[MUSIC] >> You're listening to The CyberWire Network, powered by N2K. [MUSIC] [MUSIC] >> Hello, everyone, and welcome to caveat. N2K CyberWire's Privacy Surveillance Law and Policy Podcast. I'm Dave Bittner, and joining me is my co-host, Ben Yellen, from the University of Maryland Center for Cyber Health and Hazard Strategies. Hello, Dave. >> On today's show, Ben has the story of the Supreme Court agreeing to take up a high profile case on Geofence Warrants. I look at the global question of digital sovereignty. And later in the show, Brian McGinnis, partner at Barnes and Thornburg, LLP, discusses youth protection and data privacy and the Federal Trade Commission. While this show covers legal topics and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. [MUSIC] [MUSIC] >> Quick question. Have you watched Project Hail Mary yet? Humanity is facing an existential threat and racing to solve it with a clock ticking. For security teams, that probably hits close to home with AI use, rapidly spreading. Everyone's using AI, marketing, sales, engineering. Chris, the intern without security even knowing about it. That's where Nudge Security comes in. Nudge finds shadow AI apps, integrations, and agents on day one, and helps you enforce policy without blocking productivity. Try it free at nudgesecurity.com/cyberwire. [MUSIC] All right, Ben, let's jump right in. We've got big news from the Supreme Court. What's going on? >> It's happening. [LAUGHTER] >> So it's been really eight years since the Supreme Court has taken on a high profile 4th amendment case. And that is about to change because last week, they granted Sir Shiroari, which is a fancy way of saying they agreed to hear a case on Geofence Warrens. We've actually been discussing this case over the years as it's made its way through the lower federal courts. So it is called Chattrey versus United States. It was about an individual who was arrested and prosecuted based on evidence gleaned through the use of these Geofence Warrens. So a bank, or I guess it was a credit union, we're going to be precise, was robbed in Virginia. >> Right. >> And law enforcement basically didn't have any leads on it. So they went to Google, who at the time, kept the relevant data to do these Geofence Warrens. So it's basically, what are all the devices that use Google applications that were in this particular area at this particular time? And then you got a smaller universe, so here are all the devices. And then you do more investigative work. You can figure out who the person is. So Chattrey is convicted. He appeals up to the fourth circuit court of appeals, which upholds the conviction and say that this does not count as a Fourth Amendment search. This contrasts with a fifth circuit case, which is a case called Smith versus United States. And they came to the opposite conclusion in that case that a Geofence Warrens is incompatible with the Fourth Amendment because there is no way to structure a warrant that meets the Fourth Amendment. It's a particularity requirement. So the particularity requirement means that you have to describe the persons to be searched or the things to be seized. And almost by definition, with a Geofence Warren, you don't have a suspect. And you're not really describing necessarily a place to be searched, although I think that's really the open question about this case. >> Right. How small an area can you put the fence around? >> Right. So on the one hand, you have what our founding fathers found extremely offensive. And kind of the impetus behind our Fourth Amendment drafting is the so-called general warrants. >> Where it's going to this house and see what you can find. >> We're going to look around. Go through your drawers to see. >> So this certainly in some ways feels a lot like that. But in other areas of the law, we allow law enforcement to look through extremely large databases, even without having identified a suspect and use whatever data we glean at least to start a criminal investigation. And so that's basically what the Fourth Circuit was arguing. And I think a lot of legal scholars is if you are searching X number of communications, if you're trying to find that needle in the haystack, you necessarily have to search the whole haystack. So is that type of search any more broad or fundamentally different than what we're doing with a geofence warrant where we're starting with a large universe. And for investigatory purposes, we're trying to narrow that down to a small subset, which is people who are in a particular area at a particular time. >> Yeah. So this is exciting for us, Fourth Amendment nerds. It has certainly been a minute. And my guess, since I know you're going to ask this question, I'm preempting you. My guess is that we'll have oral arguments by end of March, early April. >> Oh, that quick. >> Yeah, and then a decision by the end of June. >> Wow. So we got an action date. >> So is it because that the Fourth and Fifth Circuits disagree on this that spikes the Supreme Court's interest? >> Definitely. So one, you have a clear circuit split like this. Those are the types of cases that are high profile enough that the Supreme Court will want to take them on. That's really how they see their role most clearly. Sure, there are going to be some cases where there might be consensus within the circuits, but the Supreme Court says all of you are wrong. That happens. Especially if circuits are trying to interpret previous Supreme Court precedent and the makeup of the court changes. And the court says that's not precedent anymore. So obviously, your most famous example is the dobs case overturning Roe versus Wade. But really what they try and do in most circumstances is identify these areas where there's an inconsistency between circuits. It's not great to have a legal system in this country where in an arbitrary group of states depending on their geography and depending on the makeup of their circuit courts. There is one rule for conducting geo fence warrants and in other states that are randomly in a different place just because they have a different set of judges. There are completely different rules. Having that level of uniformity so that people know what to expect that there's kind of a clear statement of the law. Those are the kind of disputes the Supreme Court really does try to solve. Any tea leaf reading here knowing the players on the on the Supreme Court. What do you suppose there where might their interests lie in this in terms of coming up with a final decision. So it doesn't really fall neatly along ideological lines frequently when we talk about Fourth Amendment cases. Carpenter kind of did it was Roberts joining with the four liberal justices at the time. But interestingly in that case, Justice Gorsuch wrote what was a dissenting opinion but was in many effects saying like I can't really get there on this case to say that we need a warrant for historical cell cell site location information. But the Fourth Amendment in the age of modern technology needs to be changed and reformed and we have to have some better lens of understanding it than the one that we do now. So I'm very curious about the questions that he asks in oral arguments. He's a guy who believes pretty strongly in civil liberties. He's a very conservative justice. But on like a few issues he can go kind of rogue and I think this is one of them. He cited in a two person descent with Justice Sonia Sotomayor in a case that we discussed on on the state secrets provision. So we had that descent by the two of them I could see kind of a cross ideological makeup of both a majority and a descent here. If you look at the makeup of the fourth circuit in the fifth circuit the fifth circuit is far more of a conservative circuit. And they're the ones who ruled that these geofence warrants were unconstitutional. There are some political considerations here. One of them is that the most famous geofence warrant ever was the one done by federal law enforcement to apprehend January 6 suspects. Now we could have seen a pellet cases resulting from those searches because a lot of those people were convicted and went to jail, but they've all been pardoned now. So that question is is moot. But that is the most high profile example of the federal government using geofence warrants. And there were concerns about it. I mean, especially when you have a crime that depends so succinctly on whether a person was in the capital like whether they actually breach the doors or whether they weren't you know geofence warrants at least at the time and probably still now weren't exacting enough to separate people who are just their peacefully protesting versus people who are actually in the capital. The technology keeps getting better and better, but it certainly presents causes for concern. I think one of those January 6 cases would have made a compelling case of the city.
Supreme Court, but that is moot now. So I think the fact that geofence warrants are associated with that investigation, that investigation being one that conservatives think was completely overzealous and right for the abuse from the Biden Justice Department, I think that's going to be a factor in the consideration of this case of the Supreme Court. Now you mentioned that it's been a long time since there's been a fourth amendment case before the Supreme Court. Would it be expected that the Court would use this as an opportunity to address, as you were saying, the need to update things when it comes to the digital world in which we live? In other words, is this an opportunity for them, in their ruling, to express broader opinions than those that are specific to this case? Does that make any sense? Yeah, there is always that chance. To an extent, we saw that in Carpenter, and we saw that to a degree in Riley versus California, where the Court says you need a warrant to search a cell phone incident to arrest, with the justification being, that was 2014, like cell phones are basically part of our anatomy now. And it contains such a wealth of information that we need to have this new understanding of how those work. I think it's going to be a little harder to get to that kind of broad, we're changing our entire jurisprudence type of thing in a case about geofence warrants. Because I think this is a unique circumstance. It's a unique type of, the warrant itself is what's unique here, not necessarily the technology. If that makes sense, it's the fact that you don't have any individualized suspicion, but that you are leveraging the fact that private companies, at least, for a time, had records of which devices were in which locations at which time. I think this case is more about the structure of these particular warrants than it is about a broad critique of the use of the Fourth Amendment and the digital age and our outdated Fourth Amendment frameworks. But I would not be surprised at all, especially in a concurrence if one of the justices chooses to opine on that question. Justice Sotomayor did in the 2012 case United States versus Jones where she talked about how we needed to reconsider the third-party doctrine, that information we voluntarily give to telecommunications companies does not merit Fourth Amendment protection and she used that case, which didn't really have to do with third-party records that much, just be like, this is my time. I'm going to opine about the third-party doctrine. I think we could see something like that here as well. All right, well, get your popcorn ready. Yeah, I mean, some of us will be sitting there for oral arguments glued to our C-SPAN images, because it's not videotaped. You hear the audio and they show you the face of the person that's talking. So I'm looking forward to that. I mean, the one other interesting element here that I hadn't mentioned is that Google changed its policies in 2023, and they do not collect the type of data they used to that allowed prosecutors, governments to obtain geofence warrants. The reason this is still a live case is even though Google has a pretty big market share in terms of location data, there are a lot of other companies that still collect that data and prosecutors might seek data from different companies that are not Google in the future. So this is still going to be a live case even though Google has changed its policy, but that could be a factor in the case as well that there might be an element of demanding the case down to the lower courts and say, please reconsider your previous decisions in light of the fact that Google has changed its practices. I don't see that as a super-likely outcome, but it's something that I could definitely see happening. What about the sort of warrantless end-around that we've seen claims that you let law enforcement are using, basically just going right to a data broker, not having a warrant, but just buying something that is freely for sale out there, which is in some cases our location data. Yep, that's a whole other question. There's not much that a criminal defendant can do about that at this point. And I think we're going to have to have statutes from Congress that protect people's personal information from data brokers in order for that to merit any type of fourth amendment protection. Because the understanding, as of now, is that the fourth amendment applies against government action. So if the government is going to the private sector and there's a voluntary transaction where they're purchasing this data, I think that's a very different question. Then most traditional fourth amendment cases where they're obtaining a subpoena to obtain third-party records from a company or they're getting a warrant to do so. All right, interesting times. Interesting times. Indeed. I'm excited. Good for you. That makes me one of us. I mean, you know, I can nerd out on this stuff to a lesser degree than you. So what I look forward to is your summary and explanation. Yeah, I mean, I feel like we've got a long way to go and you know, we're going to have oral arguments to cover and the actual decision. So we got some content ahead of us. All right. Very good. Very good. Well, I'm happy for you, Ben. All right, let's jump in and talk about my story this week. So I'm using this particular story kind of as a framework for what I hope is an interesting discussion. This is actually, I guess you'd call it an editorial piece. This is out of the Canadian Center for Policy Alternatives, which is a progressive think tank out of Canada. This is an article written by Paris Marx. And it's provocative title caught my eye. It's titled Every Data Center is a US military base. Right? Yeah. I guess it's parked up a little bit. Yeah. Yeah. And it's I think capturing the moment that we find ourselves right now where a lot of nations around the world, including our traditional allies, are finding themselves wondering to what degree is the United States of America a good faith partner anymore. And when it comes to this notion of digital sovereignty, it's a big deal. Because I'm confused Dave. Aren't they our 51st state? Canada. Yeah. I like grass. Yeah. But the point here is that the US for so long has had a leadership when it comes to technology. The big tech companies are US companies, right? Going back to IBM, Hewlett Packard, Apple, now Facebook, Microsoft. And so they have a huge amount of influence all over the world. And so both nation states and individuals worldwide have a lot of their data and a lot of their day-to-day operations are wrapped up in US companies. And so the question is, is that a good thing long term and should these countries be looking to have their data local? I mean, this is a very live question. They have a really interesting hook in this article about what happened when the US issued sanctions against the international criminal court. So those sanctions were because of the ICC's finding on Israel and its prime minister, Benjamin Netanyahu. But people who work for the international criminal court lost access to everyday digital services. And that included one of the prosecutors who works for ICC not being able to access his email because it was hosted by a US cloud service. So they can't perform their jobs because they've been sanctioned by the US government. Less do you think this is a one off? I think the context is very important here. We're having a more adversarial relationship, not just with Canada, which is the source of the story here, but with much of Europe. Europe depends on our cloud-based services and email platforms. They depend on us economically. They have dependent on us for on national security matters and cybersecurity matters. We've had a very cooperative relationship. But a lot of that has been thrown into flux. A lot of things have happened over the past year, not just the fact that we might invade Greenland and blow up the NATO charter, which would be very bad. That would probably permanently sour our diplomatic relationship with most NATO countries. But even if that doesn't happen, there have been other things that we've done, like pulling out of the five eyes, intelligence agreement, these sanctions against the international criminal court. All of our bizarre hostility against Canada and Europe when it comes to tariffs and continuing threats of tariffs if these countries don't take particular actions. In Canada's case, referring to it as our 51st state and being kind of adversarial. So I think this is a really important question [BLANK_AUDIO]
for these other countries, Canada and countries in Europe, is should they reconsider their relationship with the US and these companies, or should they turn toward having more digital sovereignty? And I think this is a live debate that's just gonna go stronger as we move through Trump 2.0. - Yeah, they talk about concerns over the US having a kill switch over their technical infrastructure. Basically, the president of the United States could just, could change his mind on something or get a bee in his bonnet about something and insist that US tech companies no longer do business with former allies. - Right, right. - I got, is that a common former allies, or traditional allies, with whom we are having a spat with, long term, short term, whatever, and now they can't do business and now is a potential huge economic concerns. I mean, just imagine any nation if they were suddenly to be cut off from Microsoft and Amazon Web Services and down to the operating systems. - Denmark doesn't know we've invaded Greenland because their, their Chrome doesn't work because we activated the Google kill switch. - Right. - Which sounds funny until-- - It's not, right. - Right. I mean, and it is, it's funny because it's so absurd that we find ourselves in this, that we have to talk about this at all. - Yeah, I mean, you never think that we'd end up here 'cause it's a relationship that's beneficial for us as the country full of innovators who started all these big companies and we've been able to sell our services and products and countries all over the world and that's made us richer. And these countries have been able to purchase these products or they're able to have these awesome services. Like it's a cool symbiotic relationship and if you would ask me, you know, even during the first Trump term, if I could foresee something like this happening where our relationship with European allies and Canada would become increasingly hostile, like it's just not something that was under consideration. - Right. - And I think it is a wake up call. I think we've talked more about this in the context of national security in NATO where these countries have been relying on our defense capabilities for all of these years and now that they have to consider the fact that they might not be able to rely on them in the future, like they have to reconsider everything. So we've seen Germany, for example, spending far more money on defense than they ever have because of this kind of implicit threat. And I think the same thing applies here. Like for the first time these companies have to think of their digital sovereignty. - Yeah. And in a way that they just were not expecting. - Mm-hmm. Yeah, and you wonder, you know, could we see European countries regulating and saying that we cannot rely on US infrastructure or products for critical functions, right? They could say that and that would be a big hit. I mean, Canada is a smaller-ish market, but if you see that replicated and other countries around the world, it would be a big hit to US companies. You know, our hostile relationship with Canada, what was the new story item this week about? They have a new deal with China on chips? - No, cars, electric cars. - Electric cars, yeah. - Which is huge. Yeah, because China is so far ahead of the rest of the world when it comes to affordable, high quality electric cars and currently you can't sell them in North America because both Canada and the US have 100% tariff on them. Canada has struck a deal with China that took to remove that 100% tariff, which means China is gonna hit the Canadian market and the US currently doesn't have anything to compete with them. And they're good cars. - Yeah, much better than our electric cars. And we've removed a lot of incentives for both the manufacturing and the purchase of electric vehicles in our country. - Right. - So yeah, I mean, that seems pretty bad. So I think it is like, even though this was about electric cars, I think there's a broader lesson here that if they can't rely on the US, do they turn toward our geopolitical adversaries? And that seems like something that we would not want, but from the perspective of these countries, do they have any other choice? - Yeah, I mean, who else can offer the same type of services that they've come to rely on from these US companies? - Right, which I think also speaks to the broader issue of, like to what degree do you shift to other nations around the world, as you say, it's shift from the US to China for supplying some things like electric cars, pretty fundamental product, versus working on spinning up your own local version of that. In other words, Canada saying, well, we can't rely on anybody. The lesson we've learned from this is that we have to be self-reliant. And when it comes to digital things, so we need to spin up our own companies or support our own companies or whatever. But we have to be prepared for the real possibility to go it alone. - Yeah, and maybe that's a better silver lining if that's the ultimate result. Like companies try and become more self-reliant. But my fear is, Canada just doesn't have the capability to spin up cloud-based computing services that don't rely on US companies in a short period of time. And so the alternative is gonna be that they're gonna buy products from China and other adversarial countries. - Right. - So, you know, and that, to me, is not a good result for us, the United States. Like it's just, it seems like an own goal in my opinion. - Right. - But again, I know a lot of people feel differently and I think there's a widespread view that these countries have taken advantage of us. Certainly that's what President Trump has said and a bunch of different contexts. But yeah, I mean, I think we're gonna start to see the consequences of that. - Yeah. - To what degree do you think matters, like the actual geographic proximity of Canada being our neighbor to the north versus Europe with an ocean between us? - You know, it matters less than it used to just because, you know, we can fly plans to Europe pretty quickly. We can communicate electronically with Europe. I think it's more that Canada has been our most stalwart ally. I mean, there used to be a presidential tradition going up until Trump's first term that a president's first diplomatic visit would always be to Canada. - Oh, is that right? I didn't know that. - Yeah, I mean, we've cooperated with them on everything going back decades, on 9/11 when international flights had to be diverted. These small towns in Canada took in planes full of US persons and took care of them before the embargo on flights ended. So I think we do have a special unique relationship with them, whether it's because of proximity, you know, I think historically it probably is because of that proximity, but yeah, I mean, it's certainly something that's being put in jeopardy now. - Yeah. All right, well, we will have a link to that story in the show notes. And of course, we would love to hear from you if there's something you'd like us to consider for the show. Please email us. It's
[email protected]. (upbeat music) (upbeat music) (upbeat music) - Maybe that's an urgent message from your CEO, or maybe it's a deep fake trying to target your business. Doppel is the AI native social engineering defense platform fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Doppel uses it to fight back from automatically dismantling cross-channel attacks to building team resilience and more. Doppel, outpacing what's next in social engineering. Learn more at Doppel.com. That's d-o-p-p-e-l.com. (upbeat music) (upbeat music) - All right, Ben, our guest this week is Brian McGinnis, partner at Barnes and Thornburg, LLP, and the conversation centers on youth protection and data privacy and the Federal Trade Commission. (upbeat music) - AI, I would say, has been a pretty fundamental change for any kind of collection and use of data and certainly has moved the needle for legal considerations. And within that you've got AI laws, privacy laws, children's protection law, general personal information laws, consumer laws, et cetera, that we can dig into further. But the advent of AI is in particular, I think going to have a huge and already has started to have a huge impact on children in the collection of data. I mean, so in the US, as you know, we've generally lag behind the rest of the world [BLANK_AUDIO]
to laws regarding the collection in use and sharing of people's information. We've started to catch up here in the last 10 years or so or less and continue to do so with a whole host of new laws that are aimed at giving people more notice providing further transparency about the collection and use of their data. But children's data, another sensitive data types like healthcare, underhippah, and financial regulations around financial data, et cetera, have been considered historically more sensitive information. They get a higher level of protection. So, Kapa, for a while, we've been under that law protecting children's information, but that thing is getting as great as I am these days. It's about 27 years old, I think. And so you're dealing with a law that was passed, honestly, in a different age and a different era, trying to account for and keep up with technology as it continues to evolve. And presumably, it still protect children. Now, obviously that's the primary goal of this law, but it's a little bit outdated and certainly was passed in a time when we didn't have as many technological considerations as we have now. So you've got AI coming along and that, I think, is further accelerating the changes, further accelerating the difficulties in trying to continue to apply this old law to these new technologies. And it's become pretty clear that we need a new path, we need some new laws. So you've got updates to that law, you've got state laws coming in that are trying to protect that. But one of the big things it's doing is really moving away from a world where we are relying entirely on sort of people saying what they're going to collect and getting consent to collect these things and moving much more towards an era where in the background, the technology is able to do a lot more things that it just wasn't capable of doing previously, right? So you're talking about inferences from activity that users are doing, whether it's an online game or software or something like that. You can now infer a lot of things about the user that you simply couldn't before that results in ultimately the collection of additional data about children that we just never had to worry about before. So really a fundamental shift in a whole new world that we're entering. So just to hone in on Kappa a little bit, the issue is it's built as a structure where people report the data that they are collecting. And now we're in an era where AI is collecting the data and there's really nothing for actual human beings or organizations to report is that kind of the general issue with Kappa? - Yeah, I think the laws are trying to shine a light on and challenge the idea that there is nothing to report. The idea is there are things that are being collected that are using in ways that people probably don't understand. And the old model of basically disclose, here's the sort of the primary pieces of data that we're gonna collect about an individual, a name and email address, a birth date and address to mail them something and getting parental consent to do that to a world where you've got all these technologies operating in the background to collect information that can be used to identify that this person, this user is a child or a particular characteristics about that individual in ways that certainly parents and most of the children using these platforms don't really understand. So you've really moved away from that direct sort of one-to-one I get what you're collecting to a world where we've got technology collecting all sorts of things being used in ways that we probably don't really understand fully yet where that value is and that'll continue only to spin out unless we've got some laws that provide some additional protections to require more disclosure of that and put more of an onus on the companies or individuals that are collecting that data to do more to assess what kind of data they are truly collecting beyond the sort of exes and oes of things that you would put into a form box or something like that. - Before we get into what the private sector can do, obviously we've been waiting decades for a federal data privacy law. I think I'll go fully gray and even boulder by the time that happens. - It's coming soon. I've been assured of that for 10 plus years at this point. - Absolutely. Can you talk a little bit about what states have done in this space and if any states have taken the lead on protecting this type of data? And then if that can work in a world in which companies have to comply with this kind of patchwork of state laws. - Yeah, I think it can. So what it does is essentially create a vacuum in the absence of a federal law, privacy law, AI laws now, children's protection laws that are outdated that states want to fill, right? And when you're talking about more sensitive data points like children's data, I don't think it's hard to find much support to say, yeah, we probably should be doing a better job of protecting our children against misuses of their information. At the same time, you've got, again, this increase in technology, when we are growing up, the technological landscape looked a little bit different than it does now, the number of apps that are out there, the number of services, now you've got teen subbending some pretty serious time talking with chat bots, for example, disclosing some pretty sensitive information about themselves that they wouldn't want to disclose, otherwise in some real world impacts coming as a result of unauthorized disclosure of those kinds of things. So the states are stepping up and saying, well, if you're not going to give us a federal law, we're going to pass our own law. In principle, that's great. It gives protections at least in that state that are at a much higher level than individuals would otherwise have. The problem is for platform developers, software developers, app developers, game developers, et cetera, it becomes really, really complex to be able to comply with that. So a lot of my practices really helping companies who want to do the right thing, try and figure out, okay, there's this patchwork of state laws out here in addition to federal stuff that touches on this and addition to international considerations. How do we do the right thing here? How do we navigate through this? How do we show that we care about protecting these people? But just even if you want to, and even if you've got an unlimited budget, it can be really difficult to really navigate that successfully. So you've got a number of states in New York, Maryland, California have all passed some laws that are specifically targeted to the protection of children's information. There's a handful of other states as well doing things along the lines of AI protections and age verifications, data broker registration, things like this. And then one of the other things that we're really seeing that I think is really a best practice in a trend is bumping the age up historically in this country because of copper, we've really considered the children to really be those who are under the age of 13. What that miss is, of course, is that age or those ages between 13 and really 18 of a whole group of teens who are heavily on their phones, heavily user, heavy users of technology these days. And they're historically in this country has a bit of protections for them. And so that's another gap that both state and federal laws are looking to fill, which is how do we account for these age groups? And I've got kids of my own. And it's really disparate when you're talking about a 13-year-old versus a 17-year-old. They go through a lot of changes in those years, right, too. So we're seeing these laws even further break that down. Age 13 to 15 being treated differently than 16 and 17-year-olds, for example, Apple, Google, other app stores are being required to revamp their age ratings so that it has more teeth in terms of making putting the responsibility on the app developers to really categorize their apps appropriately, according to the data that they're going to collect based on age. And then putting restrictions on the uses of those ages, those kinds of things, are really filling the gap here in a lack of a privacy law. So let's get kind of dig down and get a little bit more granular when we get into the private sector. So start big picture with the big tech companies. What kind of data minimization do you think they could do to help alleviate this problem a little bit, to prevent the mass collection of data and the use of artificial intelligence? Yeah. I mean, I would start with the data collection is a choice, almost always, and people are putting tools in place that collect the data that they collect. For the longest time, we have operated under the, we need to collect more, what more can we collect? If I collect this additional data set, then I can get more information about this person that makes me basically a more effective advertiser, makes my data set more valuable. I can sell it for more money and therefore I can make more money as a company. When you're talking about sensitive data though, when you're talking about children's data, you really need a whole other set of considerations, I would say, for that. And it's really not what can we collect, but what should we collect? And I think starting from a blank piece of paper and only collecting those data points that you have to collect in order to provide the service or the platform is really the strategy that should be employed here. Now, that's a completely different set of considerations if you're building an app who's generally targeting adults or older folks and happen to collect some information about a couple, teenagers who might be interested in using your product, then it is for those companies that are specifically being built for children. Obviously, they're going to collect a lot more, but then by nature, that company either going to hopefully take more steps to make sure that they're doing that in a compliant way and a way that respects the sensitivity of that data of those individuals. But really keeping a close eye on it, understanding
what data you're collecting. I can't tell you how many clients I work with who, whether it's the marketing tools or the companies that they're working with or the partners or the business teams. There's so many opportunities out there. There's so many people selling into the data collection sort of world and business to choose from to get them to pause and stop and say, okay, maybe we could get more, but in this case, we're gonna choose not to collect additional information. We're gonna limit the data that we collect maybe because that's sensitive information about a child and really put in place a set of principles within our businesses as we're only gonna collect information about children under these circumstances. We're gonna minimize the data we collect to the bare minimum to protect the individual, protect the child and make sure that that data doesn't get into the wrong hands one day that can negatively affect them, make sure it's not being used to make decisions about them, et cetera. So there's a lot of protections you can put in place, but it really starts with making sure you're only collecting the minimum amount of data that you need in order to accomplish the goal. - Is that scalable organization to organization? Does the advice differ for your larger clients versus smaller organizations that might not have the same type of resources? Or is that not something you've really seen so far? - I mean, it can. I wouldn't say that's the biggest divider. I mean, the bigger divider is what are we trying to do here? What type of business is this? Is this an online only company that's collecting a bunch of consumer information or is this a traditional manufacturer, B2B company, et cetera? But the size does matter in the sense that the compliance efforts as you collect more data get heavier, get more involved, and require more and therefore require more cost. So if you are a small company, I don't think the answer is we don't have the money to comply with these laws. It's how do we collect the minimum amount of data necessary so we don't have to deal with compliance with a lot of these laws because we've gotten out of it through things like privacy by design and data minimization. So there's certainly strategies, smaller companies as they grow can put into place that alleviate a lot of these legal hassles that the bigger companies get into by nature, the fact that they're serving so many more people. - We've seen states propose laws and they've run into some constitutional issues around age verification. You talk a little bit about that, and if that's something you would try to avoid, like if we can get to a place where we're protecting data, especially youth data without requiring the type of arduous age verification process that involves uploading your drivers license. Can you just discuss that a little bit? - Yeah, I mean, one of our core principles when you're thinking about things like responding to data subject requests under privacy laws where they're reaching out to request deletion of their data or copy of what data you've collected about them under the various privacy laws is don't collect new information from an individual in order to provide that verification. So when you've got laws that are really, like you said, collecting driver's licenses, passports, those kinds of things, you know, requiring additional information, like parental information, you know, we can think of a scenario where it would be to the child's disadvantage to have to tell their parent about something that they're doing online or want to do, et cetera. It becomes tricky, right? So those are issues that, you know, I think that we need to have those conversations, but have them in a way that's keeping the ultimate goal of mind, which is how do we provide more protection for these individuals? I think the answer is really putting more responsibility onto the platforms and taking it off of the individual as much as we can. So much of the online world has been set up such that it's like, you know, if I, the old days anyway, if I put some kind of a notice in my, you know, two point privacy policy and tuck it away in a corner of my website somewhere, I can effectively collect and do whatever I want to do because I've provided notice. That puts all the responsibility onto the individual to read every single one of those privacy policies and despite the fact that I spend a lot of time writing those, I imagine maybe not everybody reads them as much as I do. Yeah, exactly. That's very real. So, you know, that's kind of the old way of doing things, but putting more responsibility on the apps and the people who want to collect this data to put in place, you know, certain precautions and procedures to make it less likely that they're not collecting a bunch of data that they really don't have any need for and aren't really capable of ensuring that it gets protected and secured is important. So there's a balance in there somewhere. You know, collecting official government documents is a bit tricky. So maybe we can find some ways and design some ways around that. But then, you know, again, if that is, if that process is controlled not by the individual, but by the much smaller number of, let's say vendors or operators or developers, and for example, you can handle verification via one app store for all of the apps that you download. Now you're only giving your driver's license to or parental consent or whatever sensitive data point to that app store who then controls it for all the other apps. That's better than a bunch of, you know, startup apps who now all have that same information and most of whom are probably prepared to protect it at the same level as the bigger companies, I think that's probably the solution. - And then just to kind of close things out here, how do you effectuate that culture change in organizations? I think a lot of companies are bottom line driven, they'll say, yeah, what you're saying is great, but I don't want to compromise functionality and it's hard to do the type of work that you're advocating. So how do you kind of change that culture? What are your key messages? - Yeah, I mean, you've really hit on something that is a very real problem within the companies that I work with, right? Their goal is to build a brand, build the company, build up ultimately revenue, and a lot of these privacy restrictions can go against that. One of the things that we work a lot with companies on is, you know, we're not going away from this. I think the restrictions or regulations are only gonna continue to tighten, whether that's privacy, AI, children's data, et cetera. We're in the early stages still in this country of really regulating that data. So that's the future, that's where things are heading. If we're going to have to get there ultimately, why not start now and why not do it in a way where we kind of get credit for the compliance that we're doing? So instead of, you know, treating privacy compliance or children's data, compliance is the eating your vegetable situation, get out there, do it, do a good job of it, and then use it as a marketing tactic or part of your marketing strategy. Obviously you have to be good at it, you have to be authentic in that, but if you're a company that really does care about this, if you're a company that has really taken this into account and wants to protect users, especially some of the more vulnerable users, you can, you know, really carve out a market position by doing that. So I think getting the buy-in from the top of, we are a company that wants to do right, we are the kind of company who does things in this way. I think it really ultimately serves to enforce the company's brand and reputation and standing can really drive business as opposed to just being a cost center. So getting that ultimate buy-in is just really critical in helping drive the company in that direction and then doing a good job of all these protection things as they come along and then looking down into the road to see where the future is heading with the increase in laws that we're going to have here. And then of course, that's, I guess, more of the carrot approach, the stick, is another area that I see increasing and that's on enforcement. So we're still in early days, I would say, of all of these laws coming about. There's been a bit of a period of allowing companies some time to get compliant and to account for these things within their business practices, but we are already seeing an increase in the enforcement of these laws. I think we've got a lot of the tools that we need really to ensure that the market is taking account of the sensitivity of people's information, giving them more choices in the use of their information. So that continuation of enforcement, the more the number of fines, the more somebody else in your industry, one of your competitors get hit with one of these things. The more I have conversations with clients about, I don't want that to happen to us. What do we need to do now to make sure that it doesn't? So if that's the way we need to get there, that's fine too, I think, so long as we get to the ultimate goal, which is making sure people have more control over the use of their information. (upbeat music) - Well, thank you so much, Brian, for joining us and for this. - Yeah. I think really insightful conversation. - Yeah, it was a lot of fun, appreciate you having me. Thanks, guys. - And again, our thanks to Brian McGinnis from Barnes and Thornburg for joining us. We do appreciate him sharing his expertise. (upbeat music) (upbeat music) - And that is our show brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to
[email protected]. This episode is produced by Liz Stokes. Our executive producer is Jennifer Iben. The show is mixed by Train Hester. Peter Kielpie is our publisher. I'm Dave Bittner and I'm Ben Yellen. Thanks for listening. (upbeat music)