Most companies trust their website. They shouldn't. The leaders who know better are rebuilding what it means to govern a website, and every week we sit down with privacy executives, compliance teams, and digital risk pros at the world's largest enterprises.
We dive into stories with the ones who caught a broken consent tool before the regulator did, traced a six-figure loss back to a failed tracking pixel, and rebuilt their entire data governance approach from scratch. The rules of digital trust are being rewritten right now. This show is where you hear it first.
Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.
Web Privacy Podcast - Uche Orji
===
[00:00:00] Good morning, good afternoon, and good evening, privacy professionals alike, and welcome back to another episode of the Web Privacy Podcast, where I get to take on the tall task of making my mother proud, where I get to try and bring privacy professionals together in a very clear and concise way and make things simple.
Today, we're joined by a ~s-~ very special guest, Uche Orji, who works in market data licensing, governance, and vendor management at one of the largest financial indexes in the world. Uche lives at a very interesting part of the privacy cycle that most people don't see. Before data reaches a system, someone negotiates the contract, assesses the vendor, and decides what that data is allowed to be used for.
She has handled hundreds of licensing transactions and commercial agreements in just this year. She built the vendor risk and contractual safeguards behind them, and she serves as an enterprise-wide AI security champion. Uche, I know you brought a big story today. It may seem small to some people, but for everybody who's gonna be listening in to this podcast, they'll know it's anything but small.
And I don't want to give away too many spoilers, but we [00:01:00] are going to dive into a pre-ticked checkbox in a marketing signup form. But before we do, like I said, no spoilers. If you wouldn't mind, tell us a little bit about who you are, where you're calling from today, and my favorite question of how you got into privacy.
Oh, yeah. Thanks, Ethan. So who I am, my name is Uche. I'm a lawyer with about eight-plus years experience. Like you said, I currently work in market data licensing and also in the privacy sector. So how did I get into privacy? It's actually super interesting. So I started my career as a lawyer, obviously a bit of a generalist.
Did a bit of corporate, commercial, and all types of transaction. But I got to find out, or in the course of working, I got to see that, the law, what actually was said by the law was not always operationalized within the business. So there was always a ~s-~ a certain gap between what the law said or what best practice it actually wanted from us compared to what was within the operation.
And I felt okay, this was a good gap that I could put value in, [00:02:00] and I could actually develop my skills at. And, I felt yeah, privacy was it. This is a good place to be in, and then that's where I am. So still learning, still growing, and just, it's a really big space, so I'm always very happy to talk about it.
Yeah. I love that Yeah. And ~gl-~ I'm glad you're here, like we said. And I know, again, looking at ~your~ your LinkedIn, and ~as,~ as we talked in the pre-call as well, you're somewhat of an anomaly in that you have both a law degree and an MBA. Yeah. Is that anomaly? I feel like I know a lot of lawyers that have MBA right now.
So you say even I love the law, I love to understand it, but there's also something about understanding the business and actually, like I mentioned, about the gap. It's something to know the law and to quote the law. It's also something to actually understand the nooks and crannies and the operation of the business.
So I wanted to understand the business from that perspective so that I could actually bring my legal skills to play, and I felt like the best way to do that was to get an MBA. But, I'm still learning. I have taken the CIPP certification. I'm still, like, trying to dabble a [00:03:00] lot into legal affairs.
So I'm still a lawyer through and through. Yeah. I believe it. With that in mind, actually, let's go ahead and dive into another question that, that comes up fairly often on this podcast because- ... it tends to change organization to organization. Yeah. And that is ~h-~ how does privacy look like at your organization?
And where do you live in that whole function? So privacy is usually, I think when it comes down to the crux of it, privacy is actually a legal affair because what governs privacy is actually the law. Also there are best practices, but usually it's the law, it's the article. So I would say that privacy should sit or actually sits in the legal, in legal governance.
But, it is... No matter... It depends how big a business it is. So if there's a concern or there is a risk, you actually have to bring in all product owners, business owners, cybersecurity, and all relevant stakeholders. But I would say the ownership of it should actually belong to a legal and operations team, or the legal operations team.
Interesting. And which [00:04:00] department do you feel like you interface the most with? Is that product, marketing, other? Multiple. It could be cybersecurity one day it could be marketing one day. Marketing is always a big one because that's usually where, PII is usually brought into the business.
It could also be vendor management, so there are multiple. There are always multiple stakeholders. What I would say is what triggers the workflow is where PII is being gotten. And then once that is gotten, you have to work with whichever stakeholder is bringing in that PII. Interesting.
And that is obviously a very sensitive case, so I can imagine- Yes ... that's something you guys talk about fairly often. Yeah. Yeah. And speaking of marketing, I obviously, again I don't hide the fact that I am the, the head of marketing at ObservePoint, and I often joke- Oh, you are? Nice. I am. Yes, I am.
And I often joke that you either choose to work in marketing or you live long enough to be somebody who fights with marketing every single day. And with that in mind, ~let- ~let's go ahead and jump into your story, Uche. ~I'd love to- ... ~would you mind starting with, at the beginning with~ your form- ~that we talked about in the pre-call? Yeah. [00:05:00] I'd love to paint the picture for all the listeners today. Okay. In a company that I worked for it was a pretty small company we... Or when I say we not me right now, but when I worked in the company, the marketing team had wanted to put in a Contact Us button on the website.
And, it was a conspicuous ~e-~ enough button. There was like a banner, and if you wanted, if customers wanted to, get more information about the company, they would put in like personal information like phone number, emails, and all of that stuff. And there was now like a pre-checked button that says Sign Me Up for Promotional Affairs.
And, it was pretty small, nothing crazy. The point of what marketing does, as you also know, is lead generation. We want to get clients and customers. So for them, that was just a step to actually get, customers and ~cl- ~potential clients. And then it was like a routine. I won't call it a routine check, but sometimes they, we had this internal audit of processes.
And then when I got in there, I looked at the form, and I'm like, "Okay, why is this [00:06:00] pre-checked?" And they all, they said, "this is what we've always done ," "if customers don't like it, they could choose to unsubscribe." So for them it felt like they took a more opt-out approach as opposed to opt-in.
It was like, "If you don't like it, you can unsubscribe, but we are going to sign you up before you know it." And then I had to start to explain that, the GDPR, and not just the GDPR, but even other laws. I will just say GDPR 'cause I think GDPR was the first major law that was rolled out for privacy.
So the GDPR and other laws state that, consent must be unambiguous. It must be unbundled, and it must like be given by the customer. And the fact that you have put in a pre-checked box means that- The customer didn't consent to it, you took the consent. So the point of it was to explain the framework for my decision, and also from that, I now help them to understand that customers or potential customers had to agree to receive whatever it is you want to give them.
They shouldn't be forced into it. And so with [00:07:00] that, explanation, the first step I did was to uncheck the box and let them know that nothing should be checked. But I also recommended, because, it wasn't my decision, but I recommended an opt-in approach. Whoever wanted to sign in to receive promotions had to put in their email, a link would be sent to the email, and then they had to sign on to the link.
So in this way, it was clear that whoever it is wanted the document or wanted the promotional emails actually consented to it. And, apart from the trust that it was going to generate with our companies, with our clients, I also wanted a, a good paper trail so that anyone that was coming to audit or even just a customer could know that we had put in, we had put in all the work necessary to ensure privacy.
This was my recommendation to handle that. But I also now understood that as part of a marketing workflow, they had to run this through privacy. So marketing, I think even most marketers know they don't like to run things through legal, which I don't blame them. They see legal [00:08:00] as a roadblock.
But, I had to explain that if this involves getting customer information, it had to run through the privacy team. And I told them to add that to their workflow so that, cases like this wouldn't occur again. Because what had happened was that ~we-- ~it was not a routine check. It wasn't part of our workflows to check.
It was just something that we just did occasionally. So I don't know if other things had gone that I was not aware of, but at least we put in these controls. Thankfully, nothing crazy happened. ~We didn't get, ~we didn't roll out that campaign. They were able to figure it out before we rolled it out.
But, that was where I saw just the importance of liaising with your stakeholders to prevent compliance issues. So yeah, I guess that's pretty much my story .
I love that. And e-every time... I've heard you say this a few times now, ~this,~ this story, and it brings me back to that Mike Tyson quote where he says that everybody's got a plan until they get punched in the face.
And
I feel like a lot of times in privacy, people have a plan until the fine hits them in the face. Sure. Sure. But in your case, you found it before [00:09:00] that happened. Walk me through that. What was your motivation to even get in and get your hands dirty there?
'Cause a lot of times the legal team does not have the technical chops to find these things. What led you to that point, and how'd you go about finding it? So it was actually an occasional check. So we just had a process where we could audit a department's internal processes. So it wasn't routine, it wasn't part of our workflow, but we could occasionally do this.
And then when we went occasionally, we asked them to walk us through the websites, and then they did that. It was very inconspicuous. It was something that we didn't have the chops to see. But because, when I say I had an eye for privacy, I knew what was wrong because of my previous knowledge.
But someone who was new would probably not understand, what was being done. So basically, I think in summary it was more like an occasional internal audit process. I looked through the website, I saw that something was wrong, and I'm thankful I did that. And the reason I even had that understanding was because I understood the GDPR, and I could [00:10:00] actually operationalize the GDPR in our processes.
And, I did that. ~We're able to,~ we're able to figure that out. But like I said, the next thing I did was to ensure that every campaign that had ~c-~ that was going to getting customer data had to run through privacy. It was no longer an occasional exercise, it was now routine. So that was how I figured that out.
Yeah, which makes a lot of sense too. And I like that you said it's now routine, right? You're also educating individuals as you're going through this process. ~O-~ one of the things I always think about, again, and this is my own bias as a marketer, but nobody's intentionally going out trying to violate GDPR.
My guess is that when the marketing team set up this form, they weren't thinking through all the various consent states- No ... that need to exist to abide by the all aspects of GDPR.
~What,~ what advice would you give to legal teams that are maybe having the frustrations of you sit in the spot where you maybe understand these laws inside and out, the marketing team doesn't, so you're trying to find that balance of educating them without, getting into fights every single day and slowing them down, which is what they always claim.
What would you give to someone- Yeah ... in a different company? [00:11:00] Yeah. So I think I'll talk about it from two front. So for a marketing company, I want them to understand that, these legal processes is not... They are not blockers, they are actually trust builders. Right now there are so many businesses, and every customer wants to feel like their data is being protected.
We are having data breaches here and there, and people want to know that if I give you this important information to me, you're going to keep it. So by putting in these privacy checks, you are sending a message to the consumer that we care about your data, and we want to build this trust with you. So I just want to reframe that for the CMOs and for all marketing professionals, that this is a trust builder.
This is an asset. This is not a roadblock. So running through things to your privacy team or trying to make them, trying to make sure you go through, you put in privacy best practices is a trust builder, is not a roadblock. So that's for the privacy, that's for the CMOs or marketing professionals.
But for the lawyers, I would say education is a really big deal. A marketer doesn't want to break the [00:12:00] GDPR. Nobody ~w-~ nobody actually just goes and says, "Oh, I wanna break the law," you just... Their metric is to get in customers, and so to get in customers, they put in what step they feel is the best for them.
And for them, lead generation is important, and then they're going to put every step they want to put into lead generation. So you as the lawyer, your own metric is to ensure that you are compliant. And so the best way to do that is to actually educate, and I would say make it a process. Have process documents.
Some of these things are institutional knowledge where the lawyer just feel like, "Oh man, you should know that," and the marketer are like, "I don't know that." So you actually have to write down everything step by step, make it clear for the marketers to understand, and then recommend or send in these documents that they have to follow these steps and, explain to them.
So I think the best way for lawyers is to actually put down, like I call it, operationalize the law, put everything together, have a strategy document, send it to every stakeholder involved so they [00:13:00] understand why they do what they do, and they understand how to do what they do. I guess
that's the advice I'm gonna give to both parties in this situation.
That's good. It's almost like internal marketing to the marketing team, but also- Yes ... again, it's education for the legal team as well, which is smart. Yeah. There's a lot of enablement there. ~Y-~ it got me thinking. I, so I'm actually joining this call today from Boston.
... I've been hosting a series, and I think I've mentioned this on the podcast before. I've been hosting a series of web privacy meetups across the country. We've done probably 12 to 15 of these so far, and one of the things I hear most often from privacy leaders from every large organization across the country, and across the globe too we've done quite a few of these in Europe as well, is that there is a gap.
There's a big glaring gap between the technologists that usually represent the marketing team, and then the understanding of the law that sits on the privacy teams, the legal side, attorneys, analysts, et cetera, and it's trying to bridge those gaps together. The reason I bring this up, Uche, is because you mentioned that you were going through a routine check.
A lot of people have a tough time doing that because they're turning to the [00:14:00] marketing team and asking for documentation. What does our consent currently look like? I've done enough reports in my life to know that a lot of times massive Fortune 1000 companies don't understand how out of compliance they currently are.
What advice would you give to your peers who are on the privacy legal side in doing those routine checks? How do they go about that? How do they start that? What are they looking for? Let me think about this. I think they should think like an internal auditor. You have to...
So further education that goes about it, you know that I know that there's a lot of work to be done. Just your personal day-to-day grind can actually be very stressful. But the overarching thing here is that you want your company to be compliant so that you don't get any fine, and also so that you build trust with your customers.
So I would say you work like an internal auditor. You go through, you have a plan okay, for this day we are going to check marketing. This day we're going to check cybersecurity. You go to them, you look through their processes, you ask for documentations when you can.
Sometimes they don't have it, then ask someone to run you through a [00:15:00] verbal step-by-step process. And then when they're running you through this, you document it. So as you build your own process, document it yourself, and then ask them to try it. Ask if they say, "This is what we do on our website," tell them to show you, so in this point, you are acting like an internal auditor to the business, and then when they walk you through those things, you are now able to identify the gaps or whatever, or where you see there are no compliance with the law. And with that, you're able to resolve these issues. So it's... I'll call it like a project.
It's not easy. It's not very easy to get your hands dirty. It's not very easy to, leave your day-to-day tasks and start to do this work. But I would say that once you're able to do it, it gets easier from then on. So you go through this, so like I said, ~you,~ you act like an internal auditor, audit every process, verbal, non-verbal, whatever IT they tell you, write down your recommendation and the process documents and then, work, start working from there.
Just do it step by step. It's not easy, but, it has to be done. Yeah. I totally agree. Otherwise, again you get to choose- Yeah ... the [00:16:00] risk tolerance and the risk level that you're willing to take on as a company, so- That's true ... ultimately. Yeah, that's true. You got that to me.
So that's also something that you need to work with your, what we call the controlled environment, like the, what the boss says what risk are you willing to tolerate? What risk are you willing to avoid? What risk do you feel, "Okay, I'm willing to take this." But know that privacy risks are very expensive.
I think it's about four, like a breach about 4% of your company's gross revenue. So work with that in your head while you're making this decision. But you also check out the tolerance level you have and then work with that too. Of that? Yeah, Uche, you mentioned specifically, obviously your story revolves around a marketing form and the- consent box that's associated with that. Are there other areas of that marketing journey that you're typically trying to look out for, like a cookie banner, preference centers, webinar sign-ups, gated content? Anything like that or are there others I'm missing or...? Yeah. I think something that I've started seeing a lot now is resource downloads.
So I've noticed [00:17:00] that as part of marketing, people, most companies tend to put out a resource out there, and then if you want the resource, you have to put in your information. And this is actually a really good marketing tip, but the thing is that your, this has to be unbundled. A customer saying, "I want to receive this resource," doesn't mean they want to receive promotional emails.
That's something to look out. So when you are, bringing out resource for, resources for people, you also have to check and make sure that the, whoever signs up for these resources also voluntarily signs up to receive promotional emails. It shouldn't be bundled together. And also, privacy by design should be in your website.
~A--~ the cookies, like the accept cookies button should be like the most privacy intensive option, 'cause sometimes you... That's something I think I've noticed in a few website, which I don't think is a really good idea. The default option should be the most privacy intense option, as opposed to being the least privacy centered one.
I'll say that's for cookies. Resource, there was something that came to mind also for, DSAR [00:18:00] requests that are coming. You have to ensure that ~when-whenever~ DSAR requests you receive is connected to your internal workflow. So I think this is where tools like, OneTrust, I don't know if that's something to say, if that's marketing for OneTrust, but I know that this
is where tools like OneTrust come into play where, they're able to gather this information. Like, when customers request for their, for their DSAR, is able to trigger a workflow in your system, and you're able to send that. 'Cause I think a couple of countries have different, a couple of states in America have different days where you have to respond to this.
So I think these three things are things to watch out for. But mostly privacy by design. Cookies, only essential cookies should be granted, except ~the,~ the user actually signs up for non-essential cookies. Yeah, I think that's all I can think about now. I believe that's clear enough. Y-you mentioned actually just in your response there, w-we've been talking a lot about GDPR, but you veered into the various stages of the DSAR execution.
Are there other regulations that you're constantly looking out for outside of GDPR? Does that fall under your jurisdiction, or is that others? So CCPA- Yeah ... DPDPA in even [00:19:00] India, others like that. There are so many. There are so many. So I think it's now up to your country or your company to look out for where do your, where are your customer service.
So GDPR is the biggest, I think is the most intensive regulation that I can think about right now. Because most ~ins- most,~ most national companies actually have European Union residents as their customers. So if you're in like, say, Nigeria, there is like the NDPR, which is a Nigerian Data Protection Regulation.
You have to look at that. If you're working with Indian customers, you have to look at the Indian law. So everything all depends on the states where you're working on. So I ~g-~ I guess this is where tools come in, because you can't always keep track of every country's privacy regulations. So I know there ~are~ some tools that are able to, map out these data sets or map out data points and map out what regulations actually work for you.
And I guess this is where tools come in. So this is where the legal team actually has to work with the technical team and work with, the pri- the product owners to understand these tools and to really map it out. So you just ~ha-~ you [00:20:00] have to keep being informed. You have to be aware of whatever new regulations are coming in.
The UK AI Act is out. You have to be aware of that. There are so many provisions. It's honestly a lot but, you just have to keep track of all of them. What do you think most people are getting wrong right now in the world of consent and privacy regulation? I would say it's the opt-in, opt-out rule.
Most... I know most some laws actually allow, I'm trying to remember the law now, but I think the CCPA, if I'm not correct, focuses on an opt-in and not an opt-out approach. But not every state. Some states are okay with an opt-out approach where you can implicitly sign a customer and then they now have to opt out.
So I think that's the first thing. In most states, particularly in America, people use the opt-out approach. But I know that ~in the Europe part of in Europe,~ opt-in is actually more, is more taken. So if you're working with... You can't just have a universal framework. I guess that's my point.
There's no universal framework. You have to be careful with where you're working. You have to be careful where your customers are so [00:21:00] you don't receive, you don't receive a fine. I guess maybe where, to answer your question without going too far is, you cannot have... People tend to think a universal framework will work for the entire company, and my response to that is no, because right now data is just scattered everywhere.
So even though you think you're only serving one country, and that country or some other residents of other countries could actually slip into your, to your data sets. So you can't have a universal approach. You have to~ you have to~ customize to, for ~every, ~every customer you have.
So I guess that's what I'll say it's a lot, yeah, and ~it- that's,~ that tends to be exactly what I hear. Again~ I've~ I've been traveling the country a lot, much to my young kids' chagrin- ... meeting individuals, meeting privacy professionals, and it's always the same thing. It's trying to keep up with the regulations.
It's trying to manage the opt-ins and opt-outs across millions of webpages, across- ... various user states before opted in, after opted out GPC, which we haven't even mentioned yet, the GPC signal as part of the California- Yeah, that's true ... briser regulation as well, and it's getting more complicated.
It's getting more complicated, yes, and it's ~g-~ [00:22:00] it's gonna get more complicated. So I guess this is a space for people to develop tools and, new... I'll say tools. I think your best help is going to be technical solution, for, for tools like I think about Vanta or OneTrust.
They can help to map out all of these things 'cause I don't think it's really possible to keep track of everything, just with your head it's not. I can- ... I can promise it's not, yeah. You're not wrong. Uche, I don't wanna keep you too long. Thank you ... let me give you one last question if you don't mind.
Okay. ~Last question. Last question I wanna give- Okay ... to our listeners today is- Yeah ...~ what is one thing... we've talked about a lot of things today, but what is the one thing that you'd want a privacy lead or a chief marketing officer to do differently after hearing you talk today? So I guess from my story, and what I always like to say to every marketing professional is focus on quality leads.
I know that sometimes the metric is numbers. You want to have a lot of numbers in the top, in the funnel, and this now lead people or lead the marketing team to get numbers and emails from every angle. [00:23:00] But I will say that quality is more important. You want to make sure that whoever signs in for your content or whoever subscribe to your newsletter is someone who wants to subscribe to your newsletter.
No hanky-panky. Don't try to toggle something that shouldn't be toggled. ~Don't try to, ~don't try to force people to subscribe to your content. I would say focus on putting out quality work out there, and whoever wants to come in, let them actually consent to it. And this is why I say you can do a two-factor approach, which is sending the message to their emails and letting them sign in.
Because when it comes down to it, you want convertible clients. You don't just want so much number, because this will only add noise to your data. You want clients that will convert and buy your products. So it's only a, a consensual, client that will actually buy what it is you're selling.
So I would say look at your workflows. Think of your metrics. Don't focus on numbers and don't focus on, "We have so many leads." Focus on quality leads and people who actually want [00:24:00] what it is you are having. So I guess that'd be my biggest advice to marketing professionals right now. I love that.
That's great advice, and I'm taking notes over here as well. Yeah. I know you mentioned don't give them the hanky-panky. But again, I always joke with people, if you're gonna play the game and you're gonna do things that are outside of the regulatory boundaries that have been set in these various locations, whether statewide laws in the United States, GDPR or others, LGPD, there's DPDPA, others, Yeah.
So many ... don't be don't be surprised when your hand gets bitten or you get slapped in the hand and face or anything. If you're playing there, that those are the consequences, that's true. That's true. Come with consequences, and it just also helps you to build trust, there are so many companies right now~ so many companies,~ and people are becoming concerned. Every day you see a data breach here and there, so people actually want to feel safe. They want to feel like you are safe, so you need to give off that vibe, as the kids would say give off a good vibe.
Give them a good vibe. I love it. ~A-~ and with that, Uche, thank you so much for joining. I hope everybody who joined today is going to have those good vibes. I hope they can go away and everyone go [00:25:00] check your forms. Make sure you guys are following GDPR compliance. Thank you, all. Thank you, Uche, and thank you for joining the Web Privacy Podcast, and we'll see you all next time.
All right. Thank you so much.