Me and Hannes Saarinen did a talk on #privacy in modern software development at #IAPP #DPC23 (no, not the PHP conference with the same hashtag 😀).
Competing for audience against the #EDPB Chair in the same timeslot, we managed to pull a full house! Thanks to all who came!
There were other presenters talking about the same thing. Earlier that morning, #Flutter’s Veroniki Stamati-Koromina had really insightful stuff on a Privacy by Design panel. You could clearly hear the experience talking. Next day, #Vodafone’s Henri Kujala and #Privado’s Vaibhav Antil continued on a very similar theme.
I’ll paraphrase some of the key things from our talk:
It’s important to understand the structure of the #ProductManagement organization as well as the product portfolio and backlog. You don’t want an impedance mismatch between the privacy/security function and the product management.
Scalability can only be attained by building the capabilities into product management and engineering. This requires trust; trust needs to be well-founded, but without it you’ll either burn yourself out or start creating queues and delays. (I had three deep hallway track discussions on this very topic.)
Security and privacy functions need to mesh together. Product and engineering need the support from a single point of contact. Sometimes it’ll be privacy who leads the discussion (and security follows), sometimes the other way around. The closer you get to the actual implementation the likelier it is that security will be the driver.
If scaling is your challenge, try to make your security engineers to be fake lawyers, and your lawyers to be fake engineers. You can always consult each other on difficult things, but you can often get to a 80/20 situation without having to use everyone.



