence.

You don’t want to miss this awesome and insightful episode!

Show Transcript

[00:00:00] Hello, and welcome to episode 36 of Privacy Lawls, where I, Donata Stroink-Skillrud, speak with amazing privacy professionals, and we have some laughs along the way as well. Today, I’ll be speaking with Richy Glassberg about performing vendor privacy due diligence. Richy has led seven startups in his 25-year digital media career.

He now serves as co-founder and CEO of SafeGuard Privacy. He was previously the CEO, COO of Medialets, was a founding member of CNN.com, the CEO founder of Phase 2 Media, and a co-founder of the IAB. Richy, thank you so much for joining me on the podcast today. Donata, thank you for having me. I’m looking forward to some laughs and, um, talking privacy.

Yeah. That sounds great. So, you know, you’ve had a fascinating career from helping fou- uh, found the IAB to launching CNN.com and now building SafeGuard Privacy. Um, what made you decide that vendor privacy due [00:01:00] diligence was a problem worth solving? Well, I didn’t start out to solve the problem of vendor due diligence, Donata.

Um, uh, I’m one of the few people that’s been a publisher, a network head, a ad tech head, and an agency head, and, um, so I’ve seen all different sides of this. And I’ve been in digital since ’95, so it’s now 31 years in digital. Um, and what I originally set out to do was when GDPR hit, I looked at that as an existential crisis for advertising.

I looked at GDPR as a law against advertising, and my thesis is advertising is good. Um, advertising contributes greatly to GDP here, Europe, around the world. It’s a linchpin of the economy. And I think, you know, advertising has its positives, its negatives, and, um, my belief [00:02:00] was that I wanted to start a company to help companies comply with GDPR.

So that’s what we did at the end of 2018 and 2019. What happened, Donata, was at CES in January of 2020, right before the pandemic I got NDA’d up for the second-largest bank in America for a meeting, and they said to me, “Richy…” And I’ve been dealing with them for 30 years doing their advertising in many different ways.

And they said to me, “Richy, we got a problem.” I said, “What’s the problem?” And they said, well, they spent an ungodly amount of money with a law firm to write a questionnaire about GDPR, like hundreds of thousands of dollars, pal. I mean, just crazy. Then they gave that PDF, which as you know, was outdated the minute they gave it to them- Yeah

to two 24-year-olds at their global holding company sub-agency, and those two 24-year-olds spent 7,000 [00:03:00] FT hours sending it to their 5,000 vendors. And over the course of a year, Donata, how many do you think they got back? Maybe like 10. Well, most people say 10% or 20%. They got 12. You, as a privacy professional, are actually the closest person to anybody-

I’ve asked that question in the last… They got 12 back. So they spent about a million and a half dollars, and they got nothing. Because in GDPR, you have an obligation to do an assessment and due diligence to your vendors. All of these privacy laws have the feature that you are your brother’s keeper, right?

They’re almost biblical in that way. And I spent 14 months with the second largest bank in America building vendor compliance, fully automated. Um, you know, if you look at InfoSec today, Donata, it’s still on spreadsheets. I have some of the biggest companies in the world on my platform, and I still get an InfoSec spreadsheet, and we don’t wanna do spreadsheets.

So fully [00:04:00] auditable, um, you know, timestamped, uh, verified, and a real… ’cause they’re a bank. They understand compliance, Donata. So compliance made sense to them, and they taught me compliance, and that’s when I built the vendor compliance part of SafeGuard Privacy. Yeah. Honestly, like, as somebody who’s done compliance for most of my career, I definitely dread getting those questionnaires in the email.

Right. I see the, the email that’s like, “Third-party vendor questionnaire.” I’m like, “Oh, man, I’m gonna have to be doing this and some spreadsheet for the next, like, week.” And it’s just so tedious and ter- terrible, to be honest with you. I mean, I understand why, you know, we have to do it in some form, um, but, but it’s just terrible the way that most companies do it.

So having a, a better way to do it is definitely helpful, where it’s not something where you’re just like, “Oh, man, I’m gonna have to do this now.” So let’s talk about what you just said. Let’s unpack that. That’s [00:05:00] incredibly important, everything you just laid out. So I build this. We go about it. We’re getting up there and running.

We’re getting vendors on it. We’re working our little butts off. We got a great team. We’re thinking through all the problems, and the, and the bank’s helping us, giving us direction, and we’re getting out in the marketplace. So we have COVID. That stops everything. We come out of COVID, 2021. We’re picking up speed and doing this.

Now fast-forward to the summer of 2023. Do you know what the IAB is, right? It’s the Internet Advertising Bureau. It’s the largest digital trade group in the world. It’s not just here. It’s around the world There was a meeting led by the GC of the IAB, a guy named Michael Hahn, who’s a great guy, with 80 companies, 80 Donatas, 10 law firms, and they had this meeting to exactly what you just said.

The meeting, if I would summarize it, was that old movie, Stop the Madness. Everybody was complaining. The exact same thing. I dread getting the email. [00:06:00] Everybody’s got same but different questions. None of them are consistent. Nothing is standardized. You know, Donata’s at a DSP and they’re asking you publisher questions.

Donata’s at a publisher and they’re asking you DSP questions, and none of it made sense, and it was insane, and everybody was wasting time, and it was performative. Exactly what you said. And everybody in that meeting said, “Can we standardize this?” So what the IAB did was, you know, the IAB’s a trade organization, so it took six months.

They looked at every company in the place. We were the only company that had built something like this. We had standardized an assessment for California and GDPR, ’cause those were the laws, right, in 2021 and 2022. Um, and we had done that We had a standardized assessment. You could fill it out once and share it multiple times.

So exactly all the pain points you talked about, we had already built. They looked at every company out there. They looked at, I’m not gonna name names. They looked at all the names you would think of in privacy, all the GRC [00:07:00] platforms. We were the only one that had built a fully auditable timestamped standardized platform.

They said, “All right.” So we are the white label of the IAB diligence platform. And what we’ve built has now evolved in that– So now fast-forward to 2026, we’ve got 24 laws. We, we’d started with an assessment for each state law. That just didn’t make sense. Our legal team, so my company is all lawyers and engineers.

There’s no salespeople, it’s just me. And the lawyers write everything, and we have some fantastic lawyers that have had great jobs in the industry and have had huge posts and, and been doing privacy for a long time. And what they did was they took eight months. Once we got to, I think it was 15 state laws, we now have a multi-state assessment, which is a highest bar, and one questionnaire covers the obligations of every state in the US.

The beauty then is the IAB with those 80 companies, they form committees, and the 10 law firms and all the law firms got behind it. They wrote the [00:08:00] data flow questionnaires because there is the obligations of the privacy law, and then there’s what’s actually happening with the data. And what the IAB did was we now have a questionnaire for if you’re an agency or a client to a DSP, if you’re an agency or client to a publisher, if you’re a publisher to an SSP, if you’re an SSP to a DSP.

There’s now 12 of these modules that are the correct data flows. So now we have a platform that has three legs to the stool, an assessment to all the laws. We also have GDPR. That’s a separate license, right? So you’ve got all the US state laws. You’ve got the right data flow for the right vendor And you have secure sharing that is fully auditable.

This is not a public shaming. There is nowhere you can go onto my website on our product and see Denada score. It only works if Denada’s the advertiser, and I’m the vendor, and you ask me in the platform, I accept your request, and I share [00:09:00] directly with you. Because we talked to hundreds of vendors, and vendors didn’t want a public shaming.

I mean, there’s companies out there that do these privacy scores, and then they post them every month, and that’s just wrong. So we built a platform to satisfy the vendor’s needs and the host needs. Does that resonate with you in- Yeah … your fear of getting a TPRM email? It does. I, I love the fact that all the privacy laws and, and the requirements for the due diligence are combined.

I mean, we see the same thing in privacy policies where you have companies with 30 different privacy policies for each law or, like, each section is its own law, and all the information just repeats over and over and over again. Yeah. And we’re seeing that more and more companies are now combining these disclosure requirements into one policy instead of saying, “This is the Connecticut privacy policy.

This is the California. This is the EU privacy policy.” Yeah. You know, like, we’ve gotten to the point with these privacy [00:10:00] laws where you have to start combining things, otherwise you’re gonna go insane. I agree with you. You’re absolutely right. So, you know, when people hear vendor privacy due diligence, um, you know, they often think it’s just reviewing a questionnaire once per- per year.

How do you define it or how should we define it? So let’s talk about the US versus Europe first. So in the US, I think this year we’ve had three or four new states pass. I mean, Louisiana passed a law. Mm-hmm. Connecticut amended again. California amended. Delaware’s got an amendment coming. New Jersey’s amended.

These laws are changing all the time. So we believe best practices Are to utilize the IAB diligence platform at least annually, and if there are any updates or changes. Because we have an automated platform, let’s say a question on, on Connecticut [00:11:00] changes, and it’s the highest bar for all the states, and it, it changed the state of a vendor.

You’ll be made aware of that. And in an environment where we have such drastic change– Because what we’re seeing, Donata, is that the states are all normalizing, right? There’s the California model and the not California model. But even in the not California model, everybody’s got little– We’re seeing these amendments as people get more aligned with each other.

You need to know if you’re a major advertiser, especially if you’re buying data, right? You need to know if something changed. So the beauty of not sending a spreadsheet on email, which is not updatable, is the system can flag for you, Donata, the advertiser agency client, that something has changed with one of your vendors, and you can choose to look at it in the appropriate timeframe.

So we believe a living, breathing platform is the best, with a minimum of at least once a year checking all your vendors. And our platform is set up so that [00:12:00] every year you can ask for attestation. Our platform is set up that when the vendor shares with you, Donata, there’s a little mini EULA, and they’re attesting to you that what they put in was true and valid and up to date.

That protects both parties, but especially protects you if, gosh forbid, a regulator comes in, you can say, “I’ve got an actual attestation.” You don’t have that with a spreadsheet and an email that you get from a, from a vendor. So we’ve tried to put all these belts and suspenders to help both parties do the right thing Do you think that a questionnaire is, is sufficient?

I mean, there’s, there’s been times in my experience where I look at a potential vendor and I look at their website, I look at their privacy policy, I look at their DPA, and everything looks good. And the questions, the answers that they send back, everything looks good. And then I, I like doing my research, right?

I’m like a jealous girlfriend when I’m doing vendor due diligence. And [00:13:00] I have found companies that, you know, appear as if everything is, you know, tightened up, everything is good, everything’s GDPR compliant, everything’s compliant with this or that law. But then I start looking up, um, like, their staff, and it looks like their CEO, COO, CFO are on the US sanctions list, and it turns out that they’ve been, like, laundering money, or it turns out on their reviews that, you know, they say they perform a service where they actually don’t do that.

So, you know, in your opinion, is a questionnaire enough, or should we be doing further digging to kind of, you know, confirm that these answers are actually correct to a certain point? That’s a fascinating question. Um, the version of that I get sometimes is, “Well, I went to their trust center, so I think everything’s fine.”

Yeah. The different… Right? Right. It’s like, so let’s, let’s break down the pieces. One, now, I’m not a lawyer, you are, so correct me if I do anything wrong, Donata. I’m [00:14:00] not a lawyer, didn’t even play one on television. Um, but we have a great legal team here, and, and, you know, we- we’re tied in with the IAB and the general counsel, et cetera, et cetera, and I talk to lawyers all day long.

Most lawyers tell me that a privacy policy only covers about 30% to 40% of the law. So the privacy policy is incomplete The biggest pushback we get on the platform, Donata, is that it’s too comprehensive, and I’ll take that complaint. Our questionnaire for the US laws covers every obligation of every state comprehensive privacy policy, including Washington My Health and all the sensitive data laws.

Covers it all. We’ve been due diligence by probably six hundred lawyers at this point. There’s over twelve hundred companies on the platform. Um, you know, nobody has complained. The, the biggest complaint is we’re too thorough. Then if you look at the IAB modules, they are the data flow questions that the industry has gone to great depth to write out.

And if you look at all these modules, again, [00:15:00] it’s a tremendous amount of work. But you gotta do it once, and you can share it as many times as you want. The difference is, I think, and correct me here, Donata, if I just look at a trust center and if I look at some questions they sent back and it was just on an email, and I look at their website and I look at their privacy policy, they have not attested to you anything that is true and valid.

Our platform is a legal compliance platform. It is a mini EULA. They are putting in there what they put in was true and valid. So if a regulator comes and, Donata, they lied to you and they didn’t do that service and they didn’t do that, you actually have a contract that goes back and says they, they attested that it was true and valid on the platform, which you tell me, I believe it does then pr- give you a certain level of protection that you don’t have if you say to a regulator, “Well, I looked at their public website and I looked at their trust center.”

And the regulator’s gonna say, “Well, show me your work.” You can’t. We now have [00:16:00] a platform that you can demonstrate your work through every step of it, who you invited, what you asked, the questions you asked, their answers, your review of it. Look, we had to build this for the second-largest bank in the US. It is a conforming– By the way, Donata, this could be any law.

We have HIPAA on this platform. We have COPPA on this platform. We could do GLBA. This platform is built for any law. We’re just, you know, I’m an entrepreneur. The way you die as an entrepreneur is try to boil the ocean, so I’m trying to focus on privacy. So I hope I answered your question, but I, I, I really, the, all the pieces and parts that we built gives you full compliance.

Again, if you got a bad actor, Donata, and they’re lying to you, the best thing you can have is that they’ve had to swear that what they put in was true and valid Yeah. I mean, that totally makes sense of having that attestation is very helpful. To me, I, I guess I don’t trust vendors a lot. Um, so you know, they could be compliant [00:17:00] from a privacy perspective, and I could have them attest like, okay, they’re GDPR compliant, but like, I’ll give you an example.

Um, there’s a very popular company that provides, uh, document shredding, and through vendor due diligence, um, and this wasn’t necessarily privacy related, I found out that, um, there have been multiple instances where instead of shredding the documents, they take them to a park and they dump them in the public trash cans in a park not shredded, right?

So you wouldn’t necessarily- That’s a nightmare. Right? That’s a nightmare, Denise. And this is one of the biggest shredding companies, like, in the United States, and I, I won’t name who. Oh. But, um, you know, you fi- you won’t find that out through a questionnaire. So like in my mind, the way that I do it is I, you know, I would do this questionnaire, I would have the attestation, but then I would still look up, like, reviews.

I would still look up Glassdoor. I would still look up, like, the OFAC lists and, and all that other stuff. [00:18:00] I agree with you. You’re right. So what have we done to help you with that? So in the platform, by the way, interesting that you said that. I can’t do everything, but everybody’s asked me to do InfoSec, so w- now we have a state-of-the-art InfoSec.

So you can do InfoSec and privacy in one platform. You have a secure page for every vendor. Call it Publisher X. No, that’s a real one, so don’t say X. I forgot he named it that. Publisher XYZ, right? All right, that’s our first laugh, Donata. Uh, so Publisher XYZ. In that secure page, you have a secure box to put your counterparty agreements, your contracts, DPAs, whatever you want.

You also have a secure box for comments. So you can write in there, “I looked at their glass door, and they did X, Y, and Z.” And then if a regulator comes, you can now show your work in one place, and it’s all timestamped. The other thing, I forgot to mention this, in the IAB modules, we have the DOJ bulk data transfer, you know, module.

So we do provide you with enough [00:19:00] tools that you can do if you’re, let’s say you’ve got somebody who’s in Europe, and you’re transferring the data, et cetera, et cetera. That’s awesome. We’re trying. But you know what? You’re right. There’s no– If somebody’s gonna be a bad actor, you and I can’t stop them. Bad actors are gonna find ways to do bad things.

The best I can do is give you a timestamped, auditable platform to show that you did the best you could. Yeah, and I, I mean, to a regulator, it’s like if I have done everything that I was supposed to do, and I have all this evidence backing up the fact that I did that, like, at a certain point, that’s kinda not my fault anymore, you know?

R- regulars, regulators through the dawn of time wanna see that you’re making best efforts. Mm-hmm. So let’s, let’s, let’s give the greatest example of all time. If, um, if you and I were driving down the streets of Chicago at 2:00 in the morning at 90 miles an hour, and the cop pulls us over, we’re in a lot of trouble, right?

Saturday night bars. If you were, you [00:20:00] know, you were holding our dog in your lap that got injured, and we were going to the emergency vet, or your kid with a broken arm, the cop’s gonna say, “Hey, slow down. I’m gonna give you a warning, but now let’s get you to the hospital.” Yeah. I think the regulator wants to see you tried to do the right thing, and, and you’re gonna get a, hopefully, hopefully, fingers crossed, you’re gonna get a slap on the wrist.

You’re gonna get told to be careful. But if you’ve done nothing, and this vendor is bad, you’re going, you’re, you’re getting, you’re getting crammed. Look at, you know, there’s hundreds of letters from California. I know you had Tom Kemp on. He’s a great guy, great episode. I listened to it. There’s hundreds of letters out there.

The fines are when people don’t do it, and they’re hitting people hard. These fines are getting bigger and bigger. And by the way, it’s not just the fines, Donata. If you look at the fine, whatever, I don’t wanna name names 2 million, 4 million, 12 million. It’s at least 30 to 40 million of legal costs. You’re hiring a lawyer, you know, these big time firms at [00:21:00] 2,000 an hour, and you’re negotiating over two years.

You’re spending a tri- It’s not the fine, that’s the tip of the iceberg. The amount of money and time that is spent on fighting those is huge. You know that. Yeah. Yeah, absolutely. Absolutely. Um, can you give us some, just a few examples of, like, the most important questions that we would be asking when performing vendor, um, due diligence?

I, you know, that’s a good question. I’m not sure how to answer this. I, I think vendor due diligence needs to be risk-based. If you’re buying data, I think you need to do your data providers first, right? If you’re– I think you gotta stack rank your vendors. I think that’s the question you have to ask yourself: Where’s my biggest risk?

I think it’s in the data. I think if you’ve been in digital for any amount of time, and I’ve been in it for a long time, you know that the data is [00:22:00] pretty messy, and the provenance, the provenance of the data is pretty hard, and data brokers are buying and selling from each other, and they wanna know about consent.

So was the data appropriately collected? So I think that’s job one. You gotta make sure your data fairs. We have a massive pharma, and the first thing they did was 80 data vendors. Made a lot of sense. The second thing we say to people is deal with your key, um, choke points, your agency, your DSP, right? Your, um, identity provider.

Deal with the places that interacts with your data. Third thing I would say is make sure that your first-party data providers, and this may be, this could be 1A, I’ll, I’ll, I’ll shift my answer here, Donata, make sure that the software, the CMP, CDP, whatever you call it, everybody’s got [00:23:00] their own acronyms, that’s holding your gold, which is your first-party data, is totally compliant.

I think you do those three things, and then you cascade down the waterfall. All right, I wanna look at the thousand publishers I hit on. I wanna look at the top 500 publishers first, ’cause in programmatic, you could hit a thousand publishers in a month, four thousand publishers in a year, and the long tail, while it’s nice for your delivery, you know, I think there’s the 80/10/20 rule in there.

You gotta hit the top 500 publishers and make sure they’re doing the right thing, and then you go down from there. Does that make sense to you- Yeah … how I laid that out? Yeah, that makes total sense to do a, a risk-based approach. Um, now, before you, like, initially start working with a particular vendor, let’s say that you send them this questionnaire, or you ask them to complete it, and they refuse to do it.

Obviously, the answer is pretty simple. You just, you find somebody else. Um, but, you know, let’s say you’ve been working with a [00:24:00] vendor for a while, and you’re doing a reassessment, and they just refuse to do the vendor due diligence questions. What do you do? You just hit on the million-dollar question-

Donata. That, that, I mean, so I was gonna say, then you have to… So the process is you decide who you’re gonna do, then you deploy the platform. So the way the platform works, the only email is in the invite. Everybody has a secure instance. If you’re any of the 1,200-plus, ’cause it grows every day, companies on the platform, has a secure instance.

Every instance is secure. You control it. It’s two-factor authenticated. There’s a super admin, there’s an admin. So every vendor controls their own data. If, if a vendor… And it’s all automated on the platform. If they’re there, it’s all automatically requests it. If the vendor’s on the platform, which means they’ve already done it, they can automatically share with you.

That’s a different use case if they don’t share with you, then let’s break it [00:25:00] apart. So y- this vendor has already been asked by somebody else. The beauty of the platform is every host, whether it’s an agency or a client that ask vendors, the first time a vendor is asked, that now helps everybody else, ’cause once the vendor is on the platform, they don’t get asked again.

They just get asked to share. The hardest part is getting them on the platform. Once they’re on the platform, let’s go down the thing of your question. I- I’ve used this vendor before, but if they’re on the platform, Donata, they’ve answered it for somebody else, then you have to ask yourself if they don’t wanna share with you.

Most part, we don’t see that happening. We see them sharing with you. There are some very big platforms on our platform that are making decisions about who they share with, and then that’s a business decision because they’re on the platform, they’ve done it, and they seem to be sharing with really big players.

We’re all working together to get them to share with everybody. That’s a business decision. To follow [00:26:00] your question, let’s talk about a vendor that’s never been invited before. So you, Donata, are gonna ask me I don’t accept your request. Now I think you have to have a risk-based decision tree. Is this a data vendor?

Why are they not saying yes? Why are they not getting on the platform? By the way, vendors get on the platform for free. There’s no barrier to entry. We have built massive AI tools to help the vendors get on the platform in hours. Hours. We make this so easy for a vendor to get on the platform. They have to answer the questions, they have to review the questions.

We, we typically say to a host, give them 30 days to get back to you once they’ve accepted your request. But you could do it in a day or two. So the– we’ve tried to remove all the friction and all the barriers. So now, since we’ve over the last two years, worked our butts off to re-remove all the friction and barriers, if they’re saying no, you have to make a business decision.

Is this data the same as I can get somewhere else? Why are they saying [00:27:00] no? Why are they refusing to share this with me? I’ve been using this vendor for two years. It’s a new vendor. Like, we’ve got some people that they have integrated us into the procurement process, so before they even hire a vendor for the first time, we’re part of the contracting process.

Why? Two reasons. One, our assessment is so thorough, we’re getting data back that we’re cutting the contract vendor lawyer in-house’s time by twenty-two to twenty-eight percent because if they deploy the assessment, they’re getting all the data flow questions and all the privacy questions answered, it makes it easier to write the contract.

So again, we believe… Look, in the last four years, the world changed. Four years ago, you didn’t have to do this. Now, you gotta do this. So I think you really need to ask yourself, is this ven– why are they not answering? Is this vendor Somebody I can live without. And you need to do business decisions, ’cause if you’re using this platform and you’ve got a [00:28:00] major vendor that won’t answer and the regulator comes in, what do you think the regulator’s gonna say, Donata?

They’re gonna say, “Well, why didn’t you do something to this vendor?” I’m not picking on them, but look at the Gravy case from the FTC. It’s a public case. We love Gravy. They’re good people. They’re trying their best, but they got dinged because they sent out a questionnaire and they didn’t look at them. Mm.

So what are you gonna say if you’re a regulator and you send it out to me and I refuse to answer, but you still do business with me? You’re the lawyer, Donata. If you’re a regulator, how are you gonna look at that use case? What do you think that’s gonna reflect on you? Right. Yeah, it’s, it’s not gonna reflect well, and I, I think a lot of companies lose business because they refuse to answer these questions, um, or refuse to answer them properly.

Um, and I think that kind of leads us really well into our next question. What are the biggest red flags that you’ve seen when reviewing vendors? So our platform is completely confidential, so I can’t really say anything other than it [00:29:00] surprised me when one of our hosts called us and said, “What do we do with this vendor?”

I go, “Why?” Sh- and they said, “Well, the vendor answered N/A to every question.” And I’m like, “Okay?” So we, we don’t force it’s yes, I’m compliant, no or this doesn’t apply to me, or N/A, doesn’t apply to me. I think it’s kind of impossible that we have had a vendor reply N/A to every question about every obligation of every state.

Look, Donata, human beings do funny things. Like you said, the shredding company, the, obviously the route driver got tired and he put the, or she, he, she, it, put the papers in a public trash can Uh, we have seen some crazy stuff where people will just say, “NA, I’m a data broker and I don’t do anything and nothing applies to me to these laws.”

So you know, we get crazy stuff like that happens [00:30:00] in our customer advisory board. You know, we have a ton of customers that like to give us feedback. Those meetings tend to be very funny at the end when people talk about the silly things that vendor- vendors tend to do. Yeah. I, I think, you know, when I’m doing it, one of the biggest red flags, at least in my mind, is when they’ve plastered all over their website that they’re GDPR compliant.

Um, to me that’s like an automatic red flag. I’m like, okay, so you think you’re 100% compliant, let’s see how compliant you are. Um, you know, that one always kinda triggers me a little bit. Um, you know, or DPA only available upon request. Um, or, you know, if you have a simple privacy question and they tell you, uh, “Well, we can only provide this answer if you sign up for our enterprise plan.”

Yeah, that’s crazy. And you’re like, why am I supposed to be paying- That’s crazy … for privacy? I’m supposed to be paying you more? Like I’m already paying you, and you’re [00:31:00] obligated to provide this information to me, but now you want me to pay thousands of dollars a month- Yeah … in plans that I don’t need- Yeah

to get access- Yeah … to this information? Like are you a fool? Crazy. Um, you know- If their privacy policy is out of date, if the last time it was updated was 2020, that’s easy to tell, right? Yeah. The privacy policy is out of date. Um, if they’re a data broker, uh, or, and they say that they are contextual only.

You know, people will do the craziest stuff, Donata. It’s like- Yeah … they’re all… Look, let’s take a step back. Advertising and digital has been an unregulated industry for over 100 years. We went from zero to 100. I mean, I’m not talking about kids. There’s been COPPA, right? Right. But we’ve basically been unregulated.

We now are a very heavy, heavily regulated industry, and my problem is A large percentage, not 50, but I would say 30 to 40% of the players in our industry don’t believe that they’re in a regulated [00:32:00] industry, and I think that is a horrible, horrible stance to take. Do you, do you see that too? Oh, 100%. And I think that some of these companies, I mean, they don’t care to the extent that they’re almost, like, mocking you.

Um, I, I’ll give you two examples. So example one, um, I sent a– I didn’t even go through, like, a questionnaire. I had a very simple question for them. So I sent an email to their privacy email. They didn’t respond, but they added me to their email marketing list. And every single time- I hate that … every time I try to unsubscribe- I hate that

they keep on sending me these emails. And I’ve never worked with this company, it was never, like, a consumer relationship- Oh … or anything. I emailed their privacy e-team. And then I’ll give you a second example. Um, I emailed another company, again, a simple privacy question. I have received over 90 automated emails telling me to look at their privacy policy Over [00:33:00] 90 automated emails and not a single answer to my question.

So at a certain point, these vendors are like, they’re, that’s straight up, like, mocking you. I don’t know how else to describe that. I agree with you, and I, I think the, I think the biggest fallacy is that a privacy policy, you know, papers over all sins, and I think that’s wrong. Right. I think it’s wrong.

Right. It’s wrong. And my question was, you know, your privacy policy is for your website. Do you have privacy information specific to your product? Because it’s impossible to understand which portions apply to your own website, which portions apply to your website- Oh … because it’s all combined and intermixed.

And they could have just answered my question very simply, like, “Yeah, here’s our DPA that covers the product,” or, “Here’s a separate policy that covers the product.” And that’s, like, all I needed. But instead, I got all these automated emails and not a single actual answer to my question. It, it, it’s just insane.

I, I don’t know about you, but, you know, I’m kinda, you know, I’m out there [00:34:00] publicly ’cause I have to be running a company. My phone is useless. Same. And, and I love T-Mobile, and I have all the spam filters on it. My phone rings 15 times a day with a spam call. Same. My email, my home email and my work email, it’s like I just, I hit unsubscribe all the time.

I just hate this. Mm-hmm. And they’re, we’re forgetting the consumer, right? We’re forgetting the consumer. And, and look, I, I’m a consumer just like you. I go buy something and they’re like, “Hey, give us your email and you get 15% off.” I, I, you know, I used to say, “All right, I’ll give ’em my email, get the 15% off,” and then unsubscribe, but it’s like a doom loop.

Mm-hmm. You can’t get out of it. And let’s be honest, the reason we have these privacy laws is we forgot the consumer. And my, my example to people is I buy the same pair of Merrell sneakers every five years. I go to the largest, um e-commerce site in the world. I buy the same, there’s a Merrell shoe store [00:35:00] there, I buy the same pair of sneakers.

I complete the purchase. For the next 30 days, so this is the best e-commerce site in the world, I completed the purchase. I get ads for those Merrell sneakers on every website I go to for 30 days. And I s- when I say this to people, what I call civilians, not in the industry, they go, “Yeah, it happens to me all the time.”

And they’re like, “The reason we have privacy laws is the algorithm is stupid,” I don’t care what you say about AI, and the algorithm doesn’t know the difference between a pair of Merrell sneakers and I went and searched that my mom has cancer, or my kid is depressed, or something, anything sensitive. And the algorithm will send you that for the next 30 days, and we forgot the consumer.

It, from the dawn of programmatic about 15 years ago, we just thought all data was good, and we thought everything was a touchpoint. And the greatest lie is that the ad tech, martech industry has sold your CMO of [00:36:00] X company that she’s gotta collect 2,000 data points for everything they, they buy, and you just don’t need 2,000 data points on a tube of toothpaste.

Yeah. And, and there’s just too much data out there, and we forgot the consumer, and it’s a horrible experience for the consumer. And the world has shifted that you’re doing everything online. That’s why we have these laws. Yeah. I, I completely agree. I mean, I’ve gotten to the point where some companies where I just won’t buy from them anymore and I won’t go to their website because I’m hounded by ads and emails and everything else.

And it’s gotten to the point where, like, I was actually interested in their products, but because of this, like, essentially stalking process, I’m not interested anymore. I’m gonna go buy from somebody else. And I think that’s what a lot of companies are missing. You know, they think that the most important part of their website or their business is all this data that they’re [00:37:00] getting, and I’m like, “No, the most important part of the business is the amount of products or services that you’re selling, that you’re actually selling to people.

That’s the important part.” And they’ve kind of gotten that confused and, and intermixed over time, and I think it’s, it’s terrible for consumers. I totally agree. So I think the internet really changed how we, I don’t wanna use the word society, our, how we live, work, and play- Purchase, research, everything. It took about 30 years, ’cause, you know, pre when we were starting on CNN.com in 1995, if you wanted to take a trip, you called a travel agent who had an expertise in going to Patagonia, whatever.

You can put your, insert your example here. Now, you can do all that online, all the way through booking the trips, insurance, everything, lock, stock, and barrel. What I’m worried about is I think the power of AI is gonna have the same fundamental changes on everything we talked [00:38:00] about, but it won’t take 30 years.

It’s gonna take, I don’t know, 5, 7, maybe 10. And I think w- if we don’t wake up, we’re gonna make the same mistakes about privacy, and we’re gonna make the same mistakes about pissing off consumers if we don’t realize that we need to treat the consumer better. You go all the way back to David Ogilvy, and, you know, treat them better, and it’s- Yeah

it’s crazy that we’ve forgotten these basic lessons. I, I totally agree. Um, you know, and speaking of changes and, and AI and, and how much things are changing and all these new laws that we talked about, how do you think the vendor due diligence process will change over the next five years? Great question.

So let’s talk about AI, right? So let’s use a great example. Um, all of these laws have automated decision-making. It’s covered. So we don’t need new laws on AI, we just need to pay attention to the laws we do. And I… [00:39:00] Whatever. So, um, let’s be really serious about AI agents. The IAB Diligence platform is the only privacy signal in the new IAB Tech Lab agentic media buying, also other agentic standards out there, because your obligations don’t go away.

You’re a lawyer, right? You get it. The obligations don’t go away because all of a sudden you’re using two letters that are called AI. Yeah. So let’s, let’s stop the madness here and realize you still have to do the vendor due diligence. I think it becomes even more critical as we move forward. Now let’s talk about the agent.

The advertising industry has been driven by an army of 24-year-olds at agencies, you know, that are sitting there, hands on keyboards, buying different media stuff. Think about an agent. If I hired a real estate agent to sell my house, and I was selling my house for $100, the real estate agent can’t sell it for 50 and walk [00:40:00] away, right?

Why not? Because I’m a human, and I have to sign the contract, and I’m not gonna sign the contract for less than $100. So AI should be automating systems that need automating, and humans should be giving the direction that needs to be given direction, and there should be human interaction in everything. We have three major AI products in our platform, and they all are human assistants.

It’s using AI to do the grunt work, but the human has to be involved to make sure, because as you know with legal, with hallucinations, we only use models that are enterprise, that are trained on our data, and it’s AI on proprietary data on your vendor’s data. But there is a human interaction in every step so that the AI cannot make that decision.

But that said, it speeds up the time tremendously from two to three days to do an assessment or a review of the vendor to three hours. Wow. So I think AI is [00:41:00] going to make vendor diligence 10X more important than it has been because the decision-making is gonna happen more rapidly. And what we’ve done is we’ve put the, the review, what you asked 20 minutes ago about the yearly review of vendor Richy, and you’re buyer Donata, no ad tax, no latency, where it’ll be able to say to you, when the agent goes out to buy, you’ll say, “Oh, this is an approved vendor.

Great. Richy’s cool. I’ll buy Richy.” That’s right. And I think that’s what’s gonna happen, right? Yeah That’s, that’s gonna make our lives, um, a lot easier, that’s for sure. Well, the, the black box is gonna mess you up, Donata. You can’t just have the agent go out and buy stuff that you haven’t reviewed because then the

all of a sudden you’re in a do loop. The regulator comes in and goes, “What’d you do?” “Well, I don’t know. The agent did it.” Tell me how that’s a defense. Yeah. One of our, um, this is, like, from the consumer side, one of our employees brought up this [00:42:00] example of, like, these, uh, electric cars that could come with AI, and when your car needs new tires, the AI could order new tires for you.

And I was like, “I would throw up if my car just, like, randomly ordered new tires for me without my approval.” Uh, and it seems like, you know, things are … there’s definitely many products that are proposing that. Oh, your smart fridge, you know, saw that you didn’t have any milk, so it ordered it for you from Amazon Grocery or- Ugh

you know, I th- I feel like there’s gonna be a similar thing for vendors where it’s like, oh, yeah, I need a- another license with this vendor, so this AI decided to buy it for me, and I’m just like, “Oh my God, no, I do not want any of that.” Oh, so girlfriend, let’s talk. We did our kitchen last January. The fridge, the two, the washer and dryer, stackable, and the dishwasher all wanted to be hooked up to the internet.

I’m like, “No.” Yeah, no. The stove, the stove, the fridge, the dishwasher- Yeah … and the washer and dryer, and I hooked up what I needed to hook up for the warranty and the rest, I’m like, [00:43:00] “Nope.” Yeah, none of- You’re not, you’re not … No. No. No. No, we are not … No, Hal, do not let me in the door. Whatever. Right. Yeah. Right?

None of our stuff is hooked up to the internet either. No. There’s no apps, no anything. There’s no smart light bulb, smart, um, outlets. There’s no smart cameras. There’s none of that. Um- Look, one of my best friends who started General Motors Cyberworks when I was starting CNN.com, we’ve been friends for 30 years, and we have dinner with him every Saturday night, and he’s, uh, y- got a, he’s a g- huge global president at Omnicom, and we’re best friends.

You know, you have the circle of friends in the industry. He’s got an Alexa in his, and the Google thing in his thing. And I’m like, and we love each other. We’ve known each other, and the four of us have dinner, and he’s like, “Alexa, set the timer.” I’m like, “No, Alexa, don’t listen.” And we just laugh ’cause I don’t have any of that in my h- and I’m not a Luddite.

Yeah. I’m a tech CEO, but I’m like, “No, dude.” And so we just, we battle over his Google, “Set a timer for 10 minutes.” [00:44:00] No. Yeah. No, none of that at, at my house either. I don’t, I don’t wanna be listening to, and I’m not paying for surveillance devices, so no thank you. But, and he makes fun of me for not having it in my house, and he’s as digital savvy as I am.

And I- So there’s, there’s that divide there. We just, it’s goof. We’re goofballs. For sure. It’s fine. Yeah. It’s fine. Um, well, Richy, thanks so much for, for coming on the podcast today. I really appreciate it. Did we cover everything you wanted to cover? We did. Thank you so much. Um- It was great to be here. I appreciate you having me.

This was a lot of fun, and, uh, anything you ever need, we’re always happy to help. Perfect. Thank you. And, um, to our listeners, make sure to subscribe, uh, so that you don’t miss our next episode.

Listen to more episodes!

Search the Site
Popular Articles
Browse by Category

Comparing Policy Generators

Cookie Consent Banner

Cookie Policy

Culture

Disclaimer

EULA

How To's

Privacy Policy

Terms of Service

Subscribe for Updates
Search the Site
Popular Articles
Browse by Category

Comparing Policy Generators

Cookie Consent Banner

Cookie Policy

Culture

Disclaimer

EULA

How To's

Privacy Policy

Terms of Service

Subscribe for Updates
  • This field is for validation purposes and should be left unchanged.