Published by Colleen Barry
Privacy Huddle breaks down what actually matters in the fast-moving world of data privacy — GDPR, CCPA, AI regulation, consent management, enforcement actions, litigations, and the expert shaping the future of privacy law and tech.
Listen on Apple Podcasts25 min
Last week, CalPrivacy announced its first audit in a series of sectoral audits. That was the topic of conversation on this week's Privacy Huddle , where Host and Head of Marketing, Colleen Barry at Ketch sat down with Alysa Hutnik, Partner, Kelley Drye to break down what the agency's first sectoral audit actually signals, and how privacy teams can get ready before a request lands.
27 min
In Privacy Huddle Episode #101, host Colleen Barry sits down with Aubrey Wesser, Managing Associate General Counsel for U.S. Privacy at Verizon, for a wide-ranging conversation on managing compliance in the fast-changing U.S. privacy landscape. We discuss: Risk assessments Children's privacy Leveraging AI
33 min
This week we’re dropping the 100th episode of the Privacy Huddle . Who would've thought that our little privacy podcast would come this far! To mark the milestone, Host and Head of Marketing Colleen Barry sat down with Co-founder & CEO Tom Chavez and Co-founder & Head of Product, Max Anderson to take a nostalgic trip down memory lane. It's part origin story , part honest reckoning with the technology bets they made as early founders and how they’ve panned out.
24 min
Privacy leaders are facing more pressure than ever—and the old approaches to compliance may no longer be enough. In this episode of The Privacy Huddle , Colleen Barry is joined by Alisa Hutnik and Maxwell Anderson to discuss the biggest conversations coming out of the Cincero Chief Privacy Officer Forum in Chicago. Topics include: - Why traditional data mapping projects often fail - Modern approaches to privacy risk management - Why many organizations are frustrated with legacy privacy vendors - The misconception that cookie banners alone satisfy compliance - California privacy enforcement trends - Consent management best practices - Do Not Sell/Share requirements - Identity resolution and advertising technology - How marketing technology creates hidden privacy obligations Whether you're a Chief Privacy Officer, privacy engineer, legal counsel, compliance professional, or marketing leader, this conversation offers practical insights into today's evolving privacy landscape.
15 min
Raise your hand if you've received a demand letter. Spoiler: you’re not alone. When we ask in privacy conference sessions, 70 - 80% of the room shoots their hand up. Dealing with demand letters has become part of the privacy program norm. In this week's Privacy Huddle, Host and Head of Marketing Colleen Barry and Co-founder & Head of Product Maxwell Anderson break down exactly what privacy teams should have in place before one lands on their desk. What they cover: Why plaintiff's attorneys are targeting companies that look easy to settle, The spectrum of notice & consent approaches, from disclosure-only to full opt-in, What a HAR file is, why it shows up in demand letters, and how to fact-check one, The auditability practices that make your program harder to attack.
23 min
Privacy enforcement is evolving quickly — and brands can no longer rely on “vendor limitations” as an excuse. In this episode of The Privacy Huddle, Colleen Barry sits down with Ezra Sternstein (AMC Global Media) and Max Anderson (Ketch) to unpack the latest privacy enforcement trends, identity management challenges, vendor accountability, and the growing convergence of privacy and cybersecurity. Ezra shares unique insights from his background at the New York Attorney General’s Bureau of Internet & Technology, where he investigated privacy and cybersecurity violations firsthand. The conversation dives into recent Disney and Sling settlements, cross-device identity requirements, CCPA cybersecurity amendments, data mapping strategies, and how privacy leaders should prepare for the next wave of regulation. If you work in privacy, security, compliance, adtech, martech, or legal operations, this episode offers practical guidance on what regulators actually care about — and what organizations must do now to stay ahead.
14 min
Some days, the content is great but the tech has other plans. Please bear with the video quality on this one. In the latest Privacy Huddle, Colleen Barry sits down with Alysa Hutnik, Partner at Kelley Drye, to cover three things on every privacy leader's radar right now: The SECURE Data Act. Not because it's crossing the finish line anytime soon, but because the elements inside it, particularly around third-party auditing and compliance certification, are signals worth paying attention to now, before they show up elsewhere. Demand letters. They're not going away. But having the right consent management setup, clean tag configuration, and a defensible banner isn't just good hygiene, it's what gives legal teams something to work with when the letters land. The U.S. Privacy Summit is back. October 15th, San Francisco, Convene. Free to attend. The anti-conference returns for year two. Watch the full episode.
7 min
Frictionless opt-outs keep coming up. Now we’re hearing what that actually means in practice. In this week’s Privacy Huddle, Maxwell Anderson joins Colleen Barry live from the Ketch booth at IAPP to break down what’s coming directly from regulators and recent enforcement conversations. The headline isn’t new. The expectations are just getting more specific. Regulators are focused on how opt-outs are implemented, not just whether they exist. And that’s where things start to break down. Frictionless doesn’t mean “easier UX.” It means removing barriers entirely: ✔️ One-click opt-outs, not multi-step flows ✔️ No unnecessary data collection to process a request ✔️ No redirect loops or buried links ✔️ No conflicting paths between banners, forms, and systems Because if the process introduces friction, it introduces risk. There’s also a broader signal behind all of this: responsibility sits with the business, not the vendor. If your implementation doesn’t hold up, it’s your name on the investigation. We also got into a recurring source of confusion across teams: this isn’t a cookie banner problem. It’s about how clearly you present “Do Not Sell or Share,” and whether that choice is actually enforced across your environment.
12 min
Everyone predicted the enforcement wave. Now it’s here. In this week’s Privacy Huddle, Alysa Hutnik, from Kelley Drye, joins Colleen Barry to break down what the latest settlements from Texas and California are signaling for privacy teams.
9 min
Privacy enforcement in California is accelerating — and companies are feeling the pressure. In this episode of Privacy Huddle , recorded at the California Lawyers Association Annual Privacy Summit at UCLA , Ketch Head of Marketing Colleen sits down with privacy experts Celine and Max to break down the biggest themes emerging from the conference. The conversation covers the growing role of regulators, why enforcement actions are increasing, and what companies are getting wrong about consent management platforms (CMPs) and privacy vendors. They also discuss why storing consent signals only in the browser may not meet regulatory expectations — and how companies should rethink record-keeping, vendor accountability, and technical architecture . The episode also explores an important new development: California’s DELETE Act , the state’s data broker law introducing the upcoming DROP deletion mechanism and new compliance obligations starting August 1. If you work in privacy, legal, compliance, or data governance, this discussion highlights key risks regulators are focusing on and how organizations should prepare.
9 min
In this week's episode of the Privacy Huddle, we’re diving into the topic that kept resurfacing at Privacy State of the Union: children’s privacy and age signals. If you think this is just a COPPA (under 13) issue, think again. Between app store age verification laws, state-level opt-in requirements, and evolving enforcement expectations, brands are now dealing with: Jurisdiction-specific obligations (under 13, 15, 16, 17… it depends) Age signals flowing in from app stores and potentially browsers The reality that “we’re 18+” is no longer a strategy And perhaps the hardest part? There’s no “easy button.” Age gating isn’t just a widget. It touches consent, identity, data use, and downstream enforcement. If you can tie identity together for advertising, regulators will expect you to do it for compliance, too. Watch as Alysa Hutnik, Maxwell Anderson, and Colleen Barry break down what brand leaders should be thinking about now, and why 2026 is shaping up to be a pivotal year for kids’ privacy.
14 min
In our latest episode of Privacy Huddle, we sat down the morning after Privacy State of the Union to keep the conversation going, this time with Matthew Dumiak from CompliancePoint and Maxwell Anderson joining Colleen Barry from Ketch. Coming off a day of candid regulator and practitioner discussions, we dig into what’s really top of mind as teams head into 2026: Important nuances across U.S. state privacy laws How to handle third-party disclosure obligations Common blind spots in website data collection Moving beyond the basic cookie banner Watch the full Privacy Huddle for a practical take on where privacy programs are heading, and what it will take to keep up. Featuring: - Matt Dumiak, CompliancePoint - Maxwell Anderson, Co-Founder and Head of Product, Ketch - Colleen Barry, Head of Marketing, Ketch
7 min
In #PrivacyHuddle Episode #90, Alysa Hutnik joins Colleen Barry to discuss takeaways from the Privacy State of the Union event on January 27, 2026 in Washington, DC. They discussed: How enforcement expectations are getting more concrete (and more technical) Why kids’ privacy and age-related controls are becoming central, not edge cases Where teams continue to struggle bridging policy, UX, and backend execution What regulators are really looking for when they test programs in practice
14 min
In hashtag#PrivacyHuddle Episode #89, Alysa Hutnik joins Colleen Barry to discuss CCPA rulemaking, state sweeps, and more: 1️⃣ ADMT + Risk Assessments: New rules under hashtag#CCPA are not just more of the same. Think executive sign-offs, a clear distinction between "new" and "existing" processing, and ADMT implications that go beyond consumers to employees and B2B contacts. 2️⃣ The multi-state GPC sweep: If your site isn’t honoring Global Privacy Control signals, regulators across CA, CO, CT, and more are watching—and asking questions. Multiple states, multiple letters, multiple pain points. It's not just about GPC; it's about being ready for any scrutiny. 3️⃣ Andddd… the full agenda for the October 23rd U.S. Privacy Summit in San Francisco is now LIVE 🤩 from regulator fireside chats, to practitioner panels, this is gonna be a good one folks. If you're attending, we want to know what YOU would ask the FTC, CPPA, and CA AG. Drop questions in the comments!
13 min
What does GOOD privacy UX look like in the auto industry? For the first time, we have real benchmarks—thanks to a massive new report from Privacy4Cars. In this episode of #PrivacyHuddle, Colleen Barry sits down with Merry M. and Andrea Amico (founder of Privacy4Cars) to unpack their groundbreaking research into privacy user experience across 49 automotive brands. From cookie banners to web portals, they graded how auto companies handle privacy notices, consumer choices, and transparency. Here’s what we discovered: ✅ Correct GPC (Global Privacy Control) implementation is catching on—but 1/3 of brands still forget to mention it. 🚫 One carmaker told consumers: “Don’t like our data terms? Don’t buy the car.” ⚡ After a CCPA settlement, Honda transformed its privacy UX from poor to excellent—in just weeks. 🏆 Only one brand achieved a perfect 5.0 score on web browser experience: Rivian, powered by Ketch. If you’re a UX designer, privacy professional, or auto industry insider, this conversation is a must-watch. It’s proof that consumer privacy doesn’t have to be painful—it can be transparent, user-friendly, and even a competitive advantage. 📌 Watch the full interview now, and check the pinned comment for a link to the full Privacy4Cars report.
8 min
14 min
Don't miss this deep dive into California privacy compliance with Alysa Hutnik and Celine Guillou, Special Counsel at Kelley Drye and former CPPA enforcement attorney. Colleen Barry leads a candid discussion on: Celine’s unique perspective transitioning from CPPA enforcement to private practice—and the top challenges for in-house privacy teams today, including CIPA litigation and opt-out compliance. The surprising scope of California’s new surveillance pricing bill (AB 446) and how it could impact businesses running targeted ads or loyalty programs. A special event teaser: Ketch and Kelley Drye are teaming up with WISP for a one-day privacy conference in San Francisco on October 23. Full details dropping soon!
14 min
In the latest privacy huddle, Max Anderson and Alysa Hutnik focus on the recent $1.55 million settlement involving Healthline Media due to privacy violations. The California Attorney General highlighted issues with consumer opt-out processes and the company's failure to adhere to CCPA requirements. The discussion revealed that many companies struggle with misconfigured privacy settings and lack knowledge about available tools for managing sensitive data. As expectations for privacy compliance rise, practitioners are urged to align their budgets accordingly, especially with the potential for increased penalties from multi-state enforcement actions.
9 min
Opt-out compliance is under intense scrutiny—and getting it wrong comes with real risks. In this Privacy Huddle episode, Alysa Hutnik and Colleen Barry walk through 7 critical tips for getting opt-out compliance right. Based on Alysa’s upcoming article, the conversation covers key topics like data flow mapping, CMP configurations, avoiding dark patterns, and why ongoing training and monitoring are non-negotiable. Whether you’re navigating CCPA, GLBA, or global rules, this is your go-to checklist.
7 min
In Episode 83 of the Privacy Huddle, Alysa Hutnik returns to tackle one of the most common questions from privacy professionals. Colleen Barry and Alysa discuss: - Whether data mapping is essential under current US privacy laws. - Key state-by-state regulatory updates. - A noteworthy enforcement insights report from Connecticut that privacy leaders should not miss. If you're managing a privacy program or staying ahead of compliance trends, this episode delivers the clarity and context you need.
Bring this source into Mato to analyze its transferable patterns and turn them into an original show concept for your audience.
Create a show inspired by this