Privacy Champions Community by Privacy License

Privacy & AI Governance has an awareness problem.

Only 28% of companies are fully compliant with privacy & AI Governance laws. Most privacy & AI Governance professionals are left without the support or tools they need to drive real change.

To solve this, we are building a free, curated community of Privacy Champions!

As a Privacy Champion, you'll get, 100% Free:

  • Live Trainings & Webinars - Learn directly from privacy & AI Governance leaders at Fortune 500s and cutting-edge startups.
  • Ask-the-Experts Sessions - Bring your toughest privacy & AI Governance blockers, get answers from the community of privacy & AI Governance experts from top fortune 500 companies.
  • Early Access to Open-Source Privacy & AI Governance Tools to drive real privacy change in your organization.
  • Global Peer Network - Expand your network with a community of privacy & AI Governance professionals from organizations of various sizes, industries and sectors from all over the world!
  • Make a difference - Collaborate on Open source initiatives benefitting the broader Privacy and AI Governance community!
  • First Dibs on Privacy License Offerings - Be the first to test advanced AI tools that streamline compliance, before the public release.

Bonus: $3,000+ in Free Privacy & AI Governance Resources
Our community members get early access to premium tools, expert insights, and curated templates you’d usually pay thousands for, free, forever.

Sign up for our Free Privacy Champions Community or upcoming online Webinars

Join a private, high-impact space, where Privacy and AI Governance leaders grow, learn & shape the future together.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Upcoming Privacy Champions Community Online webinars

On Wednesday, March 11th, 2026 at 10:00 AM PST, Privacy License is hosting a free, live 1-hour executive briefing on “The Illusion of Control: When “Mature” TPRM Programs Still Lose Privacy,” featuring  Shruti Mukherjee, Director, Governance, Risk and Compliance, in conversation with Founder & CEO, Nabanita De, Privacy License.

Third-party risk management (TPRM) programs have evolved significantly in recent years. Organizations now point to advanced ERM alignment, standardized assessments, continuous monitoring tools, and stronger contractual safeguards as evidence of maturity.

On paper, it looks like progress. Yet privacy incidents involving third parties continue to surface with alarming frequency.

This session examines a difficult but necessary question:  Why does privacy accountability continue to fail even in mature TPRM environments? 

Drawing on real-world advisory experience and regulatory trends, this session argues that the issue is rarely a lack of framework sophistication. Instead, failures occur where accountability is assumed rather than operationalized.

Participants will explore how privacy risk becomes diluted across legal, procurement, security, and business functions; why contracts often create a false sense of control; and how static assessments fail to keep pace with evolving vendor behavior.

The session moves beyond theory and focuses on practical mechanisms for shifting from process maturity to accountability maturity, ensuring privacy risk is actively governed throughout the vendor lifecycle, not just documented at onboarding.

Learning Objectives
Participants will:

  • Understand why advanced TPRM frameworks do not automatically ensure privacy accountability
  • Identify where ownership breaks down across the vendor lifecycle
  • Recognize the limitations of static assessments and checkbox compliance
  • Evaluate the false comfort of contractual safeguards without operational enforcement
  • Learn practical strategies to strengthen third-party privacy oversight

This session is ideal for:

• Chief Privacy Officers
• Data Protection Officers
• Third-Party Risk Managers
• Compliance & Risk Leaders
• Legal Counsel handling vendor contracts
• CISOs and Security Governance Professionals
• Board and Audit Committee Advisors

About our Speaker

Shruti Mukherjee is a GRC leader specializing in privacy governance, third-party risk management, and AI accountability. She works at the intersection of privacy, security, and operational risk, helping organizations move from documented compliance to demonstrable control effectiveness.

Shruti has led enterprise risk transformation initiatives, vendor governance enhancements, and AI governance programs across regulated environments. She is a frequent conference speaker on privacy accountability, AI risk, and modern GRC practices, and is known for translating regulatory expectations into practical, operational frameworks that withstand audit and regulatory scrutiny.

Previous Privacy Champions Community online webinars

Join Privacy Champions Community to get access to previous talks and $3,000+ in Free Privacy Resources & Trainings.
Our community members get early access to premium tools, expert insights & curated templates you’d usually pay thousands for  free, forever.

DPDP Act Implementation : Myths & Facts

By Associate Director, PWC

On Wednesday, March 4th, 2026 at 5:00 PM PST, Privacy License hosted a free, live 1-hour executive briefing on “DPDP Act Implementation : Myths & Facts,” featuring Abhishek Tiwari, Associate Director, PWC, in conversation with Founder & CEO, Nabanita De, Privacy License.

As India’s Digital Personal Data Protection Act, (DPDP Act) moves from policy discussion to real-world enforcement, organizations across startups, enterprises, healthcare, fintech, edtech, and AI ecosystems are facing a critical moment of confusion.

Many companies believe they are compliant because they have a privacy policy.
Others assume DPDP only applies to large corporations.
Some think consent banners are enough.
And many underestimate enforcement, penalties, and cross-border implications.

The result? A dangerous gap between perceived compliance and actual regulatory exposure.

This session will help privacy leaders, founders, compliance teams, and AI governance stakeholders separate myth from reality — and understand what DPDP implementation actually requires at a technical, legal, and operational level.

We’ll move beyond surface-level summaries into practical, execution-level clarity.

We covered:

• The most common myths about DPDP Act applicability and enforcement
• Who qualifies as a Data Fiduciary vs Significant Data Fiduciary — and why it matters
• The real meaning of consent under DPDP (and what invalidates it)
• Children’s data, verifiable parental consent, and age-gating challenges
• Cross-border data transfers — what is actually restricted vs misunderstood
• Notice requirements and dark pattern risks
• Data minimization, purpose limitation, and retention obligations in practice
• Grievance redressal and Data Protection Board exposure
• Penalty structures and real financial impact scenarios
• Implementation checklists for startups, mid-market, and enterprise companies
• How DPDP intersects with GDPR, CCPA, and global privacy programs
• Practical governance controls to move from “policy written” to “program implemented”

Because compliance is not about publishing a policy.
It’s about operationalizing accountability.

This session is ideal for:

• Founders and Startup Operators
• Chief Privacy Officers and Data Protection Officers
• CISOs and Security Leaders
• Legal & Compliance Teams
• AI Governance and Product Leaders
• Healthcare, Fintech, and EdTech Compliance Teams
• Risk & Regulatory Affairs Professionals
• Privacy Engineers and Technical Governance Teams
• Venture Investors evaluating regulatory risk

About our Speaker

Abhishek Tiwari is a distinguished leader in privacy, data protection, and AI governance, known for driving national-scale initiatives and elevating industry capability. He is a globally certified privacy professional; his certifications include CIPP/E, CIPM, CIPP/A, AIGP, and he is also an FIP demonstrating his commitment to the highest international standards of excellence.

His expertise is recognized globally through his inclusion in the European Data Protection Board’s Pool of Support Experts, where he contributes to impactful advisory work and policy development. Abhishek is also an IAPP Asia Vanguard Award recipient, one of the most prestigious honors in the global privacy community.

He served as an Education Advisory Board member during 2024-2025 and beginning January 2026, he will serve on the IAPP Privacy Engineering Section Advisory Board, representing India in shaping the future of privacy engineering and responsible data innovation worldwide.

Widely recognized as the driving force behind Pan-India privacy event planning and execution, Abhishek has transformed how privacy conversations happen across the country. His vision, network, and on-ground leadership have helped create one of India’s most vibrant and influential privacy communities bringing together regulators, global experts, industry leaders, and emerging professionals to accelerate the nation’s privacy and AI governance journey.

When Confidentiality Meets the Cloud: Evidentiary Priviledge Challenge in Enterprise AI

By Vice President, Regulatory Compliance, Integra Connect

On Wednesday, February 25th, 2026 at 9:00 AM PST, Privacy License hosted a free, live 1-hour executive briefing on “When Confidentiality Meets the Cloud: Evidentiary Privilege Challenge in Enterprise AI,” featuring Marlyse McQuillen, Vice President, Regulatory Compliance, Integra Connect, in conversation with Founder & CEO, Nabanita De, Privacy License.

As organizations rapidly deploy AI tools across legal, healthcare, financial services, and enterprise environments, a critical risk is being overlooked: evidentiary privilege. While privacy programs focus on safeguarding personal data, attorney-client communications, doctor-patient discussions, and therapeutic confidences are meant to be legally protected at an absolute level. However, common AI practices such as logging, model training, prompt retention, and multi-tenant cloud architectures may inadvertently waive privilege, sometimes permanently.

This session helps privacy professionals, legal teams, compliance leaders, and AI governance stakeholders understand how AI systems can silently erode centuries-old privilege protections, and what to do before irreversible legal consequences occur.

We’ll move beyond theory into practical, real-world risk scenarios and mitigation strategies.

We covered:

• The difference between privacy compliance and evidentiary privilege
• How AI tools (chatbots, copilots, enterprise AI platforms) can inadvertently waive privilege
• The impact of logging, telemetry, model training, and multi-tenant infrastructure on confidential communications
• What state ethics boards and regulatory authorities are saying about AI use in privileged contexts
• Real-world scenarios where privilege may be broken through routine AI usage
• Practical checklists and governance controls to preserve privilege in AI-enabled environments
• Contractual, technical, and operational safeguards organizations should implement immediately
• How to educate legal, product, and engineering teams on privilege-specific AI risks

Because once privilege is waived, it cannot be restored.

This session is ideal for:

• General Counsels and In-House Legal Teams
• Chief Privacy Officers and Data Protection Officers
• AI Governance Leaders
• CISOs and Security Leaders
• Healthcare, Financial Services, and SaaS Compliance Teams
• Privacy Engineers and Technical Governance Professionals
• Risk, Ethics, and Regulatory Affairs Leaders
• Founders deploying AI into regulated environments

 
About our Speaker

Marlyse McQuillen is a senior privacy, data governance, and AI governance counsel with more than 17 years of experience advising highly regulated SaaS, healthcare, and financial services organizations.

She has built enterprise privacy and AI governance programs from the ground up, led incident response and regulatory engagement that preserved tens of millions in revenue, and translated complex regimes like GDPR, CCPA/CPRA, GLBA, HIPAA, and emerging AI regulations into pragmatic controls for product and engineering teams.

Prior to going in-house, Marlyse focused on M&A and securities as an associate at Greenberg Traurig’s Miami office. Marlyse holds a JD, summa cum laude, from the University of Miami, a BA from Harvard University, and multiple industry certifications, including AIGP, CIPP/US, CIPP/E, and CIPM. She also volunteers as an advisor/DPO for The Plunk Foundation, a nonprofit promoting digital data privacy for women, children, veterans, and underserved communities.

Getting Started with India's DPDPA

By EY's Senior Privacy Consultant

On Friday, February 6th, 2026 at 05:00 PM IST, Privacy License hosted a free, live 1-hour executive briefing on “Getting Started with India’s Digital Personal Data Protection Act (DPDPA)”, featuring Chetandeep Singh Batra, Senior Consultant at Ernst & Young (EY), in conversation with Founder & CEO, Nabanita De, Privacy License.

As India enters a new era of data protection with the DPDPA, organizations across sectors are facing fundamental questions around compliance, governance, operational readiness, and regulatory interpretation. From startups to large enterprises, understanding how to practically operationalize the DPDPA is now a business-critical priority.

This session helps privacy professionals, legal teams, compliance leaders, and data governance teams understand the core building blocks required to get started with DPDPA implementation, moving beyond legal text into real-world execution.

We’ll break down what it truly takes to operationalize India’s privacy law, including practical insights from advisory work and industry experience.

We covered:

  • An overview of the DPDPA and how it compares with GDPR and other global frameworks
  • Key obligations for Data Fiduciaries and Data Processors
  • Practical steps for building a DPDPA compliance roadmap
  • Consent management, notice requirements, and data principal rights
  • Data localization, cross-border transfers, and regulatory expectations
  • Common pitfalls organizations face when starting DPDPA compliance
  • How to align legal, technical, and operational teams around privacy


This session is ideal for:

  • Data Protection Officers and Privacy Leads
  • Compliance, Risk, and Legal Professionals
  • Chief Privacy Officers and General Counsels
  • CISOs, Security and Data Governance Leaders
  • Founders and Startup Operators building in India
  • Privacy Engineers, Analysts, and Program Managers
  • Organizations preparing for DPDPA enforcement

About our Speaker

Chetandeep Singh Batra is a lawyer and privacy professional with over 5 years of experience in data protection and cybersecurity. He currently works at EY as Assistant Manager in Data Privacy and also serves as the IAPP Chapter Chair for New Delhi, contributing actively to the global privacy community.

He holds CIPP/E and ISO 27001/27701 certifications and has a strong background in privacy laws, compliance frameworks, and governance programs. An accomplished author, Chetan has written 7 books, including two focused on privacy and cybersecurity.

With a diverse background spanning legal advisory, compliance, and privacy governance, he brings a highly practical perspective on how organizations can translate regulatory requirements into real operational programs.

Traits of an effective DPO

by Head of Data Privacy at Saudi Credit Bureau

On Saturday, January 31st, 2026 at 07:30 AM PST, Privacy License hosted a free, live 1-hour executive briefing on “Traits of an effective DPO”, featuring Muneeb Imran Sheikh, Head of Data Privacy at Saudi Credit Bureau, in conversation with Founder & CEO, Nabanita De, Privacy License.

DPOs are higly sought after roles that require complex navigation between protecting the individuals’ rights and also ensuring that organizations maintain and exhibit adherence to Data privacy regulations. In an era where Data Privacy has become ever more important its important for privacy professionals to understand the competencies are essential to implement data privacy programs within an organization.

This session helped privacy professionals, compliance leaders, and data governance teams understand the core competencies required to design, implement, and manage effective privacy programs within organizations of all sizes.

We broke down what it truly takes to operationalize privacy, moving from regulatory theory to practical, actionable strategies that drive both compliance and business value.

We covered:

  • The evolving role and responsibilities of the DPO in today’s regulatory environment.
  • Core competencies every privacy professional must master
  • Practical steps for implementing privacy programs aligned with GDPR and other global frameworks
  • How to balance business objectives with data protection obligations
  • Strategies for managing cross-border data transfers, vendor risks, and consent frameworks
  • Common pitfalls that can undermine compliance and how to avoid them
  • Leveraging privacy governance as a source of organizational trust and competitive advantage

This session is ideal for:

  • Data Protection Officers and Privacy Leads
  • Compliance and Risk Management Professionals
  • Chief Privacy Officers and General Counsels
  • Data Governance and Security Leaders
    Policy Makers and Regulators overseeing privacy frameworks
  • Privacy Engineers, Analysts, and Program Managers
  • Organizations preparing for or enhancing GDPR and global privacy compliance

About our Speaker

Muneeb Imran Sheikh is Head of Data Privacy at Saudi Credit Bureau and an Data Privacy, Cybersecurity & AI Governance Expert with a forte in Strategy, Program development, Governance, Risk and compliance.

Based in Middle East region, he has worked with different clients from financial, governmental and telecommunication sector to help them in developing and implementing Cybersecurity and Privacy program in accordance with their regulatory, legal and compliance requirements. He is author of a book Data Privacy, A Practical Handbook on Governance and Operations.

He has contributed with his knowledge and expertise through various writings, podcasts, policy reviews, conference appearances.

EU AI Act Enforcement Has Begun, Implementing the General Code of Practice Now

On Wednesday, August 13th, 2025 at 10:00 AM PST, Privacy License hosted a free, live 1-hour executive briefing on “EU AI Act Enforcement Has Begun, Implementing the General Code of Practice Now”, led by our Founder & CEO, Nabanita De, Privacy License.

The EU AI Act officially came into force this month, introducing up to €35 million in penalties for non-compliance. At the heart of the regulation lies the General Code of Practice, a set of requirements that will define how AI companies, privacy leaders, and policy makers govern the lifecycle of AI systems.

While many leaders understand the policy text, far fewer have a clear blueprint for translating it into operational, engineering, and governance practices. This session will break down the regulation into practical, implementable steps so you can move from “risk” to “ready” immediately.

We covered:

  • What the General Code of Practice actually requires (beyond the headlines)
  • Day-one implementation priorities for privacy, security, and AI teams
  • How to embed governance and compliance signals into AI systems, models and data
  • Avoiding common compliance pitfalls that could trigger investigations or fines
  • Leveraging compliance as a competitive advantage in AI markets
  • Tools, frameworks, and checklists for cross-functional alignment between legal, technical, and policy teams

This session is ideal for:

  • Chief Privacy Officers and CISOs operationalizing AI governance
  • Policy makers and regulatory advisors shaping AI compliance frameworks
  • CEOs and founders of AI companies building or deploying AI systems in the EU market
  • Privacy engineers and technical leads implementing regulatory requirements
  • AI/ML practitioners who need to understand privacy requirements and build responsibly
  • Product managers responsible for embedding privacy and compliance into AI lifecycles

About our Speaker

Nabanita De is the Founder & CEO of Privacy License, where she built the missing enforcement layer for the EU AI Act and the world’s first licensing framework that governs AI training after data is scraped.

As an AI, Privacy, and Security leader at publicly traded fintech companies, Microsoft Research, and Uber, Nabanita has designed and led privacy programs spanning data governance, privacy engineering, and AI governance, acrossing exabytes of data, saving organizations over $4 billion in compliance and architectural costs.

Her groundbreaking work has been featured in Forbes, TechCrunch, Fast company, Business Insider, Washington Post, Wired, Fortune, CNN, BBC, and over 1,000+ news and research publications worldwide. She also serves on the IAPP Privacy Engineering Advisory Board.

Bridging the Gap Between Privacy Policy and Privacy Engineering

By Head of Technology Law, Privacy/Data Protection and AI Governance at Oguntoye & Oguntoye 

 

On Thursday, July 31th, 2025 at 9:00 AM PST, Privacy License hosted a free, live 1-hour webinar on “Bridging the Gap Between Privacy Policy and Privacy Engineering”, featuring Ridwan Badmus, Head of Technology Law, Privacy/Data Protection and AI Governance at Oguntoye & Oguntoye LP, in conversation with our founder & CEO, Nabanita De.

This session focussed on the persistent disconnect between privacy lawyers and privacy engineers in translating legal privacy requirements into actionable engineering outcomes. While privacy laws and policies set the framework for compliance, product teams often face challenges in implementing these frameworks effectively due to differing terminologies, approaches, and priorities.

Whether you're a privacy lawyer drafting policy or an engineer implementing technical controls, this talk equipped to collaborate more effectively across disciplines. We explored:

  • How privacy lawyers and engineers can better understand each other’s roles and priorities
  • Techniques to bridge the communication gap between legal and technical teams
  • Collaborative strategies to embed privacy-by-design into systems and product development
  • Practical approaches for aligning legal risk assessments with technical implementation
  • Methods to improve cross-functional collaboration across privacy, legal, product, and engineering
  • How to drive a unified approach to data protection that enables both compliance and innovation

This session is ideal for:

  • Privacy leaders, lawyers and policy professionals seeking to influence product decisions and translate policy into practice
  • Privacy engineers and technical leads responsible for implementing data protection controls
  • Product managers and cross-functional stakeholders embedding privacy into the product development lifecycle
  • Compliance, risk, and security professionals working to operationalize privacy across AI and data systems
  • AI/ML practitioners who need to understand privacy requirements and build responsibly
  • Anyone working at the intersection of privacy, technology, and product innovation

About our Speaker

Ridwan Badmus is the Head of Technology Law, Privacy/Data Protection and AI Governance at Oguntoye & Oguntoye LP, Privacy Engineering and AI Governance Lead at TechStabs Consulting and Co-Founder/Privacy Technologist at FR Data Protection. He's certified as an AI Governance Professional and Information Privacy Technologist with the International Association of Privacy Professionals (IAPP). Ridwan specialises in seamlessly integrating privacy, data protection & trustworthy AI requirements into products to process data responsibly. As a technology lawyer, he provides legal expertise across various domains, offering rare multidisciplinary support to startups and enterprises.

Integrating Privacy into the Artificial Intelligence Dev Lifecycle

By Senior Privacy Engineer, T.Rowe Price

On Monday, June 16th, 2025 at 9:00 AM PST, Privacy License is hosted a free, live 1-hour webinar on “Integrating Privacy into the Artificial Intelligence Dev Lifecycle”, featuring AbdulMajeed Raji, Senior Privacy Engineer, T.Rowe Price, in conversation with our founder & CEO, Nabanita De.

As artificial intelligence becomes a core pillar in product innovation, embedding privacy directly into the AI development lifecycle is critical for building trustworthy systems. Whether you are developing AI models, advising on responsible AI governance, or integrating privacy by design into data-driven products, this session provided practical strategies to bridge privacy and AI engineering. We covered:

  • How to integrate privacy considerations at each stage of the AI development lifecycle
  • Practical approaches for addressing privacy risks in model training, deployment, and monitoring
  • The evolving regulatory landscape around AI and its privacy implications
  • Real-world examples and lessons learned from implementing privacy solutions at scale

and more!

This session is perfect for:

  • Privacy professionals collaborating with AI and data science teams
  • AI practitioners looking to build privacy-resilient systems
  • Legal, compliance, and security professionals navigating AI risk governance
  • Product and engineering teams embedding privacy by design into AI initiatives
  • Anyone curious about the intersection of privacy and artificial intelligence in today’s fast-evolving landscape

About our Speaker
AbdulMajeed Raji is a Senior Privacy Engineer at T. Rowe Price, driving the implementation of privacy engineering frameworks. With a career spanning nonprofits like Save the Children International and major privacy organizations, AbdulMajeed brings deep expertise in translating complex privacy principles into practical engineering solutions that scale across industries.

Credentialing for Privacy Professionals

By Data Privacy Architect, Allegis Group

On Wednesday, June 5th, 2025 at 9:00 AM PST, Privacy License hosted a free, live 1-hour webinar on “Credentialing for Privacy Professionals”, featuring Swati Popuri, Data Privacy Architect, Allegis Group and dual-certified privacy leader (CIPT, CIPM), in conversation with our founder & CEO, Nabanita De.

As privacy becomes a boardroom priority and job listings increasingly demand privacy certifications, getting credentialed can unlock the next level in your privacy career. Whether you're transitioning into privacy, leveling up your skillset in privacy or aiming to stand out in a competitive job market, this session is catered to help you navigate the certification landscape with clarity and confidence. We covered:

  • Which privacy certification aligns with your career goals (CIPT vs CIPM vs others)
  • How to prepare effectively for your exam including study strategies, timelines, and resources
  • What to expect during the certification process and how to stay motivated
  • How to maintain your certification post-exam through CPE credits and community engagement

This session is perfect for:

  • Privacy professionals planning to get certified.
  • Aspiring privacy professionals looking to break into the field
  • Mid-career legal, compliance, product, or security professionals looking to pivot
  • Certified professionals seeking tips on maintaining credentials and growing their influence
  • Anyone curious about the practical value of privacy certifications in today’s evolving landscape

Note: This session is independently hosted and not affiliated with or endorsed by IAPP. It will not reveal any proprietary exam questions.
 
About our Speaker
Swati Popuri is a Data Privacy Architect at Allegis Group working at the intersection of technology and society. She has implemented privacy engineering frameworks at Fortune 500 companies like American Airlines and social media platforms like Twitter, helping organizations translate complex regulations into scalable, real-world systems. Swati is dual-certified with IAPP CIPT and CIPM credentials and brings firsthand insight into what it takes to prepare, pass, and apply privacy certifications in fast-paced, high-impact environments.

Privacy By Design 101

By Meta Privacy Program Manager

On Thursday May 29th 2025 at 10:30 am PST, Privacy License hosted a free live 1 hour webinar on "Privacy By Design 101", featuring Carolina Braga, Privacy Program Manager, Meta, in conversation with our founder & CEO, Nabanita De

In a world where data is the new currency and regulation is tightening, privacy can no longer be an afterthought. In this session, we unpacked how to turn privacy into a design principle, not a patch. Whether you're launching your first product or scaling privacy across global teams, this session covered how you proactively embed privacy into every layer of your business. Topics we’ll explored included:

  • What Privacy by Design really means (and what it doesn’t)
  • The 7 foundational principles of PbD—and how they apply beyond theory
  • How to operationalize PbD across the entire product lifecycle—from ideation and prototyping to engineering and post-launch reviews
  • Real-world implementation tips: how to integrate privacy workflows without slowing down innovation
  • Common pitfalls to avoid when working with cross-functional teams in agile and fast-paced environments
  • Expect practical insights, real examples, and forward-looking strategies that help you shift privacy from a compliance checkbox to a competitive advantage.

Perfect for privacy leaders, privacy managers, product leaders, engineers, founders, and privacy professionals looking to scale trust with speed. 

About our Speaker

Carolina Braga is currently Privacy Program Manager at Meta and an accomplished AI governance and data protection leader with a global track record of operationalizing scalable, risk-based privacy programs across complex, high-stakes environments. With over a decade of experience spanning technology, consulting, and corporate sectors, she has led major privacy initiatives at companies in the tech, pharmaceutical and oil and gas sectors. Carolina specializes in embedding Privacy by Design into AI product lifecycles, conducting DPIAs, and aligning enterprise operations with evolving regulations such as GDPR, LGPD, and PIPL. Her expertise bridges legal, technical, and strategic domains, driving cross-functional collaboration, streamlining compliance workflows, and spearheading regulatory readiness across global teams. Carolina holds a Master of Law, focused on Responsible AI and an MBA in Information Security Management.

 

How to Build a Privacy Program

By Privacy Engineering Manager, Lumin Digital

On  Thursday,  May  8, 2025  at 12:00 PM  PST, Privacy  License hosted a free live 1 hour webinar on “How to Build a Privacy Program", featuring Debra  Farber, Privacy  Engineering Manager at  Lumin  Digital, in conversation with our founder &  CEO, Nabanita  De. Against the backdrop of AI‑driven innovation and rapidly evolving global regulations, we unpacked why 2025 is a pivotal year for privacy, debunk common compliance myths, outline the crucial first steps for new privacy teams and reveal the lean metrics that secure executive buy‑in. Expect actionable takeaways, and a forward‑looking vision of privacy‑by‑design done right. Additonal topics we covered included -

  • Privacy compliance vs. a full privacy program.
  • Smallest viable privacy team (and how to make every function co-own the mission)
  • Spreadsheet pain point → when to adopt a privacy-tech platform
  • The 3 KPIs that tell you instantly if the program is healthy
  • First 90 days of a Privacy Program

To get access to this talk, join our community above!

About the Speaker: Debra J. Farber

Debra J. Farber is a seasoned privacy executive and leader with over 20 years of experience operationalizing privacy across complex, data-driven environments. She spent the bulk of her career operationalizing privacy programs at companies large and small before shifting left into privacy engineering. She currently serves as Privacy Engineering Manager at Lumin Digital, where her team embeds privacy early into a cloud-native digital banking platform. Debra has led privacy and security programs at Amazon Prime Video, AWS, Visa and IBM, created and hosted The Shifting Privacy Left Podcast, which published 63 episodes spotlighting how privacy engineers can integrate privacy early and effectively into the software development lifecycle before code is shipped and PII is ever collected. She's also a Member of the USENIX PEPR Conference's Programming Committee and is an Advisor to the Institute of Operational Privacy Design (IOPD).