EP 257: Data Privacy Compliance Can Be Easy w/ Arlo Gilbert, Osano
Data Privacy is the new front in the compliance wars. For many organizations Data Privacy is a dreaded subject with a maze of governance and compliance issues. Osano wants to make it easy. Led by serial entrepreneur Arlo Gilbert, it is catching fire as enterprises learn that complying with Data Privacy laws is possible and even affordable. Have a listen as Arlo and Alan Shimel discuss this important topic.
Transcript
Hey, everyone. com Security Boulevard Container Journal. You're listening to another DevOps chat.
I've got a really nice chat lined up for you that I think is going to educate and enlighten many of you. Happy to be joined by my guest. And he is Arlo Gilbert.
Arlo is the CEO founder of Osano. Alro is also a serial entrepreneur with 20 plus years of startups behind him, but Osano latest and greatest in all. Welcome to DevOps chat.
Hi, Alan. Thank you for having me. Yeah, it's our pleasure.
So before we jump into a I hope I didn't embarrass you. But give our audience a little bit of a little bit of your own personal journey that brings you to Osano today. Sure, well, I have been.
For better or for worse, building companies for over 20 years. You know, my background is in a variety of industries, from advertising to telecommunications to even the funeral industry. You know, I built my first company when I was in college and fortunately in 1997, when I built my first startup, nobody knew what they were doing.
So my my complete ignorance about the business world proved to be a good thing. And so I built a couple of companies have been pretty successful in various categories. I've had a couple of failures as well.
And those were certainly humbling learning experiences. But, you know, in 2017, I started a an enterprise SAS optimization platform and sold that to a company called Flexera out of Chicago. And and when we were finishing up our time there, you know, we just couldn't get some some conversations we had with CEOs and CISOs out of our heads.
And that's really what ended up leading us to this point in time, that Osano. Ok, great. And so let's let's get out of the way, what exactly is Osano?
So Osano is a data privacy management platform, and I know that's a lot to say in one breath, but what it means is kind of end to end from your Web site all the way to your back end operations and your vendor monitoring. We provide all the tools that small and medium sized companies need to comply with the 40 plus and growing privacy laws around the world. They often conflict the very confusing and we make it really easy.
Well, I, you know, really easy, I don't know, but I mean, you're going to have to show me to convince me on that one. Well, you but you're right. I mean, we live we live in a litigious world.
And especially when it comes to online security and compliance data privacy more than anything. It is a bit of a mishmash. I I always I always hope that this is just a phase.
We're going through that at some point we're going to have clarity and and single purpose in our data privacy laws. But I've been wishing this now our know, for 15 years, and it's only gotten more complicated instead of less. Right.
Yes. So how how does I mean, whether we're talking about EU privacy, you know, type of stuff or, you know, the the mishmash of different states acting here in absence of a federal. Single federal standard, how do you how do you how can one company help you with all of these different roads?
Yes. So so the the each law has its own nuances. Right.
So we all are probably familiar with the DDP PR or as I've heard many CISOs call it, God-dam privacy rights. The. Yeah.
So GDPR was enacted in twenty eighteen. And you know what a lot of folks are not familiar with is that California has a law now starting on January 1st called the California Consumer Protection Act or CCPA. Yep.
And and it has a lot of commonalities with GDPR. Ah, it has some differences. You also have laws in, for example, Brazil passed their own version of GDPR.
And there are a very large economy. Japan has one. India has one.
And now the UK is not part of the EU or being businesses influential. K. law.
And so what's complicated is each of these laws has its own nuances and rules. The good news is that you can map these things right. If you go through all the laws.
And Sara, what does this law say about this particular type of activity like data retention or data collection? You can end up mapping those out the rules for the most part. And and those rules serve as part of our engine.
So it allows us to kind of dynamically make sure you're complying with different laws and different regions. So let's let's dive in a little bit what it means. And if it's okay Arlo, I'm going to use MediaOps, my own company, as a as an example.
Here we operate. Well, all told, we probably operate six to nine Web sites with this three main ones. And we you know, we serve up content, mostly blog articles.
But we have some audio video downloadable and so forth. And we you know, we serve a global audience, literally every country in the globe you could think of and. You know, we we do collect information, we use tools like HubSpot and we have registration forms and signup forms and some of that information gets shared with our sponsors.
Right. How does this is a Osano help us? Sure.
Well, on the on the front end part where, you know, we think of as front of firewall, meaning your Web site, Osano, has what we think of as the most sophisticated cookie consent pop up in the world. So it's a it's a cookie consent pop up the does some pretty magical things. And Alan.
Have you ever seen those things, the pop ups that come up on the Web sites? Well, we have a pop up now. You know, I think that we in the world to know when the god damn privacy regulations stuff.
Right. That's right. And I say facetiously, I'm a big data privacy supporters, so.
Yeah. OK. Yes, we do.
We have the pop up asking people to accept. Yeah. So.
So odds are really good. Each time you see one of those stars, we have the most popular open source cookie pop up on the planet. It's used by more than seven hundred and fifty thousand companies.
They serve up a little over two and a half billion pop ups per month using our tool. But but with that open source tool, it's pretty tough to really be compliant because, I mean, A, you're setting up one pop up regardless of where that person is. You may not be displaying it in the language that the individual reads.
And you also may not be doing things like listening for when they decide or change their preferences. And so, you know, the cookie pop ups on the surface seem pretty simple. But but underneath, there's actually a lot that's supposed to happen.
And so. Osano's. Osano's commercial version, which has a free tier, which is appropriate for smaller sites all the way up to enterprise pricing.
It does a lot of really magical things. I'll tell you about the really exciting thing part, part last, which engineers get pretty interested in. So we do a couple of things.
One, we track consents. So one of your obligations under virtually all of these laws is to keep a record of when somebody says, yes, you can process my data. Right.
And that's that means filling out forms or even just saying yes or no to that cookie pop up. The other thing you have to do is you have to make sure that if somebody is in the EU, you give them a special set of options when they visit your Web site. Whereas if somebody is in the United States, all you have to do is disclose and let them opt in or out.
So we automatically manage that for you. It's automatically translated into 40 different languages. So if somebody's visiting your Web site, Alan comes from France.
But their primary language is Chinese. Even if your Web site is in English, they will see a dialogue that complies with French law and is in Chinese. So.
So how do you know the Dutch person is Chinese speaking French in France? Right. So we use the IP address with that with a very high resolution.
Look up. So we identify what region they're in. So we use that.
It's got a little over a ninety nine percent accuracy rate. If somebody wants to bypass it with a VPN, you try. And then on the language side, we're looking at the browser settings and the operating system settings which get passed to us.
And I had her. So we can quickly tell where are they from language. They talk about what language they speak.
So those are those are a couple of the things we do. But then the the other really two the two parts of it that make it really sophisticated is, one, when we collect and store that consent. So let's say somebody visit your Web site or somebody signs up for something.
What we do is we record that record on a blockchain. A private blockchain, so that we now have an unchangeable record and we can prove that it hasn't been changed. And this is one of the few uses of blockchain, I think is really legitimate because you can finally take this record into court if you get sued and you can prove that you actually got that consent.
It was managed by a third party, auditable and not changeable. But the really cool part about our consent manager is that it's a single line of code, one single javascript line in the head of your document. And with that one single JavaScript line, your security compliance devops team, really, who was ever in charge of running Osano can now stop the marketing team from implementing pixels trackers and tags until you've approved them and categorize them.
So your marketing team can keep doing their job over here, but you now have some oversight. It's almost like putting a firewall on your Web site. And it's it's pretty sophisticated when you when we show the demo to folks.
Usually there's usually a moment where an engineer goes, how did you do that? So it's a really cool tool and it it really manages that that entire kind of front end of your of your data collection process. Interesting.
Good stuff. So I know a little bit about this. Probably enough to be dangerous.
Problem or not, our problem. But our concern always is not the initial pop up for cookies. Right.
Because I think people are desensitized to that already at some level. But you know what happens? And this is what I'd like you to share with our audience.
What happens in the background when someone clicks? I accept right now. Right.
Do you do you. Have you given them permission to share? You read an article that was written or sponsored by Cisco.
I'm not picking on Cisco them. Just a name we all know, right. Or Microsoft or any of that.
Have you consented to share information with these folks? Yeah. So if the dialogue.
Sure. Yeah. So.
So they're the good news is we have some legal precedent to look at to decide. Now, what actually counts as as consenting for sharing? What we did see in the EU was there was a ruling, there were two rulings in the last couple of months that came out that are important for for even for technologists to understand.
One of them is a ruling called Planet Forty Nine and Planet Forty Nine basically decided that if you are a European visitor, you can't pre check any of the boxes. So you can't you can't pre check the marketing checkbox and the analytics checkbox and the personalization checkbox. So you have to leave them unchecked.
And if you do those things then it's considered valid consent. All right. And there's now law and case law around this.
It says this is valid consent as long as you provide freely informed consent. Right. So so that's the first part.
The second piece of the law. There was a lawsuit in Belgium about I think was settled about four months ago. And what they ruled was, if you're a website owner and you include a Facebook like button on your Web site, for example, and Facebook then has a data breach and and some of that data that was shared through your like button is part of that breach.
You're the one on the hook because you as the Web site owner, were the one who made the decision to include a Facebook and share that data. So the consent gives you the right to share the data, but it doesn't eliminate your responsibility in the event that you're downstream vendor, has some bad privacy practices and or has a breach or something like that. Yeah, I mean, you know, and this is a common thing and frankly, you know, it's also one of the things about cloud security.
Right. You can trust your cloud provider or you can delegate your cloud provider to perform certain security functions, Eugene, delegate your third party partners. Around some security and compliance issues.
But ultimately, you, as in this case, a Web site owner or a business owner, are responsible for your own. You're ultimately responsible for security and compliance. That's right.
And, you know, trying to say I delegated it out is is somewhat of a mitigation, but it's not an exoneration. If if we can. You know, get a little bit technical there, a little bit legal.
It is fascinating stuff. And I think it's important, especially people out here who are maintaining their company's websites and are dealing with these data privacy issues, which, you know, we're all dealing with in one way or another. Let's go beyond the initial consent, though, also.
What, just as a sign of hope. Yes. So, I mean, kind of tying in to that that last bit about how it's your responsibility to keep track of who you're sharing data with and know them.
We're all familiar with the money or the money laundering laws. Right. If you've signed up for a bank account for your business in the last 10 years, you've probably had to fill out some of those.
Know your customer fields and form. Right. They want to verify that you are who you say you are.
They want to check your credit. So that's the other piece of the Osano puzzle, is that we have this very robust vendor monitoring tool and we're not talking about security monitoring because there are lots of tools out there that do that. Instead, what we're talking about is monitoring their privacy practices and their litigation, because if you are sharing data with a third party and it turns out that they have really poor privacy practices that are disclosed in all of their documents, but you chose not to read them or you chose not to evaluate those statements, then you're not going to have much excuse.
Should your company end up in court? A. does a couple of pretty cool things.
We have we have a team of about 24 attorneys and those attorneys have the most boring job in the world. All day long, all they do is read all the compliance documents the companies publish, and then they go and they answer one hundred and sixty three questions. In our in our system so that we can objectively measure their privacy practices.
And what this does effectively for our customers is it takes the burden off of them for having to go and constantly monitor their privacy practices of their vendors and constantly be reading and comparing their privacy policies and GDP statements to the version that they had up three months ago. Because we all get those e-mails saying we've changed our privacy policy and, you know, 90 percent of the time, you don't know what changed it just now it's up to you. Go read it and figure it out.
So so we do that. We we turn that into a really objective score, which is a technologist I like. I don't have to be subjective about these things anymore.
I can tell you exactly how Facebook rates relative to other companies in their category. The other thing we do is we connect into Pacer and the better and then the state court systems for seven majors for the seven largest states. So if you're doing business with a company and they get sued for a data privacy breach or a security breach, you can be the first one to know.
And otherwise you could probably do that on your own. But you have to go subscribe to Lexus Nexus and set up alerts and pacer and it gets complicated and expensive. So this just becomes a a nice place to have one set of information about the vendors who do business with.
You know, it's interesting because we see I mean, we talk about Facebook as being a bad actor. And in fact, they're not very good. Objectively, I can tell you their practices are in the bottom third of our data set.
We've analyzed nine thousand companies now. So it's we have a very robust data set. But what's interesting about Facebook is if you if you go and look at them, they have over 2000 lawsuits against them now related to data privacy.
So if you're using those Osano, that's a really good red flag. Right. This this company has so many lawsuits against it.
Should I feel comfortable sharing data with them? And then that becomes your choice. Right.
You can you can choose to continue doing business with the company that has poor privacy practices without. But you have to recognize that in the event of the worst case, you know, you have a data breach. You have to go to court.
Your company ends up in the press. You know, would you be able to defend using that vendor? I mean, on the other hand, you know, Facebook is so ubiquitous now to exclude them that we do this because we have the share button on many sites like ours.
And, you know, it's interesting. We get many more shares on Twitter than we do on Facebook. But we.
Yet many more on Facebook than we do on LinkedIn, on a gig on any given day. I mean, on any given day, these things fluctuate like, you know, to just cut Facebook out would be would be difficult. Let me ask you another question Arlo and that is, look, today.
So men and I deal with vendors all day here. Right. And their Web sites and working with their marketing teams.
So many of the vendors today use programs like Marceto and HubSpot. Did you know to automate a lot of your day, you know, inbound marketing and tracking and drip campaigns and all of these things and Salesforce itself even. How does how do you guys work with those kinds of companies?
Yeah. So, I mean, great question. The good news is that the Marcatos and the huspot of the world, which we actually use HubSpot too.
They're good companies. And when you look at our data set where you find us, they're pretty highly rated. They've put a lot of effort into their data privacy practices because they know that they're collecting a lot of data.
They have to do a good job of that. You know, you do have a responsibility as a as what we call the controller of the data. So like you talk to our you own the Web site.
It doesn't matter who else you use. You're the you're that where the buck stops with you. So whether you build applications or run a Web site, you do have an obligation to keep track of where the data goes.
All right. And so, you know, you have you have a couple of tools at your disposal there. One, you're using Osano.
You can actually explore all of the vendors that your vendors share data with. So you can you can kind of see that data supply chain visually. And we like we like to say that data is like a sneeze because the moment that it gets out, you will never get it back in.
So so if you can't control the data, getting out at the very least you can do is start recording where the data's going. And so we have an API as well. That's a high volume API for storing where data has been transferred, which data has been transferred and essentially creating a third party audit log of those transfers.
So that again, it's all about worst case, right? This is not a day to day operational thing. This is all about protecting your company in the event that you end up in a lawsuit or you have a security breach, that you can show evidence that you were trying really hard to be a good actor, because that's the thing that will keep you from getting criminal charges filed against your company or having really big fines.
So so that's how we think about the market. And HubSpot is use them, validate that they meet your compliance criteria by using our tool and then verify who they're sharing data with and then start tracking where the data's going. And if you do all of those things, you're doing better than most companies.
And you can probably sleep at night knowing that if you had an audit of some kind or your board demanded proof, you can provide it. And that's important is important to these rules. You know, there's so much here, Arlo could probably talk all day.
But I'm I'm pretty sure over our allotted time I didn't have my time were running. But it sounds and we are people who want to get more information. Website, OSANO, you know?
com. Okay. And just as you mentioned, you do have free offerings and all the way up through Enterprise.
If you're listening, then you're somehow responsible for your company's data privacy or Web sites. I would highly, highly recommend it. Arlo, thanks.
Thanks for educating us a little bit today. Appreciate it. Thank you for having me, Alan.
I appreciate it. All right. com If data privacy is important to you, if compliance with GDP are similar, programs are important to you.
Give them give them a look because it's look at something we all have to deal with today, whether we're consumers, providers or what have you. Also, we'll talk to you soon. com Security Boulevard Container Journal.
You've just listened to another DevOps chat. Have a great day everyone.