Jan 2, 2019 · 35m · a16z

a16z Podcast | What to Know about GDPR

Lisa Hawk · 20m spoken Steven Sinofsky · 12m spoken Sonal Chokshi · 41s spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of the a16z Podcast, Steven Sinofsky and Everlaw's VP of Security and Compliance Lisa Hawk unpack the broad jurisdictional scope, operational implications, and practical engineering requirements of the European Union's General Data Protection Regulation (GDPR) for global tech startups.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. The host holds 2.1% of the talking time here. How this is scored →

The host as informed peer 5.1 Guest teaching 4.3 Guest disagreement 1.2 The host pushing back 1.8
05100:0010:0020:0030:001:05–4:42 · The host as informed peer 5/10 Jurisdictional Reach and Regulatory Scope of GDPR Steven asks whether GDPR's broad scope makes Europe harder to do business in for US companies. Lisa counters that European regulators view it as consolidating 28 member states' laws into a single digital market standard. Steven adapts, noting how compliance can serve as a market differentiator for nimble startups.4:42–8:29 · The host as informed peer 4/10 Data Controllers vs. Data Processors Defined Lisa defines data controllers and processors with concrete examples, noting how a single business can be both. Steven offers expert context comparing GDPR liability chain concepts to US third-party vendor law.8:29–13:16 · The host as informed peer 7/10 Scope of Personal Data and Anonymization Limits Steven demonstrates deep technical and industry knowledge by discussing machine learning data triangulation, Apple's privacy approach, and the 1990s Lotus Marketplace case. Lisa clarifies the regulatory boundaries of full anonymization versus pseudonymization under GDPR.13:16–15:38 · The host as informed peer 5/10 US Business Exposure to EU Privacy Standards Lisa outlines how US software companies inadvertently fall under GDPR via website targeting or EU employees. Steven adds the insight of viral enterprise growth where US clients bring in EU team members.15:38–18:59 · The host as informed peer 6/10 Core Rights Granted to Individual Data Subjects Steven compares data access rights to US credit reporting mechanisms, noting European regulations learned from past flaws. He also highlights the unique right to demand human review of algorithmic automated decisions.18:59–21:50 · The host as informed peer 5/10 Embedding Privacy by Design into Engineering Steven links privacy by design to software engineering's 'secure by design' framework. Lisa outlines practical software design decisions that incorporate default privacy settings for development teams.21:50–25:28 · The host as informed peer 5/10 Fines, Penalties, and Regulatory Enforcement Lisa clarifies that Article 83 treats fines as a last resort and focuses on intent and negligence, dispelling media fearmongering over 4% turnover fines. Steven draws parallels between 72-hour breach notification rules and IT operational incident management.25:28–27:31 · The host as informed peer 5/10 Creating an Organizational Culture of Compliance Lisa shares lessons from her previous compliance career regarding the importance of a 'speak up' culture to catch issues early. Steven reflects on his early software career when security shifted from a side thought to a fundamental cultural requirement.27:31–30:31 · The host as informed peer 5/10 Cloud vs. On-Premise Software and Certification Myths Lisa debunks the myth of third-party GDPR certifications, clarifying that GDPR is a law without official certification bodies. Steven warns listeners against paying high consultant fees for fake certifications.30:31–32:44 · The host as informed peer 4/10 Practical Data Inventory and Mapping Spreadsheet Tool Lisa details her practical spreadsheet tool for conducting internal data mapping and risk assessments. Steven reinforces the necessity of auditing specific data fields and SaaS tool pass-offs across departments.1:05–4:42 · Guest teaching 4/10 Jurisdictional Reach and Regulatory Scope of GDPR Steven asks whether GDPR's broad scope makes Europe harder to do business in for US companies. Lisa counters that European regulators view it as consolidating 28 member states' laws into a single digital market standard. Steven adapts, noting how compliance can serve as a market differentiator for nimble startups.4:42–8:29 · Guest teaching 5/10 Data Controllers vs. Data Processors Defined Lisa defines data controllers and processors with concrete examples, noting how a single business can be both. Steven offers expert context comparing GDPR liability chain concepts to US third-party vendor law.8:29–13:16 · Guest teaching 4/10 Scope of Personal Data and Anonymization Limits Steven demonstrates deep technical and industry knowledge by discussing machine learning data triangulation, Apple's privacy approach, and the 1990s Lotus Marketplace case. Lisa clarifies the regulatory boundaries of full anonymization versus pseudonymization under GDPR.13:16–15:38 · Guest teaching 4/10 US Business Exposure to EU Privacy Standards Lisa outlines how US software companies inadvertently fall under GDPR via website targeting or EU employees. Steven adds the insight of viral enterprise growth where US clients bring in EU team members.15:38–18:59 · Guest teaching 4/10 Core Rights Granted to Individual Data Subjects Steven compares data access rights to US credit reporting mechanisms, noting European regulations learned from past flaws. He also highlights the unique right to demand human review of algorithmic automated decisions.18:59–21:50 · Guest teaching 4/10 Embedding Privacy by Design into Engineering Steven links privacy by design to software engineering's 'secure by design' framework. Lisa outlines practical software design decisions that incorporate default privacy settings for development teams.21:50–25:28 · Guest teaching 5/10 Fines, Penalties, and Regulatory Enforcement Lisa clarifies that Article 83 treats fines as a last resort and focuses on intent and negligence, dispelling media fearmongering over 4% turnover fines. Steven draws parallels between 72-hour breach notification rules and IT operational incident management.25:28–27:31 · Guest teaching 4/10 Creating an Organizational Culture of Compliance Lisa shares lessons from her previous compliance career regarding the importance of a 'speak up' culture to catch issues early. Steven reflects on his early software career when security shifted from a side thought to a fundamental cultural requirement.27:31–30:31 · Guest teaching 5/10 Cloud vs. On-Premise Software and Certification Myths Lisa debunks the myth of third-party GDPR certifications, clarifying that GDPR is a law without official certification bodies. Steven warns listeners against paying high consultant fees for fake certifications.30:31–32:44 · Guest teaching 4/10 Practical Data Inventory and Mapping Spreadsheet Tool Lisa details her practical spreadsheet tool for conducting internal data mapping and risk assessments. Steven reinforces the necessity of auditing specific data fields and SaaS tool pass-offs across departments.1:05–4:42 · Guest disagreement 2/10 Jurisdictional Reach and Regulatory Scope of GDPR Steven asks whether GDPR's broad scope makes Europe harder to do business in for US companies. Lisa counters that European regulators view it as consolidating 28 member states' laws into a single digital market standard. Steven adapts, noting how compliance can serve as a market differentiator for nimble startups.4:42–8:29 · Guest disagreement 1/10 Data Controllers vs. Data Processors Defined Lisa defines data controllers and processors with concrete examples, noting how a single business can be both. Steven offers expert context comparing GDPR liability chain concepts to US third-party vendor law.8:29–13:16 · Guest disagreement 1/10 Scope of Personal Data and Anonymization Limits Steven demonstrates deep technical and industry knowledge by discussing machine learning data triangulation, Apple's privacy approach, and the 1990s Lotus Marketplace case. Lisa clarifies the regulatory boundaries of full anonymization versus pseudonymization under GDPR.13:16–15:38 · Guest disagreement 1/10 US Business Exposure to EU Privacy Standards Lisa outlines how US software companies inadvertently fall under GDPR via website targeting or EU employees. Steven adds the insight of viral enterprise growth where US clients bring in EU team members.15:38–18:59 · Guest disagreement 1/10 Core Rights Granted to Individual Data Subjects Steven compares data access rights to US credit reporting mechanisms, noting European regulations learned from past flaws. He also highlights the unique right to demand human review of algorithmic automated decisions.18:59–21:50 · Guest disagreement 1/10 Embedding Privacy by Design into Engineering Steven links privacy by design to software engineering's 'secure by design' framework. Lisa outlines practical software design decisions that incorporate default privacy settings for development teams.21:50–25:28 · Guest disagreement 1/10 Fines, Penalties, and Regulatory Enforcement Lisa clarifies that Article 83 treats fines as a last resort and focuses on intent and negligence, dispelling media fearmongering over 4% turnover fines. Steven draws parallels between 72-hour breach notification rules and IT operational incident management.25:28–27:31 · Guest disagreement 1/10 Creating an Organizational Culture of Compliance Lisa shares lessons from her previous compliance career regarding the importance of a 'speak up' culture to catch issues early. Steven reflects on his early software career when security shifted from a side thought to a fundamental cultural requirement.27:31–30:31 · Guest disagreement 2/10 Cloud vs. On-Premise Software and Certification Myths Lisa debunks the myth of third-party GDPR certifications, clarifying that GDPR is a law without official certification bodies. Steven warns listeners against paying high consultant fees for fake certifications.30:31–32:44 · Guest disagreement 1/10 Practical Data Inventory and Mapping Spreadsheet Tool Lisa details her practical spreadsheet tool for conducting internal data mapping and risk assessments. Steven reinforces the necessity of auditing specific data fields and SaaS tool pass-offs across departments.1:05–4:42 · The host pushing back 3/10 Jurisdictional Reach and Regulatory Scope of GDPR Steven asks whether GDPR's broad scope makes Europe harder to do business in for US companies. Lisa counters that European regulators view it as consolidating 28 member states' laws into a single digital market standard. Steven adapts, noting how compliance can serve as a market differentiator for nimble startups.4:42–8:29 · The host pushing back 2/10 Data Controllers vs. Data Processors Defined Lisa defines data controllers and processors with concrete examples, noting how a single business can be both. Steven offers expert context comparing GDPR liability chain concepts to US third-party vendor law.8:29–13:16 · The host pushing back 2/10 Scope of Personal Data and Anonymization Limits Steven demonstrates deep technical and industry knowledge by discussing machine learning data triangulation, Apple's privacy approach, and the 1990s Lotus Marketplace case. Lisa clarifies the regulatory boundaries of full anonymization versus pseudonymization under GDPR.13:16–15:38 · The host pushing back 2/10 US Business Exposure to EU Privacy Standards Lisa outlines how US software companies inadvertently fall under GDPR via website targeting or EU employees. Steven adds the insight of viral enterprise growth where US clients bring in EU team members.15:38–18:59 · The host pushing back 2/10 Core Rights Granted to Individual Data Subjects Steven compares data access rights to US credit reporting mechanisms, noting European regulations learned from past flaws. He also highlights the unique right to demand human review of algorithmic automated decisions.18:59–21:50 · The host pushing back 1/10 Embedding Privacy by Design into Engineering Steven links privacy by design to software engineering's 'secure by design' framework. Lisa outlines practical software design decisions that incorporate default privacy settings for development teams.21:50–25:28 · The host pushing back 2/10 Fines, Penalties, and Regulatory Enforcement Lisa clarifies that Article 83 treats fines as a last resort and focuses on intent and negligence, dispelling media fearmongering over 4% turnover fines. Steven draws parallels between 72-hour breach notification rules and IT operational incident management.25:28–27:31 · The host pushing back 1/10 Creating an Organizational Culture of Compliance Lisa shares lessons from her previous compliance career regarding the importance of a 'speak up' culture to catch issues early. Steven reflects on his early software career when security shifted from a side thought to a fundamental cultural requirement.27:31–30:31 · The host pushing back 2/10 Cloud vs. On-Premise Software and Certification Myths Lisa debunks the myth of third-party GDPR certifications, clarifying that GDPR is a law without official certification bodies. Steven warns listeners against paying high consultant fees for fake certifications.30:31–32:44 · The host pushing back 1/10 Practical Data Inventory and Mapping Spreadsheet Tool Lisa details her practical spreadsheet tool for conducting internal data mapping and risk assessments. Steven reinforces the necessity of auditing specific data fields and SaaS tool pass-offs across departments.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 24.6% · guest 75.4%0:00 · the host 24.6% · guest 75.4%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%24:00 · the host 0% · guest 100%24:00 · the host 0% · guest 100%27:00 · the host 0% · guest 100%27:00 · the host 0% · guest 100%30:00 · the host 0% · guest 100%30:00 · the host 0% · guest 100%33:00 · the host 0% · guest 100%33:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 3:09 Reframing regulatory burden as market advantage

When Steven suggests that GDPR makes doing business in Europe harder for US companies, Lisa explicitly reframes the premise by explaining that Europeans view it as unifying 28 distinct state regulatory regimes into a single digital market.

Hardest push from the host ▶ 11:39 Testing the technical limits of data anonymization

Steven pushes back on the assumption that technical anonymization provides a simple escape route from GDPR, raising machine learning triangulation and historical precedent like the Lotus Marketplace case.

Biggest teaching moment ▶ 1:19 Explaining universal long-arm jurisdiction

Lisa educates Steven and the audience on legal long-arm jurisdiction, explaining how EU law asserts global authority over any business anywhere processing EU subject data.

The host holds their own ▶ 11:39 Citing historical tech precedents and ML triangulation

Steven demonstrates significant domain authority by bringing up Apple's differential privacy model, machine learning re-identification, and the 1990s Lotus Marketplace census data privacy controversy.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Jurisdictional Reach and Regulatory Scope of GDPR 5423 Steven asks whether GDPR's broad scope makes Europe harder to do business in for US companies. Lisa counters that European regulators view it as consolidating 28 member states' laws into a single digital market standard. Steven adapts, noting how compliance can serve as a market differentiator for nimble startups.
Data Controllers vs. Data Processors Defined 4512 Lisa defines data controllers and processors with concrete examples, noting how a single business can be both. Steven offers expert context comparing GDPR liability chain concepts to US third-party vendor law.
Scope of Personal Data and Anonymization Limits 7412 Steven demonstrates deep technical and industry knowledge by discussing machine learning data triangulation, Apple's privacy approach, and the 1990s Lotus Marketplace case. Lisa clarifies the regulatory boundaries of full anonymization versus pseudonymization under GDPR.
US Business Exposure to EU Privacy Standards 5412 Lisa outlines how US software companies inadvertently fall under GDPR via website targeting or EU employees. Steven adds the insight of viral enterprise growth where US clients bring in EU team members.
Core Rights Granted to Individual Data Subjects 6412 Steven compares data access rights to US credit reporting mechanisms, noting European regulations learned from past flaws. He also highlights the unique right to demand human review of algorithmic automated decisions.
Embedding Privacy by Design into Engineering 5411 Steven links privacy by design to software engineering's 'secure by design' framework. Lisa outlines practical software design decisions that incorporate default privacy settings for development teams.
Fines, Penalties, and Regulatory Enforcement 5512 Lisa clarifies that Article 83 treats fines as a last resort and focuses on intent and negligence, dispelling media fearmongering over 4% turnover fines. Steven draws parallels between 72-hour breach notification rules and IT operational incident management.
Creating an Organizational Culture of Compliance 5411 Lisa shares lessons from her previous compliance career regarding the importance of a 'speak up' culture to catch issues early. Steven reflects on his early software career when security shifted from a side thought to a fundamental cultural requirement.
Cloud vs. On-Premise Software and Certification Myths 5522 Lisa debunks the myth of third-party GDPR certifications, clarifying that GDPR is a law without official certification bodies. Steven warns listeners against paying high consultant fees for fake certifications.
Practical Data Inventory and Mapping Spreadsheet Tool 4411 Lisa details her practical spreadsheet tool for conducting internal data mapping and risk assessments. Steven reinforces the necessity of auditing specific data fields and SaaS tool pass-offs across departments.

Statements from this episode (17)

Assertion Partly supported
Hawk: GDPR applies to any global company processing EU personal data
“Well, in legal terms, there's a thing called long-arm jurisdiction, and this is probably one of the longest of the long-arm jurisdictions, and what I mean by that is a situation where a local court can actually assert jurisdiction over someone in another state…”
Lisa Hawk Jan 2, 2019 ▶ 1:20
Insight
Sinofsky: Startups have a major advantage over big companies in GDPR compliance
“Yeah, I really agree with that, because, like, when you're at a big company, and you're hit with GDPR, like, you, I know exactly how this is going to work. Like, you've got all the subsidiaries, and you know, too. Well, you're paralyzed, because you have to, y…”
Steven Sinofsky Jan 2, 2019 ▶ 4:16
Assertion Not checkable as stated
Hawk: EU regulators are prioritizing transparency above all GDPR principles
“And with the data protection principles under GDPR, the one that I've heard the regulators focusing on the most is transparency. So they are putting a huge amount of work in the making sure individual citizens in Europe understand that they have the right to k…”
Lisa Hawk Jan 2, 2019 ▶ 7:14
Prediction Not checkable as stated
Sinofsky: Individual citizens will drive bottom-up enforcement of GDPR compliance
“Ultimately, I think what's going to happen is that when it comes time for there to be complaints or problems, what I think the EU regulators are sort of counting on is that there'll be a bottom-up view, and like, people will sort of police this on behalf of th…”
Steven Sinofsky Jan 2, 2019 ▶ 7:39
Assertion Supported
Hawk: Fully anonymized data is exempt from GDPR regulations
“There is one escape route from GDPR, which is the provision in the regulation, which is also the same as the 95 directive, which says that data that are fully anonymized, meaning that no individuals can be identified are outside, outside the scope of GDPR. So …”
Lisa Hawk Jan 2, 2019 ▶ 10:56
Assertion Supported
Hawk: Over 80% of US population re-identifiable with three data points
“I think there's a stat out there that says that over 80 or 85% of the U.S. Population can be identified with three pieces of data.”
Lisa Hawk Jan 2, 2019 ▶ 12:20
Insight
Sinofsky: Companies should adopt EU privacy rules as global baseline
“The US just chose not to make laws and regulations that are nearly as all encompassing as these EU ones. But often what happens is it's just better to just pick that as the standard by which to do, because it's the higher bar to the higher threshold.”
Steven Sinofsky Jan 2, 2019 ▶ 14:54
Prediction Not checkable as stated
Sinofsky: EU regulators will inspect operational implementation of GDPR rights
“So I think they're going to look at the implementation of these as well as whether or not that you have them.”
Steven Sinofsky Jan 2, 2019 ▶ 17:05
Assertion Supported
Sinofsky: GDPR explicitly details penalties despite vague engineering requirements
“As vague as the GDPR might appear to an engineer in some places, it got very specific very quickly on penalties.”
Steven Sinofsky Jan 2, 2019 ▶ 21:41
Assertion Supported
Hawk: GDPR fines are a last resort after investigations and corrective actions
“Well, I have to say, I do recommend that folks take a look at it, because working backwards from there, they actually tell you what they care about when they're going to potentially assess a fine, which is, you know, is there negligence? Was it intentional? So…”
Lisa Hawk Jan 2, 2019 ▶ 22:26
Insight
Sinofsky: Startups must treat data breaches like server downtime with response runbooks
“So I think that, that, you know, for any startup, a key thing is there's probably a good chance that, that the company has a process around the service going down, and the reality is they need the same kind of checklist, process, call list, pagers, alerts, in …”
Steven Sinofsky Jan 2, 2019 ▶ 23:59
Disclosure
Hawk: A culture of silence led to a deferred prosecution agreement
“I've been on the receiving end of a deferred prosecution agreement, largely relating to a cultural issue around not reporting things and sort of being scared to report things, and I can absolutely say You know, without reservation, that that is not where you w…”
Lisa Hawk Jan 2, 2019 ▶ 26:08
Insight
Sinofsky: Any software with user login collects private data
“A good rule of thumb is if you can sign on to your product, Then you're collecting private information, because you have that key, and then everything associated with it is private.”
Steven Sinofsky Jan 2, 2019 ▶ 28:24
Assertion Supported
Hawk: No official GDPR certification exists despite consultant claims
“GDPR is a regulation, and right now there is no certification for it. The regulation does have language around certification in it, but nothing's actually been developed. It's referenced, but it's not developed.”
Lisa Hawk Jan 2, 2019 ▶ 28:52
Opinion
Hawk: Startups do not need expensive consultants for GDPR compliance
“Startups can do it themselves. I think they have a lot of smart people. There are tools out there that you can use. Eventually you will need a lawyer to draft some contracts, but I do think there are practical things you can do without engaging a really expens…”
Lisa Hawk Jan 2, 2019 ▶ 29:48
Prediction Not checkable as stated
Sinofsky: Companies will be shocked by hidden data privacy risk
“And I think everybody's going to be shocked at just how much potential there is for risk that they weren't really thinking about.”
Steven Sinofsky Jan 2, 2019 ▶ 32:36
Insight
Hawk: Startups should appoint detail-oriented risk sentinels to lead GDPR compliance
“If you're at a smaller company and you need somebody to lead your GDPR compliance project, then, and you don't have a, you know, person in charge of compliance, then my advice is to look for what I think of as your risk sentinel. ... You want the people who ca…”
Lisa Hawk Jan 2, 2019 ▶ 33:08
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.