Jan 2, 2019 · 35m · a16z
a16z Podcast | What to Know about GDPR
gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions
In this episode of the a16z Podcast, Steven Sinofsky and Everlaw's VP of Security and Compliance Lisa Hawk unpack the broad jurisdictional scope, operational implications, and practical engineering requirements of the European Union's General Data Protection Regulation (GDPR) for global tech startups.
How this conversation actually went
Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. The host holds 2.1% of the talking time here. How this is scored →
speaking balance: gold is the host, purple is the guest (3 minute bins)
When Steven suggests that GDPR makes doing business in Europe harder for US companies, Lisa explicitly reframes the premise by explaining that Europeans view it as unifying 28 distinct state regulatory regimes into a single digital market.
Hardest push from the host ▶ 11:39 Testing the technical limits of data anonymizationSteven pushes back on the assumption that technical anonymization provides a simple escape route from GDPR, raising machine learning triangulation and historical precedent like the Lotus Marketplace case.
Biggest teaching moment ▶ 1:19 Explaining universal long-arm jurisdictionLisa educates Steven and the audience on legal long-arm jurisdiction, explaining how EU law asserts global authority over any business anywhere processing EU subject data.
The host holds their own ▶ 11:39 Citing historical tech precedents and ML triangulationSteven demonstrates significant domain authority by bringing up Apple's differential privacy model, machine learning re-identification, and the 1990s Lotus Marketplace census data privacy controversy.
the scores for every segment, with the reasoning behind each
| Chapter | Topic | The host as informed peer | Guest teaching | Guest disagreement | The host pushing back | Why |
|---|---|---|---|---|---|---|
| Jurisdictional Reach and Regulatory Scope of GDPR | 5 | 4 | 2 | 3 | Steven asks whether GDPR's broad scope makes Europe harder to do business in for US companies. Lisa counters that European regulators view it as consolidating 28 member states' laws into a single digital market standard. Steven adapts, noting how compliance can serve as a market differentiator for nimble startups. | |
| Data Controllers vs. Data Processors Defined | 4 | 5 | 1 | 2 | Lisa defines data controllers and processors with concrete examples, noting how a single business can be both. Steven offers expert context comparing GDPR liability chain concepts to US third-party vendor law. | |
| Scope of Personal Data and Anonymization Limits | 7 | 4 | 1 | 2 | Steven demonstrates deep technical and industry knowledge by discussing machine learning data triangulation, Apple's privacy approach, and the 1990s Lotus Marketplace case. Lisa clarifies the regulatory boundaries of full anonymization versus pseudonymization under GDPR. | |
| US Business Exposure to EU Privacy Standards | 5 | 4 | 1 | 2 | Lisa outlines how US software companies inadvertently fall under GDPR via website targeting or EU employees. Steven adds the insight of viral enterprise growth where US clients bring in EU team members. | |
| Core Rights Granted to Individual Data Subjects | 6 | 4 | 1 | 2 | Steven compares data access rights to US credit reporting mechanisms, noting European regulations learned from past flaws. He also highlights the unique right to demand human review of algorithmic automated decisions. | |
| Embedding Privacy by Design into Engineering | 5 | 4 | 1 | 1 | Steven links privacy by design to software engineering's 'secure by design' framework. Lisa outlines practical software design decisions that incorporate default privacy settings for development teams. | |
| Fines, Penalties, and Regulatory Enforcement | 5 | 5 | 1 | 2 | Lisa clarifies that Article 83 treats fines as a last resort and focuses on intent and negligence, dispelling media fearmongering over 4% turnover fines. Steven draws parallels between 72-hour breach notification rules and IT operational incident management. | |
| Creating an Organizational Culture of Compliance | 5 | 4 | 1 | 1 | Lisa shares lessons from her previous compliance career regarding the importance of a 'speak up' culture to catch issues early. Steven reflects on his early software career when security shifted from a side thought to a fundamental cultural requirement. | |
| Cloud vs. On-Premise Software and Certification Myths | 5 | 5 | 2 | 2 | Lisa debunks the myth of third-party GDPR certifications, clarifying that GDPR is a law without official certification bodies. Steven warns listeners against paying high consultant fees for fake certifications. | |
| Practical Data Inventory and Mapping Spreadsheet Tool | 4 | 4 | 1 | 1 | Lisa details her practical spreadsheet tool for conducting internal data mapping and risk assessments. Steven reinforces the necessity of auditing specific data fields and SaaS tool pass-offs across departments. |