3) Conducting Technical Privacy Reviews

The GDPR and other laws require privacy by design, but it remains a broad imperative without firm standards. Companies aiming to comply now often conduct a technical privacy review (TPR) as a step before a better-known exercise, the privacy impact assessment. Prominent privacy engineers from DoorDash, Meta, Microsoft and Uber, during the International Association of Privacy Professionals Global Privacy Summit 2024, performed a simulated TPR that examined a consumer app’s reliance on a large language model. This article distilled the simulation’s dialogue and resulting action items, as well as the speakers’ advice for conducting TPRs.

To read the full article

Continue reading your article with a CSLR subscription.